How Do Enterprises Govern AI in Hiring?
Summary
Enterprises govern AI in hiring through a seven-component framework: a written AI use policy, regulatory compliance mapping, vendor due diligence, bias auditing, candidate transparency, audit trails, and ongoing monitoring. Regulatory developments in the EU, New York City, and several U.S. states have made AI hiring governance an active operational requirement rather than a voluntary best practice. No single function owns this framework alone; HR, legal, and IT share responsibility across all seven components. This piece defines each component, maps ownership, and explains how Phenom X+ supports governance at the platform level.
In This Article:
How Do Enterprises Govern AI in Hiring?
AI hiring governance moved from internal preference to a legal requirement within an eighteen-month window. The EU AI Act, NYC Local Law 144, and new state statutes are already in force in jurisdictions where most enterprises hire. The seven-component framework below is what meeting that requirement looks like in practice.
A written AI use policy defining what AI may do autonomously at each hiring stage versus what requires human approval.
Regulatory compliance mapping that identifies which laws apply by jurisdiction, and confirms process controls and vendor documentation supporting that compliance.
Vendor governance, meaning procurement due diligence on a vendor's model transparency, bias testing, and security certifications.
Bias auditing, meaning statistical testing of AI scoring outputs for demographic disparities.
Candidate transparency, meaning disclosure of AI use where legally required and a working opt-out or human-review pathway.
Audit trails that log every AI action taken on a candidate record.
Ongoing monitoring, meaning scheduled reviews of model performance to catch accuracy decay or emergent bias.
No single function inside an enterprise can build all seven components of AI hiring governance alone. Enterprises hiring in the EU, New York City, Illinois, or under federal Title VII already face enforceable obligations across several of these components, regardless of whether a formal internal AI governance program exists yet.
The Regulatory Landscape: What Laws Apply to AI in Hiring?
Compliance for AI in hiring starts with a jurisdiction map. This requires a complete understanding of where and how the AI will operate. This section covers four regulatory statutes actively affecting enterprises as of mid-2026. Since AI regulations are rapidly evolving, the summaries below should be verified with qualified legal counsel before you use them to inform a specific compliance decision.
Framework | Jurisdiction | Core Requirement | Key Date |
EU AI Act | European Union | Human oversight, testing, and registration for high-risk hiring AI | High-risk deadline deferred to December 2, 2027 |
NYC Local Law 144 | New York City | Independent annual bias audit, candidate notice, alternative selection process | Enforceable since July 5, 2023 |
Title VII / UGESP | United States (federal) | Adverse impact standard (four-fifths rule) applies to AI-assisted hiring | EEOC guidance removed January 27, 2025; underlying law unchanged |
GDPR Article 22 / CPPA ADMT | EU / California | Meaningful human review of automated hiring decisions | ADMT notice and opt-out rights effective January 1, 2027 |
EU AI Act Hiring Obligations: High-Risk AI in Employment
The EU AI Act classifies AI systems used in recruitment, candidate selection, worker management, and decisions on promotion or termination as EU AI Act high-risk AI. That classification is the center of EU AI Act hiring obligations and requires human oversight, transparency to affected individuals, pre-deployment accuracy and robustness testing, registration in the EU AI Act database, and post-market monitoring. This scope has not changed.
What has changed is the timeline. High-risk obligations were originally scheduled to take effect on August 2, 2026. In November 2025, the European Commission proposed deferring that deadline as part of a broader "Digital Omnibus" simplification package. The European Parliament endorsed the revision on June 16, 2026, and the Council of the EU gave final approval on June 29, 2026, pushing the high-risk compliance deadline to December 2, 2027.
The risk for enterprises is treating this deferral as a reason to deprioritize EU AI governance work. While the deadline moved, the EU AI Act high-risk AI classification of hiring tools didn’t. The underlying obligations like human oversight, testing, and registration still have to be built before the new deadline arrives. Enterprises hiring in Illinois or New York City face nearer-term obligations regardless of what happens elsewhere. Confirm current EU AI Act hiring compliance dates and obligations with EU law counsel before relying on any specific timeline, including the one just discussed.
NYC Local Law 144: Automated Employment Decision Tools
NYC Local Law 144 has been enforceable since July 5, 2023. It requires employers and employment agencies using automated employment decision tools (AEDTs) for New York City hiring or promotion decisions to commission an independent annual bias audit, publish a summary of the results, notify candidates that an AEDT is in use, and provide an alternative selection process upon request. An AEDT is any computational process derived from machine learning, statistical modeling, or data analytics that substantially assists or replaces discretionary decision-making in hiring.
A December 2025 audit by the New York State Comptroller found the city's enforcement of NYC Local Law 144 to be inconsistent. Complaint intake was mishandled, and in test calls placed to the city's 311 hotline about AEDT concerns, 75 percent were never correctly routed to the enforcing agency. Some enterprises have read that finding as evidence that the law carries limited practical risk, and his stance frankly misreads exposure. Weak regulatory enforcement does not close off employee or candidate litigation under the law's private mechanisms, and it does not touch the separate exposure an enterprise carries under Title VII if the underlying tool produces discriminatory outcomes. A law with spotty government enforcement and functioning private legal exposure is, if anything, a harder compliance posture to defend. No regulator feedback loop tells the enterprise where its gaps are before a claim surfaces. Confirm whether a specific tool meets the AEDT definition, and confirm current audit and notice obligations with qualified US employment counsel.
EEOC AI Hiring Guidance and Title VII: A Federal Baseline With Less Federal Guidance
Between 2021 and 2024, the U.S. Equal Employment Opportunity Commission (EEOC) published technical guidance interpreting how Title VII applies to employer use of AI in hiring, including adverse impact analysis for algorithmic tools. On January 27, 2025, this guidance was removed with no clear indicator of its return.
This is a meaningful change in tone at the federal level, but it’s also one that could change again with a new administration. Regardless, this update doesn’t negate the underlying law that’s in place. Title VII of the Civil Rights Act still prohibits both disparate treatment and disparate impact, and it applies to AI-assisted selection procedures exactly as it applies to any other hiring method. The Uniform Guidelines on Employee Selection Procedures (UGESP) is a joint regulation from the EEOC, the U.S. Department of Labor (DOL), the Department of Justice (DOJ), and the Office of Personnel Management (OPM), codified at 29 C.F.R. Part 1607 since 1978. It remains in force and still supplies the enforceable standard for adverse impact AI recruiting claims, including the four-fifths rule discussed below. What enterprises lost is a document that translated that standard into AI-specific language. What they didn’t lose is the liability.
Several states have moved to fill part of that gap directly. Illinois amended its Human Rights Act (HB 3773, effective January 1, 2026) to require notice whenever AI is used in an employment decision and to bar AI's use of proxies, such as zip code, for protected characteristics. Colorado's AI Act, effective January 1, 2027, will require pre-use notice, an adverse-action process, and annual impact assessments for AI systems that materially influence consequential employment decisions. Enterprises hiring across multiple states are now managing a patchwork of state-specific notice and audit obligations layered on top of federal Title VII exposure. Confirm current federal and state enforcement posture with employment counsel, since agency guidance in this area has changed materially in the past eighteen months, and state activity is still expanding.
GDPR and the CCPA/CPRA: Automated Decision-Making and Data Privacy
GDPR Article 22 addresses GDPR automated hiring decisions directly. It gives EU individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. In hiring, this is triggered whenever an AI tool makes or substantially influences a decision about a candidate without meaningful human review. Enterprises already building EU AI Act hiring compliance processes should treat GDPR Article 22 as a parallel obligation, not a substitute. An enterprise needs either a human who meaningfully reviews AI output before a consequential decision, or a working process for candidates to request that review after the fact.
California's framework has moved well past the general CCPA data-access language most compliance teams are used to citing. The California Privacy Protection Agency finalized detailed regulations on automated decision-making technology (ADMT) on July 24, 2025. "Significant decisions" under the rule explicitly include hiring, compensation, promotion, and termination, and ADMT is defined broadly enough to cover resume-screening, interview-scoring, and candidate-ranking tools. Risk-assessment obligations took effect January 1, 2026. The notice, opt-out, and access requirements for ADMT used in significant decisions take effect January 1, 2027.
The regulation includes a specific exemption. An employer can remove a tool from ADMT coverage entirely if a human decision-maker meets three conditions:
Knows how to interpret the tool's output.
Actually reviews that output alongside other relevant information.
Has real authority to change the outcome.
A rubber-stamp review does not qualify. The exemption is written to test whether human oversight is functional, not nominal. Confirm current GDPR and CPPA ADMT obligations with data privacy counsel in the relevant jurisdictions before finalizing a candidate transparency process.
The Seven Components of an Enterprise AI Hiring Governance Framework
The regulatory landscape we just covered is part of what the law requires. What follows is the operational build enterprises use as their AI hiring governance framework to satisfy it, regardless of jurisdiction. Legal and compliance teams can use this as a governance gap assessment to understand whether a documented answer exists for each component.
Component 1: AI Use Policy
An AI use policy is a written document that hiring teams, legal, and IT can all point to during a regulatory inquiry. It defines which AI tools are approved for hiring use, and what each tool may do autonomously versus requiring human review. It also defines which hiring stages always require a human decision, regardless of AI output. Finally, it states whether AI output is treated as informational or binding, and what happens when AI output and human judgment disagree.
A useful test for whether a policy is doing its job: can a compliance officer read it and correctly predict, for any given hiring stage, whether the AI acts alone or waits on a person? If the answer requires guessing, the document is a values statement, not a governance control. A workable policy typically draws the line this way: sourcing, initial resume ranking, and scheduling logistics can run without a person in the loop. Advancing a candidate past a screening stage, rejecting a candidate, and extending an offer each route through a defined human checkpoint every time. Every other component in this framework exists to implement or enforce this policy. Without it, bias audits and audit trails have nothing to measure compliance against.
Component 2: Regulatory Compliance Mapping
Regulatory compliance mapping identifies which AI hiring regulations apply based on hiring jurisdiction, vendor tool classification (does it meet the AEDT definition under NYC Local Law 144, or the high-risk threshold under the EU AI Act), and candidate data flows. The output is a matrix: regulation, jurisdiction, AI tool, and current compliance status. This should be reviewed at least annually and updated whenever the enterprise enters a new hiring market or deploys a new tool.
A working matrix looks like this:
Regulation | Jurisdiction | AI Tool | Compliance Status |
EU AI Act | Germany | AI resume-screening tool | In scope for the December 2027 high-risk deadline; human-oversight documentation in progress |
NYC Local Law 144 | New York City | Same tool | In scope now; annual bias audit and candidate notice both required immediately |
Illinois HB 3773 | Illinois | Same tool | Notice requirement in force since January 2026 |
The value of the matrix is that it forces a single tool's compliance status to be assessed jurisdiction by jurisdiction rather than treated as a single yes-or-no answer, since a tool can be fully compliant in one jurisdiction and out of compliance in another. Build and maintain this matrix with employment and data privacy counsel qualified in the relevant jurisdictions. Vendor compliance claims are an input to the matrix, not a substitute for it.
Component 3: Vendor Governance
Vendor governance is AI vendor due diligence applied before procurement and on a recurring basis after. It should cover:
Model transparency: what inputs actually drive scoring and ranking.
Bias testing methodology and results: which demographic dimensions are tested, how often, and the actual pass/fail rates, not just a summary certificate.
Data processing agreements and sub-processor disclosures.
Security certifications such as SOC 2 Type II and ISO 27001.
Jurisdiction-specific compliance documentation, including EU AI Act high-risk registration status and availability of NYC bias audit results.
A stated incident response commitment if a bias or security issue surfaces.
The distinction that matters most in AI vendor due diligence is between a vendor handing over a bias-testing summary and a vendor handing over the underlying pass/fail rates by demographic group. The first tells a procurement team the vendor did something. The second is what lets legal actually assess exposure. Vendor governance is not a one-time procurement gate. Annual re-evaluation against updated regulatory requirements, particularly as state laws like Illinois's and Colorado's come into force, is standard practice for enterprises with mature programs.
Component 4: Bias Auditing
An AI hiring bias audit is a statistical test of whether an AI hiring tool's outputs produce disparate impact within or across demographic groups. An enforceable statistical standard for adverse impact AI recruiting claims, drawn from UGESP and still relevant to EEOC AI hiring enforcement even without an active guidance document, is the four-fifths rule. The rule states that if the selection rate for one group falls below 80 percent of the selection rate for the highest-selecting group, the result is flagged as potential adverse impact. A concrete example: an AI screening tool advances 50 percent of male applicants to interview and 30 percent of female applicants. The ratio is 30 divided by 50, or 60 percent, which sits below the 80 percent threshold and warrants further investigation regardless of whether the disparity was intentional.
Bias auditing operates at two levels. Vendor-conducted testing is the vendor's own assessment of its model's outputs and should be available for the enterprise to review directly, not just summarized. Independent bias auditing is a third-party assessment of the tool's outputs in the enterprise's specific hiring context, and it is what NYC Local Law 144 requires for covered tools used on New York City roles. Vendor test results describe how the tool performs in general. They do not describe how it performs against a specific enterprise's actual applicant pool. That is why regulators require an independent one.
Component 5: Candidate Transparency
Candidate transparency governs what is disclosed to candidates about AI use, how the disclosure is delivered (in the application flow, in a privacy notice, or as a standalone notification), what opt-out or human-review pathway exists, and how a request for human review is actually handled operationally once it arrives. NYC Local Law 144 requires specific pre-use notification. The right to contest GDPR automated hiring decisions under Article 22 requires that candidates be told about automated decision-making and given a route to request human review. California's ADMT rule requires pre-use notice and an opt-out mechanism for tools used in significant employment decisions.
The operational gap enterprises most often hit is not the disclosure itself, which is usually easy to add to an application flow, but the review pathway behind it. If a rejected candidate requests human review under GDPR or the ADMT rule, there needs to be a defined recipient, such as a specific queue, alias, or portal, a committed response window, and a person with actual authority to reverse the outcome. A disclosure that promises human review with no operational process behind it is a compliance gap dressed as a compliance control.
Component 6: Audit Trails
An AI hiring audit trail is a complete, tamper-resistant log of every AI action taken on a candidate record: what the AI did, when, on what inputs, and with what output. Audit trails serve three distinct purposes. In legal defense, they are the evidence that an AI tool was applied consistently and with human oversight if a discrimination claim is filed. In regulatory compliance, they satisfy the post-market monitoring documentation the EU AI Act requires and the recordkeeping NYC Local Law 144 implies. In operational quality control, they let a team trace an anomalous AI output back to the specific inputs that produced it.
The legal-defense function matters more than it appears to at deployment, because Title VII claims are often litigated years after the hiring decision in question. An enterprise defending a 2026 hiring decision in a 2029 lawsuit cannot reconstruct what the AI evaluated and why unless that record was captured and retained at the time. Enterprise AI hiring platforms should treat audit trail access as a standard feature available on request, not an optional add-on module.
Component 7: Ongoing Monitoring
AI models degrade as the world changes, and as the data they were built on ages. In hiring specifically, this shows up two ways. A sourcing model tuned to 2023 hiring patterns produces weaker matches against 2026 role requirements, and a screening model trained on historical hiring outcomes can quietly encode the biases embedded in those outcomes as its optimization target.
An illustration of the second failure mode is Amazon's internal resume-screening tool, built and then scrapped in 2018 after engineers discovered it had learned to downgrade resumes containing terms like "women's," as in "women's chess club captain," because it had been trained on a decade of resumes submitted to a male-dominated engineering workforce. The tool did not encode bias because anyone instructed it to. It encoded bias because the historical data it learned from already contained it, and nothing in the model's design flagged that until testing caught it before deployment.
Ongoing monitoring exists precisely because pre-deployment testing is a single snapshot, and a model that passes a bias audit at launch can still drift toward disparate outcomes as it continues to learn from new data or as the applicant pool it scores changes. A working monitoring program defines:
Review frequency.
The specific metrics used to detect degradation, such as match quality, screening accuracy, and demographic distribution of outputs.
A trigger threshold for retesting.
A named owner for the review cycle.
Vendors should commit to advance notice before any model update that could change output behavior, since a monitoring program built against last quarter's model version cannot catch a problem introduced by this quarter's model.
Who Owns AI Hiring Governance in the Enterprise?
AI hiring governance spans three functions that rarely share a reporting line: HR and talent acquisition (operational deployment), legal and compliance (regulatory risk), and IT and security (vendor and data governance). None of the seven components we listed can be fully owned by just one of these functions. This is why the most common governance failure is not a missing component, but a component with no clear owner.
CHRO and Head of Talent Acquisition: Policy and Operational Governance
The CHRO and TA leadership own the AI use policy itself, the human oversight model that defines which decisions require approval, the recruiter training that makes the policy operational rather than theoretical, and the candidate transparency process end-to-end. Their accountability is implementation. A policy that exists on paper but recruiters don't follow in practice is a governance failure that sits with this function, not with legal.
Legal and Compliance: Regulatory Mapping and Vendor Due Diligence
Legal and compliance owns the regulatory compliance matrix, vendor governance due diligence, the specific content and format of candidate disclosures, and the bias audit program, including commissioning independent audits where required. This function supplies the regulatory interpretation that TA and IT are not positioned to do on their own. The jurisdiction-by-jurisdiction picture continues to shift, as it has in the EU, New York, Illinois, and California within the same eighteen-month period.
IT, InfoSec, and Procurement: Vendor Security and Data Governance
IT, InfoSec, and procurement own vendor security certification review, data processing agreement execution, data residency and subprocessor review, the technical infrastructure that stores and makes audit trails accessible, and the recurring vendor re-evaluation cycle. Without this function, an enterprise can have a well-written policy and a legally sound compliance matrix and still fail an audit because the underlying logs were never actually retained in a queryable form.
Enterprises with functioning governance programs typically run a standing cross-functional review, often quarterly, where these three functions reconcile the compliance matrix against new regulatory developments, new AI features added by existing vendors, and any bias audit findings from the prior cycle. A governance framework that exists only as three separate documents held by three separate functions is not a governance framework. It is three risk assessments that happen not to talk to each other.
How Phenom Supports Enterprise AI Hiring Governance
Phenom X+ generative AI supports the seven principles of governance with:
Configurable Guardrails: Operationalizing the AI Use Policy
Phenom X+ guardrails let customers configure exactly what each AI agent does autonomously and what requires human approval at the level of individual hiring stages. The AI use policy defines the boundary. The guardrails are the mechanism that enforces it inside Phenom, so the boundary is not dependent on individual recruiters remembering to apply it manually. TA administrators set the parameters. The agents operate inside them."
Human Oversight by Design: AI Informs, Humans Decide
Phenom X+ is built on the principle that final hiring choices remain human decisions. Autonomous agents surface, rank, schedule, and engage candidates, but advancement, rejection, and offer decisions require human action within recruiter-defined parameters. This structure is designed to support EU AI Act hiring human oversight requirements for high-risk AI and the meaningful human review obligation under GDPR Article 22 and California's ADMT human-involvement exemption.
Audit Trails and Compliance Architecture
Phenom's AppTrail capability delivers AI hiring audit trail coverage as a standard enterprise feature across every Phenom platform an organization runs. It covers two things at once: a log of what TA and TM users did and when, and a log of why an AI agent recommended a specific candidate, including which factors and signals drove that recommendation. That combination is what turns a compliance request or audit from a scramble into a lookup. Instead of reconstructing what happened after the fact, enterprise customers can pull audit-ready reports directly from AppTrail and use them as their own defense. Phenom's compliance architecture is designed to support GDPR and CCPA data privacy obligations. Confirm current log retention periods and AppTrail specifications directly with Phenom during procurement, since retention requirements can vary by industry.
Responsible AI Commitment: Transparency and Bias Governance
Phenom develops its Applied AI platform around responsible AI talent acquisition principles covering transparency, fairness, and accountability, and enterprise customers receive documentation of Phenom's governance approach, model input transparency, and bias testing procedures as part of procurement. Phenom's integrations with existing ATS and HRIS infrastructure are also a governance point, not just a convenience feature. Because agent outputs write back into the system of record, the audit trail for a candidate's hiring journey extends across the full HR technology stack rather than stopping at Phenom.
Missed AI Hiring Governance Gaps
These are the AI hiring governance gaps that are missed the most often in AI procurement reviews.
Gap 1: Assuming Vendor Compliance Equals Enterprise Compliance
This is the most common gap. An enterprise procures an AI hiring tool, treats a SOC 2 certificate and a signed data processing agreement as the whole of its AI vendor due diligence, and then erroneously considers its own compliance obligation met. Sadly, it’s not. Under Title VII, the employer carries liability for discriminatory AI outcomes regardless of the vendor's compliance posture. Under NYC Local Law 144, the employer, not the vendor, must commission and publish the independent bias audit. The vendor's internal testing doesn’t satisfy that requirement. Under GDPR Article 22 and California's ADMT rule, the employer must ensure meaningful human review is actually functioning. A vendor cannot implement that on the employer's behalf, because the human reviewer sits inside the employer's own hiring workflow. Vendor documentation reduces risk. It doesn’t transfer the underlying obligation.
Gap 2: No Written AI Use Policy Before Deployment
An enterprise that deploys an AI hiring tool without an AI use policy that a hiring team can point to has no documented basis for its human oversight model, no defined limit on what the AI is permitted to do, and nothing to produce if a regulator inquiry or litigation discovery request asks for one. The policy does not need to be long, but it needs to exist before the tool is used for a live candidate.
Gap 3: Governing Deployment, but Not Use
Many enterprises run thorough due diligence at procurement and initial deployment, then have no defined process for governing subsequent vendor model updates, new AI features added to an existing tool, or changes the enterprise makes to the tool. Governance is not a procurement-stage exercise; it requires a standing review cycle for the life of the tool. Vendor contracts should require notice of material model changes along with updated compliance documentation.
Gap 4: Governing AI Only in Talent Acquisition
Enterprises often govern sourcing and screening tools carefully, because they are visibly labeled as AI, while missing AI features embedded in adjacent systems: job description writing tools that shape which candidates apply, reference-check tools that use AI to synthesize responses, scoring features inside video interview platforms, and AI features in onboarding tools that influence new-hire success assessments. A complete governance inventory has to cover every AI capability touching any stage of the hiring and onboarding process, not just the tools an enterprise thinks of as "the AI recruiting platform."
AI Hiring Governance Is an Operational Requirement
The regulatory picture that shaped this framework changed meaningfully in the last eighteen months, and not in a direction of exposure reduction. The EU pushed its high-risk deadline back, but did not touch the underlying classification. The EEOC took its AI guidance offline, but Title VII and its four-fifths rule stay enforceable. New York's own auditor found its bias-audit law weakly enforced, while the law's penalties and private legal exposure remained on the books. Each of these developments removed a piece of official guidance that an enterprise could previously point to, without removing a single underlying obligation. The net effect is that enterprises now carry more of the documentation burden themselves, with less regulatory hand-holding to rely on.
The enterprises ahead of this shift have done three things concretely:
Written an AI use policy before deployment rather than after a gap surfaced
Built a standing cross-functional governance team spanning HR, legal, and IT
Selected AI hiring vendors that provide the transparency, audit trail access, and compliance documentation the governance framework actually requires
Phenom X+ is built to meet the stringent clauses for AI governance in enterprises with configurable guardrails, human oversight by design, and compliance architecture built into the platform from the start.
See howPhenom Applied AI builds governance controls into the platform.
Frequently Asked Questions
Enterprises govern AI in hiring through a seven-component framework: a written AI use policy defining what AI can do autonomously versus what requires human approval; regulatory compliance mapping by jurisdiction (EU AI Act, NYC Local Law 144, Title VII, state laws, GDPR, CCPA/ADMT); vendor governance due diligence; independent bias auditing; candidate transparency and disclosure; complete audit trails for AI actions on candidate records; and ongoing monitoring for model performance and drift. Cross-functional ownership across HR, legal, and IT is required; no single function can implement all seven components alone.
Yes. The EU AI Act classifies AI systems used in employment, worker management, and access to self-employment as EU AI Act high-risk AI systems. High-risk hiring tools must meet requirements for human oversight, transparency, accuracy testing, registration in the EU AI Act database, and post-market monitoring. In 2026, EU lawmakers deferred the high-risk compliance deadline from August 2026 to December 2027, but the underlying classification and EU AI Act hiring obligations are unchanged. Verify current compliance dates with EU law counsel.
NYC Local Law 144 requires employers using automated employment decision tools (AEDTs) for New York City hiring or promotion decisions to commission an independent annual bias audit, publish the results, notify candidates that an AEDT is in use, and offer an alternative selection process on request. A December 2025 state audit found the city's enforcement inconsistent, but the law's requirements and its private legal exposure remain fully in effect regardless of enforcement gaps. Assess compliance with qualified US employment counsel.
The employer, under Title VII, regardless of whether the AI was built and operated by a third-party vendor, has liability that is not transferred by contract. The EEOC removed its EEOC AI hiring guidance documents from its website in January 2025, but Title VII and the 1978 Uniform Guidelines on Employee Selection Procedures remain fully in force and unaffected by that removal. Enterprises cannot rely on vendor compliance claims alone and need their own bias auditing, human oversight, and audit trails. Consult qualified US employment counsel on specific exposure.
An AI hiring bias audit is a statistical analysis of an AI hiring tool's outputs to determine whether it selects or advances one demographic group at a materially lower rate than others, the core question in any adverse impact AI recruiting assessment. An enforceable standard, from the Uniform Guidelines on Employee Selection Procedures, is the four-fifths rule: a selection rate below 80 percent of the highest-selecting group's rate flags potential adverse impact. NYC Local Law 144 requires independent annual bias audits for covered tools used in New York City hiring; vendor-conducted testing alone does not satisfy that requirement.
GDPR Article 22 gives EU individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, covering GDPR automated hiring decisions, such as an AI tool rejecting a candidate with no human involvement. It applies whenever an AI tool makes or substantially influences a hiring decision without meaningful human review. Enterprises hiring in the EU need a human who meaningfully reviews consequential AI output, or a working process for candidates to request that review afterward. Confirm application to a specific workflow with EU data privacy counsel.
An AI use policy hiring teams, legal, and IT can all reference should define which AI tools are approved for hiring, what each may do autonomously versus with human review, which hiring stages always require a human decision, whether AI output is treated as informational or binding, and what happens when AI output and human judgment disagree. It is the governance foundation on which every other component, from bias audits to audit trails, is built, and it should exist in writing before a tool is used on a live candidate.
While this list is not exhaustive, two prominent examples are Illinois and Colorado. Illinois amended its Human Rights Act (HB 3773, effective January 1, 2026) to require notice when AI is used in an employment decision and to bar proxies like zip code for protected characteristics. Colorado's AI Act, effective January 1, 2027, requires pre-use notice, an adverse-action process, and annual impact assessments for AI systems that materially influence employment decisions. California addresses this territory through the CPPA's automated decision-making technology (ADMT) rules rather than a dedicated AI-hiring statute. Expect this state-level patchwork to keep expanding independent of federal or EU timelines.
Fariya Banu is a content marketing writer at Phenom who loves decoding buyer psychology and crafting stories that convert. With engineering and marketing expertise, she brings analytical thinking to creative storytelling. When not writing, she's snorkelling, cooking, or diving into any adventure that sparks curiosity.
Get the latest talent experience insights delivered to your inbox.
Sign up to the Phenom email list for weekly updates!










