AI in Hiring: What the Law Actually Requires

Written from primary sources only, and honest about the two we could not open. The AI-specific statutes are narrower than the commentary suggests — and the law that will actually be used against you is the one that was already there.

Short answer

No jurisdiction here bans AI screening. New York City is the one with an operative, enforced duty today: bias audit within the past year, results published, candidate notice 10 business days ahead. California treats employment as a “significant decision” under its ADMT rules. Colorado has a new statute that takes effect on 1 January 2027, not before. Texas mostly does not reach hiring at all, because its definition of consumer excludes the employment context. And the UK has no AI hiring law, which changes nothing: the Equality Act 2010 applies, and it can require you to take the tool out of the process for a particular candidate. This is a summary of published law as at 10 August 2026, not legal advice.

This summarizes published law and official guidance as at 10 August 2026, and is not legal advice. Everything below is drawn from a primary source that we opened and read; where we could not open one, the article says so rather than filling the gap.

The law that already applied

A common mistake in this area is treating AI hiring rules as a new compliance domain to be stood up from scratch. They are better understood as a thin layer of procedure sitting on top of anti-discrimination law that has applied to hiring for decades and that never mentioned algorithms because it never needed to.

That framing matters commercially, because it changes what protects you. A bias audit satisfies a procedural duty in one city. Being able to show that your process does not disadvantage a protected group is what answers a claim anywhere. The second is the harder work and the one worth doing first.

A useful test before adopting any screening tool: if a rejected candidate asked why, in writing, could you answer in a sentence that does not begin “the system”? If not, the tool has moved a decision you are accountable for into a place you cannot see.

Where the AI-specific duties actually bite

AI-specific hiring duties, verified against primary sources on 10 August 2026
WhereIn forceWhat it requires of an employer
New York CityEnforced since 5 July 2023Annual bias audit, published summary of results, and candidate notice 10 business days before use
CaliforniaRegulations effective 1 January 2026Employment counts as a “significant decision”; risk assessment, evaluation for discrimination, and accuracy and nondiscrimination safeguards
Colorado1 January 2027Notice at the point of interaction, plain-language explanation within 30 days of an adverse outcome, right to request human review
Texas1 January 2026The employment context is excluded from the consumer duties; the intent-based discrimination prohibitions still apply
United KingdomEquality Act 2010, in force throughoutNo AI-specific duty. Non-discrimination and reasonable adjustments apply in full to whatever the tool does

New York City: the one with teeth today

Local Law 144 of 2021 is the clearest operative rule in the set, and the Department of Consumer and Worker Protection states it in one sentence: the law “prohibits employers and employment agencies from using an automated employment decision tool unless the tool has been subject to a bias audit within one year of the use of the tool, information about the bias audit is publicly available, and certain notices have been provided to employees or job candidates”.

Three things follow that catch companies out. The audit is annual, not one-off. The results must be published, not merely held — a summary posted where candidates can find it. And DCWP clarified that the notice must reach the candidate 10 business days before the tool is used, which is a scheduling constraint on your funnel, not a footer on your careers page.

It applies by where the job is, not by where your company is. A remote-friendly role open to New York candidates is the situation we see missed most often.

California: hiring is a “significant decision”

California did not write an AI hiring law. It wrote privacy regulations that happen to cover hiring squarely. The CPPA regulations on automated decisionmaking technology, adopted on 24 July 2025 and effective 1 January 2026, define a significant decision to include “employment or independent contracting opportunities or compensation”.

The regulation text asks a question that is unusual and, in our reading, the most useful in the whole set: whether the business “evaluated the automated decisionmaking technology to ensure it works as intended for the business’s proposed use and does not discriminate based upon protected classes”, together with the policies, procedures and training put in place as accuracy and nondiscrimination safeguards. Where the tool came from a vendor, it also asks whether you reviewed the vendor’s own evaluation and any limitations it identified.

That is a question you can be asked in any jurisdiction, and it has only two answers.

Colorado: nothing yet, then a lot

Colorado is where stale commentary concentrates, because the statute changed under it. SB24-205 was repealed and reenacted by SB26-189, signed in May 2026, and the Attorney General’s office states that “this new law and its provisions go into effect January 1, 2027”. Employment is expressly within its definition of a consequential decision.

From that date, a deployer must give clear and conspicuous notice at the point of interaction, must provide a plain language description of the technology’s role within 30 days of an adverse outcome, and must honour a request for meaningful human review. Records supporting compliance are retained for at least three years. Enforcement runs through the attorney general, with a 60-day notice and cure period before 1 January 2030 and no new private right of action.

The planning consequence is specific: the plain-language explanation is not something you can generate after the fact for a decision made months earlier. Whatever you deploy in 2026 needs to be recording the basis of its outputs by the end of it. The wider state-by-state picture is in AI and data protection across GDPR, UK GDPR and US state law.

Texas: the definition that excludes your candidates

TRAIGA took effect on 1 January 2026 and is widely described as imposing AI disclosure on businesses. Read the definitions. The Attorney General’s summary defines a consumer as an individual acting only in an individual or household context, and states that the term “does not include an individual acting in a commercial or employment context”. Job applicants are not consumers for this purpose, and the consumer disclosure duty is placed on governmental agencies rather than private employers.

What does apply is the prohibition on developing or deploying an AI system “with the intent to unlawfully discriminate against a protected class” — and Texas drafted the standard narrowly: “A disparate impact alone is not sufficient to demonstrate an intent to discriminate.” That is a materially different test from the one that governs federal employment-discrimination litigation, and it applies only to this statute.

UK: no AI law, and the strongest single duty

There is no UK statute governing AI in recruitment. There is government guidance from DSIT, developed with input from the ICO and the EHRC, and it is explicit that it “is not to be construed as providing any legal assurance or legal advice”. What it points at is binding: “It is essential to ensure that any system your organisation procures is compliant with the Equality Act 2010 which governs anti-discrimination law in the UK.”

The sharpest obligation in the whole of this article sits here, and it is not procedural. Reasonable adjustments under section 20 are a legal obligation, and the guidance spells out where that leads: “sometimes the substantial disadvantage a person with protected characteristics experiences can only be avoided if the AI system/technology is removed from the recruitment process.”

Read that as a design requirement rather than a legal footnote. If your process cannot run without the AI stage — if there is no human path through it — you have built something you may be required to switch off for an individual candidate and be unable to. Plan the alternative route before deployment, which is exactly what the guidance asks.

The guidance also gives buyers a concrete list to demand from suppliers: documentation of impact assessments, risk assessments, model cards and a DPIA. A supplier who cannot produce any of these is telling you something. The same procurement discipline applied to automation generally is in our buyer’s guide to choosing an agency.

What this article deliberately does not tell you

Two questions belong in an article with this title, and we are not answering them, because we could not open the primary sources on 10 August 2026.

  • Illinois. The Illinois General Assembly site did not respond to any request from our network. There is a widely reported amendment to the Illinois Human Rights Act concerning AI in employment decisions, and we are not restating its terms or its date from secondary write-ups. If you hire in Illinois, read it on ilga.gov.
  • The EEOC’s current position. Every request to eeoc.gov returned an error from our network, including the home page, so we can conclude nothing about what is or is not published there today. Federal employment discrimination law itself has not been repealed. Check the agency’s site directly rather than relying on any summary, including this one.

Naming the gap is not a disclaimer. When a primary source cannot be verified, the correct answer is silence rather than inference: on AI hiring law, an invented obligation is worse than an acknowledged gap.

What to do regardless of where you hire

  • Write down which tools touch a hiring decision. Including the ones inside your applicant tracking system that arrived as a feature rather than a purchase. In LYVIA’s experience that is where the unknown ones live.
  • Decide what each one actually does. Ranking, filtering, scoring and drafting sit in different places legally. A tool that removes candidates is a different object from one that reorders them.
  • Get the evidence a vendor owes you — evaluation results, known limitations, the assessments the DSIT guidance lists. Ask before you buy, because afterwards you are asking for a favor.
  • Keep the human path open. A candidate must be able to get through your process without the AI stage. This is a UK legal obligation and everywhere else it is the thing that lets you fix a problem quickly.
  • Look at your own outcomes. Whether or not a bias audit is required where you hire, run the comparison. Not looking is the position that is hardest to defend.

The operational side of recruitment automation, as opposed to the legal side, is in HR automation for small business. Where hiring sits against everything else a smaller company might automate is in our guide to AI automation for small business.

Frequently asked questions

Is it legal to screen candidates with AI?

Yes, in the US and the UK, subject to conditions that vary by location. No jurisdiction covered here bans it outright. What the law does is attach duties — a bias audit and candidate notice in New York City, notice and a route to human review in Colorado from 2027, and in the UK the whole of the Equality Act 2010 applied to whatever the tool does to applicants.

What does New York City actually require?

Local Law 144 "prohibits employers and employment agencies from using an automated employment decision tool unless the tool has been subject to a bias audit within one year of the use of the tool, information about the bias audit is publicly available, and certain notices have been provided to employees or job candidates." DCWP began enforcing it on 5 July 2023, and clarified that the notice must be provided 10 business days before the tool is used.

Does the Texas AI law cover hiring?

Largely not, because of a definition. TRAIGA defines "consumer" as an individual acting only in an individual or household context, and states that the term "does not include an individual acting in a commercial or employment context". Its consumer-facing duties therefore do not reach your candidates. Its prohibitions still apply, including one on developing or deploying AI with the intent to unlawfully discriminate — but that provision turns on intent, and "a disparate impact alone is not sufficient to demonstrate an intent to discriminate".

Does the UK have an AI hiring law?

No specific statute. The Equality Act 2010 does the work, and the government's own guidance is blunt about it: "It is essential to ensure that any system your organisation procures is compliant with the Equality Act 2010 which governs anti-discrimination law in the UK." The absence of an AI-specific law is not the absence of legal risk — it is the same risk under an older, well-litigated statute.

What if a candidate cannot use the tool because of a disability?

Then you adjust, and if you cannot adjust, you remove the tool for them. UK government guidance states the position plainly: "sometimes the substantial disadvantage a person with protected characteristics experiences can only be avoided if the AI system/technology is removed from the recruitment process." Reasonable adjustments under section 20 of the Equality Act 2010 are a legal obligation, and they should be planned before deployment rather than improvised on request.

Do we need a bias audit if we are not in New York City?

Not as a named statutory duty in most places, but the underlying evidence is what defends you everywhere. If you cannot show whether the tool selects differently across protected groups, you cannot answer the only question that matters when a rejected candidate complains. Doing the analysis is cheaper than the position of having never looked.

If you are deploying screening tools across several jurisdictions and want to know which duties actually attach, the inventory takes an afternoon and settles most of it. Book a call.

LYVIA

LYVIA Team

AI automation and SEO/GEO visibility

LYVIA builds custom AI tools for companies of 10 to 100 people, and gets them found on Google and inside AI answers.

Free offer

Get your free AI audit
in 30 minutes

A LYVIA expert reviews your workflows, pinpoints the 3 highest-ROI AI opportunities, and hands you a concrete roadmap. No commitment, no jargon.

  • Full diagnostic of your business processes
  • Automatable quick wins, identified
  • A personalized roadmap you keep
Book my free audit

30 min · Free · No commitment