A hiring algorithm used to answer to exactly one authority: the buyer. In under five years, that arrangement ended on three continents. The tool acquired legal names (an "automated employment decision tool" in New York City, a high-risk "AI system" in the European Union), and the data it runs on became regulated personal data in India. Read together, the new AI hiring regulations converge on one familiar set of demands: know what your tool does, document it, measure its effects by group, keep a person meaningfully in the loop, and tell the candidate. To anyone trained in personnel selection, that list is industrial-psychology hygiene written into law, and the quiet consequence follows directly: compliance cost has become a function of measurement maturity, and the burden lands lightest on the organizations that were already running validated, documented, monitored assessment.
This article is the map, not the counsel. It covers what each regime reaches, what it asks, and what a buyer should now demand from any assessment vendor; whether and how any instrument applies to a specific organization (which tools, which candidates, which dates) is a determination for lawyers, and one worth commissioning early rather than after a candidate asks why nobody mentioned an algorithm was involved. Everything here is stated as of this writing, because the one safe generalization about this body of law is that it moves.
The gap the map exposes sits in procurement. Organizations are still buying "AI-powered" screening the way they buy productivity software: a demo, a reference call, a price per seat, and no documentation trail behind the ranking the tool produces. Three jurisdictions have already made that trail the price of admission, and the ones that follow are unlikely to ask for less.
New York City audits the tool and tells the candidate
New York City's Local Law 144 of 2021, codified at Administrative Code § 20-870 et seq., is narrow and concrete, which makes it the right place to start. It applies to automated employment decision tools used for candidates or employees in New York City, and it attaches three duties to their use: an annual bias audit conducted by an independent party, a public summary of the audit's results, and advance notice to the candidates the tool will evaluate. Enforcement began on July 5, 2023.
What the audit computes is worth being precise about, because it is not new mathematics. The auditor calculates selection or scoring rates by sex and by race/ethnicity categories, and then the impact ratios that set one group's rate against another's. This is the longstanding adverse-impact arithmetic of American selection practice under Title VII — the four-fifths logic examined in the companion article on adverse impact and the four-fifths rule is the direct ancestor of the bias audit. What Local Law 144 changed is not the computation but its circulation: the number is produced by an independent party, refreshed annually, and published where a candidate can read it.
The model, note, is disclosure rather than prohibition. The city did not ban ranking software; it made the tool auditable and the candidate informed, and it moved group-level measurement from an internal analysis an employer might run to a public artifact an employer must commission. For buyers, that redefines the product. A tool that cannot surface selection rates by group leaves its user holding an audit obligation with no data to audit.
Notice does its own quiet work. A candidate told in advance that an automated tool will evaluate them can ask what it measures, and an employer obliged to say so needs an answer that survives daylight. The publication requirement has the same character: a posted impact ratio is a fact any applicant or researcher can look up, and organizations behave differently when their measurement is visible. Disclosure regimes discipline practice not by forbidding anything but by making the practitioner describe what they do in public.
New York is also only one point on a strip that now runs across three continents. Figure 1 places the dates: an Illinois statute on AI video interviews in 2020, the New York enforcement date in 2023, India's data-protection statute the same year, the EU AI Act's entry into force in 2024, India's implementing rules in 2025, and a 2026 in which both Colorado's AI Act and the bulk of the EU's high-risk duties arrive. The sections that follow take them in turn.
Brussels regulates the lifecycle, not just the output
Regulation (EU) 2024/1689, the EU AI Act, entered into force on August 1, 2024, and it takes the opposite approach on almost every axis. Where New York audits one output of one class of tool once a year, the Act classifies systems and then obligates their entire lifecycle. AI systems for employment, worker management, and access to self-employment sit in the high-risk class of its Annex III, which is where the Act concentrates its heaviest duties.
Those duties read like a systems-engineering syllabus: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy and robustness. The through-line is that none of them attaches to a score. They attach to the system that produces the score — how it was built, on what data, with what documentation, under whose oversight, and with what evidence that it stays accurate in use. A hiring tool could satisfy a New York bias audit on its outputs and still fall short of the Act's expectations for its paperwork, because the two instruments examine different objects.
The obligations phase in over time, with the bulk of the high-risk duties applying from August 2, 2026. That date, not the 2024 entry into force, is the one an employment-AI deployment calendar should be built around, and it is close enough that documentation debt taken on today comes due within the current contract term, not some successor's.
The Act also did not land on empty ground. Under Article 22 of Regulation (EU) 2016/679, the GDPR, decisions based solely on automated processing that carry legal or similarly significant effects trigger specific safeguards, including rights to human intervention. The Act's human-oversight duty extends a floor that European data law had already poured.
In the rest of the United States, old law leads and new statutes follow
Outside New York, the key American document is not a statute at all. In 2023, the Equal Employment Opportunity Commission issued technical assistance on selection procedures under Title VII and the use of software, algorithms, and AI in employment selection, and its message was continuity: the longstanding Title VII adverse-impact framework, including the four-fifths rule of thumb, applies to algorithmic selection tools, and employers remain responsible for tools used on their behalf. The document is guidance, not regulation; it creates no new obligation and needed to create none, because existing law reaches the new technology. An employer waiting for a federal AI-hiring statute before taking group-level measurement seriously has misread the situation. The measurement obligation is older than the software.
The responsibility clause deserves a moment of its own. If employers remain responsible for tools used on their behalf, then an organization cannot outsource the adverse-impact question by buying a tool; the tool's group-level effects are the employer's effects, whoever built the model. That one sentence of guidance prices vendor opacity for the buyer. A vendor who declines to show you effects by group is not sparing you a technical detail; it is asking you to carry unmeasured exposure under a framework that has bound you all along.
The states supply the statutes. Illinois moved earliest: the Artificial Intelligence Video Interview Act of 2020, codified at 820 ILCS 42, requires notice, an explanation, and consent before AI analysis of a video interview for an Illinois position, plus deletion of the interview on request. It is a narrow law about one tool class, and it is the early state marker: a legislature naming an AI hiring practice and attaching conditions, notice, explanation, consent, deletion, that would recur in the instruments that followed.
Colorado extends the European architecture inland. Senate Bill 24-205 of 2024, the Colorado AI Act, adopts a high-risk framework for consequential decisions, employment among them, and distributes duties between the developers who build such systems and the deployers who use them, taking effect from 2026. The structural point matters more than the particulars: an American state examined the classification-and-obligation model and adopted its shape. Convergence is no longer a European hypothesis.
India regulates the data the tool runs on
India's entry on the strip is a different kind of law, and precision about the difference is the point of this section. The Digital Personal Data Protection Act, 2023 is the data-layer law: the standard consent, purpose-limitation, and erasure architecture, with obligations on data fiduciaries. It is not an AI-specific hiring statute, and implementing rules followed in the Digital Personal Data Protection Rules, 2025.
For assessment, the reach comes from the data rather than the tool. A candidate's responses, scores, and session records are personal data, and the assessment data of Indian candidates flows through the DPDP Act's requirements regardless of where the employer sits. An organization headquartered elsewhere that screens applicants in Bengaluru holds Indian data-governance obligations even though no Indian regulator has said a word about its algorithm. The consent, retention, and erasure architecture this implies for testing is the subject of the companion article on candidate data privacy; the practical question for a buyer is whether the platform holding candidate data can execute notice, consent, correction, and erasure as routine operations rather than as engineering projects.
AI hiring regulations converge on five demands
Lay the instruments side by side and the divergence is procedural: New York audits, Brussels classifies and obligates, the EEOC interprets law that already existed, Illinois and Colorado legislate tool by tool, and India regulates the data layer. The convergence is thematic, and it is strong. Five demands recur: document what the tool is and does; measure its effects at the level of groups; keep humans able to oversee and intervene; tell candidates what is evaluating them; and govern the data underneath. Figure 2 marks where each of four regime families speaks to each demand in its own text.
Two things about the matrix. First, empty cells mark silence, not exemption. The EEOC's document says nothing about candidate notice because the framework it interprets concerns outcomes rather than procedure; the DPDP Act says nothing about group-level measurement because it is a data statute; yet a candidate in Illinois is owed notice by state law and a New York employer still answers to Title VII. The regimes overlap, and the gaps in one column are frequently filled by another. Second, the sparsest column still binds. A regime that speaks to a single demand can shape practice as much as one that names all five, because a published impact ratio is a very public kind of silence-breaker.
The consequence for a global employer is that meeting AI hiring regulations regime by regime is the expensive strategy. A tool documented, measured, overseen, noticed, and governed to the union of the five demands travels; a tool patched to each jurisdiction's minimum gets renegotiated at every border.
The repricing: compliance cost tracks measurement maturity
Each of the five demands corresponds to something selection science prescribed long before any legislature took an interest. Documentation is what the profession calls validity evidence: a serious instrument arrives with an account of what it measures, how it was built, and the evidence that its scores predict what they claim to predict. Group-level measurement is adverse-impact monitoring, the same practice the EEOC now points at algorithms. Human oversight is the review process a defensible testing program already operates for its flags and exceptions. Candidate notice is what the research tradition calls procedural justice, the candidate's sense that the process was transparent and fair, which assessment practice has long treated as an outcome worth designing for. Data governance is the consent, retention, and erasure discipline that any operation holding sensitive candidate records needed anyway.
This mapping is why the new law reprices rather than taxes evenly. What the statutes wrote into law is, in large part, the profession's own hygiene, and law of that kind behaves less like a new burden than like an audit of what you were already doing. Figure 3 draws the two experiences of the same five demands. For an organization whose funnel runs on undocumented tooling, every demand arrives as new work: evidence assembled after the fact, monitoring data nobody kept, a review step improvised under a deadline, notice text drafted in a hurry, data flows mapped retroactively. For an organization running validated, documented, monitored assessment, each demand maps to an artifact on file. The demands are identical. The marginal work is not, and procurement decisions made this year determine which lane an organization occupies when the 2026 dates arrive.
The same asymmetry runs through the vendor market. A vendor that maintains validity evidence, monitoring exports, and technical documentation as ordinary operations can hand each regulated buyer the same file; one that never built those exhibits must now construct them under deadline, for every regulated customer at once, retrofitted onto a product that was not designed to explain itself. Instruments built on published measurement science start that race from a different position than models whose development history is a trade secret, and the difference will surface in procurement long before it surfaces anywhere official.
Five demands to hand any assessment vendor
The buyer's translation of all this fits on one page, and Figure 4 states it as five requests. First, technical documentation on request: what the instrument measures, how it was developed, and the reasoning behind its scoring, in a form you could hand to an auditor or a regulator without a meeting to explain it. Second, data exports sufficient for an independent bias audit: if the vendor cannot produce selection and scoring rates by group, New York's regime is unmeetable and every future audit regime starts from a hole. Third, per-group monitoring as an ongoing export rather than a one-time report, because adverse impact is a property of use, not of purchase.
Fourth, candidate notice text: the plain-language account of what the tool evaluates, ready before the first candidate meets it, since Illinois wants it as consent, New York as advance notice, and India as part of the data relationship. Fifth, named human decision points, the places where a person reviews, can intervene, and answers a challenge, in the sense the review model in the companion article on integrity flags and false positives develops for one high-stakes case.
A vendor's response to the five is itself diagnostic. One that runs a documented program produces the material in days, and the conversation moves to substance; a vendor without such a program needs weeks to construct what should be an attachment. Under the old arrangement that difference was invisible at purchase and expensive later. The new instruments make it visible at purchase, which may be the most useful thing any of them does.
Four moves before the next date on the strip
For an organization that hires across borders, the work follows from the map, and most of it is worth doing under any reading of the instruments.
- Inventory the funnel against the definitions. Walk every stage, sourcing, screening, ranking, assessment, interview scoring, and record which tools plausibly meet a definition like New York's automated employment decision tool or the AI Act's high-risk employment system. Definitional edges are where the legal questions live; the inventory is what turns them into answerable ones.
- Assign ownership before the first request arrives. Documentation requests, audit commissions, candidate notices, and erasure requests all need named owners on both sides of the vendor relationship, the discipline the assessment governance article builds its ownership grid around.
- Collect the file before anyone asks for it. Technical documentation, monitoring exports, review records, notice text: the artifacts of Figure 3, gathered while the request is hypothetical. Assembled in advance, the file is routine; assembled after a regulator's letter, it is a crisis.
- Put the dates on a calendar someone owns. The strip in Figure 1 has a visible 2026 cluster and empty space to its right, and this article will age. Name the person who watches the space fill, and give the AI hiring regulations the same standing review the governance article gives security.
The deeper reading of Figure 1 is the one to end on. Regulators on three continents examined algorithmic hiring independently, with different instruments and different theories of harm, and asked for substantially the same five things the selection literature had been recommending all along. When that happens, the demands stop being compliance trivia and start looking like a specification for the product itself. The organizations that treat them that way will experience the next chip on the strip as a date to note. The rest will experience it as a deadline.
Where 5Profiler stands
Regulation has turned the paperwork into part of the product. 5Profiler is built for the buyer who now has to produce it: technical documentation available on request, per-group monitoring exports that give an independent bias auditor the data an audit needs, and candidate notice text ready before the first invitation goes out. One boundary is worth stating plainly: a platform supports your compliance; it cannot confer it, because every regime in this article puts the duty on the organization making the hiring decision. What a vendor owes you is the file — the five rows of Figure 3, produced in the ordinary course of running validated assessment rather than assembled in the week the auditor calls.
References
- Colorado General Assembly. (2024). Senate Bill 24-205, Concerning consumer protections in interactions with artificial intelligence systems (Colorado AI Act).
- European Parliament, & Council of the European Union. (2016). Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). Official Journal of the European Union, L 119.
- European Parliament, & Council of the European Union. (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act).
- Government of India. (2023). The Digital Personal Data Protection Act, 2023. The Gazette of India.
- Government of India. (2025). The Digital Personal Data Protection Rules, 2025. Ministry of Electronics and Information Technology.
- Illinois General Assembly. (2020). Artificial Intelligence Video Interview Act, 820 ILCS 42.
- New York City Council. (2021). Local Law 144 of 2021, N.Y.C. Administrative Code § 20-870 et seq.
- U.S. Equal Employment Opportunity Commission. (2023). Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII of the Civil Rights Act of 1964 (technical assistance document).