
Make talent quality your leading analytic with skills-based hiring solution.

AI hiring compliance in 2026 means two specific things for most global employers: passing an independent bias audit and posting the results under New York City’s Local Law 144 if you hire candidates who live in NYC, and treating your hiring AI as a high risk system under the EU AI Act if you use it to screen, rank, or evaluate candidates in the EU. Both regimes are active law today, both changed meaningfully in 2026, and both put direct obligations on the screening tools recruiting teams already use, not just on a compliance department.
This is general information about how these two laws work, not legal advice. Requirements vary by exact use case, jurisdiction, and how your specific tools are built and deployed, so talk to counsel about your organization’s actual obligations before finalizing a compliance program.
An Automated Employment Decision Tool, or AEDT, is any computational process using machine learning, statistical modeling, or similar techniques that substantially assists or replaces discretionary human decision making in hiring or promotion. In practice, that covers resume screening software, video interview scoring, skills assessment scoring, and any AI feature that ranks or filters candidates before a human recruiter sees them. It does not automatically cover every piece of software touching your hiring process. A tool used purely for scheduling, or one whose output a human reviewer meaningfully overrides in every case, generally falls outside the definition, though the line depends heavily on the specific facts.
The law applies based on where the candidate lives and works, not where the employer is headquartered. A remote first company with no New York office can still trigger Local Law 144 obligations the moment it evaluates a New York City based candidate with an AEDT.
A Local Law 144 bias audit requires an independent evaluation of an AEDT’s selection or scoring rates across sex, race and ethnicity categories, and their intersections, calculated at least once every twelve months and before the tool is used on covered candidates. Auditors typically apply the EEOC’s four fifths rule as a reference point, flagging any group whose selection rate falls below 80 percent of the highest scoring group’s rate as a potential adverse impact signal, though the law itself does not mandate a single pass or fail threshold.
The audit has to be conducted by an independent party, meaning one that was not involved in developing or deploying the tool being tested. Employers and employment agencies cannot simply run their own internal fairness check and call it compliant.
Two disclosure obligations sit alongside the audit itself. First, a summary of the most recent bias audit results has to be posted publicly, typically on the careers page or a linked results page, before the AEDT is used. Second, candidates and employees residing in New York City must receive notice at least 10 business days before an AEDT is used to evaluate them, including what the tool assesses and, on request, information about the data it relies on. Candidates also have the right to request an alternative selection process or accommodation where one is available.
Skipping either disclosure is treated as its own violation, separate from skipping the audit itself, so a technically compliant audit that never gets published or never triggers candidate notice still leaves an employer exposed.
New York City’s Department of Consumer and Worker Protection can fine employers between 500 and 1,500 dollars per violation, and every day a noncompliant AEDT stays in use counts as a new violation, so exposure compounds quickly on tools left unaudited for months.
Enforcement has also visibly tightened in 2026. A December 2025 New York State Comptroller audit of DCWP’s enforcement found that when the Comptroller independently reviewed 32 companies’ published bias audits, it identified at least 17 instances of potential noncompliance, compared to only one issue DCWP itself had flagged in the same companies. The audit also found DCWP had received just two complaints in its first two years of enforcement and had not tested whether its own complaint intake process worked. The takeaway for TA and HR teams is not that Local Law 144 is toothless. It is that quiet noncompliance has been easy to get away with so far, and that regulators are actively being pushed toward closer scrutiny.
Yes. Annex III of the EU AI Act explicitly classifies AI systems used to recruit or select candidates, including tools that place targeted job ads, filter applications, or evaluate candidates, as high risk AI systems. A second Annex III category covers AI used to manage active employment relationships, including performance monitoring, task allocation, and decisions about promotion or termination. Together, these two categories mean most AI powered screening, scoring, and interview evaluation tools used on candidates in the EU are high risk by default, not by exception.
High risk classification under the EU AI Act splits obligations between the provider that builds the AI system and the deployer, typically the employer, that puts it to use.
Providers generally have to maintain a risk management system across the tool’s lifecycle, govern and document the training data used, produce technical documentation, build in human oversight capability, and register the system in an EU database before it reaches the market.
Deployers, meaning most employers using a vendor’s hiring AI, carry their own obligations: using the system according to its instructions, assigning a human to meaningfully oversee its outputs, keeping logs, and informing affected candidates or employees that an AI system is being used to help make a decision about them. Higher risk deployments can also require a fundamental rights impact assessment before rollout.
Penalties for noncompliance with high risk AI obligations under the EU AI Act can reach up to 15 million euros or 3 percent of a company’s global annual turnover, whichever is higher, so this sits well above nuisance fine territory for any organization operating at scale in the EU.
Yes, and this is one of the most important updates for anyone planning around this law in 2026. The original date for Annex III high risk obligations, including the employment and recruitment categories, was August 2, 2026. Regulation 2026/1744, commonly called the Digital Omnibus on AI, was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026, pushing that application date out to December 2, 2027.
That delay matters, but it is narrower than it sounds. The Digital Omnibus deferred the high risk conformity obligations specifically, not the EU AI Act’s transparency rules. Requirements like informing people they are interacting with an AI system, and disclosure and notification duties tied to biometric and emotion recognition features, remain on their original 2026 schedule. Practically, that means an employer using AI powered video interviewing or scoring in the EU still has near term transparency duties to meet in 2026, even though the deeper high risk documentation, oversight, and conformity assessment obligations for hiring specifically now land in December 2027 instead of this past August.
Treat December 2027 as the deadline to be fully ready by, not as a reason to wait. Building bias auditing, human oversight, and documentation practices now also puts most of what Local Law 144 already requires in place, so the two compliance tracks reinforce each other rather than competing for attention.
A workable AI hiring compliance program for 2026 generally includes the following steps.
Teams looking to go deeper on how AI actually functions inside the hiring process, separate from the compliance angle, can start with glider.ai’s guide to AI in recruitment for HR professionals or the broader AI recruiting guide, both of which map out where these tools sit in a modern hiring funnel.
Yes. DCWP has enforced Local Law 144 since July 2023, and a December 2025 State Comptroller audit specifically criticized DCWP for under enforcing it, which has increased pressure for stricter oversight rather than reducing it.
Yes, if a US based company uses an AI hiring system to evaluate candidates located in the EU, or places the system on the EU market, the EU AI Act’s high risk obligations can apply regardless of where the company is headquartered.
Any tool using machine learning, statistical modeling, or similar computational methods that substantially assists or replaces human judgment in hiring or promotion decisions, including resume screening, interview scoring, and skills assessment scoring tools.
It is a common reference point where a candidate group’s selection rate below 80 percent of the highest scoring group’s rate is flagged as a potential adverse impact signal, though Local Law 144 itself does not set one mandatory pass or fail threshold.
At least 10 business days, along with a description of what the tool assesses and, on request, information about the data behind it.
The core high risk documentation, oversight, and conformity obligations for Annex III employment and recruitment systems now apply from December 2, 2027, after the Digital Omnibus deferral that took effect in July 2026. Certain transparency obligations remained on the original 2026 timeline.
Exposure compounds daily under Local Law 144, since each day of noncompliant AEDT use is its own violation, and separately, EU AI Act high risk violations can reach into the tens of millions of euros depending on company size, so the practical risk of doing nothing grows the longer a screening tool goes unaudited and undocumented.

An AI voice interview is a phone or voice call where an AI agent, not a human recruiter, asks candidates job related questions, listens to their spoken answers, and scores the conversation in real time. It is quickly becoming the default way many companies run first round screening, replacing the recruiter phone screen as the […]

Internal mobility beats external hiring on cost, speed, and retention in most measurable ways, but only when a company can actually see what its employees are capable of. Without verified skills data, an internal talent marketplace is just a job board with extra steps, and most stall out within a year of launch. The difference […]

Candidate ghosting is when a job applicant stops responding, skips a scheduled interview, or goes silent after accepting an offer, without any explanation to the employer. It is not a rare annoyance anymore. It is now a routine, recurring drain on recruiting operations, and it is getting worse heading into the second half of 2026. […]