← All articles
Recruitment AI · 11 min read

Is AI Recruiting Legal in 2026? What Agencies Must Know

AI hiring tools trigger real laws: NYC bias audits, a changed EEOC posture, and new rules in Illinois, Texas, and California. Here is what recruiting agencies must actually do.


Ask a room of recruiters whether AI hiring tools are legal and you will get three different answers, all delivered with total confidence. The truth is messier than any of them. AI recruiting is legal in the sense that no law bans a recruiter from using a language model to screen a CV or draft an email. But the moment that tool influences who gets hired, several real laws start to apply, and most agencies using AI today have no idea which ones cover them.

This is not a hypothetical risk. New York City has been auditing hiring tools since 2023. Illinois and Texas passed new hiring AI laws that took effect this January. California's civil rights regulator has new rules on the books. The EU treats recruitment AI as high risk by default. None of this makes AI recruiting illegal. It makes it regulated, the same way background checks and reference calls are regulated. The difference is that most recruiters know the rules for a background check, and almost none know the rules for an AI screening tool.

This piece walks through what is actually in force right now, what got delayed, and what a small or boutique agency needs to do about it.

Is AI Recruiting Actually Illegal? The Short Answer

No. Using AI to help source, screen, or communicate with candidates is not illegal on its own, in any US state or the EU. What the law regulates is the effect. If a tool systematically screens out candidates based on race, sex, age, disability, or another protected characteristic, that is discrimination, whether a human did it or software did it. The tool does not get a legal pass for being automated. In several jurisdictions, using an automated tool now comes with extra paperwork on top of the underlying anti-discrimination law: audits, notices, and disclosures that did not exist before.

So the honest short answer is that AI recruiting is legal, but using it carelessly is exactly as risky as any other hiring practice that produces a discriminatory result. And in places like New York City, Illinois, and Texas, you now have specific compliance steps layered on top of that basic risk.

NYC Local Law 144: Bias Audits, Notices, and Penalties Explained

New York City's Local Law 144 has been in force since July 2023, making it the oldest AI hiring law most agencies will run into. It applies to automated employment decision tools, or AEDTs: any tool that uses machine learning, statistical modeling, or similar techniques to substantially help or replace human decision-making in hiring or promotion for a role based in New York City.

If you use one, the law requires three things. First, an independent bias audit conducted within the year before you use the tool, calculating selection rates and impact ratios by race and sex, including intersectional categories like Black women or Asian men. Second, a summary of that audit posted publicly, usually on your website. Third, candidates and employees have to be notified at least ten business days before the tool is used on them, with a way to request an alternative process or accommodation.

Penalties are modest per instance: $500 for a first violation, $500 to $1,500 for each one after that. But each violation adds up fast. Every day you use a non-compliant tool without the required notice can count separately, and the New York City Comptroller's own December 2025 audit found that enforcement had been close to non-existent for the law's first two years, July 2023 through June 2025, and issued thirteen recommendations to tighten it up. Read that as a signal, not a reprieve. Weak enforcement now is not the same as no enforcement later, especially once a regulator is on record admitting the gap.

Creo Access

Creo Access is in private beta.

Request access and you'll receive product updates, testing opportunities and launch information.

Request beta access

Where Federal Law Stands After the EEOC Guidance Withdrawal

For years, the EEOC's main public guidance on AI in hiring was two documents: a May 2022 notice on AI and the ADA, and a May 2023 technical assistance document on AI and Title VII's adverse impact standard. Both were pulled from eeoc.gov on January 27, 2025. Nothing has replaced them.

That does not mean federal anti-discrimination law stopped applying to AI hiring tools. Title VII, the ADA, and the ADEA are statutes, not guidance documents, and they remain the law regardless of what is posted on a federal website. What changed is the EEOC's own enforcement posture. An executive order from April 2025 directed federal agencies to deprioritize disparate impact theory, the legal framework most AI bias cases rely on, in favor of harder-to-prove intentional discrimination claims. Then, in June 2026, the EEOC's new enforcement plan for 2025 through 2029 dropped algorithmic and AI-driven discrimination as a stated priority entirely.

In practice, this means an agency using a biased AI tool is less likely to be the target of a federal EEOC investigation than it would have been two years ago. It does not mean the underlying legal exposure disappeared. Private lawsuits are unaffected, and one is already testing new legal ground. Mobley v. Workday, a federal case in California, asks whether an AI vendor itself, not just the employer using its tool, can be held liable as the employer's agent under Title VII and the ADEA. A March 2026 ruling let the age discrimination claim move forward. If that theory holds, it changes who can be sued over a biased screening tool, and it will not just be the software company's problem.

State and local laws also do not move when federal guidance does. New York City still audits. Illinois, Texas, and California still have their own rules, described next.

The State-by-State Patchwork: Illinois, Colorado, California, Texas, and More

This is the part that catches most small agencies off guard: there is no single AI hiring law to check compliance against. There is a growing patchwork, and it depends on where your candidates and clients are.

Illinois HB 3773 took effect January 1, 2026. It amends the state's Human Rights Act to make it a civil rights violation if an employer's use of AI has a discriminatory effect on a protected class, and it requires notifying employees and applicants when AI is used in employment decisions. It also specifically bans using zip code as a stand-in for race or another protected characteristic, a common way bias sneaks into a model indirectly. This is separate from Illinois's older AI Video Interview Act, in force since 2020, which covers a narrower case: AI analysis of recorded video interviews specifically.

Texas TRAIGA, also known as HB 149, took effect the same day, January 1, 2026. It takes a different legal approach than New York or Illinois. Instead of a disparate impact standard, where an unintentional discriminatory result can trigger liability, Texas requires proof of intent to discriminate. That is a meaningfully higher bar to clear, which matters when you are weighing where your compliance risk is actually concentrated.

California moved on two fronts. The Civil Rights Council's Automated Decision Systems regulations took effect October 1, 2025, applying to employers with five or more employees and requiring four years of recordkeeping on how automated tools were used in employment decisions. Separately, a more aggressive bill nicknamed the No Robo Bosses Act was vetoed in October 2025, then reintroduced as SB 947, which is still pending. Worth watching, not yet law.

Colorado's AI Act, once expected to be one of the stricter state laws, has been delayed twice and is now set for January 2027, with its scope narrowed to a disclosure-only regime rather than the audit requirements New York uses.

The pattern across all of these: if you place candidates in New York City, Illinois, Texas, or California, or plan to, you likely already have a compliance obligation right now, not someday. If your business is concentrated elsewhere, check your state directly. This list will be out of date within a year, because more states are drafting similar bills every legislative session.

Where the rules stand right now

New York City

Local Law 144

In force, weakly enforcedSince July 2023

Illinois

HB 3773

In forceSince January 2026

Texas

TRAIGA (HB 149)

In forceSince January 2026

California

FEHC Automated Decision Systems rules

In forceSince October 2025

Colorado

Colorado AI Act

Delayed, disclosure onlyNow January 2027

European Union

EU AI Act, Annex III

High-risk obligations pushed backNow December 2027

The EU AI Act: What It Means If You Place Candidates in Europe

If your agency works with any employer or candidate in the European Union, the EU AI Act treats recruitment and hiring tools as high risk by default. Annex III of the Act specifically names systems used to target job advertisements, filter or evaluate applications, and assess candidates as high-risk AI applications, alongside things like credit scoring and law enforcement tools. That classification brings real obligations for whoever deploys the tool, not just whoever built it: risk assessments, testing for bias, human oversight, and documentation.

The original deadline for these obligations was August 2026. That date has moved. A simplification package called the Digital Omnibus, approved by the EU Council in June 2026 and in force the following month, pushed the compliance deadline for Annex III high-risk systems, which includes recruitment tools, to December 2, 2027. A separate, smaller category of high-risk systems under Annex I now has until August 2028. If you have read that recruitment AI obligations start in August 2026, that is the old date. It is worth confirming directly against the EU's own published timeline before you plan around it, since a deadline that has already moved once can move again.

The practical upshot for a US-based agency: if you are not placing candidates or working with employers in the EU, this does not apply to you yet. If you are, you have more runway than the original date suggested, but the requirements themselves have not gotten lighter, just later.

The dollar penalties are not what should worry a small agency. The bigger exposure is not being able to answer a straightforward question about what your tool does.

What Happens If You Don't Comply

The dollar penalties in most of these laws are, on their own, not what should worry a small agency. New York City's $500 to $1,500 per violation is real money but not existential. The bigger exposure is downstream: an unhappy candidate filing a discrimination complaint, a client asking during due diligence whether your screening process has been audited, or a plaintiff's attorney building a case around a tool that quietly filtered out a protected group at scale. Mobley v. Workday is exactly this kind of case, and it is still working through discovery with no trial date set, which means the legal questions it is testing are still open.

The honest risk is not getting fined for a missing notice. It is not being able to answer a straightforward question, from a candidate, a client, or a regulator, about what your AI tool actually does and how you checked that it does not discriminate.

A Practical Compliance Checklist for Recruiting Agencies

None of the following requires a legal department. It requires knowing what your tools do and writing it down.

Before you rely on any AI hiring tool

  • Know which specific tools in your workflow use AI or automated scoring, not just your ATS as a whole.
  • Check where your candidates and clients are based. Your obligations depend on jurisdiction, not where your agency is registered.
  • If you place candidates for NYC-based roles, get a bias audit done and post the summary before you rely on the tool.
  • Give candidates real notice before an automated tool is used on them, in writing, with enough lead time to request an alternative.
  • Never let zip code, school name, or other easy proxies for race or class quietly stand in for data you are not allowed to use directly.
  • Keep a written record of what each tool does and why you chose it. Documentation is what regulators and plaintiffs' attorneys ask for first.
  • Revisit this list every few months. Three of the laws above changed in the last twelve months alone.

That last point is the real lesson here. This is not a rulebook you read once. It is a moving target, and the agencies that stay out of trouble are the ones that treat compliance as a habit, not a one-time project.

Keep reading