HR teams are adopting AI faster than regulators can keep up. That gap doesn’t mean the rules don’t apply. It means employers are responsible for enforcing them internally. As Amanda Frayne, Chief Legal and Compliance Officer at Multiplier, puts it: “Employers have become their own de facto AI regulators, whether they’re ready for it or not.”
Decisions influenced by AI technology, including at the hiring, performance, and termination stages, are still subject to existing laws around discrimination. Countries and jurisdictions are developing laws and frameworks to guide AI-assisted employment processes.
The EU AI Act, NYC Local Law 144, and the National AI Policy Framework in the US all signal that AI legislation is already taking effect or arriving soon.
Companies without one are already at risk. Here is a guide for how to create policies that adapt as regulation tightens.
Building your internal AI governance framework
Companies are responsible for AI-assisted employment decisions whether the legislation is there or not. “The regulation isn’t going to wait for companies to catch up,” explains Frayne. She recommends applying an internal framework that maps existing tools
Below are the seven components Frayne recommends applying.
1. Inventory and classify every AI use case
Before anything else, HR teams need to know where AI is actually being used. Inventory across recruitment, performance, productivity, and HR advisory. Classify each use case by risk. High risk if it influences employment decisions, medium risk if it influences inputs to decisions, and lower risk if it’s a tool for administrative efficiency.
2. Make human-in-the-loop real
Teams need to define when a human reviewer must make an assessment or a decision. AI should not unilaterally decide termination, promotion, or candidate rejection. “If the human can’t explain it, the system’s not compliant,” says Frayne.
3. Build audit trails into the workflow
Every AI-influenced decision should leave a trail that logs four things: what system was used, what input data was relied on, what output was generated, and what the human decided and why. “It’s not documentation for its own sake,” says Frayne. “It’s a litigation defense.” Without it, employers can’t rebut discrimination claims, unfair dismissal claims, or regulatory inquiries.
4. Introduce bias testing as a standard control
Bias testing should happen at three points: before a tool goes live, after deployment, and on a recurring schedule, to catch new bias introduced by model drift.
5. Treat vendors as high-risk dependencies, not tools
Most AI-related legal exposure in HR will come from third-party systems. “You can’t outsource liability,” says Frayne. “If the vendor builds the model, the employer HR team owns the decision.”
6. Align globally but design for fragmentation
Teams should define a global baseline standard that accounts for the EU’s obligations, US discrimination considerations, and other high-standard regulatory environments. “The mistake would be trying to localize everything,” says Frayne. “The correct approach is a global standard plus local overlay.”
7. Separate productivity AI from employment decision AI
AI that helps HR work faster (drafting, summaries, admin) is low risk. AI that influences employment outcomes is legally sensitive.
The defensibility test
Every AI-influenced employment decision should pass a simple internal test before it proceeds. These questions are crucial for establishing defensibility. “If the answer to any of those is no,” says Frayne, “the system should not be used for that decision.”
- Can we explain the decision clearly?
- Can we evidence the outputs?
- Can we show consistent application?
- Can we demonstrate no unjustified bias?
Frayne suggests thinking of AI tooling as a regulated decision infrastructure. “HR teams need to stop thinking of AI as tooling and start treating it as a regulated decision infrastructure. The shift is from ‘can we use this tool?’ to ‘can we defend the decision?’”
What your company is required to do depends on where you operate and where your employees are based.
The regulatory landscape: what actually applies to your company right now
AI regulation isn’t waiting for a single global standard. Depending on where you hire, your obligations may already be enforceable.
Here are a few of the regulations that apply to companies using AI in employment decisions and where your obligations sit, depending on where you operate.
Regulation | Where it applies | What it requires | Who it affects |
NYC Local Law 144 | New York City employers | Annual independent bias audits for any automated employment decision tool (AEDT) used in hiring or promotion. Results must be published. Candidates must be notified. | Employers using AI to screen or evaluate NYC candidates or employees. |
EU AI Act | Providers and deployers of AI-related systems in the EU | Many AI systems used in hiring, promotion, and performance management are classified as high-risk. This triggers obligations around transparency, documentation, and responsible use. | Companies that use AI systems in the EU, place AI systems in the EU market, or use AI outputs in the EU. |
GDPR Article 22 | European Union | Individuals have the right not to be subject to solely automated decisions with significant effects. Employers must be able to provide a meaningful explanation of any automated, AI-influenced employment decision. | Any employer with EU-based employees or candidates |
California Civil Rights Council regulations | California, USA | Prohibits automated decision systems that discriminate on protected grounds. Requires meaningful human oversight with override authority, proactive bias testing, four-year record retention, and reasonable accommodations where ADS may disadvantage protected groups. | Employers using automated decision systems for hiring or personnel decisions in California |
UK ICO guidance | United Kingdom | Employers using AI in employment decisions must comply with UK GDPR Article 22 equivalents, conduct data protection impact assessments, and ensure human review is available. Non-binding but enforceable under UK data protection law. | UK employers using AI tools in employment decisions |
Singapore PDPC framework | Singapore | Model AI Governance Framework recommends human oversight, explainability, and fairness testing for AI in HR. Voluntary but increasingly referenced in procurement and due diligence. | Employers operating in Singapore |
National AI Policy Framework | The United States | National AI Policy Framework recommends that Congress establish a single federal standard for AI regulation and preempt the growing patchwork of state AI laws — including those governing AI in hiring and employment decisions. | Employers operating in the US (though this framework is a set of recommendations, not enforceable law) |
Singapore’s PDPC framework and the United States’ National AI Policy Framework both signal that AI governance is heading toward formal regulation.
While the scope and enforcement approach of these frameworks and regulations vary, there is a common thread. Employers using AI tools to make decisions within their organizations need to apply meaningful human oversight and be prepared to document and defend employee-related outcomes that these tools influence.
These regulations didn’t emerge out of nowhere. They’re a response to how quickly AI has become embedded in HR workflows.
How AI entered HR decisions before the governance frameworks did
AI tools support HR teams in their efforts to gain efficiency, align internal teams, and clarify decision-making. However, the use of this technology has outpaced internal guidance in most cases. This has led to internal use that leaves teams exposed on a few fronts.
- Legal exposure – Depending on where a company is headquartered and has employees, teams can run afoul of emerging and upcoming AI legislation, including NYC Local Law 144 and the EU AI Act.
- Data protection – Candidate and employee data shared with AI tools is subject to GDPR if the data pertains to a person based in the European Union.
- Audit trail gaps – If a candidate or employee challenges a hiring or termination decision based on AI-powered summaries, guidance, or assessment, HR teams need to be able to explain or document why specific decisions were made.
- Vendor contract gaps – Many HR AI vendor contracts disclaim compliance responsibility, meaning that if the use of an AI tool leads to an unlawful or discriminatory outcome, the legal exposure still sits with the employer.
As AI technology becomes more embedded into daily HR workflows, the need for clear guidance, policy, and decision-making frameworks is greater than ever.
Understanding where AI sits in your workflows is the first step. The next step is knowing where the risk actually concentrates.
Where AI enters employment decisions and where risk concentrates
AI risk in HR is unlikely to stem from a single tool that HR teams use in a niche workflow. This technology is embedded across the full employee lifecycle.
- Sourcing and candidate screening – Tools that parse resumes or score candidates pose a risk because they can often replicate patterns of discrimination.
- Candidate assessment tools – Any tool that assesses facial expression, tone of voice, word choice, and eye contact presents a risk, especially when hiring teams themselves cannot explain decisions made on the basis of these analyses.
- Onboarding – Data processing obligations apply, especially for EU-based employees.
- Performance management – Productivity monitoring, performance scoring, and flight risk prediction all carry legal exposure if used to make decisions about promotion, pay, or termination.
An additional driver of risk is that over half of HR professionals in the United States aren’t even aware that these regulations exist, an awareness gap that could expose their employers to significant penalties.
Where risk is highest, documentation matters most. Bias audits are one of the clearest ways to build a defensible record, and some jurisdictions require them.
Bias audits: what they require and who needs one
A bias audit is an independent evaluation of the impact an AI tool has when used in employment decisions, such as candidate screening or promotion. This audit will determine whether the tool’s use creates or leads to discriminatory outcomes.
Depending on where you operate or have employees, a bias audit may be mandatory. Employers covered by NYC Local Law 144, for example, must perform and publish findings where automated employment decision tools (AEDT) are used to “substantially assist or replace discretionary decision-making for employment decisions”. NYC Local Law 144 also requires employers to notify candidates before an AEDT is used in their assessment.
In this instance, the audit must contain:
- An independent auditor
- The source and explanation of the data used
- An analysis of selection rates and impact ratios across sex, race/ethnicity, and intersectional categories
- A summary of results published before the tool is deployed
- Date of the audit and data it is based on
Under NYC law, this bias audit needs to be performed annually.
Outside New York City, bias audits aren’t mandatory, but running one voluntarily builds a defensible record before regulators or candidates come asking.
The EU AI Act does not mandate a bias audit. However, AI tools used in hiring, promotion, and performance management are classified as “high risk” and trigger requirements around human oversight, transparency, and monitoring.
Bias isn’t the only exposure. How employee and candidate data is handled within AI tools carries its own set of obligations.
Data protection and AI: What GDPR and US privacy law require
HR teams handle large amounts of sensitive employee data. From identity verification to Right to Work documentation, using AI tools to store, process, or manage this information requires guardrails that take data protection mandates into account.
Data minimization and purpose limitation
GDPR Article 5 states that data should only be collected for specified and legitimate purposes. If data is being processed or stored for “statistical purposes” like reusing the data to train, test, or improve future hiring tools, this is not a legitimate processing of this data.
GDPR Article 22
GDPR Article 22 protects EU residents from being subject to decisions “based solely on automated processing, including profiling”. This means that companies must be able to provide a meaningful explanation of any AI-influenced, automated employment decision.
US patchwork
While no federal equivalent to GDPR currently exists in the United States, state and local governments are passing their own laws. If you operate in California (and are subject to CCPA/CPRA) or elsewhere that is moving quickly on data protections, it is essential to stay up-to-date on how new guidance will affect the way your HR teams handle, store, and use data going forward.
Much of this risk originates with third-party tools. That makes vendor due diligence a compliance issue, not just a procurement one.
What to demand from your AI HR vendors before you deploy
When use of an AI tool leads to discriminatory outcomes, the employer can still carry legal exposure. Companies often don’t know whether a vendor’s tool was trained on biased data. And because the tool influences the decision, the employer carries the liability regardless.
HR teams can do their due diligence by asking the vendor questions that help assess risk and responsibility.
What to ask before signing or renewing a vendor contract with an HR AI tool vendor:
- What data was the model trained on and how was bias tested during development?
- What happens to candidate data after it’s processed? (Will it be used to retrain the model?)
- What regulations does your tool currently comply with, and how do you handle updates as the law changes?
- What is your liability position if your tool produces a discriminatory outcome?
Before signing a contract with an HR AI tool vendor, consider the following provisions:
- Audit rights – Gives your company the right to request documentation about how the tool works, how it was tested, and how performance is monitored.
- Notification obligations – Requires notification if the tool is materially changed including major evolution of model logic, training data, and scoring or ranking methods.
- Clarity on where liability sits – Asks the vendor to spell out who is at fault in the event of legal action or adverse outcomes.
- Data purposing agreements – Specifies what candidate or employee data can be used for, including whether it can be used to retrain the model.
None of these obligations exist in isolation. And for companies hiring across borders, they can add up.
The global dimension: different rules in different markets
According to Multiplier’s Global Hiring Gap Report, 39% of HR professionals intend to use AI technology to automate aspects of candidate sourcing and screening and a further 38% want to use AI to support compliance processes.
Some employers are operating in markets where AI regulation is still developing. It is up to companies to govern their AI use in employment decision-making when it comes to bias, privacy, and jurisdictional nuance.
Consider this example: If you have employees in California, New York City, and Berlin, Germany — your AI-assisted HR workflows need to account for California’s privacy and automated decision-making rules under CCPA/CPRA, NYC Local Law 144, and the EU AI Act’s high-risk obligations.
This may seem daunting, but not taking action can lead to penalties, liability, and may open your organization up to candidate/employee challenges and legal action.
Speak to a global employment expert today about hiring compliantly with a global lens.
FAQs
Does the EU AI Act apply to companies outside the European Union?
Yes, the EU AI Act can apply to companies outside the EU if they use AI systems in the EU, place AI systems on the EU market, or use AI tools that support recruitment, hiring, promotion, performance management, or worker monitoring involving EU-based candidates or employees.
What should HR teams ask AI vendors before deploying their tools?
Before deploying any AI HR tool, ask your vendor what data the model was trained on, how bias was tested during development, and what happens to candidate data after it's processed. Get clarity on which regulations the tool complies with and where liability sits if the tool produces a discriminatory outcome.
What does GDPR Article 22 require for AI employment decisions?
Article 22 gives EU residents rights around decisions based solely on automated processes that have significant effects. Employers should be careful about using AI to make decisions that take place in the employee lifecycle without meaningful review.
Does Title VII apply to AI hiring tools?
Title VII prohibits employment discrimination regardless of whether the decision was made by a human or an algorithm. If an AI hiring tool produces discriminatory outcomes against a protected group, the employer carries the liability.