An AI system reads new applications, scores each against the role, and surfaces a shortlist. For jobs with no applicants, it sources candidates from the wider market and recommends which ones to contact. Work that used to take a recruiter a day, done before their morning coffee. The capability is real and, in hiring, already widespread. What is less settled is everything that sits behind it. These tools were shipped quickly, and the legal system is now catching up. As the implications come into focus, many companies are reconsidering whether an AI system belongs in a regulated hiring process at all.
Whatever form the technology takes, built in-house or licensed from a third-party service, the compliance responsibility sits in the same place: with the company doing the hiring. The legal exposure for a discriminatory decision lands on the employer. So compliance is not an afterthought. In a regulated domain, it is a basic building block of using AI.
So let's look at the current state laws, and what they demand of any company using AI in hiring. The specifics here are about recruiting, but the shape of the problem (enforce, record, and prove fairness) recurs anywhere AI touches a regulated decision.
The point of AI in hiring is speed and efficiency. Staying compliant is what keeps those gains from turning into liability.
The structure
Governance has two parts
The first is enforcement: every action the AI system takes is reviewed by a control layer before it takes effect. The control layer confirms AI usage disclosures have been posted, blocks biased evaluations, and enforces the system's usage limits. It keeps an audit trail of actions it allows. It runs continuously, inside the environment where the system operates, and is run by the employer or a vendor the employer pays.
The second is the audit: an independent examination of whether the system's outcomes discriminate. It happens periodically, measures outcomes across groups, and must be carried out by an independent third-party auditor.
New York City's Local Law 144 requires that separation: the bias audit must be performed by an independent party with no financial interest in the tool, so the vendor running your enforcement layer cannot also be the one auditing it.
Control layer
Enforces policy in real time, on every AI transaction.
- Continuous, proactive enforcement
- Runs inside the company's perimeter
- Allows, blocks, meters, records
- Operated by the company or its vendor
Independent audit
Examines the outcomes afterward to verify fairness.
- Detailed examination of outcomes
- Combines demographic data with the AI's decisions
- Tests for unequal outcomes across groups
- Conducted by an independent third party
Controls reduce risk. Audits establish trust.
Two lines of defense, in sequence. The control layer prevents problems in real time; an independent, third-party audit verifies the outcomes afterward.
The obligations
What the laws require
- New York — independent bias audit & candidate notice (NYC Local Law 144)
- Illinois — discriminatory-effect ban; AI-use notice (HB 3773 / Human Rights Act)
- California — anti-bias testing & recordkeeping duties (FEHA automated-decision rules)
- Texas — ban on AI used to intentionally discriminate (TRAIGA)
- Connecticut — pre-decision disclosure (AI Responsibility & Transparency Act, from 2026)
- Colorado — disclosure & transparency duties (revised Colorado AI Act, 2027)
Where the rules apply. Six states now regulate AI in hiring: four in force today (darker), and two enacted and phasing in (lighter).
Under Local Law 144, a New York employer using an automated hiring tool must commission an independent bias audit, post a plain-language summary of the results, and notify each candidate at least ten business days ahead.
Connecticut's Artificial Intelligence Responsibility and Transparency Act, signed in 2026, adds a disclosure regime: before a decision, the employer must tell the candidate that an AI tool is being used, what it does, and what data it relies on.
Illinois and Texas differ on what counts as a violation. Illinois, in its Human Rights Act amendment effective January 2026, treats a discriminatory effect as a violation on its own. Texas, in its Responsible Artificial Intelligence Governance Act (also effective January 2026), requires intent: it prohibits AI used with the intent to discriminate, and explicitly states that a skewed outcome alone is not a violation. The practical gap is plain: a hiring model that clears the intent-based Texas standard can still breach the stricter, effect-based Illinois one.
These rules are also still changing. Illinois published draft notice rules in May 2026, then withdrew them weeks later, though the statute itself stayed in force.