The biggest AI hiring law news of the last 90 days is that both rules employers were bracing for moved, and neither one disappeared. Regulation (EU) 2026/1744, in force 27 July 2026, pushed the EU AI Act's Annex III employment obligations from 2 August 2026 to 2 December 2027. Colorado repealed its AI Act on 14 May 2026 and replaced it with a narrower automated decision-making technology statute that starts 1 January 2027. Meanwhile New York City's Local Law 144, Illinois HB 3773 and California's FEHA rules are all live today, and Mobley v. Workday has put software vendors inside the liability chain.
Last reviewed 2 August 2026. This page is a standing reference and we refresh it monthly, because in this area a nine-month-old compliance memo is worse than no memo at all.
I run a company that builds hiring automation for other companies. Over the last quarter I have watched two separate clients pull a candidate screening rollout because their counsel read a headline about a deferral and concluded the whole file could wait until 2027. That reading is wrong, and it is expensive in a quiet way: the obligations that actually bite in 2026 are municipal, state-level and judicial, not European. Below is what genuinely changed, what did not, and what each change means for a company that already has AI somewhere in its funnel.
The 90-day timeline
| Date | Jurisdiction | What happened | Status on 2 Aug 2026 |
|---|---|---|---|
| 11 Dec 2025 | US federal | Executive order directs the Attorney General to stand up an AI Litigation Task Force to challenge state AI laws | Active |
| 15 Dec 2025 | New Jersey | Disparate-impact regulations covering automated employment decision technology take effect | In force |
| 1 Jan 2026 | Illinois | HB 3773 amendments to the Human Rights Act take effect | In force |
| 1 Jan 2026 | Texas | TRAIGA (HB 149) takes effect | In force |
| 31 Mar 2026 | United Kingdom | ICO publishes its report and draft guidance on automated decision-making in recruitment | Consultation stage |
| 9 Apr 2026 | Colorado | xAI files suit to enjoin SB 24-205 before its 30 June 2026 start date | Litigation continuing |
| 27 Apr 2026 | Colorado | Court grants a joint motion suspending enforcement of SB 24-205 | Enforcement suspended |
| 14 May 2026 | Colorado | Governor Polis signs SB 26-189, repealing and replacing the Colorado AI Act | Effective 1 Jan 2027 |
| 15 May 2026 | Illinois | IDHR publishes proposed AI notice rules, then postpones the rulemaking | Statute live, rules pending |
| 28 May 2026 | N.D. Cal. | Court holds AI bias-testing data may be shielded by attorney-client privilege | Decided |
| 22 Jun 2026 | N.D. Cal. | Most Mobley v. Workday claims survive dismissal, including FEHA claims against the vendor | Decided |
| 8 Jul 2026 | European Union | Regulation (EU) 2026/1744 adopted | Adopted |
| 24 Jul 2026 | European Union | Published in the Official Journal | Published |
| 27 Jul 2026 | European Union | Regulation enters into force; Annex III employment duties move to 2 Dec 2027 | In force |
| 2 Aug 2026 | European Union | Article 50 transparency duties and the Article 99 penalty regime begin to apply | Live today |
Read that table as two stories running in opposite directions. The rules that impose heavy documentation on AI builders are slipping. The rules that let candidates, regulators and plaintiffs' lawyers attack a rejection as algorithmic discrimination are arriving on schedule or getting sharper. If your AI governance framework was designed around the first story, it is pointed at the wrong risk, and so is whatever you have budgeted for reviewing your AI hiring tools.

EU AI Act employment news: Annex III moved, the rest did not
Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It defers the full high-risk obligation set for standalone Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. The Commission's stated reason is prosaic: the harmonised standards and the national competent authorities that the regime depends on are not ready.
What got deferred is the expensive part. Risk management systems, technical documentation, data governance standards, logging, human oversight design and third-party conformity assessment now sit behind a 2 December 2027 line.
What did not move matters more for most employers. The Article 5 prohibitions have applied since 2 February 2025, and they include emotion inference in the workplace, which is the single most common thing I see quietly embedded in video interview products. The Article 4 AI literacy duty and the Article 50 transparency rules were left exactly where they were, and Article 50 begins to apply today, 2 August 2026, alongside the Article 99 penalty framework. A four-month grace period runs to 2 December 2026 for content-marking on systems already on the market. GDPR Article 22 was never part of the AI Act and never paused.
So the honest summary of this piece of EU AI Act employment news is that a European employer using AI to rank candidates in August 2026 still owes candidates transparency, still cannot infer emotional state from an interview recording, still owes an Article 22 answer on solely automated decisions, and now has sixteen extra months to assemble the conformity file. Sixteen months is not a reprieve. It is a budgeting window for EU AI Act compliance, and the work inside it is evidence, not paperwork.
Which of your HR tools actually count as high-risk under Annex III
Annex III, point 4 covers employment and worker management. In practice, four categories of tool land inside it: systems used to place targeted job advertisements, systems that analyse and filter applications, systems that evaluate or score candidates, and systems that make or materially inform decisions on promotion, termination, task allocation or performance monitoring.
That sweep is wider than most HR teams assume. A resume parser that only extracts fields is usually outside it. The same parser with a fit score attached is inside. A scheduling assistant is outside. A scheduling assistant that deprioritises candidates by predicted no-show probability is inside, because it is allocating access to the process. When we audit a client's stack before building anything, the tool that most often turns out to be a high-risk AI system is not the flashy interview product. It is the ATS ranking feature that shipped in a platform update nobody read. Inventory your AI hiring tools by what they output, not by what the vendor calls them.
Penalties under Article 99 reach EUR 15 million or 3% of worldwide annual turnover for breaches of deployer obligations and Article 50 transparency, and EUR 35 million or 7% for the Article 5 prohibitions. Those are ceilings, not expectations, but they set the tone of the conversation you will have with your own board. The deferred items, including the Article 14 human oversight design work, are the ones that take a year to build rather than a week to write.
Colorado: the AI Act is gone, the ADMT Act arrives 1 January 2027
The Colorado AI Act, SB 24-205, never took effect. Its start date was pushed from February to 30 June 2026, then xAI sued Colorado's Attorney General on 9 April 2026 seeking to enjoin it on First Amendment, Commerce Clause and vagueness grounds. The Department of Justice moved to intervene on 24 April 2026, the first time the federal government has intervened in a challenge to a state AI law. On 27 April 2026 the court granted a joint motion suspending enforcement.
Then, on 14 May 2026, Governor Polis signed SB 26-189, which repealed the Colorado AI Act outright and replaced it with the Automated Decision-Making Technology Act, effective 1 January 2027 for decisions made on or after that date.
The replacement is a genuinely different animal. Gone are the high-risk classification scheme, the mandatory risk management programme, the annual impact assessments and the statutory duty of care. What remains is a disclosure and contestability regime built on four duties. Employers must give clear and conspicuous notice before using automated decision-making technology that materially influences a consequential decision. Within 30 days of an adverse outcome, they must give a plain-language explanation of the technology's role, a route to request more information, and a statement of the candidate's rights. They must offer meaningful human review and reconsideration on request where commercially reasonable. And they must keep compliance documentation for three years.
Developers carry their own load: intended uses, known harmful uses, training data descriptions, known limitations, and monitoring instructions handed to every deployer.
Enforcement runs through the Colorado Attorney General as a deceptive trade practice, with a 60-day cure period that is waived for knowing or repeated violations. There is no private right of action, which is the single most underrated fact in this whole file. The Colorado exposure is regulatory. The exposure that will actually cost a mid-market employer money is a Title VII or FEHA claim in federal court, and no state legislature can repeal that.
So if you were asking whether the repeal means you no longer owe candidates an adverse-action explanation: in Colorado specifically, you owe a narrower one, and you owe it from 1 January 2027 rather than 30 June 2026. Everywhere else, the answer depends on whether a candidate can plead disparate impact, and the answer to that has been yes since 1971.
Local Law 144 is the rule being enforced harder, not softer
NYC Local Law 144 has been in force since 1 January 2023 with enforcement from 5 July 2023, and it is the only AI hiring law in the United States with a hard, auditable, published deliverable. If you use an automated employment decision tool to substantially assist or replace discretionary hiring or promotion decisions for a role located in New York City, you need an annual bias audit by an independent auditor, a published summary of that audit on your site, and candidate notice at least 10 business days before the tool is used.
AI bias audits under this rule calculate selection rates and impact ratios by race, ethnicity and sex. An impact ratio below 0.80, the four-fifths rule, is the conventional signal of adverse impact. An AI bias audit that reports selection rates and stops short of impact ratios has not done the job, and we have reviewed several published summaries that do exactly that. Historical data from real use of the tool is preferred; test data is permitted with the limitation disclosed. Summaries stay posted for three years after you stop using the tool.
On 2 December 2025 the New York State Comptroller published an audit of how the Department of Consumer and Worker Protection had been enforcing all of this, and the finding was blunt: enforcement was ineffective. Seventy-five percent of test calls to 311 about AEDT issues were misrouted and never reached DCWP. The agency reviewed 32 companies and identified one instance of non-compliance; the Comptroller's own auditors looked at the same companies and identified at least 17 potential violations. Across the entire July 2023 to June 2025 audit window, DCWP received two complaints.
DCWP accepted most of the recommendations and committed to proactive rather than complaint-driven investigation. Read that as the end of the quiet period. Published AI bias audits are the one deliverable a regulator can check from a browser tab, so that is where a proactive programme starts. Penalties are up to $500 for a first violation and $500 to $1,500 for each subsequent one, but every day of unaudited use is a separate violation and every missed notice is a separate violation, so the arithmetic gets ugly fast. There is no private right of action under the NYC AI law itself, which is why the compounding daily structure exists.
The extraterritorial question comes up on nearly every call we have with a US client. The NYC AI law follows the job and the candidate, not your office. A company headquartered in Karachi or Austin running an automated employment decision tool against applicants for a role based in New York City is covered. Having no New York office is not a defence.
On whether you can keep running a candidate screening tool while an AI bias audit is in progress: the statute conditions use on a bias audit conducted within the previous twelve months, so an audit that is merely underway does not satisfy it. Nor does an automated employment decision tool become compliant because you have booked the auditor. The practical answer we give clients is to fall back to a documented non-automated process for New York roles until the audit summary is published, which is annoying for a fortnight and much cheaper than accruing daily penalties.
The rest of the US map
| Jurisdiction | What triggers it | Core duties | Live from | Who enforces |
|---|---|---|---|---|
| New York City | AEDT used for a job located in NYC | Annual independent bias audit, published summary, 10 business days notice | 1 Jan 2023 | DCWP, civil penalties per day |
| Illinois | AI used in recruitment, hiring, promotion, discipline or discharge | No discriminatory effect, no ZIP code as a proxy, notice to applicants and employees | 1 Jan 2026 | IDHR and the Human Rights Commission |
| Illinois (video) | AI analysis of recorded video interviews | Advance notice, consent, distribution limits, deletion within 30 days on request | 1 Jan 2020 | Private enforcement under AIVIA |
| California | ADS used in an employment decision, 5+ employees | Anti-discrimination duty, agent liability, four-year record retention, bias-testing as an affirmative defence | 1 Oct 2025 | Civil Rights Department, private FEHA claims |
| Texas | AI developed or deployed with intent to discriminate | Intent-based prohibition only | 1 Jan 2026 | Attorney General, 60-day cure, no private right of action |
| Colorado | ADMT materially influencing a consequential decision | Notice, 30-day adverse-outcome explanation, human review on request, three-year records | 1 Jan 2027 | Attorney General, 60-day cure |
| New Jersey | Automated employment decision technology | Disparate-impact analysis under the Law Against Discrimination | 15 Dec 2025 | Division on Civil Rights |
| Maryland | Facial recognition during an interview | Signed, dated applicant waiver | 1 Oct 2020 | State enforcement |
| European Union | Annex III point 4 employment systems | Full high-risk regime; Article 5 and Article 50 duties already live | 2 Dec 2027 | National market surveillance authorities |

Two things stand out when you lay them side by side. First, the standards are incompatible in a way that makes a per-state compliance strategy pointless for anyone hiring across more than four states. Texas asks whether you intended to discriminate. Illinois HB 3773 and California ask whether the effect was discriminatory, which is a completely different evidentiary question. You cannot satisfy both with a policy document; you satisfy both by building the evidence trail an algorithmic discrimination claim would demand in court.
Second, the federal government is actively trying to collapse the map. The December 2025 executive order created an AI Litigation Task Force to challenge state AI laws on Commerce Clause and preemption grounds, directed a Commerce review of burdensome state laws, and tied BEAD broadband funding to repeal. The DOJ intervention in the Colorado case was the first proof this is not rhetorical. I would not build a compliance programme on the assumption that any particular state law survives to 2028. I would also not build one on the assumption that Title VII goes anywhere, because preempting a state AI statute does nothing to a federal algorithmic discrimination claim.
Do UK employers face an equivalent regime?
There is no UK statute specific to AI in hiring. There is something arguably more demanding, because it applies to every automated decision rather than to a defined list of tools.
On 31 March 2026 the Information Commissioner's Office published a report and draft guidance on automated decision-making in recruitment, built on evidence from more than 30 employers plus public perceptions research. The headline finding was that many employers do not accept that they are doing automated decision-making at all, and therefore have no safeguards in place. The ICO's language on human involvement is the sentence to put in front of your hiring managers: it must be meaningful and active, not a token gesture or a rubber stamp.
The legal frame shifted underneath this. The Data (Use and Access) Act 2025 rewrote Article 22 of the UK GDPR into a new Article 22A. The old model was a general prohibition on solely automated decisions with narrow exceptions. The new model is a right of challenge with safeguards, which widens the available lawful bases to include legitimate interests, while keeping tighter restrictions where special category data is involved. That is a liberalisation of the entry conditions and a tightening of the operating conditions. Candidates must be told, must be able to make representations, must be able to obtain human review, and must be able to contest the outcome.
For a UK employer the practical checklist is a lawful basis, a data protection impact assessment that actually names the model and the features, transparency about the logic, fairness and bias testing, and a human review route that a real person staffs. The ICO is treating human oversight as an operating requirement rather than a design principle, and that distinction is the one employers keep missing. The Equality Act 2010 sits behind all of it, and indirect discrimination claims do not care whether a model or a manager produced the ranking.
Mobley v. Workday: vendor liability stopped being theoretical
If you read one item of AI hiring law news from this quarter and act on it, make it this one.
The case has moved steadily against the position that a software vendor is merely a tool supplier. In May 2025 the Northern District of California granted preliminary certification of an ADEA collective covering applicants aged 40 and over who were screened through Workday's system, and in July 2025 the court confirmed the collective reached applicants scored or ranked using HiredScore features. On 6 March 2026 the court rejected the argument that disparate-impact protections reach only current employees. On 28 May 2026 it held that AI bias-testing data may be protected from discovery by attorney-client privilege, which is a genuinely important tactical point about how and with whom you run your testing. On 22 June 2026 most claims survived dismissal, including California FEHA claims against Workday itself, on the reasoning that the vendor designs and operates the screening tools from its California headquarters and can be liable as an agent under Raines v. U.S. Healthworks.
The lead plaintiff, Derek Mobley, applied to more than 100 roles through employers using the screening tools and was rejected every time.
Two conclusions follow for buyers. Your vendor's AI bias audit does not discharge your obligation. Under Local Law 144 the duty to have an audit and to publish the summary sits with the employer or employment agency using the tool; a vendor-supplied audit can be a valid input, but only if it is independent and reflects your configuration and your applicant pool. A generic audit run on the vendor's aggregate data tells you almost nothing about your impact ratio, and nothing at all about whether your own funnel produces adverse impact, because your role mix and your geography are the variables that move it.
And on who carries the liability when the vendor's model discriminates: both of you, on different theories. Vendor liability and employer liability are not alternatives a court picks between. The employer faces Title VII, ADEA, ADA and state-law exposure as the decision-maker. The vendor now faces direct agent liability in at least one live case. Your commercial protection is contractual, and the terms we tell clients to insist on are the right to receive the underlying audit data rather than a summary, a defined indemnity for discrimination claims arising from model outputs, a commitment to notify you of material model changes before deployment, and audit cooperation obligations that survive termination. Most standard HR tech contracts contain none of these.
If a human signs off every rejection, are you outside the rules?
No, and this is the most common misreading I encounter.
Human sign-off changes which rules apply, not whether rules apply. It can take you outside the UK's solely-automated category and outside GDPR Article 22, and it can move you out of Colorado's "materially influences" trigger if the human genuinely reconsiders. It does not touch Local Law 144, which turns on whether the tool substantially assists the decision, not on whether a person clicks approve. It does nothing at all for disparate impact under Title VII, because the liability there attaches to the outcome.
The ICO's phrasing is the standard everyone is converging on: meaningful and active, not a rubber stamp. In our builds we treat that as an engineering requirement rather than a policy statement. A reviewer who sees only a score and a name is a rubber stamp. A reviewer who sees the score, the top contributing features, the candidate's own submitted evidence against those features, and a required free-text reason before the decision commits is doing review. The second design costs about a week of extra work and it is the difference between having a defence and having a log. It is why the reviewer screen in our AI HR Agent will not let a decision commit without a reason string attached to it.
Record retention: what to keep, and for how long
| Record | Why you need it | Minimum retention | Rule driving it |
|---|---|---|---|
| Applicant flow data by protected class | Reconstructing selection rates and impact ratio | 4 years | California FEHA ADS regulations |
| ADS and selection criteria documentation | Showing what the tool measured and why | 4 years | California FEHA ADS regulations |
| Bias audit summary as published | Proving the audit existed and was current | 3 years after tool discontinued | NYC Local Law 144 |
| Candidate notices and timestamps | Proving the 10 business day notice | Length of the claim window | NYC Local Law 144 |
| ADMT compliance documentation | Demonstrating notice, explanation and human review | 3 years after the decision | Colorado SB 26-189 |
| Model version and configuration at decision time | Answering which model produced which outcome | Life of the claim window | Evidentiary, not statutory |
| Human reviewer identity, reason and timestamp | Rebutting the rubber-stamp allegation | Life of the claim window | Evidentiary, not statutory |
The last two rows are not required by any statute I have cited, and no record retention schedule a client has handed us has ever included them. They are the two records that decide cases. If a claim lands in 2029 about a rejection in 2026, the question will be which model version scored that candidate and what the human reviewer actually did. Systems that overwrite model versions in place, which is most of them, cannot answer that.
What we build in, and what we refuse to automate
We build hiring automation for clients on the basis that every score is reconstructable. In practice that means an immutable decision log keyed to model version, an applicant-flow export that can produce impact ratios on demand without a data science project, notice generation wired into the job posting workflow so it cannot be skipped, and a reviewer interface that will not accept a decision without a stated reason. That is our AI governance framework in the hiring context, and it is deliberately unglamorous. Most of the value of artificial intelligence governance in this domain is boring plumbing that produces evidence. An AI governance framework whose only output is a policy PDF will not survive a subpoena. Ask any vendor selling you artificial intelligence governance software what it will hand a plaintiff's expert in 2029, and watch what happens to the demo.

The agentic pattern raises the stakes, because an agent that autonomously advances or rejects candidates across several systems creates decisions no single system owns. Agentic AI governance for hiring starts from a simple rule we do not bend: the agent may gather, summarise, schedule and rank, and it may not issue a rejection. We covered the wider control-plane design in our guide to agentic AI architecture, guardrails and ROI, and the same separation of duties applies here with the volume turned up. Agentic AI governance in hiring is mostly about deciding, in advance and in writing, which state transitions an agent is allowed to cause. Agentic AI governance written after the agent ships is an incident report with a nicer title.
Two things we tell clients not to automate. Do not automate accommodation requests under the ADA or the Equality Act, because the whole point is an individualised interactive process and a model cannot conduct one. And do not automate the final rejection at any stage where a candidate has already invested time in a live interview, not because a rule forbids it but because it converts a routine adverse outcome into the kind of grievance that becomes a complaint.
Our AI HR Agent is built around those constraints, and the time-to-hire case study shows what the numbers look like when the audit trail is designed in from the start rather than retrofitted. For teams that want the screening mechanics rather than the legal frame, our companion piece on AI candidate screening and where humans still decide goes into the pipeline design. If your constraint is data residency rather than hiring law, the private LLM hosting guide covers when running models on your own infrastructure is worth the operational cost.
For EU AI Act compliance specifically, the sixteen-month deferral is best spent on the conformity file rather than on nothing. Data governance evidence and logging design take longer to build than policy documents, and they are what the December 2027 deadline actually asks for. Buyers who wait until mid-2027 will be buying consultancy in a seller's market.
How to use this page
This is a standing reference and it is dated at the top. EU AI Act employment news alone changed three times in the last nine months, so AI hiring law news moves fast enough that we re-verify every claim on this page monthly against primary sources, and the sources block at the bottom carries the URL and date for each. If you are building a compliance position on any single line here, check the underlying source, because the thing that changed last week may be the thing you are relying on.
If you want a second pair of eyes on your own stack, our AI automation team runs a free audit that maps which of your AI hiring tools are AEDTs, which are Annex III systems, and which are neither. That inventory is the first artefact of any artificial intelligence governance programme that will hold up, and most teams do not have one. Book it here and bring your ATS configuration.



