TL;DR: HR teams face three overlapping compliance layers when using AI: employment law (NYC LL144, Illinois AIVIA, Colorado SB 189, EEOC guidance), data protection law (GDPR, CCPA, state privacy laws), and labor law (NLRA protections, monitoring consent, EU GDPR Article 22). Each HR AI use case carries different obligations. Resume screening tools require bias audits in NYC. Video interview AI requires consent in Illinois. Performance AI requires documented explanation mechanisms everywhere GDPR applies.
HR teams are among the heaviest users of AI tools in most organizations. Resume screening, interview scheduling, video interview analysis, performance management, compensation benchmarking, employee monitoring, and internal HR chatbots all now have AI-enabled options, and most mid-to-large HR departments have adopted several of them.
They have also, in many cases, adopted them faster than their legal and compliance functions could evaluate the obligations those tools create.
This creates a specific and serious compliance gap. HR decisions, who gets hired, who gets promoted, who gets managed out, what someone is paid, affect the most legally protected domain in employment law. Adding AI to those decisions does not reduce legal exposure. In most jurisdictions, it adds new layers of it.
This guide works through the three compliance layers HR teams face, then walks through the requirements for each major HR AI use case, and closes with a 12-item governance checklist specific to HR contexts.
The three compliance layers HR teams face
Layer 1: Employment law
Employment AI sits at the intersection of anti-discrimination law, which prohibits discriminatory hiring and HR decisions, and a growing set of state and local laws specifically targeting AI in employment contexts.
Federal EEOC guidance makes clear that employers are liable for employment discrimination even when the discrimination results from an AI tool's outputs. You cannot outsource your discrimination liability to your vendor. If your AI resume screener consistently rejects qualified candidates from protected groups at higher rates than comparable non-protected candidates, that is disparate impact discrimination, and it is your legal problem, not your vendor's.
NYC Local Law 144 is the most specific active US law targeting AI in employment. Effective July 2023, it requires NYC employers using Automated Employment Decision Tools (AEDTs) in hiring or promotion decisions to conduct independent bias audits before deployment, publish audit results publicly, and provide advance notice to candidates. See the NYC Local Law 144 AI bias audit employer guide for the specific requirements.
Illinois laws cover two distinct areas. The Artificial Intelligence Video Interview Act (AIVIA) requires disclosure, explanation, and consent before using AI to analyze video interviews. A separate Illinois law covering AI in employment decisions requires notice to candidates when AI is used in hiring decisions.
Colorado SB 189 (effective February 2027) requires developers and deployers of high-risk AI systems in consequential decisions, including employment, to use reasonable care to avoid algorithmic discrimination. Employers deploying AI hiring tools in Colorado will need to demonstrate governance and bias monitoring. The Colorado AI Act SB 189 2027 employer guide covers the specific requirements.
New Jersey has passed requirements for AI disclosure in employment decisions effective in 2026. See New Jersey AI employment law 2026 for details.
Layer 2: Data protection law
HR processes involve deeply personal data: health status (disability accommodations, drug tests, health benefits), financial information (compensation, tax status), identity data, professional history, and often protected characteristics. AI systems processing this data must comply with GDPR, CCPA, and applicable state privacy laws, with consequences substantially higher than for less sensitive data categories.
GDPR Article 22 is particularly relevant for EU-based HR AI. It prohibits purely automated decisions that produce legal or similarly significant effects on individuals without a legal basis, transparency mechanisms, and a right to human review. Performance evaluations, disciplinary AI, and AI-driven termination recommendations affecting EU employees trigger Article 22.
FCRA (Fair Credit Reporting Act) applies when HR teams use third-party data providers to supply background information for employment decisions, whether or not AI is involved. AI tools that pull from external data sources as part of hiring decisions may trigger FCRA disclosure and consent requirements. See FCRA AI hiring disclosure requirements 2026 for the specific obligations.
CCPA/CPRA creates specific employee data rights in California, including access, deletion, and opt-out rights that apply to data used in AI-driven HR decisions.
Layer 3: Labor law
The National Labor Relations Act (NLRA) protects employees' rights to engage in concerted activity: discussing wages, working conditions, and organizing collectively. AI monitoring tools that chill this activity by creating the impression that all employee communications are under surveillance may violate the NLRA regardless of the technology used.
Employee monitoring AI also intersects with state consent laws. Connecticut, Delaware, New York, and other states require that employers notify employees of workplace monitoring. These requirements apply whether you are using traditional monitoring software or AI-powered productivity tracking.
Compliance requirements by HR AI use case
Resume screening and candidate scoring
Resume screening AI filters and ranks candidates based on their application materials. These tools are among the most widely used HR AI applications and among the most legally exposed.
What applies:
- NYC employers: bias audit required before use, results must be public, advance notice to candidates (NYC LL144)
- All US employers: EEOC disparate impact liability if the tool produces discriminatory selection rates
- Third-party data sources: FCRA disclosure and consent requirements
- EU candidates: GDPR Article 22 if the screening result is the primary basis for an automated rejection
- Illinois: notification to candidates that AI is being used
What to do: Obtain the vendor's bias testing documentation. Conduct or commission a disparate impact analysis before deployment. Implement a human review layer for flagged decisions. Provide advance notice to candidates as a standard practice regardless of jurisdiction, since this will be broadly required.
For detailed guidance, see the Workday AI lawsuit HR screening checklist and AI hiring tool compliance US state laws.
Video interview AI analysis
AI tools that analyze video interviews assess candidates based on tone, word choice, facial expressions, and other behavioral signals. These tools face some of the sharpest legal scrutiny of any HR AI category.
What applies:
- Illinois: consent required under AIVIA; AI usage must be disclosed and explained before the interview; raw video cannot be shared with third parties without consent; videos must be deleted within 30 days unless the candidate consents to retention
- Maryland: prohibits using facial recognition for employment decisions in most circumstances
- All US employers: EEOC disparate impact liability and ADA concerns about AI that may penalize candidates based on disability-related communication differences
- EU candidates: GDPR Article 22; Article 9 concerns if facial analysis captures health-related characteristics
What to do: Obtain candidate consent in writing before any AI-analyzed video interview. Disclose specifically what the AI analyzes. Implement a human review step before any hiring decision based on AI video analysis. Do not use facial expression analysis for EU candidates without specific legal basis advice.
Performance evaluation AI
AI tools that analyze employee productivity, code quality, customer interaction quality, or output volume and feed those analyses into performance evaluations are subject to similar requirements as hiring AI.
What applies:
- EU employees: GDPR Article 22 right to explanation and human review for decisions with significant effects; Article 88 (specific rules for employee data processing) may require works council involvement in some EU jurisdictions
- US employees: EEOC disparate impact liability if performance scores systematically disadvantage protected groups
- Union workplaces: NLRA may require bargaining over AI performance monitoring systems before implementation
What to do: Document the evaluation methodology. Ensure every AI-generated performance score has a human reviewer before it is communicated to the employee or used in employment decisions. Provide employees with an explanation of how their score was calculated and a mechanism to contest it.
Employee monitoring and productivity AI
AI tools that monitor keystrokes, website visits, application usage, email patterns, or camera feeds to assess productivity create overlapping consent, NLRA, and GDPR obligations.
What applies:
- State notification laws: Connecticut, Delaware, New York (and others) require advance notice to employees of electronic monitoring; this applies to AI monitoring tools
- NLRA: monitoring that surveils employees discussing wages, working conditions, or organizing activities may violate the NLRA
- EU employees: GDPR legitimate interest balancing test required; monitoring must be proportionate, transparent, and subject to data subject rights; in many EU jurisdictions, works councils must be consulted before implementing monitoring systems
What to do: Provide written notice of monitoring before it begins and update the notice whenever monitoring capabilities change. Do not monitor communications channels where employees are likely to discuss wages or working conditions. For EU operations, conduct a legitimate interest assessment and involve works councils as required.
Compensation benchmarking AI
AI tools that analyze market data and generate compensation recommendations are subject to pay equity laws in an increasing number of jurisdictions.
What applies:
- Colorado Equal Pay for Equal Work Act: pay equity audit requirements apply; AI-generated compensation recommendations must be reviewable for disparate impact
- Illinois and New York City: pay transparency laws intersect with AI compensation benchmarking
- EEOC: compensation disparities that AI benchmarking perpetuates (by anchoring to historical market rates that embed prior discrimination) create disparate impact liability
What to do: Review AI compensation recommendations for disparities by protected group before implementing. Do not use AI benchmarking tools as the sole basis for setting compensation ranges for roles that will be posted in pay-transparency jurisdictions.
HR AI governance checklist
- AI tool inventory complete. List every AI tool used in any HR process, what it does, what data it uses, and which employees or candidates it affects.
- NYC LL144 compliance assessed. If you hire in New York City and use any AEDT, confirm bias audit has been conducted, results are published, and candidate notice procedure is in place.
- Illinois AIVIA compliance confirmed. If you use AI video interview analysis, confirm consent collection and disclosure mechanism is in place before any candidate interview.
- EEOC disparate impact analysis completed. For every AI hiring or HR tool, obtain the vendor's bias testing documentation and conduct or commission an adverse impact analysis.
- GDPR Article 22 review completed. For any HR AI decisions affecting EU employees or candidates, confirm legal basis, explanation mechanism, and human review right are documented.
- FCRA compliance confirmed. For any third-party data used in hiring decisions, confirm FCRA disclosure and authorization procedures are in place.
- Employee monitoring notice provided. Written notice of AI monitoring systems has been provided to all employees and is updated when systems change.
- Human review checkpoints documented. Every AI-generated HR decision (screening, scoring, evaluation, recommendation) has a documented human review step before it affects a candidate or employee.
- Explanation mechanism in place. Employees and candidates can request an explanation of any AI-generated decision that affects them.
- Data minimization reviewed. Confirmed that HR AI tools access only the data necessary for their stated purpose, with no access to health data, protected characteristics, or irrelevant personal information.
- Vendor contracts reviewed. AI vendor contracts for HR tools include appropriate representations about bias testing, data handling, and liability allocation.
- State law review current. Legal review of applicable state employment AI laws completed and calendared for quarterly refresh as new state laws take effect.
For a deeper look at specific state requirements, see the EEOC AI hiring guidance 2026 employer checklist and the AI hiring tool compliance US state laws overview.
Data that HR AI tools should not access
Regardless of what an AI vendor claims their tool does or does not use, HR teams should apply data minimization as a governance principle. Do not give AI tools access to:
- Health information, disability status, or medical history
- Pregnancy status or family planning information
- Genetic information
- Financial information beyond what the role requires (salary history where prohibited, debt status, credit history)
- Religious affiliation or belief
- Political affiliation or belief
- Social media content the candidate did not voluntarily submit as part of the application
- Information from internal communications channels (unless for a separate, disclosed monitoring purpose)
If this data is in the system the AI tool accesses, you cannot guarantee the model is not using it. The safest approach is to prevent the data from reaching the tool entirely. See AI data privacy for small teams GDPR CCPA for data minimization principles applicable to HR contexts.
Related reading
- NYC Local Law 144 AI bias audit employer guide
- Illinois AI employment disclosure law 2026
- Workday AI lawsuit HR screening checklist
- FCRA AI hiring disclosure requirements 2026
- EEOC AI hiring guidance 2026 employer checklist
- New Jersey AI employment law 2026
- Colorado AI Act SB 189 2027 employer guide
- AI hiring tool compliance US state laws
- AI data privacy for small teams GDPR CCPA
- AI governance guide for small teams
- AI governance healthcare startups HIPAA 2026
- Minnesota AI legislation 2026 employer compliance guide
- Texas TRAIGA Biometric AI in Hiring: Consent, Audit, and What HR Teams Must
- Starbuck v. Google: AI Defamation Survives Dismissal, Heads to Trial
