The 2026 field guide to every US law that governs AI in hiring, what each one actually requires, and how to comply before the deadlines land.
US state legislatures passed 131 AI-related laws in 2024, up from a single law in 2016 - Stanford HAI 2025 AI Index. That number is not a forecast or a survey of intentions. It is a body of enforceable statute that already decides whether the resume-screener, the video-interview scorer, and the ranking model in your applicant tracking system are legal to run on the people applying to your jobs.
Here is the problem that makes 2026 different from every year before it: there is still no federal AI hiring law, and in 2025 the federal government stepped back rather than forward. The EEOC quietly removed its AI guidance from its own website, and a proposed ten-year federal freeze on state AI rules died in the Senate. The vacuum did not stay empty. It filled with a patchwork of state and city laws that now vary by ZIP code, so the rules you must follow depend on where your candidate is sitting, not where your company is headquartered.
This guide maps that patchwork the way a compliance officer actually needs it: jurisdiction by jurisdiction, with the exact effective dates, the specific triggers that pull you into scope, the real penalty numbers, and a practical playbook you can run before the next hiring cycle. It covers New York City's audit law, Illinois, Colorado, California, Texas, Utah, and the guidance states, the federal floor that still applies even without new rules, and the EU AI Act's long arm into American hiring. Everything here reflects late 2025 and 2026 law, because in this area a summary written eighteen months ago describes rules that have since been delayed, amended, or vetoed.
Written by Yuma Heymans (@yumahey), who built HeroHunt.ai and has spent five years shipping autonomous sourcing software inside exactly the regulatory crossfire this guide maps, which mostly means reading a great many statutes so recruiters do not have to.
Contents
- The 2026 Compliance Landscape in One Page
- The Federal Layer: Old Laws, New Silence
- New York City: The Audit Law Nobody Reads
- Illinois: Two Laws, One January 2026 Deadline
- Colorado: The Law That Keeps Moving
- California: The Quiet Heavyweight
- Texas and Utah: The Light-Touch Model
- The Guidance States and the Vetoes
- The Federal Wildcard: The Moratorium That Almost Was
- Hiring in Europe: Why the EU AI Act Reaches US Employers
- How a Bias Audit Actually Works
- The Compliance Playbook for 2026
- Where This Goes Next: 2027 and Agentic Hiring
- The Bottom Line
1. The 2026 Compliance Landscape in One Page
The single most important fact about AI hiring law in 2026 is that compliance is now determined by candidate location, not company location. A company headquartered in Austin that recruits an engineer living in Brooklyn is subject to a New York City audit law, an applicant in Chicago pulls in an Illinois notice rule, and a candidate in Munich pulls in the European Union's AI Act. Because most employers recruit nationally and increasingly globally, the practical result is that a mid-sized company is usually subject to several regimes at once, each written by a different body with a different theory of what the problem is.
Those theories fall into three families, and recognizing which one a given law belongs to tells you most of what you need to do. The first family is transparency and audit: tell candidates a machine is involved and prove the machine was tested for bias, which is New York City's model. The second is anti-discrimination by extension: existing civil-rights law already bans discriminatory outcomes, so an AI tool that produces them is illegal regardless of intent, which is the theory behind Illinois, California, New Jersey, and the federal statutes. The third is comprehensive risk regulation on the European model, where "high-risk" AI carries documentation, impact-assessment, and governance duties, an approach Colorado adopted, then substantially retreated from.
Sorting a law into its family is the fastest way to know what it demands. A transparency-and-audit law like New York City's cares whether you disclosed and tested, not whether the outcome was perfect, so the work is procedural and provable. An anti-discrimination-by-extension regime cares only about the outcome, so a tool can be fully disclosed and still illegal if it skews results, which makes these the laws with real litigation risk. A comprehensive risk law asks for a governance apparatus, impact assessments and risk programs and documentation, which is why it is the most expensive to satisfy and, as Colorado found, the hardest to sustain politically. Almost every specific obligation in this guide is a variation on one of those three demands.
The chart below shows why this happened so fast. State AI lawmaking was essentially flat until 2023 and then went vertical, and hiring was one of the first domains regulators reached for because the harms are concrete and the case law already exists.
State AI lawmaking went vertical in 2024

The reason employment law led the wave is that hiring discrimination is one of the oldest and best-litigated areas of American law, so regulators did not have to invent a standard. They could bolt AI onto Title VII, the Age Discrimination in Employment Act, and the Americans with Disabilities Act, all of which already prohibit discriminatory hiring outcomes. That is why an employer cannot treat "the vendor's algorithm did it" as a defense: the liability attaches to the hiring decision, and the hiring decision is yours. Understanding that principle is the foundation for everything below, because it means the states that passed no AI-specific law at all are not safe harbors. They are simply jurisdictions where the old law applies without a new label.
To make the landscape scannable before we go deep, the table below summarizes the operative US regimes as of 2026, the trigger that pulls you into scope, and who enforces them. Each row is unpacked in its own chapter.
| Jurisdiction | Core law | Status / effective date | What triggers it | Enforcer |
|---|---|---|---|---|
| Federal | Title VII, ADA, ADEA | In force; EEOC AI guidance withdrawn 2025 | Any discriminatory hiring outcome | EEOC, courts, private suits |
| New York City | Local Law 144 (AEDT) | Enforced since July 5, 2023 | Using an automated employment decision tool | DCWP |
| Illinois | HB 3773 (amends IHRA) | Effective January 1, 2026 | AI in employment decisions | Illinois Dept. of Human Rights |
| Illinois | AI Video Interview Act | In force since 2020 | AI analysis of video interviews | Illinois Dept. of Labor |
| Colorado | Colorado AI Act (SB 24-205) | Delayed to January 1, 2027, scaled back | Automated decision technology | Colorado Attorney General |
| California | FEHA ADS regulations | Effective October 1, 2025 | Automated-decision systems in employment | Civil Rights Department |
| Texas | TRAIGA (HB 149) | Effective January 1, 2026 | Intent to unlawfully discriminate via AI | Texas Attorney General |
| Utah | AI Policy Act (SB 149) | In force; amended 2025 | Generative AI consumer interactions | Utah Division of Consumer Protection |
| New Jersey | DCR guidance (NJLAD) | Issued January 2025 | Algorithmic discrimination | NJ Attorney General / DCR |
| Maryland | HB 1202 | In force since 2020 | Facial recognition in interviews | Private and agency action |
| EU (for US hiring in Europe) | EU AI Act | High-risk duties from August 2, 2026 | AI affecting EU-based candidates | National market authorities |
Reading the table top to bottom reveals the practical shape of 2026: a cluster of hard deadlines lands within a few months of each other, Illinois and Texas on January 1, California already live since October, and the EU's high-risk regime in August. That clustering is not a coincidence of the calendar so much as the compounding of several years of legislative sessions finally taking effect at once, and it is why compliance teams that treated AI hiring rules as a future problem in 2024 are now behind. The rest of this guide works through each regime in the order a US employer typically encounters them, starting with the federal floor that applies everywhere.
2. The Federal Layer: Old Laws, New Silence
The federal government's posture on AI hiring in 2026 is best summarized as old laws, new silence: the statutes that ban discriminatory hiring are fully in force, but the agency guidance explaining how they apply to algorithms has been withdrawn. On his first day of the term, the administration signed an executive order titled "Removing Barriers to American Leadership in Artificial Intelligence," which revoked the prior administration's AI order and directed agencies to roll back AI policies seen as burdensome - K&L Gates. Within days, the EEOC removed its technical guidance on AI under the ADA and Title VII from its website, and the OFCCP's contractor guidance disappeared alongside it.
It is a serious mistake to read that withdrawal as deregulation. Guidance is not law, and pulling guidance does not repeal a statute. Title VII, the ADEA, and the ADA remain fully enforceable, which means an AI tool that screens out older applicants, disadvantages a protected group, or fails to accommodate a disability still creates liability - Cooley. What changed is the enforcement emphasis and one theory of liability. An April 2025 executive order directed federal agencies to deprioritize disparate-impact liability, the doctrine that reaches unintentional discrimination, which is precisely the theory most relevant to biased algorithms that no one designed to discriminate - Epstein Becker Green.
Here the federalism turns sharp. Disparate impact under Title VII may be de-emphasized at the federal level, but it is written directly into several state laws, and it is those state regimes, not the EEOC, that now carry the enforcement weight. An employer that reads the federal retreat as permission is exposed on two fronts: state agencies that adopted the impact standard, and private plaintiffs who do not need the EEOC's blessing to sue. The single most important 2025 case makes this concrete.
Mobley v. Workday is the case every talent leader should know by name. A California federal judge granted conditional certification of a nationwide collective action under the ADEA, allowing applicants aged 40 and older who were rejected through Workday's AI screening tools since September 2020 to join the suit - Proskauer. The court had earlier accepted the theory that a vendor supplying AI screening can be treated as an agent of the employer, exposing the software maker itself to discrimination liability, and the disparate-impact allegations survived dismissal even as intentional-discrimination claims were cut. By January 2026 the court-authorized opt-in period had opened, turning a single plaintiff's complaint into a potential class of millions - Forbes.
The disability dimension is the one employers most often forget, and it is where AI hiring tools are most quietly exposed. The ADA requires reasonable accommodation, and many AI assessments (timed cognitive games, video interviews scored for facial expression and tone, one-way recorded screens) can systematically disadvantage applicants with disabilities in ways that have nothing to do with the job. A candidate with a speech disability marked down by a voice-analysis model, or a blind applicant unable to complete a visual game-based assessment, has a discrimination claim that no guidance withdrawal touches, because the accommodation duty lives in the statute itself. The withdrawn EEOC guidance had explained exactly these scenarios, so its removal did not shrink the risk, it removed the roadmap while leaving the liability fully in place.
Federal contractors carry an extra layer even now. The OFCCP historically pressed contractors to validate their selection procedures, and while its AI-specific guidance was pulled alongside the EEOC's, the underlying duty to avoid discriminatory selection survives in the contract terms themselves. The honest summary of the federal layer in 2026 is therefore that the rulebook got quieter, not smaller: the same statutes apply, the same outcomes create liability, and the main change is that an employer must now navigate them without the agency roadmaps that used to explain how.
The enforcement precedent is older and even clearer. In 2023 the EEOC settled its first AI hiring case when iTutorGroup agreed to pay $365,000 after its recruiting software automatically rejected more than 200 applicants for being too old, women over 55 and men over 60 - EEOC. The discrimination surfaced because one applicant submitted two identical applications with different birth dates and only the younger one advanced. The lesson for 2026 is that federal anti-discrimination law does not require a special AI statute to bite, it requires only a biased outcome and a plaintiff, and both are now abundant. The states, meanwhile, decided the federal floor was not enough.
3. New York City: The Audit Law Nobody Reads
New York City's Local Law 144 was the first AI hiring law in the United States with teeth, and it remains the template other jurisdictions borrow from. It regulates automated employment decision tools, or AEDTs, defined as computational tools that substantially assist or replace a hiring or promotion decision. An employer using such a tool on a candidate for a job in the city must do three things: commission an independent bias audit within the prior year, publish a summary of that audit's results on its website, and give candidates at least ten business days' notice that an AEDT will be used - NYC Department of Consumer and Worker Protection. The law was enacted in 2021, took effect at the start of 2023, and has been enforced since July 5, 2023.
The definition is where the law gets slippery, and where many employers wrongly conclude they are exempt. An AEDT is a tool that uses machine learning or statistical modeling to substantially assist or replace discretionary decision-making, and the phrase substantially assist has no bright line. A resume-ranking model that sorts applicants clearly qualifies, but employers dispute whether a tool that merely flags keywords or schedules interviews crosses the threshold, and that ambiguity has quietly become a compliance strategy: argue the tool does not substantially assist, and the audit duty evaporates. The city also requires the auditor to be genuinely independent, with no financial stake in the tool, which forecloses the comfortable arrangement of letting a vendor grade its own homework.
The audit itself is not a vague attestation. It measures selection rates across sex, race and ethnicity categories and computes an impact ratio for each group, the mechanism borrowed from decades of employment-testing law that we unpack in Chapter 11. Penalties are modest per instance but compound quickly: $500 for a first violation and between $500 and $1,500 for each subsequent violation, with each day of continued use and each candidate arguably counting separately - Warden AI. On paper, this is a strong regime. In practice, it has become the clearest cautionary tale about the gap between passing a law and enforcing one.
The gap is documented. A research team of 155 student investigators examined 391 employers subject to the law and found that only 18 had posted the required bias audit and just 13 had posted the transparency notice, a compliance rate under five percent - arXiv "Null Compliance" study. The chart below shows the scale of the shortfall, and it is worth sitting with, because it explains why other states designed their laws differently.
NYC Local Law 144 compliance in practice
Those numbers describe the first two years of the law, and they might have stayed a footnote if the city's own watchdog had not confirmed them from the enforcement side. In December 2025 the New York State Comptroller published an audit of how the city agency was enforcing Local Law 144 and concluded that enforcement was ineffective - NY Office of the State Comptroller. The agency had reviewed 32 companies' bias audits and flagged only one problem, while the Comptroller's own reviewers found at least 17 potential non-compliances in the same set of companies, and three-quarters of test complaints to the city's 311 line were misrouted and never reached the enforcing agency at all.
The practical read for employers is counterintuitive. Low enforcement so far is not a reason to relax, it is a reason to expect a correction, and the correction is now on the record. The Comptroller's report came with recommendations the agency has committed to adopting, and outside counsel read the audit as a signal that scrutiny is about to rise - DLA Piper. An employer that has been quietly non-compliant because everyone else was is exactly the profile a newly motivated regulator looks for first. What the published summary must actually contain is more revealing than most employers expect, and posting it is a small act of transparency with outsized consequences. The summary states the tool's selection rates and impact ratios for each demographic category, the date of the most recent audit, and the categories used, which means an employer that posts an honest audit is publishing evidence of its own tool's disparities for any plaintiff's lawyer to read. That tension, between a transparency law that demands publication and a liability system that punishes disparity, is the quiet reason compliance is so low: some employers would rather absorb the modest audit penalty than advertise a skewed impact ratio. It is not a defensible bet once enforcement tightens, but it explains the behavior the studies keep finding.
The safer posture is to treat the audit and notice requirements as live obligations in 2026, not as a formality the city ignores.
4. Illinois: Two Laws, One January 2026 Deadline
Illinois is unusual because it regulates AI hiring twice, with an early narrow law and a new broad one that takes effect at the start of 2026. The older statute is the Artificial Intelligence Video Interview Act, in force since 2020, which applies when an employer uses AI to analyze video interviews for Illinois positions. It requires the employer to notify the applicant, explain how the AI works and what it evaluates, obtain consent before the interview, limit who sees the video, and delete it within 30 days of a request - Jones Day. It was a targeted rule for a specific technology, and for years it was the extent of Illinois AI hiring law.
That changed with House Bill 3773, which amends the Illinois Human Rights Act and takes effect January 1, 2026. The amendment is broad where the video law was narrow: it makes it a civil rights violation for an employer to use AI in a way that discriminates against a protected class, and it separately prohibits using ZIP codes as a proxy for protected classes - Seyfarth Shaw. The covered decisions are not limited to hiring. They include recruitment, promotion, discipline, discharge, and the terms and conditions of employment, which means the law reaches AI used across the whole employee lifecycle, not just at the front door.
The ZIP code clause deserves attention because it names the single most common way hiring algorithms discriminate without anyone intending it. Location is geographically neutral on its face, but in a segregated housing market a ZIP code can function as a high-fidelity stand-in for race, and a model that weights it will reproduce the segregation of the map it learned from. By banning the proxy directly, Illinois short-circuits the usual defense that the algorithm never saw a protected characteristic. The law's logic is that a variable which predicts protected status as accurately as the status itself is the status, for discrimination purposes.
Illinois also sits atop the most aggressive biometric privacy regime in the country, and the two bodies of law reinforce each other for anyone using video assessment. The state's Biometric Information Privacy Act has produced enormous class-action settlements over the collection of faceprints and voiceprints without consent, and a video interview tool that analyzes a candidate's face or voice can trigger it independently of the hiring statutes. An employer running AI video interviews on Illinois candidates is therefore exposed on three fronts at once: the video interview law's notice-and-consent rules, the new Human Rights Act amendment's discrimination and notice duties, and biometric liability with statutory damages per violation. That stacking is why Illinois, not Texas, is often the state that forces a vendor change.
The second obligation is notice. Employers who use AI for the covered decisions must tell employees and applicants that AI is being used, a requirement whose details the Illinois Department of Human Rights was directed to flesh out through rulemaking. The compliance move for 2026 is therefore twofold: first, inventory every place AI touches an employment decision and confirm none of them uses geography as a hidden proxy, and second, build the notice into the application and review flow before January. Because HB 3773 routes enforcement through the existing civil-rights complaint process, a violation is not a standalone technical fine, it is a discrimination charge with the damages and reputational exposure that category carries.
5. Colorado: The Law That Keeps Moving
Colorado wrote the most ambitious AI law in the country and then spent two years walking it back, which makes it the clearest case study in how hard comprehensive AI regulation is to actually stand up. The Colorado AI Act, or SB 24-205, was signed in 2024 as the first US law to impose European-style duties on high-risk AI systems, a category that expressly includes systems used to make consequential employment decisions - Greenberg Traurig. As originally written, it required developers and deployers to use reasonable care to avoid algorithmic discrimination, conduct impact assessments, run a risk-management program, disclose AI use to consumers, and offer a right to appeal or correct adverse decisions.
Then the dates began to slip. The original February 1, 2026 effective date was pushed to June 30, 2026 during a special legislative session, after the governor and legislators concluded the law imposed costs the state was not ready to absorb and needed more time to amend - Hunton Andrews Kurth. That delay was itself only an interim step. In May 2026 the legislature passed and the governor signed SB 26-189, which delayed the effective date again to January 1, 2027 and, more consequentially, rewrote the substance of the law - Carpe Datum Law.
The rewrite is a genuine pivot, not a tweak, and it changes what Colorado will require of employers. The 2026 amendment removed the duty to prevent algorithmic discrimination, the mandatory impact assessments, and the deployer risk-management program, and it dropped the "high-risk AI system" framework entirely. In their place it installed a lighter disclosure-and-rights model for automated decision technology: developer documentation of intended uses and limits, clear notice at the point of interaction, a disclosure to the consumer within 30 days of an adverse outcome, and consumer rights to access their data, correct factual errors, and request human review - TechTimes. Enforcement runs exclusively through the state attorney general, with no private right of action, and low-stakes activities like fraud prevention and content moderation are carved out.
The story behind the retreat is as instructive as the statute itself. Colorado passed the original law in a rush at the end of a session, with the sponsor openly acknowledging it would need fixing before it ever took effect, and the two years since were a running negotiation between advocates who wanted the nation's first real AI civil-rights law and a business community warning of compliance costs on every small deployer in the state. A special session failed to reach a compromise, the effective date slipped twice, and the final rewrite arrived only after the federal executive branch publicly held Colorado up as a cautionary example of state overreach. The result is a law that now looks less like Europe and more like Utah, and it happened in the one state that tried hardest to be different.
For a compliance planner, Colorado teaches two lessons at once. The first is practical: do not build your 2026 program around the original Colorado AI Act, because most of the obligations people spent 2024 and 2025 preparing for no longer exist, and the effective date is now 2027. The second is strategic: the "comprehensive European model" that Colorado pioneered has, in Colorado itself, been judged too heavy for a single state to carry, which tells you something about where the rest of the country is likely to land. The momentum in 2026 is toward disclosure and existing-law extension, not toward Colorado's original vision, and the states covered next confirm it.
6. California: The Quiet Heavyweight
California did not pass a headline AI hiring statute, and precisely because of that many employers underestimate it, but the state now has some of the most operationally demanding rules in the country. They arrived through regulation rather than legislation. The California Civil Rights Council finalized rules under the Fair Employment and Housing Act governing automated-decision systems in employment, and they took effect October 1, 2025 - Mayer Brown. Because they interpret an existing civil-rights statute, they apply to any employer with five or more employees, a far lower threshold than most AI laws.
Two features make the California rules bite harder than a simple notice requirement. First, they extend liability through an agency theory to the vendors and consultants that build or administer the tools, so a discriminatory outcome can implicate the software maker as well as the employer, echoing the logic of the Workday litigation - Paul Hastings. Second, they impose a four-year record-retention duty covering the ADS itself, the selection criteria it applied, and its outputs, which means an employer must be able to reconstruct what the machine did and why, years after a candidate was rejected. The regulations also treat evidence that an employer tested its tools for bias as relevant to a discrimination defense, quietly making anti-bias testing a practical necessity rather than an optional virtue.
California's legislature has been active on top of the regulations, and two efforts matter for 2026 planning. The No Robo Bosses Act, Senate Bill 7, advanced through the legislature to require human oversight and notice when automated systems are used to make significant employment decisions, part of a broader push to keep a person accountable for machine-driven calls - Covington. Separately, the California Privacy Protection Agency finalized rules on automated decisionmaking technology under the state privacy law, adding risk-assessment and opt-out obligations whose compliance dates phase in during 2027.
The No Robo Bosses framing captures a policy anxiety spreading well beyond California: the fear that automated management, not just automated hiring, will make consequential calls about promotion, discipline, and termination with no human anyone can hold responsible. That anxiety is why several states are converging on a human-in-the-loop mandate as a lowest-common-denominator rule, easier to legislate than a full audit regime and more politically durable than Colorado's comprehensive model. For an employer, the practical effect is that designing a genuine human checkpoint into every consequential automated decision is not just California-specific hygiene, it is a hedge against the direction the whole country is drifting.
The record-retention duty is the one that quietly reorganizes a talent operation, because four years is a long time to preserve not just who was hired but every input the machine considered. In practice it means logging the version of the model, the features it weighed, the score it produced, and the human decision that followed, for every applicant, and keeping all of it queryable long after the requisition closed. Most applicant tracking systems were never built to retain that granularity, so compliance is as much a data-engineering project as a legal one. An employer that discovers the requirement only after a candidate files a complaint cannot manufacture the records retroactively, which is exactly the point of the rule: it forces the evidence to exist before the dispute does.
The compounding of these regimes is the real story. An employer recruiting Californians in 2026 is already subject to the FEHA ADS rules today, must retain four years of decision records starting now, faces vendor-liability exposure that changes how procurement contracts should be written, and has privacy-law obligations arriving next. None of it came with the fanfare of a named "AI hiring law," which is exactly why it is easy to miss and expensive to ignore. The state's approach shows where extension-of-existing-law regulation can go when a well-resourced agency drives it, and it sets a template other large states are watching.
7. Texas and Utah: The Light-Touch Model
Texas and Utah represent the deliberate opposite of the European model, and they matter in 2026 both because Texas is enormous and because the two states show what "light-touch" AI regulation actually looks like in statute. The Texas Responsible Artificial Intelligence Governance Act, HB 149, was signed in June 2025 and takes effect January 1, 2026 - Norton Rose Fulbright. Where Colorado's original law reached unintentional discrimination, TRAIGA reaches only intentional conduct: it prohibits developing or deploying AI with the intent to unlawfully discriminate against a protected class. That intent standard is a much narrower target, and it deliberately avoids the disparate-impact theory that makes algorithmic bias cases winnable.
The enforcement design reinforces the light touch. TRAIGA gives exclusive enforcement to the Texas Attorney General, provides no private right of action, and requires a 60-day cure period before any penalty, so an employer that fixes a flagged problem within two months generally avoids liability. The penalties themselves are tiered: roughly $10,000 to $12,000 for a curable violation, $80,000 to $200,000 for an uncurable one, and up to $40,000 per day for continuing violations - K&L Gates. The law also creates a regulatory sandbox for companies testing AI systems, a pro-development signal that tells you which way Texas leans.
Texas TRAIGA civil penalty tiers
Those numbers look large, but the intent requirement is what determines whether they ever apply, and in practice a plaintiff or the attorney general must show an employer meant to discriminate, which is far harder than showing a skewed outcome. That is the core trade-off of the Texas model: lower compliance burden, but also weaker protection for candidates, and it is why civil-rights advocates criticized the intent standard as largely symbolic. For a national employer, the practical implication is that Texas will rarely be your binding constraint. If you are already meeting the tougher standards in New York City, Illinois, and California, you are comfortably inside TRAIGA.
There is one exception worth flagging, because it is where TRAIGA has real bite: government use. The law imposes tighter rules on state agencies deploying AI, including on biometric identification, than it does on private employers, so a company doing business with Texas public entities or operating in regulated public-sector adjacencies should read the act more carefully than a purely private employer needs to. For everyone else, the honest planning assumption is that Texas sets a floor you will clear automatically if you comply with the coastal regimes, and the value of reading TRAIGA closely is mostly to confirm you can safely deprioritize it rather than to discover a new obligation.
Utah rounds out the light-touch group with a disclosure-first approach aimed at generative AI rather than hiring specifically. The Utah Artificial Intelligence Policy Act, SB 149, took effect in May 2024 and requires businesses to disclose when a consumer is interacting with generative AI. Amendments in 2025 narrowed that duty to high-risk interactions and situations where a consumer asks, added a safe harbor for systems that clearly identify themselves as non-human, and extended the law's life to 2027 - Future of Privacy Forum. Utah is rarely the decisive rule for a hiring team, but it signals the same philosophy as Texas: tell people a machine is involved, and otherwise let the market run.
8. The Guidance States and the Vetoes
Between the states with statutes and the states with nothing sits a third category that is easy to overlook and genuinely dangerous to ignore: states where the attorney general has declared that existing law already covers algorithmic discrimination. These jurisdictions passed no new AI bill, so a checklist that only tracks statutes shows them as blank, but their enforcement position can be as aggressive as any statute. New Jersey is the clearest example, and it moved early.
In January 2025 the New Jersey Attorney General and the Division on Civil Rights issued formal guidance stating that the New Jersey Law Against Discrimination applies to algorithmic discrimination, and it went further than most by declaring that an employer can be liable even if it did not build the tool and was unaware of its bias - New Jersey Office of the Attorney General. The state paired the guidance with a new Civil Rights and Technology Initiative to investigate exactly this kind of harm. Massachusetts took the same route in 2024, when its attorney general issued an advisory confirming that the state's consumer-protection and anti-discrimination laws reach AI systems that produce discriminatory results - Massachusetts Office of the Attorney General. Neither state needs a new law to bring a case.
The practical danger of the guidance states is that they are invisible to the usual compliance scan. A team that builds its program from a list of enacted AI statutes will mark New Jersey and Massachusetts as blank and move on, never noticing that both attorneys general have already announced they will treat a biased hiring algorithm as a violation of laws that carry real damages. More states are lining up behind the same theory, because it costs a legislature nothing: the anti-discrimination statute already exists, and the attorney general simply has to say out loud that it covers algorithms. For a national employer the lesson is to plan for the standard, not the statute, because the standard (do not let your tools discriminate, and be able to prove you checked) is the one obligation every regime in this guide shares.
A handful of states also regulate a specific slice of the hiring stack without a broad AI statute. Maryland has required, since 2020, that an employer obtain an applicant's written consent before using facial recognition during a job interview, a narrow but real rule for any company using video assessment tools with Maryland candidates - National Law Review. Illinois's biometric privacy law reaches similar territory from a different direction. The pattern across these states is that the absence of a comprehensive law does not mean the absence of obligation, and the enforcement is often through private lawsuits that carry statutory damages.
The other half of this chapter is the roads not taken, because they reveal the political ceiling on AI hiring regulation. Virginia came closest to a comprehensive law: its legislature passed the High-Risk AI Developer and Deployer Act, HB 2094, which would have imposed Colorado-style duties including on employment AI, but the governor vetoed it in March 2025, calling the framework too burdensome for startups and arguing existing law was sufficient - IAPP. Connecticut's comparable bill also failed. The takeaway for a national employer is that the comprehensive model is stalling at the state level, and the durable regimes you must actually comply with are the audit laws, the civil-rights extensions, and the disclosure rules, not the European-style bills that keep dying in committee or at the governor's desk.
9. The Federal Wildcard: The Moratorium That Almost Was
The single biggest uncertainty hanging over this entire patchwork in 2026 is whether Congress will preempt it, and in 2025 that question came within one vote of being answered. A provision in the federal budget reconciliation bill would have imposed a ten-year moratorium on state and local AI laws, a freeze that would have suspended enforcement of nearly every regime in this guide, from New York City's audit law to Colorado's rewritten statute. The provision had real momentum, and for several weeks it looked likely to pass.
It did not survive. On July 1, 2025, the Senate stripped the moratorium in a 99 to 1 vote, an almost unheard-of margin in a polarized chamber, with only a single senator voting to keep it - US Senate Committee on Commerce. The amendment to remove it was bipartisan, and the debate made clear that a freeze would have halted more than a thousand AI bills then moving through state legislatures. The larger bill was signed into law days later without the moratorium, leaving the states free to keep regulating.
The reason this matters for compliance planning, rather than as political trivia, is that it settled the near-term structure of the field. For 2026, the states are the regulators, full stop, and an employer cannot wait for a unifying federal standard that the Senate just declined to create by an overwhelming margin. The practical instruction is to build for the patchwork, because the patchwork is the system, not a temporary condition awaiting federal cleanup.
That said, the 99 to 1 vote closed one door and left another ajar. The margin reflected opposition to that specific moratorium, not a settled view that AI should never be regulated federally, and the executive branch has continued to signal interest in a pro-development national framework that could preempt some state rules by other means. A wise compliance program treats federal preemption as a live possibility for 2027 and beyond, without betting on it for 2026.
It is worth understanding why the moratorium drew such rare unanimity, because the reasons will recur. Senators from both parties balked at freezing state consumer protections for a decade while Congress had passed no federal replacement, which would have left citizens with neither state nor federal safeguards during the fastest technological shift in a generation. States also guarded their own authority: AI touches insurance, elections, child safety, and hiring, all areas states have always regulated, and a blanket freeze read as a federal land grab. Those structural objections did not vanish with the vote, which means any future preemption attempt will have to offer a genuine federal standard in exchange, not merely a prohibition on state ones. In the meantime, the geography that most complicates an American employer's obligations is not a US state at all. It is the European Union.
10. Hiring in Europe: Why the EU AI Act Reaches US Employers
Most US employers assume the EU AI Act is a European problem, and most US employers are wrong, because the Act reaches any company whose AI affects people located in the European Union regardless of where the company sits. If you recruit a candidate living in Germany, France, or any member state, and an AI system screens, ranks, or assesses that person, you are within scope. The mechanism is the Act's extraterritorial reach, and it works the same way the GDPR's did, which is why compliance teams that lived through 2018 should feel a familiar dread - Hunton Andrews Kurth.
The reason hiring is squarely in scope is that the Act classifies employment AI as high-risk. Annex III of the Act lists AI systems used for the recruitment or selection of individuals, including systems that target job ads, filter applications, and evaluate candidates, as high-risk, along with systems that make decisions about promotion, task allocation, and performance - EU Artificial Intelligence Act, Annex III. High-risk classification is the heavy tier of the Act, and the obligations attached to it are real: risk management, data governance, human oversight, transparency to affected people, and technical documentation that lets a regulator reconstruct the system's behavior.
None of this is a uniquely European impulse, and the obligations do not all arrive at once, which is the single most useful thing for a US employer to internalize. The Act phases in over several years, so some duties are already live while the ones that matter most for hiring land in 2026, and reading the staggered timeline tells you exactly what to prepare first. The figure below lays out that implementation schedule.
The EU AI Act phases in, and 2026 is the year employment AI is caught

Within that timeline, the tranche that governs hiring is the high-risk one arriving in 2026, and the duty US employers underestimate most within it is human oversight. The Act does not accept a nominal reviewer; it expects a person with the competence and authority to understand the system's output, override it, and stop it if needed, which for a hiring tool means a recruiter who can actually read and reverse an AI rejection. Meeting the standard also demands real due diligence on the vendor, because a US-built tool was very likely not designed to EU high-risk specifications, and the deployer cannot assume conformity, it must verify it in writing before August.
The timeline is what makes this a 2026 concern rather than a distant one. The Act's prohibitions on the most dangerous uses took effect in early 2025, and the full slate of high-risk obligations becomes enforceable on August 2, 2026, which for employment AI is the date that counts. A US company recruiting in Europe has effectively the same summer deadline as its obligations to Illinois and its pending obligations elsewhere, and it cannot assume a US-built hiring tool was designed to meet EU high-risk requirements. That must be verified with the vendor, in writing, because the deployer carries duties of its own regardless of who built the system.
The penalties give the deadline its weight. A deployer that fails to meet its high-risk obligations faces fines up to 15 million euros or 3 percent of global annual turnover, whichever is higher, an exposure large enough that European hiring should be a board-level line item for any US company that does it at scale. Layered on top is Article 22 of the GDPR, which gives individuals a right not to be subject to purely automated decisions with significant effects, a right that predates the AI Act and already applies. The combined message is that the most demanding AI hiring regime a US employer is likely to face in 2026 was not written in Washington or Sacramento. It was written in Brussels, and it applies to anyone recruiting across the Atlantic.
11. How a Bias Audit Actually Works
Underneath every one of these laws sits the same technical question, and it is worth understanding directly rather than through a vendor's marketing, because it is simpler than it sounds and it determines whether your tools pass or fail. The question is whether an AI hiring tool selects candidates from different groups at meaningfully different rates. The standard method comes from decades of employment-testing law, and its anchor is the four-fifths rule.
The four-fifths rule works like this. For each group, you compute the selection rate, the share of applicants from that group the tool advanced. You then compare each group's rate to the rate of the most-selected group by dividing one by the other, producing an impact ratio. If any group's ratio falls below 0.8, meaning that group is selected at less than 80 percent of the top group's rate, the tool shows adverse impact and demands scrutiny. A model that advances 50 percent of one group's applicants but only 30 percent of another's produces a ratio of 0.6, well under the threshold, and that gap is the evidence a plaintiff or regulator builds a case around.
Walk it through with numbers, because the arithmetic is the whole ballgame. Suppose a resume screener advances 100 of 200 male applicants, a 50 percent selection rate, and 66 of 220 female applicants, a 30 percent rate. Divide 30 by 50 and the impact ratio is 0.6, comfortably under the 0.8 line, so the tool shows adverse impact against women even though nothing in it explicitly references sex. Now add the intersectional problem: the same tool might pass for women in aggregate yet fail badly for women over 40, or for Black women specifically, and a shallow audit that checks one axis at a time will miss it. This is why credible audits compute ratios for intersecting categories, and why a single headline pass rate proves almost nothing.
The New York City audits that employers actually posted give us a rare real-world picture of where these ratios land. When researchers gathered every publicly posted audit under Local Law 144 and plotted the impact ratios, the distribution clustered above the 0.8 line, as the figure below shows.
What real posted audit numbers look like

Read cynically, that clustering is exactly what you would expect from a self-selected sample: employers who ran an audit, saw a passing ratio, and chose to publish it, while those with damning numbers stayed quiet. The plot is therefore less a clean bill of health for AI hiring tools than a portrait of which results make it into public view, which is the same selection effect that makes the low posting rate so hard to interpret in the first place.
Two subtleties separate a real audit from a checkbox. The first is that adverse impact is not automatically illegal: an employer can defend a tool that is job-related and consistent with business necessity, but the burden shifts to the employer to prove it, and "the vendor said it was fine" is not proof. Meeting that burden is harder with a machine-learning model than with a traditional test, and the difficulty is often the real story. A validated cognitive test can point to decades of research linking the trait it measures to job performance, but a proprietary model that learned its weights from a company's own past hires may simply have learned to reproduce that company's historical preferences, including its historical biases. Proving such a model is job-related, rather than merely predictive of who got hired before, can be genuinely impossible, and that is the trap: a tool can be highly accurate at predicting past decisions and still fail the legal test, because the law asks whether it predicts the job, not whether it predicts the hiring manager. The second subtlety is that the audit is only as honest as its data. An impact ratio computed on a tiny or unrepresentative applicant pool can hide real bias or invent phantom bias, which is why New York City requires the audit to be conducted by an independent party rather than the tool's own maker. The methodology is public and old, but applying it rigorously to a modern machine-learning model, with intersectional categories and shifting applicant pools, is genuinely hard.
That difficulty created an industry, and knowing the players helps you buy the right thing. A cluster of specialist firms now conducts these audits and builds the tooling around them: BABL AI offers independent third-party bias audits structured for the New York City law, Warden AI provides continuous audit and monitoring aimed at both employers and HR-tech vendors, Holistic AI pairs governance software with audit workflows, and FairNow, now part of a larger governance platform, specializes in synthetic-data techniques for tools that lack enough real applicant history to test conventionally - BABL AI. Pricing is quoted rather than published, and it scales with the number of tools and the depth of review, but the category exists because doing this correctly in-house is beyond most talent teams. The point of understanding the method, even if you outsource the execution, is that it lets you ask a vendor the one question that matters: show me the impact ratios, computed by someone who does not profit from the answer.
12. The Compliance Playbook for 2026
Everything above converges on a manageable set of actions, and the good news is that the tougher regimes subsume the weaker ones, so a program built for the strictest law you touch will satisfy most of the others. The first and most important step is not legal at all. It is an inventory. You cannot comply with laws that regulate "automated employment decision tools" if you do not know which tools in your stack qualify, and most companies underestimate the count because AI is now embedded in applicant tracking systems, sourcing platforms, assessment vendors, and scheduling tools that no one thinks of as "AI." Map every point where software screens, ranks, scores, or filters a person, and record who built it and what it decides.
With the inventory in hand, the substantive work falls into a short sequence that applies across jurisdictions. These are the load-bearing obligations, drawn from the regimes above:
- Notice to candidates that AI is being used, worded plainly and delivered before the AI runs
- An independent bias audit of any tool that screens or ranks, refreshed at least annually
- Human review of adverse decisions, so a person is accountable for the outcome
- Record retention of the tool, its criteria, and its outputs, four years where California reaches
- Vendor contracts that require the maker to support audits and indemnify you for its bias
Each of those deserves a sentence of translation into practice, because the wording of a law and the operational reality of satisfying it are different things. Notice is cheap and high-value, so give it everywhere rather than trying to track which states require it. The audit is where money and time go, so scope it to the tools that actually make or heavily influence decisions, not every piece of software. Scoping well is its own skill, and the two failure modes are opposite: audit too little, treating a powerful ranking model as mere administrative software, and you leave the highest-risk tool untested exactly where a plaintiff will look; audit everything, including tools that only format or route data, and you burn budget and calendar on systems that make no protected decision. The discipline is to rank the inventory by how much each tool influences whether a specific person advances, then audit from the top down until you run out of tools that meaningfully affect outcomes. Human review is the requirement most often faked: a rubber-stamp that never overturns the machine is not oversight, and a plaintiff will discover that in deposition. The way to make review real is to give the reviewer both the authority and the information to disagree, which means showing the person why the tool scored a candidate the way it did, in language they can evaluate, and tracking how often they override it, because an override rate of zero is not evidence the machine is perfect, it is evidence the human is asleep. A reviewer who cannot see the tool's reasoning is not supervising it, they are laundering it, and the paper trail of unquestioned approvals becomes the plaintiff's best exhibit. Record retention is a data-engineering task more than a legal one, and it must be built before you need it, because you cannot retroactively reconstruct decisions you did not log.
The vendor dimension is the one most likely to blindside a talent team, and the Workday and California developments are the reason. Because liability can now flow to the tool's maker and because an employer cannot outsource its own duty, the procurement contract is a compliance instrument. Insist that vendors provide the data and cooperation needed for an audit, warrant that their tool has been tested for bias, and indemnify you for discrimination arising from their model. Some AI recruiting platforms are building this in as a feature rather than a liability, offering transparency into how candidates are surfaced and keeping a recruiter in the loop by design, and platforms such as HeroHunt.ai sit in that category, sourcing and reaching out to candidates while leaving the hiring decision with a human. The right question to ask any vendor is not whether their AI is unbiased, a claim no honest vendor makes, but what they will show you and stand behind when a regulator asks.
The decision tree below distills the whole playbook into the single question every employer needs to answer first, which is which laws apply to them at all.
The tree ends where every regime ends, at documentation and human accountability, because those two habits are the common denominator of compliance across a patchwork that otherwise disagrees on almost everything. An employer that gives notice, audits its consequential tools, keeps a human genuinely in the loop, retains records, and holds vendors to account is compliant with the strict laws and comfortably inside the lenient ones. The patchwork is intimidating as a list of statutes and manageable as a set of practices.
13. Where This Goes Next: 2027 and Agentic Hiring
The near future of AI hiring law is being shaped by a technology that outran the statutes: agentic AI, systems that do not just score a candidate but run the whole loop, planning searches, screening applicants, sending outreach, and handling replies with little human involvement. Every law in this guide was written with assistive tools in mind, a machine that helps a recruiter decide, and the harder question the agentic shift poses is who is accountable when the machine decides largely on its own. That is the unresolved issue the 2027 legislative sessions will grapple with, and it is why the "human in the loop" requirement keeps appearing across otherwise dissimilar laws.
The regulatory trajectory is becoming legible even though the statutes lag. Colorado's retreat from the comprehensive model, Virginia's veto, and Texas's intent-only standard together suggest that the European high-risk model is losing in the United States, and that the durable American approach will be disclosure plus existing-law extension: tell people a machine is involved, and let civil-rights and consumer-protection law reach discriminatory outcomes. California shows how far a regulator can push that model without a new statute, and it is the template other large states are most likely to copy, because it requires no politically fraught new law, only aggressive interpretation of the ones already on the books.
For talent teams, the strategic implication is that compliance and good sourcing are converging rather than conflicting. An agent that keeps an auditable record of why it surfaced each candidate, that a recruiter can inspect and overrule, is both a better product and an easier tool to defend, which is why the credible platforms are building explainability and human control in as core features rather than afterthoughts. A tool such as HeroHunt.ai, which automates sourcing and outreach while the hiring decision stays with a person, illustrates the direction: automate the labor, not the accountability. The employers who will struggle in 2027 are the ones who bought a black box because it was fast and cannot now explain what it did.
There is a second-order effect worth naming, because it changes procurement today. As liability spreads to vendors, the market is starting to price compliance into the product, and the tools that can produce an audit trail, document their selection logic, and demonstrate bias testing will command a premium precisely because they lower the buyer's legal exposure. That inverts the usual relationship between compliance and cost: for years the compliant choice was the slower, pricier one, and the emerging pattern is that the defensible tool is also the better-engineered one. Talent leaders who frame the 2026 rules as pure overhead will miss that the same features regulators demand, transparency and human control, are the features that make an AI hiring system trustworthy enough to actually rely on.
The federal picture will keep hovering over all of it. The moratorium's defeat settled 2026, but the pressure for a national standard has not gone away, and a future federal framework, whether it preempts the states or merely coordinates them, would reshape the map again. The safe planning assumption is continued state-led fragmentation through 2027, with the strictest state effectively setting the national floor for any employer that recruits nationally, much as California's emissions rules once set the standard for the auto industry. Build for the strictest rule, keep a human accountable, and the shifting map becomes a manageable background condition rather than a recurring emergency.
14. The Bottom Line
The decision framework for AI hiring compliance in 2026 fits in a paragraph, and it is worth stating plainly after so much detail. There is no federal AI hiring law and, after the Senate's 99 to 1 rejection of the moratorium, there will not be one soon, so your obligations are set by the states where your candidates live and, if you recruit in Europe, by the EU. Because those regimes stack and the strictest ones subsume the rest, the winning move is to build one program to the toughest standard you touch, almost always New York City's audit, California's records and testing, or the EU's high-risk duties, and apply it everywhere.
Concretely, that means five things, and they are the same five regardless of which logo is on your screening tool: inventory every tool that touches a hiring decision, give candidates notice, audit the consequential tools independently and annually, keep a human genuinely accountable for adverse outcomes, and retain the records that prove you did. Do those, and the effective dates clustering in 2026, Illinois and Texas in January, California already live, the EU in August, become a calendar to manage rather than a threat to fear. Skip them, and you are exposed not to a hypothetical future regulator but to the plaintiffs and state attorneys general already bringing cases, with the iTutorGroup settlement and the Workday collective action as the proof that these are live risks, not theoretical ones.
The deeper point is that none of this is really about AI. It is about the oldest promise in employment law, that people are judged on their ability to do the job and not on who they are, applied to a new kind of decision-maker that happens to be made of math. The laws differ on method and disagree on philosophy, but they agree on that promise, and an employer who keeps it, who can show its tools were tested, its candidates were told, and a human stood behind the call, is on the right side of every regime in this guide. The technology will keep changing faster than the statutes. The obligation underneath it has not changed at all.
This guide reflects US and EU AI hiring law as of August 2026. This area moves quickly (Colorado's law alone changed three times in two years), so verify the current status of any specific requirement before you act on it, and treat this as a map rather than legal advice.








