ComplianceAug 30, 20268 min read

Colorado Gutted Its AI Hiring Law. The Patchwork Around It Got Stricter Anyway.

Colorado just stripped its flagship AI employment law down to a disclosure-only regime and delayed it to 2027. California, Illinois, and New York City obligations kept advancing on schedule anyway. Here is what is actually enforceable for AI hiring tools right now, and why disclosure and recordkeeping are the two requirements every rewrite keeps landing on.

#AI hiring #Colorado AI Act #employment law #HR compliance #California employment law #Illinois HB 3773 #NYC Local Law 144 #AI regulation #automated decision systems #hiring technology
Ad

For two years, Colorado's SB 24-205 was the answer employers gave when asked what comprehensive AI employment regulation in the US would eventually look like. It was risk-based, it named "consequential decisions" including hiring and promotion explicitly, and it required the things a serious framework requires: impact assessments, a duty of care to avoid algorithmic discrimination, and documented risk-management programs for any "high-risk" AI system used in employment. Other states were expected to follow its shape.

They didn't get the chance to. Colorado has now delayed and then substantially rewritten its own law twice in twelve months — and the second rewrite did not just push the date, it removed the framework's core obligations. Meanwhile, in the states and cities that never had a comprehensive law to defer, obligations that already existed got more real, not less. The net effect for anyone deploying AI in hiring in the US right now is not "wait for the rules to settle." It's the opposite: the rules are diverging, and the safest assumption is that no single state's timeline tells you what you actually have to do today.

What happened to Colorado, twice

The original Colorado AI Act (SB 24-205, 2024) was scheduled to take effect February 1, 2026. On August 28, 2025, Governor Polis signed SB 25B-004, pushing that to June 30, 2026 — a routine-looking delay to give the state's Attorney General time to finish implementing rules.

It was not routine. On May 14, 2026, with the new June 30 date six weeks away, Polis signed SB 189. This is not a second delay of the same law — it is a different law wearing the same bill number in press coverage. Multiple law-firm trackers covering the amendment (Hunton Andrews Kurth's privacy blog, Akin Gump's AI law tracker, and Clark Hill's employment alert among them) describe the same shift: SB 189 pushes the effective date again, to January 1, 2027, and in the process eliminates the duty of care that required deployers to use reasonable care to protect people from algorithmic discrimination, drops the mandatory impact-assessment requirement, and removes the obligation to maintain a documented risk-management program. What's left is a narrower disclosure-and-transparency regime — closer to "tell people an AI system is involved" than "prove the system doesn't discriminate before you use it."

That is a meaningful downgrade, not a scheduling change. The law employers had eighteen months to prepare for — the one that would have required them to actually assess an AI hiring tool for discriminatory impact before deploying it — no longer exists in that form. What takes its place next January is closer to what several other jurisdictions already require today.

While Colorado retreated, everyone else kept moving

Three things happened on their original timelines while Colorado's framework was being narrowed, and none of them offer the "settle down and wait" option Colorado's employers effectively got.

California's hiring-specific rules are already in force — and were never on Colorado's timeline. The Civil Rights Council's regulations on Automated-Decision Systems in employment were approved June 27, 2025 and took effect October 1, 2025. They amend California's existing Fair Employment and Housing Act framework rather than creating a new AI-specific statute, which is exactly why they didn't need a rulemaking runway the way Colorado's law did — discrimination through an automated tool is treated as discrimination, full stop, with a four-year recordkeeping requirement covering the automated-decision data itself. This has been enforceable for nearly a year. It is easy to miss because it arrived through a civil-rights regulator rather than a headline "AI Act," but it is the most concrete hiring-specific obligation currently live in the US.

Illinois has a live statutory duty with no finished rulebook to point to. HB 3773's amendment to the Illinois Human Rights Act — requiring notice to applicants and employees when AI is used in recruitment, hiring, promotion, discharge, or other covered employment decisions — has been in effect since January 1, 2026. The Illinois Department of Human Rights published proposed implementing rules on May 15, 2026, opening a public comment period. Then, on June 2, 2026, IDHR withdrew those proposed rules and canceled the scheduled hearing, citing a need to coordinate with other state agencies, with no revised timeline announced (reported consistently by the National Law Review, Ogletree Deakins, and Seyfarth Shaw). The underlying notice obligation did not go away with the withdrawal — only the guidance on what satisfies it did. Illinois employers are currently complying with a duty whose precise contours the state itself has not finished defining.

New York City's oldest AI-hiring law is entering a stricter enforcement phase. Local Law 144's bias-audit requirement for automated employment decision tools has been on the books since 2023, but a New York State Comptroller audit released in December 2025 found DCWP's enforcement complaint-driven and under-resourced, and recommended the agency shift to proactive review rather than waiting for complaints. DCWP agreed to most of the recommendations. Nothing in the law's text changed — what changed is the credible likelihood that a bias-audit gap actually gets found in 2026 rather than sitting unnoticed the way it plausibly could in 2023–2025.

The pattern is fragmentation, not convergence

Put those four developments next to each other and a shape emerges that is easy to miss if you're only tracking one state at a time: the jurisdiction that tried to write one comprehensive, risk-based standard is the one that couldn't sustain it politically or administratively, twice. The jurisdictions that instead attached narrower obligations — notice, recordkeeping, audits — to existing law or existing civil-rights infrastructure are the ones that are actually live, and getting more enforced, not less.

That's a specific and useful piece of information for anyone buying or building AI hiring tools, because it tells you which bet not to make. "This will get simpler once a state finishes its comprehensive AI law" is the bet Colorado spent two years disproving. The more durable pattern across California, Illinois, and New York City is the same short list every time: tell the person an AI system is involved, and keep a record of what the system did. Those two requirements survive every rewrite because they're the floor, not the ceiling — even the framework legislatures keep retreating to.

Where this leaves a hiring platform

We don't think NiceHire should build to any one of these laws, because a product built to Illinois's notice requirement or New York's audit cadence is a product that has to be re-architected every time the next state does something different — and on this year's evidence, the next state doing something different is not a hypothetical. We built to the floor instead: every AI screening greeting NiceHire ships states plainly that the interviewer is an AI, in every language the product supports, and a customer can change the wording of that greeting but not remove the disclosure itself, because the check runs on the output rather than trusting that a template author remembered to include it. Completed AI screening interviews are recorded as a transcript against the candidate's application — with the honest limit that a session which ends without the provider returning a transcript is stored without one, and that re-running a screening replaces rather than versions the prior attempt.

Neither of those properties exists because a specific statute compelled it in every market NiceHire operates in — several of them don't reach us yet, and Colorado's newly narrowed version may never require more than what we already do. They exist because "was the candidate told" and "is there a record" turned out, across four independent legislative and regulatory processes in eighteen months, to be the two questions that survive every negotiation, delay, and rewrite. If you're evaluating AI hiring tools this year, those are the two questions worth asking regardless of which state's law is currently in the news.

Sources

This piece describes publicly reported legal and regulatory developments; it is not legal advice, and employers should confirm current requirements with counsel licensed in the relevant jurisdiction.

Ad

Ready to transform your hiring?

See how NiceHire's AI-powered hiring platform works for your team.

Get Started

Share this article

Ad

About the Author

NT

NiceHire Team

HR Tech Writer

Ad
Back to all articles
Ad
Support