Policy

AI Hiring Laws Regulate Your Tools, Not the Candidate's

None of the new AI hiring laws says anything about candidates using AI. New York City Local Law 144, the Illinois Human Rights Act amendment, the Texas act and the EU AI Act all regulate automated tools an employer deploys on candidates. Not one creates an obligation, a defense, or a template for the rule you set for applicants. A candidate AI rule is a process-consistency question instead: stated in advance, applied identically inside a req, recorded next to the decision.

The takeThe compliance roundups are not wrong, they are answering a different question, and hiring teams keep reading them for an answer that is not in any of them. There is no legal cover for a candidate AI rule and none is coming, because these statutes are about employers making automated decisions. The rule you write is a fairness and consistency artifact. Judge it the way you would judge any other term of your process, and stop waiting for a statute to bless it.

Where Olive fits

Open a role and see what the work shows

Under the automated-decision rules, the duties attach to a tool that makes or substantially assists a decision. The decision stays with the person reading an Olive report: a person writes each of the six findings and quotes the moment of the session it rests on, and a released report carries the rubric, scorer and bank versions used to produce it.

Rank your shortlist

What do the AI hiring laws actually cover?

Tools the employer runs, and the notice owed to the person they run on. New York City Local Law 144, in force since January 1, 2023, bars using an automated employment decision tool on a NYC candidate unless a bias audit was done within the prior year, a summary is posted, and the candidate got 10 business days of notice 1. That is the shape of all of them: audit, notice, consent. Applicant conduct is not addressed.

The others differ on the standard, not on the target. Illinois Public Act 103-0804 amended the Human Rights Act, effective 1 January 2026, to make it a civil rights violation for an employer to use AI that has the effect of discriminating on a protected basis, or to use zip codes as a proxy 2. Texas went the other way: its Responsible Artificial Intelligence Governance Act, effective the same day, prohibits deploying an AI system with the intent to discriminate and says expressly that a disparate impact is not sufficient by itself to show intent 3. An effects standard in one state and an intent standard in another is why "compliant with AI hiring law" is not a coherent single claim.

In the EU, Annex III point 4 of the AI Act names recruitment and selection uses as high-risk, including targeted job advertising, filtering applications and evaluating candidates 4. Classification is not an obligation yet: the Digital Omnibus on AI moved the substantive high-risk requirements to 2 December 2027, so an employer running a screening tool in 2026 is not breaching Annex III 5. The label follows what the system is built to do, whatever the employer calls the tool internally.

One correction worth carrying, because 2025 commentary is still repeating the old date: Colorado's AI Act never took effect. It was repealed and reenacted as a narrower automated decision-making regime commencing 1 January 2027 6. If a compliance summary tells you Colorado binds employers this year, it is out of date, which is a fair warning about the whole genre.

Why the enforcement tool is the real exposure

Because the thing you would buy to police a candidate rule is itself the regulated object. A detection product or scoring layer that substantially assists a screening decision is an automated employment decision tool in New York City, an automated-decision system under California's amended FEHA regulations, and a high-risk use under Annex III of the EU AI Act. A rule about applicant honesty turns into an audit-and-notice obligation of your own.

California's Civil Rights Council amended the FEHA employment regulations to cover automated-decision systems, effective 1 October 2025, defining one as a computational process that makes or facilitates a decision about an employment benefit, and naming as examples screening resumes for particular terms or patterns and analyzing word choice or voice in online interviews. An agent acting for the employer, including the vendor running the system, is itself an employer under the Act 7. Those regulations impose no audit or notice duty of their own, but they settle who is answerable.

The sequence runs like this, and it is common. A team writes a blanket ban on candidate AI use, finds it unenforceable, and buys a checking tool to enforce it. Where that tool substantially assists a decision on a New York City candidate, the audit and notice duties attach. In California, the vendor running it can be sued as an employer alongside the buyer. The rule was cheap; the enforcement is what carries the exposure. Whether a detector may be pointed at a resume at all is worked through in running a resume through an AI detector and rejecting on it.

What makes a candidate AI rule hold up

Three properties, none of them statutory. It was published before anyone applied, it was applied identically to everyone in that req, and the decision record says what was asked and what was answered, not what somebody suspected. A rule with those three survives a challenge because it is consistent, and consistency is the ground employment claims are actually fought on.

Under federal selection law, none of your stages sit outside the frame either way. The Uniform Guidelines define a selection procedure broadly enough to include informal or casual interviews and unscored application forms, so calling a stage a conversation does not move it out of scope 8. That cuts in a useful direction here: whatever rule you set is part of a selection procedure, and it should be documented like one.

What that looks like in a file: the posting text with its date, the identical instruction sent to every candidate in the req, the scorecard question that was asked of everyone, and a reason for each outcome written in the vocabulary of the work itself. Nothing in that list requires a statute to justify it, and all of it is what a challenge asks for.

The adjacent question, whether you may ask candidates about their AI use at all, has its own answer and its own limits, set out in whether you can legally ask candidates how they use AI.

Check the two places law does touch the candidate

Consent for AI analysis of a recorded video interview, and notice that an automated tool is being used at all. Illinois has required both for video since 2020: notice before the interview, an explanation of what the AI evaluates, the applicant's consent, and no evaluation of anyone who has not consented 9. Neither duty regulates what a candidate uses. Both regulate what may be run on them.

Read the Illinois video act for what it does not do, as well. It covers exactly one technology, AI analysis of applicant-submitted video, and reaches no resume screener, chat interview or take-home. It names no penalty and creates no private right of action, so an applicant dropped after declining has no remedy under that Act. The right to refuse exists on paper before it exists in practice, which is a useful thing to know before designing a process around consent.

The second place is the audit trail, and it points back at your own instruments rather than at applicants. If a tool in the loop substantially assists a screening decision on a New York City candidate, the bias audit and the 10 business days of notice attach regardless of what the tool was bought for. Running that check when the vendor holds the data is its own exercise: running an adverse impact audit on an AI screening tool.

One closing note on posture. Enforcement of these laws has been thin so far, which is not a reason to ignore them and not a reason to panic. It means the discipline that pays is the one you would want anyway: know which of your tools makes or assists a decision, keep the record, and stop looking to compliance law for permission on a question it does not answer.

Read the evidence

Common questions

Does any law require candidates to disclose that they used AI?

No jurisdiction imposes that duty on an applicant. Disclosure obligations in AI hiring law run from the employer to the candidate, not the other way. An employer can ask for disclosure as a term of its own process, and many do, but the ask is a process rule rather than a legal requirement, and nothing in statute supplies a consequence when it is ignored.

If a candidate lies about not using AI, can we rescind an offer?

That is an employment and contract question rather than an AI law question, and it turns on what was stated, what was signed, and what can be established. The establishing is the hard part: authorship of a document is not reliably provable, so a rescission resting only on suspicion is weak. Where an applicant made an explicit written attestation and independent facts contradict it, the position is different. Take it to counsel with the documents in hand.

Does the EU AI Act say anything about applicants using AI to apply?

It does not. The Act regulates providers and deployers of AI systems, and its recruitment provisions name uses the employer deploys: targeted advertising, filtering applications, evaluating candidates. An applicant using a model to draft a cover letter is not a deployer of a high-risk system in any sense the Act defines. The employer's separate AI literacy duty under the Act reaches its own staff, not candidates.

Do these laws apply if my company is not in New York, Illinois or the EU?

Often, because the trigger is usually the candidate's location or the position's location, not the employer's headquarters. Local Law 144 turns on the NYC candidate, the Illinois video act on Illinois-based positions. A remote req open across many states inherits several regimes at once, which is an argument for building the process to the strictest of them rather than tracking each one per posting.

Does a bias audit make our candidate AI rule defensible?

It answers a different question. A bias audit measures selection rates by category for a tool, and it says nothing about whether the rule you set for applicants was fair, published or applied consistently. A published audit is also a narrow artifact: it reports impact ratios, not validity, so it does not establish that the tool measures the job. Keep the two records separate and do not let one stand in for the other.

What is the single most common mistake HR makes reading these statutes?

Reading them as permission slips. The roundups list obligations, so a team scanning for an answer about candidate behavior finds nothing and concludes the area is unregulated and therefore open. The accurate reading is that the statutes are silent on applicants and specific about employer tooling, so the candidate rule stands or falls on process fairness, while the enforcement tool is where the statutory duties actually bite.

References

  1. 1. Automated Employment Decision Tools: Frequently Asked Questions NYC Department of Consumer and Worker Protection (DCWP), 2023. nyc.gov Supports the claim that Local Law 144's duties (bias audit, posted summary, ten business days of notice) fall on the employer and say nothing about applicant conduct.
  2. 2. HB3773 Enrolled (Public Act 103-0804), amending the Illinois Human Rights Act Illinois General Assembly, 2024. ilga.gov Supports the claim that Illinois holds the employer responsible for AI's discriminatory effect, an effects standard rather than an intent one.
  3. 3. Texas H.B. 149 (89R), Texas Responsible Artificial Intelligence Governance Act, enrolled text Texas Legislature Online, Texas Legislative Council, 2025. capitol.texas.gov Supports the contrast with Illinois: Texas requires intent and forecloses disparate impact as sufficient proof of it.
  4. 4. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) Official Journal of the European Union / Publications Office of the EU, 2024. publications.europa.eu Supports the claim that EU law names employer-deployed recruitment and selection uses as high-risk, and regulates no applicant conduct.
  5. 5. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) Official Journal of the European Union / Publications Office of the EU, 2026. publications.europa.eu Supports the date correction: the AI Act's substantive high-risk requirements now apply from 2 December 2027, so Annex III classification is not yet an operative duty on an employer.
  6. 6. SB26-189 Automated Decision-Making Technology - Bill Summary Colorado General Assembly, 2026. leg.colorado.gov Supports the correction that Colorado's AI Act never took effect and was replaced by a narrower regime commencing in 2027.
  7. 7. Final Unmodified Text of Proposed Employment Regulations Regarding Automated-Decision Systems (Attachment B), 2 CCR sections 11008, 11008.1 California Civil Rights Department, Civil Rights Council, 2025. calcivilrights.ca.gov Supports the claim that a checking tool bought to enforce a candidate rule is itself an automated-decision system, and that the vendor running it is an employer under the Act.
  8. 8. 29 CFR Part 1607 - Uniform Guidelines on Employee Selection Procedures (1978), sections 1607.16(Q) and 1607.3(A) U.S. Government Publishing Office, Code of Federal Regulations (Title 29, Vol. 4, 2023 edition), 1978. govinfo.gov Supports the claim that every stage of a hiring process, including an informal conversation, is a selection procedure and should be documented as one.
  9. 9. Artificial Intelligence Video Interview Act, 820 ILCS 42 Illinois General Assembly, Illinois Compiled Statutes, 2020. ilga.gov Supports the claim that the one place law reaches the candidate is consent to AI analysis of their video, which still regulates what the employer may run.

9 sources, numbered by first appearance. How Olive sources claims

General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.

Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.

Back to answers

Open your first role Ten attempts a month against a live item bank, with a human-written report on every one.