Today is a one-year anniversary for one U.S. state's AI employment rules and a go-live date for another's. Neither coincides with the other on purpose — they are two different legislatures, moving on two different clocks, that happen to land on the same square of the calendar. That collision is a better illustration of where U.S. AI hiring regulation actually stands in October 2026 than any single state's statute is on its own: there is no finished framework to wait for. Obligations are arriving piecemeal, on independent schedules, and employers who treat "the rules aren't final yet" as a reason to defer compliance work are already behind in at least one state, today, regardless of what any other state's legislature does next.
California: one year of a finalized rule
California's Civil Rights Council regulations on automated-decision systems (ADS) in employment took effect October 1, 2025 — exactly a year ago. They apply to any employer with five or more employees that uses an algorithm, machine-learning model, or other automated process to make or materially influence an employment decision, and they extend liability to the tool itself: an employer is on the hook for a discriminatory outcome even when the ADS was built and sold by a third-party vendor (Fisher Phillips; Hunton Andrews Kurth). Discrimination doesn't have to be intentional to violate the rule — a facially neutral tool that produces a disparate impact on a protected class is enough (Fisher Phillips).
Two features of the California approach are worth separating from each other, because they're easy to conflate. First, anti-bias testing of an ADS is not mandatory under the regulation. Second, whether an employer performed it — and how well — is explicitly relevant to how a discrimination claim comes out. The regulations identify several factors bearing on the quality of any such testing an employer chooses to do: the statistical methods used, how recent and how frequent the testing was, how broad its scope was, what the results showed, and how the employer responded to those results (Hunton Andrews Kurth). A single validation run at launch, with no follow-up, doesn't satisfy that framing — the rule rewards testing that is repeated and documented, not testing that merely happened once (Hunton Andrews Kurth). On top of that, covered employers must retain ADS-related records — including the selection criteria the system applied — for at least four years (Fisher Phillips; DLA Piper). Separately, SB 477 reset the California Civil Rights Department's own procedural clock, requiring it to issue right-to-sue notices within one year for an individual complaint and two years for a group complaint (Liebert Cassidy Whitmore) — a reminder that the enforcement machinery around these rules is itself still being tuned, a year in.
Connecticut: the deadline that starts today
Connecticut's path to an AI employment law looks nothing like California's. Governor Ned Lamont signed SB 5, the Connecticut Artificial Intelligence Responsibility and Transparency Act, on May 27, 2026 (Ropes & Gray). Rather than one effective date, it rolls out in stages, and the first stage lands today. Starting October 1, 2026, employers covered by Connecticut's WARN Act — generally those with 100 or more employees — must disclose to the Connecticut Department of Labor, as part of any mass-layoff or plant-closing notice, whether the layoff is related to the employer's use of artificial intelligence or other technological change (Forbes; FPF). It's a narrow requirement — a yes/no disclosure tied to a specific, already-regulated event — but it's live as of this post. The broader piece of SB 5, requiring written notice to individual applicants and employees when an AI tool is used in a hiring, promotion, or firing decision, doesn't take effect until October 1, 2027 (Forbes). Enforcement of SB 5 runs through the state Attorney General, who can treat a violation as an unfair or deceptive trade practice under Connecticut law (Forbes).
Illinois: a live statute with no instructions
Illinois presents a third pattern entirely: a law that took effect on schedule, with the regulatory guidance meant to explain it pulled back after the fact. House Bill 3773, amending the Illinois Human Rights Act, took effect January 1, 2026. It makes AI use that has a discriminatory effect on employees a civil rights violation, bars using zip code as a proxy for a protected class, and requires employers to notify employees when AI is used in recruitment, hiring, discipline, or discharge decisions (Morgan Lewis; National Law Review). Unlike California or Colorado, it never required formal bias or impact assessments (National Law Review).
Then, on June 2, 2026 — five months after the statute itself took effect — the Illinois Department of Human Rights withdrew the proposed implementing rules it had published only weeks earlier, citing a need for continued coordination with other state agencies, and gave no firm date for reissuing them (Seyfarth Shaw). Seyfarth's own alert is blunt about what that does and doesn't change: the statutory obligations are still in force; it's the operational detail — exactly what a compliant notice has to say, for instance — that is now unsettled (Seyfarth Shaw). An Illinois employer today is bound by a law whose text is final and whose interpretation is not.
Colorado: the law that keeps not arriving
Colorado is the counterexample that makes the other three legible. The Colorado AI Act, enacted in 2024, was originally due to take effect February 1, 2026. Governor Polis signed a delay to June 30, 2026 in August 2025, and then, on May 14, 2026, signed SB 189, pushing the effective date again — to January 1, 2027 — while also narrowing the law's original scope (Hunton Andrews Kurth; Law and the Workplace). Two delays and a scope reduction in under a year is its own data point: the most comprehensive of the four frameworks is also the one still being negotiated in public, with no guarantee January 2027 is the last date on it.
The pattern isn't convergence — it's asynchrony
Lay the four side by side and the thing that stands out isn't a common standard forming. It's that each state's obligations are going live on their own clock, independent of whether any other state's text is finished:
- California has a full year of operating history under a finalized rule.
- Connecticut's narrowest duty starts today, with its broader one 12 months out.
- Illinois has a statute in force and a regulatory vacuum underneath it.
- Colorado has the most detailed framework on paper and the least certainty about when, or in what form, it actually binds.
None of that is waiting on the others. A multistate employer who decided in January to hold off on AI-hiring compliance work "until the picture is clearer" has now watched that picture fail to clarify for nine months, while gaining a live obligation in California that's a year old today and a new one in Connecticut that started this morning.
What actually transfers across all four
The practical response isn't guessing which state finalizes next. It's noticing what the four frameworks already have in common, because that's the part worth building regardless of how any one of them settles:
- Know, and be able to document, what criteria the tool is actually scoring. California's four-year retention duty, Illinois's notice requirement, and Connecticut's disclosure obligation all presuppose that the employer can say, specifically, what the automated step evaluated and how. A tool whose scoring logic is opaque even to the employer using it can't satisfy any of the three.
- Treat bias testing as something you'd want on file even where no state yet requires it. California already makes the presence, recency, and scope of testing relevant to how a discrimination claim resolves — without ever mandating the testing itself. That's the shape more states are likely to copy, since it's cheaper to legislate than a full impact-assessment regime.
- Build to the strictest live obligation, not the median one. A Colorado delay doesn't relax California's four-year-old rule or Connecticut's today-dated one. The frameworks don't average out; they stack, state by state, for whichever employees sit in a given jurisdiction.
That first point — being able to state plainly what an automated step evaluated — is a design question as much as a legal one, and it's the one piece of this NiceHire can speak to directly rather than generally. Every candidate who goes through NiceHire's AI screening is scored against the same fixed set of dimensions — technical, communication, and cultural fit, each out of 100 — against a threshold the employer configures. That's a narrow claim about how the mechanism is built, not a claim that it satisfies any particular state's law or a determination about the fairness of its outcomes — judgments no vendor can credibly self-certify, and we're not asserting either one. What it does mean is that "what did the tool actually score this candidate on" has a fixed, documentable answer by construction — which is the one question all four of today's frameworks, in their very different ways, are asking employers to be ready to answer.
The calendar doesn't care that the rules aren't finished. October 1 proved that twice today.
Ready to transform your hiring?
See how NiceHire's AI-powered hiring platform works for your team.
Get Started