Skip to main content
AI hiring compliance

Regulators wrote AI hiring into law. Here is what each one asks of you.

Four jurisdictions now regulate how software screens, scores and ranks people, and more are drafting. This is the index. What applies, who it applies to, what you have to produce, and which parts Expert Hire can carry for you. Written to be useful. Not legal advice.

Book A Demo

30-day free trial with 75 Hire Credits. Card required, nothing charged for 30 days.

A cross-functional team reviewing AI hiring safeguards
Policy, product controls and human review brought into one operating view.
Why this page exists

The rule changed under the process you already run.

Nothing here bans AI in hiring. Every one of these regimes lets you use it, and every one asks you to explain it. That is a documentation problem first, and documentation is something a platform can carry.

Your hiring process became a regulated artifact.

The moment software scores, ranks or filters an applicant, several jurisdictions stop treating it as an internal workflow. It becomes a tool with disclosure, testing and record-keeping duties attached.

The cost: Legal review arrives after the vendor is chosen, and the rollout stalls at the last gate.

Nobody can say what the score was based on.

Most screening stacks output a number and keep nothing behind it. When a candidate, an auditor or a regulator asks how the number was produced, a spreadsheet of scores is not an answer.

The cost: You cannot defend a decision you cannot reconstruct, and the burden of proof sits with the employer.

The map keeps moving.

A city rule, a state civil-rights amendment, a state AI act with a shifting start date, and a European regulation phasing in over years. With remote roles, one requisition can touch several at once.

The cost: You comply where you are headquartered and get caught where the candidate actually lives.

The jurisdiction map

Five guides. Start with the one your roles sit in.

Each guide covers what the instrument is, whether it applies to you, what you have to produce, and which side of the line Expert Hire sits on. Three carry a questionnaire that walks your own setup through the scoping questions.

New York CityEnforced since July 2023

Local Law 144

The rule that started the compliance conversation in the United States. It covers automated employment decision tools, meaning software that substantially assists or replaces discretionary decision-making when you hire or promote for a role based in New York City. It does not ban the tool. It asks you to test it, publish what the test found, and tell candidates before you use it.

What it obliges you to do
  • Commission an annual bias audit from an independent auditor
  • Publish a summary of the audit results where candidates can find it
  • Give candidates notice before the tool is used, and say what data it collects
  • Handle requests for an alternative selection process or an accommodation
Read the NYC guide and take the questionnaire
IllinoisAIVIA in force since 2020

AI Video Interview Act, and the Human Rights Act amendment

Illinois moved first and has moved again. The AI Video Interview Act governs the use of AI to analyse recorded video interviews for Illinois-based roles, and it is built around consent rather than audit. A separate amendment to the Illinois Human Rights Act goes wider. It extends the state's discrimination rules to AI used across recruitment and employment decisions, and adds a notice duty of its own.

What it obliges you to do
  • Tell the applicant before the interview that AI will be used, and explain what it evaluates
  • Obtain the applicant's consent before the analysis runs
  • Limit who sees the video to people whose expertise is needed to evaluate it
  • Destroy the recording and all copies within 30 days of a deletion request
Read the Illinois guide and take the questionnaire
CaliforniaIn force, with further privacy rules phasing in

FEHA rules on automated decision systems

California did not write a new AI statute for hiring. It confirmed that the existing anti-discrimination law already reaches automated decision systems, which is a harder position for an employer, not an easier one. Liability follows the outcome rather than the intent, and a vendor's assurance that a tool is fair is generally not a defence you can rely on by itself. Separate state privacy rules on automated decision-making technology are phasing in on their own timetable.

What it obliges you to do
  • Evaluate the tool for discriminatory impact before you deploy it, not after
  • Retain applications, selection criteria and outputs for the statutory record period
  • Tell applicants when an automated system is evaluating them
  • Keep a route to an alternative selection method available
Read the California guide and take the questionnaire
European UnionIn force, obligations phasing in

EU AI Act

The broadest of the four. AI used for recruitment, for filtering applications and for evaluating candidates is classified as high risk, which brings data governance, technical documentation, logging and human oversight duties. The Act splits those duties between the provider that builds the system and the deployer that uses it. So the first question in any EU review is which of the two you are. It reaches you if the output is used in the EU, even if you are not.

What it obliges you to do
  • Confirm whether you are the provider, the deployer, or both
  • Ensure a named human can oversee, override and stop the system
  • Inform workers and candidates that a high-risk system is in use
  • Follow the instructions of use and keep the logs the Act expects
Read the EU AI Act guide and risk check
Rest of the United StatesUpdated as instruments move

State and city tracker

A widening set of states regulate part of this picture. Some cover facial analysis in interviews. Some cover biometric identifiers such as voiceprints and face geometry. Others pass general-purpose AI acts that reach employment decisions, or issue attorney-general guidance applying existing civil rights law to algorithms. The tracker groups them by the obligation they create rather than by statute name.

What it obliges you to do
  • See which states currently have something in force
  • See which obligation category each one falls into
  • See where a biometric consent law sits underneath the AI rule
  • See what is drafted but not yet operative
Open the US state-by-state tracker
The artifact

What you put in front of an auditor.

Almost every obligation on this page comes down to one question. Can you reconstruct how a candidate was evaluated, months later, without the person who ran it? The reportcard is the answer, and every round produces one.

The candidate reportcard, shown with sample data. Overall score and verdict on the left, a skill breakdown labelled as scored from transcript and code, the round it belongs to, and a right-hand rail holding the recording, a 96-line speaker-separated transcript with a search box, and the technical skills the round evidenced. Share and Download PDF sit in the header. Reports are always included and never metered.

A score with its working shown.

The overall number sits next to a skill breakdown scored from the transcript and the code, against the skills you weighted and the JD you set up. A reviewer can see which dimension carried the score and which one dragged it down.

The raw record, kept and searchable.

The full session recording plays inside the report, next to a speaker-separated transcript you can search and filter by candidate or interviewer. That is what an auditor or a candidate is asking for.

Integrity status stated, not acted on.

Malpractice status appears on the report as a fact for the reviewer, alongside the round it belongs to. A flag is never an automatic verdict, and we do not auto-reject anyone.

Jurisdiction independent

What we do everywhere, whoever is asking.

These six controls are not toggles you enable for a jurisdiction. They are how the product works by default, in every workspace. That is why the jurisdiction guides come down to paperwork you own rather than engineering you request.

Structured rounds, one rubric.

A pipeline is built from rounds, and every stage is one of five modes: resume screening, AI interview, human-led interview, AI prompt assessment or coding test. You pick the skills and set a weightage on each, you set up the JD, and answers are scored against both. Candidates are compared on a stated basis, not on whoever happened to interview them.

Five round modes

Evidence behind every score.

Scores come from the transcript, the submitted code, the skills you weighted and the JD you set up. The report keeps all of it. Nothing is scored from a signal you cannot see on the report.

Transcript, code, skills, JD

Human review and override.

A recruiter can silent-listen to a live AI round and take over in real time, and every score is advisory until a person acts on it. Malpractice and integrity signals are surfaced to a human reviewer. There is never an automated pass or fail, and we do not auto-reject anyone.

Never an automated pass or fail

Audit logs and exports.

Audit logs sit on every action, and role-based access control governs who can see what. Candidate data exports to CSV whenever you or your auditor needs the underlying record rather than the interface.

Export any time

Candidate notice support.

Candidates review a plain-language AI notice and consent before a video round begins. For the public disclosure that has to live on your careers site, we publish an editable AEDT notice template. The notice stays employer-owned, because the obligation is yours.

Consent capture built in

Data handling you can describe.

Encryption in transit and at rest, single-tenant separation with no shared candidate pool, data processing agreements, and right to erasure on request. Resumes are masked server-side, so identifying details are stripped before a report leaves the pipeline.

GDPR-ready
Ship state

Where we actually are, stated plainly.

Here is the split between what runs today, what is in flight, and what we deliberately leave to you.

Live today

Encryption in transit and at rest, role-based access control, and audit logs on every action. Single-tenant separation with no shared candidate pool, exports on demand, and data processing agreements. Right to erasure on request, and server-side resume masking. Greenhouse is available today for ATS sync, in early access.

In progress, not certified

SOC 2 and ISO are in progress. We are not certified today and will not imply otherwise on a procurement call. If your security review needs a current report before signature, tell us early and we will say where the work stands.

On the roadmap

SSO and SAML are on the roadmap, not shipped. Bullhorn, Lever, Workday and Vincere ATS connectors are on the roadmap. Claude is supported today over the OAuth-protected MCP server. ChatGPT support is in beta.

Things we do not do, by design

We do not act as your independent bias auditor, because independence is the point of the requirement. We do not publish your candidate notice for you, because the notice has to be employer-owned. We do not make the hiring decision, and we do not auto-reject anyone.

The full control list, written for a security reviewer rather than a buyer, lives in our technical and organisational measures document. Connector ship-state is on the integrations page.

Procurement

What your legal team will ask, and where the answer lives.

You should not have to book a call to get a document. Everything counsel asks for during a security and privacy review is a public page you can forward before you speak to anyone here.

Who is the processor, and on what basis is candidate data handled?

The first question in almost every procurement review. Deals stall here when there is no signable document behind it.

What technical and organisational measures are actually in place?

Encryption, access control, logging, segregation, retention, sub-processor oversight and incident detection, written for a security reviewer rather than a buyer.

How is a score produced, and can you show your work?

The skills you pick, the weightage you set, the JD answers are scored against, how rounds roll into one readiness score, and where a human sits in the loop.

Which jurisdictions have you written guidance for?

Each guide sets out what applies, who is responsible for what, and where Expert Hire stops and the employer starts.

What are the commercial and contractual terms?

Subscription terms, service commitments, refund position and the general terms of use, all published rather than sent on request.

What happens to candidate data if someone asks for it to be deleted?

Right to erasure on request, retention and deletion practice, and how deletion propagates rather than stopping at the interface.

Before you deploy

Six things to settle before the first candidate.

None of these take long, and all of them cost more to retrofit than to do in the first week. Most deals that stall in legal review stall on one of them.

  1. 01

    Map where the roles actually sit.

    Not where you are headquartered. Where the role is based, and whether a remote or hybrid posting is open to candidates in a regulated city or state. One requisition open to the whole country can pull in several regimes at once.

  2. 02

    Decide what the software is allowed to do.

    Write down, per round, whether a score advances a candidate on its own or whether a person decides. That sentence is what most of these instruments turn on. Answer it before you configure the pipeline, not after a complaint.

  3. 03

    Commission the independent audit if you are in scope.

    Where a jurisdiction requires a bias audit, it requires an independent one. Book it early. Auditor lead time is usually the long pole in a rollout, and the published summary has to be live before the tool is used on candidates in scope.

  4. 04

    Publish the candidate notice.

    It belongs on your careers site, not inside a vendor's product, and it has to be findable. Say the tool is in use, say what it evaluates and what data it collects, and link the audit summary where one is required. We publish an editable template so you are not drafting from a blank page.

  5. 05

    Wire the record trail before the first candidate, not after.

    Confirm who has access to reports and that audit logs are on. Check retention matches the longest period any regulator in scope expects, and that you can export the underlying data without asking us. Reports are always included and never metered.

  6. 06

    Put it in the contract, then re-run this list annually.

    Sign the data processing addendum, attach the technical and organisational measures, and diarise a yearly review. Audits expire, statutes commence, effective dates move. A compliance posture that was correct at signature is not automatically correct a year later.

This is a starting point, not advice. Everything on this page is provided for informational purposes only and does not constitute legal advice. Obligations vary based on how tools are configured and used, and employers are responsible for their own compliance decisions. Confirm your position with qualified counsel, and talk to compliance support if you want us to walk your configuration with you.

FAQ

Questions procurement always asks.

The seven that come up on every compliance call, answered without hedging.

Still unsure how this lands on your setup? Talk to compliance support and we will walk your configuration with you.

Run hiring you can explain.

Structured rounds, a score that traces back to a transcript and code, human review before anyone moves, and a record you can hand to an auditor. Start on the free trial and read the reportcard on your own roles.

30-day free trial with 75 Hire Credits. Card required, nothing charged for 30 days.

Prefer to start with the mechanics? Read how scoring works or see the platform.