AI Hiring Compliance: The Last Year Employers Can Treat Bias Audits as a Vendor Problem
By Chris Weinmann, Founder, OVI
Nine in ten US employers now use AI screening tools in their hiring process. Yet only 38% of HR technology vendors fully comply with New York City's Local Law 144 — the world's oldest regulation specifically targeting automated employment decision tools. As enforcement agencies reform and the EU's penalty regime counts down to a hard deadline, 2026 is the last year employers can treat AI hiring compliance as someone else's problem.
What NYC Local Law 144 Requires
New York City's Local Law 144, which took effect in July 2023, regulates the use of automated employment decision tools (AEDTs) in hiring and promotion. The law applies to any employer or employment agency that uses an AI tool to substantially assist or replace discretionary decision-making in hiring within New York City.
Under LL144, employers must conduct an independent annual bias audit of their AEDT, publish the audit results on their website, and notify candidates that an automated tool is being used in the hiring process. Penalties range from $500 to $1,500 per day, per affected candidate — a structure that compounds rapidly in class-action contexts where hundreds or thousands of applicants are evaluated by the same tool.
Despite these requirements, compliance remains the exception. According to algorithmic fairness market data, only 38% of HR vendors fully comply with LL144's requirements. The gap between the law's requirements and actual vendor behavior has created a false sense of security for employers who assumed their vendors had compliance covered.
The Enforcement Gap: Theater vs. Reality
A December 2, 2025 audit by the New York State Comptroller exposed the depth of the enforcement failure. The audit examined how the NYC Department of Consumer and Worker Protection (DCWP) — the agency responsible for enforcing LL144 — actually performed its oversight duties.
The findings were stark: DCWP flagged just one violation across 32 companies it examined. The Comptroller's own auditors, reviewing the same 32 companies, identified 17 violations. Meanwhile, 75% of the 311 hotline calls from the public about AEDTs were misrouted, meaning complaints never reached the right department.
In practical terms, enforcement was largely theater. But the audit's release has changed the calculus. DCWP has publicly committed to reform, and the Comptroller's scrutiny signals that the era of passive enforcement is ending. DLA Piper's 2026 analysis of the enforcement landscape identifies this moment as a critical inflection point — employers who relied on the enforcement gap as a de facto compliance strategy now face materially higher risk.
The EU AI Act: A Parallel Clock With Higher Stakes
While US employers process the LL144 enforcement wake-up call, European regulation is approaching on a separate and more consequential timeline.
Under the EU AI Act's Annex III, Section 4, AI tools used for CV filtering, candidate ranking, and performance evaluation are classified as high-risk systems. This classification triggers extensive obligations: technical documentation, conformity assessments, human oversight requirements, and data governance standards.
The original compliance deadline for these high-risk obligations was August 2, 2026. However, the EU Council's Digital Omnibus Act, adopted on June 29, 2026, extended this deadline to December 2, 2027 — giving employers and vendors an additional 16 months.
But the extension is not a grace period. Two earlier deadlines remain firmly in place. Article 5, which prohibits the use of emotion recognition technology in workplace contexts, has been in effect since February 2, 2025. Any employer using AI tools that analyze facial expressions, voice tone, or physiological signals during interviews is already in violation. Article 50's transparency requirements — mandating that candidates be informed when they interact with AI systems — take effect on the original August 2, 2026 schedule.
The penalty structure underscores the EU's intent. Violations of prohibited practices carry fines of up to €35 million or 7% of global annual turnover, whichever is higher. For a company with $1 billion in annual revenue, that is a potential $70 million exposure.
EU AI Act compliance among HR vendors currently sits at just 26%, according to algorithmic fairness market data — even lower than the already-poor LL144 compliance rate.
The Compliance Gap in Practice
The numbers paint a picture of an industry unprepared for the regulatory environment it is entering.
Across the AI hiring compliance landscape, 78% of organizations lack proper bias assessment frameworks, and 65% fail to meet basic documentation requirements. Bias auditors analyzing over 150 LL144 audits have identified a 40% increase in detected bias patterns compared to 2024 — a trend that reflects both improved detection methods and the growing complexity of AI screening tools.
The market is responding to this gap. The global AI bias audit and algorithmic fairness market is projected to grow from $468.58 million in 2026 to $992.69 million by 2031, representing a compound annual growth rate of 16.2%. That growth trajectory signals that compliance infrastructure is scaling — but also that most organizations have not yet invested in it.
For employers, the core risk is not the AI tool itself but the assumption that compliance is the vendor's responsibility. LL144 explicitly places the legal obligation on the employer, not the technology provider. The EU AI Act extends similar obligations to deployers of high-risk systems. In both frameworks, "our vendor handles that" is not a defense.
What HR Teams Must Do Now
The window for treating AI hiring compliance as a future concern is closing. Three actions are immediately necessary.
Run a bias audit. If your organization uses any AI tool that screens resumes, ranks candidates, or evaluates applicants, commission an independent bias audit now. Under LL144, audits must be conducted by an independent auditor, cover impact ratios across race/ethnicity and sex categories, and be published on your website. Even outside NYC, a documented bias audit is becoming the baseline expectation for responsible AI use in hiring.
Conduct a vendor compliance assessment. Ask your HR technology vendors specific questions: Have they completed an LL144 bias audit? Can they provide documentation for EU AI Act conformity? Do their tools use emotion recognition, biometric analysis, or physiological signal processing? Given that only 38% of vendors comply with LL144 and 26% with the EU AI Act, verification is essential — assumptions are not.
Build a documentation trail. Both LL144 and the EU AI Act require extensive documentation of AI systems, their intended use, their known limitations, and their bias audit results. Start building this documentation now, even if your organization is not yet subject to either regulation. The trend is unambiguous: more jurisdictions will follow New York and the EU, and a pre-existing compliance infrastructure is substantially easier to adapt than one built under deadline pressure.
What does NYC Local Law 144 require?
LL144 requires employers using automated employment decision tools (AEDTs) in NYC to conduct an annual independent bias audit, publish audit results on their website, and provide candidates with notice that an AEDT is being used. Non-compliance carries penalties of $500–$1,500 per day per affected candidate.
Who does LL144 apply to?
The law applies to any employer or employment agency that uses an AEDT to substantially assist or replace discretionary decision-making in hiring or promotion decisions involving candidates or employees located in New York City.
What does the EU AI Act classify as high-risk in hiring?
Under Annex III, Section 4, AI systems used for recruiting, screening CVs, filtering applications, evaluating candidates, and assessing employee performance are classified as high-risk. This triggers mandatory technical documentation, conformity assessments, human oversight requirements, and data governance obligations, with the compliance deadline now set to December 2, 2027.
How do I run a bias audit for AI hiring tools?
Commission an independent, qualified auditor to evaluate your AEDT's outputs for disparate impact across protected categories (race/ethnicity and sex under LL144). The audit must analyze selection rates and impact ratios, and the results must be published on your company website. Audits should be repeated annually.
What happens if my organization is non-compliant?
Under LL144, fines are $500–$1,500 per violation per day, with each candidate affected counted separately — creating significant exposure in high-volume hiring. Under the EU AI Act, prohibited AI practices (such as workplace emotion recognition) carry fines up to €35 million or 7% of global annual turnover. Documentation failures and non-conformity with high-risk requirements also carry substantial penalties.