Skip to main content
HR Software ToolsSnackNation Office

AI and HR Compliance: What Employers Need to Know

By October 2nd, 2026


AI HR compliance is the set of legal obligations that apply when a company uses software to screen, score, rank, or make decisions about candidates and employees. It’s governed by a patchwork of state and city laws rather than one federal standard, and most cover far more tools than people expect, including features that shipped inside an existing ATS or HRIS without anyone deciding to “adopt AI.”

We work with thousands of People teams at SnackNation, and lately one topic comes up in nearly every conversation: AI. Resume-screening software, chatbot interviewers, automated scheduling tools, and AI-assisted performance reviews are now standard parts of many HR tech stacks, often installed by teams who never made an explicit decision to “adopt AI.” It just shipped as a default feature in the platforms they already used. That shift has created a fast-growing category of risk that barely existed in this form a few years ago, and most of the HR leaders we talk to are flying blind on it.

This area of law is moving fast, and it isn’t going to sit still. Colorado’s original AI law is a good example: it passed in 2024, was delayed more than once, and was ultimately scrapped and rewritten from scratch. Treat the state-specific details below as a snapshot, not a permanent rulebook, and confirm anything you’re relying on against a current source before you act on it.

This guide covers what counts as “AI” under these laws, the compliance gaps employers most often miss, a practical checklist you can act on today, and where the state-by-state rules currently stand, including how a free tool like EasyLlama’s Compliance Grader can show you exactly what applies to your organization in about two minutes. 

 

Why AI HR Compliance Is Hard to Ignore Right Now

AI adoption in HR has outpaced most companies’ compliance processes. Recruiting teams use algorithmic screening to manage high applicant volume, performance tools use predictive scoring, and many HRIS and applicant tracking platforms now ship with AI features turned on by default. Recent SHRM research on AI in HR points to the same pattern across the profession: usage is climbing while governance lags behind it.

At the same time, there’s no single federal AI hiring law filling the gap. States and cities are legislating independently, and often differently, which means a company with employees or candidates in more than one state can face several distinct sets of obligations at once, and that patchwork keeps shifting under everyone’s feet. AI HR compliance can’t be treated as a policy you write once and file away. It has to be checked, updated, and documented on an ongoing basis, which is a big part of why the gaps and checklist below matter more than memorizing any single state’s statute.

 

What Counts as “AI” Under HR Compliance Law

Most of these laws don’t limit themselves to generative AI chatbots. They use broad terms like automated decision system (ADS) or automated employment decision tool (AEDT), and those definitions typically capture far more than people expect, including: resume-screening algorithms that rank or score candidates, chatbots that ask screening questions and pass or fail candidates automatically, video-interview tools that score speech patterns, word choice, or facial expressions, skills-assessment platforms that generate a numeric or percentile score, scheduling or shift-assignment software that factors performance data into promotion or discipline decisions, and algorithmic tools that flag employees for discipline or termination based on patterns in workplace data.

If a piece of recruiting or HR software touches ranking, scoring, filtering, or recommending people, it’s very likely captured by at least one of these laws, whether or not the vendor markets it as “AI.”

 

Common AI HR Compliance Gaps We’re Seeing


This is where most of the real risk sits, and it’s the part of this guide that won’t go out of date the way a specific statute’s effective date will.

  • No inventory. Most HR teams we talk to can’t produce a complete list of every tool touching recruiting, hiring, scheduling, performance, or discipline that scores, ranks, or filters people. That includes features buried inside an existing ATS or HRIS that nobody signed off on as “AI” because it just showed up in a product update.
  • Assuming the vendor carries the liability. Several states now make this explicit in their statutes, but the underlying logic applies everywhere: using a vendor’s AI tool doesn’t transfer legal responsibility away from the employer using it. If the tool makes a biased decision, the company that deployed it is the one answering for it, not the software company that built it.
  • Missing or informal notice. A number of laws require specific, plain-language notice before or after AI is used in a decision. A generic line buried in a privacy policy usually won’t satisfy that requirement, and teams are often surprised to learn their existing disclosures don’t count.
  • No bias-audit trail. Even in places where a bias audit isn’t strictly required, not having one can be used against an employer later if a discrimination claim surfaces. An audit trail is cheap insurance relative to the alternative.
  • No human-review path. Newer laws increasingly require a way for an affected candidate or employee to request human review of an AI-assisted decision, and most companies have no documented process for that at all, which means even a willing manager wouldn’t know how to handle the request if one came in.
  • Vendor contracts that don’t cover any of this. Standard software agreements rarely include representations about bias testing, audit rights, or indemnification for AI-related discrimination claims. Renewal time is usually the easiest moment to fix this, but most teams don’t think to ask.

 

A Practical AI HR Compliance Checklist

Use this as a working checklist you revisit, not a one-time exercise. This is the part of the guide worth bookmarking.

  1. Inventory every recruiting, hiring, performance, scheduling, and discipline tool that scores, ranks, filters, or recommends, including features built into your ATS or HRIS that you might not think of as “AI.”
  2. Map each tool against the laws that apply based on where your employees and candidates are located, not just where your company is headquartered.
  3. Build, or request from vendors, documentation of anti-bias testing, even where it isn’t legally mandatory in your jurisdictions.
  4. Put required candidate and employee notices in plain, accessible language and deliver them on the timeline each applicable law requires.
  5. Create a documented process for human review of AI-assisted decisions, and make sure managers actually know it exists and how to route a request.
  6. Set records-retention rules that match the longest applicable requirement in your footprint.
  7. Review vendor contracts for compliance-related representations, audit rights, and indemnification language, and flag gaps before your next renewal.
  8. Revisit this whole list at least twice a year. Several of these laws didn’t exist eighteen months ago, and more than one has already changed since it first passed.

If you want a faster starting point than working through this list cold, EasyLlama’s Compliance Grader asks a few questions about your industry, location, and workforce and returns a personalized report in about two minutes, showing which laws apply to your business and where your specific gaps are.

 

The State-by-State Landscape, In Brief

The details below are current as of September 2026 and will be amended, delayed, or replaced before long — confirm anything you’re relying on against a live source, like counsel or the Compliance Grader, before acting on it.

New York City, Local Law 144. In effect since July 2023. Applies to employers using an automated employment decision tool to substantially assist a hiring or promotion decision connected to NYC. Requires an annual independent bias audit, published results, and at least 10 business days’ notice before use. Fines run from $500 for a first violation up to $1,500 for each one after.

Illinois, HB 3773. Effective January 1, 2026. Holds employers strictly liable for discriminatory outcomes from AI tools regardless of intent, bans using zip code as a stand-in for a protected class, and requires plain-language notice whenever AI plays a role in hiring, promotion, discipline, or termination. Using a third-party vendor’s tool does not shift responsibility away from the employer.

California, FEHA automated-decision-system rules. Effective October 1, 2025. Defines an automated-decision system broadly enough to include resume screeners, rejection chatbots, video-interview scoring, and algorithmically graded skills tests. Requires four years of recordkeeping on ADS-related data and scores. Bias testing isn’t strictly mandatory, but its absence can work against an employer defending a discrimination claim.

Colorado, Automated Decision-Making Technology Act (ADMTA). A rewritten replacement for Colorado’s original AI Act, which never took effect and was repealed. Signed May 2026, expected to take effect January 1, 2027 pending state rulemaking. Centers on disclosure: advance notice, disclosure of the tool’s role within 30 days of an adverse decision, a right to request human review, and three years of records retention.

Texas, Responsible AI Governance Act (TRAIGA). Effective January 1, 2026. Uses an intent-based standard rather than a disparate-impact one, meaning an unequal outcome alone isn’t automatically a violation. Doesn’t require employee disclosure, and is enforced only by the Texas Attorney General with a required notice-and-cure period before penalties apply.

This section moves fast; treat it as a snapshot and confirm current requirements against a live source before acting on any of it.

 

What This Means for Multi-State Employers

If your company hires or employs people in more than one of these jurisdictions, and most mid-size and larger organizations do, a single AI HR policy written for one state’s rules probably won’t satisfy the others. A tool that’s fine to use in Texas under TRAIGA’s intent-based standard could still trigger a bias-audit and notice obligation the moment it touches a candidate in New York City, and a different notice requirement again if that candidate is in Illinois or California.

The practical fix isn’t five separate policies. It’s one AI governance framework, built around the strictest applicable requirement in each category (notice, audit, retention, human review), applied consistently, then layered with jurisdiction-specific notice language where the wording itself is legally mandated.

 

Where Federal Guidance Stands Right Now

The federal picture has moved in the opposite direction from the states. The EEOC’s May 2023 technical guidance on how existing anti-discrimination law applies to AI in hiring was removed from public posting on January 27, 2025, and two Department of Labor resources on AI in hiring were pulled from public availability around the same time. The Office of Federal Contract Compliance Programs’ April 2024 guidance for federal contractors is still posted, but it’s non-binding.

In practice, that means there’s no single, current federal standard employers can point to for AI HR compliance. The real compliance floor right now is set state by state, and in New York City’s case, city by city, which is exactly why a one-size-fits-all national policy isn’t enough.

 

Building AI Literacy Into Compliance Training

Knowing the law is only step one. HR and compliance teams still need to translate it into behavior across the organization: managers who understand they can’t rely solely on an algorithm’s recommendation without documenting a human review, recruiters who know exactly what a mandated candidate notice needs to say and when to send it, and employees who understand what is and isn’t an acceptable use of generative AI tools at work. Drafting a job description with an AI writing assistant is a very different risk than feeding candidate resumes into a public chatbot.

Effective AI compliance training programs typically combine role-based content (since what an HR generalist needs to know is different from what a hiring manager or a recruiter needs), documentation habits that teach people to log decisions and rationale rather than just outcomes, and refreshers timed to legal changes rather than a fixed annual schedule, given how quickly this area continues to move.

 

Where EasyLlama’s Compliance Grader Fits In

Most of the gaps above come down to one underlying problem: HR teams don’t have a fast way to know which rules actually apply to their specific business. The EasyLlama Compliance Grader is a free tool, no credit card required, that asks a few questions about your industry, location, and workforce, then returns a personalized report in about two minutes.

The report shows which compliance laws currently apply to your business by industry, location, and role, which training is legally required versus simply recommended, and exactly which risk gaps you need to close, so you’re not left guessing or digging through dozens of states’ worth of legislation on your own. For AI-specific compliance, that means seeing at a glance whether your business falls under Local Law 144’s bias-audit requirement, Illinois’s or California’s notice obligations, or the incoming Colorado disclosure rules, all in one place.

 

Frequently Asked Questions

Q: Which states regulate AI in hiring in 2026?

A: New York City (Local Law 144), Illinois (HB 3773), California (FEHA automated-decision-system rules), and Texas (TRAIGA) all have requirements in effect as of 2026. Colorado’s ADMTA is signed but not expected to take effect until January 1, 2027. More states are expected to introduce similar bills, so this list will keep growing.

Q: Is it legal for employers to use AI in hiring? 

A: Yes, in most places, but a growing number of states and cities attach specific conditions, such as bias audits, notice requirements, or human-review rights. Whether a given use is compliant depends on where your employees and candidates are located and how the tool is used.

Q: What is an automated employment decision tool (AEDT)? 

A: An AEDT, sometimes called an automated-decision system depending on the law, is software that uses a computational process, including but not limited to machine learning, to score, rank, filter, or recommend candidates or employees in a way that substantially assists an employment decision.

Q: Do all states require bias audits for AI hiring tools? 

A: No. New York City’s Local Law 144 requires an annual independent bias audit. California strongly encourages bias testing without mandating it. Texas doesn’t require bias audits at all and instead focuses on whether the AI was deployed with discriminatory intent.

Q: What is the current federal stance on AI in hiring? 

A: There’s no single binding federal AI-hiring standard in force right now. The EEOC removed its 2023 AI technical guidance in January 2025, leaving state and local laws as the primary compliance floor for most employers.

Q: How often should companies audit their AI hiring tools for bias? 

A: At minimum, annually where required by law, and any time a tool changes materially, such as a vendor update to its underlying model or scoring criteria. Regular audits are good practice even where they aren’t legally required.

Q: What happens if a company doesn’t comply with AI employment laws? 

A: Consequences vary by law and by jurisdiction, and they change as laws are amended, so check current penalties for your specific footprint rather than relying on a fixed number. Reputational and litigation risk from a discrimination claim tends to outlast any single statutory fine.

Q: How can HR teams prepare for AI compliance? 

A: Start with an inventory of every tool that scores, ranks, or filters people, map it against the laws in every state where you have employees or candidates, and use a resource like the Compliance Grader to confirm exactly what’s required for your specific business before updating your training program.

Q: Does using a third-party AI vendor reduce an employer’s compliance risk? 

A: Generally, no. Multiple states now make clear that deploying a vendor’s tool doesn’t shift legal responsibility away from the employer. Employers are expected to vet vendors, request evidence of bias testing, and document their own compliance steps regardless of who built the underlying technology.

 

The Bottom Line

AI isn’t slowing down in HR, and neither is the legislation trying to keep up with it. The specific laws in this guide will keep changing. The employers in the strongest position are the ones who stop treating that as a reason to wait and start treating AI HR compliance as an ongoing operational habit: know your tools, know your gaps, document your process, and revisit it regularly.

Start with a clear picture of what actually applies to your business. Run your organization through the EasyLlama Compliance Grader to see exactly which AI-related training and policies you need, then build the documentation habits that will hold up if a regulator or a plaintiff’s attorney ever asks.

Leave a Reply

Skip to content
Share via
Copy link
Powered by Social Snap
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.