Automated Employment Decision Tools: One Audit, Five Laws

Key takeaways

  • Automated employment decision tools now sit inside five separate legal regimes: New York City’s Local Law 144, Illinois HB 3773, California’s FEHA rules on automated-decision systems, the Colorado AI Act, and the EU AI Act. Each one defines the tool differently.
  • The European deadline moved. High-risk employment AI under Annex III shifted from 2 August 2026 to 2 December 2027. The four US regimes did not move with it.
  • An annual bias audit is a measurement, not a defence. It produces impact ratios. It does not certify that a hiring tool is lawful under Title VII.
  • Independent research found 18 published audit reports across 391 New York City employers examined. The observed compliance rate is close to zero, and that gap is itself the exposure.
  • California’s four-year retention duty is the practical floor. Build the evidence chain once at that standard and the other four regimes are largely satisfied.
A single sheet of paper drawn through a narrow slot, illustrating how automated employment decision tools filter candidates

What counts as an automated employment decision tool

New York City wrote the first binding definition, and it is narrower than most employers assume. Under Local Law 144, an automated employment decision tool is a computational process derived from machine learning, statistical modelling, data analytics or artificial intelligence that issues a simplified output used to substantially assist or replace discretionary decision making for hiring or promotion. The rules issued by the Department of Consumer and Worker Protection tightened it further: the simplified output has to outweigh other criteria or overrule a human conclusion. That narrowing did real work. It allowed a large number of employers to conclude that their resume parser merely informed a recruiter rather than substantially assisting the decision, and therefore sat outside the law. California went the other direction. Its Civil Rights Council regulations, effective 1 October 2025, define an automated-decision system as a computational process that makes a decision or facilitates human decision making regarding an employment benefit. Facilitating is a far lower bar than substantially assisting, and it pulls back in most of the tools New York’s definition let out. The EU AI Act is broader again. Annex III point 4 covers AI used to place targeted job advertisements, filter applications, evaluate candidates, decide on terms of employment, promotion and termination, allocate tasks, and monitor or evaluate the performance and behaviour of workers. Job advertising and task allocation are squarely in scope in Brussels and invisible in New York.

The definitions do not agree, and that is the first problem

The same resume screener can be out of scope in New York, in scope in California, and high-risk in the EU on the same Tuesday. There is no single test, and no jurisdiction has adopted another’s. Scope has to be determined per tool, per regime, and written down, because the New York narrowing is precisely the judgement an enforcement action will go after first. Treating one favourable scope opinion on automated employment decision tools as a global answer is the most common failure we see.

The five regimes that now apply

Automated employment decision tools are not governed by one law with five annexes. They are governed by five laws that were written independently, in different years, by legislators solving different problems.

New York City Local Law 144

In force since July 2023 and the template everyone else borrowed from. An employer or employment agency may not use an automated employment decision tool unless it has had an independent bias audit within the previous year, a summary of the audit results has been published, and candidates have been notified at least ten business days before the tool is used. Civil penalties run up to 1,500 dollars per violation, and each day of continued use counts separately.

Illinois HB 3773

Effective 1 January 2026, HB 3773 amends the Illinois Human Rights Act. It prohibits employers from using AI that has the effect of subjecting employees to discrimination on the basis of a protected class across recruitment, hiring, promotion, renewal, selection for training, discharge, discipline, tenure and the terms of employment. It also bans the use of zip code as a proxy for a protected class, which is a direct shot at the most common form of laundered redlining in hiring models. Employers must notify employees of AI use, and the Illinois Department of Human Rights enforces. Note the structure. Illinois regulates the effect, not the process. There is no audit to perform and no certificate to obtain. A discriminatory outcome is the violation.

California FEHA automated-decision systems

The Civil Rights Council regulations took effect 1 October 2025 and apply to employers with five or more employees. Three things matter operationally. Evidence of proactive bias testing is relevant to the defence, which turns testing from a compliance chore into litigation posture. Vendor conduct can be attributed to the employer. And record retention for personnel and employment records, including automated-decision system data and applicant flow logs, extends from two years to four.

Colorado

Colorado’s AI Act, as amended, lands in 2027 and takes a duty-of-care approach to algorithmic discrimination rather than an audit-and-publish approach. It is covered in full in our guide to the Colorado AI Act, so we will not duplicate it here beyond the point that matters for scoping: its definition of a consequential decision includes employment, and its trigger is substantial factor rather than substantial assistance.

EU AI Act Annex III point 4

Employment and worker management is one of the eight high-risk areas in Annex III. Article 6(2) is unambiguous about the consequence: “In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.” That classification brings the full Chapter III obligation set with it, including a risk management system, data governance, logging, technical documentation, human oversight and post-market monitoring. Our EU AI Act operator’s guide walks the provider and deployer split in detail.

The deadline that moved and the four that did not

2 August 2026 was the date the Annex III high-risk obligations were supposed to bite. It is no longer. Under the Digital Omnibus, the European Parliament voted on 16 June 2026 by 423 to 57 with 174 abstentions, and the Council gave final approval on 29 June 2026. Standalone Annex III high-risk systems, which is where hiring tools live, move to 2 December 2027, a sixteen-month deferral. High-risk AI embedded in regulated products under Annex I moves to 2 August 2028. Three things did not move, and they are the ones that decide whether the deferral is useful to you. The prohibited practices did not move. They have applied since 2 February 2025 with no grace period and no transition. Emotion inference in the workplace sits in that list, not in the high-risk tier, which means a tool that scores a candidate’s enthusiasm from a recorded interview is already unlawful in the EU rather than merely regulated. Member State law did not move. Article 2(11) of the AI Act is explicit: “This Regulation does not preclude the Union or Member States from maintaining or introducing laws, regulations or administrative provisions which are more favourable to workers in terms of protecting their rights in respect of the use of AI systems by employers, or from encouraging or allowing the application of collective agreements which are more favourable to workers.” National labour law, works council rights and data protection authorities continue to operate on their own schedule. And the four US regimes did not move. New York City has been enforcing since 2023. Illinois started in January. California started last October. There is also a reason the deferral was granted that should temper any sense of relief. The harmonised technical standards that an employer would be measured against are not finished. The specification is still being drafted, which means the extra sixteen months are being consumed by the standards bodies rather than handed to deployers as slack. Firms that read December 2027 as breathing room for their automated employment decision tools will arrive at the same starting line with less time, not more.

What a bias audit actually measures

The bias audit that Local Law 144 requires of automated employment decision tools is a specific statistical exercise, and understanding its shape is what separates a useful audit from an expensive one. The auditor calculates the selection rate for each sex, race and ethnicity category: the share of candidates in that group who were selected. For a tool that scores rather than selects, it calculates the average score per group. It then computes the impact ratio, which is the selection rate of a given group divided by the selection rate of the most-selected group, or for scoring tools the average score of a group over the average score of the highest-scoring group. The result is read against the four-fifths rule. An impact ratio below 80 percent may signal adverse impact against that group. It is a screening heuristic borrowed from the Uniform Guidelines on Employee Selection Procedures, not a legal threshold, and passing it proves considerably less than vendors imply. Two details in the rules deserve more attention than they get. An independent auditor may exclude any category representing less than 2 percent of the data used for the audit, which quietly removes small groups from the arithmetic in exactly the situations where discrimination is hardest to detect and most damaging. And independence has teeth: the auditor must have no financial interest in the tool, and a vendor cannot audit its own product.

What the audit does not do

It is not a certificate of compliance. It creates no safe harbour under Title VII. And it is a single annual snapshot of a system that is often retrained on new applicant data every quarter. The eleven months between audits are where drift lives, which is why the audit belongs inside a monitoring programme rather than standing in for one. The mechanics of the underlying failure mode are covered in our guides to AI bias and algorithmic bias.

The federal layer nobody removed

On 27 January 2025 the EEOC removed its May 2023 AI guidance from its website, following the rollback of the previous administration’s AI executive order. It subsequently moved to close pending disparate-impact charges. A number of employers running automated employment decision tools read that as the federal question closing. It did not. Title VII’s prohibition on practices with a disparate impact is statute. The Uniform Guidelines on Employee Selection Procedures and their validation requirements apply to any selection procedure, algorithmic or not, and neither was amended. Guidance explains law. It does not constitute it, and withdrawing it does not repeal anything. What actually changed is the federal enforcement posture, not the standard. Private plaintiffs, class actions and state attorneys general operate independently of the EEOC’s charging priorities, and the removal of the published guidance made the applicable standard less legible without making it less binding. For a compliance owner, an unwritten standard that still carries liability is a worse position than a written one, not a better one.

One control set, five regimes

Five regimes, five definitions, three different enforcement theories. Building five compliance programmes for the same automated employment decision tools is not viable. Building one evidence chain that satisfies all of them is, because they ask for overlapping artifacts in different words.

  1. Inventory every tool that scores, ranks, filters or monitors a person. This includes features switched on inside an applicant tracking system or HRIS that nobody procured as AI, which is where most of the unregistered exposure sits. See our guide to shadow AI for the discovery approach.
  2. Determine scope per regime, in writing. The same tool gets five answers. Record the reasoning and who signed it.
  3. Run a structured pre-deployment assessment. Article 27 of the AI Act gives a usable template even outside the EU: a description of the deployer’s processes, the period and frequency of intended use, the categories of persons likely to be affected, the specific risks of harm to them, the human oversight measures implemented, and the arrangements for internal governance and complaint mechanisms. Its relationship to a data protection assessment is set out in our note on the difference between a PIA, a DPIA and a FRIA.
  4. Commission independent bias testing and keep the artifacts, not just the summary: selection and scoring rates, impact ratios, methodology, the auditor’s independence statement, and the published result. Our guide to AI audit covers auditor selection.
  5. Make human oversight real. Article 14 requires that high-risk systems “shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use.” A recruiter who approves a ranked list without the ability or the time to disagree with it is not oversight. The distinction is the subject of our guide to human-in-the-loop versus human-on-the-loop.
  6. Keep notice artifacts and retain everything for four years. Adopt the California window as the global floor rather than tracking five retention clocks.
  7. Fix the vendor contract. It must oblige cooperation with your audit, give you access to the data needed to compute impact ratios, require notification of material model changes, and name who performs the audit. Since a vendor cannot audit its own tool, silence on that point means nobody has.
  8. Monitor between audits. Track selection rates continuously so the annual audit confirms what you already knew instead of discovering it eleven months late. This is ordinary AI risk management applied to a hiring funnel.

That chain is one programme. It produces the New York audit, the Illinois effect evidence, the California retention set, the Colorado duty-of-care record and the EU Annex III technical file from the same underlying operations.

The compliance rate nobody quotes

The strongest argument for building this properly is what the research shows about everybody else. A study published at the ACM Conference on Fairness, Accountability and Transparency examined how employers using automated employment decision tools responded to Local Law 144. Across 391 employers reviewed by 155 investigators, in a partnership between Cornell’s CAT Lab, the Data & Society Research Institute and Consumer Reports, 18 employers had posted an audit report and 13 had posted a transparency notice. Only 11 published both an audit report and a transparency notice meeting the law’s requirements. Two readings of that number are available. The comforting one is that enforcement has been light and the odds are good. The accurate one is that a near-total absence of published audits across an entire regulated market is not a stable equilibrium, and that an employer who does publish is not the target. The organisations carrying real exposure are the ones that determined they were out of scope and kept no record of why.

FAQ

What is an AEDT in recruiting? AEDT is the abbreviation for an automated employment decision tool. In recruiting it means any software that uses machine learning, statistics, data analytics or AI to produce a score, rank or recommendation that substantially assists or replaces a human decision about hiring or promotion. In practice that covers resume screeners, candidate-matching engines, assessment scoring, video interview analysis and some sourcing tools. Whether a specific tool is an AEDT depends on the jurisdiction, because New York, California and the EU each apply a different threshold to the same software. Should candidates opt out of automated employment decision tools? In New York City an employer must offer an alternative process or accommodation on request, but opting out does not guarantee a human review of your application on the same timeline, and some employers treat opt-out requests as an administrative exception. For the employer reading this, the operational point is the one that matters: an opt-out route that exists on paper but has no owner, no service level and no audit trail will not survive scrutiny, and the volume of opt-out requests is a useful early signal of how your notice is landing. Does an annual bias audit make a hiring tool legally compliant? No. A bias audit satisfies one specific requirement of one specific law. It calculates impact ratios at a point in time. It does not validate the tool as job-related and consistent with business necessity under the Uniform Guidelines, it creates no defence under Title VII, and it says nothing about the Illinois effects test or the EU high-risk obligations. Treating the audit certificate as a compliance conclusion is the single most common mistake in this area. Who is liable when a vendor’s tool discriminates, the employer or the vendor? Primarily the employer, in every regime discussed here. New York places the duty on the employer or employment agency using the tool. California’s regulations address the attribution of vendor conduct to the employer. The EU AI Act splits obligations between provider and deployer, but the deployer, defined as the body using the system under its authority, carries the deployment-side duties. Vendors carry contractual and reputational risk. You carry the regulatory risk, which is why the contract terms in step seven above are not optional. Did the EU AI Act delay remove the obligation for hiring AI? No, it moved the date. Standalone Annex III high-risk systems now have until 2 December 2027 rather than 2 August 2026, confirmed by the Council on 29 June 2026. The prohibited practices, including workplace emotion inference, have applied since February 2025 and were not deferred. Member States remain free under Article 2(11) to maintain more protective worker rules. And the deferral exists largely because the technical standards are unfinished, so the specification is still moving. Do these rules apply to a company outside New York, Illinois and California? Usually yes, through at least one route. The laws governing automated employment decision tools attach to where the candidate or the role sits, not only to where the company is headquartered, so a remote-hiring employer touches multiple regimes at once. Federal Title VII applies nationally regardless of state law. And if any part of the hiring funnel reaches candidates in the EU, Annex III applies on the European timetable. The practical answer for a multi-state or multi-country employer is to build to the strictest standard once rather than maintaining a jurisdiction matrix.

Conclusion

Automated employment decision tools are the most heavily regulated category of enterprise AI in operation today, and they are also the category most likely to have been switched on inside an existing HR platform without a procurement decision. Five regimes now reach them, using three incompatible theories of liability, and the deadline that just moved was the only one offering relief. The response that scales across automated employment decision tools is not five compliance projects. It is one inventory, one scope determination per regime, one assessment structure, one independent test with retained artifacts, one four-year retention standard, and one contract template. Every regime discussed here is satisfied by evidence drawn from that single chain. AI Sigil is built to hold that chain: system inventory, per-framework classification, control mapping and audit-ready evidence across the regimes that apply to you. If you want to see how your hiring stack maps to all five, start with our AI governance framework.

Automated Employment Decision Tools: One Audit, Five Laws

Automated employment decision tools face five overlapping regimes in 2026. Map NYC Local Law 144, Illinois, California and the EU AI Act to one audit.

AI Governance Challenges: 7 Blockers, 7 Controls

The seven AI governance challenges that stall delivery in 2026, each mapped to the EU AI Act obligation behind it and the control that closes it.

AI Benchmarking: Turning Scores Into Audit Evidence

AI benchmarking explained for governance teams: what benchmark scores prove under the EU AI Act, ISO 42001 and NIST AI RMF, and where they fail as evidence.

NIST CSF 2.0: The Six Functions and the New AI Profile

NIST CSF 2.0 explained: the six core functions, Tiers and Profiles, plus how NIST's draft Cyber AI Profile extends the framework to AI systems.

ISO 42001 Certification: Process, Cost, and Timeline

The ISO 42001 certification process explained: the five phases, the 38 Annex A controls, realistic cost and timeline, and how it prepares you for the EU AI Act.

AIGP Certification: The Operator’s Guide to IAPP’s AI Governance Credential

A vendor-neutral guide to the IAPP AIGP certification: 2026 body of knowledge, exam format, cost, salary and how to prepare for the exam.