Key takeaway: As of 26 August 2026, four AI-hiring regimes are actually in force: New York City's Local Law 144 bias-audit rules (since 5 July 2023), California's Civil Rights Council automated-decision-system regulations (since 1 October 2025), Illinois' amended Human Rights Act (since 1 January 2026), and the Texas Responsible AI Governance Act (since 1 January 2026). The two most-cited regimes are not in force: Colorado's AI Act was amended and pushed to 1 January 2027, and the EU AI Act's high-risk obligations for hiring systems moved from 2 August 2026 to 2 December 2027. Meanwhile the EEOC's AI technical assistance was removed from its website in early 2025, and Title VII, the ADA and the ADEA still apply exactly as before.
Most AI-hiring compliance content on the web was written against a 2024 or 2025 calendar and is now wrong in the two places it matters most: the dates. Two of the deadlines that vendors and law-firm alerts spent 2025 preparing employers for have moved by more than a year, and one federal guidance document that half the checklists still link to has not existed since 27 January 2025.
The dates moved in the same direction every time, toward later. Colorado's legislature signed S.B. 26-189 less than two months before the previous version of its AI Act was due to bite on 30 June 2026, cutting employer obligations back to three duties and resetting the clock to 1 January 2027 (Littler analysis of S.B. 26-189). In the EU, Regulation (EU) 2026/1744, the "Digital Omnibus on AI", entered into force on 27 July 2026 and moved the compliance deadline for standalone high-risk systems under Annex III, the annex that covers recruitment and selection, from 2 August 2026 to 2 December 2027 (AI Act Explorer, Article 6).
Enforcement pressure is moving the other way. The New York State Comptroller's December 2025 audit of the agency responsible for Local Law 144 concluded that its enforcement system was ineffective, faulting misrouted complaints and superficial review of posted bias audits, and the agency has since committed to most of the audit's recommendations (Office of the New York State Comptroller, 2 December 2025). Penalties under that law run from $500 to $1,500 per violation per day.
This piece is a dated map, not legal advice. Every rule below links to its primary source so you can check the date yourself, because the date is the part that keeps changing.
Which AI hiring laws are in force right now?
| Jurisdiction | Instrument | Status on 26 Aug 2026 | Core duties for employers | Bias audit required? |
|---|---|---|---|---|
| New York City | Local Law 144 of 2021 | In force since 5 July 2023 | Annual independent bias audit, public summary of results, candidate notice with opt-out route | Yes, annual and public |
| California | Civil Rights Council automated-decision-system regulations (FEHA) | In force since 1 October 2025 | ADS use can violate FEHA; keep employment and automated-decision data 4 years; assessments that elicit disability information may be unlawful medical inquiries | No, but anti-bias testing is evidence |
| Illinois | HB 3773, amending the Human Rights Act | In force since 1 January 2026 | No AI use with a discriminatory effect in hiring or promotion; no ZIP code as a proxy for a protected class; notice to applicants and employees | No |
| Texas | Responsible AI Governance Act (HB 149) | In force since 1 January 2026 | Intent-based prohibitions plus governance duties: written AI policies, internal review, tracking of system inputs and outputs | No |
| Colorado | AI Act as amended by S.B. 26-189 | Not yet, effective 1 January 2027 | Pre-use notice, adverse-action process with human review, 3-year record retention; attorney-general enforcement only, no private right of action | No |
| European Union | AI Act, Annex III high-risk (recruitment) | Not yet, moved to 2 December 2027 | Risk management, data governance, technical documentation, logging, human oversight for high-risk hiring systems | Conformity assessment, not a US-style bias audit |
Two entries in that table are the ones people get wrong. Colorado is not just delayed, it is a different law: the amended Act covers automated decision-making that materially influences a major employment decision, and its remedies sit with the attorney general rather than with private plaintiffs. The EU deadline shift is a fixed calendar date rather than a conditional pause, so there is no risk of it springing forward when technical standards land.
Illinois deserves a second look too, because it is the broadest of the four live regimes in one specific way: it applies to any AI use with a discriminatory effect in recruitment, hiring, promotion, discipline or the terms of employment, and it does not carve out tools that merely rank or recommend. It also bans ZIP code as a proxy for a protected class outright, and requires notice when AI is used, with the Illinois Department of Human Rights directed to set the circumstances, timing and means of that notice (Epstein Becker Green analysis of HB 3773). Illinois employers also still sit under the 2019 Artificial Intelligence Video Interview Act and the Biometric Information Privacy Act, which predate all of this.
Is there still federal AI hiring guidance?
There is federal law. There is no current federal AI-specific guidance.
The EEOC published technical assistance in 2023 and 2024 explaining how Title VII and the ADA apply to algorithmic hiring tools, then removed those documents from eeoc.gov in early 2025 after the new administration rescinded Executive Order 14110 and issued Executive Order 14179, which directed agencies to review and suspend policies enacted under the prior AI order (Husch Blackwell, 7 February 2025). Technical assistance was never law: it interpreted Title VII, the ADA and the ADEA, and all three statutes are untouched. The four-fifths rule from the Uniform Guidelines on Employee Selection Procedures is still the practical measuring stick for adverse impact, and an algorithm is still an employment practice.
The federal posture in 2026 is aimed at state law rather than at employers. Executive Order 14365 directed the creation of a Department of Justice AI Litigation Task Force to challenge state AI laws as unconstitutional regulation of interstate commerce or as preempted (DOJ Task Force memorandum). As of the first reporting deadline in March 2026 the Task Force had filed no challenges and no state AI law had been overturned (Mondaq analysis of EO 14365, 24 March 2026).
The practical reading for a talent team: do not treat federal deregulatory noise as a reason to unwind state compliance work. If a state AI statute were struck down tomorrow, the anti-discrimination statutes it sits on top of would still be there, and so would state attorneys general.
Do AI sourcing and outreach tools count as regulated hiring AI?
This is the question that decides how much of the above applies to a sourcing stack, and the answer differs by jurisdiction in a way that is easy to miss.
- New York City is the narrowest, and it says so explicitly. The enforcing agency's guidance states that the requirements do not apply where a tool is used to scan a resume bank, conduct outreach to potential candidates or invite applications, because a covered candidate is someone who has applied to a specific position. Scope turns on whether the tool substantially assists or replaces discretionary decision making for an actual applicant, which happens when the employer relies solely on its output, weights that output above every other criterion, or lets it overrule a human conclusion. We cover the definition, the three-prong test and the audit mechanics in our guide to what counts as an automated employment decision tool.
- California is broader by design. Its definition of an automated-decision system explicitly includes directing job advertisements or recruiting materials to targeted groups and screening resumes for particular terms or patterns, which pulls outbound sourcing and AI candidate screening into scope even without a score. It also defines "agent", so a vendor acting on the employer's behalf does not put distance between the employer and the obligation.
- Illinois has no scope test based on how decisive the tool is: what matters is discriminatory effect in a covered employment decision.
- Texas is the odd one out because its prohibitions are intent-based, so the exposure is less about outcomes than about what your written AI policy says you built or bought the system to do.
The pattern worth internalizing is that a single tool can be out of scope in New York City and in scope in California for the same use, so a multi-state employer cannot run one scope determination. The deciding factors are rarely the vendor's marketing category: they are whether the person has applied to a specific position, whether the tool narrows a pool in a way that carries protected-class signal, and whether a real human decision sits between the model and the outcome.
What should you ask an AI recruiting vendor?
In evaluation calls, compliance is never one question. The three most frequent compliance themes we hear from buyers are the security, data privacy and intellectual-property implications of the platform, where candidate profile and contact data actually comes from, and what security and compliance documentation is available for review. Data provenance and paperwork come up before certifications do, and one of the most common concrete objections is whether an AI sourcing tool violates another platform's terms of service.
Nine questions worth putting in writing, in the order that tends to expose real gaps:
- Which of our jurisdictions do you consider yourself in scope for, and why?
- Does the tool score, rank or reject candidates, or does it only surface them for human review?
- Where does candidate data come from, and under what terms?
- Has the tool had an independent bias audit, and can we see the impact ratios rather than a summary?
- Do you use our candidate data to train your models?
- What notice text do you supply for candidates, and does it name the qualifications assessed?
- What logs can we export to reconstruct a specific decision months later, given California's four-year retention rule?
- Which certifications do you actually hold, with dates and report availability?
- Who is contractually responsible if a jurisdiction deems the tool an AEDT and no audit exists?
Question 4 matters more than its rank suggests. In the largest published field study of Local Law 144 compliance, 155 investigators checked 391 employers and found 18 posted audit reports and 13 posted transparency notices, and nearly every audit that was posted reported an impact ratio above 0.8 (Null Compliance, ACM FAccT 2024). A posted audit that clears the four-fifths threshold is close to the default outcome, which makes the underlying selection and scoring rates the informative part, not the headline.
Questions 8 and 9 are where vendor answers diverge most, and we compare what seven AI recruiting vendors actually publish about certifications, data training and SSO in our AI recruiting software security comparison, with the SOC 2 and GDPR detail in the SOC 2 recruiting software guide.
How does an autonomous sourcing platform fit this?
At Noon, the architecture is agentic sourcing: the AI searches across the whole web rather than a single network, evaluates profiles against role-specific criteria including non-negotiables the model never relaxes, and learns from thumbs-up and thumbs-down feedback per role. Recruiters review candidates and own hiring decisions, which is exactly the boundary the New York City rules draw between assisting and replacing discretionary decision making. You can see how the sourcing side works on the AI Sourcer page.
On the diligence questions above, the verifiable facts are that Noon is SOC 2 Type II compliant and GDPR compliant, supports SSO and SAML, offers data residency options, and covers 20 or more ATS providers through a unified integration layer so the record of a decision lands in the system your auditors already read. Details are on the security page and the enterprise page. Noon also runs on one plan with unlimited sourcing, contacts, agents and seats, which removes the per-seat pressure that pushes teams toward shared logins, the single worst habit for reconstructing who decided what. There is no published dollar price; pricing is quoted per team and is the official source for cost questions.
What Noon does not do is issue you a compliance opinion. Scope calls under Local Law 144, Illinois notice text and California retention practice are employer duties, and the honest answer from any vendor is that they supply the evidence and you make the call with counsel.
What should a talent team do this quarter?
- Inventory the tools, not the vendors. One vendor can ship three features with three different scope answers. Write down, per feature, whether it ranks, scores, filters or only surfaces.
- Fix the notice layer first. Notices are cheap, and three of the four live regimes turn on them. New York City notices must name the job qualifications and characteristics assessed and explain the opt-out route.
- Set retention to four years. California's minimum is the binding one for most multi-state employers, and it explicitly covers automated-decision data, not just applications.
- Get the audit artifacts, not the audit summary. Ask for selection rates, scoring rates and impact ratios by category, and re-request annually because the New York City audit must be within one year of use.
- Write the AI policy down. Texas turns on intent, and an undocumented purpose is a bad fact. This overlaps almost entirely with the governance work in our AI agents for recruiting playbook.
- Re-check the calendar each quarter. Two of the six dates in the table above moved in the last four months. Colorado's attorney general must also issue implementing regulations by 1 January 2027, so its duties will get more specific before they start.
- Keep bias testing running even where no audit is mandated. Illinois, California and Title VII all turn on effects, and diversity sourcing work generates the pool data those tests need.
Frequently asked questions
Is it legal to use AI in hiring in the United States?
Yes. No US jurisdiction bans AI in hiring. The live regimes regulate how it is used: bias audits and notices in New York City, discriminatory effect and notice in Illinois, record retention and disability-inquiry limits in California, and documented intent and governance in Texas. Federal anti-discrimination statutes apply on top of all of them.
Did the EEOC withdraw its AI hiring guidance?
The EEOC removed its AI-specific technical-assistance documents from its website in early 2025, alongside similar removals at the Department of Labor (Husch Blackwell, 7 February 2025). The statutes those documents interpreted, Title VII, the ADA and the ADEA, are unchanged, as is the four-fifths rule used to assess adverse impact. Guidance disappearing is not deregulation.
Does the EU AI Act apply to recruiting in 2026?
Partly. The prohibited-practices and AI-literacy provisions have applied since 2 February 2025 and the Article 50 transparency obligations since 2 August 2026, but the high-risk obligations that cover recruitment and selection under Annex III moved to 2 December 2027 under Regulation (EU) 2026/1744. If you hire into the EU, the build-out window is longer than the original timeline implied, not cancelled.
What happened to Colorado's AI Act?
S.B. 26-189, signed in 2026, replaced the previous framework with a narrower one: pre-use notice, an adverse-action process with human review, and record retention of at least three years, enforceable only by the attorney general. It takes effect on 1 January 2027, after two earlier delays from February 2026 and then 30 June 2026.
Do we need a bias audit if our AI only sources candidates and does not score them?
In New York City, the enforcing agency's guidance says the bias-audit and notice requirements do not apply to scanning a resume bank, outreach to potential candidates or inviting applications, because those people have not applied to a specific position. California is broader: its definition covers targeted job advertising and resume screening for terms or patterns. Document your reasoning either way, because the employer makes the scope call and that unreviewed discretion is precisely what the Null Compliance study identified as the weak point in public accountability.
Who is liable if the vendor's tool discriminates?
The employer, in every live regime. Vendor assurances do not transfer statutory duties, and California's regulations define "agent" specifically so that acting through a third party does not break the chain. Contractual indemnities are worth having and are not a defense.
