Skip to main content
PromptQuorum
Home/Power Local LLM/US State AI Employment Laws: What Actually Applies to Your Hiring Process
RAG & Document Chat

US State AI Employment Laws: What Actually Applies to Your Hiring Process

·15 min read·By Hans Kuepper · Founder of PromptQuorum, multi-model AI dispatch tool · PromptQuorum

At least five US states (Colorado, California, Illinois, Texas, plus New York City) already impose AI-specific employment obligations as of September 2026, each with a different scope and effective date — self-hosting the AI model does not exempt an employer from any of them. A December 2025 federal executive order signals a future preemption push but does not itself override state law today.

A recruiter or HR technology lead who just got asked "are we allowed to use AI for hiring?" needs an answer scoped to specific states and specific use cases, not a general sense that "AI regulation is coming." As of September 2026, at least five states and one major city already have AI-employment-specific obligations in force or newly effective, each with its own scope, effective date, and required artifact. This guide maps them, flags what a federal executive order does and does not change, and corrects the most common and costly misconception: that self-hosting or running AI on your own infrastructure exempts you from any of this.

Key Takeaways

  • At least five states (Colorado, California, Illinois, Texas) plus New York City already impose AI-employment-specific obligations, each with different scope and effective dates.
  • Illinois HB 3773 and Texas TRAIGA are already in force (January 1, 2026); Colorado is delayed to January 1, 2027 after two rounds of amendment; California's fuller ADMT rule set phases in through January 1, 2027.
  • A December 2025 federal executive order (EO 14365) signals a preemption push but cannot itself override state law — that requires Congress or the courts.
  • Self-hosting or running AI on your own infrastructure does not exempt an employer from discrimination, notice, or audit obligations tied to a decision about a real person.
  • EU employers may be more constrained today than US employers in many states, despite the EU AI Act's high-risk deadline being deferred — GDPR Article 22 and AI Act Article 4 already apply with no delay.
  • Every state-law date and scope claim in this article should be reconfirmed with counsel before you rely on it — this area moves fast enough that a February 2026 brief was already stale by September.

The Landscape in Plain Terms

"AI employment law" is not one law. It is a patchwork of state and city statutes, each triggered by different AI use cases — hiring and candidate screening, promotion decisions, performance monitoring, and scheduling or shift assignment — and each applying to employers above different size thresholds that vary by state.

No single company-size number applies everywhere. Illinois HB 3773 applies to any employer with at least one employee in the state; NYC Local Law 144 applies to any employer using an automated employment decision tool (AEDT) for a covered decision, regardless of headcount; Colorado's law and California's ADMT rules are scoped by the type of decision more than by a fixed employee count. Check the state-by-state section below rather than assuming a single "50+ employees" or "100+ employees" threshold covers you everywhere.

The use cases these laws cover typically include résumé screening and candidate ranking, interview scoring or analysis, promotion recommendations, AI-assisted performance or sentiment monitoring, and in some scopes, automated scheduling that affects hours or shift assignment. A tool that only drafts job postings or answers internal HR policy questions is a materially different risk profile than one that scores or ranks real candidates or employees — the laws below are written around decisions that affect a specific person, not general-purpose AI assistance.

📍 In One Sentence

US AI employment law is a state-by-state and city-by-city patchwork — at least five jurisdictions have AI-specific hiring/employment obligations as of September 2026, each with its own scope, size threshold, and effective date.

💬 In Plain Terms

There is no single "AI hiring law" for the whole US. Whether you have any obligation depends on which states you actually employ people in and what the AI tool actually does — screening resumes and ranking candidates is regulated much more heavily than a tool that just drafts a job posting.

⚠️Warning: Not legal advice: this article is general orientation on state AI employment law, not a substitute for advice from a qualified employment attorney licensed in your state — confirm applicability to your specific hiring decisions before relying on it. The state-law information here reflects the law as of September 3, 2026; state AI employment law changes fast enough that some of the specifics below could already be out of date by the time you read this — verify current requirements before making a compliance decision.

State AI Employment Law Applicability Checker

Select the states where you employ people and the AI use cases you actually run to see which laws likely apply, their effective-date reference, and the artifact each one typically requires. This runs entirely in your browser — nothing is submitted anywhere, and this is not legal advice.

State AI Employment Law Applicability Checker

Select the states where you employ people and the AI use cases you actually use, then check the result. Nothing is sent anywhere — this runs entirely in your browser and is not legal advice.

Where do you employ people?

Which AI use cases apply?

State-by-State Detail

Each entry below covers what the law regulates, an effective-date reference, and an explicit note to verify current status before relying on it — treat the verify note as the actual point of each row, not boilerplate.

Colorado (SB 24-205, amended by SB 26-189)

What it covers:
AI systems that materially influence "consequential" employment decisions (hiring, promotion, discipline, termination, compensation). Requires notice, an adverse-action/human-review process, and 3+ years of records. The original bill's standalone impact-assessment and Attorney General reporting duties were removed by the May 2026 amendment.
Effective date reference:
Delayed to January 1, 2027 (originally June 30, 2026); this is the law's second delay/amendment cycle.
Verify current status:
Confirm no third amendment has moved the date again before finalizing a 2026/2027 rollout plan around this deadline.

California (Civil Rights Council FEHA ADMT rules)

What it covers:
Automated-decision-making technology used in employment — core rules (definitions, some disclosure) took effect first; risk assessments, pre-use notice, updated privacy-policy disclosures, vendor-contract terms, and opt-out/human-review rights phase in on a later date.
Effective date reference:
Core rules in force since October 1, 2025; fuller requirement set phases in by January 1, 2027.
Verify current status:
Confirm which specific requirements are live today versus still phasing in for your particular ADMT use case.

Illinois (HB 3773, Human Rights Act amendment)

What it covers:
Requires plain-language notice to employees/candidates when AI is used in recruitment, hiring, promotion, discipline, discharge, or other covered employment decisions, in languages the workforce commonly speaks. Applies to any employer with at least one Illinois employee or hiring in Illinois.
Effective date reference:
In force since January 1, 2026. Implementing regulations were proposed May 15, 2026, then temporarily withdrawn June 2, 2026 — the underlying notice duty is unaffected by that withdrawal.
Verify current status:
Check whether IDHR has re-issued implementing regulations since this was written; the statutory notice obligation applies regardless.

Texas (TRAIGA, Responsible AI Governance Act)

What it covers:
Primarily targets government AI use and prohibits AI deployed with intent to unlawfully discriminate. Unlike Colorado, Illinois, or California, it does not currently impose a broad private-employer notice or bias-audit regime.
Effective date reference:
In force since January 1, 2026.
Verify current status:
Confirm this narrower private-employer scope has not been expanded by subsequent rulemaking — TRAIGA is new and Texas' AI Council could recommend changes.

New York City (Local Law 144, AEDT)

What it covers:
Requires an annual independent bias audit of any automated employment decision tool (AEDT), public disclosure of a summary of audit results, and advance notice to candidates that an AEDT will be used.
Effective date reference:
Bias-audit and notice requirements enforceable since 2023; a December 2025 city audit found DCWP enforcement "ineffective," signaling a stricter enforcement phase ahead. A separate plain-language pre-decision notice requirement is referenced as taking effect October 1, 2027.
Verify current status:
Confirm whether that October 2027 notice-content provision is a city or state-level requirement before citing it, and expect enforcement to tighten given the audit findings.

Other states not detailed here

What it covers:
Several additional states have introduced or passed narrower AI-employment or general AI-transparency bills; scope varies widely and this article does not attempt to catalogue every one.
Effective date reference:
Varies by state — check your specific state's legislature site or a current legal tracker.
Verify current status:
If you employ in a state not listed above, do not assume no obligation applies — verify directly rather than relying on this list being exhaustive.

Federal Preemption: The Executive Order Wildcard

On December 11, 2025, the federal government signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence," directing agencies to work toward a uniform federal AI policy that would preempt state laws viewed as inconsistent with it. A "National Policy Framework for Artificial Intelligence" following from that order was published March 20, 2026, and it recommends that Congress preempt state laws seen as imposing "undue burdens" — but a recommendation to Congress is not itself a change in law.

The executive order does not, and legally cannot, override existing state law on its own. Only an act of Congress or a court ruling can actually preempt a state statute. Until either of those happens, Colorado, California, Illinois, Texas, and New York City's obligations remain enforceable exactly as described in the table above, and a company that stops complying based on the executive order alone is taking on real, current legal exposure for a preemption that has not actually happened yet.

The explicit operational guidance here: do not stop complying with any state AI employment law on the strength of an executive order alone. Treat the order as a signal worth monitoring — particularly if you operate in a state whose law might be challenged or modified by future federal legislation — not as a reason to pause your compliance work today.

💬 In Plain Terms

A federal executive order from December 2025 says the government wants one national AI policy instead of a state-by-state patchwork, and hints Congress should override state AI laws. It has not actually done that yet — an executive order cannot cancel a state law by itself, only Congress or a court can. Keep complying with your state's law until that actually changes.

What Compliance Requires Operationally

Across the states above, the operational requirements cluster into five recurring categories. State-specific detail lives in the table above; this section covers what each category generally involves.

  1. 1
    Candidate/employee notice.
    Why it matters: Nearly every state and city law above requires telling the affected person that AI is involved in a decision about them, in plain language and (in Illinois's case) in the languages the workforce commonly speaks. This is usually the first artifact to build and the easiest to get wrong by burying it in a long privacy policy nobody reads.
  2. 2
    Impact or risk assessment.
    Why it matters: Colorado's original scope and California's ADMT rules both call for documenting what the AI system does, what data it uses, and what risk of discriminatory outcome it carries — done once per tool and revisited when the tool or its training data changes materially.
  3. 3
    Human review of adverse decisions.
    Why it matters: A rejected candidate or a negative employment action driven by an AI system typically needs a path to human review, not just an automated notification. This is the control that most directly prevents an unreviewable algorithmic decision from becoming the sole basis for an adverse action.
  4. 4
    Record retention.
    Why it matters: Colorado specifies 3+ years; other jurisdictions imply similar retention through their audit or investigation processes. Retention needs to cover the AI output and the human-review outcome, not just the final employment decision.
  5. 5
    Independent bias audit (where required).
    Why it matters: NYC Local Law 144 requires an annual independent audit with public disclosure of a summary; this is the most operationally heavy requirement on this list and the one most commonly outsourced to a specialized audit vendor.

Critical Correction: Self-Hosting Does Not Exempt You

Running the AI model on your own infrastructure — self-hosted, on-premises, or air-gapped — does not remove any of the notice, discrimination, or audit obligations above. Every one of the laws in the table is triggered by the fact that an AI system materially influenced a decision about a real person, not by where the model's inference happens or which vendor built it.

This is worth stating plainly and early because it is the single most common and costly misconception HR technology teams bring into a local-LLM deployment decision. Self-hosting genuinely solves a different set of problems — it keeps candidate resumes and performance data off a third-party vendor's servers, and it removes a vendor as a data-sharing risk. It does not touch the legal trigger for notice, audit, or human review, because that trigger is "an AI system influenced a decision about a person," which is true regardless of deployment model.

A vendor-hosted AI hiring tool and a self-hosted open-weight model performing the same résumé-screening function carry the same state-law obligations. The deployment decision changes your data-privacy and vendor-risk posture; it does not change your employment-law posture.

📍 In One Sentence

Self-hosting an AI hiring or screening model does not exempt an employer from state notice, bias-audit, or human-review obligations — those obligations are triggered by the decision affecting a real person, not by where the model runs.

💬 In Plain Terms

Running your own AI on your own servers instead of using a vendor's cloud tool is a real privacy win, but it does not make Colorado's, Illinois's, or NYC's AI hiring rules go away. The law cares that AI touched a hiring decision — not whose computer the AI ran on.

What Local Deployment Does and Does Not Change

What it changes: a self-hosted deployment removes a third-party vendor from your data flow map for candidate and employee data, which is a genuine reduction in vendor-risk and cross-border data-transfer exposure — particularly relevant for a US company with EU employees, where GDPR's international-transfer rules add another layer on top of the employment-law obligations above.

What it does not change: the notice obligation to the candidate or employee, the requirement for a human-review path on adverse decisions, the record-retention duty, and (where applicable) the independent bias-audit requirement. None of those are vendor-dependent — they attach to the decision itself.

The practical sequencing most HR technology teams land on: treat local deployment as a data-governance and cost decision made independently from the compliance checklist above, then build the notice/audit/human-review artifacts the same way regardless of which deployment model you choose.

Jurisdiction Notes

Everything above covers the US state-level patchwork. For a US-headquartered company with EU employees, the EU angle applies in parallel and, in several respects, is currently stricter than any single US state: employment-related AI (candidate screening, performance monitoring, staff scheduling) is classified as "high-risk" under Annex III of the EU AI Act, and while that specific high-risk obligation was deferred from August 2, 2026 to December 2, 2027 by the "Digital Omnibus" package adopted in June 2026, three older regimes already apply in full without delay — GDPR Article 22 (automated decision-making, in force since 2018), AI Act Article 4 (AI literacy, in force since February 2, 2025), and works-council co-determination in Germany, Austria, and the Netherlands for systems that monitor performance or behavior.

This section is general orientation, not legal advice. Confirm applicability with employment counsel for your specific states, industries, and use cases before finalizing a compliance plan.

Frequently Asked Questions

Is AI hiring legal in the United States?

Yes, no US state currently bans AI-assisted hiring outright. Instead, states impose specific obligations — notice, bias audits, human-review processes, record retention — on employers who use AI for hiring or other employment decisions. Whether a specific obligation applies depends on which states you employ in and which AI use case you run; check the applicability checker above.

Which states currently have AI-specific employment laws?

As of September 2026: Colorado (delayed to January 1, 2027), California (ADMT rules, phasing in through January 1, 2027), Illinois (HB 3773, in force since January 1, 2026), and Texas (TRAIGA, in force since January 1, 2026, narrower private-employer scope), plus New York City (Local Law 144, in force since 2023). Several other states have introduced narrower bills not detailed in this article.

Does the federal executive order on AI override these state laws?

No. Executive Order 14365 (December 2025) signals a federal preemption push and directs agencies to work toward a uniform national AI policy, but an executive order cannot itself override state law — only an act of Congress or a court ruling can do that. Until either happens, the state laws above remain fully enforceable, and stopping compliance based on the executive order alone creates real legal exposure.

Does self-hosting our AI model exempt us from these employment laws?

No. Every law covered here is triggered by the fact that an AI system materially influenced a decision about a real person, not by where the model runs or who built it. Self-hosting reduces vendor-risk and data-privacy exposure, but it does not remove the notice, human-review, audit, or record-retention obligations tied to the hiring or employment decision itself.

What size company has to comply with these laws?

It varies by state — there is no single threshold. Illinois HB 3773 applies to any employer with at least one Illinois employee; NYC Local Law 144 applies to any employer using a covered AEDT regardless of headcount; Colorado and California scope by decision type more than by a fixed employee count. Check the state-by-state table above rather than assuming a single size cutoff applies everywhere.

What is NYC Local Law 144 and does it still matter given the enforcement audit?

Local Law 144 requires an annual independent bias audit of any automated employment decision tool, public disclosure of a results summary, and advance candidate notice. A December 2025 city audit found DCWP's enforcement "ineffective," but that finding is more likely to trigger a stricter enforcement phase than to make the law less relevant — treat it as a rising-risk area, not a low-priority one.

What does the Colorado AI Act actually require today?

As amended by SB 26-189 (May 2026), Colorado requires notice to affected individuals, an adverse-action process with human review, and 3+ years of record retention for AI systems that materially influence consequential employment decisions. The amendment removed the original bill's standalone impact-assessment and Attorney General reporting duties. The compliance deadline is now January 1, 2027, after two delays — confirm it hasn't moved again before relying on that date.

How is Texas TRAIGA different from Colorado, Illinois, or California's laws?

TRAIGA is narrower for private employers — it primarily targets government AI use and prohibits AI deployed with intent to unlawfully discriminate, without imposing the broad notice, audit, or impact-assessment regime that Colorado, Illinois, and California impose. Employers in Texas without operations in the other states covered here have a materially lighter compliance burden today, though this could change with future rulemaking.

Are EU employers more or less regulated than US employers on AI in hiring?

In several respects, more — despite the EU AI Act's high-risk Annex III deadline being deferred to December 2027, GDPR Article 22 (automated decision-making, in force since 2018), AI Act Article 4 (AI literacy, in force since February 2025), and works-council co-determination in Germany, Austria, and the Netherlands all already apply without delay. A US company with EU employees should not assume the AI Act deferral means less exposure in the EU than in a regulated US state.

What AI use cases actually trigger these laws?

Résumé screening and candidate ranking, interview scoring or analysis, promotion recommendations, AI-assisted performance or sentiment monitoring, and in some states automated scheduling that affects hours or shifts. A tool that only drafts job postings or answers general HR policy questions is a materially lower-risk use case than one that scores or ranks a specific candidate or employee.

← Back to Power Local LLM