Use-case guide

AI in HR & Hiring

Hiring AI was one of the first areas regulators targeted, and it remains one of the most scrutinised. AI resume screeners, video-interview analysers, and skills-assessment tools are presumed to be high-risk in the EU and a 'consequential decision' system in Colorado. Layered on top of the AI rules, you have decades of anti-discrimination law (Title VII, the EEOC, Equality Act, AGG) that already applied to the human version of these decisions — and applies just as forcefully to the automated version.

For: Talent acquisition, HRIS owners, people-ops leaders, HRTech founders, employment counsel

What's at stake

Hiring is high-risk by default in the EU

Annex III of the EU AI Act specifically lists 'AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter applications and to evaluate candidates' — all high-risk.

Bias claims travel fast

If your model systematically scores one protected group lower than another, you face anti-discrimination liability even without intent. The EEOC has been explicit that Title VII applies to algorithmic hiring tools.

Candidates have rights to know

Under GDPR Art. 22, candidates have a right not to be subject to fully-automated decisions with legal or similarly significant effects. They have a right to obtain human intervention.

New state laws are stacking up

Beyond Colorado, NYC Local Law 144 already requires bias audits for automated employment-decision tools. Illinois, Maryland, and others have laws on video-interview AI.

Regulations that apply

Do

  • ✓Commission an independent bias audit before deployment AND on a recurring basis. NYC LL144 requires annual.
  • ✓Publish a job-posting disclosure that you use AI in screening, in plain language.
  • ✓Give every candidate a route to opt for a non-AI review, and document who reviewed what.
  • ✓Document your training-data sources, model versions, and any updates that change scoring behaviour.
  • ✓For EU candidates: provide meaningful information about the logic involved in the decision (Art. 13(2)(f)).

Don't

  • ✗Don't rely on the 'legitimate interest' GDPR basis for processing candidate data through an AI model — most DPAs view explicit consent or contract necessity as the safer path.
  • ✗Don't deploy a US-trained resume screener in EU hiring without retraining on representative EU data.
  • ✗Don't ship a video-interview AI without first checking it under Illinois 820 ILCS 42 and similar state laws.
  • ✗Don't issue an adverse hiring decision without a human reviewing the rationale — both for legal protection and Colorado/EU compliance.
  • ✗Don't ignore vendor obligations — your AI vendor's failures are still your liability under the AI Act's deployer duties.

Also worth knowing

Beyond the demo set above, watch: NYC Local Law 144 (automated employment-decision tools — bias-audit + notice), Illinois 820 ILCS 42 (video-interview AI), Maryland HB 1202 (face-analysis), and the EU's Platform Work Directive (algorithmic management of workers).

Want a tailored answer?

The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.

Start the wizard →

Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.

Note: this guide was drafted with AI assistance — Anthropic Claude.