AI recruiting compliance means following federal anti-discrimination laws and a growing set of state laws whenever AI scores, ranks, or screens candidates. There is no single federal AI hiring statute, but existing law still applies in full.
Federal Anti-Discrimination Rules
- EEOC Guidelines: Title VII, the ADA, and the ADEA still govern AI-assisted hiring decisions, a principle currently being tested in the Mobley v. Workday lawsuit.
- Enforcement Shift: EEOC removed its AI-specific guidance in 2025, but underlying anti-discrimination law remains fully enforceable.
State AI Hiring Laws
- NYC Local Law 144: Requires an independent bias audit and public disclosure before deploying an automated hiring tool.
- Illinois and California: Add discriminatory-effect, notice, and vendor liability rules that vary by state.
Skima AI is a recruitment tool that supports compliance with human-reviewed scoring, documented ranking reasons, and bias testing across protected groups. It's designed to help recruiters meet these evolving state and federal standards.
Workday is currently defending a nationwide collective action that could cover job applicants at hundreds of companies who never touched the software directly. Age discrimination claims survived dismissal in March 2026. Claims related to disability and California also survived in June.
If you're using AI to screen resumes right now, you might be exposed through a vendor you didn't consider. New York's comptroller reported that city regulators found only one violation among 32 companies. In contrast, independent auditors identified 17 violations in the same group. This gap highlights a significant oversight risk.
The gap exists because AI recruiting laws are not centralized. They're scattered across state laws, agency rules still in progress, and existing federal laws. To understand what laws apply to AI in recruitment, you need to know where each one comes from. Here’s the current map, state by state.
Federal and State Recruiting Compliance Laws USA
No two states regulate this the same way. New York's AI recruiting law targets the audit and disclosure side, California's leans on existing anti-discrimination statutes, and Texas barely regulates at all. Treat the table below as your starting reference for AI recruitment laws, not a substitute for checking the current statutory text in every state where you recruit.
What EEOC Guidance Currently Covers?
There's a common myth among recruiters that the EEOC removed its AI hiring guidance because AI hiring is now less risky. That's not true. In January 2025, the agency took down its AI and algorithmic fairness guidance from eeoc.gov after the new administration cancelled Biden-era AI policy. As of March 2026, those pages still show "page not found." No new guidance has replaced them.
What hasn't changed? Title VII, the ADA, and the ADEA still apply to AI-assisted hiring just as they did before. The guidance explained how those laws related to algorithms; removing it didn't change the law. What has changed is the enforcement focus. The current EEOC chair has announced a 2026 agenda prioritizing anti-DEI enforcement and reverse discrimination claims, not algorithmic bias.
An April 2025 executive order also directed federal agencies to reduce disparate impact liability "to the maximum degree possible." This directive marks a real shift in how the federal government will handle AI bias claims, but the order doesn't affect the chances of a private lawsuit under current law. Mobley v. Workday shows that success is still possible.
What Counts as an Automated Employment Decision Tool?
Most compliance confusion starts here. The definition changes based on the law you're reading. NYC's Local Law 144 defines an AEDT narrowly. It must substantially assist or replace human decision-making.
Simple tools that merely organize resumes for recruiters usually don't count. California's regulations are broader. They cover any "computational process" that helps with a decision, from resume keyword scanners to game-based assessments to software analyzing facial expressions on video.
Additionally, Illinois's HB 3773 doesn't define any tool category. It only prohibits AI that causes discrimination against protected classes, no matter what the tool is called.
If a scoring layer affects who a recruiter shortlists, it touches a covered decision under Illinois and California's rules, even if it never gives a final yes or no. The safest approach is to always check the specific state definition before assuming otherwise.
4 Obligations for Employers Using AI in Recruitment
Independent Bias Audits
NYC requires an annual audit from an auditor with no stake in your tool's outcome, measuring selection rates across race, ethnicity, and sex categories. California doesn’t require an audit directly. However, its rules suggest that not having one can weaken your case in a discrimination claim. So, avoiding an audit can weaken your legal stance, even if it’s not mandatory.
Core Obligations
- Get an outside auditor, not internal staff
- Test selection rates by protected category
- Publish results before using the tool
- Repeat the audit every twelve months
- Cover every AEDT, not just new ones
- Keep records for at least four years
- Re-audit after major model changes
Candidate Notice and Consent
Illinois, NYC, and the video interview law all require some form of advance notice, but the timing and content differ. NYC wants 10 business days' notice before the tool is used. Illinois's implementing rules, still in draft as of mid-2026, will spell out exact timing once finalized. The video interview law goes further and requires actual consent, not just notice, before AI analyzes footage.
Core Obligations
- Notify before the tool runs, not after
- Name the AI, not just "our process"
- Explain what's being measured or scored
- Offer an alternative process on request
- Get explicit consent for video analysis
- Delete video within 30 days if asked
- Track notice delivery per candidate
Human-in-the-Loop Oversight
Several state frameworks, including draft Colorado rules and multiple state attorney general guidance documents, use language requiring "meaningful human review" with someone trained and empowered to override the AI's output. That phrase is doing real legal work now.
A recruiter who rubber-stamps every AI ranking without authority to deviate from it doesn't satisfy this requirement, even if a human technically clicked the button.
Core Obligations
- Assign a named reviewer, not a rotation
- Give that reviewer override authority
- Document overrides and the reasons why
- Train reviewers on what the tool can't see
- Review score-driven rejections, not just advances
- Set a review checkpoint before any final decision
- Log reviewer decisions for audit purposes
Vendor Due Diligence
Mobley v. Workday changed how procurement teams should think about vendor contracts. The court's June 2026 ruling allowed disability and California FEHA claims against Workday to proceed on the theory that a vendor's tool can make the vendor an "agent" of the employer, with its own liability exposure separate from the client using it.
California's FEHA regulations formalize the same idea, defining "agent" broadly enough to cover any vendor performing a function the employer would otherwise handle, including screening.
Ask a vendor to actually show you audit results, not just describe a bias-testing methodology in a sales deck. Ask how their tool handles the human-override requirement in practice.
A platform like Skima AI, built around white-box explainable scores rather than a black-box rejection, is easier to document for compliance purposes because a reviewer can see why a candidate scored the way they did instead of just trusting an opaque output. This transparency doesn't remove your obligation to review vendor contracts, but it makes the review faster.
Core Obligations
- Request the vendor's most recent audit
- Confirm audit covers your specific use case
- Get contractual indemnification language
- Verify the tool explains its own scoring
- Check for a documented override mechanism
- Ask how candidate data gets deleted
- Reassess vendors after any model update
Building One Compliance Program for a Multi-State Workforce
Chasing 8 separate state checklists burns time you don't have, especially since Colorado’s checklist was rewritten mid-year. Build to the strictest applicable standard instead, and treat everything else as a subset.
In practice, this means adopting NYC’s auditing standards and Illinois’ notification rules across all operations. You should also apply California’s four-year record retention window regardless of where a candidate applied.
A single unified process costs less to maintain than 8 separate ones. It also protects you when a low-risk state becomes a liability. Texas employers who assumed TRAIGA's light touch meant no exposure soon discovered that federal ADEA and Title VII claims ignore state law.
Centralize your AEDT inventory in one place, owned jointly by legal, HR, and whoever manages your ATS or scoring tools. New York's own audit of its enforcement agency found that DCWP surveyed 32 companies and flagged only one as non-compliant, while the same 32 companies, reviewed by state auditors using a stricter process, produced 17 flags.
This discrepancy didn't happen because the companies changed. It happened because an inconsistent review missed what a tighter process caught. Your internal review needs to be the tighter process, not the looser one.
Penalties and Real Enforcement Risk in 2026
Two things matter more than the numbers on this table. First, enforcement intensity is rising even without new statutes. New York's December 2025 comptroller audit found that 75% of test calls to the city's 311 hotline about AEDT complaints never reached the enforcement agency at all, and the agency has since committed to fixing that. Expect more investigations, not fewer, going forward.
Second, a light state law doesn't mean minimal legal liability. Texas employers who read TRAIGA's 60-day cure period as a safe harbour are still fully exposed to nationwide federal claims like the one against Workday, which has nothing to do with any state's statute.
Where Federal Preemption Is Headed Next?
President Trump's December 2025 executive order (EO 14365) established a national AI framework. It also aimed to challenge state AI laws that conflict with it. This has caused uncertainty, with Colorado's law being the most affected. A federal court paused its enforcement in April 2026.
In May, state lawmakers passed a narrower replacement, delaying the effective date to January 1, 2027. It's still unclear if New York or Illinois will follow this pattern. Both states remain firm, and NYC's enforcement is becoming stricter.
Don’t base your compliance program on uncertain outcomes. Federal anti-discrimination laws like Title VII, the ADA, and the ADEA remain unchanged. These laws were the foundation of the Workday lawsuit. State laws may change, but the duty to avoid discrimination through algorithms will stay.
How Skima AI Helps as a US Recruiting Compliance Ready Tool?
Most vendors answer compliance questions with a paragraph of reassurance. Skima AI answers with numbers you can actually check. Its internal fairness evaluation evaluated 792 candidate profiles across five demographic splits (sex, race, age, disability, and intersectional combinations) using the Four-Fifths Rule used by the EEOC to flag disparate impact.
Every group cleared the 0.80 threshold, including the toughest intersectional demographic group tested (Black or African American women, impact ratio 0.8644). That's a real result from a real test, not a claim. It's worth being precise about what that evaluation is and isn't. It is Skima AI's own internal testing program, and an independent third-party audit is planned as its next milestone.
For NYC-based employers, that distinction matters: Local Law 144 requires an audit from an auditor with no conflict of interest. So Skima AI's numbers support your compliance documentation trail, but they don't replace the outside audit you're still required to commission. What they do give you is a model you're not walking into that audit blind on.
The architecture choices behind those numbers are more interesting to a recruiter evaluating vendor risk. Skima AI's scoring model uses skills, verified experience, and role-relevant qualifications, and due to contractual DPA obligations, it never processes protected attributes like race, religion, or disability as scoring inputs.
Candidate resumes and PII are handled entirely inside Skima AI's own models hosted in Dublin, Ireland; nothing candidate-related gets sent to a public LLM API. And at every stage, from the initial ranking to the final rejection, a human has to authorize the outcome. The AI surfaces a ranked shortlist. It doesn't reject anyone on its own.
None of this shifts your compliance obligation onto Skima AI. Every law in that table still holds the employer responsible, not the software provider. What a documented, human-in-the-loop architecture does is make your side of that obligation faster to prove when a regulator or a plaintiff's attorney asks for it.
AI Hiring Compliance Laws in the US Checklist
- Inventory every tool that scores, ranks, or filters candidates, including features bundled inside your ATS
- Confirm which state definitions of "automated employment decision tool" your tools trigger
- Schedule an independent bias audit annually, even in states that don't strictly require one
- Build candidate notice into your application flow before the tool runs, not after
- Assign a named human reviewer with real authority to override AI output
- Document every override, along with the reason for it
- Request current audit results and override documentation from every vendor, including recruiting tools like Skima AI that layer onto your existing ATS
- Retain ADS-related records, outputs, and audit findings for at least four years
- Re-run your compliance check after any vendor model update
- Track Colorado, Illinois, and NYC rulemaking activity quarterly, since all three are still in motion
Final Note
The federal government stepped back from AI recruiting guidance, but federal anti-discrimination law remains unchanged, and Mobley v. Workday is the warning to every employer right now.
States are filling the gap unevenly: NYC is tightening enforcement after its own comptroller called it broken, Illinois is still writing the rules for a law already in effect, and Colorado's flagship statute got frozen and rewritten within months of taking effect.
None of that is a reason to wait. Build one compliance program to the strictest standard you're exposed to, document your human review, and treat vendor diligence as seriously as your legal team treats a contract. The law will keep shifting. Your obligation not to discriminate through an algorithm won't.
Frequently Asked Questions
1. What is recruiting compliance?
Recruitment compliance refers to following labor, anti-discrimination, and data privacy laws throughout the recruitment process, from job postings to candidate screening and rejection. It covers federal statutes like Title VII plus state-specific AI hiring regulations.
2. Why is recruitment compliance important?
Recruitment compliance protects employers from lawsuits, fines, and reputational damage while ensuring candidates receive a fair, unbiased evaluation. Non-compliance now carries real financial risk, from NYC's daily penalties to nationwide collective-action lawsuits.
3. What compliance features does Skima AI offer for healthcare and legal industries?
Skima AI verifies licenses and credentials for healthcare roles, offers on-premises deployment for strict data-control needs, and provides explainable, evidence-based scoring that legal and compliance teams can audit and defend.
4. What are compliance reports?
Compliance reports are documented records showing how hiring decisions were made, including bias audit results, candidate notices, and human review logs. They're the paper trail regulators and auditors request during investigations.