In May 2023 the EEOC published a plain-language explainer on how Title VII applies when employers use AI to screen and select candidates. If you were an HR leader trying to work out whether your new screening tool was legal, that document was where you started.
It's gone. Following Executive Order 14179, the EEOC removed its AI guidance in January 2025. The Department of Labor and OFCCP withdrew theirs. As of 2026, eeoc.gov/ai returns a not-found page.
Here's the part that trips people up: the law didn't change. The guidance was non-binding. It explained existing obligations rather than creating new ones. Title VII and the ADA apply exactly as they did in 2024. The EEOC's Strategic Enforcement Plan for FY 2024 to 2028 still names technology-related employment discrimination, including algorithmic decision-making, as a priority.
What went away was the manual. Not the exam.
Meanwhile four US jurisdictions have written their own rules, no two the same, and the EU has moved its deadline by sixteen months. If you're trying to work out what actually applies to you right now, this is the map.
A note on how this page works. Statutes and government sources are linked directly wherever a public URL exists, so you can check us. Everything below was verified on 30 July 2026 & we re-verify quarterly. Dates in this area have moved repeatedly, in one case three times for the same law. Check the verified date at the bottom before you rely on anything here, and treat this as general information rather than legal advice. Your obligations depend on facts specific to your process, and you need your own counsel for those.
The federal picture: liability without a roadmap
Nothing at the federal level currently tells you how to comply. Plenty still tells you that you can be liable.
Title VII prohibits employment discrimination on the basis of race, color, religion, sex and national origin. It's concerned with outcomes. A tool that produces a disparate impact is a problem regardless of whether a human or an algorithm produced it, and regardless of whether anyone intended it.
The ADA creates obligations around screening that may disadvantage candidates with disabilities. Automated video assessment, timed testing, and voice or facial analysis all raise questions here, and the withdrawn guidance was the main place employers found them explained.
Enforcement priority remains. The Strategic Enforcement Plan continues to identify employment discrimination arising from technology, including algorithmic decision-making, as a focus area.
The practical consequence: you are expected to know your tools are not discriminating, and there is no longer a federal document telling you what "knowing" looks like. Which means the state rules below aren't just compliance obligations. Right now they're the clearest available statement of what regulators think reasonable practice looks like.
The state patchwork
Four jurisdictions, four different approaches, four different trigger conditions.
| Jurisdiction | In force | Core requirement |
|---|---|---|
| New York City | Since 5 July 2023 | Annual independent bias audit, published results, candidate notice |
| California | Since 1 October 2025 | Bias testing relevant to discrimination claims, extended recordkeeping |
| Illinois | Since 1 January 2026 | Disclosure when AI is used in employment decisions |
| Colorado | From 1 January 2027 | Pre-use notice, adverse-outcome explanation, right to request human review |
New York City: the audit regime
Local Law 144 has been enforced by the Department of Consumer and Worker Protection since 5 July 2023. If you use an automated employment decision tool on a candidate for a New York City role, three things are required.
A bias audit by an independent auditor, conducted no more than one year before the tool is used. A public summary of the results on your website. And notice to candidates at least ten business days before the tool is used to evaluate them.
Two details catch people out. The audit and the notice are separate obligations, so failing both is two violations rather than one. And each day of non-compliance counts separately, with penalties running from $500 for a first violation to $1,500 for subsequent ones. That adds up faster than most people expect. DCWP publishes a detailed FAQ covering audit scope, data requirements and what counts as an independent auditor.
Worth knowing that in December 2025 the New York State Comptroller published an audit of DCWP's enforcement of the law, covering July 2023 through June 2025. Draw your own conclusions about enforcement intensity, but don't plan around it. The obligation exists whether or not anyone has knocked.
California: your testing becomes evidence
California's Civil Rights Council finalized regulations on automated-decision systems under FEHA, effective 1 October 2025. The mechanism here is different and quietly more powerful than a notice requirement.
The regulations make anti-bias testing, or its absence, relevant to a discrimination claim. You are not ordered to test. But if a claim is brought, whether you tested, how, and what you did about the results becomes part of the picture. The regulations also extend recordkeeping obligations covering selection criteria and automated-decision data.
That inverts the usual incentive. Under a notice regime, doing nothing is a documented failure you can see coming. Under this one, doing nothing is an evidentiary weakness that only surfaces once you're already being sued.
Separately, California Privacy Protection Agency rules on automated decision-making technology add disclosure and opt-out rights where automated technology replaces human decision-making.
Illinois: disclosure
Illinois amended its Human Rights Act effective 1 January 2026, requiring employers to disclose when artificial intelligence is used in employment decisions. Narrower than the others, and refreshingly simple. If you use it, say so.
Colorado: the cautionary tale
Colorado is worth understanding in full, because the sequence tells you something about this whole area.
SB 24-205, passed in May 2024, was going to be the first comprehensive state AI law in the country: a duty of care to avoid algorithmic discrimination, mandatory risk management programs, impact assessments, annual reviews, reporting to the attorney general.
It never took effect. Its start date slipped from 1 February to 30 June 2026. In April 2026 xAI filed a constitutional challenge, the Department of Justice moved to intervene in support, and a federal court stayed enforcement. In May 2026 the legislature repealed and replaced the whole framework with SB 26-189, signed 14 May 2026 and effective 1 January 2027.
The replacement is much narrower. The duty of care, risk management programs and impact assessments are gone. What survived is instructive, because it's what a legislature kept when it stripped out everything it could:
- Clear and conspicuous notice before covered automated decision-making technology is used in a consequential decision. For hiring, that likely means the job posting or careers page.
- A plain-language explanation within 14 days of an adverse outcome, describing the technology's role, the inputs used, and how to request more.
- A right to correct factually inaccurate personal data used by the system.
- A right to request meaningful human review and reconsideration, to the extent commercially reasonable.
Note the shape of that last one. It's a right the individual exercises, not a blanket requirement that a human review everything. That distinction gets misreported constantly, including by us in an earlier draft of this page.
Records must be retained for at least three years. Enforcement sits solely with the attorney general as a deceptive trade practice, with no private right of action. AG rulemaking is due by 1 January 2027, and litigation over the framework continues.
Europe: transparency now, high-risk later
Under the EU AI Act, Article 50 transparency obligations apply from 2 August 2026.
The heavier high-risk regime for Annex III systems, which explicitly covers employment and worker management, was originally scheduled for the same date. The Digital Omnibus on AI changed that: endorsed by the European Parliament on 16 June 2026 and adopted by the Council on 29 June 2026, it deferred those obligations to 2 December 2027. AI embedded in regulated products moves to 2 August 2028.
Sixteen extra months is real relief, and it's worth being clear about what it isn't. The obligations themselves didn't change. Conformity assessment, technical documentation and human-oversight design are the kind of work that expands to fill whatever time you give it. Teams that treat this as a reprieve rather than runway will arrive in late 2027 in the same position they were in this July.
What every framework is actually asking for
Four jurisdictions, four drafting styles, one shared answer: notice, explanation, human review, and records.
None of them requires a human to review everything. What they require is that you can show your work. Different statutes, same underlying demand.
That convergence is useful, because it means you don't need four compliance programs. A process that can do these four things satisfies the substance of all of them:
- Tell candidates that automated tools are used, before they are used.
- Explain a decision in plain language when it goes against someone.
- Route a contested outcome to a person with the authority and information to genuinely reconsider it.
- Reconstruct any decision from your own records, years later.
We wrote more on how this plays out with AI agents specifically. A system that can't do those four things fails every framework at once. One that can is in reasonable shape under all of them, and it's also, not coincidentally, the kind of process candidates actually trust.
Twelve questions for any vendor
Compliance obligations sit with you as the employer. But most of what you need to meet them has to be built into the tool. These are the questions worth asking before you sign, and the answers worth getting in writing.
On decisions
- Can the system reject or decline a candidate without a human reviewing it? If yes, can that be turned off?
- Which actions execute automatically and which require confirmation? Ask for the actual list, not a principle.
- Is that boundary configurable, and who can change it?
On explanation
- If a candidate is scored, can you produce the reasoning in language a recruiter could repeat to them?
- Can you produce that explanation within 14 days of an adverse outcome, in plain language, including which inputs were used?
On records
- Can you show who reviewed a recommendation, when, and what they changed?
- How long is that retained, and can you export it?
- Could you reconstruct a specific hiring decision from two years ago?
On testing
- Has the tool been bias-audited by an independent auditor, and can you see the results? This matters most for scoring and assessment tools, which we cover separately in our guide to candidate assessment software.
- How often is that repeated?
On candidates
- Can a candidate be told, before assessment, that AI will be used?
- Can a candidate request an alternative, and is that request recorded against them?
Two notes on using this list. Ask for demonstrations rather than assurances: "show me the audit trail for this candidate" surfaces far more than "do you have an audit trail." And a vendor that answers question 2 with a principle instead of a list is telling you something. The list either exists internally or it doesn't.
The next 90 days
If you're starting from nothing, in this order:
Inventory. Every tool that scores, ranks, filters or assesses candidates, including ones inside your ATS you may not think of as AI. Resume matching counts. Scoring counts.
Map jurisdictions. Where are your roles based, and where do your candidates live? NYC's rule follows the job, not your headquarters, and Colorado's reaches out-of-state applicants evaluated for Colorado roles.
Fix notice first. It's the cheapest thing on the list and it appears in three of the four frameworks. A few sentences in the job posting and the application confirmation.
Document the human step. Not that one exists, but who performs it, what they see, and what authority they have to override. This is the piece that is hardest to retrofit and most valuable when questioned.
Then testing and records. More work, longer timelines, and the point where your vendor's capabilities either help you or become the constraint.
FAQs
Is AI in hiring legal? Yes, and it's widely used. Anti-discrimination law applies to outcomes regardless of what produced them, so the question is not whether you may use these tools but whether you can demonstrate they are being used fairly and with human accountability.
The EEOC guidance was withdrawn. Does that mean less risk? No. The guidance was non-binding and explained existing law. Title VII and the ADA are unchanged and the EEOC continues to list algorithmic decision-making as an enforcement priority. What you lost was the explanation, not the exposure.
Does the EU delay mean I can stop preparing? The high-risk obligations moved from August 2026 to December 2027, but Article 50 transparency obligations still apply from 2 August 2026. The delayed work is also the slow kind: documentation, conformity assessment, oversight design.
Does Colorado require a human to review every AI-assisted decision? No, and this one is widely misreported. SB 26-189 gives individuals a right to request meaningful human review and reconsideration after an adverse outcome, to the extent commercially reasonable. That is narrower than a blanket review requirement, and it takes effect 1 January 2027.
We are a small company. Does any of this apply? Probably some of it. NYC's Local Law 144 follows the job rather than employer size. Coverage thresholds vary, and a small employer hiring for a New York City role can be squarely within scope.
Our vendor says the tool is compliant. Is that enough? No. Compliance obligations sit with the employer, and no vendor can discharge them for you. A vendor can supply the capabilities you need, which is what the twelve questions above are for. Get the answers in writing, and have counsel look at what the contract actually says about liability. If you are still building a shortlist, our guide to what recruiting software costs covers the commercial side.
What if we get this wrong? Penalties vary. NYC runs $500 to $1,500 per violation per day, with the audit and notice counted separately. Colorado's regime is enforced by the attorney general as a deceptive trade practice. And underneath all of it sits ordinary discrimination liability, which is where the real exposure has always been.
Where uRecruits fits
We built our platform around the four capabilities in the convergence section above, because they were the obvious through-line before the statutes made them explicit.
Candidates are never declined by software. Every decline is made by a member of the recruiting team. Screening produces a recommendation for a recruiter to review, and the recruiter's decision governs the outcome. Proposals, reviews and changes are tracked in an audit trail. A candidate who would rather not be assessed by AI can request an alternative, and that request is not recorded against them.
What any given deployment actually does depends on how it is configured. We would rather you verify that in a trial than take it on trust, which is also our honest answer to question 2 above: ask us for the list.
The bottom line
The federal explainer is gone. The obligations aren't. Four states have written rules that differ in detail and agree in substance. The EU has bought everyone sixteen months.
Underneath the variation, every framework wants the same four things: tell people, explain decisions, let a human reconsider, keep records. Build a process that does those things and you're in reasonable shape across all of them. You'll also be in reasonable shape for whatever gets written next, because the direction has been consistent for three years.
Your tooling either supports that or it doesn't. Better to ask your vendor that question before someone else asks you.
Rules verified 30 July 2026. This page is reviewed quarterly. Regulatory timelines in this area have moved repeatedly, in one case three times for a single law, so confirm current status before relying on any date here.
This article is general information about AI in hiring. It is not legal advice and does not create an advisory relationship. Statements about laws reflect our understanding as of the verified date and may not reflect later developments. Your obligations depend on facts specific to your organization and process. Consult qualified counsel.



