Key takeaway: A tool is an AEDT under New York City Local Law 144 only if all three things are true: it uses machine learning, statistical modeling, data analytics or AI; it helps make an employment decision; and it substantially assists or replaces discretionary decision making. That last prong has a specific three-part definition, and the city's own guidance says scanning a resume bank, conducting outreach to potential candidates and inviting applications are not covered because the people involved have not applied for a specific position. If your tool is in scope, you need an independent bias audit within the past year, a published summary with impact ratios, and candidate notice at least 10 business days before use.

The phrase "automated employment decision tool" gets used as a synonym for "AI in hiring". It is not. It is a defined term in one city's law, with a narrow test attached, and the difference between being in scope and out of scope is the difference between an annual independent audit plus published impact ratios and no obligation at all.

The gap between the term's colloquial use and its legal meaning has real consequences. In the largest published field study of Local Law 144, 155 investigators audited 391 employers and found only 18 posted bias audit reports and 13 posted transparency notices, and the researchers attributed most of that gap not to defiance but to employers deciding, on their own reading, that their tools were out of scope (Null Compliance, ACM FAccT 2024). Enforcement did not close the gap either: the New York State Comptroller's audit released 2 December 2025 found the enforcing agency's system for pursuing violations ineffective, with complaints misrouted and posted audits reviewed superficially (Office of the New York State Comptroller).

None of which makes the law optional. Penalties run from $500 for a first violation to $1,500 for each subsequent violation, and each day of continued use without a valid audit is a separate violation (NYC DCWP), so a self-serving scope call is an expensive thing to get wrong. This guide walks the test as written, then the paperwork it triggers.

The city's enforcement agency states the test as three conditions that must all be met. The tool must:

  1. Use machine learning, statistical modeling, data analytics or artificial intelligence, and
  2. Help employers or employment agencies make employment decisions, and
  3. Substantially assist or replace discretionary decision making.

Condition 1 has its own definition, and it is narrower than "any software". The technique must generate a prediction or a classification, and it must identify the inputs, the relative importance of those inputs, and other parameters in order to improve the accuracy of that prediction or classification. A prediction includes an assessment of a candidate's fit for a job or likelihood of success. A classification is the assignment of an observation to a group, such as a categorization by skill set or aptitude (DCWP AEDT FAQ).

Condition 2 is broader than most people expect: "employment decision" is not limited to the final hire or promotion. The city says explicitly that it includes screening, and that if an AEDT substantially helps assess or screen candidates at any point in the hiring or promotion process, the requirements apply before use.

Condition 3 is where nearly all scope arguments actually live.

What does "substantially assist or replace discretionary decision making" mean?

The rules define this through a tool's simplified output, meaning a score, tag, classification, ranking or similar. A tool substantially assists or replaces discretionary decision making when an employer does any one of the following:

Prong The employer's use pattern Typical example
Sole reliance Relies solely on a simplified output, with no other factors considered Auto-rejecting every applicant below a model score
Dominant weight Uses the simplified output as one of a set of criteria, but weights it more heavily than any other criterion A rubric where the AI match score counts for more than experience or interview notes
Override Uses the simplified output to overrule conclusions derived from other factors, including human decision making A recruiter advances a candidate, and the tool's low score removes them anyway

Read that table twice, because the common summary of it, "you are fine as long as a human is in the loop", is wrong on two of the three prongs. A human who reviews the ranked list but always follows the order is close to prong one. A human who weighs the score above everything else is prong two, no matter how much reviewing they do. The only clearly safe pattern is one where the model's output is one input among several, is not the heaviest, and does not have veto power.

Note also that the calculus belongs to the employer's use, not the vendor's product. The same tool can be an AEDT at one company and not at another. That is why vendor claims about scope are worth very little and why the reasoning behind your own scope determination should be written down at the time you make it.

What is explicitly out of scope?

Two exclusions matter most for teams running outbound sourcing.

Sourcing, outreach and invitations to apply. The city answers this directly: the requirements do not apply if an employer or employment agency uses a tool to scan a resume bank, conduct outreach to potential candidates or invite applications. The reason is the definition of "candidate for employment", which means a person who has applied for a specific position by submitting the required information in the required format. Someone your team found and messaged has not applied, so an assessment of that person is not an assessment of a candidate. This is the single most consequential carve-out in the law for anyone running an AI candidate screening or outbound sourcing stack, and it is why the same tool can be in scope for inbound applicants and out of scope for sourced prospects.

Jobs with no New York City nexus. The law applies only to use "in the city", which the agency reads as: the job is located at least part time in a New York City office, or the job is fully remote but its associated location is a New York City office, or the employment agency using the tool is located in the city. A national employer can therefore be in scope for some requisitions and not others.

Two more limits are worth knowing. Imputed or inferred demographic data cannot be used to conduct a bias audit, so inferring race or sex from names or photos to manufacture an audit dataset is not permitted. And a bias audit does not oblige you to act on its results: the law requires the audit, not a remedy. Federal, state and city anti-discrimination law is what decides whether a disparate impact you discover has to change.

One caveat before anyone treats the sourcing carve-out as a free pass. It is specific to New York City. California's automated-decision-system regulations, in force since 1 October 2025, define scope to include directing job advertisements to targeted groups and screening resumes for particular terms or patterns, and Illinois' amended Human Rights Act, in force since 1 January 2026, turns on discriminatory effect with no decisiveness test at all. The multi-state picture and current effective dates are in our AI hiring compliance guide.

What must a bias audit actually contain?

A bias audit is an impartial evaluation by an independent auditor. At minimum it must calculate selection or scoring rates and the impact ratio across sex categories, race and ethnicity categories, and intersectional categories. Requesting only a pass or fail summary from a vendor means you are not seeing the part that carries information.

Data rules constrain the audit more than the arithmetic does:

  • Historical data is the default. That means data collected during your own use of the tool to assess candidates or employees for promotion.
  • Shared audits are allowed with conditions. An audit can pool historical data from multiple employers using the same tool, but you can rely on it only if you contributed your own historical data to that audit, or it is your first time using the tool.
  • Test data is the fallback. If there is not enough historical data for a statistically significant audit, test data may be used, and the published summary has to explain why and how that data was sourced or developed.
  • Small categories can be excluded. Categories representing under 2% of the data may be omitted from the calculations, with disclosure.
  • Annual expiry. An audit is good for one year from the date it was conducted, so a tool in continuous use needs a rolling annual audit.

The published summary has to include four things: the date of the most recent audit, the source and explanation of the data used, the number of individuals assessed who fall in an unknown category, and the number of applicants or candidates plus the selection or scoring rates and impact ratios for all categories. You must also publish the distribution date, meaning the date you started using the tool. The summary can live on your careers page or behind an active hyperlink from it.

The Null Compliance researchers found that nearly every audit that was published reported an impact ratio above the 0.8 four-fifths threshold. Treat a clean headline ratio as the expected outcome rather than as evidence, and read the underlying selection and scoring rates.

What notice do candidates get?

Three separate disclosures, and teams routinely ship the first and forget the others:

  1. Notice that an AEDT will be used, given at least 10 business days before use, identifying the job qualifications and characteristics the tool will assess.
  2. Instructions for requesting an alternative selection process or a reasonable accommodation, which is where accessibility obligations under disability law intersect with this law.
  3. Information about the type and source of the data used by the tool, and your data retention policy, published on the site or provided within 30 days of a written request.

The 10-business-day lead time is what makes notice an operational problem rather than a legal one. It has to be in the job posting or the application flow, before the tool runs, which means the requisition template is the right place to fix it, not the offer stage.

Where does an autonomous sourcing platform sit?

Noon is built for the outbound side of the funnel, which is the part the city's guidance places outside the AEDT requirements. The AI searches the entire web rather than one network, evaluates profiles against role-specific criteria including non-negotiables it never relaxes, finds and enriches contact details, and runs email, LinkedIn and SMS outreach to people who have not applied to a specific position. Recruiters review the candidates the AI Sourcer surfaces and decide who advances, and the system calibrates from their thumbs-up and thumbs-down feedback per role.

The honest boundary: Noon also offers a Voice AI Interviewer and screening capability, and if you use those to assess people who have applied to a specific position for a job with a New York City nexus, that use is far more likely to be in scope, and it is your call to make with counsel. What a vendor can supply is evidence rather than a scope opinion, and the evidence Noon can supply is verifiable: SOC 2 Type II compliance, GDPR compliance, SSO and SAML, data residency options, and integration with 20 or more ATS platforms so the audit trail for a requisition lives in the system of record your legal team already reviews. The security page documents the controls, and our AI recruiting software security comparison and SOC 2 recruiting software guide show how those claims stack up against other vendors. Noon runs on one plan with unlimited sourcing, contacts and seats, so nobody shares a login to save a seat, and shared logins are the fastest way to destroy an audit trail.

How do you decide scope in practice?

A defensible determination is a short written record per tool, per requisition family. Work through it in this order:

  1. Is there a New York City nexus? Office-based at least part time, or remote and associated with a New York City office. If no, the law does not apply and the other questions are about California, Illinois and Texas instead.
  2. Has the person applied to a specific position? If not, the sourcing and outreach carve-out applies.
  3. Does the tool produce a simplified output? A score, tag, ranking or classification. If it produces raw information with no ordering or grouping, prong three is hard to satisfy.
  4. How is that output used? Sole reliance, heaviest criterion, or override. Any one of those puts you in scope.
  5. Write down the answer and the date, with the requisitions it covers and who made the call. Scope determinations are exactly what the Null Compliance study found employers making silently and unaccountably, and a dated memo is cheap insurance.
  6. If in scope, sequence the work: independent audit, then published summary with impact ratios and distribution date, then the notice in the posting template, then a calendar entry to re-audit inside 12 months.
  7. Keep bias testing going even when out of scope, because Title VII, the ADA and state statutes are effects-based, and the pool data from diversity sourcing work is what makes that testing possible.

Frequently asked questions

Is an applicant tracking system an AEDT?

Only when it does more than store and route. Keyword search over applications, knockout questions and configurable filters generally do not generate a prediction or classification with learned input weights. Ranking, match scoring and predictive fit features can, and they are usually optional modules, so the determination has to be per feature and per configuration rather than per platform.

Is a resume screener an AEDT?

Usually yes, if it scores or ranks applicants to a specific position with a New York City nexus and a recruiter relies on that output solely, weights it above other criteria, or lets it override human conclusions. Screening explicitly counts as an employment decision under the law, so being early in the funnel is not a defense.

Does Local Law 144 apply to sourcing tools?

The city's guidance says the requirements do not apply to scanning a resume bank, conducting outreach to potential candidates or inviting applications, because those people have not applied for a specific position. California's regulations are broader and reach targeted job advertising and resume screening for terms or patterns, so a multi-state employer should not generalize the New York City answer.

Who is responsible for the bias audit, the employer or the vendor?

The employer or employment agency using the tool must ensure an audit was done. Vendors commonly commission and publish audits to make that easier, but the legal duty and the publication obligation sit with the user of the tool.

Can a bias audit use another company's data?

Yes, if the audit pools historical data from multiple employers using the same tool and either you contributed your own historical data to it or it is your first time using the tool. The pooled employers do not have to hire for the same kinds of roles you do.

What are the penalties for non-compliance?

$500 for a first violation and up to $1,500 for each subsequent violation, with each day of continued use without a valid audit counting as a separate violation. Failure to provide the required notices is separately actionable, and the state Comptroller's December 2025 audit has pushed the enforcing agency toward tightening its complaint handling.

Does an annual audit have to be repeated if the tool has not changed?

Yes. Reliance is capped at one year from the date the audit was conducted, regardless of whether the model changed, so continuous use requires a rolling annual audit and a refreshed published summary.