AI hiring is now regulated. Here's what enterprise TA teams must do in 2026.
The era of deploying an AI screening tool and hoping for the best is over. Two of the world's largest markets now regulate automated hiring directly — and the common thread running through both is a demand you can't retrofit: show your work.
For a decade, "AI in hiring" was a procurement decision with no regulator in the room. That is no longer true. In New York City, a bias-audit law has been actively enforced since 2023. In the European Union, the AI Act places recruitment squarely in its highest-risk tier. If your organization interviews or screens candidates with software, these rules now shape what you're allowed to buy and how you're allowed to run it.
New York City: the audit is already mandatory
NYC's Local Law 144 has been enforced by the Department of Consumer and Worker Protection since 5 July 2023. It prohibits employers from using an "automated employment decision tool" unless three conditions are met: the tool has passed an independent bias audit within the prior year, a summary of that audit is posted publicly on the employer's website, and candidates receive advance notice plus the right to request an alternative process.
The bias audit isn't a formality. It must test the tool for disparate impact across protected categories — sex, race, and ethnicity — and be conducted by an independent third party, renewed annually. Penalties run from $500 to $1,500 per violation, per day. A 2026 review of the law's enforcement signaled that regulators are sharpening, not softening, their approach.
The EU AI Act: high-risk, delayed but not defused
Under the EU AI Act, AI used in recruitment, candidate evaluation, selection, and targeted job advertising is classified as high-risk. That triggers a heavy set of obligations: risk assessments, technical documentation, bias testing, human oversight, transparency disclosures, and continuous monitoring — with fines that can reach €15 million or 3% of global annual turnover.
There has been a reprieve on timing. In mid-2026 the EU approved the "AI Omnibus," which pushed the compliance deadline for high-risk employment obligations from 2 August 2026 to 2 December 2027. But — and this matters — the delay is not a cancellation, and it is not total. The transparency duties, the AI-literacy requirement, and the emotion-recognition ban still take effect on the original August 2026 date. Deployers who assume "we have until 2027" are misreading the calendar.
The through-line
Both regimes converge on one requirement: a decision an AI system influenced must be explainable, auditable, and contestable by a human. A tool that returns an opaque score cannot satisfy either.
What this means for your interview stack
Strip away the jurisdictional detail and a practical checklist emerges for any enterprise buying or running AI hiring tools in 2026:
Demand explainability by default. If your vendor cannot produce written reasoning for every score — traceable to specific candidate responses — you cannot produce the audit trail these laws assume. Opaque scores are a compliance liability, not just a UX shortcoming.
Keep a human in the loop, on the record. Both frameworks lean heavily on human oversight. A system that auto-rejects candidates is far harder to defend than one that evaluates, recommends, and leaves the decision — and the documented authority to overrule — with your team.
Insist on bias testing you can show. NYC requires it explicitly; the EU requires it as part of high-risk conformity. Ask vendors how scoring is monitored for disparate impact, and whether they'll support your independent audit.
Get transparency and consent right now. The EU's transparency duties land in August 2026 regardless of the Omnibus delay. Candidates must know when they're interacting with AI. Build that disclosure into the flow, not the fine print.
The strategic read
It's tempting to treat all of this as cost. The better framing: regulation is quietly sorting the market. Tools built around explainability, human authority, and auditability were already the better hiring instruments — the rules just made those properties non-negotiable. The vendors that treated a defensible score as the product, rather than a feature to bolt on later, are the ones that will still be procurable in 2027.
Which is the uncomfortable question for most TA leaders reading this: if a regulator, a rejected candidate, or your own audit committee asked why a specific candidate was screened out last quarter — could you answer, with evidence, today?
NYC DCWP — Automated Employment Decision Tools · nyc.gov/site/dca
Gibson Dunn — EU AI Act Omnibus Agreement, Postponed High-Risk Deadlines
Ogletree — EU Nears Approval of Agreement to Delay AI Use in Employment Decisions
DLA Piper — Critical audit of NYC's AI hiring law signals increased risk for employers
This article is general information, not legal advice. Consult counsel for your jurisdictions.