
- In 2024 alone, AI-powered hiring tools processed over 30 million applications while triggering hundreds of discrimination complaints, according to Akerman LLP’s AI hiring compliance analysis. This is already happening.
- Employers are fully liable for discriminatory outcomes produced by AI tools they purchased from vendors. “The algorithm did it” is not a legal defense under Title VII, the ADA, or the ADEA.
- The legal landscape in 2026 is a patchwork: six states and one city have active AI hiring requirements, a seventh (California CCPA ADMT) takes effect in 2027, and federal legislation to harmonize these requirements is expected by late 2026 or early 2027.
- The Trump administration’s April 2025 executive order reduced federal disparate impact enforcement. It did not change private litigation rights, state-level enforcement, or the underlying federal statutes. Legal risk has not decreased. The source of risk has shifted from federal enforcement to private lawsuits and state AGs.
- Five concrete compliance obligations every HR team should have in place: employer liability documentation, regular bias audits using the four-fifths rule, candidate disclosure where required, human review before AI decisions, and vendor due diligence.
- This is informational content, not legal advice. Consult qualified employment counsel before finalizing your AI compliance program.
The legal conversation about AI in hiring changed character in 2025. What had been primarily a research and ethics discussion became an active litigation landscape.
In 2024 alone, AI-powered hiring tools processed over 30 million applications while triggering hundreds of discrimination complaints. Courts have accepted class action status in Mobley v. Workday.
State legislatures have passed new laws in Illinois, Texas, New Jersey, and Colorado. The CPPA in California finalized ADMT rules taking effect in 2027.
HR leaders who built their AI compliance posture around federal EEOC enforcement are now operating in a different environment.
State AI hiring tool regulations are filling the federal void, as Reed Smith’s employment law team noted in April 2026.
The regulatory gap left by reduced federal enforcement has been occupied by state-level action and private litigation that operates independently of executive priorities.
This guide covers the complete legal and ethical landscape: what the law actually requires, where the political changes have and have not changed the liability picture, the state-by-state requirements, vendor liability, and the practical compliance obligations every HR team should have in place.
- The Federal Framework That Has Not Changed
- The Political Complication: What Changed and What Did Not
- The State-Level Patchwork in 2026
- Vendor Liability: The Changing Picture
- The Five Practical Compliance Obligations
- Building a Defensible AI Hiring Program
- The Cluster Articles: Where to Go Deeper
- Frequently Asked Questions
- Conclusion
The Federal Framework That Has Not Changed
The executive branch changes its priorities. Congress has not repealed the statutes.
Three federal laws remain fully in force and fully applicable to AI-assisted hiring in 2026.

Title VII of the Civil Rights Act (1964)
Title VII prohibits discrimination based on race, color, religion, sex, and national origin in any employment decision, including hiring.
The EEOC’s 2023 technical assistance document (later removed from the agency’s public website) made the liability framework explicit: using an AI hiring tool does not transfer the employer’s responsibility for discriminatory outcomes.
The employer remains the liable party. That position reflects Title VII itself, not just the guidance document. The statute has not changed.
Americans with Disabilities Act (ADA)
The ADA prohibits screening out candidates with disabilities unless the criteria being used are genuinely related to the essential functions of the job.
Algorithmic hiring tools create ADA risk in three documented ways: screening out candidates because of disability-related traits (such as employment gaps that may reflect medical leave), applying qualification requirements not genuinely necessary for job performance, and failing to provide reasonable accommodations for candidates with disabilities in the application or assessment process.
AI-generated job descriptions are particularly prone to the second risk. An AI model reproducing language from historical postings may include physical or sensory requirements that were copied from similar jobs but are not genuinely required for the specific role.
For more on this specific risk, read: Can You Use AI-Generated Job Descriptions Legally?
Age Discrimination in Employment Act (ADEA)
The ADEA protects workers aged 40 and older.
AI hiring tools have documented bias against older workers in two forms: direct filtering (the iTutorGroup case, where the tool automatically rejected women over 55 and men over 60) and indirect filtering through language patterns that signal preference for younger candidates (digital native, recent graduate, energetic, fresh perspective) or through years-of-experience requirements that function as age proxies.
It established that AI tools can violate the ADEA just as decisively as human decision-makers can.
The Political Complication: What Changed and What Did Not
On April 23, 2025, President Trump signed Executive Order 14281, “Restoring Equality of Opportunity and Meritocracy,” directing federal agencies to reduce their reliance on disparate impact liability theory “in all contexts to the maximum degree possible.”
On June 9, 2026, the Department of Justice’s Office of Legal Counsel issued a memorandum opinion concluding that the EEOC’s longstanding disparate impact framework under Title VII is unconstitutional, characterizing it as a “qualified racial-proportionality mandate” that pressures employers into race-based decision-making.

The OLC opinion does not have the force of law, is not binding on federal courts, and does not repeal Title VII’s disparate impact provisions. Private plaintiffs retain the right to bring disparate impact claims.
These are real changes with real consequences for federal enforcement priorities. The EEOC’s 2023 AI guidance was removed from the agency’s website. Federal agency prosecution of disparate impact cases has slowed.
What these changes did not do:
They did not repeal Title VII, the ADA, or the ADEA. Private plaintiffs retain their right to bring disparate impact claims directly under these statutes. Courts decide those cases, not executive agencies.
They did not affect Mobley v. Workday or other ongoing private litigation. Class action lawsuits proceed through federal courts applying statutory law. An executive order about agency enforcement priorities does not bind federal courts hearing private cases.
They did not change state law. As of spring 2026, HR leaders face a landscape in which multiple state and local jurisdictions impose distinct obligations around bias audits, impact assessments, employee notice, and anti-discrimination enforcement tied to algorithmic employment tools.
State attorneys general operate independently of federal executive priorities.
The practical implication for HR compliance teams: the reduction in federal enforcement does not reduce your legal exposure.
It changes where the exposure comes from: private class actions, state enforcement, and state attorney general activity. HR teams that relaxed AI governance based on the executive order’s framing may have made a compliance error.
The State-Level Patchwork in 2026
The absence of a federal AI hiring law has produced a fragmented landscape of state and local requirements, each with different scope, different enforcement mechanisms, and different timelines.

New York City: Local Law 144 (in effect since July 2023)
The most established and actively enforced AI hiring requirement in the United States.
NYC LL 144 requires employers using Automated Employment Decision Tools (AEDT) to conduct annual bias audits by independent auditors, publish audit results and deployment dates publicly on the careers page, and notify candidates in advance with an option to request alternative assessment.
Violations carry fines of $500 to $1,500 per violation.
NYC LL 144 applies to any employer using a qualifying AEDT for a position located in New York City, regardless of where the employer is headquartered.
A company based in Arizona using AI resume screening for a remote role that would be performed in New York City falls under this law.
For the full guide to disclosure requirements under this and other laws, read: How to Disclose AI Use in Your Hiring Process to Candidates
Illinois: HB 3773 (effective January 1, 2026)
Illinois amended the Illinois Human Rights Act to prohibit AI that discriminates in employment and to require employers to notify applicants and employees when AI is used in hiring, recruitment, or other employment decisions.
Illinois also has a separate, older law specifically governing AI in video interviews: the Artificial Intelligence Video Interview Act (effective 2020), which requires candidate consent before AI-based video evaluation. Both apply simultaneously.
Draft rules from the Illinois Department of Human Rights would require employers to preserve notices and disclosures about AI use for four years and would extend obligations to third parties, including recruiters and agencies acting on the employer’s behalf.
Colorado: SB 26-189 (effective January 1, 2027)
Colorado’s framework changed significantly in 2026. The original Colorado AI Act (SB 24-205, passed in 2024) was repealed and replaced by SB 26-189, a narrower law effective January 1, 2027.
The replacement law eliminated the original statute’s impact assessment requirements and formal duty-of-care provisions while retaining pre-use notice, adverse outcome disclosure, recordkeeping, and meaningful human review requirements.
Any compliance plan built around the original 2024 Colorado AI Act needs revision before the 2027 effective date of the replacement law.
California: Multiple Overlapping Frameworks
California Governor Newsom vetoed a comprehensive AI hiring notice bill in October 2025. Two other California frameworks still impose obligations:
The California Civil Rights Department regulations (effective October 2025) restrict discriminatory AI use in employment under the California Fair Employment and Housing Act, with transparency and recordkeeping obligations.
The California Privacy Protection Agency ADMT rules (effective January 1, 2027) require CCPA-covered businesses (generally those with over $25 million annual revenue or processing data of 100,000+ California residents) to provide pre-use notice and the right to opt out of automated decision-making for significant decisions, including employment.
New Jersey: December 2025 Regulations
New Jersey’s Division on Civil Rights added chapter regulations in December 2025 implementing the NJ Law Against Discrimination specifically as it pertains to algorithmic discrimination.
The explicit extension of liability for unintentional discrimination is more expansive than the Texas framework.
Texas: TRAIGA (effective January 1, 2026)
Texas’s Responsible Artificial Intelligence Governance Act (TRAIGA) prohibits developing or deploying AI with the intent to discriminate but limits liability to intentional discrimination and provides a 60-day cure period for violations.
This is the most employer-favorable state framework in the current landscape.
What Is Coming
Organizations that invest in robust compliance now will be better positioned for federal requirements when they arrive.
Vendor Liability: The Changing Picture
For years, the standard assumption in HR technology purchasing was that AI tool vendors might face some regulatory scrutiny, but the employer remained primarily liable for hiring outcomes. That assumption is being tested.
Mobley v. Workday is the direct test of this principle. A California federal court in 2024 rejected Workday’s motion to dismiss, holding that Workday could be treated as an “agent” of the employers who used its platform.
As of April 2026, the case is ongoing in active litigation. If the courts ultimately hold that Workday bears direct liability for algorithmic discrimination, the implications for every employer-vendor relationship in the HR technology space will be significant.
A separate class action filed in January 2026 against an AI recruiting and talent intelligence company advanced a different theory: that the company violated background check law (FCRA) by collecting and scoring applicant data from unverified third-party sources without consent.
This represents a new compliance angle beyond discrimination law, specifically the consumer reporting and privacy dimensions of candidate data handling.
The practical implication: vendor contracts for AI hiring tools should address liability distribution explicitly.
Your standard vendor agreement’s disclaimer that “the client retains control over hiring decisions” may carry less weight than you assumed if the AI tool’s outputs effectively determine who advances and who does not.
For more on specific ATS and screening tool selection with compliance in mind, read: AI Tools for Resume Screening: What Actually Works
The Five Practical Compliance Obligations
These five obligations represent the minimum defensible AI hiring compliance program in 2026. None of them require specialized technology or enterprise-level investment.
All of them require consistent execution.
Obligation 1: Document Your AI Tool Inventory
List every tool used in your hiring process that has AI or automated features.
For each tool, document: what it evaluates or automates, how its output is used in candidate decisions, whether it has been independently audited for bias, and what disclosure obligations it triggers in the jurisdictions where you hire.
Many HR teams do not have this inventory. ATS platforms have added AI features as default-on upgrades that hiring teams did not deliberately enable.
Candidate scoring that was opt-in two years ago may be active in your current workflow without anyone having made a deliberate decision to use it.
Obligation 2: Apply the Four-Fifths Rule to Screening Data
The four-fifths (80%) rule is the standard for detecting adverse impact. If your AI screening tool advances candidates from a protected group at a rate less than 80% of the advancement rate for the most-advanced group, that is a potential indicator of adverse impact requiring investigation.
Pull your screening data for the past 12 months. Calculate advancement rates by race, age, sex, and disability status at each stage: application to phone screen, phone screen to interview, interview to offer.
Any stage where a protected group’s advancement rate falls below 80% of the highest-advancing group warrants investigation. Document the calculation. This is a compliance record.
For more on how to run this analysis and what to do with the results, read: AI Bias in Hiring: What HR Teams Need to Know
Obligation 3: Implement Candidate Disclosures Where Required
Determine which disclosure requirements apply to your specific operating jurisdictions and hiring locations. NYC, Illinois, California (ADMT-covered businesses), Colorado (effective January 2027), Connecticut (phasing in through 2027), and Maryland (facial recognition specific) all have requirements.
Build disclosure language into your application workflow at the point where AI is used, not only in your privacy policy.
Several laws specifically require notice at or before the point of AI use, not as fine-print buried in a terms page candidates never read.
For detailed guidance and sample disclosure language: How to Disclose AI Use in Your Hiring Process to Candidates
Obligation 4: Keep Humans Between AI Outputs and Candidate-Facing Decisions
No automated rejection should reach a candidate without human review. This is both a legal risk-reduction step and a candidate experience protection.
The fastest path to an EEOC complaint or a state enforcement action is an automated rejection pipeline where candidates with a plausible discrimination claim can demonstrate that no human reviewed the AI’s decision before it was communicated.
Document your human review process. Keep records of who reviewed which AI outputs, when, and what decision was made. Several state laws have four-year recordkeeping requirements for documentation of AI use in employment decisions.
Obligation 5: Audit Job Description Language Before Posting
AI-generated job descriptions reproduce language bias from training data: gender-coded terms, age-coded phrases, unnecessary credential requirements, and disability-exclusionary language.
These create legal exposure under the same discrimination statutes as screening tool bias, but they are significantly easier to catch and fix before they cause harm.
A structured pre-posting audit using free tools (Gender Decoder, Ongig’s Text Analyzer) takes 15 to 20 minutes per description. The process is documented, repeatable, and creates a record showing deliberate attention to language quality.
For the full audit process with a printable checklist: How to Audit AI Job Posts for Bias Before Publishing
Building a Defensible AI Hiring Program
The organizations that navigate the AI hiring compliance environment most successfully in 2026 and 2027 are the ones with documented AI governance, not those who simply adopted AI more cautiously.
Documentation is the primary distinction between a defensible hiring program and an exposed one. When a candidate files a complaint, when a regulator opens an inquiry, or when a lawsuit names your organization, the first question is: what did you know, when did you know it, and what did you do about it?

Organizations with documented bias audits, disclosed AI use, human review processes, and four-year retention records of those documents are in a structurally better position than organizations that used the same AI tools but built no governance around them.
Structuring a defensible AI hiring program involves six elements:
AI tool inventory. Know what you are using, what it does, and what obligations it triggers. Updated at least annually.
Vendor due diligence. Before purchasing an AI hiring tool, request independent bias audit results, ask about jurisdiction-specific compliance features, and confirm what the vendor contract says about liability distribution.
Bias monitoring. Apply the four-fifths rule to your screening data quarterly. Track patterns. When you find disparate impact, investigate and document the investigation.
Disclosure infrastructure. Build jurisdiction-specific notices into your application workflow. Keep records of what notice language was in effect at what time and for which roles.
Human review documentation. Document that humans reviewed AI outputs before candidate-facing decisions were made. The record does not need to be elaborate. It needs to exist.
Audit and communication trail. Pre-posting bias audits on job descriptions, with records. Vendor communication records. Legal review dates. These are the artifacts that demonstrate program seriousness if they are ever needed.
The Cluster Articles: Where to Go Deeper
Understanding bias in AI hiring systems:
- AI Bias in Hiring: What HR Teams Need to Know — the research, the mechanisms, documented cases, and the four-fifths rule applied
Legal compliance for job description content:
- Can You Use AI-Generated Job Descriptions Legally? — what the law requires, 2026 state regulatory changes, and the five pre-posting checks
Disclosure requirements by jurisdiction:
- How to Disclose AI Use in Your Hiring Process to Candidates — NYC LL 144, Illinois HB 3773, Colorado SB 26-189, California, sample disclosure language
Practical bias auditing before publishing:
- How to Audit AI Job Posts for Bias Before Publishing — the six-step audit process with a printable checklist and free tools
Related articles in other clusters:
- AI Tools for Resume Screening: What Actually Works — which tools have explainable AI, independent bias audits, and compliance features
- Manatal vs. Workable: AI Recruiting Features Compared — AI features in the context of ATS platforms
Other pillar guides:
- Complete Guide to AI Tools for HR Professionals
- AI Writing Tools for Recruiters: The Complete Guide
- AI for HR Communications and Documentation: The Complete Guide
Frequently Asked Questions
No. Executive Order 14281 (April 2025) directed federal agencies to reduce their reliance on disparate impact enforcement. It did not repeal Title VII, the ADA, or the ADEA. Private plaintiffs retain their right to bring disparate impact claims under these statutes directly in federal court. State attorneys general enforce state discrimination laws independently of federal executive priorities. Class action lawsuits like Mobley v. Workday proceed through courts, not through executive agencies, and are not affected by executive enforcement priorities. The DOJ’s June 9, 2026 OLC memorandum concluding EEOC’s disparate impact framework is unconstitutional adds legal uncertainty but does not change existing law. It is not binding on federal courts and does not repeal Title VII’s disparate impact provisions. The practical risk has not decreased. The source of risk has shifted from federal agency enforcement toward private litigation and state enforcement.
No. The EEOC’s position, reflected in its 2023 technical assistance document (since removed from its website but not withdrawn as guidance), is explicit: employers are liable for discriminatory outcomes from AI tools regardless of whether those tools were vendor-built. The Mobley v. Workday litigation is actively testing whether the vendor bears additional direct liability alongside the employer, but that potential additional vendor liability does not reduce employer liability. You cannot transfer legal responsibility to a vendor by purchasing their tool. Your compliance obligations attach to the outcomes your hiring process produces, not to whether a human or an AI produced those outcomes.
Contact your ATS vendor and ask specifically which AI features are active in your account. Include: candidate scoring or ranking, resume parsing with AI-based matching, candidate screening chatbots, automated rejection triggers, and AI-enhanced job description tools. ATS platforms routinely enable AI features through product updates without requiring customer approval for each new capability. Your ATS’s default configuration in 2026 may include AI-based candidate ranking that was not present or was not active when you signed your contract. This is an inventory step that cannot be skipped in a compliance program.
Four things: (1) audit every job description for biased language before posting using free tools like Gender Decoder and Ongig’s Text Analyzer (15 to 20 minutes per description); (2) ensure no automated candidate rejection goes out without a human reviewing it; (3) add clear, plain-language disclosure to your application materials noting AI use in your hiring process; and (4) ask your ATS vendor what AI features are active and request any available bias audit documentation. These four steps are achievable for a two-person HR team with existing tools, cost nothing beyond time, and create documentation that demonstrates good-faith compliance effort. They do not substitute for legal counsel on jurisdiction-specific requirements but they reduce the most common compliance exposures in AI-assisted hiring.
Four specific areas: (1) what warranties does the vendor make about bias testing and non-discrimination compliance; (2) what does the contract say about liability distribution for discriminatory outcomes; (3) what audit rights do you have over the tool’s configuration and training data; and (4) what is the vendor’s obligation when you discover disparate impact in your hiring data and attribute it to their tool? Contracts that include comprehensive disclaimer language transferring all risk to the client deserve scrutiny. The Mobley v. Workday case is testing whether such disclaimers hold up when AI tools exercise meaningful control over hiring decisions. A contract review by qualified employment counsel before purchasing AI hiring tools is a reasonable investment given the potential liability.
Conclusion
AI in hiring is not optional in 2026. The tools are already active in most HR workflows, often in ways organizations did not explicitly choose.
The legal landscape has moved significantly, creating real compliance obligations in multiple jurisdictions, ongoing class action litigation, and a shifting federal enforcement posture that has moved risk rather than eliminated it.
The organizations navigating this environment most successfully are not those that avoided AI.
They are those that deployed it with documented governance: inventoried tools, regular bias audits, disclosed AI use, human review before decisions, and vendor contracts that address liability honestly.
The cluster articles linked throughout this guide give you the specific tools, audit processes, disclosure language, and legal frameworks to build that governance program.
The path through AI hiring compliance in 2026 is not simple, but it is documented. The steps are available. The legal exposure for organizations that do not take them is real and growing.
The regulatory tracking in this guide, including the Colorado repeal, the DOJ OLC opinion, and the California ADMT timeline split, reflects what the Ailovyu team monitors across law firm updates, state regulatory filings, and court dockets, because this area changes faster than most compliance calendars account for.

We research and test AI tools so you can make informed decisions before spending money on them. Every review, comparison, and tutorial on this site is based on actual use, not vendor marketing.
Learn more on our About page.
Legal information in this article is sourced from Akerman LLP HR Defense Blog (November 2025), Harris Beach Murtha (January 2026), DarrowEverett LLP (May 2026), Reed Smith Employment Law Watch (April 2026), Agenticinterviewer.com Bias and Legal Risks guide (May 2026, last verified June 2026), SynHR AI Hiring Regulations guide, WorkWise Compliance, Brownstein Hyatt Farber Schreck (June 2026), Jackson Lewis (June 2026), Crowell and Moring (June 2026), and Sullivan and Cromwell (June 2026) for the DOJ OLC opinion analysis. This article is for informational purposes only and does not constitute legal advice. Employment law varies by jurisdiction and changes frequently. Consult qualified employment counsel before finalizing your AI compliance program. No affiliate relationships are disclosed in this article.
