AI hiring bias audit requirements: NYC Local Law 144, Illinois, Colorado, the EU AI Act and the UK
Among the rules covered here, only New York City's Local Law 144 requires a published, independent bias audit of AI hiring tools, done within 1 year before use and reporting impact ratios by sex and race or ethnicity. Illinois (since January 1, 2026) and Colorado (from January 1, 2027) require notice and target discriminatory outcomes without an audit mandate, and the EU AI Act treats CV screening as high-risk from December 2, 2027. The UK relies on equality law and new automated decision rules instead.
- New York City requires an independent bias audit within 1 year before use, a public summary with impact ratios, and notice to candidates 10 business days ahead.
- An impact ratio divides a group's selection rate by the top group's rate; US federal guidelines treat ratios under 0.8 as general evidence of adverse impact.
- Illinois' HB 3773 and Colorado's SB 26-189 require notice to candidates but no audit.
- EU duties for CV screening apply from December 2, 2027, after the Digital Omnibus postponed them.
- One published audit excluded almost 75 million records with unknown gender, and New York City's required calculations do not cover age.
AI hiring bias audit requirements depend on where the job is. The same resume screener or matching engine needs a published independent audit in New York City, a notice to applicants in Illinois, and a set of provider and employer duties in the EU that apply from December 2, 2027.
This guide covers New York City, Illinois, Colorado, California, the EU, the UK and several other markets as of September 24, 2026, and ends with an audit checklist. It is general information, not legal advice. We are independent, and no vendor paid to be named here.
What AI hiring bias audit requirements measure: selection rates and impact ratios
A bias audit compares outcomes between groups. Under New York City's rules, the selection rate is the share of a group that moves forward, and the impact ratio is that rate divided by the rate of the most selected group; for scoring tools, the scoring rate is the share of a group scoring above the median. The city's example: if 40 of 100 Hispanic women who apply are selected for an interview, their selection rate is 40 percent.
The city says its calculations are consistent with the US federal Uniform Guidelines on Employee Selection Procedures of August 25, 1978, which at 29 CFR 1607.4(D) treat a selection rate below four fifths, or 80 percent, of the top group's rate as general evidence of adverse impact. Local Law 144 requires the calculation but sets no threshold and demands no specific action on the results.
Research shows why regulators want the numbers. In a University of Washington study presented in October 2024, 3 AI models ranked more than 550 real resumes with only the names changed: white-associated names were preferred 85 percent of the time and Black-associated names 9 percent.
- Collect self-reported demographicsNew York City bars imputed or inferred sex or race.
- Compute each selection rateSelected divided by applicants: 40 of 100 is 40 percent.
- Divide by the top group's rateThe most selected group is the reference at 1.0.
- Compare with 0.8Federal guidelines treat lower ratios as general evidence of adverse impact.
NYC Local Law 144: an independent audit every year, published
Local Law 144 of 2021, New York City Administrative Code sections 20-870 to 20-874, took effect on January 1, 2023, and has been enforced since July 5, 2023. It covers software based on machine learning, statistics or AI that issues a score, classification or recommendation used to substantially assist or replace discretionary hiring or promotion decisions for jobs tied to a city office.
Before use, the employer needs a bias audit by an independent auditor from the past year and a public summary with the audit date, the data source, the number of people in unknown categories, and the rates and impact ratios for sex, race or ethnicity and their intersections. Candidates who live in the city must be told at least 10 business days before use, including how to request an alternative selection process or accommodation.
A vendor may commission the audit, but the employer stays responsible for making sure one exists, and the auditor may not work for or hold a financial interest in either. Tools used only to search resume databases or invite applications are outside the law. Penalties under section 20-872 run up to $500 for a first violation and $500 to $1,500 for each later one, with each day of use counted separately.
Enforcement has been light. A December 2025 audit by the New York State Comptroller, covering July 2023 to June 2025, found that the city's consumer protection department had reviewed 32 published bias audits and found 1 issue of noncompliance, while the Comptroller's auditors found at least 17 potential issues in the same set. In tests, 75 percent of calls to the 311 hotline about these tools never reached the department.
Potential noncompliance issues in the same 32 published bias audits. New York State Comptroller audit, December 2025, as summarized by DLA Piper.
Illinois, Colorado and California: notice and anti-discrimination rules, no audit mandate
Illinois amended its Human Rights Act through HB 3773, Public Act 103-0804, in effect since January 1, 2026 (775 ILCS 5/2-102). Employers may not use AI that has a discriminatory effect on a protected class or use zip codes as a proxy, and must give notice when AI is used in recruitment, hiring, promotion, discipline and other employment decisions. The law does not explicitly require an audit.
The Illinois Department of Human Rights published proposed notice rules on May 15, 2026, and withdrew them on June 2, 2026; the statute applies regardless. A separate Illinois law on recorded video interviews is covered in our guide to AI video interview software.
Colorado shows how fast these rules move. After a federal magistrate judge blocked enforcement of the 2024 Colorado AI Act on April 27, 2026, in a lawsuit by xAI in which the US Department of Justice intervened, the state replaced it with Senate Bill 26-189, signed on May 14, 2026, and effective January 1, 2027. The new law drops impact assessments. Employers whose automated tools materially influence hiring must give notice at the point of interaction, explain adverse outcomes within 30 days, offer data correction and, where commercially reasonable, meaningful human review, and keep records for 3 years.
California has no audit mandate either. Its Civil Rights Council regulations under the Fair Employment and Housing Act, in effect since October 1, 2025, state that an automated-decision system can violate anti-discrimination law and require employers to keep automated-decision data for at least 4 years.
What each rule asks of AI hiring tools, September 2026.
EU AI Act: CV screening is high-risk, with duties from December 2, 2027
The EU AI Act, Regulation (EU) 2024/1689, lists AI for recruitment or selection as high-risk in Annex III, point 4(a), including analyzing and filtering applications and evaluating candidates. The Digital Omnibus, Regulation (EU) 2026/1744, in force since July 27, 2026, moved these duties from August 2, 2026, to December 2, 2027.
Most bias work falls on the provider. Article 10 requires the data behind the system to be examined for possible biases, with measures to detect, prevent and mitigate them, and a new Article 4a from the Omnibus lets providers and deployers process special category data where strictly necessary to detect and correct bias, with safeguards such as pseudonymization. For employment systems, providers assess conformity themselves under Article 43(2), without a notified body.
Employers, as deployers, must follow the instructions for use, assign human oversight to trained staff, keep input data they control relevant and sufficiently representative, monitor the system, keep logs for at least 6 months, and inform workers' representatives before use at the workplace (Article 26). The focus is on testing and oversight rather than a published audit summary like New York City's.
Data protection law already applies. In SCHUFA (C-634/21, December 7, 2023), the Court of Justice held that a score calculated by one company is an automated individual decision under Article 22 GDPR, prohibited in principle, where the company using it gives it a determining role. A candidate score that recruiters follow without real review may raise the same question.
The UK: equality law and automated decision rules instead of an audit mandate
The UK has no audit requirement on the New York City model; existing law does the work. Under section 19 of the Equality Act 2010, a provision, criterion or practice that puts people sharing a protected characteristic at a particular disadvantage is indirect discrimination unless the employer can show it is a proportionate means of achieving a legitimate aim.
Section 80 of the Data (Use and Access) Act 2025, fully in force since February 5, 2026, replaced Article 22 of the UK GDPR with Articles 22A to 22D. Solely automated significant decisions are allowed with safeguards, including information, the chance to make representations, human intervention and a way to contest the decision, and are restricted where they rest on special category data.
The regulator expects testing anyway. After auditing AI recruitment tool providers, the ICO made almost 300 recommendations in November 2024, having found tools that let recruiters filter out candidates with protected characteristics and providers inferring gender and ethnicity from names. In March 2026 it told employers using automated decisions in hiring to test regularly for biased outputs.
Other markets: disclosure and explanation rights
The rules we checked elsewhere require disclosure or explanation rather than audits. Since January 1, 2026, Ontario Regulation 476/24 under the Employment Standards Act, 2000, has required employers with 25 or more employees to state in public job postings whether AI screens, assesses or selects applicants. China's Personal Information Protection Law, Article 24, in force since November 1, 2021, gives people a right to an explanation of automated decisions that significantly affect them and to refuse decisions made solely by automated means.
Article 2 of South Korea's Framework Act on the Development of Artificial Intelligence, in force since January 22, 2026, defines evaluations with a significant impact on a person's rights, such as employment decisions, as high-impact AI. Vendor disclosure varies too: Gupy, a Brazilian applicant tracking system, says its AI orders applications by fit and that selection stays the employer's responsibility, but its AI transparency page reports no bias test results.
A practical checklist before you rely on a bias audit
A published audit is a starting point, not a verdict. New York City's required calculations cover sex and race or ethnicity, not age or disability, yet the group certified in Mobley v. Workday, a US case over AI screening, is defined by age. On May 16, 2025, a federal judge in California preliminarily certified a nationwide collective of applicants aged 40 and over who applied through Workday's platform since September 24, 2020, and were denied employment recommendations; Workday can still seek decertification.
Eightfold AI publishes audits by BABL AI that show the method and its limits. Its March 2026 audit of the matching model covered more than 29 million assessments with self-declared demographics, and all groups stayed above 0.8, the lowest at 0.880. It also excluded 74,997,062 records with unknown gender and 85,587,944 with unknown race or ethnicity.
Test data has limits too. Eightfold's June 2026 audit of its AI Interviewer tested race and ethnicity on synthetic interviews, with a large language model playing 12 candidate personas, because real data was insufficient. New York City allows test data in that case, but not inferred demographics.
Certificates are not audits either. In our directory, 3 of the 25 CV screening tools list ISO/IEC 42001, which Bizneo describes as validating its AI management system. That shows how a vendor runs its AI program, not the impact ratios of your model.
Before you rely on a vendor's bias audit, check these points.
- Get the latest audit summaryAuditor, dates, data period and data source.
- Confirm independenceNo employment by, or financial stake in, you or the vendor.
- Check whose data was usedYour own, pooled from other customers, or synthetic.
- Read the unknown categoryHow many candidates were left out for missing demographics.
- Compare impact ratios with 0.8Including intersections of sex and race or ethnicity.
- Test what the audit leaves outAge, disability, language and accent where relevant.
- Re-test after configuration changesWeights, knockout questions and thresholds change outcomes.
- Keep the records4 years in California, 3 in Colorado, EU logs for at least 6 months.
- Plan notices and human reviewNYC notice 10 business days ahead, Colorado explanations within 30 days.
Tools in this article
Frequently asked questions
Which laws require a bias audit for AI hiring tools?
Among the rules covered here, New York City's Local Law 144 is the one that requires an independent bias audit within 1 year before use, with a published summary. Illinois and Colorado require notice without an audit mandate, and the EU AI Act puts bias testing duties on providers from December 2, 2027.
What is a good impact ratio in a bias audit?
New York City sets no pass mark. US federal guidelines treat a selection rate below 80 percent of the top group's rate as general evidence of adverse impact, and audits such as Eightfold's compare results with 0.8. Smaller gaps can still matter if they are significant in statistical and practical terms.
Does the EU AI Act require a bias audit for CV screening?
Not a published audit summary. It classifies CV screening as high-risk, requires providers to examine and mitigate bias in their data, and requires employers to monitor the system and keep human oversight, from December 2, 2027.
Is Colorado's AI Act in effect?
No. The 2024 law was replaced by Senate Bill 26-189, signed on May 14, 2026, which takes effect on January 1, 2027. It requires notice, explanations of adverse outcomes and human review instead of impact assessments.
Sources
- NYC Department of Consumer and Worker Protection, Final Rules on Automated Employment Decision Tools
- NYC DCWP, Automated Employment Decision Tools: Frequently Asked Questions
- Cornell Law School LII, 29 CFR 1607.4, Uniform Guidelines on Employee Selection Procedures
- University of Washington, AI Tools Show Biases in Ranking Job Applicants' Names (October 31, 2024)
- New York City Council, Local Law 144 of 2021
- NYC Department of Consumer and Worker Protection, Automated Employment Decision Tools
- DLA Piper, Critical Audit of NYC AI Hiring Law Signals Increased Risk for Employers (January 30, 2026)
- Duane Morris, Illinois Enacts Artificial Intelligence Law Focused on Employment Practices
- Ogletree, Illinois Postpones Proposed Regulations on AI in Employment (June 4, 2026)
- McDermott Will & Schulte, Colorado AI Law in Flux (May 27, 2026)
- Colorado General Assembly, SB26-189 Automated Decision-Making Technology
- Ogletree, Colorado's New AI Act Targets Automated Decision-Making for Consequential Decisions
- California Civil Rights Department, Civil Rights Council Secures Approval for AI Employment Regulations (June 30, 2025)
- Hicks Morley, Ontario Job Posting Requirements Take Effect January 1, 2026
- EU AI Act, Annex III: High-Risk AI Systems
- European Commission, AI Omnibus Enters into Force
- Gibson Dunn, EU AI Act Omnibus Agreement, Postponed High-Risk Deadlines
- EU AI Act, Article 10: Data and Data Governance
- AI Act Explorer, Digital Omnibus on AI, Regulation (EU) 2026/1744
- EU AI Act, Article 43: Conformity Assessment
- EU AI Act, Article 26: Obligations of Deployers
- Court of Justice of the EU, Press Release 186/23, SCHUFA Holding (Scoring), C-634/21
- EU AI Act, Article 5: Prohibited AI Practices
- European Commission, Guidelines on Prohibited AI Practices, C(2025) 5052
- legislation.gov.uk, Equality Act 2010, Section 19
- legislation.gov.uk, Data (Use and Access) Act 2025, Section 80
- ICO, Intervention into AI Recruitment Tools Leads to Better Data Protection for Job Seekers (November 6, 2024)
- ICO, Automated Decision-Making in Recruitment Needs the Right Safeguards (March 31, 2026)
- Cyberspace Administration of China, Personal Information Protection Law (Chinese)
- CSET, Translation of South Korea's Framework Act on the Development of Artificial Intelligence
- Gupy, Inteligencia Artificial: Privacidade e Seguranca (Portuguese)
- US District Court, N.D. Cal., Mobley v. Workday, Order Granting Preliminary Collective Certification (May 16, 2025)
- Eightfold AI, AI Bias Audit Results (BABL AI, March 2026)
- Eightfold AI, AI Interviewer Bias Audit Results (BABL AI, June 2026)
- Bizneo, Certified Security
- ai-toolfinder.com dataset, September 2026
