Policy

What Does HR Have to Build in 90 Days After an AI-First Mandate?

An AI-first mandate leaves HR owing three things inside 90 days, and the memo is not what makes them due: an inventory of every place AI already touches an employment decision, a notice and a retained record for each use a statute reaches, and one named person who can switch a use off. Which uses a law reaches is set by your industry and your states, not by the mandate. Literacy training, headcount modeling and a competency framework have no outside clock and can wait.

The takeThe exposure that bites first is not the one on an invoice. Illinois's notice duty starts January 1, 2026, and it attaches to the use rather than the purchase, so the riskiest system in most companies is a manager's own chat window with forty resumes pasted into it. Nobody procured it, nobody classified it, and no vendor will answer for it. On what regulators have said so far, I would expect the first painful cases to land on employers who could not produce a list at all, before they land on employers whose list had a bad row in it.

Where Olive fits

Open a role and see what the work shows

Once the inventory exists, each row needs an answer to what the tool produced and who decided. Olive produces six written findings, each anchored to a timestamped excerpt, with a person writing every word and no automated decision anywhere in it, and the candidate is granted the same report.

Rank your shortlist

What has to exist by day 90?

Three artifacts, and none of them is a training program. An inventory of every place AI already touches an employment decision. A notice and a retained record for each of those places a statute reaches. And one named person with the authority to switch a use off. Everything else on the mandate's implied list is a choice about pace, not a legal deadline.

The inventory is the piece most companies skip, and it is the one every later question depends on. It is a table rather than a document, and five columns are enough:

  • The use, not the tool. "Screening applications for the analyst req" is a use. "Copilot" is not.
  • Who runs it, by name, including the hiring manager quietly pasting resumes into a chat window.
  • What it produces: a shortlist, a summary, a draft, a number.
  • Whether a human decides afterward, and what that human actually sees before deciding.
  • Where the affected people are, because the rules attach to their location as well as to yours.

Run the inventory as a survey of managers, not as an IT asset scan. The uses that create exposure are usually unbudgeted: a recruiter's personal subscription, a spreadsheet formula calling a model, a summarizer inside a video interview product nobody classified as a hiring tool.

The NIST AI Risk Management Framework is a usable skeleton for those columns, and NIST states that it is intended for voluntary use 4. Bring it to your CEO as the structure you chose, never as the thing the law demanded. Training sits in the same category: worth doing, and not the same thing as checking people can do the work afterward.

Which AI uses does a law already reach?

The ones that touch recruitment, hiring, promotion, discipline, discharge or the terms of employment. Illinois amended its Human Rights Act to cover exactly that list, effective January 1, 2026, and added a duty to notify employees when an employer uses AI for those purposes 1. New York City requires a bias audit within one year of use, a published summary of the results, and notice before use 2.

Two details in the Illinois text are worth reading in the original. It reaches generative AI, not only scoring models. And it bans using zip codes as a proxy for a protected class, which is an instruction to look at your inputs rather than at your intentions 1.

At the federal level the older machinery still applies. The Uniform Guidelines ask a user of a selection procedure to keep records of impact by race, sex and ethnic group, and treat a selection rate below four-fifths of the highest group's rate as evidence of adverse impact 3. None of that changed because a model produced the shortlist.

The trigger is the use, not the purchase. A manager who pastes forty resumes into a chat window and asks which five to call has run a selection procedure. No contract, no vendor, no audit trail. That is the hardest case to close inside 90 days, because auditing a vendor's tool at least gives you a vendor to ask.

Olive's compliance page names the regimes above and the checks Olive has not performed yet. See how Olive measures this.

Why your 90-day list is not another company's

Because the control follows the use and the jurisdiction, not the memo. A company that already validates models for a regulator adds employment uses to a register that exists, and the 90-day job is a few rows and an owner. A company with no such register is building one, and that is most of the ninety days. Hiring in Illinois and New York City adds two dated duties 12; hiring where neither applies leaves federal records expectations 3 and no notice clock.

The practical split is between companies where an employment tool lands inside an existing control process and companies where it lands nowhere. One question tells you which you are: if a model informed a decision about a person last quarter, who could produce the record of it today, and how long would that take? A name and a week means you are adding rows. A shrug means the inventory is the whole project.

Sector matters in a second way. Where AI sits close to the revenue work (engineering, analysis, underwriting, claims), the mandate carries a real question about which roles change and which do not, and that question is separable from the compliance work. In a function where AI mostly drafts copy, the compliance work is small and the interesting problem is quality.

What can wait, and what to push back on

Literacy curricula, a competency framework, headcount modeling and tool consolidation can all wait past day 90, because nothing outside the company is counting them. Push back on three items a mandate hands HR by default: buying and securing tools, judging whether a model is good enough for a given workflow, and setting headcount targets. Those belong to IT and security, to the function using the model, and to finance.

The pushback lands better with the reason attached than as a refusal. HR owns the employment decision and the record of it. HR does not own model performance and cannot own it. The person who can tell whether a summarizer dropped the wrong clause is the one who reads those clauses for a living.

Two items sit on the line and are worth negotiating rather than declining. Hiring for AI skills or training the team you already have is a genuine HR call, and it turns on evidence about the current team that nobody has collected yet. Headcount planning against an assumed productivity gain is a finance model, and HR should read it before it becomes a hiring freeze, because the freeze arrives as an HR announcement whatever its origin.

One item is worth adding rather than deferring: a written rule for what a manager may say to a candidate about a decision AI touched. It costs an afternoon, and it is the first thing anyone asks for when a rejected candidate wants to know why.

Write the 90 days as three dated blocks

Days 1 to 15: the inventory, with one owner's name against each row. Days 16 to 45: notice text, the retained record for each in-scope use, and legal sign-off on both. Days 46 to 90: the first bias audit or adverse-impact check where one is owed 23, and a written rule for what a manager may do with an AI-produced judgment about a person.

Dating the blocks is not project theater. It converts a mandate into something that can be reported against, and it keeps the genuinely optional parts of the list from being pulled forward by enthusiasm. A CEO who asked for AI-first in 90 days will take "notice text is done, the audit is booked for day 70" over a status update with no dates in it.

Write the result as one page, not a binder. An AI hiring policy needs three paragraphs (what candidates may use, what you evaluate with, what you keep), and a one-page document gets legal review while a twenty-page one waits.

Then keep the inventory alive. Add a row when a use starts, put the next review on a date rather than on someone remembering, and treat any use a manager started without telling you as the normal case rather than the exception.

Read the evidence

Common questions

Does an AI-first mandate itself create a legal obligation?

No. The obligation attaches to a use and a place, not to an announcement. Illinois's amended Human Rights Act reaches AI used in recruitment, hiring, promotion, discipline and discharge from January 1, 2026, and New York City's rule reaches automated employment decision tools used on candidates or employees in the city. If your company already used AI in those ways before the memo, the duties were already running. If it does not use AI that way yet, the mandate has given you a deadline of your own choosing.

Who should own AI in hiring: HR, legal or IT?

HR owns the employment decision and the record of it. Legal owns the notice text and the reading of each jurisdiction. IT and security own procurement, access and data handling. The failure mode is a shared owner, because a use nobody can switch off is a use nobody is accountable for. Put one name against each row of the inventory, give that person authority to stop the use, and route the rest through the usual approvals.

Do we need a bias audit if AI only writes our job descriptions?

Probably not, but write down why. The audit and notice duties key off tools that substantially assist or replace a decision about a person. A drafting assistant that a recruiter rewrites is a different use from a tool that scores or filters applicants. The distinction has to be recorded, because the question arrives later as "prove it did not screen anyone," and the record is the answer. Wording still matters for a different reason: a description AI drafted can narrow your applicant pool without touching a decision.

What if the mandate arrives with a headcount reduction target?

Separate the two. Headcount is a finance and executive decision, and HR does not have to own the arithmetic to be accountable for how it lands. What HR does own is the selection: if any model, score or AI-produced ranking informs who is let go, that is a selection procedure, and impact by race, sex and ethnic group has to be measurable afterward. Ask for the selection criteria in writing before the list exists, not after.

Should we buy an AI-skills assessment in the first 90 days?

Only if a role is actually open. An assessment bought to demonstrate momentum becomes a hiring gate nobody validated, and it enters the same inventory as everything else. If you do buy one, the vendor's bias-audit evidence and its notice language become your records, so ask for both before signing rather than during the first dispute. A pilot that runs beside your existing round, with no candidate outcome attached, costs far less to unwind.

References

  1. 1. Public Act 103-0804 (HB3773), amending the Illinois Human Rights Act Illinois General Assembly, 2024. ilga.gov Effective 1/1/2026: bars AI with a discriminatory effect in recruitment, hiring, promotion, discipline, discharge and terms of employment, bars zip code as a proxy, and requires notice.
  2. 2. Automated Employment Decision Tools (Local Law 144 of 2021) NYC Department of Consumer and Worker Protection, 2023. nyc.gov Bias audit within one year of use, a publicly available summary of results, and notice to candidates and employees before use.
  3. 3. 29 CFR 1607.4 - Information on impact (Uniform Guidelines on Employee Selection Procedures) Electronic Code of Federal Regulations, 1978. ecfr.gov Records of impact by race, sex and ethnic group, and the four-fifths rule as evidence of adverse impact.
  4. 4. AI Risk Management Framework (AI RMF 1.0) National Institute of Standards and Technology, 2023. nist.gov NIST states the framework is intended for voluntary use, which is why it structures an inventory but does not create a deadline.

4 sources, numbered by first appearance. Every one was opened and checked against the claim it carries. How Olive sources claims

General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.

Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.

Back to answers

Open your first role Ten attempts a month against a live item bank, with a human-written report on every one.