Deploying an AI system to screen resumes, flag a compliance exception, or run part of a performance review used to sit in a legal gray area. That gray area closed during 2026. A handful of state laws and one federal standard now apply directly to what most companies are calling an AI employee, AI worker, or digital staff member: Illinois, New York City, Colorado, California, and the EEOC all regulate the moment an automated system touches a hiring, promotion, discipline, or termination decision. None of these laws use the phrase "AI employee." All of them cover one.
This guide covers what's actually enforceable right now, not what's still moving through a state legislature. Illinois amended its Human Rights Act instead of writing a new AI statute. New York City's law only reaches a narrow legal category called an automated employment decision tool. Colorado repealed its original AI Act less than two years after passing it and replaced it with something considerably smaller. California is running two separate tracks at once: one already in force, one vetoed and rewritten. And the EEOC pulled its own hiring guidance in 2025, then reissued a version of it in April 2026. None of this is settled. All of it is real, and all of it applies whether the system making the decision is called an agent, a bot, or an AI employee.
For a while, the assumption in US AI policy was that states would follow Colorado's first move: a broad statute covering "high-risk" AI systems in general, with compliance duties for anyone who builds or deploys one. That's not what actually took hold. Every state that passed a real, enforceable rule on AI in employment picked a narrower target: the specific moment an automated tool makes or materially informs a decision about someone's job. Illinois amended an existing civil rights statute rather than write a new one. New York City defined one legal category of tool and attached an audit requirement to it. Even Colorado, after its broad law collapsed, rewrote itself around automated decision-making technology used in consequential decisions, employment among them, instead of AI generally.
The practical result is that there's no single "AI employment law" to check against. There's a set of narrow, overlapping rules that trigger based on where your workforce or applicants are located, what the tool actually does, and which decision it touches. A company operating in Illinois, New York City, Colorado, and California is subject to four differently worded sets of obligations for the same underlying AI system, and none of the four fully covers what the others require.
That matters most for companies that assumed one compliance review would cover the whole country. A resume-screening tool used by a remote-first company hiring in ten states doesn't get evaluated once. It gets evaluated against Illinois' notice-and-effect standard for any Illinois-based applicant, against NYC's audit requirement for anyone hiring into a New York City role, and against California's ADMT rules for California applicants, all from the same underlying system and the same vendor contract. A compliance program built around "our AI hiring tool is fine" as a single yes-or-no answer misses that the answer depends on where the candidate sits, not where the tool runs.
The table below is the fast version. Read past it for what each row actually requires and what it doesn't, since the differences between "in effect" and "not yet in effect" matter more here than in most areas of employment law.
Jurisdiction | Law | Status | Effective date | What it covers |
|---|---|---|---|---|
Illinois | HB 3773 (IHRA amendment) | In effect | January 1, 2026 | Bans AI use that has a discriminatory effect in employment decisions; requires employee/applicant notice; bans zip code as a protected-class proxy |
New York City | Local Law 144 (AEDT) | In effect, enforcement tightening | In force since 2023; stricter enforcement expected through 2026 | Independent annual bias audit, published summary, and candidate notice for automated hiring or promotion tools |
Colorado | SB 26-189 (repeals and replaces SB 24-205) | Not yet in effect | January 1, 2027 | Disclosure and transparency requirements for automated decision-making technology in consequential decisions, including employment |
California | CCPA automated decision-making technology regulations | In effect; phased compliance | January 1, 2026, with full compliance required by January 1, 2027 | Consumer rights and business obligations for ADMT used in employment and other consequential decisions |
California | "No Robo Bosses Act" (SB 947, formerly SB 7) | Pending, not enacted | N/A | Would add notice and human-oversight requirements for AI used in workplace management, if it becomes law |
Federal | Title VII (EEOC enforcement) | In effect, always has been | N/A | Disparate-impact liability for discriminatory outcomes from any selection procedure, AI included; the employer is liable regardless of who built the tool |
Illinois House Bill 3773 amended the Illinois Human Rights Act and took effect on January 1, 2026. It does three things. First, it prohibits employers from using AI that has the effect of subjecting employees or applicants to discrimination based on a protected class, covering recruitment, hiring, promotion, renewal of employment, selection for training or apprenticeship, discharge, discipline, tenure, and any other term or condition of employment. Second, it requires employers to notify employees and applicants when AI is being used to make or influence those decisions. Third, it explicitly bans using zip code as a proxy for a protected characteristic, closing off a common workaround for demographic screening that doesn't ask about race or ethnicity directly.
The word doing the most work in that first provision is "effect." Illinois didn't write an intent-based standard. An employer doesn't need to have built a tool to discriminate, or even know that it does, to be liable if the outcome shows a discriminatory pattern across a protected class. That's a disparate-impact standard applied directly to AI, and it puts the burden on the employer to actually know what its screening tool is doing to different applicant pools, not just what it was designed to do. Complaints go through the Illinois Department of Human Rights, the same body that handles other IHRA claims, which means an AI-driven hiring decision is now litigated the same way a human recruiter's decision would be.
HB 3773 isn't Illinois' first move here. The state passed the Artificial Intelligence Video Interview Act back in 2020, which already required employers to notify candidates before using AI to analyze video interviews, get their consent, and destroy the recordings within 30 days of a request. HB 3773 takes that same instinct, disclosure and consent before an automated system evaluates a person, and applies it across the entire employment lifecycle instead of just video interviews.
For HR teams building or buying these tools, that burden shows up long before a legal review does. See our guide to AI in HR for where automated screening and notice requirements actually sit inside a hiring and onboarding workflow.
New York City's Local Law 144, in effect since 2023, requires employers and employment agencies using an Automated Employment Decision Tool for NYC hiring or promotion decisions to get an independent bias audit once a year, publish a summary of the results, and give candidates notice that an AEDT is in use. The audit has to measure selection rates across race, ethnicity, and sex categories and calculate an impact ratio for each. Violations carry civil penalties of up to $1,500 per violation per day, and each day of continued non-compliance can count separately.
For its first two years, the law had a reputation for being real on paper and thin in practice. A December 2025 audit by the New York State Comptroller gave that reputation a number. Three-quarters of the test calls the Comptroller's office made to NYC's 311 hotline about AEDT issues were misrouted and never reached the Department of Consumer and Worker Protection, the agency responsible for enforcement. In a parallel review, DCWP surveyed 32 companies and found one case of non-compliance; the Comptroller's own auditors reviewed the same 32 companies and found at least 17 likely violations.
DCWP has since agreed to most of the Comptroller's recommendations: better complaint routing, staff cross-trained specifically on AEDT review, use of the technical resources available through the NYC Office of Technology and Innovation, and a shift away from a purely complaint-driven model toward proactive review. Employment law firms tracking the law are telling clients to expect a materially stricter enforcement posture through the rest of 2026, not a continuation of the light-touch pattern from the law's first two years.
What a bias audit has to reconstruct is close to what any AI employee handling a consequential decision should already be keeping on its own: what data the tool saw, what it scored, and on what basis. That's the same substance a decision audit trail produces for any AI system making or influencing an outcome that affects someone's employment, not a system log showing that a process ran, but a reviewable record of what was seen, decided, and why.
Colorado passed the first comprehensive state AI law in the US in 2024, Senate Bill 24-205, often shortened to the Colorado AI Act. It set out a broad compliance regime for "high-risk" AI systems, employment decisions included, with separate duties for developers and for deployers. It never actually took effect. The legislature delayed it once in August 2025, pushing the effective date to June 30, 2026. Then, in May 2026, Governor Polis signed Senate Bill 26-189, which repealed the original law entirely and replaced it with something considerably narrower.
The replacement, sometimes called Colorado's Anti-Discrimination in AI framework, drops the original developer-and-deployer compliance regime and focuses instead on disclosure and transparency requirements for automated decision-making technology used in consequential decisions, a category that still includes employment. It takes effect January 1, 2027, and the Colorado Attorney General's office is running a separate rulemaking process to fill in the operational detail before then.
If a search result or an older compliance memo describes Colorado's AI law as a sweeping high-risk-AI statute with detailed impact-assessment obligations for every deployer, it's describing a law that no longer exists. What's actually coming into effect in Colorado in 2027 is a narrower disclosure regime built around consequential decisions, not the original SB 205 framework.
California's AI-in-employment picture splits into two tracks that are easy to conflate.
The first track is already moving. Regulations implementing the California Consumer Privacy Act's rules for automated decision-making technology were finalized on September 23, 2025 and took effect January 1, 2026. ADMT under these rules is defined broadly enough to reach employment screening and evaluation tools, and it comes with consumer-facing rights: pre-use notice, and in many cases the ability to opt out of or access information about how the ADMT was used. Businesses already using ADMT before the rules took effect have until January 1, 2027 to reach full compliance. Penalties run up to $2,500 per unintentional violation and $7,500 per intentional violation, assessed per affected person, which compounds fast for a hiring tool screening thousands of applicants a year.
The second track hasn't started. A bill known as the "No Robo Bosses Act," originally introduced as SB 7, would have added separate notice and human-oversight requirements for employers using AI in workplace management decisions. Governor Newsom vetoed it in October 2025, citing overly broad restrictions and notification requirements. A revised version was reintroduced as SB 947 in February 2026. As of this writing it's a pending bill, not a law. Track it, but don't build a compliance program around it yet.
At the federal level, Title VII of the Civil Rights Act still governs disparate impact in employment decisions, AI-assisted or not. In 2025 the EEOC withdrew its AI-hiring technical assistance documents following Executive Order 14281, which directed federal agencies to de-prioritize disparate-impact enforcement generally. That withdrawal changed enforcement posture, not the underlying law. Title VII's disparate-impact provisions are written into the statute itself, not into EEOC guidance, and they stayed fully enforceable regardless of what the agency's stated priorities were that year. Private plaintiffs kept bringing claims through the period when the EEOC's own technical guidance was unavailable. In April 2026 the EEOC issued a new technical assistance document specifically addressing disparate-impact analysis for resume screeners and AI video-interview tools, a partial return to the position it had walked back the year before.
The rule that survived all of this intact is the one that matters most for anyone deploying AI in hiring: an employer can't point to a vendor to avoid liability. If a company's selection procedure produces a discriminatory outcome, the company is responsible for that outcome, whether it built the underlying tool itself or bought it from someone who did. Vendor contracts and indemnification clauses may shift the cost after the fact. They don't shift the legal liability itself.
None of this makes an AI employee a legal employee. The term describes an operating model: software given a job, a scope of authority, and a way to be measured, not a person with FLSA wage protections, unemployment eligibility, or the right to organize. An AI system deployed to screen resumes or flag disciplinary exceptions has no standing under any of the laws above. It can't be fired, and it can't sue.
That distinction doesn't reduce anyone's liability. It moves the liability entirely onto the organization that deployed the system, the same way a company remains liable for a human employee's discriminatory conduct or for a defective vendor product. See our breakdown of how AI workers actually differ from human workers for the fuller version of that distinction.
What follows from it, practically, is that governance has to sit at the deployment level, not inside the AI system itself. A named process owner has to define what the tool is allowed to decide on its own and where it has to stop and escalate to a person. That policy, often called an Agent Operating Procedure, needs to be something the process owner can update directly when a state changes an effective date or a threshold, not something that requires an engineering ticket every time a compliance deadline moves. And every action the system takes that touches someone's employment needs a decision log behind it: what the tool saw, what it decided, and why, tied to a specific case and reviewable by whoever eventually has to answer for it. That's the same substance NYC's bias-audit law is trying to force into existence through an annual third-party review. An organization that builds it in from the start doesn't need an outside audit to discover it's missing.
For companies in banking, financial services, healthcare, or pharma, employment law is only one layer. Those industries carry AI compliance requirements of their own on top of it: see our guide to AI employees in US banking and financial services and our guide to AI employees in US healthcare and pharma for what changes when the AI system is also handling a regulated financial or clinical process.
These laws will keep moving. Colorado already proved that a state can pass a comprehensive AI statute and take it apart within two years. Illinois, NYC, and California all show the opposite pattern: narrower rules, tied to a specific decision or tool category, that are proving harder to walk back once they're in force. What won't change in either direction is the underlying principle. The organization deploying the system owns the outcome, and the only defense that has held up so far, in an audit, in an EEOC complaint, or in court, is being able to show, case by case, what the system did and why.