AI Hiring Tools Compliance: Bias Audits, Review Records and Evidence

Share Article

Table of Contents

Forty-three percent of organizations used AI for HR tasks in 2025, up from 26% the year before, according to SHRM’s State of AI in HR research, with recruiting the single most common use case. Regulators noticed at roughly the same pace.

Four separate compliance regimes now touch the same resume-screening tool: New York City’s bias audit law, Colorado’s rewritten automated decision-making statute, California and Illinois record keeping and notice rules, and the EU AI Act’s high-risk classification for recruitment systems. None of them share a definition, a deadline, or a documentation format.

This piece maps what each regime actually requires, where the requirements overlap, and how to build one evidence trail that satisfies all of them instead of five separate ones.

Why AI Hiring Compliance Turned Into a Recordkeeping Problem

Ask a compliance lead what changed about AI hiring regulation in 2026, and the answer usually isn’t a new prohibition. It’s a shift from asking whether the tool is fair to asking whether you can prove it. Four of the five regimes covered in this piece treat documentation quality itself as evidence in a discrimination claim, not just as a paperwork requirement sitting beside one.

California’s amended Fair Employment and Housing Act regulations put this most plainly: anti-bias testing, or the absence of it, is explicitly relevant evidence in a discrimination case. Regulators and courts will look at how recently a tool was tested, how thorough the testing was, what it found, and whether the employer acted on the results. A well-run audit with no paper trail is functionally the same as no audit.

That reframing matters for procurement, too. A vendor who can produce a bias audit report, a model card, and a change log on request is solving a different problem than a vendor who can only promise the tool is fair. Govern365.ai’s audit evidence management module keeps bias audit reports, notices, and remediation records tied to the specific model version they were run against, so the evidence survives a vendor update instead of going stale with it.

The Bias Audit Baseline: NYC Local Law 144

Local Law 144 is the oldest and most tested of the group. Since July 2023, it has required an independent bias audit within one year of using any automated employment decision tool (AEDT) on a New York City candidate, publication of a summary of that audit on the employer’s website, and at least 10 business days’ notice to candidates before the tool is used.

The audit itself is a specific statistical exercise: calculate selection or scoring rates by sex, race and ethnicity category (and their intersections), then compute the impact ratio each group’s rate divided by the rate of the most-selected group. An impact ratio under 0.80 signals potential adverse impact under the EEOC’s long-standing four-fifths rule.

What changed in 2026 is enforcement, not the statute. A New York State Comptroller audit published December 2, 2025 found that the city’s Department of Consumer and Worker Protection had reviewed 32 companies and identified one compliance issue, while the Comptroller’s team reviewing the same companies found at least 17. Three-quarters of relevant 311 complaint calls never reached the DCWP at all. The department has committed to more rigorous, less complaint-dependent enforcement going forward, and employment counsel are advising clients to expect it.

One detail worth building into a compliance checklist: the candidate opt-out. Applicants can request an alternative selection process instead of AEDT evaluation, and that alternative has to be real and actually offered, not a check-box that nobody uses.

If your organization uses automated employment decision tools in New York City, review the NYC Local Law 144 bias audit requirements alongside your internal compliance program.

Colorado’s Reset: From “High-Risk AI” to Covered ADMT

Colorado’s original AI Act, SB 24-205, would have been the most demanding employment AI statute in the country: risk management programs, pre-deployment impact assessments, and an affirmative duty to prevent algorithmic discrimination. It never took effect. After two delays and a constitutional challenge from xAI that the U.S. Department of Justice took the unusual step of supporting, Colorado’s legislature scrapped it.

On May 14, 2026, Governor Jared Polis signed SB 26-189, which repeals SB 24-205 entirely and replaces it with a narrower regime built around “covered automated decision-making technology,” or ADMT any system that processes personal data and generates outputs used to materially influence a consequential decision, including hiring, promotion, compensation, and termination. The risk management program and impact assessment mandates are gone. What survives is smaller but still consequential for HR teams: point-of-interaction notice, a post-adverse-outcome disclosure within 30 days, a right to request meaningful human review and three years of compliance recordkeeping covering ADMT version identifiers, change logs, and documentation of material updates.

SB 26-189 takes effect January 1, 2027, with the Attorney General required to issue implementing rules by the same date. As of mid-2026, enforcement is further complicated by the fact that the Attorney General has stated he will not enforce SB 24-205 or its successor until rulemaking concludes, following the court-ordered stay in the xAI litigation. That gives employers a real runway, but the recordkeeping regime the law describes is exactly the kind of system that takes months to stand up, not weeks. [VERIFY] Confirm the AG’s rulemaking status closer to the effective date, since draft implementing rules were not yet published as of this writing.

Organizations deploying AI in employment should also monitor broader US regulations through this Colorado AI Act compliance checklist for automated decision-making technology.

California and Illinois: Notice Duties and a Longer Paper Trail

California took a different path from Colorado: instead of a standalone AI statute, the Civil Rights Council folded automated decision systems directly into existing Fair Employment and Housing Act regulations, effective October 1, 2025. Any employer using a computational process to make or assist an employment decision is covered, whether it is a sophisticated model or a simple screening algorithm.

The practical center of gravity is recordkeeping: personnel and ADS-related records must now be retained for four years, up from the previous two, and that includes the inputs, outputs, selection criteria, and any testing or evaluation results tied to the tool. The regulations also extend liability to an employer’s “agents,” a definition broad enough to reach staffing firms and vendors performing hiring functions on the employer’s behalf.

Illinois took a third approach entirely. House Bill 3773, effective January 1, 2026, amends the Illinois Human Rights Act to prohibit AI that has a discriminatory effect in employment decisions and to ban zip codes as a proxy for protected characteristics. It does not mandate a bias audit the way New York City does. But because liability is strict a discriminatory outcome is enough, regardless of intent the practical effect is the same incentive toward documented, pre-emptive testing that Colorado and California create through explicit rules. Illinois employers must also notify employees and applicants when AI is used in a covered decision; the Department of Human Rights’ implementing rules were still in draft form as of early 2026.

Lay the three regimes side by side and a pattern appears: none of them agree on what to call the technology, what triggers coverage, or how long to keep records, but all three treat the record itself as the thing that determines whether an employer can defend a discrimination claim.

The EU AI Act: Recruitment as a High-Risk Use Case

For employers hiring across borders, the EU AI Act adds a fifth framework with its own timeline. Annex III of the Act classifies AI systems used for recruitment, candidate screening, and evaluation of job applicants as high-risk, triggering conformity assessments, technical documentation, human oversight design requirements, and logging obligations before the system can be placed on the EU market.

The compliance date for those Annex III obligations has moved. Under the Digital Omnibus on AI, the Council of the EU gave final approval on June 29, 2026, following the European Parliament’s endorsement on June 16, 2026, confirming a deferral of Annex III high-risk obligations from the original August 2, 2026 date to December 2, 2027. Formal publication in the Official Journal was pending at the time of writing but is expected imminently, and the deferred date is the one legal teams are now planning against.

One date has not moved: the Article 50 transparency obligations, which require disclosure when a person is interacting with an AI system, still apply from August 2, 2026, regardless of how the high-risk timeline shifts. For a multinational employer, the practical read is that the deadline pressure eased, but the substantive design work conformity documentation, human oversight, logging is the same work the U.S. state laws are asking for in narrower form, just on a longer runway.

One Evidence Trail, Five Regulators: A Cross-Framework Mapping

Most compliance guides treat each of these laws as a separate checklist. That’s how a mid-size employer ends up running the same resume screener through five uncoordinated review processes. The more useful exercise is mapping the requirements against the control structures most GRC teams already maintain: ISO/IEC 42001 clause 6.1’s risk assessment and treatment requirements, NIST AI RMF’s Govern-Map-Measure-Manage functions, and each jurisdiction’s specific hiring rule.

Cross-framework requirements for AI hiring tools (as of mid-2026)

RequirementNYC LL144Colorado SB 26-189California FEHA regsIllinois HB 3773EU AI Act (Annex III)
Independent bias auditRequired annuallyNot requiredNot mandated; used as evidenceNot mandated; used as evidenceConformity assessment required
Candidate notice10 business days pre-usePoint-of-interactionNot specified in ADS rulesRequired, timing TBD by ruleArticle 50 disclosure
Recordkeeping durationAudit + summary, ongoing3 years [VERIFY]4 yearsNot specifiedFull technical file, life of system
Human review rightAlternative process on requestMeaningful human reviewIndividualized assessment for certain usesNot specifiedHuman oversight by design
Compliance deadlineEnforced since July 2023January 1, 2027In effect since October 1, 2025In effect since January 1, 2026December 2, 2027 (deferred)

Colorado’s 3-year figure is drawn from the enacted text of SB 26-189; confirm against Attorney General implementing rules once published.

Read across the rows rather than down the columns and the design implication is clear: build one AI hiring system inventory, run one bias testing cadence sized to the shortest applicable cycle, and retain one evidence set for the longest applicable retention period currently the EU’s life-of-system standard, with California’s four years as the practical U.S. floor.

Govern365.ai’s AI model registry generates this kind of clause-level mapping automatically, tagging each hiring tool against its applicable ISO 42001 controls, NIST AI RMF functions and jurisdiction-specific obligations from a single system record.

Building an Audit-Ready Evidence Trail

The regimes above share enough structure that a single evidence framework can satisfy all of them, provided it is built around six recurring components.

  1. Tool inventory. [All frameworks] Document every system that screens, scores, or ranks candidates or employees, including embedded features inside applicant tracking systems, not just standalone AI products.
  2. Bias or anti-bias testing record. [NYC LL144, CA FEHA, EU AI Act] Selection and scoring rates by protected category, impact ratios, testing methodology, and the auditor’s independence attestation.
  3. Point-of-use and post-adverse-outcome notices. [NYC LL144, Colorado SB 26-189, Illinois HB 3773] Timed, jurisdiction-specific candidate communications, logged with delivery date and method.
  4. Human review and correction request logs. [Colorado SB 26-189, CA FEHA, EU AI Act] Who reviewed an adverse decision, what evidence they considered, and whether the outcome changed.
  5. Version and change history. [Colorado SB 26-189, EU AI Act] Model or vendor updates, retraining events, and re-testing triggered by material changes.
  6. Retention schedule mapped to the longest applicable period. [CA FEHA (4 yrs), Colorado (3 yrs), EU AI Act (life of system)] A single retention clock per tool, set to the strictest jurisdiction where it is used, rather than five overlapping schedules.

The sixth item is the one most compliance programs get wrong first. Teams often set retention by policy default rather than by where the tool is actually used, then discover during a discrimination claim that the specific testing record from 14 months ago was already purged under a two-year internal schedule that predates the California amendment.

What Enforcement Actions Are Actually Testing

The EEOC’s 2023 settlement with iTutorGroup, which allegedly configured its hiring software to automatically reject female applicants over 55 and male applicants over 60, remains the reference case for a simple reason: it did not turn on a novel legal theory. It applied ordinary Title VII disparate-treatment principles to a system, and “the algorithm did it” was not a defense.

The pending Workday litigation, alleging that its AI screening tools produced discriminatory outcomes across race, age, and disability, has moved further and raised a harder question for the industry: whether an AI vendor providing the screening tool can itself be treated as an employment agency subject to anti-discrimination law, not merely a software supplier. If that theory holds, it changes vendor due diligence from a contractual nicety into a legal necessity, since employers cannot outsource discrimination liability to the tool they bought.

The common thread across both cases and the DCWP’s own enforcement failures in New York is not exotic AI risk. It is the ordinary compliance discipline of testing, documenting and correcting done consistently enough to produce a real record when someone asks for one.

Frequently Asked Questions

Do I need a bias audit if my company is not based in New York City?

Yes, if any candidate you evaluate resides in New York City, regardless of where your company is headquartered or where the role is performed. Local Law 144 follows the candidate’s location, not the employer’s. Remote roles filled by NYC residents are covered the same as in-office positions.

Does Illinois HB 3773 require a formal bias audit like New York City’s law?

No. HB 3773 does not name a bias audit requirement. It prohibits AI that produces a discriminatory effect and requires notice to employees and applicants, with liability that does not depend on proving intent. Many employers run bias testing anyway, since it is the clearest way to defend against a strict-liability discrimination claim.

What happened to Colorado’s original AI Act?

SB 24-205 was repealed and replaced by SB 26-189, signed May 14, 2026. The new law drops the risk management program and impact assessment mandates and instead requires notice, a 30-day post-adverse-outcome disclosure, human review rights, and three-year recordkeeping. It takes effect January 1, 2027.

How long do I need to keep AI hiring records?

It depends on jurisdiction: three years under Colorado’s SB 26-189, four years under California’s FEHA regulations, and effectively the life of the system under the EU AI Act’s technical documentation requirements. Employers operating across states typically set retention to the longest applicable period rather than tracking separate schedules per tool.

Is the EU AI Act’s high-risk classification for hiring tools still coming in August 2026?

No. The Digital Omnibus on AI, formally approved by the Council on June 29, 2026, defers Annex III high-risk obligations, which include recruitment AI, to December 2, 2027. The Article 50 transparency disclosure requirement is unaffected and still applies from August 2, 2026.

Can a vendor’s bias audit satisfy my obligations as the employer?

Generally, no. Most of these laws place the compliance obligation on the employer or deployer, not the vendor, even when the vendor built and ran the underlying testing. A vendor’s audit report can be part of your evidence, but you still need your own notice practices, recordkeeping, and human review process layered on top.

What counts as an automated employment decision tool under these laws?

Definitions vary, but most cover any computational process, including simple algorithms and not just advanced AI, that substantially assists or replaces discretionary decisions about hiring, promotion, or termination. Tools used purely for scheduling or administrative support are typically excluded, as are basic spreadsheets and calculators.

Conclusion

The five regimes covered here will keep diverging on definitions and deadlines. What they agree on is the underlying test: not whether your hiring tool is theoretically fair, but whether you can produce the record that proves it, on the specific version of the tool you were using, on the day a candidate asks.

Start with the tool inventory. Everything else, from bias testing cadence to retention schedules, follows from knowing what you actually have running in your hiring pipeline.

Govern365.ai maps each AI hiring tool in your inventory against ISO 42001, NIST AI RMF, and jurisdiction-specific rules like the ones covered here, and keeps the audit evidence tied to the model version it was tested against.

Start your 14-day free trial to see your current AI hiring tools mapped against this year’s compliance requirements. Govern365.ai, by the Global AI Certification Council.

Stay ahead of the curve

Join 5,000+ industry leaders who receive our weekly briefing on AI governance and secure enterprise collaboration.

About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

Globally certified instructor in ISO/IEC, PMI®, TOGAF®, and Scrum.org disciplines with hands-on experience in ISO/IEC 42001 AI governance across the US, EU, and Asia-Pacific.

Summarize with AI

AI-Powered Data Governance Platform

Secure, Govern, and Collaborate on Sensitive Data—All Within Microsoft 365

Further Reading

Related Insights

nyc-local-law-144-bias-audit-requirements

NYC Local Law 144 Bias Audit Requirements for AI Hiring Tools

Nearly half of US organizations, 43% according to SHRM’s 2025 Talent Trends survey of 2,040

Read More →
ftc-ai-claims-compliance-checklist

FTC AI Claims Evidence Checklist Before You Market AI Features

The Federal Trade Commission’s civil penalty for a knowing violation of an existing order or

Read More →
naic-ai-model-bulletin-checklist-insurers

NAIC AI Model Bulletin Checklist for Insurers Using AI

Since the National Association of Insurance Commissioners adopted its Model Bulletin on the Use of

Read More →

Summarize with AI

Transforming AI Risks into Strategic Assets.

Request a Personalized Demo

Our governance experts will walk you through the platform and help you map out your ISO 42001 or EU AI Act roadmap.