AI Hiring Laws in 2026: NYC Local Law 144, EU AI Act, GDPR and US State Rules

The main AI hiring laws and their status as of September 2026 — NYC Local Law 144, Illinois, California, Colorado, US federal law, the EU AI Act, GDPR and the UK — plus an agency compliance checklist.

By Beatview Team · Published · Updated · 9 min read

AI hiring compliance review showing NYC Local Law 144, EU AI Act, GDPR and Illinois status

Key takeaways

  • There is no single AI hiring law; duties come from city, state, federal, EU and UK rules that follow the candidate and the job location.
  • NYC Local Law 144 requires a bias audit within the past year, a published summary and candidate notice 10 business days before using an AEDT.
  • Illinois requires notice, explanation, consent and deletion on request for AI-analysed video interviews; HB 3773 adds anti-discrimination and notice duties from 2026.
  • The EU AI Act treats recruitment AI as high-risk; those duties were postponed to 2 December 2027, but workplace emotion recognition has been banned since February 2025.
  • Everywhere: tell candidates, keep a person meaningfully involved, be able to explain decisions, test for bias and keep records.

AI hiring laws are the rules that govern using automated tools — resume screening, AI interviews, ranking — to make or support employment decisions. As of September 2026 there is no single AI hiring law: obligations come from city and state rules in the US (New York City's Local Law 144, Illinois, California, Colorado), from anti-discrimination law that applies to any selection procedure, and in Europe from data protection law and the EU AI Act. The common threads are the same everywhere: tell candidates when AI is used, keep a person meaningfully involved, be able to explain decisions, test for bias and keep records. This guide summarises the main rules with their current status, then gives an agency-ready compliance checklist. It is a preparation aid, not legal advice — rules change often, so confirm with the primary sources and a qualified adviser.

AI hiring laws at a glance (September 2026)

Overview of AI hiring laws in 2026: NYC Local Law 144, Illinois, California, Colorado, EU AI Act, GDPR and the UK Data (Use and Access) Act with status
Rules follow where the candidate is and where the job is — not where your office is.
JurisdictionRuleStatus (Sept 2026)Core duties
New York CityLocal Law 144 (automated employment decision tools)Enforced since 5 July 2023Independent bias audit within the past year; publish a summary; notify candidates at least 10 business days before use
IllinoisArtificial Intelligence Video Interview ActIn force since 1 January 2020Notice, explanation of how the AI works, consent, limited sharing, deletion within 30 days on request
IllinoisHB 3773 (Human Rights Act amendment)In force since 1 January 2026No AI use that discriminates (including via proxies such as zip codes); notice when AI is used in employment decisions
CaliforniaCivil Rights Council regulations on automated-decision systemsIn force since 1 October 2025Anti-discrimination law applies to automated systems; keep related records for at least four years
ColoradoSB 26-189 (replacing the 2024 AI Act)Takes effect 1 January 2027Disclosure and transparency duties for automated decision-making in consequential decisions, including employment
US federalTitle VII, ADA, ADEA; Uniform Guidelines (29 CFR 1607)In forceSelection procedures with adverse impact must be job-related; applies to automated tools too
European UnionAI Act (Regulation (EU) 2024/1689)Prohibitions in force since Feb 2025; high-risk duties for recruitment postponed to 2 December 2027Recruitment AI is high-risk: risk management, human oversight, transparency, logging; emotion recognition at work is banned
EUGDPR (Article 22 and transparency rules)In forceLimits on solely automated decisions with significant effects; transparency; lawful basis; candidate rights
United KingdomUK GDPR as amended by the Data (Use and Access) Act 2025 (Articles 22A–22D)In force since 5 February 2026Significant automated decisions allowed with safeguards: information, human intervention, the right to contest

New York City Local Law 144

NYC Local Law 144 applies to employers and employment agencies that use an automated employment decision tool (AEDT) to substantially assist decisions about candidates or employees for jobs in New York City. Before using an AEDT you need an independent bias audit conducted within the past year, a published summary of its results, and notice to candidates at least 10 business days before the tool is used, including the job qualifications and characteristics it assesses. The city's Department of Consumer and Worker Protection enforces it; penalties run from $500 to $1,500 per violation, and each day of a continuing violation counts separately. If you place candidates into NYC roles with any scoring tool, read the DCWP guidance directly and take advice on whether your tool is an AEDT.

Illinois: AI video interviews and HB 3773

The Artificial Intelligence Video Interview Act is the rule most specific to AI interviews. Employers who use AI to analyse applicants' video interviews must, before the interview: notify the applicant that AI may be used, explain how the AI works and what general characteristics it evaluates, and obtain consent. Videos may be shared only with people whose expertise is needed to evaluate the applicant, and must be deleted within 30 days of an applicant's request, including copies held by others. Separately, HB 3773 amended the Illinois Human Rights Act from 1 January 2026 to prohibit using AI in ways that discriminate — including using zip codes as a proxy — and to require notice when AI is used in employment decisions. Proposed implementing rules were withdrawn, but the statutory duties stand.

California, Colorado and other US states

California's Civil Rights Council regulations, in force since 1 October 2025, confirm that the state's anti-discrimination law covers automated-decision systems in employment and require related records to be kept for at least four years. Colorado's original AI Act was delayed, then blocked in federal court in April 2026, and replaced by SB 26-189, which takes effect on 1 January 2027 with a disclosure-and-transparency approach to automated decisions. Several other states have bills in progress; check where your candidates and jobs are.

US federal law and litigation risk

In January 2025 the EEOC removed its earlier technical-assistance documents on AI from its website, but the underlying law did not change: Title VII, the ADA and the ADEA apply to selection procedures whether a person or software runs them, and the Uniform Guidelines' adverse-impact framework — including the "four-fifths" rule of thumb — still frames how selection procedures are assessed. Litigation is active: in Mobley v. Workday, a federal court in May 2025 allowed age-discrimination claims about AI screening to proceed as a nationwide collective action and rejected the argument that the software vendor could not be liable as an agent of employers.

European Union: the AI Act and GDPR

The EU AI Act lists AI systems used for recruitment and selection — including filtering applications and evaluating candidates — as high-risk. Its prohibitions, including emotion recognition in the workplace, have applied since 2 February 2025. The high-risk obligations for recruitment systems were due in August 2026 but were postponed to 2 December 2027 by the Digital Omnibus regulation adopted in July 2026; transparency duties for AI interacting with people still apply from August 2026. Under GDPR, candidates have the right not to be subject to solely automated decisions with legal or similarly significant effects except in limited cases, and to meaningful information about the logic involved.

United Kingdom: UK GDPR after the Data (Use and Access) Act

Since 5 February 2026, Articles 22A–22D of the UK GDPR replace the old Article 22 prohibition with a permission-plus-safeguards model: significant automated decisions (using non-special-category data) are allowed if you tell candidates, let them obtain human intervention and let them contest the decision. The ICO's 2024 audit of AI recruitment tools produced nearly 300 recommendations and found problems such as tools inferring gender or ethnicity from names; it is the most practical UK reference for what regulators expect.

AI hiring compliance checklist for recruitment agencies

1. Scope before you read any law

QuestionWhy it matters
Where are the candidates located?Data protection and some AI rules follow the candidate
Where will the person work?Employment and selection rules usually attach to the job location (e.g. NYC)
Who makes the hiring decision — you or the client?Determines who answers for the process and who controls the data
Which tool outputs affect who advances?A score that filters candidates is treated differently from notes a recruiter reads
Is anyone rejected without a person reviewing?Fully automated rejection triggers the strictest obligations

2. Document what your tools actually do

Write a one-page factual description per tool: what is scored, from which inputs, how scores combine, which steps run automatically, what is logged, where data is stored and for how long. Your adviser cannot assess a process you can only describe vaguely. Explainable tools make this easier — see explainable AI in recruiting.

3. Tell candidates, and get consent where required

State that AI is used, what it evaluates, that a person reviews results, how to request an alternative or human review, and how long recordings are kept. Put it in the job ad or application and in the interview invitation.

4. Keep humans meaningfully involved

Human review must be real: a person who reads the evidence and can overrule the score, not someone approving a ranked list unseen.

5. Test and monitor for bias

Commission a bias audit where required (NYC), monitor selection rates by stage where you lawfully can, and ask vendors for their testing methods. See bias in hiring.

6. Keep records and review on a schedule

Keep tool descriptions, notices, audit results and decision records (California requires four years for automated-decision records), and re-check the primary sources on a fixed schedule. A starting point for agencies is our AI recruiting policy template for agency clients.

Common assumptions that are not compliance

How Beatview supports a compliant process

Beatview's accurate description for your tool record: resumes are read and scored against role criteria with a written match analysis; recorded interviews ask fixed, timed questions and score the content of answers on relevance, clarity, depth of knowledge and overall, with written feedback — nothing visual is scored; the overall match score is the plain average of the resume and interview scores; automatic invitations run only if you enable stage rules; an event log records each step; recordings are retained for up to one year unless law requires otherwise; and customer and candidate data is not used to train shared models. Beatview does not provide bias audits, demographic analytics or legal advice. See security.

Frequently asked questions

What is NYC Local Law 144?

A New York City law, enforced since July 2023, that requires employers and employment agencies using automated employment decision tools for NYC jobs to obtain an independent bias audit within the past year, publish a summary of results and notify candidates at least 10 business days before use.

When does the EU AI Act apply to recruitment?

Recruitment AI is classed as high-risk. Prohibitions such as emotion recognition in the workplace have applied since February 2025, and the high-risk obligations for recruitment systems were postponed to 2 December 2027 by the Digital Omnibus regulation adopted in July 2026.

Is it legal to use AI in hiring in the US?

Yes, but federal anti-discrimination law applies to automated tools, and several jurisdictions add duties: NYC requires bias audits and notice, Illinois regulates AI video interviews and AI discrimination, California’s regulations cover automated-decision systems and Colorado’s new law takes effect in 2027.

Do candidates have to consent to AI interviews?

In Illinois, employers must obtain consent before using AI to analyse video interviews. Elsewhere notice is more common than consent, but data protection law such as GDPR requires a lawful basis and transparency. Check each jurisdiction where your candidates are.

Does GDPR ban automated hiring decisions?

EU GDPR restricts solely automated decisions with legal or similarly significant effects unless an exception applies, and requires safeguards such as human intervention. The UK moved to a permission-with-safeguards model in February 2026.

Is a recruitment agency responsible for its AI vendor’s compliance?

Often, at least partly. Duties generally fall on employers and, depending on the arrangement, agencies running the process; courts have also allowed claims against vendors. Get factual capability statements from vendors and legal advice for your situation.

Sources