AI

Your Hiring Algorithm Might Be Illegal. Here’s What the New AI Employment Laws Actually Require.

AI hiring algorithm employment law compliance Colorado Texas NYC
AI hiring algorithm employment law compliance Colorado Texas NYC

By Chris Meredith


If your company uses AI to screen resumes, rank candidates, or flag employees for performance review, you may already be operating in violation of state law — and the legal landscape just got significantly more complicated.

2026 marks the year AI hiring regulation moved from theoretical concern to active compliance requirement. Texas’s Responsible AI Governance Act went live January 1. New York City’s hiring transparency law, which most employers still haven’t fully implemented, has been in force since 2023. Colorado rewrote its landmark AI Act in May 2026, replacing the original law with a narrower transparency framework that takes effect January 1, 2027. And a Trump executive order attempting to consolidate all of this into a single federal framework is being challenged by state attorneys general who don’t want to give up their ability to regulate their own labor markets.

The result is a patchwork of requirements that varies significantly by state, creates real legal exposure for employers who haven’t done an audit, and will almost certainly get more complicated before it gets simpler.

Rows of identical translucent cards sorted into two diverging paths with one card highlighted in amber

Why This Is Happening Now

Hiring has always been opaque. Hiring with AI is opaque in ways that scale.

A traditional human recruiter develops biases over time, makes inconsistent decisions, and discriminates in ways that can eventually be identified and corrected through pattern analysis. A biased AI model makes inconsistent decisions at tens of thousands of decisions per month, encodes those patterns into numerical scores, and produces outputs that are difficult to audit without the underlying model documentation.

The canonical cases that pushed legislators toward action aren’t hypothetical. Amazon quietly shut down an AI recruiting tool in 2018 after discovering it had taught itself to penalize resumes that included the word “women’s” and downgraded graduates of all-women’s colleges. That model had been trained on a decade of Amazon’s historical hiring data, which reflected existing gender imbalances in tech. The algorithm was doing exactly what it was trained to do — replicate past decisions — and the past decisions were discriminatory.

The legislators writing AI hiring laws in 2025 and 2026 had access to five additional years of similar case studies. The laws reflect a clear theory: that automated hiring systems require transparency obligations and bias auditing precisely because their errors are systematic rather than idiosyncratic.

What Colorado’s New Law Actually Requires

Colorado has the most instructive recent history of any state on AI hiring regulation — not because its law is currently in force, but because of what happened to the first one.

The original Colorado AI Act, SB 24-205, would have been the most demanding employer AI law in the country: broad impact assessment requirements, a duty-of-care mandate on developers, and an aggressive enforcement structure. It was supposed to take effect February 1, 2026. It never did. Business stakeholders pushed back hard on the compliance burden, and the legislature repealed and replaced it before it ever went live.

The replacement — Senate Bill 26-189, signed into law May 14, 2026 — takes a fundamentally different approach. Where SB 24-205 imposed prescriptive governance obligations, SB 26-189 focuses on transparency, disclosure, and consumer rights. There are no impact assessment requirements. No duty-of-care mandate on developers. The framework is narrower by design.

What SB 26-189 does require, for consequential decisions including hiring, termination, promotion, compensation, and scheduling: deployers must notify employees and job applicants when an automated decision-making tool materially influences a consequential outcome affecting them. If that decision is adverse — a rejection, a demotion, a termination — the affected person has the right to an explanation within 30 days and the right to request meaningful human review of the decision.

On the developer side, companies building automated decision-making tools must provide deployers with technical documentation covering the tool’s intended uses, training data categories, known limitations, and instructions for appropriate human review. The compliance obligation runs in both directions.

The critical timing point: SB 26-189 doesn’t take effect until January 1, 2027. Colorado is not a current compliance requirement — it’s a 2027 compliance requirement that smart employers are preparing for now.

Overlapping translucent panels stacked into a layered relief, representing a patchwork of state AI regulations

What Texas Did Instead

Texas’s approach is instructive precisely because it’s different from Colorado’s, and the difference reflects a genuine policy disagreement about how AI should be regulated.

The Texas Responsible Artificial Intelligence Governance Act — TRAIGA — establishes a general framework that explicitly prohibits AI systems from intentionally discriminating against individuals based on protected characteristics. The key word is “intentionally.” Unlike Colorado, TRAIGA does not recognize disparate impact as a standalone basis for liability. An AI system that produces discriminatory outcomes without evidence of intentional discriminatory design is not automatically in violation of TRAIGA.

This is a meaningful limitation. Most AI discrimination claims involve disparate impact: the system wasn’t designed to discriminate, but its outputs disproportionately harm protected groups because the training data encoded historical disparities. Colorado’s revised law (SB189, effective January 2027) and Texas both require disclosure and notification when AI influences consequential employment decisions, but neither makes disparate impact alone a basis for liability. The difference between the two states is one of degree rather than philosophy at this point — Colorado is more prescriptive about documentation and human review, Texas is more permissive.

The practical effect for multi-state employers is that satisfying Colorado’s 2027 requirements will largely cover Texas as well. But the philosophical difference is worth understanding: Texas is signaling that the state doesn’t want employment discrimination law substantially rewritten through AI regulation, which is what broad disparate impact liability in AI would functionally accomplish. Colorado agrees, which is why it walked back its original law.

New York City: The Disclosure Baseline

NYC’s Automated Employment Decision Tool law — AEDT — was the first of its kind when it went into effect in July 2023, and it established a disclosure and audit framework that influenced the state laws that followed.

Under the NYC law, employers using automated employment decision tools to screen or evaluate job candidates or employees in positions based in New York City must:

Conduct a bias audit of the tool within one year before deployment and annually thereafter. The audit must be conducted by an independent auditor and evaluate the tool for bias with respect to sex, race, and ethnicity.

Post a summary of the most recent bias audit results on their website, or provide it to job candidates or employees on request.

Disclose to any job candidate or employee subject to AEDT screening that such a tool was used and what characteristics it evaluated.

The law has been in effect for three years and compliance remains inconsistent. Many employers using AI-assisted hiring tools either don’t know the law applies to them or have concluded the enforcement risk is manageable. That calculus is about to change as state-level laws with more aggressive enforcement mechanisms go live.

The Federal Wildcard

On December 11, 2025, President Trump signed Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence.” The order directs federal agencies to develop guidelines aimed at preempting state AI regulations in favor of a unified national standard. The underlying logic is that a 50-state patchwork of AI regulations is inefficient and that national standards serve innovation better than jurisdictional fragmentation.

The problem is that executive orders don’t preempt state law. Preemption requires either a federal statute or a regulatory framework authorized by a statute and subject to notice-and-comment rulemaking. Until Congress acts or a federal agency finalizes binding rules that explicitly preempt state requirements, employers must continue complying with applicable state and local laws.

Several state attorneys general have already signaled their intention to resist federal preemption efforts, arguing that labor market regulation has historically been a state function and that the administration lacks authority to override state hiring laws through executive action alone.

The practical guidance for employers right now is simple: assume Colorado, NYC, and Texas rules apply where relevant. Don’t wait for federal clarity that may be years away.

The Case for AI in Hiring (and Why It Doesn’t Resolve the Compliance Question)

Before treating AI hiring regulation purely as a compliance burden, it’s worth engaging with the honest counterargument: AI-assisted screening, done well, can reduce human bias rather than amplify it.

Human hiring decisions are consistently influenced by factors that have nothing to do with job performance — a candidate’s name, their college, their accent in a phone screen, whether they remind the interviewer of themselves. A well-designed algorithmic system, evaluated against validated job-relevant criteria and audited for disparate impact, could in principle make hiring more consistent and fairer than the unstructured gut-feel process it replaces.

This argument is real, and regulators largely accept it. None of the current AI hiring laws ban automated decision-making in employment contexts. The disclosure requirements and bias auditing frameworks aren’t built on the premise that AI is inherently bad for hiring — they’re built on the premise that AI in hiring needs to be transparent and verifiable, not just trusted. The compliance requirement and the bias-reduction opportunity aren’t in conflict. You can build an AI hiring system that’s genuinely fairer than the alternative and still be required to disclose its use, document its training data, and provide human review on adverse outcomes. The law just asks you to prove it.

The Audit Imperative

The common thread running through every AI hiring law currently in force is the bias audit requirement. Not just a review of the model’s training data. Not just an accuracy check on outcomes. A systematic evaluation of whether the system produces discriminatory disparities across protected groups, conducted before deployment and repeated annually.

For most employers, this requires engaging an independent auditor with AI expertise, which is a real cost and a real operational commitment. The alternative is to assume your HR software vendor has handled this on your behalf. Some have. Many haven’t, and the deployment contract you signed likely pushed the compliance obligation back to you.

The audit requirement also creates a documentation trail that matters in litigation. An employer who conducted regular bias audits, documented the results, and took action to remediate identified disparities is in a categorically different legal position than an employer who deployed the system and never looked at the outputs.

What Employers Should Do Before the End of 2026

The window for getting ahead of this is narrowing. The states with the most aggressive requirements are already enforcing them. Others are watching and will follow.

Every employer using AI tools in hiring, performance management, or compensation decisions should begin with a complete audit of which tools are in use and what decisions they influence. Many HR and talent software platforms now incorporate AI features that weren’t present when the original contract was signed.

For every tool identified, determine whether it meets the applicable state law’s definition of a high-risk or automated employment decision system. The definitions vary, but any system that scores, ranks, or makes recommendations about individual candidates or employees based on machine learning outputs is almost certainly covered.

Engage with your vendors to understand what audit documentation they’ve produced, what training data was used, and what outcome disparities they’ve tested for. If they can’t answer those questions, that’s a compliance risk you’re absorbing.

Build the notification and appeal workflows that allow affected candidates and employees to request human review. This is required under NYC’s AEDT framework now, under Colorado’s SB189 starting January 1, 2027, and is coming to more jurisdictions — building it once is far less costly than building it state by state under deadline.

Finally, document everything. The companies that get through enforcement actions intact are the ones that can demonstrate a good-faith compliance effort with a paper trail, not the ones that had perfect tools.

The Baseline Is Moving

AI hiring laws are not going to get less stringent. Colorado’s legislative arc — ambitious law, business pushback, revised narrower framework — is actually the more optimistic scenario for employers. The revised law is workable. That’s not guaranteed in jurisdictions that haven’t gone through that recalibration yet.

NYC’s disclosure framework is being adopted and expanded across the country. Colorado’s SB189 disclosure and human review model arrives January 2027. The federal government’s attempt to rationalize this into a single standard will eventually produce something, but the timeline is uncertain.

The companies that build compliance infrastructure now — candidate disclosure workflows, vendor documentation reviews, human review processes — are building it once. The companies that wait are building it under deadline, probably under legal pressure, and almost certainly at higher cost.

AI in hiring isn’t going away. The compliance requirement around it isn’t going away either. The question is just whether you handle it on your schedule or someone else’s.


Chris Meredith writes about AI, technology, and the systems shaping how we work.

Chris Meredith writes about AI, technology, and what it actually means for real people. Follow along on Substack: monkeyattack.substack.com

Leave a Reply

Your email address will not be published. Required fields are marked *