Home AI Foundations for HR Teams What NYC Local Law 144 and the EU AI Act Mean for Your Automated Hiring Tools

What NYC Local Law 144 and the EU AI Act Mean for Your Automated Hiring Tools

Two very different regulatory regimes now govern the AI in your recruiting stack — here's what each actually requires of you, in plain terms.

By Theo Brandt, a former talent-acquisition lead who now trains HR teams on AI · Published 18 June 2026 · 9 min read · Reviewed against our editorial standards

ADVERTISEMENT

If your recruiting stack scores, ranks, or filters candidates automatically, two regulatory regimes now sit on top of it: New York City's Local Law 144 and the European Union's AI Act. They come from different legal traditions, ask for different things, and trip up teams in different ways. If you hire in either place — and most teams reading this hire in both — you need a working mental model of each.

I'll keep this practical. This is not legal advice, and the details below are the kind of thing you confirm with counsel before you rely on them. But you can't ask counsel good questions if you don't understand the shape of the rules.

NYC Local Law 144: the narrow, specific one

Local Law 144 has been in force and enforced since 2023. It's narrow on purpose. It regulates a specific thing it calls an Automated Employment Decision Tool (AEDT): a tool that uses machine learning or similar techniques to substantially assist or replace a hiring or promotion decision for a role based in New York City.

Three obligations sit at its core:

The practical friction points I see most:

First, "substantially assist" is doing a lot of work. A tool that ranks candidates and a recruiter who reliably works the list top-down may well fall in scope even if a human technically makes the final call. Teams talk themselves out of coverage too easily here.

Second, the audit depends on data you may not have. Impact ratios require demographic data. If you don't collect it, or your vendor doesn't retain enough historical scoring data, the auditor may have to rely on test data — which is permitted in some circumstances but weaker. Sort out data availability before you commission the audit, not during.

Third, vendors don't make you compliant. A vendor can hand you an audit for their tool in general, but the notice and the public posting are on you, the employer. Plenty of teams assume the vendor covered everything and discover otherwise.

ADVERTISEMENT

The EU AI Act: the broad, risk-tiered one

The AI Act is a different animal — a horizontal law covering AI across the whole economy, sorting systems into risk tiers. It entered into force in 2024 and phases in over several years, with obligations landing on a staggered timeline rather than a single switch-flip date.

What matters for HR: AI systems used for recruitment and for employment decisions are classified as high-risk. That covers tools that target job ads, screen or filter applications, and evaluate candidates — as well as systems used after hire for promotion, task allocation, and monitoring. High-risk is the second-strictest tier, below only the handful of outright banned uses.

Note one thing that is in the banned tier and touches hiring: systems that infer emotions in the workplace are prohibited, with narrow exceptions. If a vendor is selling you "emotion detection" in video interviews for the EU, that's a red flag, not a feature.

The Act splits duties between providers (the vendors who build the system) and deployers (you, the employer using it). Most of the heavy engineering burden — risk management, data governance, technical documentation, a CE-style conformity assessment — sits with the provider. But deployers carry real obligations of their own, and this is where HR teams need to focus:

There's also a broader transparency baseline arriving across the Act: people should generally know when they're interacting with AI, and certain AI-generated content should be disclosed. For recruiting, the safe posture is simple — tell candidates when AI is involved.

ADVERTISEMENT

How the two compare, and how to think about both at once

Local Law 144 is disclosure-and-audit: prove your tool doesn't produce disparate impact, post it, warn candidates. It cares intensely about one thing — bias measured as impact ratios — and says little about the rest.

The EU AI Act is governance-and-accountability: build, document, oversee, and monitor the whole lifecycle, with duties split between vendor and employer. Bias is in there, but so are documentation, human oversight, logging, and transparency.

A tool can satisfy one and not the other. A vendor's polished EU conformity documentation doesn't produce your NYC bias-audit summary. A clean NYC audit doesn't establish the human-oversight and monitoring practices the EU expects. Don't let one green checkmark stand in for the other.

ADVERTISEMENT

A starting checklist

  1. Inventory what you run and where. List every tool that scores, ranks, filters, or targets, and map it to the jurisdictions you hire in. You can't comply for a system you forgot you had.
  2. Classify honestly. For each tool, ask: is this an AEDT under 144? Is it high-risk employment AI under the EU Act? When in doubt, assume yes and confirm with counsel.
  3. Pin down data availability for demographic-based auditing before you commission anything.
  4. Get the paper from vendors in writing — their bias audits, their EU technical documentation and instructions for use, and clarity on which duties they're covering versus leaving to you.
  5. Own the deployer duties yourself — candidate notice, public posting, human oversight, monitoring, logging. These don't transfer.
  6. Set a recurring cadence. The NYC audit is at least annual, and EU obligations are ongoing. Compliance here is a subscription, not a one-time purchase.

Regulation in this area is moving. Other U.S. states and localities have their own rules landing, and EU timelines phase in over time, so treat the specifics above as a snapshot to verify rather than settled ground.

This is general information for HR practitioners, not legal advice. Requirements, effective dates, and enforcement practice change and vary by jurisdiction — confirm your specific obligations with qualified employment counsel before relying on any tool.

compliancelocal-law-144eu-ai-actregulation

Put this into practice

Work out what an AI model actually costs per month from your token usage, and compare the major models side by side.

Open the AI API Cost Calculator →

A note on shelf life. AI products change fast. This guide deliberately focuses on the parts that stay true — how to judge a tool, what the trade-offs are — rather than ranking products that will have changed by the time you read it. Prices and feature claims should always be checked against the provider before you rely on them.

ADVERTISEMENT