If an AI tool rejected your job application, the question that actually matters isn't whether using AI to screen candidates is legal -- almost everywhere, it still is. It's whether the specific company and tool followed the specific rule that applies to them, and that answer now depends on four things that have nothing to do with how the rejection felt: where the job is based, which law is actually in force there today, whether a federal regulator would even look at a complaint, and one ongoing lawsuit that could change how much the software vendor itself is on the hook, separate from the employer.
This isn't an abstract compliance question. AI-exposed entry-level jobs are already measurably harder to land than they were two years ago, and a resume-screening tool is the exact point where that pressure turns into one specific rejection. None of the laws below ban using AI to screen candidates -- not one of them does. They specify what has to happen first, and most employers using these tools aren't volunteering whether they actually did it.
Where the law actually reaches, right now
New York City has the most concrete rule in the country. Since July 5, 2023, Local Law 144 bars an employer or employment agency from using an AEDT -- an automated employment decision tool -- in hiring or promotion unless it has been checked by an independent auditor for disparate impact by sex and race/ethnicity within the past year, a summary of that audit is posted publicly, and candidates get at least 10 business days' notice before the tool is used on them. The city's Department of Consumer and Worker Protection enforces it.
Illinois runs two separate laws that cover different parts of the same process. The older one, the Artificial Intelligence Video Interview Act (in effect since 2020), requires an employer to tell an applicant before a video interview that AI may analyze it, explain in general terms how the AI works and what it evaluates, get the applicant's consent, and -- with no stated exceptions -- delete the recording within 30 days of a request, including copies held by anyone else it was shared with. The newer one, HB3773, amended the Illinois Human Rights Act effective January 1, 2026: it bars using AI in hiring, promotion, discipline, or discharge decisions where the AI use has a discriminatory effect on a protected class, separately bars using a zip code as a stand-in for one, and requires notice that AI is being used -- though the Illinois Department of Human Rights floated notice rules on May 15, 2026 and withdrew them 18 days later, so what a compliant notice actually has to say is still unsettled.
Colorado is the state to watch precisely because its first attempt never actually took effect. The 2024 Colorado AI Act would have required bias audits and risk-management programs for 'high-risk' hiring AI, but lawmakers delayed its start date twice and then Gov. Jared Polis signed a full replacement, SB 26-189, on May 14, 2026. The rewrite drops the audit and impact-assessment regime entirely and takes effect January 1, 2027 with a narrower set of rights instead: notice before a consequential decision, a plain-language explanation after an adverse one, the right to correct inaccurate personal data the tool used, and the right to request meaningful human review -- a reviewer with actual authority to overturn the system's call, not just restate it. Connecticut's CART Act takes a third approach again: its clarification that automated hiring tools are no defense against a discrimination claim is already in force, but the fuller notice regime for employers doesn't become operational until October 2027.
What each AI-hiring law actually requires
| NYC Local Law 144 | Illinois AIVIA + HB3773 | Colorado SB 26-189, 2027 | |
|---|---|---|---|
| What triggers it | Any automated tool used to screen or rank candidates for hiring or promotion | AI analyzing a video interview, or any AI employment decision with a discriminatory effect | Automated decision tech that 'materially influences' a consequential decision |
| Core requirement | Independent bias audit within the past year; summary posted publicly | Notice and consent for video analysis; ban on discriminatory effect and zip-code proxies | Notice, post-decision explanation, data-correction rights, human review on request |
| Advance notice | 10 business days before the tool is used | Before the interview (AIVIA); HB3773's own notice rules are still unset | Before use, and again after an adverse decision |
| Who enforces it | NYC Dept. of Consumer and Worker Protection | Illinois Dept. of Human Rights, or a private civil action | Colorado Attorney General |
| In force since | July 5, 2023 | 2020 (AIVIA); Jan. 1, 2026 (HB3773) | Jan. 1, 2027 -- replacing a 2024 law that never actually took effect |
The regulator that stepped back
Until early 2025, the EEOC's own technical-assistance pages told employers directly to self-audit AI selection tools for adverse impact and warned that a vendor's assurance of fairness didn't shield the employer that used it. Both that May 2023 Title VII guidance and a May 2022 ADA companion document were pulled from the agency's site following a presidential executive order -- the Title VII page's own old web address now returns a flat 404, confirmed directly against the EEOC's own site. Then, on September 30, 2025, an internal memo directed EEOC field offices to administratively close every pending disparate-impact-only charge and begin issuing right-to-sue letters, rather than investigate them. The underlying law didn't change -- Title VII, the ADA, and the ADEA are all still on the books -- only the agency's own willingness to investigate a disparate-impact theory on its own did. A charge that also alleges intentional discrimination, not just disparate impact, is likelier to stay under EEOC review.
Practically, that means a charge filed over an AI hiring tool's disparate impact alone is likely to get closed quickly and converted into a right-to-sue letter rather than investigated -- which sounds like a dead end but isn't one. The letter is what a private attorney needs to actually file the claim in federal court, and state and local laws with their own disparate-impact standards, including NYC's and Illinois's, aren't touched by anything the EEOC decided. The agency stepping back from the investigation doesn't mean the claim is weaker; it means the first move toward resolving it shifted from a federal agency to a private lawsuit or a state agency.
The one case to actually watch
Mobley v. Workday, filed in the Northern District of California in 2023, is the case most likely to decide how much responsibility a hiring-software vendor carries, as opposed to the employer using it. Derek Mobley alleges Workday's AI-driven applicant-screening features produced age, race, and disability discrimination against him and a potential class of other rejected applicants. Workday disputes this directly -- its chief responsibility officer, Kelly Trindel, has said "Workday AI does not make hiring decisions and is not designed to automatically reject candidates" -- and no court has found otherwise. What makes the case worth tracking is a narrower, procedural question: can Workday be sued at all, given that it never makes the final hiring call itself?
Mobley v. Workday, so far -- allegations only, no liability finding
- 2023 — Derek Mobley sues Workday in the Northern District of California, alleging its screening tools produced age, race, and disability discrimination.
- Jul 2024 — Judge Rita Lin denies Workday's motion to dismiss, letting the case proceed on the theory that Workday can be liable as an 'agent' of the employers who use its software -- not as an employer itself.
- Jan 2026 — The court authorizes notice to potential plaintiffs, letting other applicants over 40 join the age-discrimination claim as a collective action.
- May 2026 — A discovery order requires Workday to produce its EEO-1 and federal-contractor compliance filings, while limiting plaintiffs' access to Workday's own internal bias-testing data.
- Jun 2026 — The court again refuses to dismiss the core disability and age claims, while dismissing several newly added claims on procedural grounds.
None of this is a reason to assume a rejection from a Workday-powered tool specifically was discriminatory, or that it wasn't. It's a reason to know that the question of who answers for an AI hiring tool's behavior -- the employer, the vendor, or both -- is still being argued in federal court, not settled, and that reporters and employers describing the case as a finished verdict are getting ahead of what's actually happened.
The actual check
None of the above requires becoming an employment lawyer before your next job application. It requires running down five specific questions, in order, against the one rejection you're actually asking about.
Check whether the AI tool that rejected you had to follow a rule
- These are the only places with an operative AI-hiring-specific rule right now. The company's headquarters doesn't count -- it's where the job itself is based.
- Local Law 144 requires both before an AEDT can be used at all, and the audit summary is supposed to be public on the employer's own site.
- HB3773 bans a discriminatory-effect AI decision and requires notice, but the state hasn't finished rules defining what that notice has to contain -- so the honest question right now is what the employer actually did, not what a form should say.
- Since September 30, 2025 the agency closes disparate-impact-only charges as a matter of policy, not case-by-case judgment about your specific facts.
- Mobley v. Workday has let claims proceed past a motion to dismiss four times without a liability finding -- that's evidence a court takes the theory seriously, not evidence the theory has won.
Running those five checks takes longer than reading a rejection email, but it's the difference between having an actual complaint and having a feeling.
Four ways this check gets skipped or botched
None of this means an AI hiring tool rejected you unfairly, or that it didn't -- it means that question now has an actual, checkable paper trail behind it in a handful of places, and a real gap everywhere else. The same access-first instinct applies to an AI meeting notetaker that needs everyone's consent before it starts recording: a tool quietly making a decision about you is worth the five minutes it takes to ask what, specifically, it was required to do first.
- NYC's Local Law 144 requires a bias audit and 10 business days' notice before screening.
- Illinois bars AI hiring decisions with a discriminatory effect, effective January 1, 2026.
- The EEOC stopped investigating AI-bias complaints in September 2025; private lawsuits still work.
- Mobley v. Workday's age and disability claims survived another dismissal motion in June 2026.
- Caveat: Colorado scrapped its 2024 bias-audit law in May 2026, before it ever took effect.