AI Hiring Compliance: An Orientation to Key Rules
Last reviewed
Summary
Several jurisdictions now regulate AI used in hiring. The EU AI Act treats many recruitment and selection systems as high-risk, New York City requires bias audits for automated employment decision tools, and data-protection law restricts solely automated decisions. This page is an orientation, not legal advice.
What the evidence says
- The EU AI Act lists AI systems intended for recruitment or selection, such as analyzing and filtering applications and evaluating candidates, among high-risk systems, which carry requirements for risk management, data governance, transparency, human oversight and record-keeping. [1]
- The EU AI Act also prohibits AI systems that infer the emotions of a person in the workplace or in education, except for medical or safety reasons. Organizations should review any emotion-related assessment features against this provision with legal counsel. [1]
- New York City's Local Law 144 requires employers and employment agencies using an automated employment decision tool to have a bias audit carried out, publish a summary of the results and notify candidates. [2]
- The GDPR restricts decisions based solely on automated processing that produce legal or similarly significant effects, and requires transparency about such processing. [3]
- In the United States, the Uniform Guidelines on Employee Selection Procedures set out how adverse impact and validity are assessed for selection procedures. [4]
- Voluntary frameworks such as the NIST AI Risk Management Framework and the ISO/IEC 42001 management-system standard give organizations a structure for governing AI risk. [5][6]
AuraSync's interpretation
The common thread across these rules is transparency, human oversight, testing for adverse impact and records that let a decision be reviewed. AuraSync is built around those same principles, but compliance depends on how each employer uses a tool, in which jurisdiction and for which decisions, so responsibility stays with the employer.
What AuraSync claims
- AI output in AuraSync is decision support and must not be the sole basis of a hiring decision.
- Every candidate consent is recorded with the version of the notice shown, and the ATS keeps an audit trail of sign-ins and significant actions.
- Customers remain responsible for making sure their use of AuraSync complies with the laws that apply to them.
Limitations
This is a summary of selected rules for orientation. It is not legal advice, does not cover every jurisdiction, and laws and official guidance change. Employers should confirm their obligations with qualified counsel.
Sources
- [1]Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- [2]New York City Department of Consumer and Worker Protection. Automated Employment Decision Tools (Local Law 144 of 2021). https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page
- [3]Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2016/679/oj
- [4]Uniform Guidelines on Employee Selection Procedures (1978), 29 C.F.R. Part 1607. https://www.ecfr.gov/current/title-29/subtitle-B/chapter-XIV/part-1607
- [5]National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1). https://doi.org/10.6028/NIST.AI.100-1
- [6]International Organization for Standardization. (2023). ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system. https://www.iso.org/standard/81230.html
This page summarizes third-party research for orientation. It is not an evaluation of AuraSync, and any summary of law is not legal advice.