# What Are the AI Hiring Bias Audit Requirements in 2026?

psychprofile.io · September 23, 2026

> What the core requirements actually are As of September 24, 2026, there is no single federal rule requiring every U.S. employer to conduct an AI hiring...

## What the core requirements actually are

As of September 24, 2026, there is no single federal rule requiring every U.S. employer to conduct an AI hiring bias audit. Requirements come from federal anti-discrimination law, state laws, city ordinances, and—in many cases—the EU AI Act. The central question is whether an automated system substantially assists or replaces a hiring decision, because employment-related AI used to screen applicants, rank candidates, assess video interviews, parse résumés, or predict employee performance is commonly treated as a high-impact employment tool. An audit is generally not enough by itself: employers must also provide required notices, preserve records, test disparate impact, investigate complaints, and correct problematic outcomes. A vendor’s generic certificate or compliance dashboard does not usually satisfy an employer-specific duty. The exact obligations depend on where candidates are located, which system is being used, and whether the employer makes the final decision.

**Also worth reading:** [What are the specific NYC Local Law 144 audit requirements for automated employment decision tools in 2026?](https://psychprofile.io/knowledge/what_are_the_specific_nyc_local_law_144_audit_requirements_for_automated_employment_decision_tools_in_2026.php) · [Is Auditing Recruitment Algorithms for Bias Actually Enough to Guarantee Fair Hiring in 2026?](https://psychprofile.io/knowledge/is_auditing_recruitment_algorithms_for_bias_actually_enough_to_guarantee_fair_hiring_in_2026.php) · [Why Do Traditional Algorithmic Bias in Hiring Audits Fail to Catch Discriminatory AI Systems?](https://psychprofile.io/knowledge/why_do_traditional_algorithmic_bias_in_hiring_audits_fail_to_catch_discriminatory_ai_systems.php)

Federal law remains the baseline. Title VII prohibits employment discrimination based on race, color, religion, sex, and national origin, while the ADA and the Pregnant Workers Fairness Act can also apply. The U.S. Equal Employment Opportunity Commission has used the “four-fifths rule” as a screening guideline: an adverse-impact rate below 80% of the rate for the favored group may warrant scrutiny, although it is not a safe harbor and does not determine liability. A selection rate of 50% for one group compared with 70% for another produces a ratio of about 71%, below that guideline. Employers should examine statistical differences, job relevance, alternative employment practices, and small-sample uncertainty before drawing conclusions.

## New York City: the clearest U.S. audit mandate

New York City Local Law 144, enforced by the Department of Consumer and Worker Protection, is the most explicit U.S. mandate for bias audits of automated employment decision tools. A covered employer or employment agency must conduct a bias audit at least once annually and within one year before the tool is used, make the audit available to an enforcement officer on request, and publish a summary of the data and results on its website. The law applies broadly to tools used to assist or replace discretionary decision-making, including résumé screening, candidate ranking, interview assessment, and hiring or promotion decisions. It also requires notice to candidates about the tool’s use, the purpose, and the contact details of the employer’s designated bias-audit contact.

The compliance details are often missed. A notice must be supplied at least 10 business days before the tool is used to help make a hiring decision, although a shorter notice can be given in limited circumstances, and a notice is not required for certain internal uses. Covered employers must provide training to relevant personnel about the law and the tool. Since enforcement began in July 2023, companies operating in the city should treat the annual audit as an operational requirement rather than a one-time project. The audit must examine the tool’s impact by sex, race and ethnicity, and intersectional categories such as race and sex; it should include the categories, sample sizes, selection rates, impact ratios, statistical testing, and the date of the review. A report that merely states that the vendor is “fair” is unlikely to answer the ordinance’s questions.

## Colorado, Illinois, and Connecticut: different duties, different deadlines

Colorado’s SB 24-205 took effect on June 30, 2026, but its duty applies to decisions made on or after February 1, 2027. Employers making high-risk artificial-intelligence decisions about applicants or employees must provide a notice explaining the AI system’s role and why the decision is subject to the law. They must also exercise reasonable care to protect applicants and employees from known or reasonably foreseeable algorithmic discrimination. An employer can rebut a presumption of discrimination through a demonstration of reasonable care. The law defines covered systems by function, including systems used to eliminate or substantially alter employment opportunities, duties, compensation, promotion, termination, or other terms. Vendors can assist with documentation, but the employer remains responsible for the deployment and its consequences.

Illinois has moved in a different direction, emphasizing notice and complaint procedures. The Illinois Human Rights Act, effective January 1, 2026, requires an employer that uses artificial intelligence for recruitment, hiring, promotion, renewal, or other employment decisions to notify applicants and employees. Employers must also provide information about how the system works and must establish a process through which a person can request a review of a potentially discriminatory decision. The system may not make or effectively make an employment decision on behalf of the employer without human review. Illinois law should be read together with existing discrimination law rather than treated as a standalone safe harbor. Connecticut’s amendments likewise create a notice and reporting framework for employment AI, and the original effective date was January 1, 2026. These laws do not necessarily require a public annual audit report, but they do require governance records, transparency, and meaningful review mechanisms.

| Feature | New York City Local Law 144 | Colorado SB 24-205 | Illinois amendments | Connecticut amendments |
| --- | --- | --- | --- | --- |
| Main requirement | Annual independent bias audit and public summary | Notice, reasonable care, and protected decision process | Notice, explanation, and human review of AI decisions | Notice and reporting duties |
| Effective timing | Enforced since July 2023 | Rules apply to decisions on or after Feb. 1, 2027 | January 1, 2026 | January 1, 2026 |
| Advance notice | Generally 10 business days | At least 30 days before the system is used in covered circumstances | Before the AI decision is used | Employer must provide required notice |
| Audit report | Public summary generally required | No universal public report, but records are important | No universal public audit mandate | No universal public audit mandate |
| Core risk | Failure to audit or publish required information | Failure to exercise reasonable care | Discriminatory decision without proper review or review process | Violation of notice or reporting duties |

## The EU AI Act and the meaning of a “bias audit”
For employers recruiting people in the EU, the EU AI Act creates a separate regime that is often stricter than U.S. state rules. Recruitment, candidate selection, screening, ranking, and assessment systems generally fall within the definition of a high-risk AI system because they affect access to employment or a self-employment opportunity. The Act requires risk management, data governance, technical documentation, record-keeping, human oversight, accuracy and robustness controls, transparency, and provider and deployer obligations. A deployer must use a high-risk system in accordance with instructions, assign human oversight to competent people, monitor operation, keep logs, and inform workers and representatives before putting the system into service. Providers and deployers also face obligations to investigate and report serious incidents.

The EU framework does not reduce a bias audit to one numerical ratio. Testing should consider whether training and validation data are sufficiently representative, whether proxies create unlawful disadvantage, whether the system reproduces historical discrimination, and whether the model’s features are appropriate for the job. Accuracy claims must be tested across relevant groups and operating conditions. For a psychological assessment, the employer should also examine whether a measure used in training has independent evidence of job-related validity and predictive fairness. The EU AI Act’s obligations apply on a staged timetable that is tied to the system’s category and the applicable prohibition or high-risk provisions, so a global employer should not assume that the June 2025, 2026, and 2027 milestones are interchangeable. A U.S.-only vendor certificate is not proof of compliance with every EU deployment requirement.

## How employers should conduct a defensible audit

A useful audit begins with inventory and purpose analysis, not with buying a fairness dashboard. Record the vendor, model version, intended job, affected population, decision point, human overrides, and the data used to develop and validate the system. Identify whether the tool screens applicants, evaluates recorded interviews, generates summaries, scores personalities, predicts turnover, or ranks candidates. Then map protected classes and intersectional groups to the laws that apply in every hiring location. For federal purposes, include race, sex, national origin, disability, and religion, and add state-specific categories such as age, pregnancy, sexual orientation, gender identity, or lawful off-duty conduct. Define the comparison groups and the stage of the hiring process before reviewing results, so the team does not choose metrics only after unfavorable outcomes appear.

Testing should cover the entire process: outreach, application, screening, interview, offer, and sometimes promotion and termination. Calculate selection rates, pass rates, false-positive and false-negative rates, score distributions, adverse-impact ratios, and the impact of human overrides. Examine whether the model behaves differently when equivalent résumés contain different names, addresses, school names, accent features, disability-related gaps, or caregiving information. At least two analysts should review the results, and a statistically significant result should be investigated rather than automatically treated as proof of discrimination. A sample with fewer than 30 observations in a subgroup may be too small for reliable conclusions; many organizations use 100 or more observations per group as a practical target, but sample size alone does not cure poor design. Keep the underlying data, analysis code, versions, and decisions for a defined period such as three to seven years, subject to applicable record-retention rules.

## Costs, alternatives, and what psychological profiles can add

A simple internal review can cost little more than staff time, but a genuinely independent audit often falls roughly between $10,000 and $100,000 for a single tool and workflow. Complex systems using video, audio, behavioral data, or multiple hiring stages can cost several hundred thousand dollars when testing, privacy review, legal analysis, and data collection are included. Bias-testing software may be priced per job family, candidate volume, model, or subscription year, and some open-source projects reduce licensing costs while leaving substantial validation work. Manual expert review, third-party testing, and vendor-assisted analysis can be combined, but the cheapest option is not necessarily the most defensible. The right comparison is the cost of an employment claim, agency investigation, hiring delay, damaged employer reputation, and the risk of a challenged promotion or termination decision.

Alternative controls include structured interviews, work-sample tests, validated cognitive ability measures, human review panels, and removing irrelevant data. Work-sample testing can reduce dependence on proxies, but it can still exclude candidates when the sample does not reflect the actual job. Human review is not automatically fair; reviewers may reproduce the model’s score or defer to an automated recommendation. AI psychological profiles should therefore be treated as one input among several, with independent validation for the specific role and population. The tool should not infer sensitive traits, personality diagnoses, or future behavior unless there is a documented, lawful, and job-related basis. A psychological profile can add value by organizing evidence and flagging patterns, but it cannot establish legal compliance or replace an audit of the underlying hiring system.

## Common mistakes and when to act now

The most common mistake is assuming that a vendor’s statement that its model is “bias-free” ends the inquiry. Another is testing only the model’s overall accuracy while ignoring how the tool changes the pass rate of different groups. Employers frequently fail to compare the tool’s results with a reasonable, less discriminatory alternative, or they publish an audit without explaining sample sizes, categories, methodology, and limitations. Other failures include reviewing data only once during procurement, changing model versions without retesting, using a model for a different job than the one validated, and treating a candidate’s request for accommodation as an adverse employment decision. Keeping an AI system live because “everyone approved it” is not a defensible response to a complaint or a regulator’s inquiry.

The time to act depends on exposure, not only on the official effective date. Organizations that hire in New York City should act before the next annual cycle if they lack a current audit and public summary. Colorado employers should build documentation and review processes now, because the February 1, 2027 application date will make post-selection evidence less useful. Illinois and Connecticut employers should verify that notices and review procedures are operating in the actual applicant experience, not just in a policy file. A company with substantial EU recruiting should map high-risk systems and engage qualified counsel and technical testers before deploying or materially changing them. As a practical trigger, begin a project within 30 days when an AI tool affects 500 or more candidates per year, touches a protected group at a materially different rate, or is used in a role with prior discrimination complaints.

## A practical compliance standard

The strongest answer to “what are the requirements?” is that employers need a documented, repeatable, and jurisdiction-specific process, not a one-time PDF. Start with a complete inventory, identify the applicable law for each hiring location, obtain a model-specific test report, conduct an independent review, publish or preserve the required notices, and establish a correction and human-review process. Track the legal threshold: New York City’s annual audit is a clear deadline, Colorado’s reasonable-care standard is approaching, and Illinois and Connecticut now make notice and review central. Federal discrimination law applies throughout the United States, while the EU AI Act adds technical and governance duties for high-risk recruitment systems. By September 24, 2026, an employer that cannot explain what data was tested, who was affected, what discrepancies appeared, and what was changed in response is not ready to defend its use of AI in hiring.

## Quick answers

### Does the U.S. federal government require an annual AI hiring bias audit?

There is no single federal law that requires every U.S. employer to publish an annual AI hiring audit. Federal anti-discrimination duties still apply, but states and cities may impose specific audit, notice, and reporting obligations, including New York City Local Law 144.

### What is the four-fifths rule for AI hiring?

The four-fifths rule compares a protected group’s selection rate with the higher rate of a reference group. A ratio below 80% can indicate a possible adverse-impact concern, but it is a screening guideline rather than an automatic finding of discrimination, and small samples can make results unreliable.

### Does using an AI system automatically make an employer liable for discrimination?

No. Liability depends on how the system is designed, validated, deployed, and used, as well as the employer’s employment practices. A system can create legal risk when it reproduces discriminatory patterns or when the employer ignores known warning signs and lacks reasonable review controls.

### Can a vendor’s fairness certificate satisfy New York City’s audit law?

Not by itself. Local Law 144 requires a bias audit of the tool used by the covered employer, and the employer must meet the ordinance’s documentation, testing, and publication requirements. A generic vendor report may inform the audit but usually does not replace employer-specific analysis.

### Are AI psychological profiles required to undergo bias testing?

If they influence hiring or promotion, they should be included in the employer’s broader testing and validation process. Testing should cover group outcomes, job-related validity, data quality, proxies, human oversight, accommodation issues, and whether the system is more accurate or less discriminatory than a reasonable alternative.

Canonical: https://psychprofile.io/knowledge/what_are_the_ai_hiring_bias_audit_requirements_in_2026.php
Markdown: https://psychprofile.io/knowledge/what_are_the_ai_hiring_bias_audit_requirements_in_2026.php/index.md
