Articles

5 New AI Hire Laws: What AI Regulation Every HR Employer Needs to Know in 2026

Published on Updated on By Sanat Hegde12 min read
5 New AI Hire Laws

Five sets of rules now govern how you can use AI in hiring, and three of them have dates on the calendar. New York City audits. Illinois lets candidates sue. Colorado's rewritten law starts on January 1, 2027. The EU's high-risk obligations for recruitment tools land on December 2, 2027, with transparency duties already in force since August 2, 2026. Washington has stepped back: the Senate voted 99 to 1 to kill a federal AI moratorium, so the states own this.

LawStatusCore dutyPenalty
NYC Local Law 144In force since July 5, 2023; enforcement audited December 2025Annual independent bias audit, published results, candidate notice$500 to $1,500 per day per violation
Illinois AI Video Interview Act, 2026 amendmentIn force since January 1, 2026Notice and consent for AI-analyzed video; ban on discriminatory AI outcomes; private right of actionCivil suits by candidates
Colorado SB 26-189Signed May 2026, effective January 1, 2027Notice before use, adverse-action notice with human review, three-year recordsUp to $20,000 per violation, 60-day cure, AG only
EU AI Act (Annex III, employment)Transparency duties since August 2, 2026; high-risk obligations from December 2, 2027Risk management, documentation, human oversight, loggingUp to €35 million or 7% of global turnover
FederalNo statute; moratorium rejected 99 to 1Title VII disparate impact still appliesLitigation

Below: what each one requires, who it reaches, and what to do about it. Employment counsel in your jurisdiction has the final word.

Why the laws arrived all at once

Timeline of AI hiring laws from 2023 to 2027

Workday and Amazon both faced AI employment bias claims in 2025. Those cases put a face on the argument that algorithmic screening can shut out protected classes at scale, and they unstuck bills that had been stalled for years.

The laws that followed share a shape: tell candidates when AI is used, test or assess the tool for bias, and keep a human in consequential decisions. Build for that shape once and most jurisdictions are covered.

Law 1: New York City Local Law 144

In force since July 5, 2023. If you use an automated employment decision tool to hire or promote people located in NYC, you need an annual bias audit by an independent auditor, you must publish the results, and you must tell candidates the tool is in use. The Department of Consumer and Worker Protection enforces it at $500 to $1,500 per day per violation.

Enforcement has been weak, and that is about to matter. The New York State Comptroller audited DCWP in December 2025 and called its enforcement "ineffective": little monitoring, few penalties. DLA Piper's January 2026 note read that as a signal the city will tighten up. That reading is right. An agency publicly told it has failed to enforce responds by enforcing more.

The definition of an AEDT is wide: any computational process using machine learning, statistical modeling, data analytics or AI that substantially assists or replaces discretionary decision-making about candidates. Plenty of ordinary ATS features with AI screening qualify. If you have not audited your vendor stack for AEDT status, do it before the enforcement climate changes.

Law 2: Illinois, now with a private right of action

Illinois got here first. The AI Video Interview Act (820 ILCS 42) has required notice, an explanation of how the AI works, and consent before recording since 2020, and it bars sharing the video with third parties without consent.

The amendment effective January 1, 2026 changes the stakes. It bans AI discrimination in hiring even when unintentional, and it gives candidates a private right of action. A candidate who believes an AI tool discriminated against them can sue you directly, no agency complaint first. No other state does this. Stinson LLP calls Illinois the high-water mark for candidate rights and expects other states to copy the provision.

If you hire Illinois residents with any AI in the loop, the absence of a regulator knocking on your door no longer protects you.

Law 3: Colorado's rewritten AI Act, effective January 2027

Colorado's original Artificial Intelligence Act (SB 24-205, signed May 2024) was the most demanding framework in the country on paper: impact assessments, risk management programs and an affirmative duty to avoid algorithmic discrimination for anyone deploying high-risk AI in employment. The start date slipped once. Then in May 2026 the legislature replaced it with Senate Bill 26-189, effective January 1, 2027 (Littler's summary).

What is left is a notice-and-review law. If you use automated decision-making technology in a consequential employment decision you must give clear and conspicuous notice beforehand. Within 30 days of an adverse decision you must tell the person what role the technology played, how to ask for information about it, and give them an opportunity for meaningful human review, subject to a "commercially reasonable" exception. You keep compliance records for three years.

Gone: impact assessments, risk management policies, annual tool reviews, privacy policy updates, reporting of discriminatory outcomes and the affirmative anti-discrimination duty. Only the Attorney General can enforce it, as an unfair trade practice, up to $20,000 per violation with a 60-day cure period. No private right of action.

The duties fall on the deployer, which means the employer. Your contract should say what disclosure text the vendor supplies and how a candidate's request for human review reaches someone who can act on it.

Law 4: EU AI Act, high-risk obligations dated December 2027

The EU AI Act entered into force on August 1, 2024 and lists recruitment and selection systems, including screening and evaluation of candidates, as high-risk under Annex III. The dates moved in 2026. The AI Omnibus amendment, in force since July 27, 2026, set the application date for Annex III employment systems at December 2, 2027 (European Commission). The Act's transparency duties for AI used in hiring took effect on August 2, 2026 and are enforceable now (DLA Piper).

For high-risk systems the Act requires a risk management system and technical documentation, training data controls for bias, human oversight built into the system, logging, and registration in the EU database for public-sector deployments. Fines reach €35 million or 7% of worldwide turnover, whichever is higher.

US companies are not exempt. The Act applies to any AI system deployed in the EU regardless of where the provider sits, so recruiting EU candidates with a US tool brings you in. Greenberg Traurig's analysis covers the cross-border position. For most SMBs the practical step is to ask your vendor whether it is doing the risk assessment and documentation work, and to remember that the deployer's responsibility does not transfer with the invoice.

Law 5: the federal vacuum

The Senate's 99 to 1 vote against a federal AI moratorium means no national standard is coming soon. Twelve or more states have passed AI hiring laws or have bills moving. Beyond Illinois and Colorado, Maryland has enacted a notice requirement for AI in employment decisions, and New Jersey and New York State have bills in progress. Requirements differ: some want bias audits, some want notice, some want human review.

Build to the strictest set once. Documented human oversight of AI-assisted decisions, candidate notice whenever AI is used, some form of bias or impact assessment, and a way for candidates to ask for a human. That combination satisfies every enacted law above and will survive the next one.

Where Hirevire sits

The question every regulator is asking is the same: who made the decision? Hirevire is built so the answer is a person.

Candidates record video, audio or text answers to structured questions. Recruiters and hiring managers review them and decide. By default no algorithm scores anyone, and each decision has the candidate's own answer sitting behind it.

Hirevire does offer AI Scorecards, which score answers and resumes against criteria you write. They are off until you switch them on for a workspace, and the Data Processing Agreement fixes their output as advisory and display-only: no sorting, filtering, hiding or rejecting, and you remain responsible for human review. If you turn them on for candidates in NYC, Illinois, Colorado or the EU, treat the score as AI assistance and run the notice, consent and human-review steps that state requires. Leave them off and you have a structured screening tool with no automated evaluation layer.

Auto-disqualification is a rule you write against a must-have criterion such as work authorization. No model is involved. It still rejects automatically, so disclose the criteria and keep a path to a human.

Every screening interaction is logged and shareable, and the Timeline on each application shows who changed a stage and when. When an auditor, a regulator or a candidate asks how a decision was made, that record is the answer. Candidates see what they are submitting and to whom, and you can link your own privacy notice on the application page.

Try Hirevire free.

What to do this quarter

Five-step compliance checklist graphic

Map your tools to jurisdictions. List every AI tool in the funnel, including optional scoring features that are switched on, and note where you hire. Nothing else works without this list.

Read your vendor contracts for who owns compliance. Deployer and developer duties overlap under most of these laws. If the contract does not say who runs the bias audit and who keeps the documentation, assume it is you.

Write the candidate notice now. NYC, the Illinois video law and Colorado from January 2027 all require it. Put standard language in job postings and application confirmation emails that says which AI tools are used and how they inform decisions.

Put a human review checkpoint before every adverse decision, and document it. For scored tools that means a recruiter reads the recommendation before a rejection goes out. This one change covers Colorado, Illinois and the EU at once.

Talk to counsel before the first complaint arrives. Most HR teams doing this exercise discover their ATS vendor never told them the tool falls within a regulated definition. Counsel who knows AI employment law will find those gaps quickly.

Frequently asked questions

Which AI hiring law has the highest penalties?

The EU AI Act: up to €35 million or 7% of annual global revenue for high-risk system breaches. In the US, NYC Local Law 144 runs $500 to $1,500 per day per violation, which compounds across candidates. Colorado's SB 26-189 allows up to $20,000 per violation from January 2027.

Does my company need to comply with NYC Local Law 144 if we're not based in New York City?

Yes, if you use automated employment decision tools on candidates located in New York City or on NYC employees up for promotion. The law follows the location of the person being evaluated.

What is a private right of action, and why does Illinois's law matter?

It means an individual can sue you directly without first filing with an agency. Illinois's 2026 amendment gives candidates that right for AI discrimination in hiring. Every other US AI hiring law relies on a regulator, so Illinois raises litigation exposure for anyone using AI on Illinois candidates.

What does "human oversight" mean under AI hiring law requirements?

A person with authority who can review, override and answer for a decision made with AI help. Colorado's SB 26-189 requires an opportunity for meaningful human review after an adverse decision. The EU AI Act requires oversight designed into the system. A recruiter reviewing AI recommendations before a decision reaches the candidate satisfies both in practice.

Is async video interviewing covered by AI hiring laws?

It depends on what the tool does with the video. If AI analyzes it and produces a score, rating or recommendation, as HireVue and similar tools do, it is likely covered. If the platform records and shows answers to a human reviewer, as Hirevire does by default, it does not generate an AI decision and is not usually subject to the same rules. Hirevire's optional AI Scorecards change that: switch them on and treat the role as AI-assisted.

What should HR leaders do if they operate across multiple states with different AI laws?

Build to the strictest standard once: Illinois's consent and anti-discrimination rules, Colorado's notice and human review, NYC's bias audit. A process that satisfies all three will not need rebuilding when the next state passes a law.

Will federal AI hiring regulation pass?

No. The 99 to 1 vote against a federal moratorium means no preemption of state law is in sight. Plan for more state laws.

What to watch

Graphic listing upcoming AI hiring law milestones

The first Illinois lawsuits under the private right of action will define what "AI discrimination" means in practice and how much it costs.

NYC's response to the Comptroller audit. Employers without a completed bias audit and published disclosure should treat that as urgent.

Colorado's January 1, 2027 start. Notice language, an adverse-action process with a human review path, and three-year record retention need to be ready, and Attorney General guidance on "commercially reasonable" review is the piece still missing.

New Jersey, Texas, Washington and California all have AI hiring bills moving. Watch for private rights of action; that is the provision that changes the risk.

Teams with transparent, human-supervised screening will absorb each of these with a policy update. Teams running opaque scoring tools have a rebuild ahead of them. Hirevire is the first kind by default: answers reviewed by recruiters, AI scoring optional and advisory, every decision logged.

Get started with Hirevire

Get Started

Stop scheduling screening calls. Start today.

Start your 7-day free trial today. No credit card required.