compliance

AI Hiring Laws in 2026: What Talent Teams Actually Have to Do

·9 min read

The short answer

If a tool influences who advances in your hiring process, four sets of rules now apply depending on where you hire: New York City requires an annual independent bias audit and advance notice; the EU classifies recruitment AI as high-risk, with obligations that began applying in August 2026; Colorado and Illinois require notice, impact assessment and a ban on discriminatory outcomes; and US federal law already holds you liable for disparate impact regardless of who built the tool.

  • The obligations fall on you as the employer using the tool, not only on the vendor. "The vendor said it was audited" is not a defence.
  • Every regime needs the same three things: tell candidates, be able to explain the basis of a decision, and show someone checked the tool for group-level disparities.
  • Tools that score against a visible rubric with a human reviewing outcomes are straightforward to comply with. Tools that rank from an opaque model are not.
  • Start with an inventory: list every tool that touches a hiring decision, what it decides, and which of your candidates are in a covered jurisdiction.

Cohesyve is our product. Its scoring is rubric-based and every result is reviewable, which is the shape these rules reward.

This is a practitioner's summary written for talent teams, not legal advice. The rules below are moving, enforcement practice is still forming, and the right answer for your organisation depends on where you hire, where your candidates are, and what your tools actually do. Use this to know what to ask; confirm the answers with counsel.

Why this got serious in 2026

For most of the last decade, AI in hiring was governed by general anti-discrimination law and not much else. That changed in three steps. New York City's Local Law 144 came into force in 2023 and established the template: audit, publish, notify. The EU AI Act was adopted in 2024 and put recruitment squarely in its high-risk category, with the obligations for those systems applying from August 2026. And a run of US state laws, led by Colorado and Illinois, extended notice and anti-discrimination duties to AI in employment decisions from 2026.

The practical effect is that a talent team can no longer treat a screening or assessment tool as a vendor's problem. In every one of these regimes, the employer that uses the tool carries obligations of its own.

New York City: Local Law 144

Who it covers. Employers and employment agencies using an "automated employment decision tool" to substantially assist or replace discretionary decisions about hiring or promotion for candidates or employees in New York City. The definition is broad enough to reach résumé-ranking tools, matching tools and many assessment products.

What you have to do.

  • Commission an independent bias audit of the tool no more than one year before you use it, and every year after. The audit calculates selection or scoring rates and impact ratios by sex, race and ethnicity, including intersectional categories.
  • Publish a summary of the most recent audit results on your careers site.
  • Give candidates notice at least ten business days before the tool is used, including the job qualifications and characteristics the tool will assess, and information on how to request an alternative process or accommodation.
  • Make available, on request, information about the data the tool collects and how it is used.

What it looks like in practice. Vendors selling into New York already commission these audits and can supply them; ask for the most recent one and check the date. The notice is usually a paragraph in the job posting or application flow. The part teams miss is that the audit has to be repeated annually and that the employer, not the vendor, is the one penalised for a lapse.

Cohesyve

See what candidates can do before you interview them

Cohesyve turns a job description into a role-specific assessment with a scoring rubric. Each candidate gets a different version, so questions cannot be shared. Ten candidates free, no card.

European Union: the AI Act

Who it covers. Anyone placing an AI system on the EU market or using one in the EU, with obligations split between providers, who build the system, and deployers, who use it. AI used for recruitment and selection, including targeting job advertisements, filtering applications and evaluating candidates, is classified as high-risk. So are systems used for promotion, termination, task allocation and performance monitoring.

What deployers have to do, with the high-risk obligations applying from August 2026:

  • Use the system in line with the provider's instructions and assign human oversight to people who are competent, trained and have the authority to intervene.
  • Make sure the input data you feed it is relevant and representative for the purpose.
  • Monitor the system's operation and keep the logs it generates for at least six months.
  • Inform workers' representatives and affected workers before putting the system into use.
  • Tell individuals that they are subject to a decision made with a high-risk AI system, and be able to provide a clear explanation of the system's role in the decision on request.
  • Carry out a data protection impact assessment where GDPR requires one, which for candidate data it usually does.

What providers have to do. Risk management, data governance, technical documentation, logging, transparency, human-oversight design, accuracy and robustness requirements, a conformity assessment, and registration in the EU database. As a buyer, the practical question is whether your vendor can show you that documentation. If they cannot, the system may not be lawfully placed on the EU market at all.

One prohibition worth knowing. Emotion-recognition systems in the workplace and in education have been prohibited outright since February 2025, with narrow exceptions for medical and safety uses. Some video-interview products have historically included facial or vocal emotion analysis. Check.

Penalties. Breaches of high-risk obligations carry fines of up to fifteen million euros or three percent of global annual turnover, whichever is higher. Prohibited practices carry higher ceilings.

Colorado: the Artificial Intelligence Act

Who it covers. Developers and deployers of "high-risk artificial intelligence systems", meaning systems that make or are a substantial factor in consequential decisions, including employment decisions, affecting Colorado residents. The law was signed in 2024, its start date was pushed back by the legislature in 2025, and it took effect in mid-2026.

What deployers have to do.

  • Use reasonable care to avoid algorithmic discrimination, with a rebuttable presumption of reasonable care if you follow the statute's programme.
  • Maintain a risk-management policy and programme for the system.
  • Complete an impact assessment before deployment and at least annually, and after any substantial modification.
  • Notify individuals before a consequential decision is made using the system, and after an adverse decision explain the principal reasons, provide an opportunity to correct the data, and provide an opportunity to appeal for human review.
  • Publish a statement describing the high-risk systems you deploy and how you manage discrimination risk.

Enforcement is by the state Attorney General. Small deployers have some exemptions; check the current thresholds.

Illinois

Illinois has two relevant rules. The Artificial Intelligence Video Interview Act, in force since 2020, requires employers using AI to analyse video interviews to notify applicants, explain how the AI works and what characteristics it evaluates, obtain consent, limit sharing of the video, and delete it on request. It also requires demographic reporting if AI is used to decide who gets an in-person interview.

More broadly, an amendment to the Illinois Human Rights Act effective January 2026 makes it a civil-rights violation to use AI in recruitment, hiring, promotion or similar decisions in a way that has a discriminatory effect on protected classes, or to use zip codes as a proxy for protected characteristics. It also requires employers to notify employees when AI is used for those decisions.

United States federal law

There is no federal AI hiring statute, but it would be a mistake to read that as an absence of rules. Title VII of the Civil Rights Act, the Americans with Disabilities Act and the Age Discrimination in Employment Act all apply to decisions made with the help of a tool exactly as they apply to decisions made without one. Disparate impact liability does not depend on intent, and the employer is liable even when a vendor designed the tool.

The EEOC published technical assistance in 2023 explaining how it would apply Title VII to algorithmic tools, including the long-standing four-fifths rule of thumb for spotting adverse impact. That guidance was later withdrawn under a change of administration. The underlying law was not. Plaintiffs and state agencies continue to use the same yardstick, and litigation against employers and vendors over algorithmic screening is active.

Two federal points are easy to miss. Under the ADA, a tool that screens out someone because of a disability, or that a disabled candidate cannot fairly complete, creates liability regardless of how well the tool performs for everyone else; you need an accommodation path. And any tool that infers age from graduation dates or years of experience is a straightforward age-discrimination exposure.

Elsewhere

The UK relies on existing equality and data-protection law rather than an AI statute, and the data-protection regulator has published guidance on AI in recruitment that reads like a compliance checklist. Canada, Australia and several other jurisdictions are somewhere on the same path. If you hire globally, assume that notice, explanation and impact checking will be expected everywhere within a few years, and design for that once rather than jurisdiction by jurisdiction.

The common thread

Strip away the differences and every regime asks for the same three things.

  1. Tell people. Candidates should know a tool is used, what it assesses, and how to ask for an alternative or an explanation.
  2. Be able to explain. For any individual decision, someone should be able to say what the tool measured and how that fed into the outcome. This is where opaque ranking models struggle and rubric-based scoring does not.
  3. Check for disparity. Selection or scoring rates by group should be measured, by someone independent where the law requires it, on a schedule, with results kept.

Tools differ enormously in how easy they make this. An assessment that scores a work sample against a written rubric, with a person reviewing outcomes, produces an explanation for free and makes a bias audit a matter of arithmetic. A model that ranks résumés on learned patterns produces neither, and no amount of process on your side fixes that.

A working checklist

  • Inventory. List every tool that touches a hiring decision: sourcing, screening, matching, scheduling, assessment, video interview, background check. For each, write down what it decides or influences.
  • Map jurisdictions. For each tool, note whether any candidates it touches are in New York City, the EU, Colorado or Illinois. Remote roles often are.
  • Collect vendor documentation. Bias audit with date; EU conformity documentation if applicable; a plain description of what the tool measures; the data it collects and retains.
  • Write the notices. Job-posting language for NYC; pre-use notice for Colorado and the EU; consent flow for video analysis in Illinois. Keep them in one place with a version date.
  • Assign human oversight. Name the people who review outcomes, make sure they can override the tool, and record that they have been trained on what it does.
  • Build the explanation path. Decide how a candidate's request for reasons is answered and who answers it. Test it with a real past decision.
  • Schedule the audit. Annual, on the calendar, with the summary published where the law requires and kept where it does not.
  • Provide an alternative. A route for candidates who need an accommodation or decline the tool, and a person who owns it.
  • Retain records. Logs, audits, notices and decisions for the periods the applicable laws require; six months is the EU minimum for logs, and several years is prudent for audits.

Common questions

Do these rules apply if a person makes the final decision? Usually yes. Most of the regimes cover tools that substantially assist a decision, not only tools that make it. If a person only ever sees the candidates a tool ranked highly, the tool is deciding.

Our vendor says the tool is compliant. Is that enough? No. The vendor's obligations are theirs; yours are yours. Ask for the documentation, keep it, and do your own notices, oversight and records.

Do skills assessments count as automated employment decision tools? Often, yes, particularly if they score automatically and the score influences who advances. The compliance burden is lighter when the scoring is transparent and reviewed, but the notice and audit duties can still apply.

We are a small company. Does any of this apply? New York City's law has no size threshold. The EU AI Act applies to any deployer. Colorado has some small-deployer exemptions. Federal anti-discrimination law applies from fifteen employees. Assume yes and check the exemptions rather than the reverse.

What is the single most useful thing to do this quarter? The inventory. Most teams discover they are using more tools that influence decisions than they thought, and the rest of the checklist follows from knowing what is in scope.

Cohesyve · Skill assessments for hiring

See what candidates can do before you interview them

Cohesyve turns a job description into a role-specific assessment with a scoring rubric. Each candidate gets a different version, so questions cannot be shared between applicants.

1,500+

assessments completed

50%

faster time-to-hire

90%

completion rate

5 min

from JD to assessment

No credit card · 10 free candidates · Plans sized to your hiring volume

For candidates

Preparing for a role like this yourself? Practise on the same AI job simulations companies use — 5 free assessments a month, no card required.

See Cohesyve in action

Free 30-min walkthrough

See it on your role