AI Hiring Laws in 2026: NYC Local Law 144, the EU AI Act, Colorado and What Employers Must Do
A plain-English guide to AI hiring rules in 2026: NYC bias audits, the EU AI Act's new 2027 deadline, Colorado SB 26-189 and Illinois.
By the HireRabbit.AI team · Published · Last updated
This article is general information, not legal advice. Talk to employment counsel about your situation. Laws in this area are changing quickly, and several deadlines moved during 2026. We note the date we last checked each point, and the sources are listed at the end.
If your hiring team uses AI to screen resumes, rank candidates or run interviews, 2026 is the year the rules stopped being hypothetical. New York City is enforcing more aggressively, the European Union has set a firm date for its high-risk rules, Colorado has rewritten its law, and a federal court case has made clear that vendors and employers can both be on the hook. This guide walks through each one in plain English and ends with a checklist.
The short version: three duties most laws share
The details differ, but most AI hiring rules come back to the same small set of duties:
- Notice. Tell candidates when automated tools are used to evaluate them, and in some places what those tools assess.
- Explanation. Be able to explain, in terms a person can understand, how an automated tool contributed to a decision, especially an adverse one.
- Human review. Keep a person meaningfully involved, with the authority to review and override automated outcomes.
Two further duties appear in many of them: bias testing, meaning a regular check of whether the tool's outcomes differ across groups, and records, meaning you can reconstruct what happened later. If your process handles these five well, you are in a much better position under almost every regime below.
NYC Local Law 144: bias audits and notice
New York City's law on automated employment decision tools has been enforced since July 5, 2023. It applies when an employer or employment agency uses an automated tool to substantially assist in screening candidates or employees for jobs in the city.
Before using a covered tool, you need:
- An independent bias audit conducted within one year before use. The audit reports impact ratios, comparing selection rates across sex and race/ethnicity categories and their intersections.
- A public summary of the audit results, posted before use.
- Notice to candidates at least 10 business days before use, including that an automated tool will be used and the qualifications it assesses, with information about how to request an alternative process or accommodation.
Penalties have been reported at up to $1,500 per violation per day. For the first two years, enforcement was light. That changed in December 2025, when the New York State Comptroller published an audit finding that the city's enforcement had been ineffective. The city's consumer protection department had identified one issue across 32 companies it reviewed; the Comptroller's auditors found at least 17 potential violations in the same set. The department committed to stronger enforcement, so employers should assume the law will be taken more seriously from here.
The practical point is that the audit is the employer's obligation. A vendor can provide data, tooling and even a commissioned audit of its product, but the employer using the tool is responsible for ensuring an audit exists and that notice is given.
The EU AI Act: hiring AI is high-risk, now from December 2, 2027
The EU AI Act sorts AI systems by risk. Systems used in recruitment and selection, including tools that filter applications and evaluate candidates, are listed as high-risk in Annex III, point 4. High-risk status brings obligations that include risk management, data governance, logging, transparency, human oversight and documentation, with duties for both the providers who build these systems and the employers who deploy them.
The timeline changed in 2026. The high-risk obligations were originally due to apply from August 2, 2026. The EU's Digital Omnibus on AI, adopted in mid-2026, moved the Annex III high-risk obligations to December 2, 2027. This is a delay, not a repeal. Many guides published before mid-2026 still quote the August 2026 date, so check the date on anything you are relying on.
The Act can apply to organizations outside the EU. If you are hiring into the EU, or the output of your AI system is used in the EU, you should assume it is relevant to you and get advice.
One part of the Act is already in force and is worth knowing about separately. Since February 2, 2025, Article 5(1)(f) has prohibited AI systems that infer the emotions of a person in the workplace, with narrow medical and safety exceptions. The prohibition covers recruitment. Fines for prohibited practices can reach €35 million or 7% of worldwide turnover. If a vendor's product claims to read candidates' emotions, confidence or honesty from video or voice, treat that as a serious red flag for any EU hiring.
Colorado SB 26-189: explanations within 30 days and meaningful human review
Colorado passed the first broad US state AI law in 2024 (SB 24-205). Its effective date was delayed, and in April 2026 a federal court blocked its enforcement. On May 14, 2026, Colorado repealed and replaced it with SB 26-189, which takes effect on January 1, 2027.
The replacement law is narrower than the original but still relevant to hiring. Deployers of automated decision systems used in employment decisions must, among other things:
- Give notice that automated decision-making is being used.
- Explain adverse decisions in an easily understandable way within 30 days.
- Let people access and correct the personal data used.
- Offer meaningful human review by a person with the authority to override the system.
Enforcement sits with the state Attorney General; there is no private right of action. The earlier law's impact-assessment and duty-of-care provisions were removed. The core idea that survives is simple: if an automated system contributes to a decision against someone, you need to be able to explain it to them and have a person who can change it.
Illinois: the AI Video Interview Act
Illinois has had a law specifically about AI in video interviews since January 1, 2020: the Artificial Intelligence Video Interview Act (820 ILCS 42). It applies when an employer asks applicants for Illinois-based positions to record video interviews and uses AI to analyze them.
Before the interview, the employer must:
- Notify the applicant that AI may be used to analyze the video interview.
- Explain how the AI works and what general types of characteristics it uses to evaluate applicants.
- Obtain consent from the applicant to be evaluated by the AI.
The law also limits who the video can be shared with and requires employers to delete an applicant's videos, including copies, within 30 days of a request. Separately, Illinois' biometric privacy law may apply wherever an interview tool captures biometric identifiers, so video-based tools deserve a careful look with counsel.
California's automated-decision rules
California's Civil Rights Council adopted regulations on automated decision systems under the state's Fair Employment and Housing Act, effective October 1, 2025. They confirm that discrimination through an automated decision system is covered by existing anti-discrimination law, apply to employers with five or more employees, and require employers to keep automated decision system data for four years. They also note that some automated assessments could amount to unlawful medical or psychological inquiries.
For most employers, the practical impact is record keeping: you need to be able to show what your tools did and what data they used, for years after the decision.
The lawsuit that changed vendor risk: Mobley v. Workday
Laws are not the only pressure. Mobley v. Workday, filed in federal court in California in February 2023, has become the reference case for AI hiring liability. The plaintiff alleges he was rejected from more than 100 jobs through Workday's screening tools because of his age, race and disability.
Key moments:
- In July 2024, the court allowed disparate-impact claims to proceed on the theory that a screening vendor can act as an employer's "agent".
- On May 16, 2025, the court conditionally certified a nationwide collective of applicants aged 40 and over under the Age Discrimination in Employment Act.
- On June 22, 2026, the court declined to dismiss most of the discrimination claims.
Workday's own discovery responses put the number of applications rejected through its tools at around 1.1 billion during the relevant period. There has been no settlement or trial as of this writing. Whatever the outcome, the case has made two points widely understood: automated rejection at scale draws scrutiny, and "the vendor's tool did it" is not a shield for the employer, or necessarily for the vendor.
Federal guidance, meanwhile, has moved the other way. The EEOC removed its AI technical assistance documents on January 27, 2025. That did not change the law: Title VII, the ADA and the ADEA still apply to hiring decisions made with AI, and disparate-impact liability remains.
An employer checklist
Use this as a starting point for a conversation with counsel, not as a substitute for one.
- Inventory your tools. List every place automated tools touch hiring: resume screening, ranking, assessments, interviews, scheduling. Note which ones influence who moves forward.
- Map your jurisdictions. Where are the jobs, and where are the candidates? NYC, Colorado, Illinois, California and the EU each have different triggers.
- Commission bias audits where required, and repeat them on a schedule. Keep the results and publish summaries where the law requires.
- Write candidate notices that say what is automated, what it assesses and how to request an alternative or accommodation. Deliver them early enough.
- Make explanations possible. For every automated score or outcome, you should be able to show what criteria were used, what evidence was considered and how the result was calculated.
- Keep humans in charge of rejections. Decide who sets automated thresholds, who confirms them and how anyone can reverse them. Avoid rejections that happen with nobody looking.
- Retain records. Keep scores, criteria, notices, audit results and decision logs for at least the longest period any applicable law requires.
- Review vendors' claims. Treat claims of emotion or personality detection from video or voice with caution, especially for EU hiring.
What to ask your ATS vendor
Your applicant tracking system is where most of this becomes real. Ask any vendor:
- How is each score produced? Can you see the criteria, the evidence and the arithmetic, or only a final number?
- Can the model reject someone on its own? If there is automated rejection, who sets the rule, who triggers it and how is it undone?
- What does the system log? Can you reconstruct who did what, when and why, for years?
- What data goes into scoring? Only what the applicant submitted, or data compiled from elsewhere?
- What notice and consent does the candidate see before any AI assessment, including AI interviews?
- Has the tool had an independent bias audit? If not, what data can the vendor provide to support yours?
As one example of how a vendor might answer: in HireRabbit.AI, the AI judges resumes on four criteria and the platform computes every weight, total and average, including the headline score. Auto-reject runs only on a threshold the recruiter sets and a batch the recruiter confirms, sends no email, and any filed candidate can be moved back. Candidates see a consent screen before an AI interview, and integrity flags from the interview are for human review and never change the score. HireRabbit.AI has not yet completed an independent bias audit, so NYC employers would need to plan for one.
FAQ
Is AI resume screening legal?
Generally yes in the United States, but employers remain responsible for discriminatory outcomes under existing law, and specific rules apply in places such as New York City, Colorado, Illinois and California. In the EU, recruitment AI is treated as high-risk with obligations applying from December 2, 2027.
Do I need a bias audit?
If you use an automated tool to screen candidates for jobs in New York City, yes: an independent bias audit within one year before use is required. Elsewhere, bias testing is strongly advisable and increasingly expected, even where it is not yet mandatory.
Does the EU AI Act apply to US companies?
It can. The Act reaches providers and deployers outside the EU when their AI systems are placed on the EU market or their outputs are used in the EU. If you hire into the EU, get advice.
Sources
- NYC Department of Consumer and Worker Protection, Automated Employment Decision Tools: https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page
- DLA Piper, critical audit of NYC AI hiring law (Jan 2026): https://www.dlapiper.com/en-us/insights/publications/2026/01/critical-audit-of-nyc-ai-hiring-law-signals-increased-risk-for-employers
- EU AI Act, Annex III: https://artificialintelligenceact.eu/annex/3/
- Freshfields, the final Digital Omnibus on AI: https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber
- Future of Privacy Forum, the EU prohibition on workplace emotion recognition: https://fpf.org/blog/red-lines-under-eu-ai-act-unpacking-the-prohibition-of-emotion-recognition-in-the-workplace-and-education-institutions/
- Norton Rose Fulbright, Colorado enacts revised AI law: https://www.nortonrosefulbright.com/en-us/knowledge/publications/18733d31/colorado-enacts-revised-ai-law
- Illinois Artificial Intelligence Video Interview Act (820 ILCS 42): https://www.ilga.gov/Legislation/ILCS/Articles?ActID=4015&ChapterID=68&Print=True
- Paul Hastings, California automated-decision regulations (Oct 2025): https://www.paulhastings.com/insights/client-alerts/new-california-regulations-on-employers-use-of-ai-to-make-decisions-go-into-effect-oct-1-2025
- AI Lawsuit Tracker, Mobley v. Workday: https://ailawsuittracker.com/cases/mobley-v-workday-3-23-cv-00770-rfl/
- Civil Rights Litigation Clearinghouse, Mobley v. Workday: https://clearinghouse.net/case/44074/
- Cooley, federal laws still apply after EEOC guidance removal (Feb 2025): https://www.cooley.com/news/insight/2025/2025-02-21-gone-but-not-forgotten-federal-laws-still-apply-despite-guidance-disappearance-act