AI Hiring Bias Audit: Do You Actually Need One?

Start with the trigger, because most people get the scope wrong in one direction or the other. The question is not whether you use AI somewhere in hiring. It is whether a tool substantially assists...

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
8 September 20261 min read

AI Hiring Bias Audit: Do You Actually Need One?

Start with the trigger, because most people get the scope wrong in one direction or the other. The question is not whether you use AI somewhere in hiring. It is whether a tool substantially assists or replaces a human decision about who gets hired or promoted. Using a language model to tidy up a job advert is not in scope. Using one to rank, score, or filter candidates almost certainly is.

If you hire for a role located in New York City, that distinction carries a legal obligation with a per-day penalty attached, wherever your company is based.

What New York actually requires

Local Law 144 governs automated employment decision tools, and it imposes three obligations on employers and employment agencies using one on candidates or employees in New York City:

  1. An annual bias audit by an independent auditor, testing the tool for disparate impact across protected categories including sex, race, and ethnicity, using historical or test data.

  2. A publicly posted summary of the audit results on your website.

  3. At least ten business days' notice to candidates before the tool is used on them.

The city's Department of Consumer and Worker Protection publishes an FAQ covering what counts as a tool and what an audit must contain. Civil penalties run from 500 to 1,500 dollars per violation per day, and the obligation attaches to the job location rather than the employer's headquarters. A company in Lisbon hiring for a New York role is covered.

Two practical notes. The audit must be by an independent auditor, which rules out the vendor who sold you the tool. And it is annual, not once, so an audit from 2024 does not cover you now.

Elsewhere, the position moved in 2026

This is where advice written a year ago is actively wrong, and the Colorado example is the clearest case.

Colorado's SB 24-205, the first broad state AI act, was originally due to take effect on 1 February 2026, then postponed to 30 June 2026. In April 2026 a federal magistrate judge blocked enforcement following a constitutional challenge. Governor Polis then signed SB 26-189 on 14 May 2026, which repeals and reenacts those provisions with new requirements for automated decision-making technology in consequential decisions, taking effect on 1 January 2027. The replacement is narrower and centred on disclosure, technical documentation, and a right to human review, rather than the original impact-assessment regime.

So Colorado is not currently enforcing the law many compliance checklists still cite, and the thing arriving in 2027 is a different instrument. If you built a programme against SB 24-205, it needs rereading.

The EU is the other pole. Employment is a high-risk category under the AI Act, which brings its own obligations on risk management, data governance, human oversight, and record keeping. Those are heavier than a bias audit and land on a separate timetable, covered in the EU AI Act high-risk deadline.

What an audit actually involves

It is a statistical exercise, not a code review. The auditor computes selection rates by protected category at each stage the tool influences, then compares them, most commonly using an impact ratio against the highest-scoring group.

That has two consequences people are unprepared for.

First, you need demographic data to audit against, and many organisations do not collect it. Where historical data is thin, the law permits test data, but the summary must disclose that you used it.

Second, the audit tells you whether outcomes differ, not why. A failing ratio does not identify the cause, and the remediation work afterwards is usually longer than the audit itself.

Budget for a real engagement rather than a certificate. An auditor who does not ask for your selection data at each stage is not doing the analysis the law describes.

If you would rather not be in scope

Reasonable position, and it is achievable. The trigger is substantial assistance to the decision, so the question is where the tool sits relative to a human judgement.

  • Generating a job advert or an interview question bank: out of scope. Nothing about a candidate is being scored. That is the safe use, and it is the one covered in prompting AI to write a job description.

  • Summarising an application for a human who reads it anyway: usually out of scope, and worth documenting that the human sees the original.

  • Ranking or scoring candidates: in scope. A human who reviews the ranking is not a defence if the ranking determined who they reviewed.

  • Automated rejection at a threshold: squarely in scope.

The failure mode to avoid is the tool nobody procured. A hiring manager pasting a stack of CVs into a chatbot and asking for a shortlist has created an automated employment decision tool without a contract, an audit, or a record. That is shadow AI with a legal exposure attached, and it is why an AI usage policy that names hiring explicitly is worth more here than any vendor assessment.

The wider risk

Compliance is the floor. A tool that systematically disadvantages a group is a discrimination problem before it is a paperwork problem, and existing employment law applies regardless of which AI-specific statute is in force this quarter. That is worth holding onto given how much the statutory picture moved in 2026, and it sits alongside the other exposures set out in AI risks.

When you are procuring, ask the vendor for their most recent independent audit, their impact ratios rather than a compliance claim, and what data the audit used. A vendor who cannot produce those is telling you something, which is the general point of vetting an AI vendor before it is in your process rather than after.

FAQ

Does Local Law 144 apply if my company is not in New York?

Yes, if the role is located in New York City. The obligation follows the job, not the employer's headquarters.

Does using AI to write a job advert require a bias audit?

No. The law targets tools that substantially assist or replace a decision about a specific candidate. Generating an advert scores nobody.

Is the Colorado AI Act in force?

Not as originally passed. Enforcement of SB 24-205 was blocked by a federal court in April 2026, and it has been repealed and replaced by SB 26-189, effective 1 January 2027 with a narrower disclosure-focused framework.

How often does the audit need repeating?

Annually under Local Law 144, and the summary posted publicly must correspond to the current audit. A single audit does not provide ongoing coverage.

Can our AI vendor do the audit?

No. The audit must be conducted by an independent auditor, which excludes the vendor supplying the tool and generally anyone with a financial interest in the outcome.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.

AI Hiring Bias Audit: Do You Actually Need One? | swarmz.net