How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment
    Compliance Checklist

    AI Governance for HR Copilots: EEOC and State Law Checklist

    HR copilots used for resume screening, candidate ranking, or performance evaluation are subject to EEOC guidance on algorithmic adverse impact and to state laws such as NYC Local Law 144, the Illinois AI Video Interview Act, and Colorado's AI Act. Meeting these obligations requires runtime controls, not policy documents alone: permission scoping, audit logging of every recommendation, disparate-impact testing tied to model versions, and human-in-the-loop review before any adverse action.

    HR copilots used for resume screening, candidate ranking, or performance evaluation are subject to EEOC guidance on algorithmic adverse impact and to state laws such as NYC Local Law 144, the Illinois AI Video Interview Act, and Colorado's AI Act. Meeting these obligations requires runtime controls, not policy documents alone: permission scoping, audit logging of every recommendation, disparate-impact testing tied to model versions, and human-in-the-loop review before any adverse action.

    Why HR Copilots Create Direct Regulatory Exposure

    HR copilots that screen resumes, rank candidates, schedule interviews, or contribute to performance evaluations are functioning as algorithmic decision tools under existing EEOC guidance, regardless of whether they were built internally or licensed from a vendor. EEOC's 2023 technical guidance on Title VII states that employers can be held liable when a selection tool produces disparate impact, and points to the four-fifths rule as a common benchmark for detecting that impact.

    Separately, EEOC's 2022 guidance addresses ADA exposure, noting that algorithmic screening can constitute disability discrimination if it screens out applicants without an accommodation review. Neither guidance treats the underlying tool's origin as a mitigating factor. The practical consequence for CHROs is that governance obligations attach to how the copilot is used in production, not to a vendor's compliance claims or a one-time procurement review. This shifts the compliance burden toward runtime evidence: what the copilot recommended, what data it accessed, and whether a human reviewed the outcome before it became an adverse action.

    Regulatory Requirements at a Glance

    The following instruments shape how HR copilots must be governed in production. Requirements differ by jurisdiction, but they converge on auditability, notice, and documented risk management.

    InstrumentCore obligation
    EEOC Title VII Guidance (2023) Employers may be liable if algorithmic tools produce disparate impact, referencing the four-fifths adverse-impact benchmark.
    NYC Local Law 144 Requires an independent bias audit within one year prior to use and a 10-business-day candidate notice.
    Illinois AI Statutes Video interview consent requirements plus a 2026 amendment prohibiting discriminatory AI use in employment decisions.
    Colorado SB24-205 Classifies employment AI as high-risk, requiring impact assessments and a documented risk management policy.

    Runtime Governance Controls That Enforce These Requirements

    Policy statements and procurement questionnaires are not enough. The controls below bind compliance obligations to the path where the copilot produces recommendations and where those recommendations can become employment decisions.

    1. Separation of recommendation from execution

      Insert a mandatory approval gate between copilot output and any consequential HR action.

    2. Scoped data access

      Limit copilot visibility to only the fields necessary for the specific HR task to reduce disparate-impact exposure.

    3. Version-linked compliance artifacts

      Connect model or dataset changes to updated impact assessments and bias audit records.

    Documentation and Auditability Standards

    When an EEOC charge or state investigation arrives, the organization must reconstruct the copilot's role in the decision. The standards below make that reconstruction possible without relying on tribal knowledge or vendor goodwill.

    • Retention policy for decision records: Retain audit logs long enough to reconstruct a copilot's role in any adverse decision during an EEOC charge or state investigation.
    • Override and escalation documentation: Capture the rationale whenever a human reviewer overrides or accepts a copilot recommendation.
    • Living impact assessments: Update bias audit and impact assessment documentation whenever the underlying model or decision logic materially changes.
    • Assigned governance ownership: Designate a joint CHRO and legal function accountable for AI risk management obligations under laws such as Colorado's AI Act.
    • Vendor audit rights: Secure contract terms granting audit rights and data access needed to independently verify a vendor's bias audit and impact assessment claims.

    Governance obligations attach to production use. A one-time procurement review does not satisfy ongoing audit, notice, and documentation duties under EEOC guidance or state AI employment laws.

    Frequently asked questions

    Does state AI employment law apply beyond hiring, to performance evaluation or termination?

    Scope varies by statute. Some state laws are written narrowly around hiring and promotion, while others reference broader employment decisions. Applicability to performance evaluation or termination use cases should be confirmed against the specific statute text before relying on a copilot for those decisions.

    Are we still liable if the HR copilot is vendor-built rather than developed in-house?

    Yes. EEOC guidance treats employer liability as attaching to how an algorithmic tool is used in production, regardless of whether it was built internally or licensed from a vendor. Procurement review alone does not satisfy ongoing audit and documentation obligations.

    How often should bias audits be updated?

    NYC Local Law 144 requires an audit within one year prior to use. Beyond that baseline, audits should be re-run whenever the underlying model or dataset changes, since a version update can alter disparate-impact results without a corresponding policy change.

    Operationalize These Controls at Runtime

    Meeting EEOC and state AI employment law requirements depends on enforcing permission scope, audit logging, and human-in-the-loop review at the point where the HR copilot acts, not on policy documents alone.

    Explore Runtime Governance