By use case · AI in hiring and employment
AI in hiring and employment: the rules that apply
Hiring and employment is the use case regulated most often and most specifically: bias audits, notices to candidates, impact assessments, human review of decisions and record keeping appear in city, state, national and supranational rules. An organisation that uses AI anywhere in the employee lifecycle is a deployer in most of them.
- Jurisdictions
- 10
- Evidence items
- 66
What the rules have in common
Tell the candidate, test for disparate impact, keep a human able to change the outcome, and keep the records that show you did. The wording differs; the controls do not, which is why one bias-testing control below serves duties in several jurisdictions.
Where they differ
Who must run the audit, how often, whether it is published, and whether a candidate can opt out or request an alternative process. Those details are on each duty page with the article cited.
Which controls meet these duties?
Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.
| Control | Satisfies | Supports | Owner · frequency |
|---|---|---|---|
| AI interaction and use disclosure notices Process | 7 | 3 | Product owner · at launch and on material change |
| Decision explanation, human review and appeal route Process | 7 | 2 | Customer operations lead · once per ai system |
| AI risk assessment and lifecycle risk register Process | 4 | 2 | AI system owner · once per ai system |
| AI governance policy and accountability structure Policy | 4 | 2 | Executive sponsor for AI · annual |
| Technical documentation, model cards and instructions for use Process | 4 | 2 | Product or model owner · at launch and on material change |
| AI incident management and regulatory reporting Process | 4 | 1 | Incident coordinator · continuous |
| Human oversight design and override procedure Process | 3 | 5 | AI system owner · once per ai system |
| Privacy and data-protection controls for AI Process | 3 | 0 | Data protection officer · once per ai system |
| Post-deployment monitoring and drift detection Technical measure | 2 | 5 | AI system owner · continuous |
| Accuracy, robustness, fairness and security testing Technical measure | 2 | 5 | Quality or testing lead · at launch and on material change |
| AI impact and fundamental-rights impact assessment Process | 2 | 4 | AI system owner · once per ai system |
| Data governance and dataset documentation Process | 2 | 3 | Data governance lead · once per ai system |
| Prohibited and unacceptable-use screening gate Process | 2 | 0 | AI governance lead · once per ai system |
| AI system inventory and classification Process | 1 | 4 | AI governance lead · continuous |
| Model release and change-management gate Process | 1 | 2 | Release manager · at launch and on material change |
| Contractual allocation of AI duties across the supply chain Contractual term | 1 | 2 | Legal counsel · once per ai system |
| AI literacy and role-based training programme Training programme | 1 | 2 | Learning and development lead · annual |
| Quality management system for AI development and supply Policy | 1 | 1 | Quality lead · annual |
| Training-data provenance and copyright register Process | 0 | 2 | Model development lead · at launch and on material change |
| Automatic event logging and record retention Technical measure | 0 | 2 | Engineering lead · continuous |
| Vendor and third-party AI due diligence Process | 0 | 2 | Procurement or vendor risk lead · once per ai system |
| Conformity assessment, declaration and registration Process | 0 | 2 | Regulatory compliance lead · once per ai system |
Which duties are recorded?
Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).
Australia 1 duty
-
VoluntaryAustralian Voluntary AI Safety Standard · Guardrails 4, 5 and 6Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)
Colorado (United States) 9 duties
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(3)applies from 30 Jun 2026Deployers must complete impact assessments for high-risk AI
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(2)applies from 30 Jun 2026Deployers must implement a risk management policy and programme
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(7)applies from 30 Jun 2026Deployers must notify the Attorney General of discovered algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(5)applies from 30 Jun 2026Deployers must publish a statement about the high-risk AI systems they use
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(1)applies from 30 Jun 2026Deployers must use reasonable care to avoid algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702applies from 30 Jun 2026Developers must document high-risk systems and disclose known risks
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702(5)applies from 30 Jun 2026Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702(1)applies from 30 Jun 2026Developers must use reasonable care to avoid algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(4)applies from 30 Jun 2026Notify consumers and explain adverse consequential decisions
European Union 21 duties
-
Legal requirementEU AI Act · Article 10applies from 2 Aug 2026Apply data governance and quality criteria to training, validation and testing data
-
Legal requirementEU AI Act · Article 26(4)applies from 2 Aug 2026Deployers must ensure input data they control is relevant and representative
-
Legal requirementEU AI Act · Article 86applies from 2 Aug 2026Deployers must explain individual decisions taken with high-risk AI on request
-
Legal requirementEU AI Act · Article 26(5)applies from 2 Aug 2026Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
-
Legal requirementEU AI Act · Article 26(11)applies from 2 Aug 2026Deployers must tell natural persons that a high-risk AI system is used in decisions about them
-
Legal requirementEU AI Act · Article 26(9)applies from 2 Aug 2026Deployers must use the provider's transparency information in their data protection impact assessment
-
Legal requirementEU AI Act · Article 25(1) and 25(2)applies from 2 Aug 2026Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
-
Legal requirementEU AI Act · Article 5applies from 2 Feb 2025Do not deploy or provide AI for prohibited practices
-
Legal requirementEU AI Act · Article 11 and Annex IVapplies from 2 Aug 2026Draw up technical documentation before placing a high-risk system on the market
-
Legal requirementEU AI Act · Article 26(7)applies from 2 Aug 2026Employers must inform workers and their representatives before using high-risk AI at work
-
Legal requirementEU AI Act · Article 14; Article 26(2) for deployersapplies from 2 Aug 2026Enable and assign effective human oversight
-
Legal requirementEU AI Act · Article 4applies from 2 Feb 2025Ensure AI literacy of staff operating AI systems
-
Legal requirementEU AI Act · Article 9applies from 2 Aug 2026Establish a risk management system for high-risk AI
-
Legal requirementEU AI Act · Article 22applies from 2 Aug 2026Non-EU providers must appoint an EU authorised representative for high-risk AI
-
Legal requirementEU AI Act · Article 72applies from 2 Aug 2026Operate a post-market monitoring system
-
Legal requirementEU AI Act · Article 17applies from 2 Aug 2026Operate a quality management system
-
Legal requirementEU AI Act · Article 13applies from 2 Aug 2026Provide deployers with clear instructions for use
-
Legal requirementEU AI Act · Article 6(4); Article 49(2)applies from 2 Aug 2026Providers must document and register a conclusion that an Annex III system is not high-risk
-
Legal requirementEU AI Act · Article 16applies from 2 Aug 2026Providers must meet the full set of provider duties for high-risk AI
-
Legal requirementEU AI Act · Article 20applies from 2 Aug 2026Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
-
Legal requirementEU AI Act · Article 26applies from 2 Aug 2026Use high-risk AI as instructed, monitor it and inform affected people
New York (United States) 5 duties
-
Legal requirementNYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(b)(3); 6 RCNY Section 5-303applies from 5 Jul 2023Employers and employment agencies must disclose the data collected and their retention policy for the tool
-
Legal requirementNYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(b)(1); 6 RCNY Section 5-303applies from 5 Jul 2023Employers and employment agencies must let candidates request an alternative selection process or accommodation
-
Legal requirementNYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(b)(1) and (b)(2); 6 RCNY Section 5-303applies from 5 Jul 2023Employers and employment agencies must notify candidates and employees before an automated tool is used
-
Legal requirementNYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(a)(1); 6 RCNY Section 5-301applies from 5 Jul 2023Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool
-
Legal requirementNYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(a)(2); 6 RCNY Section 5-302applies from 5 Jul 2023Employers and employment agencies must publish a summary of the bias audit results
Singapore 1 duty
-
VoluntarySingapore Model AI Governance Framework · Second edition, Part on human involvement in AI-augmented decision-makingDetermine the appropriate level of human involvement in AI decisions
South Korea 5 duties
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must be able to explain outputs and the main criteria behind them
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must ensure human management and supervision
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must establish and operate a risk management plan
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
-
VoluntaryFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 35applies from 22 Jan 2026Operators of high-impact AI should assess its impact on fundamental rights before use
Texas (United States) 1 duty
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.056applies from 1 Jan 2026Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
United Arab Emirates 1 duty
-
Legal requirementUAE PDPL · Article on data-subject rights relating to automated processing (reviewer to cite article number)Respect the right to object to automated decision-making without human intervention
United Kingdom 5 duties
-
Legal requirementICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025Apply safeguards to solely automated decisions with significant effects
-
Legal requirementICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance sectionCarry out a data protection impact assessment for high-risk AI processing
-
VoluntaryUK AI regulation framework · Principle 2, Part 3Provide appropriate transparency and explainability
-
VoluntaryUK AI regulation framework · Principle 5, Part 3Provide routes to contest AI outcomes and seek redress
-
VoluntaryUK AI regulation framework · Principle 3, Part 3Use AI in ways that are fair and do not discriminate unlawfully
United States 1 duty
-
VoluntaryNIST AI RMF · GOVERN functionEstablish AI governance policies, roles and accountability (Govern)
What evidence would a reviewer expect?
- AI customer or deployer clause set Contract clause or supplier term
- AI data-flow and legal-basis record Register entry
- AI decision challenge and human review procedure Procedure or standard operating process
- AI governance forum minutes Governance meeting record
- AI impact assessment Impact assessment
- AI incident record Incident record
- AI incident response playbook Procedure or standard operating process
- AI intake and classification procedure Procedure or standard operating process
- AI interaction or use notice Disclosure or notice
- AI policy Policy document
- AI quality management system manual Policy document
- AI responsibility map Register entry
- AI supplier and component register Register entry
- AI supplier clause set Contract clause or supplier term
- AI supplier due-diligence assessment Supplier assessment
- AI system event logs Access or activity log
- AI system register Register entry
- AI system risk assessment Risk assessment
- AI training completion records Training record
- AI training curriculum and materials Policy document
- Adverse-decision explanation template Disclosure or notice
- Board or executive approval of the AI policy Approval or sign-off record
- Challenge and reversal log Monitoring record
- Conformity evidence pack Technical documentation file
- Contract clause index against the AI register Register entry
- Copyright and rights-reservation policy Policy document
- Data protection impact assessment for an AI system Data protection impact assessment
- Data quality and bias check report Evaluation or test report
- Dataset approval for use Approval or sign-off record
- Dataset documentation sheet Dataset documentation
- Declaration of conformity or certificate Conformity declaration or certificate
- Human oversight and override procedure Procedure or standard operating process
- Human-involvement design rationale Approval or sign-off record
- Impact assessment approval Approval or sign-off record
- Impact assessment procedure and template Procedure or standard operating process
- Incident report to an authority Regulatory filing or notification
- Independent data audit or DPO review Audit or assurance report
- Instructions for use Disclosure or notice
- Internal audit of the AI management system Audit or assurance report
- Log integrity and retention check Audit or assurance report
- Log schema and retention standard Procedure or standard operating process
- Management review minutes Governance meeting record
- Model card or deployer information pack Model documentation
- Monitoring dashboard or periodic monitoring report Monitoring record
- Monitoring review decision Approval or sign-off record
- Notice catalogue Register entry
- Notice wording approval Approval or sign-off record
- Overseer training completion Training record
- Per-system AI risk register Risk register
- Post-market monitoring plan Procedure or standard operating process
- Pre-release test report Evaluation or test report
- Privacy notice section on AI use Disclosure or notice
- Prohibited-use screening record Approval or sign-off record
- Public summary of training content Disclosure or notice
- Registration record in the relevant database Regulatory filing or notification
- Release and change-classification procedure Procedure or standard operating process
- Release or change approval record Approval or sign-off record
- Release test sign-off Approval or sign-off record
- Residual-risk acceptance Approval or sign-off record
- Risk-tier classification sign-off Approval or sign-off record
- Role-to-curriculum training matrix Procedure or standard operating process
- Screening list and escalation procedure Procedure or standard operating process
- Supplier onboarding decision Approval or sign-off record
- Technical documentation file Technical documentation file
- Test plan and acceptance criteria Procedure or standard operating process
- Training source register Register entry
Latest changes to these instruments
Texas TRAIGA takes effect
European Commission proposes Digital Omnibus adjustments to AI Act timelines
Colorado delays the AI Act effective date to 30 June 2026
EU AI Act general-purpose AI, governance and penalty provisions start to apply
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Does using an off-the-shelf screening tool make my company responsible?
- In most instruments yes: the employer is the deployer and carries the notice, oversight and record-keeping duties, whatever the vendor promised. Some rules place the audit duty on the vendor, others on the employer.
- What evidence do these duties produce?
- A bias or impact assessment, the notice text shown to candidates, the human-review procedure, the system register entry and the decision logs. The controls below list each one.