Skip to contentNew: Does ChatGPT recommend your brand? Free 60-second AI visibility check →
By The DDH Team · Digital Dashboard Hub

AI Bias Audit Legal Requirements in 2026: NYC LL 144, EU AI Act, Colorado AI Act, Illinois AIVIA, EEOC Guidance, and California SB 1001 — What You Actually Have to Do

Six overlapping AI bias audit regimes are now live or about to be. NYC Local Law 144 has been enforced since July 2023. The EU AI Act flips on its high-risk obligations through 2026 and 2027. Colorado's AI Act becomes the first US comprehensive AI statute in February 2026. Illinois AIVIA has been in force since 2020. The EEOC keeps publishing technical assistance. California SB 1001 and AB 2930 add disclosure and ADM rules on top. Sources cited inline, June 2026.

By DDH Research Team at Digital Dashboard HubUpdated

If you deploy an AI system that touches hiring, lending, housing, insurance, education, or essential services in 2026, you are almost certainly subject to at least one mandatory bias audit regime — and probably three. The category that did not exist in 2022 now spans New York City's automated employment decision tool rules at https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page, the EU AI Act's Annex III high-risk obligations at https://artificialintelligenceact.eu/, and Colorado's SB24-205 comprehensive AI statute at https://leg.colorado.gov/bills/sb24-205. Each rulebook defines 'bias audit' differently, demands different auditor credentials, sets different cadences, and imposes different penalties. Before you commission anything, run the candidate-volume math through the EU AI Act compliance checklist so you scope only the obligations that actually bind you.

**NYC Local Law 144** is the original — it covers automated employment decision tools (AEDTs) used for NYC-based hires, requires an annual independent bias audit, and mandates candidate notice ten business days before use. The **EU AI Act** at https://artificialintelligenceact.eu/ classifies most HR, credit-scoring, and access-to-essential-services AI as high-risk under Annex III #4 and demands conformity assessments, fundamental rights impact assessments, and post-market monitoring. The **Colorado AI Act** (SB24-205) at https://leg.colorado.gov/bills/sb24-205 takes effect February 1, 2026 and imposes algorithmic discrimination duties on developers and deployers of consequential AI. **Illinois AIVIA** at https://www.ilga.gov/legislation/ilcs/ilcs5.asp?ActID=4015 governs AI video interviewing. **EEOC guidance** at https://www.eeoc.gov/ai applies Title VII to AI hiring tools regardless of state law. **California SB 1001** (bot disclosure) and **AB 2930** (automated decisionmaking) add a separate California-specific overlay. All citations sourced from official statute and regulator pages as of June 2026.

The rest of this guide breaks down what each regime defines as a 'bias audit,' who can perform one, how often, what you must publish, what notice candidates get, and the penalties for getting it wrong. You will get a six-column decision matrix, a five-step compliance plan, and the answers to the nine questions general counsel will ask. We also link to the matching policy template at AI acceptable use policy template and to the AI vendor security questionnaire you should be sending every model provider this quarter.

Digital Dashboard Hub

Compliance reviews ask for prompt receipts. DDH's Saved Prompt Library has them — every version, every branch, exportable to JSON. Built by indie operators who hate spreadsheet evidence too.

Start free 14-day trial — AICHAT30 = 30% off Pro for 3 months.

AI bias audit regimes side-by-side — scope, cadence, penalties, June 2026

Feature
NYC LL 144
EU AI Act high-risk
Colorado AI Act
Illinois AI Video Interview Act
EEOC guidance
California SB 1001
ScopeAutomated Employment Decision Tools used to substantially assist hiring or promotion decisions for NYC-based rolesHigh-risk AI systems listed in Annex III — HR, credit, education, essential services, law enforcement, migration, justiceHigh-risk AI making or substantially contributing to consequential decisions affecting Colorado consumersAI analysis of video interviews for Illinois-based positionsAll AI used in employment decisions subject to Title VII, ADEA, ADA, GINABots used to incentivize a sale or influence an election vote with California residents
Audit cadenceAnnual bias audit before AEDT is used and every year thereafterConformity assessment before placing on market plus continuous post-market monitoring and incident reportingAnnual impact assessment for deployers; ongoing risk management for developersNo mandatory audit — disclosure and consent required; race data must be reported annually if AI is sole basis to advance candidatesNo fixed cadence; recommends ongoing four-fifths rule monitoring and validation per Uniform GuidelinesNo audit cadence — disclosure obligation only
Independent auditor requiredYes — independent auditor under DCWP rules at https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.pageNotified Bodies for certain Annex III systems; internal conformity assessment otherwise per https://artificialintelligenceact.eu/Not explicit; impact assessment can be internal but must be defensible to AGNot requiredNot required; EEOC encourages third-party validationNot required
Public disclosure requiredYes — summary of most recent bias audit and distribution date posted on employer websiteYes — registered in EU public database for high-risk systems; CE marking; instructions for useNotice to consumers and AG notification within 90 days of discovered algorithmic discriminationNot public; candidate notice and consent onlyNo statutory disclosure; EEOC may publish enforcement actionsYes — clear and conspicuous disclosure that user is communicating with a bot
Candidate / consumer notice10 business days before use; candidate may request alternative processRight to explanation, right to human review, transparency obligations for usersPre-decision notice plus right to correct data, right to appeal to human, right to explanation if adverseBefore interview: notify, explain how AI works, obtain consent, allow opt-outReasonable accommodation obligations under ADA; recommended pre-use noticeClear and conspicuous bot disclosure at the start of any covered conversation
Sectors coveredEmployment only (hiring and promotion)Eight Annex III categories including employment, credit, education, essential public and private services, biometrics, law enforcementAll sectors where a consequential decision is made — employment, education, housing, insurance, financial, healthcare, legal, governmentEmployment only (video interviews)Employment only — but covers all stages, sourcing through terminationCross-sector — commerce and election speech
Penalties$500 first violation, up to $1,500 per subsequent violation per day, per candidate per https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.pageUp to EUR 35M or 7% global turnover for prohibited practices; up to EUR 15M or 3% for high-risk violationsEnforced exclusively by Colorado AG; no private right of action; deceptive trade practice penaltiesNo specific monetary penalty in AIVIA; HRDC enforcement under Illinois Human Rights Act for discriminationTitle VII back pay, compensatory and punitive damages, injunctive reliefUp to $2,500 per violation for unlawful business practice under California UCL
Effective dateEnforced July 5, 2023Prohibited practices Feb 2, 2025; GPAI obligations Aug 2, 2025; high-risk Aug 2, 2026 (most) and Aug 2, 2027 (Annex II)February 1, 2026January 1, 2020Existing law; updated technical assistance published 2023 and 2024July 1, 2019 (SB 1001); AB 2930 still pending as of June 2026
Enforced byNYC Department of Consumer and Worker Protection (DCWP)National competent authorities in each Member State plus the AI OfficeColorado Attorney GeneralIllinois Department of Human Rights and private right of action under Illinois Human Rights ActEEOC and state fair employment agenciesCalifornia AG and private right of action under UCL
Vendor or deployer obligationDeployer (employer or employment agency) responsible; vendor often supplies the auditBoth — providers (developers) and deployers (users) carry distinct obligations under Articles 16 and 26Both — developers must provide documentation; deployers must run impact assessments and notifyDeployer (employer) responsibleDeployer (employer) liable for discriminatory outcomes regardless of vendorDeployer responsible for disclosure
Exempt activitiesTools that do not substantially assist or replace human decisionmaking; spam filters; some assistive techAI for personal non-professional use; AI for free open-source where not on EU market; military and national securitySmall business deployers with under 50 employees who do not train the model and use it as intended; certain low-risk activitiesIn-person interviews; video interviews not analyzed by AINone — Title VII applies regardless of human or AI decisionmakerBots clearly used for non-deceptive purposes; certain platforms over 10M monthly US users
Best fit / who it bindsAny employer hiring for a NYC-based role using AI screeningAny business placing AI on EU market or whose AI output is used in EU regardless of where developedAny business making consequential decisions about Colorado residents using AIAny employer using AI video interview analysis for Illinois rolesEvery US employer with 15+ employeesAny business operating an online chatbot reachable by California residents

Sources as of June 2026 — verify at the relevant regulator: https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page, https://artificialintelligenceact.eu/, https://leg.colorado.gov/bills/sb24-205, https://www.ilga.gov/legislation/ilcs/ilcs5.asp?ActID=4015, https://www.eeoc.gov/ai, https://capitol.texas.gov/. AI statutes and regulator guidance change frequently — confirm current text with counsel before any deployment decision.

What each statute actually requires (and the consultancy decks you should ignore)

**NYC Local Law 144** is the most operationally specific bias audit law on the planet. The DCWP final rules at https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page define an Automated Employment Decision Tool as software that uses machine learning, statistical modeling, or AI to substantially assist or replace discretionary employment decisions. If you use one for NYC-based hires or promotions, you must commission an annual independent bias audit, publish a summary on your public site, and notify candidates at least ten business days before the AEDT is used. The audit must compute selection rate ratios and impact ratios across race/ethnicity and sex categories using the federal four-fifths rule framework — not a marketing 'fairness score.'

**The EU AI Act** at https://artificialintelligenceact.eu/ is a horizontal product safety regulation that treats AI like a regulated good. Annex III lists eight categories of high-risk systems; #4 covers AI used in employment, worker management, and access to self-employment — recruitment, advertising, screening, evaluating performance, terminating relationships. Providers of high-risk AI must run conformity assessments, maintain technical documentation, register the system in the EU public database, and operate a post-market monitoring system. Deployers must run a fundamental rights impact assessment, ensure human oversight, monitor system operation, and report serious incidents within 15 days. Most high-risk obligations apply from August 2, 2026; obligations for products in Annex II apply from August 2, 2027.

**The Colorado AI Act** (SB24-205) at https://leg.colorado.gov/bills/sb24-205 is the first comprehensive US state AI statute, effective February 1, 2026. It imposes algorithmic discrimination duties on both developers and deployers of high-risk AI systems — those making or substantially contributing to a consequential decision in employment, education, financial services, healthcare, housing, insurance, legal services, or essential government services. Deployers must run an annual impact assessment, notify consumers when high-risk AI is used to make a consequential decision, and offer correction and appeal rights. Enforcement is exclusive to the Colorado Attorney General; there is no private right of action, but algorithmic discrimination is treated as a deceptive trade practice.

**Illinois AI Video Interview Act** at https://www.ilga.gov/legislation/ilcs/ilcs5.asp?ActID=4015 has been in force since 2020 and is narrower than the headlines suggest. It applies only to employers using AI to analyze applicant video interviews for Illinois positions. Required actions: notify the applicant before the interview, explain how the AI works and what general characteristics it evaluates, obtain consent, limit who can view the video, destroy videos within 30 days of an applicant's request, and — if AI alone selects who advances to in-person interviews — report race and ethnicity data annually. There is no mandatory audit, but the disclosure-and-consent regime can stop a tool dead in its tracks if your vendor cannot describe the model in plain English.

**EEOC guidance** at https://www.eeoc.gov/ai is not new law — it is the agency's published view that Title VII, the ADA, ADEA, and GINA apply unchanged when AI is the decisionmaker. The 2023 technical assistance on the Uniform Guidelines on Employee Selection Procedures makes clear that the four-fifths rule is a starting point, not a safe harbor, for AI selection tools. The 2024 ADA guidance on AI in hiring addresses reasonable accommodation obligations when an assessment screens out candidates with disabilities. Employer liability does not transfer to the vendor; you are responsible for the discriminatory output of the tool you bought.

**California SB 1001** at https://leginfo.legislature.ca.gov/ is a bot-disclosure law that took effect July 1, 2019 — narrow but enforceable. It requires clear and conspicuous disclosure when an online bot is used to incentivize a sale or influence an election vote with California residents. **California AB 2930** is the proposed automated decisionmaking statute that has been re-introduced multiple times. As of June 2026, AB 2930 is not yet enacted — verify status at https://leginfo.legislature.ca.gov/. The California Civil Rights Council has finalized regulations on automated decisionmaking systems in employment under FEHA, effective October 2025, which functionally extend bias audit expectations to California employers.


Who counts as an independent auditor — the question every counsel asks

NYC LL 144 is the only one of the six regimes that mandates an independent auditor by statute, and the DCWP rules are surprisingly strict. Per https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page, an independent auditor must not have been involved in the development, training, or use of the AEDT; must not have a direct financial interest in the AEDT's continued use; and must not be an employee of the employer or the vendor. Practically, this disqualifies most vendor-led 'we audited ourselves' reports and forces engagement with a third-party firm — often a labor economist, an industrial-organizational psychologist, or a specialized algorithmic auditing firm.

The EU AI Act takes a different approach. For most Annex III high-risk systems, providers can self-certify through an internal conformity assessment per https://artificialintelligenceact.eu/. Only a narrow subset — remote biometric identification systems and AI components of products already covered by Annex II — require a Notified Body, the EU's accredited third-party assessor regime. This means most EU high-risk AI providers will run internal quality management systems documented to ISO/IEC 42001 or similar standards, and only call in a Notified Body when their product touches biometric identification or a regulated product category.

Colorado's SB24-205 does not require an independent auditor by statute. The impact assessment that deployers must complete can be performed internally, but it must include a description of the high-risk AI's purpose, intended outputs, data used, mitigation steps for algorithmic discrimination, and post-deployment monitoring. Pragmatically, the impact assessment must be defensible if the AG asks for it — which means most Colorado deployers will use a third-party assessor anyway, even though they are not strictly required to.

Illinois AIVIA does not require any audit at all. The compliance obligation is procedural: notify, explain, consent, restrict access, destroy on request, report demographics. The EEOC similarly does not mandate a specific audit. It does, however, expect employers to validate selection tools under the Uniform Guidelines on Employee Selection Procedures — a standard that pre-dates AI and that most AI hiring vendors do not meet out of the box. The compliance gap here is significant and underestimated.

California's emerging FEHA regulations on automated decisionmaking systems, effective October 2025, are closer to NYC LL 144's posture — they require anti-bias testing, recordkeeping for four years, and documentation of how the system was validated for the specific employment use case. They do not mandate an independent third party, but they do require records the Civil Rights Council can inspect on request.

The practical 2026 playbook: if you operate in NYC, hire an actual independent auditing firm. If you operate in the EU, build an internal quality management system aligned to ISO/IEC 42001 and reserve Notified Body engagement for biometric or Annex II products. If you operate in Colorado, document the impact assessment with the rigor you would use for a SOC 2. If you operate everywhere, the cheapest path is engaging one auditor whose work product satisfies the strictest regime that applies to you — usually NYC.


Audit cadence and what 'annual' actually means in practice

NYC LL 144 mandates an annual bias audit before an AEDT is used and every year thereafter. The DCWP rules at https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page require that the audit use data from at least the prior twelve months of actual use — or, if not available, test data prepared in a documented methodology. The audit summary that appears on your public site must include the dates of the audit, the source of the data, and selection rate plus impact ratio calculations for each major race/ethnicity and sex category. This is not a one-and-done procurement event; it is a recurring operational cost.

The EU AI Act treats cadence as continuous rather than annual. Post-market monitoring under Article 72 requires providers to systematically collect, document, and analyze data on the performance of the high-risk AI throughout its lifetime. Serious incidents must be reported to authorities within 15 days. Significant modifications that affect compliance trigger a fresh conformity assessment. Practically, this is heavier than an annual audit — it is a permanent process, more like ISO 27001 surveillance audits than a once-a-year report card.

Colorado's SB24-205 requires an impact assessment annually and within 90 days after any intentional and substantial modification to the high-risk AI system. The Colorado AG can also require additional documentation on request. The cadence is similar to NYC's but the substance is broader — Colorado's impact assessment must address all consequential decisions, not just employment.

Illinois AIVIA has no audit cadence because it has no audit. The annual race/ethnicity demographic reporting obligation only kicks in if AI is the sole basis to advance candidates to in-person interviews, and the data goes to the Illinois Department of Commerce and Economic Opportunity, not to a public database.

EEOC enforcement does not impose a cadence but expects ongoing monitoring under the Uniform Guidelines. Practically, employers should refresh their adverse impact analysis quarterly during heavy hiring cycles and annually otherwise, with a full revalidation any time the tool, the role, or the candidate population materially changes. Failure to monitor is a key fact pattern that turns a defensible disparate impact case into an indefensible one.

The cross-cutting answer: build an annual audit calendar that includes NYC LL 144, Colorado impact assessment, EU post-market monitoring report, and EEOC adverse impact review on the same cycle, then layer change-triggered re-audits when the model, training data, or use case changes materially. This is what most large multi-state employers are running by mid-2026, and it is what the AI vendor security questionnaire at AI vendor security questionnaire should be probing your vendors for as well.


Candidate and consumer notice — the part most teams get wrong

NYC LL 144 requires candidate notice at least ten business days before the AEDT is used. The notice must state that an AEDT will be used, what job qualifications and characteristics will be evaluated, where the candidate can request information about the data collected, and where to find the most recent bias audit summary. Critically, the candidate may request an alternative selection process — though the law does not require the employer to grant that request, denying it without a documented reason is the kind of fact pattern plaintiffs' counsel loves.

The EU AI Act layers multiple notice obligations. Article 26 requires deployers of high-risk AI to inform natural persons subject to the system's use that they are subject to such use. Article 86 grants affected persons the right to a clear and meaningful explanation of an AI-assisted decision that produces legal or significant effects. Article 50 requires transparency for emotion recognition and biometric categorization systems regardless of risk tier. The aggregate effect is that EU candidates must know they are being evaluated by AI, must understand the decision, and must have a path to human review.

Colorado's SB24-205 builds in a pre-decision notice obligation, an explanation right when AI contributes to an adverse consequential decision, the right to correct personal data used by the system, and the right to appeal to a human reviewer. The deployer must also publicly publish a summary statement describing what high-risk AI systems they use and how. This is the most consumer-rights-heavy of the US state regimes and the closest in spirit to the EU AI Act.

Illinois AIVIA requires three things before the interview: notify the applicant that AI may be used, explain how the AI works and what general characteristics it evaluates, and obtain explicit consent. If the applicant does not consent, the employer cannot use the AI analysis. Post-interview, the applicant may request that the video be destroyed and must be destroyed within 30 days of that request, including by all third parties.

EEOC technical assistance recommends — but does not require — that employers give candidates notice that AI is being used and an opportunity to request reasonable accommodations. The ADA reasonable accommodation obligation is the sharp edge here: if an assessment screens out a qualified candidate with a disability who could perform the job with accommodation, the employer is liable regardless of whether the AI was the proximate cause of the screen-out.

California's combined regime — SB 1001 bot disclosure, CCPA/CPRA right to opt out of automated decisionmaking once the regulations are finalized, and FEHA automated decisionmaking regulations — creates a notice obligation that resembles a hybrid of EU AI Act and Colorado. The pragmatic compliance posture for any multi-state employer is to write one candidate notice that satisfies the strictest applicable regime and deliver it before any AI evaluation, every time, regardless of jurisdiction. Trying to gate notice by candidate IP geolocation is more legal risk than it is worth.


Penalties and enforcement — what actually happens when you get caught

NYC LL 144 penalties are modest on their face but compounding in practice. Per https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page, the first violation is $500, each subsequent violation up to $1,500, and each day of continuing violation counts as a separate violation. For an AEDT used on hundreds of candidates over months before an enforcement action lands, the math is brutal. DCWP has issued enforcement notices since 2023 — verify current enforcement posture at the DCWP page before any deployment.

The EU AI Act has the highest theoretical penalty regime in the world for AI. Article 99 sets maximum fines at EUR 35 million or 7% of total worldwide annual turnover for prohibited practices, EUR 15 million or 3% for high-risk violations, and EUR 7.5 million or 1% for supplying incorrect information to authorities. The percentages bind even mid-cap companies that would not approach the absolute caps. Enforcement is by national competent authorities in each Member State; expect German, Dutch, and Irish DPAs to lead aggressive enforcement based on their GDPR track record.

Colorado's SB24-205 is enforced exclusively by the AG. There is no private right of action, which materially limits litigation risk compared to traditional discrimination statutes. Violations are treated as deceptive trade practices under Colorado law, which means penalties up to $20,000 per violation under the Colorado Consumer Protection Act, plus injunctive relief and restitution. The AG can also require compliance reports and impose consent decrees.

Illinois AIVIA has no specific monetary penalty in the statute itself. Enforcement runs through the Illinois Human Rights Act if discrimination is alleged, and the Illinois Attorney General has parallel consumer protection authority. The practical penalty exposure is a discrimination claim under IHRA, where damages can be substantial. The recordkeeping and disclosure obligations are also evidence the plaintiffs' bar will demand in any related discrimination case.

EEOC enforcement uses the Title VII penalty regime: back pay, compensatory damages up to caps that vary with employer size, punitive damages, attorney's fees, and injunctive relief. EEOC has been signaling AI hiring tool enforcement since 2022 and has resolved settlements involving algorithmic screening tools that produced disparate impact against older workers. The litigation cost alone often exceeds the audit cost by an order of magnitude.

California SB 1001 violations are unlawful business practices under the UCL, with penalties up to $2,500 per violation plus injunctive relief. The new FEHA automated decisionmaking regulations carry FEHA discrimination remedies — back pay, emotional distress damages, punitive damages, attorney's fees. Texas TRAIGA (HB 149, the Texas Responsible AI Governance Act) was enacted in 2025 — verify current text at https://capitol.texas.gov/ — and creates a tiered penalty regime for prohibited and high-risk AI uses, plus a regulatory sandbox; it is the third US comprehensive state AI law and is increasingly cited by counsel as a template for what other red-state legislatures will pass in 2027.


Build vs buy: who you actually hire to run the audit

The independent auditor market has matured fast since NYC LL 144 went live. The credible vendors fall into three buckets. First, established labor economics and I/O psychology consultancies — Aon, Korn Ferry, SHL, DCI Consulting — that have decades of disparate impact analysis experience and have built AEDT audit practices on top. Second, algorithmic auditing specialists like ORCAA, Babl AI, BNH.AI, and Eticas that focus exclusively on AI fairness audits. Third, Big Four advisory practices — Deloitte, EY, KPMG, PwC — that bundle AI audits into broader risk assurance engagements.

Pricing as of June 2026 is opaque because vendors quote per system. A defensible AEDT bias audit for a single hiring tool used at moderate scale runs roughly $25,000 to $75,000 for the first engagement and $15,000 to $40,000 for annual renewals, per practitioner reporting; verify with each vendor before contracting. EU AI Act conformity assessments by a Notified Body for biometric systems run materially higher — six figures is common. Colorado impact assessments performed internally are essentially the loaded cost of two to four weeks of compliance and legal time per high-risk system.

The cheapest credible path for a US-only multi-state employer is engaging one specialist auditor — typically an algorithmic auditing firm — to run a single audit work product that satisfies NYC LL 144's selection rate and impact ratio requirements, Colorado's impact assessment requirements, and EEOC's adverse impact framework simultaneously. This requires asking the auditor up front for a multi-regime scope of work; do not let them default to the NYC-only template.

Where build-it-yourself works: large employers with internal I/O psychology or people analytics teams can run the actual statistical analysis in-house and engage an outside auditor only for the independence signature required by NYC LL 144. This pattern saves real money on annual renewals but requires that the internal team genuinely understands the four-fifths rule, two-sample tests, and the EEOC's preferred validation studies. If your in-house bench is shallow, this becomes 'we did it ourselves and the AG noticed.'

Where build-it-yourself does not work: any time the AI system is a black-box vendor model where you cannot inspect training data or model weights. In those cases, the audit is a downstream input-output analysis only, and the vendor often holds the data you need to do it. Push the vendor to provide audit-ready data exports as a contractual obligation — selection rates by candidate demographic, score distributions by demographic, validation evidence by job family. If they refuse, the tool is not deployable in NYC, Colorado, or the EU.

The bottom line on the auditor decision: do not let your AI vendor pick your independent auditor. The conflict-of-interest rules in NYC LL 144 make vendor-selected auditors a defensibility risk, and the optics in any enforcement action are bad. Engage an auditor directly, with a scope of work written by your counsel, and treat the auditor's report as your work product — not the vendor's marketing collateral. The matching policy framework lives at AI acceptable use policy template.


Texas TRAIGA, sectoral AI rules, and what is coming next

Texas joined the comprehensive AI statute club with HB 149 — the Texas Responsible AI Governance Act — enacted in 2025; verify current text and effective dates at https://capitol.texas.gov/. TRAIGA borrows structure from the EU AI Act and Colorado SB24-205 but is narrower than either: it focuses on prohibited uses (manipulative AI, social scoring by government), creates a regulatory sandbox under the Texas Department of Information Resources, and imposes algorithmic-discrimination duties on developers and deployers of certain high-risk systems. Enforcement is by the Texas Attorney General. Penalty tiers run from $10,000 to $200,000 per violation, with cure-period provisions that NYC LL 144 lacks.

Beyond the comprehensive statutes, a thicket of sectoral rules now expects bias-audit-like documentation. The Department of Housing and Urban Development's 2024 guidance on tenant screening AI; the CFPB's adverse action notice expectations when AI is used in credit decisions; the FDA's published framework for AI/ML medical devices with the Predetermined Change Control Plan; New York Department of Financial Services Circular Letter No. 7 on AI in insurance underwriting — each of these now expects fairness testing documentation that looks a lot like a bias audit, even if the statute does not use the words.

State-level activity is accelerating. As of June 2026, more than 25 US states have either enacted or have pending comprehensive AI legislation. Connecticut, Virginia, New Jersey, and Washington all have bills in committee that follow the Colorado template — high-risk AI systems, impact assessments, algorithmic discrimination duties, AG enforcement. The pragmatic compliance posture for any multi-state employer is to assume the Colorado regime is the floor and design around it.

On the federal side, no comprehensive AI statute has cleared Congress as of June 2026. The October 2023 White House Executive Order on AI was rescinded in early 2025 and replaced with a lighter-touch directive emphasizing US AI competitiveness. NIST's AI Risk Management Framework remains the de facto federal reference and is increasingly cited by state regulators — the NIST AI RMF Generative AI Profile published in 2024 is the document your compliance team should be reading alongside the statutes.

Internationally, the OECD AI Principles, UK's pro-innovation approach (no comprehensive statute, sector-led), Canada's AIDA (delayed but pending), Brazil's PL 2338 (passed Senate in 2024), Korea's Framework Act on AI (effective 2026), and Japan's lighter guidance regime all shape multinational compliance. If you operate in the EU plus three of these jurisdictions, you are running at least five overlapping audit regimes. Map them to one matrix and pick the strictest as your global floor.

What is coming next that practitioners should be watching: the EU AI Office's harmonized standards under Article 40, which will define what 'conformity' actually means in practice; the next round of NYC DCWP rule revisions that may extend AEDT obligations to broader employment decisions; the Colorado AG's first enforcement actions in 2026 that will calibrate expectations; and the FTC's continued posture that AI-driven unfair or deceptive practices are squarely within Section 5 enforcement, regardless of state statute. The compliance burden is going up, not down. Build for it now.


The opinionated 2026 pick: how to actually stand up a compliant program

If I were standing up an AI bias compliance program for a US multi-state employer with 5,000 employees and AI in hiring tomorrow, I would do four things. First, commission an NYC LL 144 bias audit on every AI hiring tool used for NYC roles, even tools used in only one role, even tools the vendor claims are 'not AEDTs.' The DCWP definition is broad and the penalty for being wrong is more expensive than the audit. Use a specialized algorithmic auditing firm, not the vendor's preferred partner.

Second, run a Colorado SB24-205 impact assessment on every high-risk AI system before February 1, 2026. The impact assessment scope is broader than NYC LL 144's bias audit — it covers algorithmic discrimination mitigation, data quality, post-deployment monitoring, and consumer notice. Document it like you would document a SOC 2 control narrative. The Colorado AG will be looking for substance, not boilerplate.

Third, if you have any EU footprint — even just EU-resident customers, EU-resident employees, or EU-targeted output of the AI — assume the EU AI Act applies and build the technical documentation and post-market monitoring system now. The August 2026 deadline for most high-risk obligations is a hard wall; do not start scoping in Q2.

Fourth, write one candidate notice template that satisfies NYC LL 144, Colorado SB24-205, Illinois AIVIA, California FEHA automated decisionmaking, and the EU AI Act Article 86 explanation right simultaneously. Deliver it to every candidate at the start of any AI-evaluated process, regardless of jurisdiction. Trying to gate notice by candidate location is more risk than it saves.

If I were a small employer — say, 50 to 200 employees, no NYC roles, no EU footprint — the calculus is simpler. The EEOC framework binds you regardless of state law; document your AI hiring tool selection, validate it under the Uniform Guidelines as best your vendor allows, run an internal adverse impact review quarterly during heavy hiring periods, and revisit each January. If Colorado roles appear, add the SB24-205 impact assessment. If NYC roles appear, hire the auditor.

The one thing I would not do in 2026 is treat AI bias audits as a one-time procurement event. The statute text is settling, but the enforcement posture and the harmonized standards are still being written. Build a compliance program that updates annually, not a checkbox that ages instantly. And for everything you build, validate that your AI vendors will support it — the AI vendor security questionnaire covers the procurement-side questions that map to these obligations.

How to pass an AI bias audit across NYC LL 144, EU AI Act, and Colorado in 2026

  1. 1

    Step 1: Inventory every AI system that makes or substantially assists a consequential decision

    Before you commission anything, build a single spreadsheet listing every AI system in use at your company that affects hiring, promotion, termination, compensation, credit, housing, insurance, education, healthcare, or government services. For each, capture: vendor, model, what decision it informs, in which jurisdictions, candidate or consumer volume per year, whether the output is sole basis or human-reviewed, what data flows in, what data flows out. Most companies underestimate this list by 2 to 3 times — resume screeners, calendar scheduling AI, video interview analyzers, performance management tools, internal mobility recommenders, and benefits eligibility engines all qualify. If you cannot list it, you cannot audit it. If you cannot audit it, you cannot defend it.

  2. 2

    Step 2: Map each system to the regimes that bind it

    For every system in the inventory, mark which of the six regimes applies: NYC LL 144 (NYC-based roles), EU AI Act Annex III (EU placement or output), Colorado SB24-205 (Colorado consumers), Illinois AIVIA (Illinois video interviews), EEOC (always), California FEHA ADM regs (California applicants or employees). Add Texas TRAIGA per https://capitol.texas.gov/ for Texas-resident impacts. Most enterprise systems hit three to five regimes simultaneously. Design the audit work product to satisfy the strictest applicable regime — that is almost always either NYC LL 144 for the statistical methodology or the EU AI Act for the documentation completeness. Build once, defend everywhere.

  3. 3

    Step 3: Engage a genuinely independent auditor with a multi-regime scope of work

    Issue an RFP to two or three algorithmic auditing firms — not your AI vendor's preferred partner. The scope of work must include: NYC LL 144 selection rate and impact ratio calculations across the federal race/ethnicity and sex categories, EEOC Uniform Guidelines adverse impact analysis, Colorado SB24-205 impact assessment narrative including algorithmic discrimination mitigation, and an EU AI Act conformity assessment gap analysis if EU is in scope. Negotiate the deliverable: a public-facing audit summary suitable for the NYC LL 144 disclosure obligation, plus a confidential full report defensible to the Colorado AG and EU competent authorities. Pricing reference is roughly $25,000 to $75,000 per system for the first audit; verify with each firm before signing.

  4. 4

    Step 4: Publish the disclosures and stand up candidate notice and explanation flows

    Post the NYC LL 144 audit summary on your public site at a stable URL — DCWP rules at https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page expect it within the employer's careers section or equivalent. Update every job posting touched by an AEDT to include the candidate notice ten business days in advance, with the alternative-selection-process language and the data-collection inquiry path. Build the explanation flow: when an AI-assisted decision adversely affects a candidate or consumer in Colorado or the EU, the system must produce a written explanation describing what the AI evaluated, what data was used, and how to appeal to a human reviewer. Most existing ATS systems do not support this out of the box — scope the build.

  5. 5

    Step 5: Operationalize annual cadence plus change-triggered re-audits

    Bias audits are not procurement events. Build an audit calendar that pairs every AI system with its annual review date, its EU AI Act post-market monitoring report date, its Colorado impact assessment refresh date, and a change-trigger rule for re-auditing whenever the model, training data, candidate population, or use case changes materially. Assign an internal owner — usually People Analytics or Compliance, not Legal — who owns the inventory, the renewal cadence, and the change-trigger reviews. Budget the annual cost as a fixed line item in compliance, not as a per-deal expense. Layer the matching policy framework from AI acceptable use policy template on top so usage rules and audit obligations move in lockstep across the business.

Continue your research on adjacent topics — calculators, rate limits, head-to-head comparisons, and guides.

Frequently Asked Questions

Does NYC Local Law 144 apply if my company is headquartered outside New York but I hire for a NYC-based role?

Yes. NYC LL 144 applies to any AEDT used to substantially assist or replace discretionary employment decisions for a position physically located in New York City — or for a fully remote position where the employer is in NYC. Headquarters location is irrelevant. Per the DCWP final rules at https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page, the obligation attaches to the use of the tool for the NYC role, not the employer's principal place of business. If you hire one NYC-based engineer through an AI-screened ATS, the AEDT used for that requisition needs an annual independent bias audit, the public summary disclosure, and the 10-business-day candidate notice. Companies that try to ring-fence NYC roles out of the AI-screening flow have generally found that operationally messier than just running the audit.

When does the EU AI Act actually start enforcing high-risk AI obligations?

The EU AI Act has a staggered effective date schedule per https://artificialintelligenceact.eu/. Prohibited AI practices became enforceable February 2, 2025. General-purpose AI model obligations took effect August 2, 2025. Most high-risk system obligations under Annex III — including the employment AI relevant to HR teams — apply from August 2, 2026. Annex II products (AI components of regulated products like medical devices, vehicles, machinery) get an additional year, applying from August 2, 2027. For HR and recruitment AI specifically, the August 2026 wall is the binding deadline. Conformity assessments, technical documentation, post-market monitoring, fundamental rights impact assessments, EU database registration, and the rest of the high-risk obligation stack must all be in place by that date for any system placed on the EU market or whose output is used in the EU.

Is the Colorado AI Act actually going to be enforced in February 2026, or will it be delayed?

As of June 2026, SB24-205 took effect February 1, 2026 as scheduled per https://leg.colorado.gov/bills/sb24-205. There were active discussions in the Colorado legislature throughout 2025 about narrowing the statute's scope or extending the effective date, and a 2025 amendment did clarify several definitions, but the core algorithmic discrimination duties and impact assessment requirements went live on schedule. Enforcement is exclusive to the Colorado Attorney General, and the AG's office signaled in early 2026 that the first year would focus on egregious violations and willful non-compliance rather than technical paperwork gaps. That said, technical paperwork gaps in 2027 will be a different conversation. Build the impact assessments now; verify current enforcement guidance at the AG's office.

What is the difference between the EU AI Act conformity assessment and an NYC LL 144 bias audit?

They overlap but are not the same. NYC LL 144's bias audit is narrow and statistical: selection rate ratios and impact ratios by race/ethnicity and sex categories, performed by an independent auditor, summarized publicly. The EU AI Act's conformity assessment is broader and process-based: documentation of the AI system's intended purpose, risk management system, data governance, technical documentation, transparency provisions, human oversight, accuracy, robustness, cybersecurity, and quality management system. Most high-risk EU systems use internal conformity assessment; only biometric identification systems and Annex II products need a Notified Body. Practically, a strong NYC LL 144 audit can be one input into the broader EU conformity assessment — but it does not replace it. Per https://artificialintelligenceact.eu/, the EU expects the full technical file.

Do I need to audit AI tools we use internally that do not directly make hiring decisions?

Maybe — read the statute language carefully. NYC LL 144 covers AEDTs used to substantially assist or replace discretionary employment decisions. An AI tool that summarizes calls between recruiters and candidates probably does not qualify. An AI tool that scores candidates and presents a ranked list to recruiters, even if the recruiter makes the final call, probably does. The DCWP final rule's definition of substantially assist is broad. The EU AI Act's Annex III #4 is broader still — any AI used in recruitment, candidate selection, evaluating performance, allocating tasks, or terminating employment is high-risk regardless of whether a human signs off. Colorado SB24-205 uses substantially contribute, which similarly captures recommendation engines. The safe operational posture: any AI whose output measurably changes who advances or what they are offered is in scope.

Can I rely on my AI vendor's bias audit instead of commissioning my own?

Generally no. Under NYC LL 144 specifically, the DCWP rules at https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page require an audit performed by an independent auditor — and a vendor-engaged audit on the vendor's own product typically fails the independence test. Even when a vendor's audit was performed by a credible third party, it audits the tool in general, not your deployment, your candidate population, or your role-specific configuration. The EEOC has been clear that employer liability does not transfer to the vendor; you are responsible for the discriminatory output of the tool you bought regardless of what the vendor's marketing claims. The defensible posture is to engage your own auditor, use the vendor's documentation and data exports as inputs, and treat the audit as your work product.

What does Illinois AIVIA require if I use AI to screen video interviews?

Per https://www.ilga.gov/legislation/ilcs/ilcs5.asp?ActID=4015, AIVIA imposes five procedural obligations on employers using AI to analyze applicant video interviews for Illinois positions. First, notify the applicant before the interview that AI may be used. Second, provide information explaining how the AI works and what general types of characteristics it uses to evaluate applicants. Third, obtain the applicant's consent to be evaluated by the AI. Fourth, limit who can view the video — only persons whose expertise or technology is necessary to evaluate the applicant. Fifth, destroy the video and all copies within 30 days of an applicant's request. Additionally, if AI is the sole basis to advance applicants to in-person interviews, employers must report race and ethnicity data annually. AIVIA does not require a bias audit, but the disclosure and consent regime functionally limits what tools can be deployed.

How does EEOC guidance on AI differ from formal AI bias audit laws?

EEOC guidance at https://www.eeoc.gov/ai is not new law and creates no new audit obligation. It is the agency's published interpretation that existing federal employment statutes — Title VII, ADA, ADEA, GINA — apply unchanged when AI is the decisionmaker. The 2023 technical assistance applies the Uniform Guidelines on Employee Selection Procedures to AI selection tools, including the four-fifths rule as a starting point for disparate impact analysis. The 2024 ADA technical assistance addresses reasonable accommodation obligations when AI screens candidates. The practical effect is that every US employer with 15 or more employees has an ongoing obligation to validate AI hiring tools and to monitor for adverse impact, regardless of whether NYC, Colorado, Illinois, or California law applies. EEOC enforcement under Title VII is well-established and the remedies are substantial — back pay, compensatory and punitive damages, attorney's fees.

What is Texas TRAIGA and how does it compare to Colorado SB24-205?

The Texas Responsible AI Governance Act (HB 149) was enacted in 2025 — verify current text at https://capitol.texas.gov/ — and is the third comprehensive US state AI statute after Colorado SB24-205 and the patchwork in California. TRAIGA borrows the developer-and-deployer structure from Colorado and the prohibited-practices structure from the EU AI Act, but is narrower than either. It prohibits certain AI uses (manipulative AI causing harm, social scoring by government), establishes a regulatory sandbox under the Texas Department of Information Resources, and imposes algorithmic discrimination duties on developers and deployers of high-risk systems. Enforcement is by the Texas Attorney General with cure-period provisions Colorado lacks. Penalty tiers run from $10,000 to $200,000 per violation. For multi-state employers, TRAIGA adds a third comprehensive regime to the Colorado plus EU plus NYC stack — design the compliance program to satisfy the strictest applicable obligation and the others fall into place.

You now know which AI bias audit laws bind you. Now make every prompt your AI hiring tools run actually hit.

AI Prompt Generator builds production-ready system prompts that work across ChatGPT, Claude, Gemini, and every AI hiring, screening, and evaluation tool covered by the regimes in this article — so your audit-ready AI outputs are defensible, consistent, and traceable, not generic AI fluff. Stop tweaking prompts by hand and start shipping prompts that survive a regulator's review. 14-day free trial, no credit card required.

Browse all prompt tools →