What each statute actually requires (and the consultancy decks you should ignore)
**NYC Local Law 144** is the most operationally specific bias audit law on the planet. The DCWP final rules at https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page define an Automated Employment Decision Tool as software that uses machine learning, statistical modeling, or AI to substantially assist or replace discretionary employment decisions. If you use one for NYC-based hires or promotions, you must commission an annual independent bias audit, publish a summary on your public site, and notify candidates at least ten business days before the AEDT is used. The audit must compute selection rate ratios and impact ratios across race/ethnicity and sex categories using the federal four-fifths rule framework — not a marketing 'fairness score.'
**The EU AI Act** at https://artificialintelligenceact.eu/ is a horizontal product safety regulation that treats AI like a regulated good. Annex III lists eight categories of high-risk systems; #4 covers AI used in employment, worker management, and access to self-employment — recruitment, advertising, screening, evaluating performance, terminating relationships. Providers of high-risk AI must run conformity assessments, maintain technical documentation, register the system in the EU public database, and operate a post-market monitoring system. Deployers must run a fundamental rights impact assessment, ensure human oversight, monitor system operation, and report serious incidents within 15 days. Most high-risk obligations apply from August 2, 2026; obligations for products in Annex II apply from August 2, 2027.
**The Colorado AI Act** (SB24-205) at https://leg.colorado.gov/bills/sb24-205 is the first comprehensive US state AI statute, effective February 1, 2026. It imposes algorithmic discrimination duties on both developers and deployers of high-risk AI systems — those making or substantially contributing to a consequential decision in employment, education, financial services, healthcare, housing, insurance, legal services, or essential government services. Deployers must run an annual impact assessment, notify consumers when high-risk AI is used to make a consequential decision, and offer correction and appeal rights. Enforcement is exclusive to the Colorado Attorney General; there is no private right of action, but algorithmic discrimination is treated as a deceptive trade practice.
**Illinois AI Video Interview Act** at https://www.ilga.gov/legislation/ilcs/ilcs5.asp?ActID=4015 has been in force since 2020 and is narrower than the headlines suggest. It applies only to employers using AI to analyze applicant video interviews for Illinois positions. Required actions: notify the applicant before the interview, explain how the AI works and what general characteristics it evaluates, obtain consent, limit who can view the video, destroy videos within 30 days of an applicant's request, and — if AI alone selects who advances to in-person interviews — report race and ethnicity data annually. There is no mandatory audit, but the disclosure-and-consent regime can stop a tool dead in its tracks if your vendor cannot describe the model in plain English.
**EEOC guidance** at https://www.eeoc.gov/ai is not new law — it is the agency's published view that Title VII, the ADA, ADEA, and GINA apply unchanged when AI is the decisionmaker. The 2023 technical assistance on the Uniform Guidelines on Employee Selection Procedures makes clear that the four-fifths rule is a starting point, not a safe harbor, for AI selection tools. The 2024 ADA guidance on AI in hiring addresses reasonable accommodation obligations when an assessment screens out candidates with disabilities. Employer liability does not transfer to the vendor; you are responsible for the discriminatory output of the tool you bought.
**California SB 1001** at https://leginfo.legislature.ca.gov/ is a bot-disclosure law that took effect July 1, 2019 — narrow but enforceable. It requires clear and conspicuous disclosure when an online bot is used to incentivize a sale or influence an election vote with California residents. **California AB 2930** is the proposed automated decisionmaking statute that has been re-introduced multiple times. As of June 2026, AB 2930 is not yet enacted — verify status at https://leginfo.legislature.ca.gov/. The California Civil Rights Council has finalized regulations on automated decisionmaking systems in employment under FEHA, effective October 2025, which functionally extend bias audit expectations to California employers.