AI Candidate-Screening Compliance: Disclosure, Bias Testing and Record-Keeping
Short answer (as at 26 August 2026): if an AI agent scores, ranks or filters candidates, three obligations follow almost everywhere — tell the candidate before you use it, test the tool for adverse impact on a fixed cadence, and keep the records that prove both. New York City’s Local Law 144 is the only regime enforcing all three today. The EU’s high-risk rules for employment AI now apply from 2 December 2027, and Australia’s automated-decision privacy-policy duty starts 10 December 2026.
A screening agent ringing a candidate triggers telemarketing and transparency rules, employment-discrimination law, and statutes written for this exact use case. For the operational side, see how AI screening agents work; this is the compliance half.
This is general information, not legal advice. Employment law is jurisdiction-specific and the deadlines below move; take advice on your own deployment.
Five rulebooks, one screening agent
| Jurisdiction | Regulates AI screening? | Core obligation | Status at 26 August 2026 |
|---|---|---|---|
| European Union — AI Act, Annex III point 4(a) | Yes — a listed high-risk category. | Full high-risk regime on the provider; deployer duties including human oversight. | Deferred to 2 December 2027. Article 50 applies now. |
| New York City — Local Law 144 of 2021 | Yes, if it substantially assists or replaces discretionary decision making. | Independent bias audit within the past year, published summary, 10 business days’ notice. | In force and enforced since 5 July 2023. |
| Illinois — AI Video Interview Act (820 ILCS 42) | Video interviews only. | Pre-interview notice, explanation, consent, deletion on request. | In force since 1 January 2020. |
| Illinois — Human Rights Act as amended by HB 3773 | Yes — all employment decisions. | No discriminatory effect on protected classes, no ZIP-code proxy, notice of AI use. | In force since 1 January 2026. |
| Colorado — SB 26-189 | Yes — employment is a consequential decision. | Advance notice, post-decision disclosure, consumer rights. | Signed 14 May 2026, effective 1 January 2027. |
| Australia — Privacy Act 1988, APPs | Indirectly — no AI-hiring statute; the APPs apply. | APP 1.7–1.9: privacy policy must disclose the personal information used in significant automated decisions, and the decisions made. | Commences 10 December 2026. OAIC’s final guidance not yet published. |
EU: employment is Annex III point 4 — but the clock moved
Annex III point 4(a) covers “AI systems intended to be used for the recruitment or selection of natural persons, in particular … to analyse and filter job applications, and to evaluate candidates”. Point 4(b) adds promotion, termination and performance monitoring. That wording comes from the AI Act Explorer, an unofficial mirror, because EUR-Lex — the official text — was unreachable when this was checked.
What changed is when. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — deferred the stand-alone Annex III obligations from 2 August 2026 to 2 December 2027. It left Article 50 alone, so an EU candidate must still be told they are interacting with an AI system (see what applies after the Omnibus). Treat December 2027 as a build deadline.
New York City: the regime that already bites
NYC’s Department of Consumer and Worker Protection has enforced Local Law 144 since 5 July 2023. A tool is caught only where its output substantially assists or replaces discretionary decision making, which DCWP’s final rules define as relying solely on a simplified output, weighting it above every other criterion, or using it to overrule human conclusions. An agent that only transcribes sits outside: a simplified output “does not refer to the output from analytical tools that translate or transcribe existing text”. Score the candidate and sort by that score and you are inside.
Inside, three things bind. The audit must be run by an independent auditor — not anyone who “is or was involved in using, developing, or distributing the AEDT” — and must calculate selection rates and impact ratios for each sex, race/ethnicity and intersectional category. Section 5-301(a) prohibits use “if more than one year has passed since the most recent bias audit of the AEDT”. The results summary must be published before use, and DCWP’s AEDT FAQ is specific on notice: “Provide the notice 10 business days before using an AEDT”. Buying rather than building shifts nothing: “Employers and employment agencies are ultimately responsible for ensuring a bias audit was done before using an AEDT.”
Illinois: two laws, not one
The AI Video Interview Act, in force since 1 January 2020, reaches only AI analysis of video interviews. Under 820 ILCS 42/5: notify applicants beforehand, give them information “explaining how the artificial intelligence works and what general types of characteristics it uses to evaluate applicants”, obtain consent, delete on request within 30 days. (The Illinois General Assembly’s site was unreachable when this was checked, so that text is quoted from FindLaw’s codes database, a secondary source.) HB 3773 is broader, amending the Illinois Human Rights Act from 1 January 2026: as law firm Duane Morris put it in a client alert, it “prohibits an employer from using AI if it has a discriminatory effect on employees based on protected classes or uses ZIP codes as a proxy for a protected class”.
Colorado and Australia
Colorado’s SB 26-189 (signed 14 May 2026, effective 1 January 2027) makes employment a consequential decision under a notice-and-disclosure regime, not a NYC-style audit regime.
Australia has no AI-hiring statute. From 10 December 2026, APP 1.7–1.9 bite where an entity has arranged for a computer program to make, or substantially and directly help make, a decision that could reasonably be expected to significantly affect a person’s rights or interests — rejecting a job application clears that bar. The OAIC’s May 2026 ADM issues paper says it “intends to release guidance by September 2026, prior to the commencement date for this new ADM obligation”, and submissions closed 15 June 2026. As at 26 August 2026 that guidance has not published — anyone quoting OAIC ADM guidance today is quoting a consultation paper. Our ADM transparency statement guide covers what to draft meanwhile.
What a recruiter should actually do
- Disclose at first contact, not in the terms. In the first fifteen seconds: this is an AI assistant, it is running an initial screen, a human reviews the outcome. That serves Article 50, Illinois’ notice duty and Colorado’s advance notice — but not Local Law 144, with its ten-business-day written notice.
- Put a human on every rejection. No rule below the EU high-risk regime requires it; do it anyway. A tool whose output is one equally weighted input among several may also fall outside the AEDT definition.
- Hold a bias-testing cadence. Annual is the floor: NYC makes a twelve-month-old audit a use-prohibition. Check adverse impact each quarter; re-audit sooner if you retrain or reweight, using historical data from your own use.
Records: what to keep
- Disclosure evidence — script version, timestamp, transcript segment.
- Consent — for Illinois video interviews, tied to the applicant, with the explanation version shown.
- Audit artefacts — auditor’s report, data set description, impact-ratio tables, independence attestation.
- The published summary — NYC requires it posted at least six months after the tool’s latest use; keep the evidence behind it that long.
- Human-review logs — reviewer, date, decision, and any departure from the model’s recommendation.
- Model versioning — which model and prompt version scored which candidate; without it you cannot answer a claim about a decision two releases old.
Retain for the longest applicable limitation period where you recruit, and no longer. Ask any vendor: does the tool score, or only transcribe — and has it had an independent bias audit in the past twelve months?
Where Zian fits
Zian AI runs autonomous phone, SMS, email and WhatsApp agents, including a Professional Recruitment agent for first-contact screening in 30+ languages. Disclosure scripting, logging and human handoff are configuration decisions you control. The bias audit is not: it sits with you as employer or agency, whoever built the tool. If you will not run that programme, configure the agent to gather and transcribe without scoring. Zian is in waitlist and partnership beta.
Frequently asked questions
Does an AI phone screen count as an automated employment decision tool in New York City?
Only if its output substantially assists or replaces discretionary decision making — relied on alone, weighted above other criteria, or used to overrule human conclusions. DCWP’s rules exclude transcription, so an agent that transcribes and summarises is likely outside it; one that ranks is likely inside.
Are employers actually complying with Local Law 144?
Largely not, on the available evidence. In “Null Compliance: NYC Local Law 144 and the challenges of algorithm accountability” (FAccT ’24, by researchers from Cornell, Data & Society and Consumer Reports), investigators reviewed 391 employers: “Among these employers, 18 posted audit reports and 13 posted transparency notices.” DLA Piper’s January 2026 note on the December 2025 State Comptroller audit reports DCWP’s enforcement system was found ineffective, with most fixes accepted.
Does Australia require me to tell candidates an AI screened them?
Not directly, and not yet. From 10 December 2026, APP 1.7–1.9 require your privacy policy to disclose the kinds of personal information used in significant automated decisions and the kinds of decisions made — a policy-level obligation, not an individual notification right. The OAIC’s final guidance had not published as at 26 August 2026.
Screening candidates with AI, without the compliance debt
Disclose at first contact, keep a human on rejections, audit annually, and log enough to reconstruct any decision — get those four right and the jurisdictional detail becomes paperwork, not exposure. To scope a screening agent for the jurisdictions you recruit in, Apply For Partnership.