A bias audit on a hiring model returns an impact ratio of 0.61. What happens next depends entirely on where you are, and the answers run in opposite directions.
The most surprising answer belongs to a state whose law never mentions a bias audit. Texas Business and Commerce Code section 552.105(e):
A defendant in an action under this section may not be found liable if: (1) another person uses the artificial intelligence system affiliated with the defendant in a manner prohibited by this chapter; or (2) the defendant discovers a violation of this chapter through: (A) feedback from a developer, deployer, or other person who believes a violation has occurred; (B) testing, including adversarial testing or red-team testing; (C) following guidelines set by applicable state agencies; or (D) if the defendant substantially complies with the most recent version of the “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile” published by the National Institute of Standards and Technology or another nationally or internationally recognized risk management framework for artificial intelligence systems, an internal review process.
The phrase “bias audit” does not appear anywhere in chapter 552, and no testing of any kind is required. Finding your own violation through testing nonetheless bars liability outright. Section 552.105(c) adds a rebuttable presumption that the person used reasonable care.
Nine hundred miles north, the same bias audit finding is the violation itself.
Six regimes, six consequences. What follows sorts them by how much protection the act of testing buys you, from complete immunity down to self-incrimination. Every position is quoted from the instrument, because this is the question buyers of bias audits most often ask and the one published guidance most consistently avoids.
| Jurisdiction | Effect of discovering disparity through testing |
| Texas | Bars liability under chapter 552 |
| Connecticut, California | Your response to the finding becomes evidence, in either direction |
| European Union | Creates a duty to mitigate what you found |
| New York City | Publish it and you have complied. The publication is admissible elsewhere |
| Illinois | The disparity is the violation |
| Federal, Title VII | Not testing permits an inference against you |
Texas rewards self-discovery and forecloses the statistic that produces it
A bias audit in Texas sits inside a design that shows itself only when section 552.105(e)(2) is read beside the substantive prohibition. Section 552.056:
(b) A person may not develop or deploy an artificial intelligence system with the intent to unlawfully discriminate against a protected class in violation of state or federal law. (c) For purposes of this section, a disparate impact is not sufficient by itself to demonstrate an intent to discriminate.
A bias audit in Texas therefore does two things at once. Disparate impact, the number a bias audit produces, cannot by itself establish the violation. And testing that uncovers a violation bars liability for it. A bias audit in Texas is worthless as proof against you and valuable as protection for you, which is an unusual combination and a strong argument for running one in a state that requires nothing.
Penalties sharpen the incentive to run a bias audit. Section 552.105(a) sets 10,000 to 12,000 dollars for a curable violation, 80,000 to 200,000 for an uncurable one, and 2,000 to 40,000 for each day a violation continues. Section 552.104 bars the Attorney General from acting before the sixtieth day after a notice of violation, and bars action entirely where the recipient cures and certifies the cure within that window. Section 552.105(f) removes penalties for a system that has not been deployed.
Chapter 552 took effect on 1 January 2026, and its bias audit incentive applies to any person developing or deploying an AI system in the state, not to employers alone.
Connecticut and California make your response to the finding the evidence
Bias audits land in the same legal position in two states that converge on identical wording, and the shared sentence does more work than either statute’s headline.
California’s Civil Rights Council regulations on automated decision systems took effect on 1 October 2025, adding 2 CCR section 11008.1 and amending twenty other sections of the employment regulations. The word “audit” appears zero times across the whole package. The operative sentence, at section 11009(f) and repeated verbatim in seven further sections so that it reaches every protected characteristic, is this:
Relevant to any such claim or available defense is evidence, or the lack of evidence, of anti-bias testing or similar proactive efforts to avoid unlawful discrimination, including the quality, efficacy, recency, and scope of such effort, the results of such testing or other effort, and the response to the results.
Connecticut copied the sentence into a statute that never uses the words bias audit. Public Act 26-15, signed in June 2026, contains no instance of the phrase “bias audit” and instead provides that a commission or court “may consider evidence of anti-bias testing or similar proactive efforts to avoid the discriminatory practice, including, but not limited to, the quality, efficacy, recency and scope of such testing or efforts, the results of such testing or efforts and the response thereto.”
Six things about a bias audit are made relevant, and only the first four describe the test itself. The results and the response to the results describe what you did afterwards. An employer whose bias audit returned 0.61 and who then changed nothing has manufactured a documented record of knowledge with no remediation attached to it. Such a position is worse than never having tested, and both regulations say so in terms.
Connecticut then adds a bias audit provision with no American precedent. In the same subdivision:
the use of an automated employment-related decision technology … shall not be a defense against a complaint
Blaming the tool is foreclosed by statute, whatever the bias audit said. Connecticut also requires state agencies to complete an AI impact assessment and post it on the agency website “not later than sixty days prior to deployment”, which makes it the second published assessment duty in the United States, though it reaches only the public sector.
California retention moved from two years to four in the same package. Section 11013(c) now lists “automated-decision system data” among the records preserved, and section 11008.1(d) defines that term to include data used to develop or customise a system for a particular employer. A four-year retention rule applied to test outputs means your 0.61 survives four years of litigation exposure whether or not anyone asks for it.
The European Union converts a finding into a duty to fix
Annex III point 4 of Regulation (EU) 2024/1689 makes recruitment, selection, application filtering, candidate evaluation, promotion, termination, task allocation and performance monitoring high-risk. Article 10(2) then requires data governance practices covering, at point (f), “examination in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law”, and at point (g), “appropriate measures to detect, prevent and mitigate possible biases identified according to point (f)”.
Detect, prevent, mitigate. Nowhere else in this survey does a bias audit finding create an obligation to do something about it.
Application begins on 2 December 2027. Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026 and moved Annex III high-risk systems to that date, with Annex I product-embedded systems moving to 2 August 2028. The Commission’s original proposal made the delay conditional on harmonised standards being available, and the adopted text substitutes fixed calendar dates.
Article 27 does not reach a private employer running a hiring tool
Bias audit marketing routinely tells private employers that an Annex III hiring system obliges them to perform a fundamental rights impact assessment. The exclusion is on the face of Article 27(1):
Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights
Three categories carry that duty: bodies governed by public law, private entities providing public services, and deployers of creditworthiness and life or health insurance pricing systems at Annex III points 5(b) and 5(c). A private company hiring for itself sits in none of them. What it does owe is Article 26, and Article 26(7) requires a deployer that is an employer to inform both workers’ representatives and the affected workers before putting a high-risk system into service at the workplace.
New York City makes publication the compliance act and the disclosure
Bias audit, as a defined legal term, exists in exactly one instrument in force in the United States. New York City Administrative Code section 20-870:
“Bias audit” means an impartial evaluation by an independent auditor. Such bias audit shall include but not be limited to the testing of an automated employment decision tool to assess the tool’s disparate impact on persons of any component 1 category required to be reported by employers pursuant to subsection (c) of section 2000e-8 of title 42 of the United States code as specified in part 1602.7 of title 29 of the code of federal regulations.
Section 20-871(a) attaches two conditions:
In the city, it shall be unlawful for an employer or an employment agency to use an automated employment decision tool to screen a candidate or employee for an employment decision unless: 1. Such tool has been the subject of a bias audit conducted no more than one year prior to the use of such tool; and 2. A summary of the results of the most recent bias audit of such tool as well as the distribution date of the tool to which such audit applies has been made publicly available on the website of the employer or employment agency prior to the use of such tool.
What the bias audit must contain. 6 RCNY section 5-301(b) requires selection rates and impact ratios for each category, calculated separately for sex categories, for race and ethnicity categories, and for intersectional categories of sex, ethnicity and race, with the number of individuals excluded because they fall in an unknown category stated. Section 5-300 defines the arithmetic: selection rate is the rate at which individuals in a category are selected to move forward or assigned a classification; scoring rate is the rate at which they score above the sample median; impact ratio is a category’s rate divided by the rate of the most selected or highest scoring category.
Who may run the bias audit. Section 5-300 defines an independent auditor entirely by disqualifying conflicts: involvement in using, developing or distributing the tool, an employment relationship with the employer, employment agency or vendor during the audit, or a direct or material indirect financial interest in any of them. No licence, accreditation or register exists anywhere.
What data. Section 5-302 requires historical data of the tool, poolable across employers using it, with test data permitted only where historical data is insufficient for a statistically significant audit, in which case the summary must explain why and describe how the test data was generated.
Clocks. Section 5-301(a) prohibits use where more than a year has passed since the most recent audit. Section 5-303(c) keeps the published summary up “for at least 6 months after its latest use of the AEDT for an employment decision.” Section 20-871(b) requires notice to city residents no less than ten business days before use, with data source and retention information supplied within thirty days of a written request. Section 5-304(a) adds that nothing in the subchapter requires an employer to provide an alternative selection process.
Penalties. Section 20-872 sets not more than 500 dollars for a first violation and each additional violation the same day, and 500 to 1,500 dollars for each subsequent violation, with each day of use a separate violation and each notice failure a separate violation again.
Publishing 0.61 discharges the duty and creates the exhibit
A bias audit under Local Law 144 obliges you to publish and nothing further, and New York State Comptroller report 2024-N-6 states the point without qualification:
LL144 does not require employers to take specific action if they find an AEDT tool has produced biased or discriminatory outcomes.
So the answer in New York City is that a 0.61 impact ratio, published, is full compliance with Local Law 144. The exposure moves rather than disappearing. City Human Rights Law and Title VII claims remain available, and a plaintiff now has a dated admission on the employer’s own website, published by the employer, calculated by an auditor the employer selected. Buyers of bias audits are rarely told that the deliverable is discoverable by design.
Illinois makes the finding the violation
Public Act 103-0804, signed 9 August 2024 and effective 1 January 2026, added subsection (L) to section 2-102 of the Illinois Human Rights Act:
for an employer to use artificial intelligence that has the effect of subjecting employees to discrimination on the basis of protected classes under this Article or to use zip codes as a proxy for protected classes under this Article
Has the effect of. An effects standard in the statute itself, with no intent element and no audit requirement, plus a flat prohibition on zip codes as a proxy that carries no effects qualifier at all. Paragraph (2) adds a notice duty and directs the Department of Human Rights to make rules on its circumstances, timing and means. The rules were proposed in May 2026 and withdrawn in June 2026 pending collaboration with other state agencies, so the notice obligation has been in force since January with nothing specifying how to discharge it.
Remedies for a bias audit finding run through the ordinary Human Rights Act machinery. Section 8A-104(K) permits a civil penalty “not exceeding” 16,000 dollars where no prior violation has been adjudged, 42,500 dollars with one prior violation in the preceding five years, and 70,000 dollars with two or more in the seven-year period ending on the date the charge was filed. Caps rather than tariffs, and the lookback runs to the filing of the charge.
Set Illinois beside Texas, since both took effect on 1 January 2026 and a national employer runs one bias audit for both. In Texas, discovering the disparity through testing bars liability. In Illinois, the disparity is the liability.
Federal law penalises not looking, without requiring you to look
Title VII obliges no employer to run a bias audit, to test, to validate or to publish anything. Validation under the Uniform Guidelines is a defence available once adverse impact has been shown, not a condition of lawful use.
Bias audit arithmetic nonetheless has a federal ancestor. The Uniform Guidelines on Employee Selection Procedures at 29 CFR Part 1607, unamended since 1981 and interpretive rather than legislative, use advisory language throughout. Section 1607.4(A): each user “should maintain and have available for inspection records or other information which will disclose the impact which its tests and other selection procedures have upon employment opportunities of persons by identifiable race, sex, or ethnic group”. Should, not shall.
Section 1607.4(D) states the four-fifths rule in terms routinely misquoted as a legal threshold:
A selection rate for any race, sex, or ethnic group which is less than four-fifths (4/5) (or eighty percent) of the rate for the group with the highest rate will generally be regarded by the Federal enforcement agencies as evidence of adverse impact
Generally regarded by the federal enforcement agencies as evidence. Not a violation at 0.79, not a safe harbour at 0.81. The paragraph continues that smaller differences may still constitute adverse impact where statistically and practically significant, and that larger differences may not where numbers are small. Its closing sentence is the federal answer to an employer who declines to measure: where impact data has not been maintained, the agencies “may draw an inference of adverse impact” from that failure, where the group is underutilised relative to the relevant labour market.
Federal guidance on how a bias audit applies to AI is no longer published. Checked by request on 16 September 2026, eeoc.gov/ai returns 404, and the URL for the 2023 technical assistance on assessing adverse impact in software, algorithms and artificial intelligence redirects to a page that also returns 404. The 2022 resource on AI and the Americans with Disabilities Act still resolves. No formal rescission notice accompanied the removals, which is why the accurate description is that the documents were taken down rather than withdrawn.
What the enforcement record says about all of this
Bias audit obligations reveal nothing about how hard anyone is looking. Only New York City has published an audit of its own enforcement, and the findings deserve more weight than any vendor risk estimate.
Comptroller report 2024-N-6 was issued on 2 December 2025. Its audit period ran from July 2023 to June 2025. Over those two years the Department of Consumer and Worker Protection received two complaints about automated employment decision tools. The auditors tested why, placing twelve calls to 311 in August and September 2024: representatives connected them to DCWP three times, and in one call the representative said they did not have DCWP’s direct number. Neither complaint portal carries an AEDT category, and DCWP told the auditors it had not added one because it did not see enough need to justify diverting information technology resources.
Proactive bias audit review was thinner still. DCWP reviewed the websites and bias audits of 32 companies, and the sample came from publications by Cornell University and the American Civil Liberties Union. The report:
DCWP surveyed websites and bias audits of 32 companies and identified just a single issue of non-compliance. However, DCWP’s review did not use the formal procedures created by OTI, as part of DCWP’s MOU, nor did it address all requirements of LL144. We reviewed the same companies and identified at least 17 instances of potential non-compliance under LL144.
Two demand letters followed the bias audit review. One recipient’s posted audit had expired three days before DCWP made contact, which DCWP did not notice, and the report records that “DCWP officials stated they do not have a process for monitoring the dates of bias audits.” No civil penalty for an AEDT violation is publicly reported anywhere, in the audit or since.
Measurement of bias audit publication reached the same place from the other direction. Wright and colleagues, at the 2024 ACM Conference on Fairness, Accountability and Transparency, put 155 student investigators to work recording what 391 employers had published: eighteen had posted audit reports, thirteen had posted transparency notices. The authors decline to call that a non-compliance rate, and the refusal is the paper’s thesis. Because each employer decides for itself whether its tool is in scope, an empty website is consistent with compliance. The authors named the condition null compliance.
Discovery reaches your test results before any regulator does
Bias audit results reach a courtroom through discovery long before they reach a regulator, and one 2026 development makes the point.
Mobley v. Workday, in the Northern District of California, survived dismissal in July 2024 on the theory that a software vendor can be liable as an agent of the employers using it under Title VII, the ADEA and the ADA. A nationwide ADEA collective was preliminarily certified in May 2025 and expanded in July 2025 to applicants screened through HiredScore features. Court-approved notice went out and the opt-in period opened in January 2026, closing on 7 March 2026.
Then, on 13 July 2026, the court extended the class certification deadlines by two months because Workday had produced three internal bias evaluation reports late, after a data scientist’s deposition and two days before the corporate designee’s. Certification is now listed for 9 March 2027, with a vendor’s own bias audit material at the centre of the delay. A vendor’s own internal bias evaluations became the discovery fight, which is the practical answer to anyone who believes a low ratio can be tested quietly and shelved. Three years into this wave of litigation there is still no verdict anywhere in the United States, only motion rulings, one certification order and a handful of settlements.
Two numbers in wide circulation that will not survive checking
Two figures prop up most guidance on this subject, and both break under a source check.
The first figure claims that 99 per cent of Fortune 500 companies use AI to screen applicants. Most citations credit a 2021 Harvard Business School and Accenture report, which lends the figure academic weight. The report’s own footnote 79 attributes the figure to a November 2019 blog post by Jobscan, a commercial service selling résumé optimisation to job seekers, whose product depends on the number being high and whose method is unpublished. The claim is also about applicant tracking systems rather than AI, and Harvard’s own news coverage converted “applicant tracking systems” into “artificial intelligence tracking systems” on the way out.
The second is any claimed rate of bias audit compliance or non-compliance under Local Law 144. Eighteen audit reports across 391 employers is a count, not a rate, for the reason the authors give.
The same Harvard report does contain figures worth using, provided they are dated and scoped. Its employer survey covered 2,275 executives across the United States, United Kingdom and Germany, fielded in January and February 2020, and found that 88 per cent of employers believed qualified high-skills candidates were vetted out because they did not match the exact criteria in the job description, rising to 94 per cent for middle-skills roles. Both figures measure belief about criteria-based filtering, before the generative AI era, and support no conclusion about model behaviour.
One more bias audit negative is worth stating precisely. The California Privacy Protection Agency regulations on automated decisionmaking technology took effect on 1 January 2026, with compliance for significant decisions required by 1 January 2027 under section 7200(b). The approved text contains no instance of “bias audit”, “anti-bias” or “disparate impact”. The word “bias” appears once, at section 7152(b), listing experts in detecting and mitigating bias among the sources a business may draw on for a risk assessment. A privacy risk assessment is not a bias audit, and different agencies enforce the two Californian regimes under different statutes.
The day the ratio comes back low
A bias audit produces one number, six regimes do six different things with it, and the first decision is which of them you are standing in.
| If the finding is | Then |
| In Texas | Record that the disparity was found through testing, and keep the testing record. Section 552.105(e)(2) turns self-discovery into a liability bar |
| In California or Connecticut | Document the response, not only the result. The regulation makes the response to the results relevant, and a finding with no response is the worst evidential position available |
| Under the EU AI Act from December 2027 | Detect, prevent and mitigate under Article 10(2)(g). A finding creates a duty |
| In New York City | Publish it. Publication is compliance, and the published figure is a dated admission that supports a claim elsewhere |
| In Illinois | Treat the finding as exposure rather than evidence. The effect is the violation |
| Under Title VII | Keep the impact data. Section 1607.4(D) permits an inference against a user who has not maintained it |
Three operational points cut across all six bias audit regimes. A bias audit expires: Local Law 144 permits use only where one was conducted within the previous year, and a state auditor found an employer whose posted audit had lapsed three days before the regulator called. A vendor’s audit is not automatically yours, because section 20-871 puts the duty on the employer or employment agency, pooled historical data is available only where you contributed your own or have never used the tool, and an auditor with a financial interest in the vendor fails the independence test. And the result is discoverable in every jurisdiction on this page, including the ones that require nothing.
Govern365.ai holds the mapping from a provision to the artefact that proves it, with the expiry date and the jurisdiction attached, so a test result, the response to it and the publication that followed sit against the obligations they actually answer rather than in a folder somebody has to interpret later. One record usually serves more than one regime: the same tool file supports a Local Law 144 posting, an AI system inventory entry and an EU AI Act classification, and one vendor assessment answers both processor diligence and deployer duties. Our AI compliance evidence guide sets out the artefact types across regimes, and third-party AI risk management covers what to ask the vendor whose tool you are testing.
Two existing pages sit beside this one and answer different questions. Local Law 144 bias audit requirements is the New York City operational guide, covering AEDT scope, remote roles and notice mechanics in more depth than the section above. AI bias risk: detection, testing and mitigation is the technical companion on fairness metrics, proxy variables and mitigation at the pre-processing, in-processing and post-processing stages. The page you are reading is about consequence: what each legal system does with the number once you have it.
Frequently asked questions
Which laws actually require an AI bias audit?
One. New York City Local Law 144 of 2021, with the rules at 6 RCNY Subchapter T, requires an impartial evaluation by an independent auditor conducted within the previous year and a summary of results published before the tool is used. Illinois, Texas, California, Connecticut and Colorado require no audit, and Title VII requires no proactive testing of any kind.
What happens if a bias audit returns an impact ratio below 0.8?
The answer depends on jurisdiction and the answers conflict. Texas bars liability where the defendant discovered the violation through testing. California and Connecticut make the result and the response to it evidence in a claim or defence. The EU AI Act requires mitigation of identified bias. New York City requires publication and nothing more. Illinois treats the discriminatory effect as the violation. Under 29 CFR 1607.4(D), a ratio below 0.8 is what federal enforcement agencies will generally regard as evidence of adverse impact, which is a prosecutorial screen rather than a legal threshold.
Does testing for bias help or hurt you legally?
Both, depending on where. In Texas, self-discovery through adversarial or red-team testing bars liability under section 552.105(e)(2). In California and Connecticut, testing without acting on the findings is a worse evidential position than not testing, because the regulations make the response to the results relevant. Under the Uniform Guidelines, failing to maintain impact data permits an inference of adverse impact.
Does a bias audit have to be repeated?
Under Local Law 144, yes. 6 RCNY section 5-301(a) prohibits use where more than one year has passed since the most recent bias audit, and the published summary must stay up for at least six months after the last use of the tool. No other US jurisdiction sets an audit clock, because no other jurisdiction requires an audit.
Who can perform a bias audit under Local Law 144?
Anyone without the conflicts listed in 6 RCNY section 5-300: involvement in using, developing or distributing the tool, an employment relationship with the employer, employment agency or vendor during the audit, or a direct or material indirect financial interest in any of them. No licence, accreditation or register exists, so independence is a question of conflicts rather than credentials.
Does the vendor’s bias audit cover the employer using the tool?
Not automatically. Section 20-871 places the duty on the employer or employment agency. Pooled historical data from multiple users of the same tool may be relied on only where the employer contributed its own historical data or has never used the tool, and an auditor with a financial interest in the vendor does not satisfy the independence test.
Does Illinois HB 3773 require a bias audit?
No. It makes it a civil rights violation for an employer to use artificial intelligence “that has the effect of” subjecting employees to discrimination, and bars zip codes as a proxy. A notice duty applies, but the Department of Human Rights rules specifying its circumstances, timing and means were proposed in May 2026 and withdrawn in June 2026.
Does Texas HB 149 require a bias audit?
No, and it goes in the opposite direction. Section 552.056 requires intent and provides that disparate impact alone is insufficient to demonstrate it. Section 552.105(e)(2) then bars liability where the defendant discovered the violation through testing, including adversarial or red-team testing, or through substantial compliance with the NIST AI Risk Management Framework Generative AI Profile together with an internal review process.
What does Connecticut’s AI law require?
Public Act 26-15 requires no bias audit. The Act permits a commission or court to consider evidence of anti-bias testing, using the same six dimensions as the California regulations, and provides that the use of an automated employment-related decision technology is not a defence against a discrimination complaint. State agencies must also post an AI impact assessment at least sixty days before deployment.
Does Colorado still require an impact assessment?
No. Senate Bill 24-205 was postponed to 30 June 2026 and then repealed and reenacted by Senate Bill 26-189, signed 14 May 2026, before its obligations ever commenced. The replacement takes effect on 1 January 2027 and contains no duty of reasonable care, no impact assessment and no audit. Deployers retain records for at least three years, disclose adverse outcomes within thirty days, and face exclusive Attorney General enforcement with a sixty-day cure period and no private right of action.
Must a private employer run a fundamental rights impact assessment under the EU AI Act?
Usually not. Article 27(1) reaches deployers that are bodies governed by public law, private entities providing public services, and deployers of Annex III points 5(b) and 5(c) systems. A private company hiring for itself falls outside it. Article 26 deployer duties still apply, including the Article 26(7) duty to inform workers’ representatives and the affected workers before putting a high-risk system into service.
How actively is the bias audit requirement enforced?
Sparsely, on the only published record. New York State Comptroller report 2024-N-6 of December 2025 found two complaints received over two years, two demand letters sent, and no penalty for an AEDT violation is publicly reported. The same report found at least 17 instances of potential non-compliance among 32 companies where the regulator had found one
