Organizations using artificial intelligence in hiring, promotion, performance evaluation or termination decisions face binding requirements from the Equal Employment Opportunity Commission and a growing number of state laws. These requirements are not recommendations. They impose specific obligations on covered employers to test AI systems for bias, disclose their use to applicants and employees, retain detailed records and in some cases undergo independent audits. Leadership is accountable for compliance whether or not the AI system was developed in-house or purchased from a vendor.
The business problem is structural. Compliance with these requirements spans multiple domains—legal, human resources, information technology and vendor management—yet no single function typically owns the outcome. The technical substance of bias testing, the legal interpretation of what counts as an employment decision, and the operational challenge of disclosure and record-keeping sit in different parts of the organization. Without executive ownership that cuts across these boundaries, organizations implement fragmented controls, fail to comply with specific mandates or discover gaps only after enforcement action.
What the EEOC Guidance Establishes
The EEOC has clarified that Title VII of the Civil Rights Act of 1964, the Americans with Disabilities Act and the Age Discrimination in Employment Act apply to the use of algorithmic decision-making tools in employment. The guidance explains that employers may be liable for discrimination if an AI system has a disparate impact on protected groups, even if there was no intent to discriminate. Disparate impact occurs when a facially neutral employment practice disproportionately excludes or disadvantages individuals based on race, color, religion, sex, national origin, age or disability.
Under the EEOC's framework, an employer using an AI tool that screens out a substantially higher percentage of candidates in a protected class must demonstrate that the tool is job-related and consistent with business necessity. Even when that showing is made, liability may still attach if an alternative selection procedure with less adverse impact is available and the employer refuses to adopt it. The guidance makes clear that these obligations apply regardless of whether the employer developed the AI system itself or procured it from a third-party vendor. An employer cannot delegate its legal responsibility by outsourcing the algorithm.
State AI Employment Laws and Their Technical Requirements
Several states have enacted laws that go beyond federal anti-discrimination principles by imposing affirmative duties on employers that deploy AI in employment decisions. New York City's Local Law 144, which took effect in July 2023, requires employers using automated employment decision tools (AEDTs) to conduct annual bias audits, publish summary results of those audits, and provide notice to candidates and employees that an AEDT is being used. An AEDT is defined as any computational process that substantially assists or replaces discretionary decision-making for hiring or promotion. The law specifies that a bias audit must be conducted by an independent auditor within one year of use and must calculate selection rates and impact ratios for sex, race and ethnicity categories.
California's AB 331, effective January 2024, prohibits employers from using AI tools that have discriminatory impacts and requires that any AI system used in employment decisions be subject to regular testing for bias. Illinois's Artificial Intelligence Video Interview Act, in effect since 2020, applies specifically to video interviewing software that uses AI to analyze applicants. It requires employers to notify applicants before the interview that AI is being used, explain how it works and what characteristics it evaluates, obtain consent from the applicant, and limit sharing of videos to persons whose expertise is necessary to evaluate fitness for the position. Illinois also mandates that applicants be allowed to request destruction of their video within 30 days of receiving such a request.
These state laws create overlapping and sometimes inconsistent obligations. An employer operating in multiple jurisdictions must comply with each jurisdiction's requirements where they apply. The technical specifications for bias audits vary: New York City prescribes specific statistical measures; California's law is less prescriptive but establishes a standard of regular testing; Illinois focuses on transparency and consent. Organizations cannot treat these as a uniform standard.
What Constitutes an Employment Decision Under These Frameworks
A critical question is what activities trigger these obligations. The laws generally apply to AI systems used to make or substantially assist in decisions to hire, promote, assign, evaluate performance, determine compensation or terminate employees. New York City's definition includes any tool that substantially assists or replaces discretionary decision-making. This is broader than a final hiring decision. Resume screening tools that rank or filter candidates, interview platforms that score responses, performance evaluation systems that generate ratings, and scheduling tools that allocate shifts based on algorithmic predictions may all fall within scope, depending on the degree of influence the system has on the ultimate employment action.
Employers must examine each AI tool in the employment lifecycle to determine whether it meets the statutory definition. This is not solely a legal question; it requires understanding how the tool is configured, what weight its outputs carry in human decision-making, and whether a human reviewer can and does meaningfully override the system. A tool marketed as a decision-support aid may in practice function as the primary decision-maker if its recommendations are routinely accepted without independent analysis.
Bias Testing and Audit Requirements
New York City Local Law 144 prescribes the technical standard for a bias audit. The audit must calculate selection rates for different demographic groups and compare them. A selection rate is the rate at which individuals in a category are either selected to move forward in the hiring process or assigned to a category by the tool. The law requires calculation of impact ratios: the selection rate for a demographic group divided by the selection rate for the most selected group. An impact ratio below 0.80 (the four-fifths rule used in federal disparate impact analysis) is a warning sign, though not automatically dispositive.
The audit must be conducted by an independent auditor, defined as a person or group that is capable of exercising objective judgment and is not the employer or the vendor that developed or distributes the AEDT. The auditor must have access to the data necessary to perform the calculations, which means the employer must either collect demographic data from candidates or rely on historical data from similar tools. The results must be published on the employer's website, including the distribution date of the AEDT, the selection rates for each category and the impact ratios.
California's requirement for regular testing is less prescriptive about methodology but establishes the ongoing nature of the obligation. A single audit at procurement is insufficient. As the AI system is used over time, its outputs may shift due to changes in the underlying data, model drift, or modifications to the algorithm. Regular testing means periodic reassessment, though the statute does not specify intervals. Organizations must determine a testing cadence appropriate to the risk profile and frequency of use of each system.
Disclosure and Notice Obligations
Transparency requirements vary across jurisdictions. New York City requires employers to provide notice to each candidate or employee whose data is being evaluated by an AEDT at least ten business days before use. The notice must include the job qualifications and characteristics the tool will assess. For current employees being considered for promotion, the same notice requirement applies. The notice must be posted in a clear and conspicuous manner. If the employer does not directly interact with the candidate (for example, because the employer is using a staffing agency), the notice requirement still applies and must be communicated through available channels.
Illinois's Video Interview Act imposes more detailed disclosure obligations specific to video interviewing. Before the interview, the employer must notify the applicant that AI will be used to analyze their responses, explain how the AI works and what characteristics it evaluates, and obtain the applicant's consent. This is an affirmative consent requirement, not merely passive notice. The applicant must have the opportunity to decline, though declining may mean they cannot proceed in that particular selection process.
Organizations must map their candidate communication workflows to ensure notices are delivered at the correct stage, in the required form, and documented. The obligation is not satisfied by a general statement in a privacy policy that AI may be used. The notice must be specific to the particular tool and decision being made, delivered within the statutory timeframe, and retained as evidence of compliance.
Record-Keeping and Data Governance
Record-keeping obligations arise from both the substantive legal requirements and the need to demonstrate compliance in the event of an enforcement action or private lawsuit. Under the EEOC framework, employers must retain records that could be relevant to determining whether discrimination occurred. When an AI system is involved, this includes documentation of how the system was validated, what data it was trained on, how it is configured, what outputs it generated for specific decisions, and whether human reviewers intervened or overrode its recommendations.
New York City requires employers to retain certain records for at least three years, including the bias audit reports and the notice provided to candidates and employees. Illinois requires that videos and associated AI analysis be destroyed within 30 days of a candidate's request, which means the employer must have a system to track such requests and execute deletions within the statutory window. These retention obligations conflict with indefinite retention, which many organizations default to when uncertain.
Data governance becomes critical. Organizations must know what data the AI system collects, where it is stored, how long it is retained, who has access, and whether it can be retrieved and produced in response to a regulatory inquiry. Vendor contracts must allocate responsibility for data retention and must ensure the organization can satisfy its legal obligations even if the vendor relationship ends or the vendor fails to cooperate.
Vendor Relationships and Contractual Allocation of Responsibility
Most organizations using AI in employment decisions procure the systems from third-party vendors rather than developing them internally. The EEOC guidance is explicit that this does not relieve the employer of liability. The employer remains responsible for ensuring the tool complies with anti-discrimination laws and for conducting or procuring the required bias testing. If a vendor's AI system produces discriminatory outcomes, the employer is the party subject to enforcement action, though the employer may have a subsequent claim against the vendor depending on contractual indemnification provisions.
Vendor contracts must address bias testing, audit rights, data access, transparency about the algorithm's operation, and cooperation with any independent auditors the employer engages. Vendors often resist disclosing proprietary details of their algorithms, but employers need sufficient information to understand what the system does, validate its outputs, and satisfy regulatory disclosure requirements. A contract that allows the vendor to refuse access to the data or methodology necessary for a bias audit places the employer in breach of its legal obligations.
Organizations should establish a pre-procurement review process that evaluates AI employment tools against compliance requirements before purchase. This includes requiring vendors to demonstrate prior bias testing, provide documentation of their validation methodology, commit to ongoing audits, and grant the employer rights to conduct independent testing. If the vendor cannot or will not meet these requirements, the organization must either accept the compliance risk or select a different tool. The decision to proceed despite gaps must be a documented, executive-level risk acceptance, not a default outcome of inattention.
Who Owns Compliance in the Organization
Compliance with AI employment laws requires coordination across legal, human resources, IT, procurement and risk management. The legal function interprets the statutes and guidance, determines what constitutes an employment decision under each jurisdiction's law, and drafts the required notices. Human resources owns the employment processes being augmented by AI and must determine how to integrate testing, notice and consent into existing workflows without disrupting hiring timelines. IT manages the technical implementation, data flows and vendor integrations. Procurement negotiates vendor contracts and must incorporate the compliance requirements into terms and conditions. Risk management assesses the organization's overall exposure and reports to senior leadership and the board.
None of these functions individually owns the outcome. Legal cannot conduct bias audits. HR cannot interpret the technical sufficiency of an audit methodology. IT cannot determine what constitutes adequate notice to applicants. The gap is not a lack of capability within any function; it is the absence of a single accountable executive with the authority to make cross-functional decisions, establish standards, allocate budget, and report progress to the CEO and board. This is a governance problem, not a task distribution problem.
Adequate ownership requires an executive role with three characteristics: accountability for regulatory compliance outcomes across technology domains, authority to direct actions by legal, HR, IT and procurement without requiring consensus at each step, and direct reporting to the CEO or general counsel. In many organizations, this responsibility is assigned to a chief information security officer, chief privacy officer, chief compliance officer or chief risk officer. The title matters less than the scope of authority and the clarity of accountability. The executive must be able to answer the question, 'Are we compliant with AI employment laws in every jurisdiction where we operate?' with specific evidence, not assurances.
The Connection to AI and Emerging Technology Governance
AI employment law compliance is a specific instance of a broader governance challenge. Organizations are deploying AI systems across multiple functions—marketing, customer service, underwriting, fraud detection, clinical decision support, employment—each subject to different regulatory regimes and each requiring similar governance capabilities: risk assessment, bias testing, transparency, human oversight, vendor management, incident response and documentation. Building separate compliance programs for each use case is inefficient and creates gaps where responsibilities overlap or no function claims ownership.
A coherent AI governance framework establishes organization-wide standards for evaluating, procuring, deploying and monitoring AI systems regardless of functional domain. It assigns ownership for maintaining an inventory of AI systems, classifying them by risk, establishing testing and validation requirements for each risk tier, defining approval workflows, and ensuring ongoing monitoring. Employment AI is one category within this inventory, subject to both the general governance framework and the specific legal requirements applicable to employment decisions.
Organizations that treat AI employment compliance as solely an HR or legal project miss the structural need for enterprise governance. The same principles that require bias testing and transparency in hiring apply, with different technical specifications, to AI used in credit decisions under the Equal Credit Opportunity Act, in housing under the Fair Housing Act, and in healthcare under HIPAA and state medical AI laws. Leadership must establish a governance structure that addresses AI risk as an enterprise concern, then applies that structure consistently across domains. [Virtual CISO leadership](/vciso/) provides the executive ownership and cross-functional authority necessary to establish and maintain this governance layer, bridging the gap between technical capabilities, legal requirements and business strategy.
Practical Next Steps for Leadership
Leadership should take the following actions to establish control over AI employment law compliance:
- Inventory all AI systems currently used or substantially assisting in hiring, promotion, performance evaluation or termination decisions. Include both internally developed tools and vendor-provided platforms. Document what each system does, what data it uses, what outputs it generates, and how those outputs influence final decisions.
- Determine which jurisdictions' laws apply based on where candidates and employees are located. Map the specific requirements of each applicable law—audit frequency, notice timing and content, record retention periods, and consent requirements—and identify conflicts or gaps in current practice.
- Assign a single executive owner accountable for compliance across all AI employment systems and all jurisdictions. Ensure this executive has authority to direct legal, HR, IT and procurement actions, budget to procure audits and implement controls, and a direct reporting line to the CEO or general counsel.
- Conduct or procure bias audits for each in-scope AI system according to the most stringent applicable standard. Engage independent auditors where required by law. Document the methodology, data sources, results and any remedial actions taken. Publish summaries where required.
- Review and revise candidate and employee communications to incorporate required notices. Ensure notices are delivered at the correct point in the process, contain the required information, and are documented. Establish a process for obtaining and recording consent where required.
- Audit existing vendor contracts for AI employment tools. Identify gaps in audit rights, data access, transparency about algorithmic operation, and indemnification. Renegotiate terms where gaps create unacceptable compliance risk or establish a timeline to transition to compliant vendors.
- Establish a pre-procurement review gate for any new AI employment tools. Require vendors to demonstrate compliance with applicable laws, provide documentation of prior bias testing, and commit contractually to ongoing audits and cooperation with the organization's independent auditors.
- Implement record-keeping procedures that capture the documentation necessary to demonstrate compliance: audit reports, notices sent, consents obtained, data retention schedules, vendor due diligence, and evidence of human review or override of AI recommendations. Ensure records are retained for the required periods and are retrievable in response to regulatory inquiries.
- Review the organization's broader AI governance framework. Determine whether the capabilities required for employment AI compliance—risk classification, validation standards, vendor management, monitoring—are being built as reusable components applicable to AI systems in other domains, or whether each domain is building separate controls.
Organizations uncertain whether their current controls satisfy these requirements, or lacking a clear executive owner for AI governance outcomes, should consider a confidential consultation to assess the gap between current state and regulatory expectations. Heights Consulting Group provides virtual CISO leadership that establishes the governance structure, assigns accountability, defines compliance standards and reports progress to senior leadership and the board. If your organization would benefit from an objective assessment of AI governance maturity and a roadmap to close specific gaps, reach out to discuss your situation in confidence.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: AI and Emerging Technology Governance
Governance for how your organization adopts artificial intelligence: approved uses, data handling boundaries, review before deployment, and accountability for the output.