What NYC Local Law 144 Actually Requires
Local Law 144 of 2021, commonly called the NYC Bias Audit Law, took effect on January 1, 2023, and regulates the use of "automated employment decision tools" (AEDTs) by employers and employment agencies hiring in New York City. The law applies whenever an AEDT is used to substantially assist or replace discretionary decision-making about hiring, promotion, or termination. The NYC Department of Consumer and Worker Protection (DCWP) enforces it through a public notice rule rather than a licensing or pre-approval system, which is a structure that has drawn criticism from compliance professionals because it places the burden of methodological soundness on the user rather than on the regulator.
Also worth reading: What is AI wage and hour compliance software, and do employers actually need it in 2026? · What does a joint pay assessment under the EU Pay Transparency Directive actually involve, and how should employers build a compliant workflow? · What is automated employment decision tools compliance, and how do employers comply with AI hiring laws in 2026?
A covered employer must, before using an AEDT: (1) conduct a bias audit of the tool no more than one year before the use date; (2) make the results of that audit publicly available on the employer's website; and (3) provide written notice to each candidate at least ten business days before the tool is used, describing what the tool does, the job qualifications it weighs, and instructions on how to request an alternative process. The bias audit itself must be conducted by an independent auditor — defined as a person or firm that does not participate in the development, sale, or distribution of the tool, and that has no financial interest tied to the outcome of the audit.
The current enforcement date most relevant to readers is July 5, 2023, when DCWP began issuing Notices of Violation rather than warnings. As of mid-2025, NYC has issued penalties and the regulatory environment has continued to evolve, with proposed federal preemption rules from the Trump administration adding another layer of uncertainty that compliance teams must track alongside the city rule.
Who Must Comply and Which Tools Are Covered
The law reaches any employer or employment agency using an AEDT in connection with a job located in New York City, even if the company's headquarters are elsewhere. A "covered AEDT" is any computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, a score, or a recommendation influencing employment decisions. Recruitment tools used only for sourcing passive candidates without producing a score or recommendation are generally treated as outside the rule, though employers should still document that scope decision in writing.
Resumes screeners, video interview analytics, coding assessment scorers, and ATS ranking engines all commonly fall inside the law's scope. Tools used solely for internal scheduling, calendar management, or background-check retrieval are not covered. Job boards offering plain listings without algorithmic ranking also fall outside. The classification decision frequently becomes the most contested part of an internal compliance review, because vendors often market tools as "advisory" or "candidate matching" to imply that the law does not apply.
The DCWP has clarified that an algorithm producing a score, classification, or recommendation that a hiring manager relies on — even informally — meets the definition. This means a recruiter who reads the tool's output and gives it weight in deciding whom to interview is using an AEDT, regardless of whether the tool is technically "automated" in the final decision. Practical coverage therefore extends well beyond what most vendor contracts describe as a "decision" tool.
The Statutory Bias Audit Methodology
The most technical compliance obligation is the bias audit itself. DCWP's rule prescribes two specific calculations, both expressed as "selection rate" and "impact ratio" comparisons across categories. The first calculation compares the selection rate of the most-selected category against every other category, for both sex and race/ethnicity separately, and for each intended employment decision (for example, hire versus not hire, or interview versus not interviewed). The second calculation compares, again by sex and by race/ethnicity, the selection rate of each category against the selection rate of the most-selected category.
The auditor must use historical data from the tool's own prior year of use by that employer whenever the tool has been in production for at least one year. If the tool is new to the employer, the audit may rely on a pre-deployment sample, a pilot study, or test data, but the audit must document the source and representativeness of that data. The "selection rate" is the proportion of applicants in a category who advance past the decision point being audited. The "impact ratio" is the lower selection rate divided by the higher selection rate, which produces a number between 0 and 1, where 1.0 indicates parity and lower numbers indicate larger disparities.
The rule does not set a numerical pass/fail threshold. Instead, employers must publicly disclose the calculated rates and ratios, leaving readers to interpret whether the disparities are acceptable. This approach has been widely criticized in industry commentary, including by BABL AI and the International Association of Privacy Professionals (IAPP), because it produces apparent compliance without any guarantee of substantive fairness. A vendor can run an audit, post the numbers, and still operate a system that screens out protected groups at a rate that would fail a four-fifths (80 percent) rule commonly used in EEOC adverse-impact analysis. Employers should not treat an audit as evidence that the tool is fair; they should treat it as a disclosure obligation satisfied.
Practical Steps to Complete a Compliant Audit
The first operational step is to inventory every algorithmically driven tool that touches the hiring pipeline and determine which of those qualify as AEDTs under the rule. This inventory should include the vendor name, the date the tool was first used in NYC, the data inputs, the decision it influences, and the contact for the vendor's compliance team. The inventory is a foundational document for any later audit, and it is the document that most commonly becomes outdated because vendors add features, change model versions, or expand into new use cases without notifying customers.
The next step is to select an independent auditor. Independence means the auditor has not developed, sold, or licensed the tool, and has no financial relationship that could be perceived as compromising the audit's objectivity. Several firms have built a market around this work, including BABL AI, ORCAA, and a growing list of boutique consultancies. Costs for an audit typically range from roughly $5,000 to $40,000 per tool per year depending on the number of decision points, the complexity of the data, and whether the auditor must also serve as the public-facing point of contact. Employers that use multiple AEDTs can expect the per-tool cost to decrease as the auditor amortizes fixed work across the engagement.
The auditor then performs the two required calculations, assembles the dataset, and produces a public summary report. The summary must include the date of the audit, a description of the tool, the data source, the selection rates and impact ratios for each protected category, and the auditor's name. The employer then publishes the report on its public website in a location that is reasonably accessible to the public — typically a "NYC Bias Audit" or "AI Compliance" page linked from the footer. Finally, the employer updates candidate-facing notices to describe the tool and to provide a ten-business-day pre-use window during which the candidate may request an alternative process.
Comparison of Audit Approaches and Tools
| Approach | Who performs it | Data source | Cost range (USD) | Time required | Key limitation |
|---|---|---|---|---|---|
| Statutory DCWP calculation | Independent auditor | Tool's own historical data | $5,000–$40,000 per tool | 4–10 weeks | No pass/fail threshold; only structured disclosure |
| Four-fifths (80%) rule analysis | Internal or external statistician | Same historical data, EEOC framework | $3,000–$15,000 | 2–6 weeks | Not officially recognized by DCWP; may be layered on top |
| Vendor-supplied audit summary | Vendor or partner firm | Often sample or pre-deployment data | Often free with license | 1–3 weeks | Independence and NYC compliance questionable |
| Internal data science review | Internal team | Production data | Cost of staff time | 4–12 weeks | Cannot be the sole basis; does not meet independence rule |
| Third-party full algorithmic audit (e.g., BABL AI, ORCAA) | Specialized audit firm | Production data plus fairness testing | $20,000–$100,000+ | 6–16 weeks | Expensive; may exceed statutory minimum |
Common Mistakes and Enforcement Risks
The most common compliance failure is treating a single public posting as a one-time event. Local Law 144 requires an annual audit, and many employers have let the year lapse between the first audit and the renewal. A second, equally common error is using the same data set across multiple years without confirming that the population, scoring logic, and decision flow have not changed, which can render the disclosed ratios stale by the time candidates read them. Hiring teams that change their resume-screening vendor or upgrade the model version should trigger a fresh audit and updated public notice before the new tool is used against any NYC candidate.
The third, and most consequential, mistake is publishing a report whose numbers do not match the underlying calculations. DCWP enforcement officers have reportedly sampled published reports and requested source data, and a discrepancy between the disclosed impact ratio and the underlying selection rates is treated as a substantive violation, not a clerical one. The fourth error is failing the ten-business-day candidate notice rule, which is a separate obligation from the audit and the public posting. A tool used on day eleven after notice, when the notice was sent on day nine, is a violation.
Enforcement to date has focused on notices of violation and monetary penalties. Civil penalties can reach up to $500 for a first violation and up to $1,500 for each subsequent violation, with each day of noncompliance counted as a separate violation. Critics, including the National Law Review, have noted that the enforcement structure does not require a substantively fair outcome, only a documented process, which can leave candidates with limited recourse if the disclosed numbers still indicate large disparities.
How Local Law 144 Interacts with Federal and State Rules
Local Law 144 sits inside a wider web of overlapping obligations, and the interaction between rules is now a major source of compliance risk. The EEOC's April 2023 guidance on AI-enabled employment assessments treats many AEDTs as tests that must satisfy the Uniform Guidelines on Employee Selection Procedures (UGESP), including the four-fifths rule. The Office of Federal Contract Compliance Programs (OFCCP) applies a similar framework to federal contractors. A compliant NYC bias audit does not, by itself, demonstrate UGESP compliance, because the NYC rule does not impose a numerical threshold, but a separate impact-ratio analysis against the four-fifths benchmark often satisfies both obligations if documented properly.
State-level rules in Illinois, California, and Connecticut impose disclosure and consent requirements that go beyond NYC's. The 2024 Illinois AI Video Interview Act amendments and California's Civil Code section on automated decision tools, among others, create overlapping notice obligations. For employers operating in multiple jurisdictions, the practical answer is to adopt the strictest applicable notice window (often ten business days, matching NYC) and the most thorough disclosure template, and then to layer state-specific language on top. Separately, the Trump administration's 2025 executive order on state AI laws has triggered litigation, and HR teams should expect the federal-state map to change in 2026 as the order works through the courts.
What to Do Today and What to Track
For a company that has not yet audited, the right first step is to freeze any new AEDT deployment for NYC-bound roles until a current bias audit exists, a public summary is posted, and the ten-business-day notice template is operational. The next step is to engage an independent auditor under a direct contract and to define the data extract the vendor must supply. For a company that has audited already, the most cost-effective action is to build an annual calendar with three triggers: the twelve-month audit anniversary, any vendor model update, and any change in decision flow. The triggers should be owned by a named individual in HR compliance, and each should produce a documented review of whether a new audit is required.
Looking forward, the 2026 risk profile is shaped by three forces. First, more states are likely to adopt NYC-style rules, and several already have, which raises the cost of running a single-jurisdiction audit. Second, the federal preemption question is unresolved, so companies should not assume the NYC rule will disappear. Third, the EPL (employment practices liability) insurance market is pricing AI hiring exposure higher, and Munich Re and other carriers have signaled that documented bias audits and adverse-impact testing are becoming underwriting prerequisites rather than optional add-ons. The combined direction is toward a world in which a defensible AI hiring program is documented, audited annually, and reviewed whenever the underlying model changes.