Everyone Lists the Same Four Laws. Almost No One Has the Dates Right.

NYC, Illinois, Colorado, and the EU each regulate AI hiring differently — and three of the four changed within the last year. Here's what's actually in force right now, what isn't yet, and what each one actually requires once it is.

Everyone Lists the Same Four Laws. Almost No One Has the Dates Right.

6 min read

Key Takeaways

  • Three of the four frameworks moved in the last year — Colorado’s original AI Act was blocked by a federal court and then repealed and replaced, Illinois’s HB 3773 took effect January 1, 2026, and the EU’s deferral of high-risk hiring rules is now fully in force, not just proposed. Anything citing the old versions is already wrong.
  • “In force” isn’t one condition — NYC’s audit-and-publish duty, Illinois’s notice duty, Colorado’s future notice-and-recourse duty, and the EU’s product-safety duty are four structurally different obligations, not four versions of the same rule.
  • A law taking effect and a law being fully defined aren’t the same milestone — Illinois’s statute is live, but the state’s own implementing rules were pulled back mid-2026, leaving employers bound to requirements without finalized guidance on exactly how to meet them.
  • None of these laws tell you what makes a bias audit itself trustworthy — sample size, methodology, auditor independence. That’s a separate question from whether a law applies, and it’s the one most compliance checklists skip entirely.

Most compliance checklists treat these four laws the same way: one bullet apiece, same tone, same implied urgency. That’s not accurate, and it wasn’t accurate six months ago either. One of these laws was blocked by a federal court before its own start date. Another had its heaviest provisions pushed back more than a year, then that delay itself became final law. Treating “AI hiring law” as one flat category is how a checklist goes stale the day it publishes — and for an employer hiring across state lines, this isn’t trivia. It’s four separate obligations, on four separate timers, with four different definitions of “compliant.” Getting one date wrong doesn’t just mean an awkward correction later. It means telling a candidate or a regulator that a control exists when it doesn’t yet, or that it doesn’t apply when it already does.

Timeline comparing when AI hiring laws in New York City, Illinois, Colorado, and the European Union take effect and when further changes are expected.

NYC Local Law 144: AI hiring compliance in force since 2023

Status: In force since July 5, 2023 — the only one of the four with real track record.

Any automated tool used to evaluate candidates for NYC-based roles needs an independent bias audit, repeated every year, with a summary published where candidates can find it — selection rates and impact ratios by category, the audit date, and where the data came from, the same kind of numbers referenced in our own mythbusting piece on this topic. Candidates get a separate notice, too: employers must post that an automated tool will be used at least ten business days before it runs, with instructions for requesting an alternative process. NYC’s Department of Consumer and Worker Protection enforces it, and a tool running without a current audit on file is a gap regardless of how well it performs. Eightfold’s own NYC disclosure is what that looks like from the vendor side.

Illinois — HB 3773

Status: In force since January 1, 2026 — statute live, implementing rules still unsettled.

Illinois didn’t build a new audit regime. It folded AI-assisted employment decisions directly into the state’s existing Human Rights Act. Employers must notify candidates when AI plays a role in hiring, promotion, discipline, or discharge, and be able to explain what the tool does in plain language. A discriminatory outcome isn’t a novel “AI” violation — it’s prosecuted the same way a human decision would be, under a Human Rights Act the state has enforced for decades. “The algorithm decided, not us” was never going to be a defense. One wrinkle worth knowing: in June 2026, the Illinois Department of Human Rights withdrew its proposed implementing rules to keep coordinating with other state agencies, with no revised timeline given. The statute’s notice and non-discrimination duties still apply in full — employers just don’t yet have finalized regulatory detail on exactly what notice language or timing satisfies it.

Colorado — Senate Bill 26-189

Status: Not yet in force. Effective January 1, 2027 — and litigation isn’t over.

The original Colorado AI Act (SB 24-205) was one of the most demanding frameworks in the country: mandatory impact assessments, an explicit duty to prevent algorithmic discrimination, ongoing risk-management programs. It never took effect as written — a federal court blocked its enforcement in April 2026 after a constitutional challenge, and facing that pressure plus industry pushback, Colorado’s legislature repealed it and signed SB 26-189 in its place in May 2026. What’s left, effective 2027, is considerably lighter: advance notice before using “covered automated decision-making technology,” a plain-language explanation within 30 days of an adverse decision, a right to request data correction, and a right to request human reconsideration — “to the extent commercially reasonable,” the statute’s own qualifier, not an unconditional guarantee. Legal challenges to this version are reportedly expected too, so treat January 2027 as the current target date, not a settled one.

Framework Core duty Status
Original SB 24-205 Impact assessments, discrimination-prevention duty, ongoing risk management Blocked by federal court; repealed
SB 26-189 Advance notice, 30-day adverse-decision explanation, data correction, conditional human reconsideration Effective January 1, 2027; further challenges possible

The European Union — the AI Act

Status: High-risk hiring obligations effective December 2, 2027 — now confirmed, not proposed.

The EU’s Digital Omnibus deferral cleared its final procedural step: it entered into force in July 2026 as Regulation (EU) 2026/1744, pushing Annex III high-risk obligations — which name recruitment and employee-evaluation tools explicitly — from August 2026 to December 2, 2027. That’s mandatory risk management, technical documentation, human oversight, and formal conformity assessment once it lands. One piece isn’t waiting on that extension at all: Article 50’s transparency duty was never delayed, so a candidate talking with an AI interviewer in the EU should already be told, in that conversation, that it’s AI. High-risk non-compliance carries penalties up to €15 million or 3% of global turnover — the middle of three tiers, below the €35M/7% ceiling reserved for banned practices.

Federal Anti-Discrimination Law Remains the Baseline for AI Hiring Compliance Laws

None of this replaces the federal baseline. Title VII bars employment discrimination for covered employers with 15 or more employees; the ADA uses the same threshold; the ADEA covers employers with 20 or more. Those statutes apply whether a tool or a person made the call. EEOC guidance sits alongside them, not inside them — its 2022 ADA technical assistance and 2023 Title VII guidance address algorithmic risk, but neither is itself an enacted AI-specific law. A vendor’s audit results don’t shift an employer’s own exposure either way.

AI hiring compliance laws: four different levers, one employer answer

Line them up and the differences are structural, not cosmetic. NYC uses audit-and-publish: prove your numbers annually, in public, or you’re out of compliance regardless of intent. Illinois uses an existing civil-rights framework — an AI-assisted decision wins or loses the same way a human one would. Colorado, post-rewrite, uses notice-and-recourse: tell people before, explain yourself after, let them ask a person to look again. The EU uses product-safety: classify, document, assess, prove it before it ships — closer to how a regulator treats a medical device than a marketing claim. Same underlying concern in all four, four entirely different ways of making an employer answer for it. A vendor that only knows how to answer one of those questions isn’t ready for a customer operating across more than one.

Building an AI Hiring Compliance Checklist That Actually Works

  1. Map every recruitment tool by role location, including remote work, and inventory who owns each one.
  2. Classify each use and assign provider/deployer or controller/processor responsibility in writing.
  3. For NYC roles, confirm the bias audit on file is current within 12 months before using the tool.
  4. Send the notice each jurisdiction requires — including NYC’s ten-business-day timing.
  5. Keep a human involved at every material decision point, and log correction and reconsideration requests.
  6. Track legislative and rulemaking dates quarterly — Illinois and Colorado alone show how fast a “final” framework can still move.

What none of this tells you

Four jurisdictions, four different definitions of “in force,” and that’s before the next state files its own version. None of these laws tell you what actually makes a bias audit valid — how large a sample has to be before a result means something, or what separates a real gap from a coincidence in this quarter’s data. That’s not a legal question. It’s a math one, and it’s the one almost nobody outside the auditors explains clearly.

One more thing this piece doesn’t do: replace your own counsel. Effective dates shift — three of the four changed in the time it took to track them — so confirm applicability against the current statutory text before filing anything on the strength of a blog post, ours included.

That’s next.

Frequently Asked Questions

Does a later EU deadline delay a live NYC or Illinois obligation? No. Each jurisdiction’s timeline runs independently — meet every applicable deadline that’s currently in force, regardless of what’s still pending elsewhere.

Is an employer responsible for a vendor’s tool? Yes. Vendor documentation and contracts can allocate tasks, but they don’t remove the employer’s own employment-law exposure. A human decision-maker still has to be involved at material points.

Is a Local Law 144 alternative process the same as an ADA accommodation? No. They’re separate requests handled through separate processes — one doesn’t substitute for the other.

What do staffing firms need to know? Under the EU AI Act specifically, a firm that develops or materially modifies a tool becomes a “provider” with documentation duties; one that simply uses it for recruitment is a “deployer” following the provider’s instructions. Both roles carry duties — allocation isn’t automatic and belongs in the contract, with counsel.

How does location affect coverage? Map the candidate’s location, the role’s location, and the employer’s footprint separately — NYC coverage, for instance, can turn on where the job is based even when interviews happen elsewhere. Remote-work facts are genuinely jurisdiction-specific; route them to counsel rather than assuming.

What if an NYC audit is older than 12 months? Don’t use the tool for covered NYC hiring activity until a current, independent bias audit is completed and the required summary is published.

How often should this map get reviewed? At minimum quarterly, and before launching any new tool or expanding into a new role location — these four clocks move faster than an annual policy cycle.

Share Popup Title

Share this article