AI Hiring Laws by State: A 2026 Map

AI hiring laws are a patchwork of state and city statutes that regulate automated employment decision tools (AEDTs) used to screen, rank, or interview job candidates. As of 2026, there is no single federal AI hiring law in the United States, so employers face overlapping obligations from New York City Local Law 144, Illinois, Colorado, and a growing set of states, alongside federal anti-discrimination enforcement under Title VII and the Americans with Disabilities Act (ADA). The main compliance triggers are bias audits, candidate notice and consent, and adverse-impact testing of any algorithm that influences hiring.

This map covers what each jurisdiction requires, who is liable when an AI tool discriminates, and what to put in place before deploying one.

What counts as an AI hiring tool under the law?

Most statutes regulate a defined category rather than "AI" in general. The common term is automated employment decision tool (AEDT): any computational process, derived from machine learning, statistical modeling, data analytics, or artificial intelligence, that issues a simplified output (a score, ranking, or recommendation) used to substantially assist or replace human judgment in an employment decision.

In practice, the laws reach:

  • Resume screeners that parse and rank applicants

  • Automated video interview systems that score facial expression, word choice, or tone

  • Chatbot or assessment platforms that gate candidates before human review

  • Matching and sourcing engines that decide who sees a job or advances

What usually falls outside the definition: spreadsheets, simple keyword filters with no learned weighting, and tools that only support a decision a human makes independently. The line is whether the output substantially assists or replaces a person. That phrase carries most of the legal weight, and parties read it differently.

Is there a federal AI hiring law in 2026?

No. There is no comprehensive federal statute that governs AI in hiring as of 2026. Existing civil rights law applies to algorithmic tools the same way it applies to any other selection procedure.

The federal baseline rests on three sources:

  1. Title VII of the Civil Rights Act of 1964 prohibits employment discrimination based on race, color, religion, sex, and national origin. A hiring algorithm that produces a disparate impact on a protected group can violate Title VII even without intent to discriminate.

  2. The Americans with Disabilities Act (ADA) prohibits screening out people with disabilities. EEOC technical guidance warns that AI assessments can illegally screen out candidates who could do the job with a reasonable accommodation.

  3. The Age Discrimination in Employment Act (ADEA) protects workers 40 and older. Age has driven some of the most prominent AI hiring enforcement so far.

The Uniform Guidelines on Employee Selection Procedures (1978) remain the reference point for adverse-impact analysis. The widely cited four-fifths (80%) rule treats a selection rate for any group below 80% of the highest-scoring group's rate as evidence of adverse impact the employer must then justify as job-related.

Which states and cities have AI hiring laws in 2026?

The most concrete obligations come from a handful of jurisdictions. The table summarizes the active hiring laws.

Jurisdiction: New York City
Law: Local Law 144.
Core requirement: Conduct an independent bias audit of Automated Employment Decision Tools (AEDTs), publish a public audit summary, and provide advance notice to candidates.
Status: Enforced since July 5, 2023.

Jurisdiction: Illinois
Law: Artificial Intelligence Video Interview Act.
Core requirement: Provide candidates with notice, obtain consent, explain how AI evaluates video interviews, and delete recordings upon request where required.
Status: Effective January 1, 2020.

Jurisdiction: Illinois
Law: Amendment to the Illinois Human Rights Act (HB 3773).
Core requirement: Prohibits discriminatory use of AI in employment decisions and imposes notice requirements.
Status: Effective January 1, 2026.

Jurisdiction: Colorado
Law: Colorado AI Act (SB 24-205).
Core requirement: Exercise reasonable care to prevent algorithmic discrimination in high-risk AI systems, including those used in employment, and provide required consumer notices.
Status: Effective date is subject to change pending legislative updates.

Jurisdiction: Maryland
Law: Facial Recognition in Interviews Law (HB 1202).
Core requirement: Obtain written consent before using facial recognition technology during a job interview.
Status: In effect.

A few clarifications matter:

  • New York City Local Law 144 is the most operationally demanding, requiring an audit by an independent auditor and a published summary. For a full breakdown of audit scope, the bias-metric calculations, and the notice timeline, see our detailed guide to New York City Local Law 144.

  • Illinois was first to regulate AI video interviews specifically. The 2026 amendment to its Human Rights Act extends liability to AI used in a broader set of employment decisions, not just video.

  • Colorado's law is the broadest single-state framework, assigning duties to both developers and deployers of high-risk AI systems and treating employment as a high-risk use. Its effective date has moved more than once and the statute has been subject to repeal-and-replace activity, so confirm the operative text and date in Colorado before relying on it. [date to verify]

Other states have introduced or studied bills on automated decision systems, and several have task forces or narrower transparency rules. Because the picture changes each legislative session, treat any list as a snapshot and verify current text in the relevant jurisdiction before deployment.

What does NYC Local Law 144 actually require?

Local Law 144 sets the template other jurisdictions borrow from. The law applies to employers and employment agencies using an AEDT to screen candidates or employees for a position in New York City.

The three obligations:

  1. Bias audit. Within the prior 12 months, the AEDT must undergo an independent bias audit calculating selection or scoring rates and impact ratios across sex, race/ethnicity, and their intersections.

  2. Published results. A summary of the most recent audit, including the tool's distribution date, must be posted publicly on the employer's website.

  3. Candidate notice. NYC residents must be notified at least 10 business days before the tool is used, told what job qualifications and characteristics it assesses, and given a way to request an alternative process or accommodation.

Penalties run from $500 to $1,500 per violation, and each day of noncompliant use can count separately. The lesson for employers outside NYC: this audit-and-notice model is spreading, and building to it now reduces rework later.

Who is liable when an AI hiring tool discriminates?

Liability is shared and contested, the most important point for executives signing vendor contracts. Three categories of party can be exposed:

  • The employer (deployer). Anti-discrimination law attaches to the entity making the hiring decision. An employer generally cannot avoid Title VII liability by pointing to a vendor's tool.

  • The vendor (developer). Whether a software provider can be sued directly is the central question in Mobley v. Workday, which alleges that Workday's screening tools discriminated against applicants on the basis of age. A federal court in California allowed the disparate impact claim under the ADEA to proceed and, in 2025, granted preliminary collective certification covering applicants age 40 and older. The court did not rule on the merits, and the scope of vendor exposure is still developing, so track the docket. [docket status to verify]

  • The auditor. Independent auditors carry reputational and contractual exposure, and several state frameworks address their role explicitly.

Two enforcement actions show the pattern in practice:

  • iTutorGroup (EEOC, 2023). The company's recruiting software was configured to automatically reject female applicants over 55 and male applicants over 60. The company settled with the EEOC, agreeing to pay $365,000 and adopt anti-discrimination measures. It was an early signal that the EEOC would treat automated rejection as ordinary age discrimination.

  • Amazon's scrapped recruiting tool (reported 2018). Amazon built an experimental tool to rank resumes and found it had learned to penalize resumes containing the word "women's" and to down-rank graduates of certain all-women's colleges, because it was trained on a decade of male-dominated hiring data. Amazon abandoned the project. The episode is the most cited example of training-data bias producing a discriminatory model.

The pattern: an algorithm trained on historical decisions can reproduce the patterns in that history, and the law treats the result as the employer's responsibility.

How does the EU AI Act affect US employers?

The EU AI Act reaches US companies that use AI hiring systems on candidates located in the EU, or whose output is used there. The Act classifies AI systems used for recruitment, selection, and decisions about work as high-risk under Annex III.

High-risk classification brings obligations that go beyond most US state laws:

  • Risk management and data governance across the model lifecycle

  • Human oversight designed into the system

  • Technical documentation and logging sufficient for an audit

  • Transparency to people subject to the system

The high-risk obligations for these employment systems are scheduled to apply from August 2, 2026, though the timeline has been the subject of proposed amendment, so confirm the operative date. [date to verify] For a US employer with EU operations or EU applicants, the AI Act often sets the effective compliance ceiling, because meeting it generally exceeds what NYC or Colorado require. Many global employers standardize on the stricter EU obligations rather than run a separate process per region.

What should employers do before deploying an AI hiring tool?

Compliance is achievable with an ordered process. The steps below apply across jurisdictions and map to what auditors and regulators look for.

  1. Inventory every tool that touches a hiring decision. Include sourcing, screening, assessment, and interview systems, plus any embedded vendor features inside your applicant tracking system.

  2. Classify each tool against the AEDT definition. Decide whether the output "substantially assists or replaces" human judgment, and document the reasoning.

  3. Demand audit results and documentation from vendors. Get the bias audit, impact ratios, training-data description, and validation evidence in writing before you sign.

  4. Run or commission an independent bias audit. Calculate selection rates and impact ratios across sex and race/ethnicity categories and their intersections, using the four-fifths rule as a screen, not a safe harbor.

  5. Build notice and consent into the candidate flow. Provide advance notice, describe what the tool assesses, and offer an alternative process or accommodation, especially for ADA reasons.

  6. Test for disability screen-out. Confirm the tool does not penalize candidates who need accommodation, including assessments that measure traits unrelated to the job.

  7. Keep a human in the loop with real authority. Document where a person can override the tool, and make that override genuine rather than a rubber stamp.

  8. Re-audit on a schedule. NYC requires an audit within the prior 12 months; treat annual re-auditing as the baseline.

Frequently asked questions

Do AI hiring laws apply to small businesses?

It depends on the law. NYC Local Law 144 applies to any employer using an AEDT for an NYC position, regardless of size. Federal Title VII generally applies to employers with 15 or more employees, and the ADEA to those with 20 or more. State laws set their own thresholds. A small employer using a covered tool in NYC can still be obligated to audit and provide notice.

Is using an AI resume screener legal?

Yes, using an AI resume screener is legal in most of the US, but it is regulated. The tool must not produce a disparate impact on protected groups, and in jurisdictions like NYC it must be bias-audited and disclosed to candidates. Legality depends on how the tool is built, validated, and monitored, not on whether AI is used at all.

What is a bias audit for hiring AI?

A bias audit is an independent evaluation that calculates the selection or scoring rates a tool produces for different demographic groups and compares them, typically as impact ratios. Under NYC Local Law 144, the audit covers sex, race/ethnicity, and intersectional categories, must be performed by an independent auditor, and its summary published before the tool is used.

Does the EU AI Act apply to US companies hiring in the US?

Not for purely US hiring. The EU AI Act applies when an AI hiring system is used on candidates located in the EU or when its output is used there. A US company hiring only US-based candidates is governed by US federal, state, and local law. A US company recruiting EU candidates falls under the Act's high-risk obligations.

Next steps checklistAction: Inventory all hiring tools and vendor AI features.
Owner: Talent and IT.
Cadence: Quarterly.

Action: Classify each tool against the Automated Employment Decision Tool (AEDT) definition.
Owner: Legal.
Cadence: For every new tool.

Action: Obtain vendor bias audits and model validation evidence.
Owner: Procurement and Legal.
Cadence: Before signing the contract.

Action: Commission an independent bias audit.
Owner: Legal and an external auditor.
Cadence: Annually.

Action: Implement candidate notice, obtain consent where required, and provide an alternative process.
Owner: Talent Operations.
Cadence: Before deployment.

Action: Test AI systems for potential disability-related screen-out under the ADA.
Owner: Legal and accessibility team.
Cadence: Annually.

Action: Verify that hiring managers can meaningfully override AI-assisted decisions.
Owner: Hiring managers.
Cadence: Ongoing.

Action: Monitor new state AI legislation and developments in the Mobley v. Workday case.
Owner: Legal.
Cadence: Ongoing.

Next
Next

How to Write an Internal AI Policy (Template)