In New York City, Colorado, and the European Union (EU), most of the artificial intelligence (AI) hiring laws people talk about in 2026 start on dates that haven’t arrived yet. The AI rules that already bind employers in those three places are narrower and sharper than the coverage suggests: a New York City law that requires a bias audit of automated employment decision tools and advance notice to candidates and employees who live in the city, and EU bans on uses such as inferring emotions at work, with a fine ceiling of 7% of worldwide turnover.
The legal picture isn’t settled, and a lot of what’s written about it treats every rule as live and every duty as the employer’s.
This article covers New York City, Colorado, and the EU, and leaves out Illinois and California, whose AI hiring rules are already in force. For those three places, it’s a dated calendar of what already binds employers, what binds vendors, and what starts in 2027. It also makes one argument I’d hold in all three: having a person make the final call doesn’t, by itself, put a tool outside these laws. Each law has its own test for whether a tool is covered, and those tests are already written down. So even though most of the employer duties arrive in 2027, and a federal court order has put Colorado’s enforcement on hold, I wouldn’t read the wait as a reprieve.
The AI hiring laws of 2026 and 2027, in one table.
The dates below come from the laws themselves. The column that trips most teams up is the last one: a rule that binds your vendor isn’t automatically a duty for your recruiters, and a rule that binds you still applies when the vendor built the tool.
| When | What applies | Who owes it |
|---|---|---|
| Enforced since 5 July 2023 | New York City Local Law 144: a bias audit, a published summary, and notice before an automated employment decision tool is used | Employers and employment agencies |
| Since 2 February 2025 | EU AI Act bans, including inferring emotions at work and biometric categorization of sensitive traits, with fines since 2 August 2025 | Anyone who uses such a system, employers included |
| Since 2 February 2025 | EU AI literacy duty, rewritten in July 2026 as a duty to support literacy | Vendors and employers |
| Since 2 August 2026 | EU AI Act Article 50(1): people are told they’re dealing with an AI system unless it’s obvious | Providers, usually the vendor |
| Since 2 August 2026 | EU AI Act Article 50(3): people exposed to emotion recognition or biometric categorization are informed | Employers using those systems (deployers) |
| From 1 January 2027 | Colorado’s automated decision law: notice, an explanation within 30 days of an adverse decision, correction and human review, and three years of records | Employers (deployers) for notice, explanation, and review; vendors (developers) for documentation; both keep records |
| From 2 December 2027 | EU high-risk rules for hiring AI, including telling candidates and workers’ representatives; systems already on the market or in service are covered only if their design changes significantly | Vendors and employers |
Every date in the table is what the texts say today, which is the limit of any calendar like this one.
What already binds employers in these three places.
New York City’s Local Law 144 applies to an employer or employment agency that uses an automated employment decision tool to screen candidates or employees. Under the city’s rules, a tool counts as one when it gives a simplified output, such as a score, classification, or ranking, and the employer relies on that output alone, weights it more than any other criterion, or uses it to overrule conclusions drawn from other factors, including human decision-making. Before using one, the employer needs a bias audit carried out no more than a year before use, and a summary of the results and the tool’s distribution date on its website. Candidates and employees who live in the city get notice at least 10 business days ahead, saying the tool will be used and what it will assess, with instructions for requesting an alternative selection process or an accommodation. The type and source of the data the tool uses, and the employer’s retention policy, go on its website or out on written request. The penalty is up to $500 for a first violation and for any further violation on the same day, then between $500 and $1,500 for each one after that. Each day a tool is used in violation, and each missed notice, counts as a separate violation.
The law took effect on 1 January 2023, and the city has enforced it since 5 July 2023, which isn’t the same as enforcing it much. A December 2025 audit by the New York State Comptroller found the city’s complaint process ineffective, and when the state’s auditors reviewed the same companies the city had reviewed, they found far more potential non-compliance than the city had.
In the EU, the AI Act’s bans have applied since 2 February 2025, and two of them reach hiring directly. One covers using AI to infer a person’s emotions at work, with an exception for medical or safety reasons. The other covers biometric categorization that deduces traits such as race, political opinions, trade union membership, religious beliefs, or sexual orientation. The European Commission’s guidelines put the first one plainly: “Using emotion recognition AI systems during the recruitment process is prohibited.” The fines have applied since 2 August 2025.
Since 2 August 2026, Article 50(3) has also required an employer that uses an emotion recognition or biometric categorization system to inform the people exposed to it, and it’s the employer’s duty. In hiring, the bans already cover emotion recognition at work outside medical or safety uses, so I read Article 50(3) as reaching mainly the systems of those two kinds that the bans don’t prohibit.
The AI literacy duty in Article 4 has applied since 2 February 2025 as well. Regulation (EU) 2026/1744, adopted on 8 July 2026, rewrote it as a duty to “take measures to support the development of AI literacy” among the people who operate these systems, with no guaranteed level. The Act sets no amount for breaching it. Member States set the penalties, which may include fines.
Telling candidates an AI is talking to them is usually a duty on your vendor.
Article 50(1), which has applied since 2 August 2026, says providers must design AI systems that interact directly with people so that those people are told they’re dealing with an AI system, unless that’s obvious to a reasonably well-informed person. Under the Act’s definitions, the provider is whoever develops the system, or has it developed, and puts it on the market or into service under its own name, and the deployer is whoever uses it. In hiring software, that usually makes the vendor the provider and the employer the deployer.
If a candidate chats with an assistant that schedules interviews, Article 50(1) makes the disclosure a design duty of the provider. The buyer’s question is whether the vendor has built it in. The July 2026 amendments left Article 50(1) as it was, and what stays with the employer is the Article 50(3) notice when it uses emotion recognition or biometric categorization, the literacy duty, and the high-risk duties that arrive in 2027.
Colorado starts on 1 January 2027, with a court case in the background.
Colorado’s Senate Bill (SB) 26-189, signed on 14 May 2026, repealed and re-enacted the state’s 2024 AI law. Its duties apply to what the act calls consequential decisions made on or after 1 January 2027, and employment decisions are one of the kinds it covers. An employee counts, and so does a job applicant who lives in Colorado.
If you’ve seen Colorado’s law dated 30 June 2026, that was the start date of the 2024 law after SB 25B-004, passed in a 2025 special session, pushed it back. SB 26-189 replaced that law, and the new law’s duties start on 1 January 2027.
Most of the duties fall on deployers, which the act defines as a person doing business in Colorado that deploys a covered tool, when the tool materially influences a decision:
- A clear and conspicuous notice that the tool is being used, before it’s used.
- If a decision it influenced goes against the person, within 30 days after making the decision, a plain-language description of the decision and the role the tool played.
- Rights to correct inaccurate personal data and to request human review and reconsideration.
- Records kept for at least three years, by deployers and developers alike.
Vendors, which the act calls developers, owe employers documentation of the tool’s intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. The attorney general must adopt rules on the disclosures and on those rights by 1 January 2027, and proposed rules were filed on 11 August 2026. Enforcement belongs to the attorney general alone, as a deceptive trade practice. Until 1 January 2030, when the cure provision is repealed, any action comes only after a notice and 60 days to cure, where the attorney general deems a cure possible.
The start date also sits beside a federal lawsuit. X.AI LLC, the company behind the Grok AI model, sued Colorado’s attorney general on 9 April 2026, arguing that the 2024 law is unconstitutional, and the federal Justice Department joined the suit on 24 April. On 27 April, before SB 26-189 was signed, the court ordered, at the parties’ request, that the attorney general not start enforcement, investigations included, over violations of the 2024 law “or any legislation replacing or amending SB24-205 enacted during this legislative session.” The order covers violations that have happened, or happen, up to 14 days after the court rules on X.AI’s coming motion for a preliminary injunction. X.AI has to file that motion within 28 days of the attorney general’s rules being finally adopted.
Those words fit SB 26-189, which replaced the 2024 law in the same session. So in Colorado, the attorney general, who alone enforces the new law, can’t pursue anything an employer does under it up to 14 days after the court’s ruling on the preliminary injunction. When that ruling comes depends first on when the attorney general’s rules are finally adopted, because X.AI’s 28 days to file its motion count from then. Even with the hold, the law’s duties apply to consequential decisions made on or after 1 January 2027.
Colorado passed a second AI law in 2026. House Bill (HB) 26-1263 covers conversational AI services, which it defines as AI systems “accessible to the general public” that primarily simulate human conversation, and from 1 January 2027 it requires their operators to tell users the service is AI. Whether a recruiting assistant counts as that kind of service is untested.
The EU high-risk hiring rules start on 2 December 2027, for some tools.
The AI Act lists AI systems intended for recruitment or selection as high-risk, in particular those that place targeted job ads, analyze and filter job applications, or evaluate candidates. The July 2026 amending regulation, in force since 27 July 2026, moved the date those rules apply to 2 December 2027. Plenty of summaries written before July still say 2 August 2026.
A listed tool can still fall outside these rules. Under Article 6(3), it isn’t high-risk if it poses no significant risk of harm, including by not materially influencing the outcome of a decision, and it’s also meant for one of these: a narrow procedural task; improving the result of a human activity already completed; spotting decision-making patterns or departures from earlier ones, when it isn’t meant to replace or influence a completed human assessment without proper human review; or a preparatory task to an assessment.
From 2 December 2027, an employer using a high-risk hiring system, which the Act calls a deployer, has to:
- Take technical and organizational measures to use it according to the instructions for use that come with it (Article 26(1)).
- Assign human oversight to people with the competence, training, and authority for it, and the support they need (Article 26(2)).
- Monitor how it runs against those instructions, and if using it may present a risk, tell the provider or distributor and the market surveillance authority and suspend it (Article 26(5)).
- Keep the logs it generates automatically, where they’re under the employer’s control, for at least six months unless other law says otherwise (Article 26(6)).
- Inform workers’ representatives and the affected workers before using it at work (Article 26(7)).
- Tell the people it helps make decisions about that it’s being used on them (Article 26(11)).
The wording of those duties didn’t change, and only the date moved.
The amended Article 111(2) adds a condition most summaries leave out. For high-risk systems already on the market or in service before 2 December 2027, the rules apply “only if, as from that date, those systems are subject to significant changes in their designs.” The regulation’s recitals say the grace period attaches to a type and model, so new units of an unchanged model are covered by it too. The AI Act’s own recitals say a significant change should be read as equivalent in substance to a substantial modification. The Act defines that term as a change made after the system’s release that the provider didn’t foresee or plan in its initial conformity assessment and that affects the system’s compliance with the high-risk requirements or changes the purpose it was assessed for. I don’t know how that applies to software that releases an update every week. I’d ask the vendor that question in writing, and then ask counsel what the answer means.
Article 86 adds a right for a person affected by an employer’s decision based on one of these systems to get “clear and meaningful explanations of the role of the AI system” from the employer using it, where the decision has legal or similarly significant effects that the person considers adverse to their health, safety, or fundamental rights. Article 86 sits outside the chapter the 2027 date moved, so when it starts to apply is unsettled.
The final click is not the test in any of the three places.
A common reassurance in AI hiring is that a person makes the final decision. It’s good practice, and I’d keep it. On its own, it does not take a tool out of scope under any of these laws.
New York City’s test, set out in the section on what already binds employers, counts a tool when its output is relied on alone, weighted more than any other criterion, or used to overrule conclusions that include human decision-making. So a tool whose output carries no more weight than anything else the person looks at can fall outside the New York City law, and that’s the closest a human decision comes to deciding scope. A score that outweighs everything else is covered even when a person clicks the button.
Colorado asks whether the output affects the outcome, “including by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how a consequential decision is made.” Nothing in the test asks who presses the button. The EU asks what the system is for. Filtering applications and evaluating candidates are on the high-risk list, and an AI system on that list “shall always be considered to be high-risk where the AI system performs profiling of natural persons.” The provider has to document any claim to the Article 6(3) exemptions, and they fall away when the system profiles people.
None of this displaces anti-discrimination law. Colorado’s act says so directly: using such a technology in a consequential decision “does not excuse, justify, or provide a defense to any obligation or liability” under state or federal law, including obligations related to discrimination.
The question I’d ask of every tool is what its output does to the decision: how much weight it carries, whether it ranks, scores, or recommends, and what the vendor built it to do.
Notice shows up in every regime, owed by different people.
Telling people about the AI is the one duty that appears in some form in all three places. It’s owed by different parties, from different dates:
- New York City employers, when a tool counts under Local Law 144, at least 10 business days before use, since 2023.
- EU employers using an emotion recognition or biometric categorization system, since August 2026.
- EU vendors, who design systems that interact with people so those people are told, since August 2026.
- Colorado employers, before a covered tool influences a decision, from 1 January 2027.
- Operators of a conversational AI service open to the public, under Colorado’s HB 26-1263, from 1 January 2027.
- EU employers using a high-risk hiring system, from 2 December 2027.
One notice rarely satisfies all of them, because each law sets its own trigger, timing, and content. For the work inside your own team, Metaview’s guide to writing an AI policy for recruitment covers how disclosure connects to the list of tools a team uses, and a separate guide covers recording interviews, which the next section turns to.
Whatever the scope answer, keep the record.
From 1 January 2027, Colorado asks an employer to describe the role a tool played in a decision that went against a person, and the EU’s Article 86 asks for something similar once it applies. An interview recording is not that explanation, and nothing here meets a legal duty on its own. Recording and keeping interviews also falls under data protection and consent law, which this calendar doesn’t cover. Separately from any legal duty, what a recording does is keep the interview evidence that sat beside the tool’s output, so a team can answer from evidence instead of memory. This article doesn’t settle where Metaview’s Notetaker, which records and transcribes interviews and turns them into structured notes, falls under these laws.
Good interviewers know they are contributing to a hiring decision. Bad interviewers believe they are making a hiring decision.”
Shahriar wrote that about interviewers, and a good interview record shows the same split: what each person contributed to the decision, which is a different thing from who signed off on it.
Brex, the finance platform, records its engineering values interviews. One of the results listed in Brex’s case study reads: “Debriefs on evidence, not memory. When a panel splits on a candidate, anyone can go back to the recorded values interview and find the exact moment in question.”
Metaview’s short customer video on Brex, below, tells more of that story.
When an interview is recorded, Metaview captures every spoken word, so a disagreement about what a candidate said can be checked against the transcript.
The Notetaker joins as a visible participant, and the consent process belongs to the employer. The copy candidates see reads: “If both you and the interviewer consent, you will see a ‘Metaview Notetaker’ appear as a participant during the interview.”
Three months to Colorado, 14 months to the EU, and what to do with them.
The employer duties mostly arrive in 2027, and the dates hold unless a court or a new amendment moves them.
That leaves about three months before Colorado’s law applies and about 14 before the EU’s high-risk rules do. I’d spend them answering, for every tool, what its output does to the decision, because that answer doesn’t change on the day a law starts.
Keep a record your team can go back to.
A demo of the Metaview Notetaker, from the interview to the notes and transcript your team reviews.
Frequently asked.
Is Colorado’s AI hiring law in effect?
Its duties don’t apply yet. Colorado’s SB 26-189 was signed on 14 May 2026, and its duties apply to consequential decisions made on or after 1 January 2027, including employment decisions. It replaced the state’s 2024 law, whose start had been pushed back to 30 June 2026. A federal court order of 27 April 2026 in X.AI LLC v. Weiser bars the attorney general from starting enforcement, investigations included, over violations of the 2024 law or of legislation passed that session to replace or amend it, for anything up to 14 days after the court rules on X.AI’s coming motion for a preliminary injunction.
Does Article 50 of the EU AI Act apply to employers?
Article 50(1) has applied since 2 August 2026, and it binds providers, the companies that build AI systems that interact with people. Article 50(3) applies to employers that use an emotion recognition or biometric categorization system, and requires them to inform the people exposed to it.
When do the EU AI Act rules for hiring tools start?
The high-risk rules for AI used in recruitment and selection apply from 2 December 2027, after Regulation (EU) 2026/1744 moved the date. For systems already placed on the market or put into service before then, the grace period in Article 111(2) means they apply only if the design changes significantly after that date, and the regulation’s recitals apply that to a type and model. The AI Act’s bans, including on inferring emotions at work, have applied since 2 February 2025.
Does a human making the final decision take an AI hiring tool out of scope?
Not by itself, in any of the three places. New York City looks at how much weight the output carries, Colorado at whether the output materially influences the outcome, and the EU at what the system is intended for and whether it profiles people.
Is this article legal advice?
No. It summarizes the texts of the New York City, Colorado, and EU laws as read on 29 September 2026. Whether a particular tool or use is covered depends on facts this article can’t know, so check with counsel before relying on it.