AI Hiring Laws in 2026: NYC Local Law 144, EU AI Act, GDPR and US State Rules
The main AI hiring laws and their status as of September 2026 — NYC Local Law 144, Illinois, California, Colorado, US federal law, the EU AI Act, GDPR and the UK — plus an agency compliance checklist.
By Beatview Team · Published · Updated · 9 min read

Key takeaways
- There is no single AI hiring law; duties come from city, state, federal, EU and UK rules that follow the candidate and the job location.
- NYC Local Law 144 requires a bias audit within the past year, a published summary and candidate notice 10 business days before using an AEDT.
- Illinois requires notice, explanation, consent and deletion on request for AI-analysed video interviews; HB 3773 adds anti-discrimination and notice duties from 2026.
- The EU AI Act treats recruitment AI as high-risk; those duties were postponed to 2 December 2027, but workplace emotion recognition has been banned since February 2025.
- Everywhere: tell candidates, keep a person meaningfully involved, be able to explain decisions, test for bias and keep records.
AI hiring laws are the rules that govern using automated tools — resume screening, AI interviews, ranking — to make or support employment decisions. As of September 2026 there is no single AI hiring law: obligations come from city and state rules in the US (New York City's Local Law 144, Illinois, California, Colorado), from anti-discrimination law that applies to any selection procedure, and in Europe from data protection law and the EU AI Act. The common threads are the same everywhere: tell candidates when AI is used, keep a person meaningfully involved, be able to explain decisions, test for bias and keep records. This guide summarises the main rules with their current status, then gives an agency-ready compliance checklist. It is a preparation aid, not legal advice — rules change often, so confirm with the primary sources and a qualified adviser.
AI hiring laws at a glance (September 2026)

| Jurisdiction | Rule | Status (Sept 2026) | Core duties |
|---|---|---|---|
| New York City | Local Law 144 (automated employment decision tools) | Enforced since 5 July 2023 | Independent bias audit within the past year; publish a summary; notify candidates at least 10 business days before use |
| Illinois | Artificial Intelligence Video Interview Act | In force since 1 January 2020 | Notice, explanation of how the AI works, consent, limited sharing, deletion within 30 days on request |
| Illinois | HB 3773 (Human Rights Act amendment) | In force since 1 January 2026 | No AI use that discriminates (including via proxies such as zip codes); notice when AI is used in employment decisions |
| California | Civil Rights Council regulations on automated-decision systems | In force since 1 October 2025 | Anti-discrimination law applies to automated systems; keep related records for at least four years |
| Colorado | SB 26-189 (replacing the 2024 AI Act) | Takes effect 1 January 2027 | Disclosure and transparency duties for automated decision-making in consequential decisions, including employment |
| US federal | Title VII, ADA, ADEA; Uniform Guidelines (29 CFR 1607) | In force | Selection procedures with adverse impact must be job-related; applies to automated tools too |
| European Union | AI Act (Regulation (EU) 2024/1689) | Prohibitions in force since Feb 2025; high-risk duties for recruitment postponed to 2 December 2027 | Recruitment AI is high-risk: risk management, human oversight, transparency, logging; emotion recognition at work is banned |
| EU | GDPR (Article 22 and transparency rules) | In force | Limits on solely automated decisions with significant effects; transparency; lawful basis; candidate rights |
| United Kingdom | UK GDPR as amended by the Data (Use and Access) Act 2025 (Articles 22A–22D) | In force since 5 February 2026 | Significant automated decisions allowed with safeguards: information, human intervention, the right to contest |
New York City Local Law 144
NYC Local Law 144 applies to employers and employment agencies that use an automated employment decision tool (AEDT) to substantially assist decisions about candidates or employees for jobs in New York City. Before using an AEDT you need an independent bias audit conducted within the past year, a published summary of its results, and notice to candidates at least 10 business days before the tool is used, including the job qualifications and characteristics it assesses. The city's Department of Consumer and Worker Protection enforces it; penalties run from $500 to $1,500 per violation, and each day of a continuing violation counts separately. If you place candidates into NYC roles with any scoring tool, read the DCWP guidance directly and take advice on whether your tool is an AEDT.
Illinois: AI video interviews and HB 3773
The Artificial Intelligence Video Interview Act is the rule most specific to AI interviews. Employers who use AI to analyse applicants' video interviews must, before the interview: notify the applicant that AI may be used, explain how the AI works and what general characteristics it evaluates, and obtain consent. Videos may be shared only with people whose expertise is needed to evaluate the applicant, and must be deleted within 30 days of an applicant's request, including copies held by others. Separately, HB 3773 amended the Illinois Human Rights Act from 1 January 2026 to prohibit using AI in ways that discriminate — including using zip codes as a proxy — and to require notice when AI is used in employment decisions. Proposed implementing rules were withdrawn, but the statutory duties stand.
California, Colorado and other US states
California's Civil Rights Council regulations, in force since 1 October 2025, confirm that the state's anti-discrimination law covers automated-decision systems in employment and require related records to be kept for at least four years. Colorado's original AI Act was delayed, then blocked in federal court in April 2026, and replaced by SB 26-189, which takes effect on 1 January 2027 with a disclosure-and-transparency approach to automated decisions. Several other states have bills in progress; check where your candidates and jobs are.
US federal law and litigation risk
In January 2025 the EEOC removed its earlier technical-assistance documents on AI from its website, but the underlying law did not change: Title VII, the ADA and the ADEA apply to selection procedures whether a person or software runs them, and the Uniform Guidelines' adverse-impact framework — including the "four-fifths" rule of thumb — still frames how selection procedures are assessed. Litigation is active: in Mobley v. Workday, a federal court in May 2025 allowed age-discrimination claims about AI screening to proceed as a nationwide collective action and rejected the argument that the software vendor could not be liable as an agent of employers.
European Union: the AI Act and GDPR
The EU AI Act lists AI systems used for recruitment and selection — including filtering applications and evaluating candidates — as high-risk. Its prohibitions, including emotion recognition in the workplace, have applied since 2 February 2025. The high-risk obligations for recruitment systems were due in August 2026 but were postponed to 2 December 2027 by the Digital Omnibus regulation adopted in July 2026; transparency duties for AI interacting with people still apply from August 2026. Under GDPR, candidates have the right not to be subject to solely automated decisions with legal or similarly significant effects except in limited cases, and to meaningful information about the logic involved.
United Kingdom: UK GDPR after the Data (Use and Access) Act
Since 5 February 2026, Articles 22A–22D of the UK GDPR replace the old Article 22 prohibition with a permission-plus-safeguards model: significant automated decisions (using non-special-category data) are allowed if you tell candidates, let them obtain human intervention and let them contest the decision. The ICO's 2024 audit of AI recruitment tools produced nearly 300 recommendations and found problems such as tools inferring gender or ethnicity from names; it is the most practical UK reference for what regulators expect.
AI hiring compliance checklist for recruitment agencies
1. Scope before you read any law
| Question | Why it matters |
|---|---|
| Where are the candidates located? | Data protection and some AI rules follow the candidate |
| Where will the person work? | Employment and selection rules usually attach to the job location (e.g. NYC) |
| Who makes the hiring decision — you or the client? | Determines who answers for the process and who controls the data |
| Which tool outputs affect who advances? | A score that filters candidates is treated differently from notes a recruiter reads |
| Is anyone rejected without a person reviewing? | Fully automated rejection triggers the strictest obligations |
2. Document what your tools actually do
Write a one-page factual description per tool: what is scored, from which inputs, how scores combine, which steps run automatically, what is logged, where data is stored and for how long. Your adviser cannot assess a process you can only describe vaguely. Explainable tools make this easier — see explainable AI in recruiting.
3. Tell candidates, and get consent where required
State that AI is used, what it evaluates, that a person reviews results, how to request an alternative or human review, and how long recordings are kept. Put it in the job ad or application and in the interview invitation.
4. Keep humans meaningfully involved
Human review must be real: a person who reads the evidence and can overrule the score, not someone approving a ranked list unseen.
5. Test and monitor for bias
Commission a bias audit where required (NYC), monitor selection rates by stage where you lawfully can, and ask vendors for their testing methods. See bias in hiring.
6. Keep records and review on a schedule
Keep tool descriptions, notices, audit results and decision records (California requires four years for automated-decision records), and re-check the primary sources on a fixed schedule. A starting point for agencies is our AI recruiting policy template for agency clients.
Common assumptions that are not compliance
- "A human reviews it, so we're fine." Nominal review — approving a list without reading the evidence — may not count.
- "We have an audit trail." An event log shows what the software did; it is not a bias audit.
- "Our vendor is compliant, so we are." Duties generally fall on the employer and, depending on the arrangement, the agency. Ask vendors for factual capability statements, not compliance promises.
- "We ask everyone the same questions, so it's fair." Consistency helps; it does not prove fairness.
How Beatview supports a compliant process
Beatview's accurate description for your tool record: resumes are read and scored against role criteria with a written match analysis; recorded interviews ask fixed, timed questions and score the content of answers on relevance, clarity, depth of knowledge and overall, with written feedback — nothing visual is scored; the overall match score is the plain average of the resume and interview scores; automatic invitations run only if you enable stage rules; an event log records each step; recordings are retained for up to one year unless law requires otherwise; and customer and candidate data is not used to train shared models. Beatview does not provide bias audits, demographic analytics or legal advice. See security.
Frequently asked questions
What is NYC Local Law 144?
A New York City law, enforced since July 2023, that requires employers and employment agencies using automated employment decision tools for NYC jobs to obtain an independent bias audit within the past year, publish a summary of results and notify candidates at least 10 business days before use.
When does the EU AI Act apply to recruitment?
Recruitment AI is classed as high-risk. Prohibitions such as emotion recognition in the workplace have applied since February 2025, and the high-risk obligations for recruitment systems were postponed to 2 December 2027 by the Digital Omnibus regulation adopted in July 2026.
Is it legal to use AI in hiring in the US?
Yes, but federal anti-discrimination law applies to automated tools, and several jurisdictions add duties: NYC requires bias audits and notice, Illinois regulates AI video interviews and AI discrimination, California’s regulations cover automated-decision systems and Colorado’s new law takes effect in 2027.
Do candidates have to consent to AI interviews?
In Illinois, employers must obtain consent before using AI to analyse video interviews. Elsewhere notice is more common than consent, but data protection law such as GDPR requires a lawful basis and transparency. Check each jurisdiction where your candidates are.
Does GDPR ban automated hiring decisions?
EU GDPR restricts solely automated decisions with legal or similarly significant effects unless an exception applies, and requires safeguards such as human intervention. The UK moved to a permission-with-safeguards model in February 2026.
Is a recruitment agency responsible for its AI vendor’s compliance?
Often, at least partly. Duties generally fall on employers and, depending on the arrangement, agencies running the process; courts have also allowed claims against vendors. Get factual capability statements from vendors and legal advice for your situation.
Sources
- NYC DCWP: Automated Employment Decision Tools (Local Law 144).
- Illinois General Assembly: Artificial Intelligence Video Interview Act (820 ILCS 42).
- California Civil Rights Department: regulations on automated-decision systems.
- EUR-Lex: Regulation (EU) 2024/1689 (AI Act); Gibson Dunn: AI Act omnibus — postponed high-risk deadlines.
- UK legislation: Data (Use and Access) Act 2025, section 80; ICO: AI tools used in recruitment.
- eCFR: 29 CFR Part 1607, Uniform Guidelines on Employee Selection Procedures.
- Holland & Knight: Mobley v. Workday collective action; McDermott: Colorado replacement AI law.