AI in Employment and HR
AI tools used in hiring, performance management, workforce planning, and employee monitoring are among the most tightly regulated AI applications globally. Jurisdictions from New York City to the EU AI Act treat employment AI as high-risk by default, requiring bias audits, disclosure obligations, and human oversight. This topic covers the specific legal obligations and governance controls for organizations deploying AI in HR and talent contexts.
Key board-level questions
- 1.Do our AI-assisted hiring tools comply with NYC Local Law 144, Colorado's AI Act (SB205), and applicable EU AI Act high-risk obligations?
- 2.Are employees and candidates informed when AI is used to evaluate them?
- 3.Have we conducted independent bias audits of AI tools used in selection, promotion, or performance assessment?
- 4.How do we ensure human decision-makers retain meaningful control over AI-assisted employment decisions?
Regulatory frameworks
Colorado AI Act (SB 24-205), repealed
Colorado's SB 24-205, signed in May 2024, would have regulated developers and deployers of high-risk AI. It never took effect: its start date slipped from February 2026 to June 2026. In May 2026 Colorado repealed it and replaced it with SB 26-189, a narrower automated decision-making law effective 1 January 2027.
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.
Illinois Biometric Information Privacy Act, AI Provisions
Illinois BIPA, 740 ILCS 14, restricts collection, storage, use, and disclosure of biometric identifiers and information. It affects AI processing facial geometry, voiceprints, iris scans, and similar data. BIPA has generated extensive biometric privacy litigation.
NIST AI Risk Management Framework (AI RMF 1.0) and Playbook
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.
Playbook guidance
How do we detect and mitigate algorithmic bias?
How do we measure and mitigate algorithmic bias?
What does meaningful human oversight look like for high-risk AI decisions?
How do we ensure human-in-the-loop review is actually effective?
What are our obligations under emerging AI regulations?
What does audit-ready AI documentation look like in practice?
