· Neha Chandra · Playbooks · 17 min read
AI Hiring Laws for Staffing Agencies in 2026: What NYC, Illinois and Colorado Now Require
Automated screening is now regulated. Here is the plain-English guide to NYC Local Law 144, Illinois HB 3773, the AI Video Interview Act, Colorado's delayed AI law and the federal rules, with the exact candidate notices you can copy and use today.

If your recruiting software scores, ranks, or filters candidates with AI, and you place workers in New York City, Illinois, or Colorado, you are already inside the reach of at least one AI hiring law, whether you know it or not. The obligation usually sits on you, the employer or the staffing agency, not on the vendor who built the tool. New York City has enforced a bias-audit requirement since July 5, 2023. Illinois amended its civil rights law to cover AI on January 1, 2026, on top of a video-interview law from 2020. Colorado’s AI law keeps getting pushed back but is still coming. And federal anti-discrimination rules apply to an algorithm exactly the way they apply to a human recruiter. This is the guide to what each law requires, how agencies get caught, and the candidate notices you can copy today so your automation stays fast and legal.
Key takeaways
- NYC Local Law 144 is live and enforced. Use an automated employment decision tool on NYC candidates and you need an annual independent bias audit, a public summary on your site, and 10 business days’ notice to candidates. Penalties run from $500 to $1,500 per day (NYC DCWP).
- Illinois now covers AI twice. HB 3773 (January 1, 2026) bans AI with a discriminatory effect, requires notice, and forbids zip code as a proxy. The older AI Video Interview Act has required notice, consent, and 30-day deletion since 2020.
- Colorado is delayed, not dead. SB 24-205 was replaced by SB 26-189, pushing the effective date to January 1, 2027 (Hunton).
- The vendor’s compliance is not yours. Under Title VII, an agency can be liable for a discriminatory tool even when an outside vendor built and ran it (EEOC).
- Notice is cheap; penalties are not. Disclosure costs a few messages. Getting NYC wrong can cost six figures over one non-compliant year.
Table of contents
- Why this landed on your desk in 2026
- What non-compliance actually costs
- The AI hiring law wave, 2020 to 2027
- NYC Local Law 144: the one already being enforced
- Illinois: two laws, one state
- Colorado: delayed, reshaped, still coming
- The federal floor: Title VII and FCRA
- What each jurisdiction requires, side by side
- Steal these: the candidate notices you can use today
- How this plays out for a solo, mid, and large desk
- How agencies actually get caught
- Common objections, answered
- FAQ
Why this landed on your desk in 2026
For years, “AI in hiring” was a vendor pitch, not a legal category. That changed. The tools staffing agencies run every day, resume rankers, chat screeners, voice agents, video-interview analysis, all issue a score or recommendation that “substantially assists or replaces” a human decision, the exact language regulators now use to define what they govern. And it matters more in staffing because you screen at volume. The American Staffing Association counts roughly 27,000 US staffing and recruiting companies employing around 2.2 million temporary and contract workers in an average week in 2024 (ASA). A tool that quietly filters out a protected group does it to thousands, and at that scale a small skew becomes a pattern a regulator can see. Most small agencies are not deliberately breaking these rules; they are running an AI feature their software turned on, in states with laws they never read. The fix does not require a compliance department, just knowing which laws touch you and wiring a few disclosures into cadences you already run.
What non-compliance actually costs
Start with the number. New York City’s Department of Consumer and Worker Protection can fine an employer or employment agency $500 for a first violation of Local Law 144 and up to $1,500 for each additional day of non-compliance (NYC DCWP). The “per day” clock runs while the tool is in use, so a tool you run non-compliant for a full quarter is not a $500 problem.
Money is only the first cost. A bias claim is a lawsuit, not a fine, and it names your agency in a public filing that clients read, which moves a req to another desk before the verdict lands.
The AI hiring law wave, 2020 to 2027
There is no single federal AI hiring statute. What you have is a rolling wave of state and city laws, each with its own trigger and its own paperwork. Here is the timeline that matters to a recruiter. The oldest law is narrow (video interviews), the newest ones are broad (any AI that affects a hiring decision), so treating this as a one-time NYC problem is a mistake.
NYC Local Law 144: the one already being enforced
This is the law with teeth today. Local Law 144 applies when you use an automated employment decision tool (an AEDT) to screen candidates who live in New York City. The DCWP defines an AEDT as a computational process from machine learning or statistics that produces a score, classification, or recommendation used to “substantially assist or replace” human decision-making in hiring or promotion (NYC DCWP). A resume ranker that sorts applicants by fit score is squarely inside it, and so is a chatbot that auto-advances or auto-rejects.
If a tool counts as an AEDT, you must do three things. Commission an independent bias audit within the prior year, run by an auditor with no stake in the tool, calculating selection rates across the federal EEO-1 sex, race, and ethnicity categories. Publish a summary of the results on your website. And give candidates at least 10 business days’ notice before the tool is used, with the job qualifications it assesses.
The most common way an agency trips here is assuming the law is the vendor’s problem. It is not. Local Law 144 puts the obligation on the employer and the employment agency using the tool. A vendor can hand you an audit, but you post the summary and give notice. Even with the enforcement gaps a December 2025 state audit found at DCWP (NY OSC), the real exposure is private lawsuits, where the notice you skipped becomes the plaintiff’s first exhibit.
Illinois: two laws, one state
Illinois regulates AI hiring twice, and both apply to positions based in the state.
The newer law, HB 3773, took effect January 1, 2026 and amends the Illinois Human Rights Act. It makes it a civil rights violation to use AI that “has the effect of subjecting employees to discrimination” on the basis of a protected class, across recruitment, hiring, promotion, and discipline. It requires you to notify applicants and employees when you use AI in those decisions, and it specifically bans using zip code as a proxy for a protected class (Morgan Lewis). That zip-code line matters for staffing, because geo-targeting a candidate pool is easy to do without thinking about what a zip code stands in for.
The older law, the Artificial Intelligence Video Interview Act (820 ILCS 42), has applied since 2020 to any employer that asks Illinois applicants to record a video interview and uses AI to analyze it. Before the AI runs, you must tell the applicant AI analysis may be used, explain how it works and the characteristics it evaluates, and get consent. On request, you must delete the video and all copies within 30 days (Littler). The state was still finalizing HB 3773 rules in 2026, so confirm current rule text before leaning on fine detail.
Colorado: delayed, reshaped, still coming
Colorado wrote the first comprehensive US state AI law, and it is the clearest lesson in why you watch effective dates, not headlines. The original SB 24-205, signed in May 2024, aimed at “high-risk” AI systems used in “consequential decisions,” hiring among them, to guard against algorithmic discrimination.
Then it kept slipping. The February 1, 2026 start date was pushed to June 30, 2026, and then a replacement bill, SB 26-189, moved it again to January 1, 2027 while reshaping the law around “automated decision-making technology” that “materially influences” a consequential decision (Hunton). The practical read: nothing is enforceable in Colorado yet and the details are still moving, so do not build around a specific Colorado requirement this quarter. Keep the notice-and-record habits you build for NYC and Illinois, because when Colorado lands it will ask for the same basics: tell people, document your checks, show your work.
The federal floor: Title VII and FCRA
Even where no state AI law reaches you, two federal rules already do.
Title VII of the Civil Rights Act bans practices that create an unjustified adverse impact on a protected group, and that applies to an algorithm exactly as it applies to a hiring manager. In 2023 the EEOC explained that the “four-fifths rule,” where one group’s selection rate falls below 80% of the top group’s, is a rule of thumb for spotting disparate impact, and that an employer can be liable even when an outside vendor built or ran the tool (Littler). The EEOC pulled those documents in 2025 and federal enforcement has cooled, but Title VII itself did not change, and private plaintiffs still bring these claims.
The Fair Credit Reporting Act governs the background-check side. Using a third-party screening company, you must give a standalone written disclosure and get consent before the check, and if you take adverse action on the report, follow the two-step process: a pre-adverse notice with a copy of the report, then a final notice (FTC). Automating the check is fine; automating it in a way that skips the disclosure or the adverse-action pause is a violation, and it is the most common one I see in a staffing workflow. Same discipline as TCPA-compliant recruiting texts: a message that goes out fast is only an asset if the consent behind it is real.
What each jurisdiction requires, side by side
Match this against your footprint.
| Rule | Who it covers | Candidate notice | Audit / records | Penalty exposure |
|---|---|---|---|---|
| NYC Local Law 144 | AEDTs used on NYC candidates | Yes, 10 business days | Yes: independent bias audit + public summary | $500, then up to $1,500 per day |
| Illinois HB 3773 | AI in employment decisions, IL jobs | Yes | No formal audit; no discriminatory effect; no zip-code proxy | Illinois Human Rights Act complaint |
| Illinois AI Video Interview Act | AI analysis of video interviews, IL jobs | Yes, plus consent | Delete video within 30 days on request | Enforcement under state law |
| Colorado AI law (from 2027) | ADMT in consequential decisions | Expected yes | Risk program / impact assessments (details moving) | AG enforcement, not yet live |
| Federal Title VII / FCRA | All employers, nationwide | FCRA disclosure required | No adverse impact; adverse-action steps | Lawsuits, EEOC and FTC action |
The column that matters most for a small agency is the second one. Four of these five rules turn on the same act: telling the candidate. Get notice right everywhere and you have handled most of your exposure before you touch an audit.

Steal these: the candidate notices you can use today
This is the part you can act on this afternoon. Drop these plain-language notices into an application form, an SMS cadence, or an email so disclosure happens automatically at the right moment. They are practical starting templates, not legal advice, so run them past your own counsel and adjust the specifics to your tools.
1. General AI-use disclosure (application form or SMS, use everywhere)
“To respond quickly, we use automated tools, including AI, to help review and organize applications for this role. A member of our team reviews candidates before any hiring decision. Reply STOP to opt out of text updates at any time.”
2. NYC AEDT notice (send at least 10 business days before screening a NYC candidate)
“This role may hire from New York City. We use an automated employment decision tool to help assess candidates for this position, evaluating [job-related skills you list]. You may request an alternative process or an accommodation. A summary of our most recent bias audit for this tool is at [your public audit URL].”
3. Illinois video-interview consent (before any AI-analyzed video)
“This role asks for a recorded video interview, and we may use artificial intelligence to analyze your responses. The AI reviews factors such as [the characteristics your tool evaluates] to assess fit. Please confirm your consent to AI video analysis before you record. You may request that we delete your video and all copies, and we will do so within 30 days.”
4. FCRA background-check disclosure (standalone, before the check)
“As part of considering you for this position, we will obtain a consumer report (a background check) from a third-party screening company. Please sign below to authorize it. If we consider adverse action based on the report, we will first send you a copy of the report and a summary of your rights.”
Two rules make these work. Send the notice before the tool runs, and log the timestamp of every notice and consent against the candidate record, because if a claim comes, “we always send it” is a story and a dated record is proof. Run screening through a system like AI candidate screening in GoHighLevel and the notice becomes the first automated step, stamped and stored automatically.
How this plays out for a solo, mid, and large desk
The same laws land differently by size and footprint. Run the framework for three shops.
The solo contingency recruiter. You place in one or two metros, run no formal scoring engine, and your “AI” is a chat screener and a scheduler. Your exposure is federal and Illinois-shaped, not the NYC bias audit. Add the general AI-use disclosure to your application and first text, use the FCRA disclosure before any background check, and add the consent line if you ever ask for an AI-analyzed video. That is your whole program: do not commission a bias audit you do not need, but do send the notices.
The mid-size agency, 8 recruiters, light-industrial. You run an ATS with AI ranking on and recruit across several states, including a metro touching NYC or Illinois. You are the profile most likely to be non-compliant without knowing it, because a feature screens quietly. Three jobs: confirm whether your ATS ranking is an AEDT for any NYC candidate and, if so, get the audit and post the summary; turn the disclosure notice on for every applicant; and put one person in charge of keeping the audit current.
The large shop, 25-plus seats, multi-state. You almost certainly use an AEDT somewhere and have the volume that makes a skew visible. You need a lightweight program: an inventory of every tool that scores candidates, an annual audit for anything that qualifies, standardized notices across your footprint, and record-keeping that can produce a dated consent for any candidate. This is where a centralized workflow beats a pile of point tools, and the build-versus-buy math rhymes with staffing ATS pricing for 2026: consolidation is a compliance advantage, not just a cost one.
How agencies actually get caught
Watch for these patterns.
The quiet feature. Your ATS shipped AI ranking or sourcing and turned it on by default. You are now using an AEDT and never decided to. Fix: audit your tool settings and know what scores candidates.
The vendor shrug. Your vendor said “we’re compliant,” so you moved on. Their compliance is about their product. Posting the audit summary and sending candidate notice is on you. Fix: treat the vendor’s audit as an input, not the finish line.
The zip-code proxy. You geo-targeted a candidate pool by zip code inside an AI process in Illinois, which is specifically prohibited. Fix: target by role, radius, or job site, not zip code, in any AI screening step.
The after-the-fact notice. You disclose AI once the candidate is already screened, which in NYC misses the 10-business-day rule entirely. Fix: make the notice the first step of the workflow, before the tool runs. Every one of these is a workflow problem, not a legal one, which is the good news.
Common objections, answered
“I’m a small agency. This is for the big players, right?” No. NYC’s law applies to employment agencies of any size using an AEDT on NYC candidates, and the FCRA and Illinois notice rules have no headcount floor. The obligation scales with the tool you use, not your size, and a small shop can fix it in an afternoon.
“My software vendor handles compliance.” They handle theirs. The bias-audit summary has to live on your website, the candidate notice has to come from your workflow, and under Title VII you can be liable even if the vendor built the tool. Ask them in writing which parts they cover and which are yours.
“Won’t all these notices slow me down or scare candidates off?” No, when you do it right. A one-line disclosure inside an application or a text adds a sentence, not a step, and candidates increasingly expect to be told when AI is involved. A candidate discovering after the fact that a bot rejected them is what actually damages your brand.
“The rules keep changing. Why build anything now?” Because the moving parts are the details, not the direction. Every version of every law asks for the same core habits: disclose that AI is used, avoid discriminatory effects, and keep records. Build those habits now and you are ready for whatever state adds a law next.
FAQ
Do AI hiring laws apply to small staffing agencies?
Yes. NYC Local Law 144 applies to employment agencies of any size using an AEDT on NYC candidates, and federal FCRA and Illinois notice rules have no headcount threshold. What matters is the tool you use and the state you recruit in, not your seat count.
What counts as an automated employment decision tool under Local Law 144?
An AEDT is a process built from machine learning, statistics, or AI that produces a score, classification, or recommendation used to substantially assist or replace human decision-making in hiring or promotion. A resume ranker or an auto-advancing chat screener generally qualifies; a tool that only schedules interviews does not.
Do I need a bias audit if my ATS vendor already did one?
Their audit can help, but it does not fully discharge your duty. Under Local Law 144 the agency using the tool posts the public audit summary and gives candidate notice. Confirm the audit covers how you use the tool, and make sure the summary and notice come from you.
Is Colorado’s AI law in effect yet?
No. SB 24-205 was delayed twice and then reshaped by SB 26-189, effective January 1, 2027. Nothing is enforceable in Colorado today, so keep the NYC and Illinois habits rather than building around a specific Colorado rule now.
Can my agency be sued for a discriminatory AI tool the vendor built?
Yes. Under Title VII an employer can be liable for adverse impact from a selection tool even when an outside vendor built or ran it. Federal enforcement has softened, but Title VII is unchanged and private plaintiffs still bring these claims. A vendor indemnity is a private agreement, not a release from your responsibility to candidates.
About the author
Neha Chandra is the Staffing Compliance and Operations Expert behind the Hiring Snapshot. With a background in HR operations and contingent-workforce compliance, she audits every cadence against TCPA, EEOC, and FCRA realities so automation never outruns the rules. This article is general information for staffing operators, not legal advice; confirm the current rules for your states with your own counsel.
Related reading
- TCPA Compliance for Recruiting Texts: The 2026 Rules Every Staffing Agency Must Follow
- AI Candidate Screening in GoHighLevel: How to Qualify Applicants in Seconds
- AI Phone Screening for Recruiters: How Voice Agents Screen and Book Candidates 24/7
- Staffing ATS Pricing in 2026: What Bullhorn, Crelate, Loxo and JobAdder Really Cost
- How to Use GoHighLevel as an ATS: Build a Recruiting Pipeline That Fills Reqs Faster
Want recruiting automation that moves fast without outrunning the rules? See how the Hiring Snapshot works, then get the full snapshot for a one-time $997.



