Skip to main content
Tuesday, May 26, 2026

LAW AND EVERYTHING ELSE

News, Analysis, and Commentary
Controversy

The AI Hiring Patchwork: Why Employers Can't Wait for Congress

With Colorado's AI Act taking effect June 30, Illinois and California already in force, and federal preemption efforts stalled, employers face a state-by-state compliance landscape with real enforcement teeth. The patchwork is messy. It is also, for now, the law.

By The Editors ·

An estimated 75 percent of large U.S. employers now use some form of AI in their hiring processes: resume-screening algorithms, video-interview analysis, candidate-ranking software, automated scheduling for interviews. The technology arrived faster than the law, and for several years employers operated in something close to a regulatory vacuum. That vacuum is closing rapidly, but it is closing unevenly, and the result is a state-by-state compliance landscape that is harder to manage than employers expected and that shows no sign of being simplified by federal action any time soon.

Here is the rough map. New York City has had a binding AI hiring law since 2023. Illinois's AI in hiring statute took effect January 1, 2026. California has amended its Fair Employment and Housing Act to regulate Automated Decision Systems in employment, effective last October. Colorado's comprehensive AI Act covers employment AI starting June 30. Texas's Responsible Artificial Intelligence Governance Act also took effect in January. More than a dozen other states have legislation in some stage of progress. The result is that an employer recruiting in five states may be subject to five different sets of rules.

What the laws actually require

The state laws differ in detail but cluster around a few recurring requirements. The strictest is New York City's Local Law 144, which requires annual bias audits of automated employment decision tools by an independent third party, with the audit results made publicly available. The vendor of the tool cannot conduct its own audit. Employers using a tool that has not been independently audited within the past year may not use it for hiring or promotion decisions affecting New York City residents.

Illinois's House Bill 3773, effective January 1, 2026, takes a different approach. It prohibits employers from using AI in ways that result in discriminatory bias against protected classes under the Illinois Human Rights Act, whether the discrimination is intentional or not. Employers must notify employees and candidates when AI is used in employment decisions. The statute specifically bans using ZIP codes as proxies for protected characteristics, a recognition that discriminatory outcomes can occur even when protected characteristics are not directly considered by the system.

California's amendments to the Fair Employment and Housing Act, which took effect October 1, 2025, prohibit the use of Automated Decision Systems for discriminatory hiring or employment practices, with a four-year record retention requirement for ADS-related data including input data, outputs, criteria used, and bias testing results. The law also assigns to the employer responsibility for discriminatory outcomes produced by third-party vendor systems.

Colorado's AI Act, which takes effect June 30, is the most comprehensive of the state laws and creates a dual obligation structure for AI "developers" and "deployers." An employer using high-risk AI in employment decisions is a "deployer" under the Act. Deployers must complete annual impact assessments, provide candidates with transparency notices when AI influences employment decisions, and maintain documentation that supports an appeals process if an applicant is adversely affected by an AI-influenced decision. Failure to comply is treated as an unfair trade practice under Colorado's consumer protection laws. Civil penalties can reach $20,000 per violation, meaning that an employer that fails to notify and provide appeals to ten rejected applicants could face $200,000 in cumulative fines.

Texas's TRAIGA, also effective January 1, 2026, focuses on disclosure: employers using AI systems that make or substantially influence employment decisions must inform affected individuals and provide information about the basis for the decisions. Texas is also developing broader high-risk AI legislation that may extend further into employment contexts.

The federal complication

Federal law has not changed materially. Title VII of the Civil Rights Act, the Americans with Disabilities Act, and the Age Discrimination in Employment Act all continue to apply to AI-driven employment decisions exactly as they apply to human-driven ones. The Equal Employment Opportunity Commission has issued guidance noting that AI-driven adverse-impact discrimination is actionable under existing federal civil rights statutes, but the EEOC has not issued binding rules specific to AI hiring tools.

What has changed is the political posture toward state AI regulation. In December 2025, the Trump administration issued Executive Order 14365, which directs the Department of Justice to establish an AI Litigation Task Force to challenge "burdensome" state AI laws. The White House published a National AI Legislative Framework in March 2026 recommending broad federal preemption. Neither has produced binding legal change. An attempt at federal preemption surfaced in mid-2025, when the One Big Beautiful Bill Act initially included a proposed ten-year moratorium on state and local AI regulation. That provision was removed from the final bill after bipartisan opposition.

The administration's posture appears to be shifting again. Following the limited April 2026 release of Anthropic's Mythos model, which demonstrated unprecedented capabilities in identifying and exploiting cybersecurity vulnerabilities, the White House began circulating in early May a draft executive order that would establish a federal review process for advanced AI models prior to public release. The draft is reportedly focused on national-security risks from frontier models rather than on the employment-context AI tools that the state laws regulate. Whether the broader federal preemption push survives the administration's pivot toward AI oversight remains an open question.

What this means in practice

For employers, the practical compliance question has settled into a relatively clear shape. Until federal preemption is enacted, which may not happen, state laws apply where they apply. An employer recruiting remote workers in California, Illinois, and New York City needs to comply with all three regimes simultaneously for those candidates. The compliance burden does not depend on where the employer is headquartered. Recruiting or employing remote workers in a jurisdiction with an AI law renders the employer subject to that jurisdiction's regulations.

The practical advice from employment-law practitioners has converged on a common approach: design AI hiring governance to meet the most stringent applicable state requirement, then apply that standard nationwide. California is currently the most stringent in terms of record retention and vendor accountability. Colorado will be the most stringent in terms of impact assessments and candidate notice requirements once it takes effect. New York City remains the most stringent in terms of bias audit requirements. An employer that meets all three is effectively in compliance everywhere else.

The hidden risk for employers is the disparate-impact exposure under federal law that the state laws are now making more visible. A bias audit conducted under NYC Local Law 144 may produce documentation that supports a Title VII disparate-impact claim against the same employer. Records retained under California's four-year ADS retention requirement may be subpoenaed in federal civil rights litigation. The state laws are not just compliance obligations; they are evidence-generation obligations whose outputs may be used against the employer in subsequent litigation under federal law.

The vendor problem

A separate, increasingly important question is who bears the compliance burden when an employer uses third-party AI hiring software. Under NYC Local Law 144, the bias audit must be conducted by an independent third party; the vendor cannot audit its own product. Under Colorado's law, AI developers must provide deployers with model cards and dataset documentation and must notify the state attorney general within ninety days if the system causes or is likely to cause algorithmic discrimination. Under California's law, the employer bears responsibility for discriminatory outcomes produced by vendor systems, but contracts can allocate that responsibility between employer and vendor.

The result is a complex set of contractual negotiations now underway between employers and AI hiring vendors. Many vendor agreements that predate the current generation of state laws do not clearly allocate bias-audit responsibilities, notice-and-disclosure responsibilities, or indemnity for state-law violations. Employers renegotiating these contracts in 2026 are asking for substantially more comprehensive compliance guarantees than they would have asked for two years ago.

What is likely to happen next

Three trajectories are plausible. The first is that federal preemption arrives in some form, either through legislation or through a successful DOJ challenge to one of the existing state laws under the Commerce Clause or some other theory. The Trump administration's AI Litigation Task Force was created precisely for this purpose. Whether it can identify a state AI law that is vulnerable to such a challenge, and whether the courts will agree, is unclear.

The second is that the patchwork stabilizes, with most states converging on something like the Colorado model and the federal government accepting state regulation of employment AI as a permanent feature of the landscape. This is the most likely outcome if federal preemption efforts continue to stall.

The third is that federal civil rights enforcement under existing statutes catches up to the state-law innovations. The EEOC could issue binding rules. Courts could develop case law clarifying how Title VII disparate-impact doctrine applies to AI hiring tools. Employer practice would then converge under federal pressure rather than state pressure.

None of these trajectories suggests that employers can wait for clarity. The state laws are in force now. The compliance obligations are real now. The penalties are real now. For employers using AI in any aspect of hiring or workforce management, the time to design a compliance program was last year. The next-best time is this quarter.

Sources