If you run hiring technology across more than one US state, 2026 has been the year the ground moved under your compliance program four times — in four different directions. Illinois’ AI-in-hiring statute went live on schedule and is already being enforced. Colorado’s marquee AI law was frozen by a federal court, then rewritten by its own legislature into something narrower and pushed back over a year. New York City’s original bias-audit law — the model every other state borrowed from — was just found by its own state auditor to be barely enforced at all. And in the background, the federal government spent the first quarter of the year trying to make most of this moot.
None of these four things happened in isolation, and none of them point the same direction. That’s the actual story: not “AI hiring regulation is tightening” or “AI hiring regulation is loosening,” but that the four biggest players in this space are now pulling against each other, and an employer using an AI screening or interview tool has to comply with all of them at once, in whichever combination follows their candidates.
The federal move: preempt first, ask Congress later
On December 11, 2025, President Trump signed an executive order titled “Ensuring a National Policy Framework for Artificial Intelligence,” aimed squarely at the growing pile of state AI statutes — hiring laws very much included (Morgan Lewis; Paul Hastings). The order does three concrete things. First, it directs the Attorney General to stand up an AI Litigation Task Force within 30 days — it began operating January 10, 2026 — whose job is to challenge state AI laws in federal court on preemption, dormant-Commerce-Clause, or other grounds (Seyfarth). Second, it told the Secretary of Commerce to publish, by March 11, 2026, a review naming the state AI laws it considers overly burdensome. Third, and most relevant to any vendor whose sales pitch includes the words “reduces bias,” it directed the FTC to issue a policy statement — also due March 11 — treating state-mandated bias mitigation as a potential per se deceptive trade practice under the FTC Act, on the theory that forcing a model to alter a “truthful” output is itself a form of deception (Latham & Watkins).
What the order does not do is repeal anything. Every legal analysis of it says the same thing: an executive order cannot itself override a state statute — only Congress or a court can do that, and until one of them does, state AI laws stay enforceable (Latham & Watkins). So the order is best read as a declaration of litigation intent, not a change in what’s currently required of you. It matters anyway, because four months later it appears to have gotten its first scalp.
Colorado: frozen, then rewritten, then delayed again
Colorado’s SB 24-205 was supposed to be the first comprehensive US state law governing “high-risk” AI in consequential decisions, hiring included, with a duty of care, mandatory impact assessments, and deployer disclosure obligations. It never actually took effect as written. The legislature pushed the original February 1, 2026 date to June 30, 2026 in a special session in August 2025 (Akin Gump). Then, on April 27, 2026 — barely two months before that second date — a federal court paused enforcement of the law entirely while litigation over it proceeds.
Two and a half weeks later, on May 14, 2026, Governor Polis signed SB 189, which doesn’t just delay the Colorado AI Act — it repeals and replaces it. The duty of care, the risk-management program requirement, and the mandatory impact assessments are gone. In their place is a narrower, disclosure-focused regime built around “automated decision-making technology” used in consequential decisions (employment among them): advance notice to the person being evaluated, post-decision disclosures, and a defined set of consumer rights, enforced centrally by the state Attorney General rather than through a private duty of care (Wilson Sonsini; Holland & Knight). The new law’s effective date is January 1, 2027 — a full eleven months after the original statute was ever supposed to apply, and it now asks employers for far less than it originally did.
It’s tempting to read Colorado’s retreat as the federal executive order working exactly as designed. The timeline lines up too neatly to ignore, but none of the legal commentary we found draws a direct causal line between the December EO and the April injunction — the underlying litigation predates and is broader than the EO. What’s fair to say is that Colorado is now the clearest example of a state AI hiring law announced, delayed twice, partially enjoined, and substantially narrowed, all before it ever actually bound a single employer.
Illinois: no drama, just enforcement
Illinois took the opposite path. HB 3773, which amends the Illinois Human Rights Act to prohibit AI that has “the effect of” discriminating against employees or applicants on the basis of a protected class, took effect exactly on schedule on January 1, 2026 — no delays, no injunction (natlawreview). It requires employers to notify applicants and employees when AI is used in recruitment, hiring, promotion, discipline, or discharge decisions, and it separately bans using a zip code as a proxy for a protected characteristic (Ogletree). The liability standard is the sharp edge here: it’s an effects test, not an intent test. If an AI tool produces a discriminatory outcome, the employer is liable through the ordinary Illinois Department of Human Rights charge process regardless of whether anyone meant for that to happen.
Illinois then had its own smaller stumble, worth noting precisely because it illustrates how little a rulemaking delay actually buys an employer. IDHR published proposed implementing rules on May 15, 2026, opened a comment period running to June 29, and scheduled a June 10 public hearing — then, on June 2, 2026, postponed the whole rulemaking process, including the hearing, to allow more time to coordinate with other state agencies (Seyfarth; DataGuidance). That sounds like Colorado’s story in miniature, but it isn’t: the underlying statute — the notice duty, the zip-code ban, the effects-based liability standard — was in force from January 1 regardless of whether the specific implementing rules ever get finalized. A withdrawn rule postpones the fine-grained “how do I comply” guidance. It does not postpone the law.
New York City: the original model, audited and found wanting
It’s worth remembering that none of this started in 2026. New York City’s Local Law 144, requiring an independent annual bias audit of any “automated employment decision tool,” a public summary of the results, and 10 business days’ advance notice to candidates, has been the reference model for state-level AI hiring regulation since 2023. What’s new is that the law’s own enforcer just got graded, and failed. The New York State Comptroller’s audit, covering July 2023 through June 2025 and released in December 2025, found the city Department of Consumer and Worker Protection’s enforcement of LL144 to be “ineffective” — citing misrouted complaints, superficial reviews of the bias audits employers post, and a complaint-driven posture with no proactive investigation (DLA Piper). DCWP has since committed to better complaint routing and more proactive enforcement, and outside counsel is now advising clients to expect more investigations and higher penalties as a result, not fewer.
The lesson generalizes beyond New York: a disclosure or audit requirement on paper is not the same thing as a functioning enforcement pipeline, and a state auditor calling out a three-year enforcement gap is itself a strong signal that scrutiny is about to increase, not decrease.
What actually holds still across four moving pieces
Strip away the procedural churn and there’s a pattern in what each of these four regimes — even the federal one, in its FTC framing — treats as the non-negotiable minimum: the person being evaluated should be able to find out that an automated system is involved, and the criteria the system is applying should be something more specific than a black box producing a number. Illinois requires notice. Colorado’s replacement law is now only about disclosure. NYC requires a public audit summary specifically so outsiders can see what a tool measures. Even the federal order’s own theory — that mandated changes to a “truthful output” are the problem — presumes the output is legible enough to argue about in the first place.
That’s not a coincidence, and it’s also not a new idea to us. We built AI disclosure into every NiceHire AI screening interview greeting — every shipped language, first attempt and reconnect alike — not because a specific statute told us to, but because a candidate should be able to tell they’re talking to a machine before they decide how much of themselves to bring to the conversation. Every candidate we score is measured against the same three fixed dimensions — technical, communication, and cultural fit, each out of 100, against a threshold the employer sets and can see — rather than an opaque composite score. Neither of those design choices makes us compliant with Illinois’ statute, Colorado’s new one, or NYC’s audit regime — compliance with a specific law is a legal determination for each employer’s own counsel to make, not a marketing claim we’re in a position to award ourselves — but they mean the two things every one of these four regimes is converging on, disclosure and legible criteria, aren’t things we’d have to bolt on after the fact.
What this means if you’re actually running hiring right now
Don’t wait for the patchwork to resolve into one federal standard — nothing above suggests that’s imminent, and even the executive order can’t force the issue by itself. Don’t read a paused or repealed state law as less work either: Colorado employers still need to track a law that now takes effect in 2027 with different obligations than the one they prepared for in 2025, and Illinois employers who relaxed when IDHR pulled its draft rules are still bound by the statute those rules were only ever going to interpret. And don’t assume an enforcement gap, like the one New York’s comptroller just documented, stays a gap — audited regulators tend to overcorrect, not continue quietly as before. The one thing that travels safely across all four jurisdictions, present rules or future ones, is telling candidates when AI is involved and being able to say plainly what it measured. Build for that regardless of which version of the map is current when you read this.
Ready to transform your hiring?
See how NiceHire's AI-powered hiring platform works for your team.
Get Started