In minutes, not weeks.

Compliance & Legal

AI Hiring Compliance: NYC Local Law 144, the EU AI Act, and What's Coming Next

What companies using AI in hiring need to audit, document, and disclose in 2026 — and how to avoid six-figure penalties

Upstack AI ResearchMay 8, 202613 min read
  • Home
  • Insights
  • AI Hiring Compliance: NYC Local Law 144, the EU AI Act, and What's Coming Next
Back to all insights
€35M
Max EU AI Act fine
Or 7% of global revenue
$500–$1,500
NYC LL144 per-violation
Per day, per candidate
8
US states with AI hiring laws
As of mid-2026
70%
Companies non-compliant
Industry self-assessment

Why This Matters in 2026

Through 2024 and most of 2025, AI hiring regulation was a checkerboard of state and city laws — easy to ignore if you weren't operating in New York City or Illinois. That changed when the EU AI Act's high-risk system requirements took effect in February 2026, classifying most hiring AI as "high risk" and pulling any company that hires in the EU into scope.

Simultaneously, US state-level laws have multiplied. Colorado's AI Act, California's automated decision-making rules under CCPA, and similar legislation in Illinois, Maryland, New Jersey, Texas, Washington, and Virginia create a patchwork that's effectively impossible to dodge if you hire across state lines.

United States

NYC Local Law 144: The Original Template

In effect since July 2023, NYC's Automated Employment Decision Tools (AEDT) law applies to any employer using an AEDT to screen candidates for positions located in NYC, regardless of where the employer is headquartered.

What it requires

  • Annual bias audit by an independent auditor, covering sex, race/ethnicity, and intersectional categories
  • Public summary of audit results posted on the employer's website
  • 10 business days notice to candidates before AEDT use, with information about the tool and characteristics it evaluates
  • Alternative selection process available on candidate request

What counts as an AEDT

Any computational process using machine learning, statistical modeling, or AI that issues a simplified output (score, classification, recommendation) used to substantially assist or replace discretionary decision-making. This intentionally captures more than just "AI" — even classical statistical screening tools are in scope.

Penalties: $500 for first violations, up to $1,500 for subsequent violations, per day, per affected candidate.

European Union

EU AI Act: The Highest Stakes

The EU AI Act classifies any AI system used in recruitment or selection of natural persons as a "high-risk" system. This includes:

  • AI used to target job advertisements
  • AI used to analyze and filter job applications
  • AI used to evaluate candidates during interviews or assessments
  • AI used to make promotion, termination, or task allocation decisions

High-risk system obligations

  • Risk management system documented and maintained throughout the AI lifecycle
  • Data governance demonstrating training, validation, and test datasets are relevant, representative, and free of statistical biases
  • Technical documentation sufficient to assess compliance — model architecture, training process, performance metrics, known limitations
  • Logging of system operation enabling traceability and post-incident analysis
  • Transparency to deployers and candidates about AI use, capabilities, and limitations
  • Human oversight measures designed into the system — meaningful, not rubber-stamp
  • Accuracy, robustness, and cybersecurity appropriate to the intended purpose

Penalties scale with severity: prohibited AI uses carry fines up to €35M or 7% of global annual revenue, whichever is higher. High-risk obligations: €15M or 3%.

The EU AI Act applies extraterritorially. A US-headquartered company using AI hiring tools to screen candidates for EU-based roles is fully in scope — regardless of where the AI vendor or the candidate data resides.

United States

US State Law Patchwork

Beyond NYC, an expanding list of US states regulates AI in hiring:

  • Illinois — AI Video Interview Act requires consent, explanation of how AI works, and limits on data retention
  • Maryland — Facial recognition in job interviews requires written consent
  • Colorado — AI Act (effective 2026) creates duties of care for developers and deployers of high-risk AI systems including employment tools
  • California — CCPA automated decision-making regulations require disclosure and opt-out rights
  • Texas, Washington, Virginia, New Jersey — varying disclosure and consent requirements

The trend is unmistakable: by 2027, federal employment AI legislation in the US is increasingly likely, and the floor is rising in the meantime.

Compliance Requirements at a Glance

JurisdictionTriggerKey RequirementMax Penalty
EU AI ActAI in hiring (high-risk)Risk mgmt, documentation, human oversight, audit€35M / 7% revenue
NYC LL144AEDT for NYC rolesAnnual independent bias audit, candidate notice$1,500/day/candidate
Colorado AI ActHigh-risk AI deploymentImpact assessment, transparency, anti-discriminationPer-violation civil
Illinois AIVIAAI video interviewsConsent, explanation, retention limitsCivil penalties
California CCPA/CPRAAutomated decision-makingDisclosure, opt-out, access rights$7,500/intentional
GDPR Article 22Solely automated decisionsRight to human review, explanation€20M / 4% revenue
Action

The 7-Item Compliance Checklist

Whatever AI you use in hiring — vendor-provided or internally built — you need answers to these seven questions before an audit or regulator asks.

  1. Inventory. What AI tools are used in any stage of your hiring funnel? Include resume parsers, ranking systems, AI chatbots, interview scoring tools, and any predictive models.
  2. Classification. Which jurisdictions do your hiring activities touch? Each tool gets mapped to applicable laws (EU AI Act, NYC LL144, state AI laws).
  3. Bias audit. Is each AI tool independently audited at least annually? Are results documented and, where required, published?
  4. Notice & consent. Are candidates clearly informed before AI evaluation, including characteristics evaluated and source data?
  5. Human oversight. Is there meaningful human review of AI outputs before adverse hiring decisions? "Meaningful" rules out rubber-stamp approvals.
  6. Logging & documentation. Do you retain logs of AI evaluations, model versions, and decision rationale for audit and litigation defense?
  7. Vendor compliance. Have you obtained EU AI Act compliance documentation, bias audit reports, and DPAs from every AI vendor in your hiring stack?

The most common compliance gap isn't building biased AI. It's failing to document that the AI was tested for bias, that humans review the outputs, and that candidates were notified. Documentation — not algorithm quality — is what regulators audit first.

What to Demand From Your AI Hiring Vendors

If you license AI hiring tools (rather than building them), most of the technical compliance burden sits with your vendor. But the deploying employer remains liable in most jurisdictions. Before signing or renewing:

  • Request the vendor's EU AI Act conformity assessment and CE marking documentation (where applicable)
  • Request the most recent independent bias audit report — not vendor self-attestation
  • Confirm the vendor provides candidate-facing notices that meet NYC LL144 and similar state requirements
  • Confirm the vendor's training data does not include legally protected characteristics, and that adverse impact analysis is conducted regularly
  • Negotiate indemnification clauses for compliance failures that originate in the vendor's system
  • Confirm the vendor's data processing meets GDPR / CCPA standards and that DPAs are in place
Transform Your Hiring

Ready to Solve These
Hiring Challenges?

See how Upstack addresses the core problems identified in this research — ranking 1,000 applicants in under an hour, with 87% less time reviewing and 30% faster time-to-hire.

Our Compliance & Security Standards

GDPR
CCPA
EU AI Act Aligned
Regional Hosting
AES-256
TLS 1.3

Hosted on AWS infrastructure with SOC 2 Type II & ISO 27001 certified data centers — with data residency available across EU, Middle East, and other regions

Across WorkLab and LearnLab, our AI assists — it does not replace — human hiring, grading, and academic decisions. The "EU AI Act Aligned" badge reflects alignment with the Act's principles by design — transparency, human oversight, and documentation — not a certification. Learn more.

Upstack.AIUpstack.AI

Filter the noise. Interview real candidates. One link works anywhere—no ATS migration needed.

Upstack AI FZ-LLC
FOAM2471, Compass Building
Al Shohada Road, AL Hamra Industrial Zone-FZ
Ras Al Khaimah, United Arab Emirates

Microsoft Store
Publisher: UPSTACK AI
Store ID: 9NT2GR4TDZ0G

© 2022 - 2025 Upstack.AI • All Rights Reserved

Powered By

React
TypeScript
Tailwind
Python
AWS
SSL

Last updated: 21/1/2026