Policy
Five US AI Hiring Laws Bind You Today, and Colorado Is Not One
As of August 2026, five US regimes impose live duties on an employer using AI in hiring: New York City Local Law 144, Illinois HB 3773 amending the Human Rights Act, the Illinois AI Video Interview Act, Maryland's facial-recognition waiver, and California's FEHA automated-decision-system regulations. Texas TRAIGA also applies, but reaches only intentional discrimination. Colorado binds nobody: its 2024 act was repealed before it ever took effect. Underneath all of them sit Title VII, the ADEA and the ADA. Recruiting into the EU adds the AI Act.
The takeMost published compliance maps are worse than no map, because they are stale and do not say so. A page still listing the Colorado AI Act as a June 2026 obligation was written in 2025 and nobody went back to it. Put a date on your own map, re-read it twice a year, and treat an undated checklist as a document about the past. Colorado's statute changed twice inside a year, and the odds of a third revision are not small.
Where Olive fits
Open a role and see what the work shows
Under rules like these, the question a regulator or a plaintiff asks is what the record shows, not what a tool concluded. Olive produces no composite and no automated decision: a person writes each of the six findings, every finding carries the excerpt it rests on, and a released report exports with its rubric and bank versions attached.
Rank your shortlistWhich five regimes actually impose duties today?
Five, and none of them is federal. New York City Local Law 144 bars an employer from using an automated employment decision tool on a city candidate unless a bias audit was done within the prior year, a summary of the results is posted publicly, and the candidate got notice at least ten business days beforehand 1. Illinois adds two separate statutes and Maryland one. California's civil rights regulator amended its discrimination rules to name automated-decision systems outright 4.
Here is the set, with the date each one started binding:
- NYC Local Law 144. In effect since January 1, 2023 and enforced by the Department of Consumer and Worker Protection since July 5, 2023, with statutory civil penalties of $500 to $1,500 a day 1.
- Illinois HB 3773 (Public Act 103-0804), amending the Illinois Human Rights Act as of January 1, 2026. It is a civil rights violation to use AI that has the effect of discriminating on a protected basis, to use zip codes as a proxy for a protected class, or to fail to notify an employee that AI is being used 2. The timing and form of that notice sit in rulemaking, not in the statute.
- The Illinois AI Video Interview Act (820 ILCS 42), in force since 2020. Before AI analyses a recorded video interview for an Illinois-based position, tell the applicant, explain what the system evaluates, and get consent. An applicant who has not consented may not be evaluated that way 3.
- Maryland's facial recognition waiver (Md. Code Lab. & Empl. section 3-717), in force since October 1, 2020. An employer may not use a facial recognition service to create a facial template during an applicant's interview unless the applicant signs a waiver covering their name, the interview date, consent, and whether they read it 10. The statute is narrow: facial templates only, no penalty, no private right of action, and nothing that stops an employer from declining to interview a candidate who will not sign.
- California's FEHA automated-decision-system regulations, effective October 1, 2025. An automated-decision system is a computational process that makes or facilitates a decision about an employment benefit, and the rules name resume screening for terms or patterns, analysis of facial expression, word choice or voice in online interviews, and computer-based assessments of personality or aptitude 4. A vendor running the system counts as an employer under the Act.
Four of the five ask you to act: audit plus notice before the tool runs in New York City, notice under the Illinois Human Rights Act (its timing waits on rulemaking), notice-plus-consent before AI touches a recorded video interview, and a signed waiver before facial recognition runs in a Maryland interview. California changes what has to be proved after someone complains. Sorting obligations that way is more useful than sorting them by state, and it is the first thing to settle when you work out whether a given tool counts as an automated employment decision tool.
This maps US law. Recruiting into the EU adds the AI Act: its AI-literacy duty and its ban on emotion-inference AI in the workplace have applied since February 2025 11, and the high-risk hiring rules arrive December 2027 12.
Why Colorado belongs off your list
Because the statute everyone still cites never applied to anyone. Colorado SB 24-205 was scheduled to start February 1, 2026, pushed to June 30, 2026 by SB 25B-004, and then repealed and reenacted by SB 26-189, which the governor signed on May 14, 2026 5. The replacement is a narrower automated decision-making regime that does not take effect until January 1, 2027.
What the replacement asks for is worth reading now, because the start date is close and the content is not what the 2024 act contained. SB 26-189 names employment as a consequential decision, requires a deployer to give notice at the point of interaction, to provide a plain-language description of the technology's role within 30 days of an adverse outcome, and to honour a request for meaningful human review 5. The 2024 act's duty of care against algorithmic discrimination, its deployer risk-management programs and its impact assessments did not survive into the new text.
So the instruction is narrow. If your AI hiring policy names Colorado as a live obligation with a 2026 date, that paragraph is wrong today, and the repair is a deletion rather than an edit. Diary the January 2027 date, note that a law amended twice inside a year can be amended again, and move the hours you were spending on Colorado onto the five regimes that already reach you.
What the federal floor still requires
Everything on the state map sits on top of Title VII, the ADEA and the ADA, which apply in every state and carry a private right of action. Title VII puts disparate impact in the statute itself at 42 U.S.C. 2000e-2(k): once a plaintiff identifies a particular practice causing the impact, the employer has to show that practice is job related for the position in question and consistent with business necessity 6.
That test is the one an AI hiring tool is most likely to face in a courtroom, and it does not care which state you sit in. It is also why the state statutes read the way they do. Illinois wrote an effects standard straight into its Human Rights Act 2. Texas went the other way: the Responsible Artificial Intelligence Governance Act took effect January 1, 2026 and prohibits developing or deploying an AI system with the intent to unlawfully discriminate, saying expressly that a disparate impact by itself does not demonstrate intent 7. Enforcement there belongs to the attorney general alone, after a 60-day period to cure.
Two consequences follow. First, "compliant with AI hiring law" names no single standard: Illinois asks what the tool did, Texas asks what you intended. Write to the stricter effects standard and the intent standard comes along. Second, federal enforcement posture and federal law are different things, and the gap between them is wider than usual right now. Executive Order 14281, signed April 23, 2025, directs agencies to deprioritize enforcement of disparate-impact liability and names 42 U.S.C. 2000e-2 in the text 9, and the EEOC took its AI technical assistance documents down in late January 2025 8. Every statute behind both stayed where it was.
Run the map against your own stack this quarter
Start with a tool inventory, not a legal memo. List every system that touches a candidate, mark which of them produces an output a human treats as a conclusion, and write down where your candidates actually are. Your office address is not the one that matters. Those two facts, what the tool does and whose state reaches the candidate, decide every question on this page.
Five steps, in the order that saves the most rework:
1. Inventory every candidate-facing system, including the ATS features nobody switched on deliberately and the ones a vendor enabled in an upgrade. 2. For each system, write a one-line classification and the reason for it. The reason is the part that has to survive being read back to you. 3. Check the candidate side of the ledger, not only the company side. A remote posting puts you under the candidate's state law, which is the single most common way a compliance map drawn at headquarters turns out to be the wrong map. 4. Where an audit duty attaches, settle the data question early. Running an adverse impact audit when the vendor holds the data takes months, and it takes longer when the contract says nothing about access. 5. Put the whole thing in one dated document. What belongs in an AI hiring policy is a shorter list than most drafts assume, and naming the person who signs it matters more than the length.
Confirm the classifications with counsel before they go in writing. The classification is the document a regulator or a plaintiff reads first, and it is the one place where a guess written in confidence costs more than a question asked early.
Common questions
Does Local Law 144 apply if the company has no New York office?
It can, but the trigger is the job's location, not the applicant's. The law reaches a role whose job location is a New York City office at least part time, a fully remote role whose associated location is a NYC office, and an employment agency using the tool from the city 1. Once it applies, candidates who are city residents must get the ten-business-day notice. A candidate's home address alone does not pull a role into scope, so the answer lives in where the role sits, and edge cases go to counsel.
Executive Order 14281 deprioritized federal disparate-impact enforcement in 2025. Does the federal floor still matter?
Yes. An executive order directs agencies; it does not repeal a statute 9. 42 U.S.C. 2000e-2(k) is an act of Congress, private plaintiffs can still bring disparate-impact claims, and state and local laws are untouched by federal enforcement priorities 6. What changed is who is likely to bring the case. Fewer agency-initiated investigations means the realistic exposure now runs through private litigation and state regulators, which is exactly the exposure a shift in federal priorities does not reduce.
Does Texas TRAIGA make an AI hiring tool safe to use in Texas?
No. TRAIGA sets an intent standard and says a disparate impact alone does not show intent, which makes it a narrow prohibition rather than a shield. Title VII still applies in Texas on its own terms, and a Texas employee's federal claim runs on the federal standard regardless of what the state statute says. TRAIGA also has no private right of action and imposes no audit, notice or testing duty, so it changes very little about what a hiring team should actually do.
Do these laws reach a tool that only schedules interviews or parses a file?
Usually not, but the classification has to be written down rather than assumed. Local Law 144 reaches tools whose output substantially assists or replaces discretionary decision-making, which a scheduler does not do. The Illinois video statute covers exactly one technology, AI analysis of recorded video interviews. California's rules are broader, since they reach any computational process that facilitates a decision about an employment benefit, so a parser that drops candidates below a threshold is a different question from one that only reformats a document.
How often does this map need re-checking?
Twice a year, plus whenever a vendor ships a feature that changes what a tool decides. The record of the last two years justifies the cadence: an Illinois amendment took effect in January 2026, California's regulations landed in October 2025, and Colorado's statute was delayed once and then repealed and replaced inside nine months. A compliance page written in 2025 and never revisited is now wrong in at least one paragraph, and the wrong paragraph is usually the one about Colorado.
References
- 1. Automated Employment Decision Tools: Frequently Asked Questions nyc.gov Supports the Local Law 144 duties: bias audit within the prior year, posted summary, ten business days of notice, the in-the-city scope test keyed to the job's location, and the enforcement dates and penalty band.
- 2. HB3773 Enrolled (Public Act 103-0804), amending the Illinois Human Rights Act ilga.gov Supports the January 1, 2026 Illinois effects standard, the zip-code proxy ban and the notice obligation.
- 3. Artificial Intelligence Video Interview Act, 820 ILCS 42 ilga.gov Supports the Illinois notice-explain-consent requirement before AI analyses a recorded video interview.
- 4. Final Unmodified Text of Proposed Employment Regulations Regarding Automated-Decision Systems (Attachment B), 2 CCR sections 11008, 11008.1 calcivilrights.ca.gov Supports the October 1, 2025 effective date, the definition of an automated-decision system, its named examples, and the vendor-as-employer clause.
- 5. SB26-189 Automated Decision-Making Technology - Bill Summary leg.colorado.gov Supports the claim that Colorado SB 24-205 never took effect and was repealed and reenacted as a narrower regime starting January 1, 2027.
- 6. 42 U.S.C. 2000e-2(k) - Burden of proof in disparate impact cases uscode.house.gov Supports the federal disparate-impact test: job related for the position in question and consistent with business necessity.
- 7. Texas H.B. 149 (89R), Texas Responsible Artificial Intelligence Governance Act, enrolled text capitol.texas.gov Supports the Texas intent standard, the express statement that disparate impact alone does not show intent, and attorney-general-only enforcement.
- 8. Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII of the Civil Rights Act of 1964 (archived capture, 2025-01-25) web.archive.org Supports the claim that the EEOC's AI technical assistance documents came off eeoc.gov in late January 2025 while the statutes behind them stayed in force.
- 9. Executive Order 14281 of April 23, 2025 - Restoring Equality of Opportunity and Meritocracy govinfo.gov Supports the April 23, 2025 direction that agencies deprioritize disparate-impact enforcement, including under 42 U.S.C. 2000e-2, and that an executive order does not repeal the statute.
- 10. Chapter 446 (House Bill 1202), Labor and Employment - Use of Facial Recognition Services - Prohibition, Md. Code Lab. & Empl. section 3-717 mgaleg.maryland.gov Supports the Maryland waiver requirement before a facial recognition service creates a facial template during an applicant's interview, its October 1, 2020 start, and the absence of a penalty or a private right of action.
- 11. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) publications.europa.eu Supports the Article 4 AI-literacy duty on deployers and the Article 5(1)(f) prohibition on inferring emotions in the workplace, both applying since 2 February 2025.
- 12. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) publications.europa.eu Supports the deferral of the high-risk hiring rules in Annex III point 4 to 2 December 2027, and the fact that the deferral left the prohibitions and the literacy duty untouched.
12 sources, numbered by first appearance. How Olive sources claims
General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.
Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.