Back to Blog

    AI Hiring Compliance: Why the Quiet Period May Be Ending 

    By Antony Marceles·

    Most AI hiring compliance conversations rest on a quiet assumption: that the market has worked this out. Vendors mention audits. Legal has presumably checked. 

    The published evidence is thinner than that. None of this is legal advice, but I would treat it as a reason to check your file. 

    What 391 Employers Actually Published 

    Since July 2023, New York City’s Local Law 144 has required employers using an automated employment decision tool to run an independent bias audit, publish a summary, and notify candidates in advance. Researchers measured what followed. 

    In Null Compliance, presented at the 2024 ACM FAccT conference, 155 investigators checked 391 employers and found 18 with a published bias audit and 13 with a transparency notice. 

    The explanation matters more than the count. Because the law leaves employers wide discretion over scope, the researchers could not determine whether it applied to many of the employers checked. Silence therefore cannot be read as non-compliance, a condition they named null compliance. 

    Why That Silence May Not Stay Safe 

    For two years, that looked like safety in numbers. Then the regulator’s performance was audited. 

    The New York State Comptroller’s December 2025 audit found the enforcing agency’s system for securing compliance ineffective. The agency had reviewed 32 companies and found one instance of non-compliance. Comptroller auditors applying the agency’s own procedures to the same 32 identified at least 17 potential violations. Two complaints arrived in two years. Penalties under the law run from $500 to $1,500 per violation, per day. The agency has since committed to most of the recommendations, which include more proactive investigation. 

    That is a commitment to act, not evidence that enforcement has intensified. But the gap is now documented by the state and acknowledged by the body that would have to close it. 

    The Exposure Was Never Only About Publication 

    A self-assessment that a tool sits outside scope helps only if it is correct and written down. In a complaint, the questions become who decided, on what basis, and when. An informal judgment nobody recorded is hard to rely on later. 

    That exposure does not wait for a regulator. In Mobley v. Workday, a federal court let discrimination claims proceed on the basis that the complaint plausibly alleged Workday acts as an agent of its client employers, and granted preliminary certification of an age-based collective. Nothing is decided on the merits. Workday was also ordered to identify employers that had enabled its AI screening features, expanding discovery into which employers used the relevant features. 

    The calendar elsewhere moved, though the direction did not. Illinois amended its Human Rights Act effective January 1, 2026, and the and the EU’s Digital Omnibus, in force since July 2026, deferred its high-risk employment obligations to December 2, 2027. 

    A Practical Control Framework Has Three Parts 

    These regimes do not impose identical requirements, but a workable internal control set covers three: disclose that automation is used and what it assesses, document per-candidate evidence of what was evaluated, and demonstrate consistency across candidates for a role. 

    The third is where I see the most work outstanding, and it has little to do with software. Four interviewers choosing their own questions and keeping private notes have nothing comparable to produce. That gap sits there whether or not AI touches your funnel, so a governance review that stops at the vendor list will miss it. 

    The vendor list still matters, though. Ask each vendor for its independent bias audit and the impact ratios behind it, not just a compliance badge. A tool that has been tested across real candidates gives you evidence you can point to; a claim does not.

    Make the Record a By-product 

    One artifact does much of the work across all three: a documented, consistent assessment record. It is easier to produce when it falls out of how interviews are run than when someone assembles it afterward. Hence agreeing the assessment criteria before candidates are assessed, scoring against them during the interview, keeping the evidence behind each score, and leaving the decision itself with a person. That is the design we built Relevana around: a Blueprint the hiring manager approves, recruiter-led interviews, an Interview Report that holds the evidence, and humans making every hiring decision. We also had it tested. Relevana’s independent Local Law 144 bias audit, conducted by Asenion across 5,000 candidates, found no evidence of disparate impact.  

    Whether a tool falls in scope is a question for counsel. Showing what you asked, what you scored, and who decided is a process question you can settle now. 

    Eighteen audits out of 391 was never evidence the requirements were unenforceable. It was a snapshot of a lightly enforced moment, now measured and formally challenged. For more on keeping judgment with people while preserving a clear evidence trail, read Human-Led Interview Intelligence: Solving the Signal Crisis.