Nearly half of US organizations, 43% according to SHRM’s 2025 Talent Trends survey of 2,040 HR professionals, now use AI somewhere in their HR function, up from 26% a year earlier. A meaningful share of that AI sits inside hiring: resume screeners, chatbot interviewers, and scoring algorithms that decide who advances. In New York City, using one of those tools without a current bias audit is not a gray area. It is a violation of Local Law 144, and as of late 2025, the city is under formal pressure to start enforcing it like one.
What Counts as an AEDT Under Local Law 144
Local Law 144 does not regulate AI in hiring as a broad category. It regulates a specific, narrower thing: an automated employment decision tool, or AEDT, defined by the NYC Department of Consumer and Worker Protection (DCWP) as a computational process, derived from machine learning, statistical modeling, data analytics, or AI, that issues a simplified output such as a score, classification, or recommendation used to substantially assist or replace discretionary decision making in hiring or promotion.
The phrase substantially assist or replace does the real work in that definition. A tool crosses the line if it is the sole factor in a decision, a weighted factor alongside human judgment, or capable of overriding a human recommendation. A basic applicant tracking system that just stores resumes and lets a recruiter search keywords generally falls outside the definition. A tool that scores candidates and auto advances the top quartile, or that a recruiter is instructed to defer to, falls squarely inside it.
Translation and transcription tools are explicitly carved out, since they do not generate a decision output. Everything else that scores, ranks, classifies, or filters candidates or employees, including resume parsers with weighted scoring, video interview analysis, chatbot pre-screeners, and predictive attrition models used in promotion decisions, is fair game for scrutiny.
The Three Core Obligations: Bias Audit, Public Disclosure, Candidate Notice
Local Law 144 is built around three separate obligations, and employers commonly satisfy one or two while missing the third entirely.
- Independent bias audit. An independent auditor, someone with no financial or employment relationship to the employer or the AEDT vendor that would compromise their objectivity, must test the tool for disparate impact on sex, race, and ethnicity categories, including intersectional categories such as Black women or Asian men, within one year prior to its use. The audit repeats annually.
- Public disclosure. A summary of the most recent bias audit, including the audit date, the tool’s distribution date, and a description of the source data, must be posted clearly and conspicuously on the employment section of the employer’s or employment agency’s website.
- Candidate notice. Candidates and employees who reside in New York City must receive notice at least 10 business days before an AEDT is used to evaluate them. The notice must identify what the tool assesses and inform them of their right to request an alternative selection process or a reasonable accommodation.
| What most compliance teams get wrong: Teams frequently treat the bias audit as the whole law and stop there. DCWP’s own enforcement reviews, discussed below, found that public disclosure and candidate notice are where gaps most often surface, not the audit itself. |
How the Bias Audit Works: Selection Rates, Impact Ratios, and the Four-Fifths Rule
The audit itself is a statistical test, not a document review. For AEDTs that produce pass or fail outcomes, the auditor calculates a selection rate for each demographic category by dividing the number of candidates selected from that group by the total number of candidates in that group. For tools that produce continuous scores, the auditor instead calculates a scoring rate, typically the proportion of each group that scores above the median.
The auditor then compares every group’s rate to the rate of the group with the highest rate, producing an impact ratio. This methodology traces directly back to the EEOC’s Uniform Guidelines on Employee Selection Procedures, codified at 29 CFR Part 1607, which has governed adverse impact analysis under Title VII since 1978. Under the four-fifths rule embedded in those guidelines, an impact ratio below 80% is treated as evidence of potential adverse impact.
A simple example makes the arithmetic concrete. If an AEDT selects 60% of male candidates and 40% of female candidates, the impact ratio for women is 40 divided by 60, or 67%. That falls below the 80% threshold and would be flagged in the bias audit summary, triggering closer review of the tool’s inputs and validation, even though nothing in Local Law 144 itself bans the tool outright. The law requires disclosure and audit, not automatic prohibition.
Where individuals cannot be classified into a demographic category from available data, the auditor must report the count of unknown category individuals separately rather than silently excluding them, since excluding them tends to understate adverse impact for smaller groups.
Completing a bias audit is only one part of compliance. Organizations should also understand the broader AI hiring tools compliance requirements for documentation, governance, and audit evidence.
| Govern365.ai in practice: This is exactly the kind of calculation that benefits from being run continuously rather than once a year. Govern365.ai’s risk assessment module recalculates selection and scoring rate impact ratios each time new hiring data flows in, so a drift toward adverse impact surfaces months before the annual audit, not after. |
Why 2026 Enforcement Looks Different: Inside the Comptroller’s Findings
For its first two years, Local Law 144 was a law with real requirements and, in practice, thin enforcement. That changed with a New York State Comptroller audit published December 2, 2025, which reviewed DCWP’s enforcement of the law from July 2023 through June 2025 and found it, in the Comptroller’s own language, ineffective.
The specifics are unflattering. DCWP surveyed the websites and bias audits of 32 companies and identified a single instance of non-compliance. Comptroller auditors reviewed the same 32 companies using the enforcement procedures DCWP was supposed to be using and found at least 17 potential violations. Separately, the audit found that a large share of test calls placed to the city’s 311 hotline about AEDT issues never made it to DCWP at all, and that DCWP received only two formal complaints during the entire two year window it examined.
DCWP has agreed to adopt most of the Comptroller’s recommendations: better complaint routing, staff cross trained on AEDT review, use of the technical evaluation resources available through the NYC Office of Technology and Innovation, and a shift away from purely complaint driven enforcement toward proactive review. Employment law firms tracking the law, including DLA Piper, are advising clients to expect a materially stricter enforcement posture through 2026.
The practical implication is that the relevant risk is no longer only whether your bias audit exists. It is whether it would survive a DCWP review that is finally checking the enforcement workbook it was supposed to be using since 2023.
Who Has to Comply, Including Remote Roles and Vendors
Local Law 144 follows the candidate, not the employer’s address. If a candidate or employee resides in any of the five boroughs, the law applies to that individual’s evaluation regardless of where the hiring company is headquartered, where the role is physically performed, or whether the position is fully remote. A company based in Austin hiring a remote engineer who lives in Queens is squarely inside the law’s scope for that hire.
The legal obligation sits with the employer or employment agency, not the AEDT vendor. A vendor’s marketing claim that its tool is Local Law 144 compliant does not transfer legal responsibility, and employers who rely on that claim without their own audit and disclosure remain exposed. That said, vendors increasingly find that a documented, third party bias audit is now a procurement requirement rather than a nice to have, since enterprise buyers are asking for it before signing.
Local Law 144, ISO/IEC 42001 and the EU AI Act: One Compliance Program, Not Three
Local Law 144 is narrow by design. It covers one jurisdiction and one use case: employment decisions. Organizations operating across US states and internationally are almost never managing Local Law 144 in isolation. They are also tracking ISO/IEC 42001, the international AI management system standard, and the EU AI Act’s high risk system obligations, which cover employment AI as an explicitly named high risk category under Annex III.
The three regimes ask different questions in different vocabularies, but they overlap more than most compliance calendars reflect. LL144’s bias audit maps closely to the bias and fairness testing expected under ISO 42001’s risk assessment and performance evaluation clauses [VERIFY], and to the data governance and human oversight requirements the EU AI Act sets for high risk systems. Building one clause level mapping, instead of three separate audit trails, is the difference between compliance work that compounds and compliance work that gets redone every time a new regulator asks a slightly different question.
Cross-framework mapping: employment AI bias and fairness obligations
| Obligation | NYC Local Law 144 | ISO/IEC 42001:2023 | EU AI Act (high risk AEDT) |
|---|---|---|---|
| Independent testing for discriminatory outcomes | Annual bias audit by an independent auditor | Risk assessment and monitoring controls under Clause 6 and Annex A [VERIFY] | Bias monitoring under Article 10 data governance and Article 15 accuracy requirements |
| Public transparency | Bias audit summary posted on employer website | Documented AI management system reporting to stakeholders | Technical documentation and instructions for deployers under Article 13 |
| Individual notice and recourse | 10 day candidate notice plus opt-out to an alternative process | Stakeholder communication controls under Annex A [VERIFY] | Human oversight and the right to explanation under Article 14 and Article 86 |
| Ongoing review cadence | Annual re-audit before continued use | Continual improvement cycle, typically annual management review | Post-market monitoring for the system’s operational lifetime |
| Govern365.ai in practice: Govern365.ai’s compliance dashboard is built around exactly this overlap. An AI hiring tool logged once in the AI model registry can be mapped simultaneously to its Local Law 144 audit cycle, its ISO 42001 Annex A controls, and its EU AI Act risk classification, so one annual bias audit produces evidence that satisfies more than one regulator. |
Many employers also use the NIST AI RMF implementation framework to strengthen AI inventories, risk assessments, and continuous monitoring beyond Local Law 144 requirements.
Building an Audit-Ready AEDT Compliance Program
The gap between having a bias audit and having a defensible compliance program is usually process, not paperwork. The steps below reflect what a program needs to withstand the kind of review the Comptroller’s office just recommended DCWP start running.
- Inventory every hiring and promotion tool that scores, ranks, or classifies candidates, including features embedded inside a larger HRIS or ATS. (Owner: GRC / AI governance team)
- Determine which tools meet the AEDT definition by testing whether the tool substantially assists or can override human discretion. (Owner: Governance professional, with legal review)
- Engage an independent auditor with no financial or employment relationship to the vendor or employer, and confirm their methodology covers intersectional categories. (Owner: Procurement / GRC team)
- Run the bias audit within 12 months of the tool’s next use and retain the underlying data and calculations, not just the summary. (Owner: Independent auditor, evidence retained by GRC team)
- Publish the audit summary, including audit date, distribution date, and source data description, in a clearly labeled section of the public careers site. (Owner: HR / Marketing, reviewed by legal)
- Build a 10 business day notice workflow into the ATS so every NYC resident candidate receives notice before AEDT evaluation, with a working opt-out path. (Owner: HR technology / Talent acquisition)
- Log the tool, its audit history, and its notice workflow in a central AI system inventory that maps to ISO 42001 and EU AI Act obligations if applicable. (Owner: AI governance lead)
- Re-run the audit annually and after any material change to the model, training data, or scoring logic, not just on the calendar anniversary. (Owner: AI governance lead / Independent auditor)
Penalty Exposure and Common Compliance Gaps
DCWP can impose a civil penalty of $500 for a first violation, plus $500 for each additional violation on the same day as the first, and between $500 and $1,500 for each subsequent violation. Each day a non-compliant AEDT remains in use is treated as a separate violation, and each missing notice or missing disclosure can independently count as its own violation.
Run the arithmetic on a single non-compliant tool used continuously for 30 days without a valid audit, and the exposure lands between roughly $15,000 and $45,000 for that one tool in that one month [VERIFY], before accounting for separate notice and disclosure violations layered on top. High volume employers running an AEDT across thousands of applications carry meaningfully higher exposure than the headline per violation figures suggest.
The most common gaps are rarely the audit itself. They are a bias audit summary that exists but is buried outside the careers section where DCWP’s own reviewers would not clearly and conspicuously find it, a candidate notice process that was designed for the launch of a tool but never updated when the tool was replaced, and an inventory that misses AEDT functionality embedded inside a broader HR platform the compliance team never flagged as in scope.
Frequently Asked Questions
Does Local Law 144 apply to companies not headquartered in New York City?
Yes. The law applies based on where the candidate or employee resides, not where the employer is headquartered or where the role is performed. If a candidate lives in any of the five boroughs, evaluating them with an AEDT triggers Local Law 144, even for a fully remote role tied to an out of state company.
What is the difference between a bias audit and a normal vendor security review?
A bias audit is a statistical test for disparate impact on protected categories, run by an independent third party under Local Law 144’s specific methodology. A vendor security review typically evaluates data protection and system reliability, and does not satisfy the bias audit requirement even if it is thorough.
Can the AEDT vendor perform the required bias audit?
No. DCWP’s rules require an independent auditor with no financial or employment relationship to the vendor or employer that would compromise objectivity. A vendor can support data collection for the audit, but it cannot serve as the auditor of its own tool.
What happens if a bias audit reveals an impact ratio below 80%?
Local Law 144 does not prohibit using the tool outright. It requires the finding to be disclosed in the public audit summary. In practice, a sub 80% impact ratio should trigger a closer look at the tool’s training data, scoring logic, and validation before continued use, given the discrimination liability under Title VII and New York City and State human rights law.
How does Local Law 144 relate to the EU AI Act’s high risk AI system rules?
Both regulate employment AI, but Local Law 144 is narrower and procedural, requiring an annual audit and disclosure. The EU AI Act treats employment AEDTs as a named high risk category under Annex III and layers on broader obligations, including technical documentation, human oversight, and post market monitoring, for any organization deploying such tools to evaluate candidates in the EU.
Is a chatbot used for initial candidate screening covered by Local Law 144?
It depends on what the chatbot does with the interaction. If it only schedules interviews or answers FAQs, it likely falls outside the AEDT definition. If it scores responses, ranks candidates, or its output substantially assists or replaces a human’s decision to advance or reject a candidate, it meets the definition and requires a bias audit.
How often does the bias audit need to be repeated?
At least once every 12 months, and the audit must be completed within a year prior to the tool’s use. Best practice is to re-run the audit sooner if the model, its training data, or its scoring logic changes materially, rather than waiting for the calendar anniversary.
Who enforces Local Law 144 and how are complaints filed?
The NYC Department of Consumer and Worker Protection enforces the law. Complaints can be filed online without creating an account, though a December 2025 state audit found the complaint intake process itself, including 311 call routing, has significant gaps that DCWP has committed to fixing in 2026.
Conclusion
The mechanics of Local Law 144 have not changed since 2023. What has changed is the odds that a gap between your posted bias audit and your actual compliance file gets noticed. A regulator that just had its own enforcement record publicly graded ineffective has every institutional incentive to demonstrate otherwise in 2026.
Start with the inventory. Most organizations discover their real exposure is not the flagship applicant tracking system but a scoring feature buried inside a platform nobody flagged as an AEDT.
Govern365.ai maps every AEDT in your inventory to its Local Law 144 audit cycle alongside ISO 42001 and EU AI Act obligations in one place. Start your 14 day free trial to see your current audit and notice gaps mapped in minutes.
