AI Hiring Laws 2026: Your Rights as a Candidate (EU AI Act, NYC Local Law 144 & More)
AI hiring laws in 2026 have moved from theoretical policy debate to something candidates run into directly: a notice buried in an application form, an automated rejection with no human explanation, or a video interview scored by software you never agreed to. If you've applied for more than a handful of jobs recently, you've almost certainly been evaluated by an automated system at some point in the process — over 75% of large employers now use AI-powered applicant tracking systems to filter resumes before a recruiter ever sees them. This guide walks through what the major AI hiring laws worldwide actually require in 2026, what rights that gives you as a candidate, and what to do when you suspect an automated system rejected you unfairly.
This is general information to help you understand your options, not legal advice — if you believe you've been harmed by an unlawful hiring practice, consult an employment attorney in your jurisdiction.
Why this matters more in 2026 than it did two years ago
AI use across HR tasks climbed to 43% in 2026, up from just 26% two years earlier, and that adoption curve has finally caught regulators' attention. The laws below split into two categories: comprehensive rules that treat hiring AI as inherently "high-risk" and regulate it broadly (the EU AI Act), and narrower, US-style laws that target specific practices — bias audits, video-interview analysis, or automated decision transparency — without regulating AI use in employment as a whole category.
The EU AI Act: the world's broadest AI hiring regulation
The EU AI Act classifies AI systems used in employment-related decisions as high-risk by default — covering recruitment and candidate-selection tools, performance evaluation, task allocation, worker monitoring, and decisions on promotion or termination. That scope is broad enough to capture nearly every modern resume-screening, candidate-matching, and scoring tool in active use.
For employers deploying these systems, obligations include mandatory risk assessments, technical documentation, bias testing, human oversight, transparency disclosures to affected candidates, and continuous monitoring, with logs retained for at least six months. Penalties for non-compliance are steep: up to €15 million or 3% of global annual turnover for high-risk system violations, rising to €35 million or 7% of turnover for outright prohibited practices.
Timeline note for 2026: the original compliance deadline for high-risk AI obligations in employment was August 2, 2026. As of mid-2026, the EU Council and Parliament reached a provisional agreement to delay this to December 2, 2027 as part of a broader "Digital Omnibus" simplification package — but that delay only takes effect if it's formally adopted before the original deadline. If the Omnibus isn't finalized in time, the original August 2026 obligations apply as written. Candidates in the EU should treat both dates as live until the Omnibus is formally confirmed.
What this means for you as a candidate in the EU: you're entitled to a clear notice when a high-risk AI system is involved in a decision about your application, a channel to seek explanation or human review, and — under GDPR Article 22, which predates and works alongside the AI Act — the general right not to be subject to a decision based solely on automated processing that has a significant effect on you, such as a fully automated rejection, unless narrow exceptions apply.
United States: a patchwork of state and city laws
Unlike the EU's single comprehensive framework, the US regulates AI hiring through a growing patchwork of state and city laws, each with a different scope.
NYC Local Law 144 (the AEDT law)
New York City's Local Law 144 has been in force since 2023 and actively enforced since July 2023. It requires that any Automated Employment Decision Tool (AEDT) used to substantially assist or replace a human hiring decision undergo an independent bias audit, with a summary of results published publicly. Employers must also give candidates advance notice that an AEDT will be used and must offer an alternative evaluation process or accommodation on request. Penalties are modest by design — $500 for a first violation, $500-$1,500 for each subsequent one — but the disclosure and audit requirements themselves are the more meaningful protection: they force employers to document what their tools actually measure.
Illinois AI Video Interview Act
Illinois has regulated AI-analyzed video interviews since 2020, making it one of the earliest laws in this space. Employers using AI to evaluate a candidate's recorded video interview must notify the applicant in advance, explain in general terms how the AI works and what characteristics it evaluates, and obtain the candidate's written consent before conducting the AI-analyzed interview. Candidates can decline to be evaluated by AI without being automatically disqualified, though in practice enforcement of this alternative-path requirement varies.
Colorado AI Act
Colorado's comprehensive AI Act extends coverage to employment starting June 30, 2026, treating AI systems that are a "substantial factor" in consequential employment decisions as High-Risk AI Systems (HRAIS). Deployers must implement a documented AI risk management program, conduct and publish annual impact assessments, post a public statement describing the tool's use and discrimination-risk management, and give candidates direct notice of the type of system used, the decisions it informs, and any adverse decision it contributed to.
The broader state landscape
Beyond these three, dozens of additional state bills addressing AI in employment have been introduced or passed across the US as of 2026, covering everything from resume-screening transparency to worker-monitoring disclosure. If you're job hunting across multiple US states, assume the specific protections available to you vary meaningfully by both the state you're applying in and the state the employer is headquartered in — check your state's current law rather than assuming NYC or Illinois-style protections apply everywhere.
What these laws do and don't cover
It's worth being precise about the limits here, because the coverage gaps are exactly where candidates get caught off guard:
- Most laws regulate disclosure and auditing, not the underlying decision. An employer can generally still use an AI tool that rejects you, as long as they've met notice and audit obligations — these laws create transparency and process requirements, not a guarantee of a favorable or even human-reviewed outcome in every case.
- "Substantially assists" thresholds are fuzzy. Several laws (NYC's especially) only apply once an AI tool crosses a threshold of influencing the decision, which leaves employers room to argue a given tool falls just under that bar.
- Enforcement is uneven. NYC's Local Law 144 penalty structure is genuinely modest, and Illinois' law relies heavily on individual complaints rather than proactive audits — meaning the practical protection often depends on candidates actually knowing their rights and asking questions.
- Cross-border remote hiring complicates jurisdiction. If you're in the EU but applying to a US-headquartered remote employer, or vice versa, which law actually governs the hiring decision is not always straightforward and can depend on where the decision is made, where you're resident, and the employer's own compliance posture.
What you can actually do as a candidate
- Ask directly whether AI is used in the process. Under NYC, Illinois, Colorado, and (once in force) EU AI Act rules, you're entitled to know. Asking your recruiter "is any part of this process automated or AI-assisted?" is a reasonable, increasingly normal question — not an adversarial one.
- Request the alternative process where one exists. NYC's law explicitly requires an alternative evaluation option on request; Illinois' law lets you decline AI video analysis. Use these rights if you're uncomfortable with automated evaluation, particularly for accessibility or accommodation reasons.
- Optimize for what the system actually measures, not just a human reader. Whether or not you exercise your right to an alternative process, most resumes still pass through some form of automated keyword and skills matching before a human sees them. Running your resume through ClavePrep's ATS checker shows you what an automated system is likely to flag or miss before you submit it.
- Document unusual or unexplained rejections. If you're rejected immediately after an AI-scored video interview or automated assessment with no further contact, and you believe the outcome doesn't reflect your actual qualifications, keep records — the notice you received, the date, and the tool used, if disclosed. This matters if you later want to file a complaint or consult an attorney.
- Practice for the specific format, not just the content. If you know a video interview will be AI-scored, factors like pacing, clarity, and eye-contact-adjacent camera behavior may matter more than they would in a live conversation with a flexible human interviewer. ClavePrep's AI mock interview tools let you rehearse in a similar format so the evaluation medium itself isn't the thing that trips you up.
For a deeper look at how AI screening actually works in practice — not just the legal framework around it — see our guide on beating AI interviews and how ClavePrep's tools map to real screening formats.
Common mistakes candidates make
- Assuming "AI hiring laws" means AI can't reject you. These laws create transparency and process obligations, not a right to a favorable outcome or guaranteed human review in every jurisdiction.
- Not asking about AI use at all. Many candidates never ask, assuming it's not their place to — but in jurisdictions with disclosure requirements, employers are obligated to tell you, and asking directly is a legitimate, low-risk question.
- Ignoring the specific jurisdiction's rules. Protections in NYC, Illinois, Colorado, and the EU are meaningfully different from each other — what applies to a friend's experience in a different state or country may not apply to yours.
- Skipping ATS-level resume optimization out of principle. Even with strong disclosure laws in place, most hiring pipelines still route through some automated first pass. Treating that as a technical filter to pass, not a moral objection to win, is the more effective strategy.
Sources
- EU Artificial Intelligence Act — official text (EUR-Lex)
- NYC Department of Consumer and Worker Protection — Local Law 144 (AEDT)
- Illinois General Assembly — Artificial Intelligence Video Interview Act
- Colorado General Assembly — Colorado AI Act (SB 24-205)
Frequently asked questions
Can an employer legally reject me using only an AI tool?
In most jurisdictions with AI hiring laws today, yes — as long as required disclosures, bias audits, or alternative-process offers are met. The EU's GDPR Article 22 is a partial exception, giving a general right not to be subject solely to automated decisions with significant effects, subject to specific carve-outs.
How do I know if a company used AI to evaluate my application?
Ask directly. In NYC, Illinois, and (from June 2026) Colorado, employers are legally required to disclose AI or automated-tool use in specific circumstances; in practice, asking your recruiter directly is the fastest way to get a clear answer regardless of jurisdiction.
Does the EU AI Act apply to me if I'm applying to an EU company from outside the EU?
Generally, the EU AI Act's employment provisions are triggered by where the AI system is deployed and where the affected person is located, so if you're applying from outside the EU to an EU-based role, the specifics can vary — check with the employer or, if in doubt, an employment law professional in the relevant jurisdiction.
What should I do if I think an AI tool rejected me unfairly?
Document what happened — the notice you received (if any), the date, and any tool name disclosed — and consider requesting the alternative evaluation process where your jurisdiction guarantees one. If you believe you were subject to discrimination, consult an employment attorney familiar with AI hiring law in your specific location.
Is NYC Local Law 144 still in effect in 2026?
Yes, it has been in force since 2023 and remains actively enforced by the NYC Department of Consumer and Worker Protection as of 2026.
Does the Colorado AI Act apply to all employers in Colorado?
It applies to deployers and developers of AI systems that are a substantial factor in consequential employment decisions, starting June 30, 2026 — smaller employers and lower-stakes tools may fall outside its high-risk classification, so scope depends on the specific system and decision involved.
Can I opt out of an AI-analyzed video interview?
Under Illinois' AI Video Interview Act, yes — you can decline AI analysis of your recorded interview, and the employer cannot use your refusal alone as grounds for exclusion, though you should still expect to complete some form of interview through an alternative method.
Will the EU AI Act's hiring rules definitely take effect in December 2027 instead of August 2026?
As of mid-2026, that delay is a provisional political agreement between the EU Council and Parliament, not yet fully finalized. If the underlying Digital Omnibus package isn't formally adopted before August 2, 2026, the original deadline and obligations apply as originally written — so treat the December 2027 date as likely, not guaranteed, until formal adoption is confirmed.
The direction of travel across every one of these laws is the same: more disclosure, more auditing, and more candidate recourse than existed even two years ago. Knowing which rules actually apply to your specific situation — and asking direct, reasonable questions of recruiters — is the most practical thing you can do with that shift right now.
