Direct Answer: State AI Rules for Automated Hiring
State AI hiring laws are not one uniform national regime. As of September 26, 2026, employers must evaluate requirements based on where they recruit employees, where the candidate primarily works, how many people the business employs, and whether software is used to screen, rank, interview, select, or make employment decisions. New York City still audits qualifying automated employment decision tools, Illinois regulates the use of AI in certain employment decisions, and California treats the use of AI as a potentially prohibited employment practice. Texas’s responsible artificial intelligence governance statutes took effect January 1, 2026, while other states have enacted narrower notice, testing, disclosure, or discrimination rules.
Also worth reading: How Should Employers Test AI for Bias in HR by September 2026? · What does the EU AI Act classify as high-risk AI for HR and how should employers prepare by September 2026? · What are the current Colorado AI Act impact assessment requirements for employers as of September 2026?
There is no single state that regulates every private employer’s hiring AI. New Jersey’s Artificial Intelligence Tester Act, for example, applies to developers and deployers of certain automated employment decision tools and imposes testing and summary-reporting duties, rather than imposing one universal rule on every company nationwide. The same caution applies to Colorado: its Artificial Intelligence Act uses exemptions and scope thresholds, so employers should not assume that a commercial recruiting tool is regulated or exempt merely because the law is called a “high-risk AI” statute. Existing federal and state discrimination, consumer-report, privacy, records, and labor laws continue to operate alongside these newer provisions.
The safest practical position is to inventory recruiting technology by jurisdiction and function, identify decision points where automation can materially affect an applicant, and document the lawful basis for each use. Employer size, job location, tool function, and vendor role determine which statute and threshold apply. This answer is a compliance orientation, not a substitute for a jurisdiction-specific legal review, and statutes or effective dates should be checked against official sources before relying on a policy.
How State AI Hiring Requirements Differ
State rules generally target one or more of five areas: notice to candidates, testing for discriminatory bias, documentation of tool use, independent review or appeal, and vendor contracting. Notice-only rules impose fewer obligations than statutes that directly regulate decisions concerning access to employment. Testing rules may require statistical validation, expert assessment, or a test that predicts whether a tool will produce discriminatory results. These are separate duties, and satisfying a disclosure rule does not prove that a tool complies with anti-discrimination law.
Thresholds can refer to total employees, annual revenue, applicants processed, jobs filled, contractor or developer status, or the location of the employee. For example, New York City’s Local Law 144 applies to employers and employment agencies using covered automated tools for candidates or employees in the city when the tool is substantially used to assist or replace discretionary decisions. Its audit requirement is divided into an initial audit and a bias audit, while separate notices explain how the technology is used and what information the employer has about selection criteria. Neither test applies in exactly the same way to a company outside New York City.
Rules also differ according to what the system does. A tool that extracts skills from résumés may be treated differently from a system that ranks finalists, makes a hiring recommendation, determines compensation, schedules interviews, or selects employees for layoffs. Even vendors that merely make tools available may have reporting or testing responsibilities, but those duties should not be confused with the employer’s independent duty to monitor selection outcomes. The location of the candidate and the employer’s business size should therefore be treated as legal classification inputs, not administrative details.
| Compliance feature | New York City Local Law 144 | New Jersey AI Tester Act | Colorado AI Act | Federal and general state law |
|---|---|---|---|---|
| Main focus | Notice and independent bias audits | Testing and summaries for certain employment tools | Exemptions, governance, impact assessment, and high-risk AI duties | Discrimination, privacy, consumer reports, and emerging rules |
| Geographic scope | NYC employers, employment agencies, and covered uses | New Jersey businesses within statutory scope | Colorado systems within the Act’s definitions and exemptions | Varies by federal statute or state |
| Typical threshold or trigger | Substantial use for qualifying NYC employment decisions | Deployers and developers meeting statutory conditions | Developer, deployer, revenue, employee, and risk criteria can affect scope | Employer, record, transaction, or protected-activity criteria vary |
| Core duty | Bias audit plus candidate or employee notice | Testing, reporting, and summary disclosure | Documentation, risk controls, assessments, or consumer notice | Reasonable accommodation, data accuracy, validation, and lawful use |
| Employer implication | Review tool, notice, audit cadence, and vendor reports | Obtain testing results and ask vendors about role allocation | Map the system before labeling it in or out of scope | Continue discrimination and privacy reviews |
Illinois’ Artificial Intelligence in Employment Act, 820 ILCS 130, is a prominent employment-specific rule. Its reach is tied to the employer, the AI system, and covered employment decisions involving recruitment, hiring, promotion, renewal, selection for training, discharge, discipline, assignment, compensation, and other terms or conditions. The law contains a threshold concerning the number of employees in Illinois, while exceptions apply to certain medical or disability-related tools and other uses described in the statute. Because the statute has been amended and subject to litigation, an employer should confirm the operative text and any court orders before treating an older summary as current.
California’s existing employment discrimination framework remains important. The Fair Employment and Housing Act generally applies to employers with five or more employees and can cover discrimination based on enumerated characteristics, including race, sex, disability, religion, national origin, and other protected categories. A newer automated-decision-system rule extends California’s employment discrimination and retaliation framework to covered uses of an “employment technology system.” An employer should not publish a claim that “AI is unbiased” and treat it as a legal defense; automated scoring can still function as an adverse employment practice if it screens out protected groups or applicants.
New York City remains different from statewide New York law. Local Law 144 requires qualifying users to conduct and preserve a bias audit within a specified period, conduct a second audit on a later schedule, and provide notices. State and local discrimination statutes still apply in addition to the Local Law 144 duties, so a passing audit does not necessarily resolve a claim concerning accommodation, retaliation, privacy, or a failure to follow the employer’s own policy. The compliance objective is not merely a PDF report; it is a defensible system in which the employer understands the tool, receives usable vendor information, monitors outcomes, and provides a process for correction.
Colorado, Texas, Connecticut, and Other State Approaches
Colorado’s Artificial Intelligence Act, enacted in 2024, originally scheduled to take effect in 2026 after legislative changes to the original timeline. For September 2026, employers should use the current statutory dates and any final implementing rules rather than relying on the version proposed in 2024. The Act generally regulates developers and deployers of certain high-risk AI systems and includes exclusions, exemptions, and impact-assessment requirements. A hiring algorithm should not automatically be classified as high-risk solely because it is algorithmic; classification depends on the statute’s defined system, purpose, and deployment conditions.
Texas’s Responsible Artificial Intelligence Governance Act generally took effect January 1, 2026, according to the enacted text. It is intended to provide a consent-based approach involving governance, disclosure, data, and protections concerning government AI, while avoiding the broad decision-specific structure of some employment statutes. The key employer question is whether the Act reaches the particular system and the company’s proposed use, and whether a vendor’s public or contractual promise satisfies applicable notice and governance duties. A tool that ranks applicants should still be evaluated under ordinary Texas and federal discrimination law even if the AI Act itself does not impose a special employment test.
Connecticut’s 2025 employment AI law and other new state measures illustrate a narrower approach. The research context identifies restrictions on certain employer AI uses and notice for AI-related reductions in force, but the effective dates, covered employers, and interaction with federal employment statutes require careful current-law review. Similar developments in New Jersey, Maryland, and other jurisdictions can be summarized in secondary compliance articles, but official legislation and regulations should control. As a result, a national HR policy may need several state addenda rather than one universal AI clause.
What Employers Must Do to Comply
The first step is to create a complete inventory of AI used in recruiting and workforce decisions. This includes résumé parsing, job advertising, candidate search, interview scheduling, transcript generation, scoring, ranking, background screening, onboarding, promotion, performance management, compensation, discipline, and reductions in force. For each system, record the vendor, model or version where available, purpose, data categories used, decision points, human reviewers, candidate location, employee location, vendor role, and the applicable law. Systems bought through a staffing agency or third-party platform should be included, as should tools that employees believe are automated even if no model name is visible.
The second step is to separate assistance from decision-making. A tool that schedules an interview after a recruiter selects finalists is not necessarily the same as a system that rejects applicants automatically. The employer should document who can override the output, how overrides are recorded, and whether the business treats the result as a recommendation or a final decision. This distinction is not a safe harbor; it can clarify which controls and laws apply, but the tool’s practical influence still matters. An employer that asks a system for a “recommendation” but ignores every output may need to explain why the technology was used at all.
The third step is to conduct a job-relatedness and anti-discrimination review. The employer should compare selection rates, pass rates, error patterns, accommodation requests, and outcomes across lawful audit groups, while considering whether any disparity reflects job-related factors rather than protected status. Data should be sufficiently complete to support analysis, but collection should be limited to what is needed for a lawful purpose. Where a statute requires an expert test, a formal evaluation, or a specified report, a vendor’s generic marketing claim that it is “fair,” “inclusive,” or “compliant” is not a substitute for the required record.
Vendor Review, Documentation, and Human Review
Vendor review should be a documented procurement process rather than a post-purchase questionnaire. Contracts should identify the intended use, prohibit uses that the vendor does not support, allocate testing and reporting responsibilities, and require information about data sources, model changes, known limitations, security, retention, subcontractors, and deletion. Illinois, New Jersey, and other regimes may place duties on a deployer even when a vendor performs the testing, so the employer should determine which obligations cannot be transferred. A contract that promises a report but does not provide raw aggregate data needed to evaluate outcomes is often operationally weak.
Human review is valuable only when it is meaningful. A recruiter should know the tool’s purpose, see the relevant evidence, have authority to disregard the result, and receive enough time and guidance to exercise independent judgment. “Human in the loop” language should not be used to describe a rubber-stamp process in which reviewers receive no training, cannot access applicant data, or are measured by their agreement rate with the system. Documentation should record the review stage, the reason for overriding the model, and the corrective action taken when the output appears inaccurate.
An employer should also create a candidate-facing notice process. Notices should identify the use of automation where required, explain the principal decision purposes, describe selection criteria or job-related information in accessible language, and provide a contact method for questions or accommodation requests. A notice should not overstate the employer’s ability to explain a complex model or imply that the system makes a decision when a person actually does. The wording should be tested by jurisdiction because “use of AI,” “automated employment decision tool,” and “employment technology system” can have different statutory meanings.
Common Mistakes and When to Act
A frequent mistake is assuming that a vendor is responsible for all legal exposure. Vendors may provide testing or compliance reports, but employers remain responsible for deciding whether to use a system, whether the advertised use is accurate, and whether employment outcomes are lawful. Another mistake is treating a bias audit as a one-time purchase. Tools, training data, job duties, recruiting channels, and workforce demographics can change, and statutory rules may require a first audit and a later audit rather than a single certificate. Storing a report without knowing the tool version, date, scope, and auditor assumptions is also inadequate.
Employers often fail by ignoring applicants or employees outside the headquarters state. Rules can be triggered by the job’s location, the candidate’s location, the location of the hiring activity, or the location of the business, depending on the statute. A recruiter sitting in Illinois who processes applications for New York City positions may therefore require more than a general California notice. Contractors and staffing agencies create another boundary: a client can direct decisions, while a platform supplies the algorithm or the interface, and both sides may have duties.
Employers should act before expanding a high-risk use, changing the tool’s purpose, or launching a new recruiting campaign. A company should also act when it receives a complaint, accommodation request, regulator inquiry, or evidence of a persistent selection disparity. A prompt review can identify a notice problem, incorrect job criteria, inaccessible accommodation channel, or inaccurate vendor statement. Waiting for a lawsuit may increase exposure and does not automatically correct an underlying control failure.
Cost, Deadlines, and Building a Sustainable Program
There is generally no universal filing fee or government charge for complying with a state AI hiring law, but compliance costs are real. External bias audits, independent testing, legal review, model documentation, accessibility review, and vendor contract changes can range from thousands to tens of thousands of dollars per system or jurisdiction, with larger costs possible for enterprise-scale deployment. The number of systems and locations matters more than the purchase price of the AI product. A low-cost ranking tool can create a high-cost problem if it processes thousands of applicants and cannot explain or validate its selection criteria.
Time requirements vary. New York City’s Local Law 144 has historically required an initial bias audit no earlier than one year after the law’s effective date and a second audit no earlier than one year after the first, subject to current statutory and regulatory text. New Jersey rules may require testing and a summary before or during deployment depending on the covered actor and system. Colorado deadlines depend on statutory scope, exemptions, implementing rules, and the current effective date. Employers should therefore track exact dates in a compliance calendar rather than assume that all obligations begin simultaneously on January 1 or February 1.
A defensible program is sustainable when it is tied to ordinary employment operations. The employer can assign ownership to HR, legal, privacy, security, procurement, and accessibility personnel, while requiring engineering or vendor teams to maintain technical evidence. Review frequency should reflect the tool’s purpose, rate of change, available outcome data, and applicable law. The final product is not a single “AI certificate”; it is a documented chain of decisions showing why the tool was selected, how it was tested, what candidates were told, how humans reviewed results, and what happened when the system failed.
Overall, the central answer is that employers need a state-by-state system, not a nationwide assumption that AI hiring is unregulated or automatically prohibited. Start with New York City, Illinois, California, New Jersey, Colorado, Texas, and any state where the employer recruits or employs workers, then verify the current statute, thresholds, dates, and amendments. AI-powered labor law compliance software can organize inventories, notices, audit records, and deadlines, but it cannot determine legal scope or make an employer’s selection practices lawful by itself. A careful human decision-maker remains necessary even where the statute imposes no formal human-review requirement.