As of August 2026, there is no single federal law requiring bias audits of AI hiring tools. Instead, employers face a growing patchwork of state and local requirements, each with its own scope, timing, and enforcement mechanism. The two most consequential mandates remain New York City's Local Law 144, which has required annual independent bias audits of automated employment decision tools (AEDTs) since July 5, 2023, and Colorado's Artificial Intelligence Act (SB 24-205), which takes a disclosure-and-duty-of-care approach rather than mandating audits outright. Illinois amended its Artificial Intelligence Video Interview Act in 2024 to add notice, explanation, and anti-discrimination duties. Connecticut enacted its own AI law covering automated employment decisions, and several other states — including California through regulations from its Civil Rights Council, and Texas through its TRAIGA framework — are moving toward similar rules. Understanding exactly what each jurisdiction requires, and where the gaps sit between them, is now a baseline competency for any HR or compliance function operating across state lines.

The Direct Answer: Which States Require Bias Audits Today

Also worth reading: What are the joint pay assessment requirements under the EU Pay Transparency Directive and how must employers comply? · How does AI compliance HR workflow automation function in 2026, and what are the regulatory requirements for employers? · How do automated labor compliance management systems work and what should employers know before implementing them?

Only one jurisdiction currently imposes a formal, recurring, independently conducted bias audit requirement on employers: New York City, under Local Law 144. That law requires any employer using an AEDT to screen candidates for employment decisions within the city to commission an independent bias audit at least once per year, publish a summary of the results on its website before using the tool, and provide candidates with advance notice at least 10 business days before the tool is used, including instructions for requesting an alternative selection process or accommodation. Penalties run $500 for the first violation and up to $1,500 for each subsequent violation within a six-month window per affected candidate.

No other state has copied Local Law 144's audit mandate verbatim. Colorado's AI Act, Illinois's AIVIA amendments, Connecticut's SB 2, and California's pending Civil Rights Council regulations instead emphasize impact assessments, disclosures to candidates, human review of adverse decisions, and general anti-discrimination obligations under existing civil rights statutes. This distinction matters enormously for compliance planning: an employer that satisfies NYC's audit requirement may still be non-compliant in Colorado if it fails to complete and document a risk-based impact assessment, while an employer fully compliant with Colorado's disclosure regime may still owe NYC an annual published audit report.

The practical takeaway is that bias audit obligations are location-triggered rather than tool-triggered. The same vendor algorithm may require an annual published audit for one office in Manhattan and only documented impact assessments and notices for offices in Denver, Hartford, or Chicago.

Why States Are Regulating Differently: Audits Versus Disclosure

The divergence among states reflects genuine disagreement about whether mandatory third-party audits actually reduce algorithmic discrimination. New York City's experience with Local Law 144 has been instructive and, by some accounts, disappointing. Enforcement data and reporting from outlets covering the law's first two years have highlighted low compliance rates among covered employers, ambiguity about what qualifies as an "independent" auditor, and questions about whether published audit summaries give candidates meaningful information. Critics argue the audit requirement created a cottage industry of checkbox reports without demonstrably changing hiring outcomes.

Colorado lawmakers drew a different conclusion. Rather than mandating audits, SB 24-205 requires developers and deployers of high-risk AI systems — explicitly including systems used for employment decisions — to exercise reasonable care to avoid algorithmic discrimination, conduct impact assessments, notify consumers when AI is used in consequential decisions, and allow appeals to human reviewers. Bloomberg Law and other legal press have characterized this as a deliberate turn toward transparency and duty-of-care standards over audit mandates. Connecticut followed a similar philosophy in its 2025 legislation, and Illinois's 2024 amendments to the AIVIA focused on disclosure and explanation rights rather than third-party testing.

This regulatory split creates real strategic questions for employers. An audit can serve as evidence of reasonable care under Colorado-style laws even where it is not strictly required, so many multi-state employers voluntarily adopt NYC-style audits as a defensive measure. But treating the audit as the whole compliance program is a mistake; disclosure timing, human-review mechanisms, and recordkeeping carry equal or greater weight in most new regimes.

State-by-State Comparison Table

FeatureNew York City (Local Law 144)Colorado (AI Act, SB 24-205)Illinois (AIVIA amendments)Connecticut (2025 AI law)
Audit required?Yes — annual independent bias auditNo formal audit; impact assessments requiredNo formal audit; notice and explanation dutiesImpact assessment orientation, not mandated audits
Effective dateJuly 5, 2023Phased implementation beginning Feb 1, 2026Jan 1, 2024 amendmentsPhased from mid-2026
ScopeAEDTs used for NYC employment decisionsHigh-risk AI systems incl. employmentAI video interviews for IL rolesAutomated employment decision tools
Candidate notice10 business days before use, with accommodation optionDisclosure that AI is used in consequential decisionsNotice before video interview; explanation of AI role within 30 days of requestAdvance disclosure of AI use
Publication dutyAudit summary posted publicly before useNone specific; documentation retainedNoneLimited
Human reviewAlternative process available on requestAppeal to human reviewer for adverse decisionsNot explicit; anti-discrimination duties applyHuman oversight expectations
Penalties$500 first violation; $500–$1,500 per subsequent violationAG enforcement; unfair trade practice penaltiesCivil penalties per violationState AG enforcement
Enforcement bodyNYC DCWP / MOCSColorado Attorney GeneralIllinois AG / IDOLConnecticut Attorney General
Employers should read this table as a floor, not a ceiling. California's Civil Rights Council has been developing regulations under FEHA addressing automated-decision systems, with proposed requirements around record retention, testing, and adverse-impact analysis expected to phase in during 2026–2027. Texas's TRAIGA, effective January 1, 2026, prohibits certain manipulative and discriminatory AI uses and imposes intent-based liability. Washington, New Jersey, and other legislatures have introduced bills in successive sessions, meaning the map will keep shifting through 2027.

How Bias Audits Actually Work Under Local Law 144

An employer subject to Local Law 144 must take four concrete actions. First, it must determine whether any tool it uses qualifies as an AEDT — defined as software that uses machine learning, statistical modeling, data analytics, or artificial intelligence to substantially assist or replace discretionary employment decisions such as screening, ranking, or recommending candidates. Second, it must engage an independent auditor. The law does not license auditors, but independence generally means the auditor did not develop the tool and does not control its deployment. Third, the audit itself must calculate selection rate differences and impact ratios by sex, race/ethnicity, and intersectional categories for each stage of the funnel the tool touches — for example, resume screening, skills assessment scoring, and final ranking. Under the EEOC's four-fifths rule, an impact ratio below 0.80 for any protected group typically flags adverse impact. Fourth, the employer must post the audit summary publicly before deploying the tool and keep records of the audit date, the tool's job classifications, and the underlying data.

Timing matters as much as content. The audit must be completed within the year preceding use of the tool, and the summary must be posted no later than 30 days after the audit concludes. Employers that deploy a new tool mid-year cannot wait until their next annual cycle; the publication obligation attaches immediately upon deployment. Vendors also bear obligations: they must make the data and documentation necessary for the audit available to customers within 30 days of a request, and vendors themselves must publish their own audit summaries if they market tools to NYC employers.

Practical Steps for Multi-State Compliance Programs

A defensible program starts with inventorying every algorithmic tool touching hiring decisions — applicant tracking system screeners, asynchronous video interview scorers, game-based assessments, chatbot pre-screeners, and resume parsers all potentially qualify. For each tool, document the jurisdictions where it operates, because that determines which regime applies. A tool used only for remote hires into Colorado triggers Colorado's impact-assessment and disclosure duties; the same tool used for a New York City office triggers the annual audit and posting requirement.

Next, sequence the work around the strictest applicable standard. Commissioning an NYC-compliant independent audit annually, even for tools not legally subject to it, generates the adverse-impact data needed for Colorado-style impact assessments and provides evidence of reasonable care everywhere else. Pair the audit with the operational controls most new laws demand: candidate notices drafted to satisfy both NYC's 10-business-day rule and Illinois's pre-interview notice, a documented human-review path for adverse decisions, an appeal process consistent with Colorado's requirements, and retention schedules aligned with California's proposed multi-year recordkeeping expectations.

Finally, assign ownership. Compliance failures under these laws rarely stem from ignorance of the statute; they stem from unclear internal accountability between HR, procurement, legal, and IT. Organizations using AI-powered labor-law compliance platforms typically centralize this mapping — tracking which tools touch which jurisdictions, automating notice delivery, and timestamping audit publications — precisely because manual spreadsheets break down once more than three or four states are involved. Whatever system you use, the output regulators will ask for is documentation: dated audits, posted summaries, delivered notices, and completed impact assessments.

Common Mistakes and Enforcement Gaps

The most frequent error is assuming vendor certification equals employer compliance. Even when a vendor publishes an audit summary, the NYC employer remains responsible for ensuring the audit covers its own use case, that the summary is posted on its own site, and that candidate notices go out on time. Relying on a vendor's marketing page as your publication vehicle does not satisfy the ordinance.

The second mistake is misjudging what counts as an AEDT. Employers often exempt chatbots or scheduling algorithms on the theory that they merely assist. Under Local Law 144, a tool that substantially assists a discretionary decision — for example, by automatically advancing only top-scored applicants to a recruiter — falls within scope. Conversely, some employers over-scope, spending audit budgets on simple keyword filters that arguably fall outside the definition. Getting the scoping analysis right, ideally with counsel, prevents both under- and over-spending.

Third, employers underestimate the enforcement gap problem. Reporting on Local Law 144's early years noted limited proactive enforcement and low observed compliance, and commentators have flagged similar gaps in Illinois's AIVIA regime. But gaps close. Private plaintiffs increasingly cite audit failures as evidence in disparate-impact litigation under Title VII and state fair-employment acts, meaning the practical exposure of skipping an audit exceeds the nominal municipal fine. Treating weak enforcement as permission to wait is the costliest error available.

Fourth, companies conflate bias audits with security or model-validation reviews. An information technology audit examines management controls over IT infrastructure; a bias audit measures differential selection rates across protected groups. They share nothing methodologically, and substituting one for the other leaves you exposed on both fronts.

Costs, Timelines, and When to Act

Independent bias audits under Local Law 144 typically range from roughly $10,000 to $50,000 per tool per year depending on the number of job categories, data volume, and auditor sophistication, with enterprise multi-tool engagements running higher. Impact assessments under Colorado-style regimes are usually less expensive because they can be performed internally or by counsel, though documenting them properly adds meaningful legal spend. Budgeting $25,000 to $100,000 annually for a mid-sized multi-state employer's full algorithmic-hiring compliance program — audits, assessments, notices, and platform support — is a realistic planning figure.

On timing, the calendar through 2026 is unforgiving. Colorado's AI Act obligations began phasing in February 2026, Connecticut's law phases in mid-2026, and California's ADS regulations are expected to finalize with compliance dates in late 2026 or 2027. Employers should treat Q3–Q4 2026 as the window to complete inventories, commission audits, and stand up notice workflows before the next wave of effective dates. Waiting until a regulator or plaintiff forces the issue converts a planned expense into an emergency with litigation attached.

The Bottom Line

Bias audit requirements by state in 2026 form a deliberately uneven patchwork: one hard audit mandate in New York City, duty-of-care and disclosure regimes in Colorado, Illinois, and Connecticut, and pending rulemaking in California and elsewhere. The rational response is not to chase each statute separately but to build one program calibrated to the strictest standard — annual independent audits, public summaries, timely candidate notices, documented impact assessments, and human review of adverse outcomes — then localize the details by jurisdiction. Employers who do this once, systematically, will absorb future legislative changes as configuration updates rather than crises.