← AI hiring compliance

AI Hiring Laws by State: The 2026 Employer Tracker

9 min read · Last reviewed 1 Aug 2026

General information, not legal advice. Laws in this area change; verify against the official sources at the end of this guide and confirm specifics with employment counsel.

There is no federal AI hiring statute, so the rules arrive as a patchwork: a city ordinance here, a human-rights-act amendment there, one comprehensive state AI act, and a layer of agency guidance stretching old discrimination law over new tools. For an employer, the practical question is not "what is the law" but "which laws attach to where I hire," because duties follow the candidate and the job, not your headquarters.

This tracker covers what is enacted and in force as of its last review date, what exists as guidance, and what is pending. Laws in this space move quickly (Colorado repealed and replaced its AI act before it ever took effect), so treat this as a map, verify anything you rely on against the linked primary sources, and confirm decisions with counsel. General information, not legal advice.

How to read this tracker

Three tiers matter differently. Enacted and in force means a statute or final regulation with current effect: these define concrete duties (audits, notices, records) you can be cited for missing. Agency guidance means a regulator's stated interpretation of existing law: not new law, but a reliable preview of enforcement theory, and existing anti-discrimination statutes already cover algorithmic tools everywhere. Pending means bills and draft rules: worth watching if you hire in those states, not worth building processes around yet.

Jurisdiction attaches through the job and the candidate. A Denver company hiring for an NYC-based role owes NYC duties for it; a fully remote company screening a Chicago applicant touches Illinois law. If you hire nationally, you are effectively regulated by the strictest jurisdictions in your applicant pool, which is the argument for a single baseline process rather than per-state logic.

Everything below reflects the guide's last-review date shown on this page.

Enacted: the big four

New York City (Local Law 144, enforced since July 2023): the strictest regime. Annual independent bias audit of any automated employment decision tool used for NYC jobs, published summary of the results, and candidate notice 10 business days before use. No small-business exemption. Full guide: /compliance/nyc-local-law-144.

Illinois (HB 3773, effective January 1, 2026): amends the Human Rights Act (1+ employees). Prohibits AI with a discriminatory effect, bans ZIP-code proxies, requires notice when AI is used across the employment lifecycle. Illinois also has the older AI Video Interview Act (2020): consent and explanation before AI analyzes interview videos. Full guide: /compliance/illinois-hb-3773.

California (FEHA ADS regulations, effective October 1, 2025): discrimination through automated-decision systems explicitly unlawful for employers with 5+ employees, liability extends through agents and vendors, four-year recordkeeping, and anti-bias testing counts as evidence. Separate CCPA ADMT rules phase in for large businesses through 2027. Full guide: /compliance/california-ai-hiring-rules.

Colorado (ADMT law, SB 26-189, signed May 14, 2026, effective January 1, 2027): the 2024 AI Act was repealed and reenacted before it ever took effect. The narrower replacement covers automated decision-making technology in consequential decisions like hiring: point-of-interaction notice, a plain-language explanation after an adverse decision, data correction, meaningful human review, and 3-year records, for deployers of every size. Full guide: /compliance/colorado-ai-act-hiring.

Enacted, narrower: Texas, Maryland, Utah, Connecticut

Texas (TRAIGA, the Texas Responsible Artificial Intelligence Governance Act, effective January 1, 2026): comprehensive in name, but for private employers its hiring-relevant core is a prohibition on developing or deploying AI with the intent to unlawfully discriminate, and the statute states that disparate impact alone does not establish that intent. Most of its obligations fall on government agencies. Practical read for private employers: a lighter-touch regime than Colorado's, but intentional misuse of AI in hiring is squarely covered, and Texas candidates remain protected by federal law.

Maryland (HB 1202, effective 2020): narrow and specific: employers may not use facial recognition services to create a facial template during a job interview without the applicant's signed consent waiver. Relevant only if your interview tooling analyzes video.

Utah (AI Policy Act, 2024): a disclosure statute for generative AI in consumer interactions, with proactive disclosure duties concentrated on regulated occupations. It touches hiring only at the edges (a screening chatbot interacting with applicants is the plausible contact point), but it signals the disclosure-first direction smaller states are taking.

Connecticut (CART Act, Public Act 26-15, signed June 2, 2026): the newest entrant. From October 1, 2027, businesses using an automated employment-related decision process as a substantial factor must give applicants and employees a plain-language written disclosure, with additional duties when the decision is adverse, and the act prohibits using such processes to discriminate (using AI is not a defense to a discrimination claim). Most other provisions take effect October 1, 2026.

The guidance layer: old law, new tools

Even where no AI statute exists, regulators have said existing law covers algorithmic hiring. New Jersey went furthest: after January 2025 guidance, the Division on Civil Rights adopted binding disparate-impact rules (N.J.A.C. 13:16, effective December 15, 2025) codifying disparate-impact liability under the Law Against Discrimination, with automated decision-making tools expressly among the practices that can produce it. That moved New Jersey from interpretive guidance to enacted administrative rules, and employers cannot outsource the responsibility to vendors.

Federally, the picture inverted in 2025: the EEOC's AI-specific technical assistance was withdrawn from circulation and an executive order directed agencies to deprioritize disparate-impact enforcement. What that changes is federal enforcement appetite, not the law: Title VII's disparate-impact provisions remain enacted, private plaintiffs still sue (the Mobley v. Workday collective action over algorithmic age discrimination is the leading example), and state agencies enforce their own statutes on their own theories.

The operational conclusion: guidance-tier jurisdictions are not "safe" jurisdictions. They are jurisdictions where the complaint arrives under a familiar statute instead of a new one.

Pending and worth watching

The pipeline is wide, and this section ages fastest; check current status before relying on any of it. New York State has repeatedly advanced bills to extend LL144-style audit and notice duties statewide (the "Bossware" and AI-employment bills), and a statewide regime would multiply the number of covered employers overnight. Massachusetts, Washington, Vermont, Connecticut, and New Mexico have each seen comprehensive or hiring-specific AI bills progress through committees, several modeled on Colorado's deployer framework. California continues to layer: the CCPA ADMT compliance dates run into 2027, further Civil Rights Council rulemaking is possible, and a broad workplace-ADS bill (SB 7) passed the legislature in 2025 only to be vetoed that October (veto sustained March 2026), so expect successor bills.

Tracking all of this yourself is unnecessary. Two habits substitute: revisit this hub (each guide carries its last-reviewed date and primary-source links), and re-run the 2-minute compliance check when your hiring footprint changes, since new jurisdictions in your applicant pool matter more than new bills in the news.

If a bill passing tomorrow would change your process materially, that is the real signal your current process is thin: the baseline in the next section absorbs new laws with little more than a notice-text update.

The multi-state playbook: one baseline instead of fifty

Employers who hire across states keep asking the same question: how do we track all of this? Mostly, you should not. The enacted regimes overlap enough that a single baseline satisfies nearly everything at once: (1) an AI-use notice in every posting stating what the tool assesses; (2) job-related, human-set criteria with no location or proxy signals; (3) a human making every final decision, with no auto-rejection anywhere in the funnel; (4) exported records of criteria, scores, evidence, and outcomes, retained four years; (5) a periodic four-fifths self-check on the funnel; and (6) if NYC-based roles are in the map, the vendor's current independent audit summary published on your careers page.

That baseline is NYC's notice discipline, California's records-and-testing posture, Illinois' non-discrimination hygiene, and Colorado's explainability duty rolled together, and every pending bill in the pipeline is a variation on the same themes. It is also, not coincidentally, just a description of transparent screening: criteria you set, evidence you can read, decisions you make, records you keep. SiftFirst implements that shape by default, with the notice generator and bias self-check free at the edges. Where a specific law's details bind you, the individual guides above go deeper, and counsel gets the final word.

Key takeaways

  • Three regimes are in force today: NYC LL144 (audit + notice), Illinois HB 3773 (effect liability + notice), and California's FEHA ADS rules (records + testing as evidence); Colorado's replacement ADMT law (SB 26-189) is enacted and takes effect January 1, 2027.
  • Texas, Maryland, Utah, and Connecticut (CART Act, disclosures from October 2027) have narrower enacted statutes; New Jersey adopted binding disparate-impact rules covering automated tools; federal enforcement softened in 2025 but Title VII private claims continue.
  • Duties attach to the job's and candidate's location, not your headquarters, so national hiring means complying with the strictest jurisdictions in your applicant pool.
  • A single baseline (notice, job-related criteria, human decisions, four-year records, periodic self-checks, published audit where NYC applies) satisfies the overlapping core of every enacted regime.
  • The pending pipeline (New York State, Massachusetts, Washington, and others) recycles the same themes, so the baseline absorbs new laws with minor updates; verify current status via primary sources.

Screening built for these rules

SiftFirst scores candidates against criteria you set, quotes the resume line behind every score, never auto-rejects, and exports the records these laws expect. The candidate notice generator and bias audit self-check are free.

FAQ

We hire fully remote. Which state's rules apply to a given candidate?

As a working rule: the state where the candidate resides and the place the job is tied to both matter, and either can pull you into a regime (NYC's notice duties attach to NYC-resident candidates; Illinois protects Illinois applicants). Determining this per candidate is impractical at screening time, which is why the baseline approach (comply with the strictest common denominator for everyone) is the standard answer for remote-first employers.

Do I actually need to track legislation in all fifty states?

No. Track the four in-force regimes if you hire in them, keep the baseline process everywhere, and revisit a maintained tracker a few times a year. New laws in this space have consistently been variations on notice, non-discrimination, records, and audits, so a process built on those four pillars has absorbed every enactment so far without structural change.

How current is this page?

Each guide in this hub carries a last-reviewed date (shown at the top of the page) and links to primary sources, and the content is re-verified against those sources on a scheduled review. Between reviews, treat fast-moving items (Colorado amendments, pending New York State bills, CCPA ADMT dates) as candidates for change and check the linked sources before relying on details.

Related

Official sources

More guides