If you hire in the United States and any part of your process touches AI — resume parsing, automated scoring, an AI-run screening call — you are no longer operating under one rulebook. You are operating under at least five, and one of them changed twice in the last four months. Illinois has a notice-and-nondiscrimination law that has been in force since New Year's Day. California's employment regulator has been enforcing a broad automated-decision-system rule since October 2025. New York City's bias-audit law — the oldest in the country — just got a government report card that changes what its quiet enforcement history means. Texas took the opposite approach and wrote a narrow, discrimination-only law. And Colorado — the state with the most ambitious AI-in-employment statute on the books — spent the spring getting sued by xAI, joined by the US Department of Justice, and rewrote its own law in response before it ever took effect.
This piece separates what is actually binding today from what is proposed, delayed, or stayed pending litigation, and looks at what the through-line is for anyone running hiring AI across state lines.
Illinois: notice and a nondiscrimination duty, in force since January 1
Illinois House Bill 3773 amends the Illinois Human Rights Act and took effect January 1, 2026. It does two things. First, it makes it a civil rights violation for an employer to use AI in a way that has the effect of subjecting employees or applicants to discrimination on the basis of a protected class — covering recruitment, hiring, promotion, renewal of employment, selection for training, discharge, discipline, tenure, and the general terms and conditions of employment. Second, it requires employers to notify employees and applicants when AI is being used in those decisions, and separately prohibits using a zip code as a proxy for a protected characteristic.
The detail worth knowing if you're relying on secondary summaries: the Illinois Department of Human Rights was supposed to issue implementing rules spelling out exactly when and how notice must be given, and it withdrew its proposed rule text rather than finalize it. That means the statutory obligations — the discrimination prohibition, the zip-code ban, and the general notice duty — are live and enforceable right now, while the fine print of "what counts as adequate notice" is still unsettled. That's an unusual state to legislate in: the duty exists, the compliance checklist for satisfying it does not, fully, yet. Employers in Illinois using AI screening should not wait for the rule to finalize before disclosing; the statute doesn't wait either.
California: already the broadest rule in the country, and already enforced
California's contribution didn't arrive with 2026 headlines — it's been in effect since October 1, 2025, which makes it easy to miss in a roundup of "new" 2026 laws even though it's arguably the most consequential one operating today. The California Civil Rights Department's regulations on automated-decision systems ("ADS") apply to any employer with five or more California employees, and they define an ADS broadly: any computational process that makes or substantially assists a decision about an employment benefit, whether or not it's marketed as "AI."
Two features stand out. First, liability attaches on a disparate-impact basis, not just intentional discrimination — an ADS that produces a statistically skewed outcome across a protected class can violate the law even without any employer intent to discriminate. Second, and this is the one that matters most if you buy hiring software rather than build it: employers are held responsible for discriminatory outcomes from an ADS even when it's sourced from a third-party vendor. "Our vendor's model did it" is not a defense under this framework. Employers are also expected to retain ADS-related data for four years. If you have any California hiring volume, this rule — not the more publicized Illinois or Colorado statutes — is probably your actual floor.
And California's reach may not stop at California hires. In Mobley v. Workday — the federal case testing whether an HR software vendor itself can be liable for discriminatory screening — the court on 22 June 2026 declined to dismiss the plaintiffs' California FEHA claims on a jurisdictional theory worth sitting with: it found a sufficient nexus to California because Workday allegedly designs, develops and operates its screening algorithms from its California headquarters, regardless of where the employer using the tool or the rejected applicant is actually located. If that reasoning holds, a vendor's home state can pull a discrimination claim into that state's law even when neither the employer nor the candidate ever set foot there. "We don't do business in California" is not the same question as "does our vendor."
New York City: the oldest law just got told its enforcement isn't working
New York City's Local Law 144 predates everything above — enacted 2021, in force since 5 July 2023. It requires employers using an "automated employment decision tool" to screen candidates for hiring or promotion in NYC to have the tool independently audited for bias within the prior year, publish a summary of the results, and notify candidates at least ten business days before the tool is used on them, with penalties running up to $1,500 per violation per day. What changed recently is not the statute but what its enforcement record means. On 2 December 2025, the New York State Comptroller published an audit of the city agency responsible for enforcing it, and the findings were blunt: enforcement to date has been "ineffective." When auditors placed test calls to the city's 311 hotline to report AEDT complaints, 75 percent were routed incorrectly and never reached the agency at all. And where the agency's own compliance survey of 32 companies found exactly one instance of non-compliance, the Comptroller's auditors reviewing the same 32 companies found at least 17 potential violations. The agency agreed to the audit's recommendations — fixing the complaint intake, running proactive sweeps — on the record.
The tempting read is "enforcement is broken, so the risk is low." That is backwards. A regulator publicly committed to fixing a seventeen-fold undercount in its own sample is a specific, dated signal that the compliance bar employers have actually been held to is about to move toward what the statute always said — and a quiet enforcement history was never evidence of a compliant process, only of an unexamined one.
Texas: the lightest touch of the five
Texas's Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149) took effect the same day as Illinois's law, January 1, 2026, but reads almost like a rebuttal to Colorado's approach. An earlier, more sweeping Texas proposal (HB 1709) would have imposed disclosure duties and use-case inventories on employers; the version that actually passed dropped nearly all of that. What remains, as it touches hiring, is a prohibition on developing or deploying an AI system with the intent to discriminate against a protected class. There's no mandated candidate disclosure, no required audit, no use-case registry. The practical takeaway for a multi-state employer: satisfying Texas's bar does essentially nothing to satisfy Illinois's or California's, because Texas asks a narrower question (did you intend to discriminate) where the others ask broader ones (did the tool produce a discriminatory effect, and did you tell people you were using it).
Colorado: the law that got sued, stayed, and rewritten in one legislative session
Colorado passed the most comprehensive state AI-employment statute in 2024, built around a "high-risk AI system" framework requiring impact assessments, risk-management policies, and reporting of algorithmic discrimination — obligations well beyond what Illinois or California impose. It never got the chance to apply as originally written.
In April 2026, xAI sued to block the law, and the US Department of Justice intervened on xAI's side — a first: the federal government moving to invalidate a state AI statute. The DOJ's argument leaned on Executive Order 14365, the December 2025 order establishing a DOJ "AI Litigation Task Force" to challenge state AI laws, and made an equal-protection argument: that requiring companies to prevent disparate impact on protected groups amounts to compelling race- and sex-conscious decisions. A federal judge stayed enforcement of the law that same month, pending a ruling on xAI's request for a preliminary injunction.
Colorado didn't wait the litigation out. On May 14, 2026, Governor Polis signed SB 189, which pushed the effective date from its original date to January 1, 2027 and substantially narrowed what the law requires: gone are the mandated risk-management policies, impact assessments, annual reviews, and algorithmic-discrimination reporting. What remains are three obligations — notice to affected individuals, a structured adverse-action and human-review process, and a three-year record-retention duty — enforceable only by the Colorado Attorney General, with no private right of action. Multiple legal trackers report that the federal stay applies to the amended law too, so even this narrowed version is not currently being enforced while the litigation proceeds. Colorado went, in one legislative session, from the most ambitious framework in the country to a disclosure-and-recordkeeping rule that isn't yet in force.
The pattern underneath the patchwork
Four states plus a city, five different tests, and none of them defer to where your company is headquartered — what applies is generally where the employee or applicant is located (and, if the Mobley nexus theory holds, sometimes where your vendor builds the tool). A recruiting team hiring across Illinois, California, New York City, Texas, and Colorado today is actually complying (or failing to) against five different legal theories at once: an effects-based nondiscrimination-plus-notice duty (Illinois), a disparate-impact liability regime that reaches your vendors (California), a bias-audit-and-notice regime whose under-enforcement was just publicly called out (NYC), an intent-based prohibition with minimal process (Texas), and a disclosure-and-recordkeeping duty currently frozen by a federal court (Colorado). There is no federal floor underneath any of this — the closest thing, the EU AI Act's high-risk hiring obligations, doesn't apply to US-only employers at all, and we've written separately about how its own deadline just moved.
What we'd actually tell a hiring team evaluating AI tools against this landscape, rather than a state-by-state checklist that will be stale by the time you finish reading it:
Ask what the vendor discloses, and to whom, by default. Illinois requires notice; Colorado's narrowed law (whenever it takes effect) requires notice; California doesn't mandate a specific disclosure format but a candidate who was never told an ADS scored them is a worse position to defend from than one who was. A tool where disclosure is a configurable option a customer has to remember to turn on is a different risk posture than one where it's structurally part of every interaction. In our own screening product, every AI interview greeting states that the interviewer is an AI — across every language we support and on both the first attempt and a reconnect after a dropped call — because that check runs on every greeting path rather than living in a template a customer could edit away.
Ask what happens when the vendor's model is wrong, not just what happens when it's used maliciously. California's ADS rule is explicit that disparate impact, not intent, creates exposure, and that the employer can't point at the vendor. That means the actual due-diligence question for a buyer isn't "does this vendor promise not to discriminate" — every vendor will say yes — it's "does this vendor score every candidate against the same fixed set of criteria, or does the model improvise per candidate." A tool that evaluates everyone against the same stated dimensions is at least auditable; one that free-forms a judgment per resume is much harder to defend statistically if an outcome is challenged.
Don't assume Colorado's story is over. A stayed law is not a repealed one. If the preliminary-injunction ruling goes against xAI, Colorado's narrowed obligations could take effect on relatively short notice, and "we build for the strictest applicable state" is cheaper to say in a vendor questionnaire in August than to retrofit in December.
None of this is a compliance guarantee we're offering on anyone's behalf — a five-state comparison in a blog post is not a legal opinion, and given how fast this specific area is moving, treat every effective date above as something to reconfirm before you act on it. What it is, is a map of where the actual obligations sit right now, and a reminder that "compliant with AI hiring regulation" isn't a single box to check in 2026. It's at least four, and they don't agree with each other.
Sources consulted: coverage of Illinois HB 3773 from the Illinois State Bar Association, Crowell & Moring, Ogletree Deakins, and the National Law Review; California CRD automated-decision-system regulations coverage from Ogletree Deakins, Jackson Lewis, Mayer Brown, and Paul Hastings; the Mobley v. Workday 22 June 2026 motion-to-dismiss order as covered by Duane Morris's class-action-defense blog and Norton Rose Fulbright; NY State Comptroller, "Enforcement of Local Law 144 – Automated Employment Decision Tools," 2 Dec 2025 and DLA Piper's January 2026 analysis of it; Texas HB 149 (TRAIGA) analysis from HireRight, Berkshire Associates, and K&L Gates; Colorado SB 189 and the xAI/DOJ litigation from Hunton Andrews Kurth, Littler, Fisher Phillips, Clark Hill, Law and the Workplace / National Law Review, Jenner & Block, Barnes & Thornburg, Norton Rose Fulbright, and Government Contractor Compliance & Regulatory Update.
Ready to transform your hiring?
See how NiceHire's AI-powered hiring platform works for your team.
Get Started