←
AI for HR Certification
Strategic · M26 · lesson 26 of 27 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
US Federal and State AI Employment Laws: Building Compliance Across a Patchwork Landscape
📖
now learning

US Federal and State AI Employment Laws: Building Compliance Across a Patchwork Landscape

15 min

Overview

The US doesn't have a unified federal AI law yet. Instead, you're navigating a patchwork:
- Federal guidance from EEOC, DOL, FTC (not law yet, but enforceable)
- State laws, NYC, Illinois, Colorado, Maryland all have AI employment laws. More states are considering them.
- Existing employment laws applied to AI, Title VII discrimination law, FCRA credit reporting law, ADEA age discrimination law, state wage laws

This creates compliance complexity. But the pattern is clear: transparency, non-discrimination, and explainability. If you're compliant with the strictest state (New York) and federal guidance, you'll likely be compliant almost everywhere.

This lesson walks you through the major US laws and guidance, what they require, and how to build compliance that works across all jurisdictions. We also address common gray areas, enforcement mechanisms, and what happens when you get it wrong.

Federal Guidance: The EEOC, FTC, and DOL Positions

EEOC Guidance on AI & Discrimination

What they care about: AI can't discriminate based on protected characteristics.

Their position: Title VII of the Civil Rights Act applies to AI just like it applies to human hiring. If your AI has disparate impact (screens out protected groups at higher rates), you've violated Title VII.

Key principle: "Employers are liable for discriminatory AI decisions even if discrimination wasn't intentional."

What you need to do:
- Validate AI for bias (show it doesn't discriminate)
- Monitor outcomes (track selection rates by demographic group)
- Be transparent (tell candidates AI is used)
- Have appeal process (candidates can challenge decisions)

Enforcement: EEOC can sue on behalf of job applicants. They've already filed cases.

FTC Position on AI (Enforceable)

What they care about: Unfair or deceptive AI practices.

Their position:
- Don't make false claims about AI capabilities ("Our AI is 99% accurate" if it's not)
- Protect consumer privacy in AI systems
- Consider harmful effects of AI (especially on protected groups)

Enforcement: FTC can sue companies for unfair AI practices. They've already filed enforcement actions.

DOL & OSHA Guidance

What they care about: AI affecting workplace safety and conditions.

Their position: OSHA cares about AI monitoring/surveillance (e.g., AI monitoring employee productivity). Guidance focuses on fair use and worker protections.

Key State AI Laws

New York Local Law 144 (Video Interview Bias Audit)

Applies to: Any AI used to analyze job candidates in interviews

Requirements:
- Bias audit before using AI to assess candidates
- Annual re-audit
- Notify candidates that AI is used
- Provide results of bias audit to candidates (if requested)

What counts: Facial recognition, tone analysis, speech analysis, "any automated decision system" analyzing candidate video

Practical impact: If using video interview AI, you need bias audit before launch, then annually.

Your action: If using AI video interview analysis:
- Get bias audit done (before launch)
- Schedule annual re-audit
- Disclose to candidates (in interview materials)
- Be prepared to share audit results if requested

Penalties: $500-$1,000 per violation (can add up fast if you violate for multiple candidates)

Illinois AI Video Interview Act

Similar to NYC but narrower scope: Only applies to video interview analysis

Requirements:
- Notify candidate that AI is used in video interview
- Get consent before recording/analyzing
- Disclose limitations of AI

Your action: If using video interview AI:
- Notify candidates upfront
- Get consent before recording
- Disclose: "The AI may not accurately assess all candidates"

Colorado Automated Employment Decision Systems Law

Broader than NYC, regulates automated employment decisions generally

Requirements:
- Notice to candidates
- Accuracy testing
- Human review option

Your action: Provide notice that AI is used; conduct testing; offer human review.

Maryland Law

Similar approach to Colorado, transparency and non-discrimination

Compliance Matrix: Which Law Applies Where?

Requirement
Federal (EEOC/FTC)
NYC 144
Illinois
Colorado
Maryland

AI disclosure
Yes (transparency)
Yes
Yes (video only)
Yes
Yes

Bias audit
Recommended (expected)
Required (video)
Not required
Recommended
Recommended

Consent
Not required
Not required
Yes (video)
Recommended
Recommended

Appeal process
Recommended
Not required
Not required
Recommended
Recommended

If you operate in multiple states: Do the most restrictive thing (satisfies all).

Practical Compliance Checklist

For Resume Screening AI:

  • [ ] EEOC: Validated for bias? Outcomes tracked by demographic group?
    - [ ] State compliance: Where do your candidates come from? (If NY, CO, MD: additional requirements)
    - [ ] Transparency: Is AI disclosed in job posting?
    - [ ] Appeal process: Can candidate challenge decision?
    - [ ] Documentation: Can you show you audited for bias?

For Video Interview AI:

  • [ ] NYC: Bias audit completed? Results available to candidates?
    - [ ] Illinois: Candidate notified? Consent obtained?
    - [ ] Transparency: Candidate knows AI is analyzing their video?
    - [ ] Testing: Have you validated accuracy?
    - [ ] Limitations: Can you clearly state limitations?

For Any Employment Decision AI:

  • [ ] FTC: Making accurate claims about capabilities?
    - [ ] EEOC: Tested for bias? Outcomes equitable?
    - [ ] State laws: Which states apply to your hiring?
    - [ ] Documentation: Can you show you did due diligence?

New laws coming:
- Federal AI bill (Congress is debating; unlikely before 2025-2026)
- More state laws (CA, TX, and others considering AI employment laws)
- EEOC enforcement focus on AI discrimination

Strategy: Build compliance with:
- Transparency (always disclose)
- Non-discrimination (audit for bias)
- Documentation (show your work)
- Human oversight (people make final decisions)

This approach will work for current laws and future laws.

Template: AI Compliance Checklist for Your State(s)

AI System: [Name]

Jurisdiction Compliance:

[ ] Federal (EEOC/FTC applicable):
- [ ] AI does not have disparate impact
- [ ] No false claims about AI
- [ ] Outcomes tracked and audited
- [ ] Candidates can appeal

[ ] New York (if recruiting/assessing candidates):
- [ ] Bias audit completed (if video interview analysis)
- [ ] Candidate notified
- [ ] Audit results available to candidate on request

[ ] Illinois (if video interview analysis):
- [ ] Candidate notified before recording
- [ ] Consent obtained
- [ ] Limitations disclosed

[ ] Colorado (if automated employment decision):
- [ ] Candidate notified
- [ ] Testing completed
- [ ] Human review option offered

[ ] Maryland (if relevant):
- [ ] Transparency confirmed
- [ ] No discrimination

Case Study: Compliance Done Right vs. Wrong

Case Study 1: The Compliant Approach (Hypothetical Tech Company)

A mid-sized tech company implemented an AI resume screening tool. Here's how they did compliance:

Pre-deployment:
- Conducted fairness audit with external auditor (checked for 4/5ths rule violations)
- Added to job postings: "We use AI to help screen applications"
- Built appeal process: "If screened out, you can request human review"

Post-deployment:
- Quarterly bias audits (tracked selection rates by demographic group)
- Quarterly reporting to compliance committee
- When a bias issue was found (disparate impact detected), they paused, investigated, retrained the model, and re-audited
- Trained managers on the tool and its limitations

Result: Tool deployed successfully, no regulatory issues, candidates trusted the process, organization continued improving it.

Case Study 2: The Non-Compliant Approach (Hypothetical Financial Services Company)

A financial services company deployed the same type of tool without proper preparation:

Pre-deployment:
- No fairness audit
- No disclosure to candidates
- No appeal process
- Thought: "It's just a screening tool; how much risk can there be?"

Post-deployment:
- Someone complained to EEOC (candidate was screened out, later manually reviewed, and was qualified)
- EEOC opened investigation
- Company discovered: tool had 35% disparate impact against women (women screened in at 45% vs. men at 70%)
- No documentation of bias audit
- No evidence that company thought about fairness

Result: EEOC enforcement action, settlement costs >$500K, reputational damage, had to rebuild recruiting process, candidates avoided company.

Common Compliance Gray Areas

Q: If our AI tool has disparate impact, are we automatically liable?

A: Not automatically, but it creates significant legal exposure. Title VII allows a "business necessity" defense: "We have disparate impact, but there's a legitimate, non-discriminatory reason." This is hard to prove. It's much safer to avoid disparate impact in the first place.

Q: Do we need to disclose all the data the AI uses?

A: No, but transparency about what the AI considers (resume content, previous work history, etc.) is expected. You don't need to explain every variable, but candidates should understand the general process.

Q: What if we use AI for screening but humans make final decisions? Are we still liable?

A: Yes. You're liable for discriminatory AI, even if humans make final hiring decisions. The AI's recommendations carry weight. Humans often follow them. Your liability exists upstream.

Q: Can we use different AI models for different groups (e.g., one model for engineers, another for sales)?

A: Yes, if it's job-related. One model for engineers, another for salespeople = legitimate. One model for men, another for women = illegal discrimination.

Red Flags: What Not to Do

Red flag: "We won't disclose AI use"
- Federal guidance expects transparency
- State laws (NYC, Colorado, Illinois) require it
- Hiding it makes things worse if discovered
- Candidates will eventually find out; trust is destroyed

Red flag: "We can't afford bias audits"
- EEOC expects them
- They're ~$5-10K/quarter (cheap compared to litigation)
- Not auditing is much more expensive (lawsuit risk easily runs $500K-$2M)
- Auditing is a compliance investment, not a cost

Red flag: "Only the AI decides"
- EEOC expects humans to make final decisions
- "The computer said no" isn't a legal defense
- You're liable for discriminatory AI decisions
- Humans must review and can override

Red flag: "No appeal process"
- EEOC expects appeal rights
- State laws recommend it
- Not having one puts you at legal risk
- Easy to implement: "If you disagree with our screening decision, request human review"

Red flag: "We can't test the model because it's proprietary"
- You can and should test
- EEOC's position: your responsibility to validate, not vendor's
- If vendor won't allow testing, that's a vendor problem
- You need to ensure compliance

>
CALLOUT BOX: The State Compliance Strategy

If you operate nationally, don't try to comply with 50 different standards. Instead:

  • Identify your highest-risk states. NY, CA, IL, CO, MD are strictest.
    - Comply with the strictest standard. If you satisfy NY law 144, you're in good shape almost everywhere.
    - Document your compliance. Can you show you audited for bias, disclosed AI, offered appeal? Good.
    - Monitor for changes. More states will pass AI laws. Watch for them.

Example:
- You hire nationally
- NY, CO, IL are your biggest hiring markets
- You implement: bias audits (quarterly), AI disclosure (in job postings), appeal process
- This satisfies federal guidance + NY + CO + IL
- When CA passes a law, you likely already comply

Deliverable: Your US Compliance Checklist (2 pages)

Create a document covering:

Page 1: Federal & State Requirements
- Federal (EEOC, FTC, DOL guidance)
- State-specific (identify which states apply to you)
- Compliance requirements for each

Page 2: Implementation Checklist
- For each AI system, verify compliance
- For each jurisdiction, verify requirements are met
- Document your compliance actions

What to Do Monday Morning


  • Map your hiring geography. Where do your candidates come from? Which states are biggest sources?

  • Identify applicable laws. Federal guidance applies to all. Which state laws apply to you?

  • Create your compliance checklist. Use template above. Which requirements apply?

  • Implement bias audits. If not already doing them, start now. Quarterly minimum.

  • Update job postings. Add: "We use AI to help screen applications."

  • Create appeal process. How can candidates challenge decisions?

  • Brief your Legal team. Make sure they know requirements for your states.

Key Takeaways


  • No single federal law yet, but EEOC/FTC enforce existing laws against discriminatory AI. Title VII discrimination law applies to AI.

  • State laws are proliferating. NYC, Illinois, Colorado, Maryland all have AI employment laws. More coming.

  • Transparency + non-discrimination + documentation = compliance in almost all jurisdictions.

  • Do the most restrictive thing. If you operate in NY, you're already complying with Illinois and most other states.

  • Documentation is your defense. Show you audited for bias, validated accuracy, disclosed AI use.

Deep Dive: Title VII and AI Discrimination

Title VII of the Civil Rights Act prohibits employment discrimination based on race, color, religion, sex, or national origin. The law applies to AI just like it applies to human decision-making.

Key concepts:

Disparate treatment: You intentionally treat someone worse because of their protected characteristic. Example: "We use AI, but we override it for women." Illegal.

Disparate impact: Your policy has a neutral appearance but disproportionately affects protected groups. Example: AI screens out women at 30% vs. men at 20%. The policy (use AI screening) is facially neutral, but the impact is discrimination. Potentially illegal unless there's a business necessity.

Business necessity defense: You can have disparate impact if there's a legitimate, non-discriminatory reason and no less-discriminatory alternative. Example: "Selection rate is lower for this group, but they have objectively lower qualifications." The key: you must have analyzed this and have documented evidence.

Your Title VII compliance checklist:
- [ ] AI doesn't intentionally discriminate (disparate treatment)
- [ ] AI doesn't have disparate impact (4/5ths rule or similar)
- [ ] If disparate impact exists, you have documented business necessity
- [ ] You have less-discriminatory alternatives and rejected them for legitimate reasons
- [ ] You can explain your decision to regulators

Understanding FCRA and AI

The Fair Credit Reporting Act (FCRA) applies to AI used to make employment decisions, if a third party is involved in compiling/using the information.

Key requirement: If you use a third-party vendor to provide background checks or assessments:
- You must disclose to the candidate that a report is being used
- You must get consent
- If you take adverse action (don't hire based on report), you must notify the candidate and give them chance to dispute

In practice: If you use a vendor's AI screening tool, and it recommends screening someone out, and you don't hire them, FCRA disclosures might apply. Check with your attorney.

Accommodations and AI

The Americans with Disabilities Act (ADA) requires reasonable accommodations for qualified individuals with disabilities. AI can't screen someone out based on disability.

Red flag areas:
- Video interview analysis: May discriminate against people with speech disabilities, mobility limitations, etc.
- Timed tests: Might need accommodations for people with certain disabilities
- Keyboard/mouse requirements: Need alternatives for people with mobility limitations

Your ADA compliance checklist:
- [ ] AI doesn't screen based on disability
- [ ] Accommodations are available for candidates with disabilities
- [ ] You can test the AI with accommodations in place

FAQ

Q: Do we need separate bias audits for each state?

A: No. One bias audit that meets the most stringent requirement (e.g., NYC) satisfies all states. But if you operate in multiple states, you should know what applies where.

Q: Is bias audit required federally?

A: Not legally required, but strongly recommended by EEOC. Do it anyway (liability reduction is worth it). If you're sued, documentation of audits is your best defense.

Q: What if a federal AI law passes?

A: Most likely will be similar to state laws (transparency, non-discrimination, documentation). You'll already be compliant if you follow this roadmap. Federal law will likely set a floor, not a ceiling, states can be more strict.

Q: How do we respond if media asks about our AI hiring practices?

A: Have a statement prepared. "We use AI to help screen applications. We audit for bias quarterly. All hiring decisions are reviewed by people. We have an appeal process for candidates who disagree." Keep it simple, factual, and proactive.

Q: Do we need consent from candidates to use AI?

A: Depends on state. Most states: no. NYC/Colorado: transparency required, but not explicit consent. But disclosure is always smart. It builds trust.

Q: What if EEOC opens an investigation into our AI practices?

A: Cooperate fully. Provide all requested documentation. If you audited for bias, have documented the results, and took action when issues were found, you're in a much stronger position. Have counsel advise you. Don't admit wrongdoing, but be transparent.

What's Next

You've navigated current US laws. But regulations are moving fast. New laws are coming. You need to prepare for regulations that haven't been written yet. Next lesson: Preparing for Emerging Regulations.

Your current compliance keeps you safe today. Your regulatory resilience keeps you safe tomorrow.