The Party No AI Hiring Law Regulates

The Party No AI Hiring Law Regulates

Article Contents

Categories

On May 14, 2026, Governor Jared Polis signed SB 26-189, which repealed and replaced the Colorado Artificial Intelligence Act weeks before the original statute was due to take effect, and moved the operative date from June 30, 2026 to January 1, 2027.

The replacement removed the provisions employers had been preparing for. Gone is the duty of care aimed at preventing algorithmic discrimination. Gone are the deployer obligations to maintain risk management programs and conduct impact assessments, along with certain reporting duties to the Attorney General. What remains is narrower: disclosure and transparency requirements around automated decision-making technology, developer obligations to inform deployers about intended uses, potentially harmful uses, categories of training data, and oversight instructions. The statute preserves limited individual rights, including access and correction and a right to meaningful human review of adverse automated decisions.

The retreat did not happen in isolation. A federal executive order issued in December 2025 identified the Colorado law as excessive state regulation and directed agencies to challenge state AI statutes inconsistent with federal deregulatory policy. On April 9, 2026, xAI sued the Colorado Attorney General on First Amendment, dormant Commerce Clause, vagueness, and equal protection grounds, and the Department of Justice intervened in support. On April 27 the court entered a stipulated order suspending enforcement, an order the Attorney General had joined. The replacement bill was introduced four days later, cleared both chambers within eight days, and was signed on May 14.

Colorado had been the most ambitious attempt at comprehensive state AI regulation in the country. Whether its retreat reflects legislative judgment or federal pressure, the practical result is the same: the duty of care is gone and disclosure survived. That outcome is worth examining alongside what all of these statutes assume about who is doing the automating.

The Shared Premise

The active employment AI regimes diverge on liability standards and converge on something more basic.

New York City’s Local Law 144 governs automated employment decision tools, requiring an annual bias audit and candidate notice. Illinois HB 3773, effective January 1, 2026, amends the Illinois Human Rights Act to bar employers from using AI with a discriminatory effect on protected classes, bar zip code as a proxy for a protected class, and require notice when AI is used in employment decisions. Texas took the opposite approach on the same date: the Responsible Artificial Intelligence Governance Act prohibits developing or deploying an AI system with the intent to discriminate against a protected class, and unequal outcomes absent intent do not violate it. Colorado, under both the repealed statute and its replacement, addresses developers and deployers of systems used in consequential decisions.

Effect in Illinois, intent in Texas, audit and notice in New York City, disclosure in Colorado. The drafting choices are genuinely different. The premise underneath them is not. In every case the regulated conduct is the employer’s. The employer procures a tool, the employer applies it to applicants, the employer owes duties of audit, notice, disclosure, or care. Candidates are the protected class. The statutes are written as consumer protection with the applicant cast as the consumer and the employer as the operator of the machine.

That architecture is coherent where the facts support it. In high-volume sectors that run applicant tracking systems with automated ranking and knockout logic, the employer is unmistakably the automated actor.

The question worth putting to the drafters is whether that description holds across the economy, or whether it describes a particular set of industries and got generalized.

A Sector Where It Does Not Hold

Healthcare offers a clean counterexample, and the numbers are not close.

Incredible Health’s 2026 State of Nursing Report, a national survey of 2,240 registered nurses conducted alongside platform data covering roughly 1.5 million U.S. healthcare professionals, found that 39% of nurses now use AI in their job search. The same report puts the share of healthcare employers using AI in hiring at 4%.

In one of the largest employment sectors in the United States, candidates are roughly ten times more likely to be running an AI-assisted process than the employers evaluating them. Applicants generate resumes, tailor them per posting, and rehearse interviews with voice tools. Hiring managers read those materials, conduct interviews, and make decisions largely by hand.

The two numbers do not measure the same act, and the difference is the point. An employer using AI to rank applicants is making an automated employment decision, which is exactly the conduct these statutes were drafted to reach. A nurse using a chatbot to rewrite a resume is making no decision about anyone. The statutes are right to treat those differently. What no drafter anticipated is that the second behavior would arrive first, at scale, and generate its own set of employer obligations that no statute has described.

The tools involved compound the problem. Among nurses using AI, 65% reach for general-purpose assistants, with Microsoft Copilot at 40%, ChatGPT at 37%, and Gemini at 24%. Only 34% use anything healthcare-specific. A consumer chatbot in a candidate’s hands is not an automated employment decision tool under Local Law 144’s definition, is not covered automated decision-making technology under Colorado’s replacement framework, and is not an employer use of AI under Illinois or Texas law. The definitional architecture of every active statute excludes it. A legislature that wanted to reach candidate-side AI would have to start from a different premise, not amend the existing one.

Every statute described above lands on the party doing less of the automating. The compliance obligation arrives before the conduct it was drafted to reach.

This does not make the laws wrong. Healthcare is one sector, and the asymmetry may narrow. It does suggest that the regulatory frame was built from a subset of employer behavior and will fit unevenly across industries, which has consequences for enforcement priorities and for how counsel advises clients on exposure.

The Unlegislated Side

The same survey shows why this matters now rather than eventually. AI job-search use among nurses runs at 60% for those under 28, 45% for ages 28 to 43, 39% for ages 44 to 59, and 27% for those 60 and older. A 33-point spread across the age range means any employer policy touching candidate AI use touches age.

It runs in both directions, and neither is comfortable. A policy penalizing AI-assisted applications falls hardest on the youngest applicants, who sit outside the ADEA’s protected class, producing an adverse impact with no obvious federal hook. A process that rewards AI fluency, whether by design or through the practical advantage a well-tailored application confers, falls hardest on candidates over 60. That one lands inside the statute.

The more consequential gap is that no state has addressed candidate-side AI at all, and the questions it raises are already live in hiring practice.

Consider what an employer may lawfully do about an application it believes was AI-generated. No state has enacted a disclosure obligation running from candidate to employer. There is no safe harbor for an employer that declines a candidate on suspicion of AI-assisted material, and given that AI detection tools have documented accuracy problems and demonstrated bias against non-native English writers, an adverse action grounded in a detector output carries obvious disparate impact exposure under existing law.

Related questions follow. If an employer deploys verification measures specifically designed to defeat candidate AI use, is that verification method itself an automated employment decision tool subject to audit and notice? If a candidate uses an assistive tool as a disability accommodation, how does a no-AI application policy interact with the ADA? If an employer requires in-person or proctored assessment to establish authenticity, what happens to the accessibility gains that remote hiring produced?

None of this is addressed in Local Law 144, HB 3773, the Texas Act, or Colorado in either version. The statutes were drafted on the assumption that automation is something done to applicants.

What Comes Next

Colorado’s replacement statute directs the Attorney General to adopt implementing rules before the January 1, 2027 effective date, covering post-adverse-outcome disclosures and the consumer rights provisions. Those rules do not exist yet. Under the stipulated order, the state cannot enforce the original act or its successor until fourteen days after the court rules on the preliminary injunction motion, and that motion is not due until rulemaking is final. The practical position is a statute with an effective date, no implementing rules, and a suspended enforcement mechanism. Employers should build toward January 1 anyway, on the straightforward reasoning that the compliance work is documentation and inventory, which takes longer to assemble than the litigation will take to resolve.

For practitioners, the practical guidance in the near term is unglamorous. Outside Illinois, the surviving obligations are largely disclosure, notice, and documentation, which makes the compliance work inventory and recordkeeping rather than algorithmic auditing. Illinois is the exception worth watching, since HB 3773 puts a substantive discrimination standard into the Human Rights Act rather than leaving it to Title VII analogues. Even there the detail remains unsettled. The Department of Human Rights published proposed notice rules in May 2026, withdrew them, and canceled the scheduled hearing, while the underlying statutory obligations stayed in force throughout.

And the first novel dispute in this area is more likely to concern what an employer did about a candidate’s AI than what an employer’s AI did to a candidate. No statute currently governs it.

Tags

Share
Law News Day Staff
Staff at Law News Day.

Other articles

The Party No AI Hiring Law Regulates

In This Article

Article Contents

Categories
Share
Facebook
Twitter
Pinterest
WhatsApp
Telegram
Share
Facebook
Twitter
Pinterest
WhatsApp
Telegram
Add Your Heading Text Here

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Add Your Heading Text Here

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.