
I've been in enough of these conversations now to know what signals a real problem versus a compliance checkbox. The signal I remember most from this last year was a CHRO who brought her general counsel onto our call. She walked him through what I'd described about the conflict between Illinois HB 3773 and the EU AI Act's data representativeness requirements — the fact that removing zip codes to satisfy Illinois's proxy prohibition could fail the EU's Art. 10(3) mandate for representative training data. She asked him directly, in the room, whether their vendor had resolved that conflict. His answer — after a pause — was that he didn't know. Not that it was handled. Not that it was on the roadmap. He didn't know.
That exchange told me more than any industry survey. A GC at a Fortune 500 company, who had signed off on the bias audit report, didn't know whether the company's primary AI hiring platform was compliant with two live regulatory requirements that directly conflicted with each other.
What the NY State Comptroller's Audit Taught Me About Methodology

I spent a lot of time in December 2025 with the NY State Comptroller's audit of LL144 enforcement, and the number that stayed with me wasn't the penalty exposure — it was the methodology gap.
The Comptroller's office found 17 potential violations in the same 32-company sample where DCWP had found one. DCWP had asked employers whether their tools were in scope. The Comptroller looked at API call logs and ATS integration traces. Same companies. Same law. Seventeen versus one.
DCWP acknowledged its staff lacked the technical expertise to evaluate AEDTs and agreed to adopt proactive, methodology-driven enforcement going forward. That's not a regulatory clarification — it's a posture shift. The window that existed when NYC compliance meant filing a self-classification memo is gone.
The Cornell / Data & Society / Consumer Reports paper at FAccT 2024 named this posture "Null Compliance" — operating AEDTs while claiming the tools don't substantially assist hiring decisions. Among 391 NYC employers, only 18 had published bias audit reports (4.6%) and only 13 had posted required candidate notice. Most of the compliance work that happened in response to LL144 was paperwork designed to argue scope, not audits designed to test impact. That's the paper trail that a regulator with API-log access is now actively sifting through.
LL144 penalties run up to $1,500 per day per violation — up to $547,500 per year for a single continuously-deployed AEDT that hasn't been audited. The math was always there. What changed is that the methodology to find violations finally matches the law's ambition.
The Conflict No Vendor Has Mapped

What I find myself explaining most often to compliance leads and legal teams is the Illinois-EU proxy conflict, because it's the one that most directly exposes the gap between "we have a bias audit" and "we have a compliant AEDT."
Illinois HB 3773, live since January 1, 2026, explicitly prohibits using zip codes as proxies for protected classes in hiring AI — implementing the Illinois Human Rights Act's anti-proxy provision. The EU AI Act's Art. 10(3), which becomes enforceable for high-risk recruitment tools on August 2, 2026, requires training data to be "relevant, representative, free of errors." Geographic coverage is one of the ways practitioners achieve representativeness across demographic groups. Remove zip codes to satisfy Illinois. Your EU representativeness argument gets weaker.
I've asked every bias audit vendor I've spoken with whether they have a reconciled methodology for this. None of them have published one. Some have a position on it, but a position isn't a methodology, and a methodology isn't the documented reasonable-care defense Colorado SB 24-205 requires when that June 30 deadline hits.
The bias audit vendors aren't building this because no single audit engagement pays for solving a cross-jurisdictional conflict. They're paid to deliver a report against a specific methodology — LL144, or EU AI Act, or Colorado. The client who asks "and how do these reconcile?" is asking a question the engagement wasn't scoped to answer.
What the Mobley and Kistler Complaints Actually Mean for Your Stack

My compliance work deepened significantly when I read both complaints carefully, not just the headlines.
Mobley v. Workday isn't only about Workday. Judge Rita F. Lin's May 2025 ruling held that an AI hiring vendor can be directly liable as an "agent" when its tool participates in decision-making by recommending or filtering candidates — independent of what the employer has claimed about scope. The court ordered Workday to produce an exhaustive list of employers who enabled HiredScore Spotlight and Fetch, rejecting attempts to exclude the post-acquisition products. Plaintiffs' counsel has noted potential class scope of over one billion applicants. The discovery timeline now means every employer on that production list is being evaluated by plaintiffs' counsel for settlement exposure.
Kistler v. Eightfold AI (Contra Costa Superior, January 2026) is testing something different, and I recognized the pattern from earlier in my career. The complaint alleges Eightfold scraped data from LinkedIn, GitHub, Stack Overflow, and public databases to build candidate dossiers from more than 1.5 billion data points and produced 0-to-5 match scores — without FCRA certification, notification, disclosure, authorization, or dispute workflows. The Fair Credit Reporting Act consumer-reporting-agency theory: if Eightfold is a consumer reporting agency, it owed every scored candidate an adverse-action notice and a dispute workflow. Statutory damages under the FCRA run $100 to $1,000 per consumer per violation.
The background-check industry went through exactly this reckoning in 2017. A wave of FCRA litigation forced 18 months of system rewrites across employers who had been relying on background vendors without adverse-action workflows. If Kistler sustains the CRA theory, any AI hiring platform that scores candidates from scraped data is in the same position the background-check industry was in eight years ago. That's not a future risk — the complaint is in discovery now.
Neither of those theories appears in a standard LL144 bias audit report. Both are live exposure today.
The Two Tests Your LL144 Audit Doesn't Run

Two hiring compliance risks fall entirely outside the bias-audit framework, and I've started treating them as separate compliance disciplines.
My team has spent real time on the ASR accuracy question since the ACLU filed in March 2025. An Indigenous Deaf employee identified as D.K. filed a complaint with the Colorado Civil Rights Division and the EEOC alleging ADA, Title VII, and Colorado Anti-Discrimination Act violations in connection with a HireVue-integrated video interview at Intuit. HireVue CEO Jeremy Friedman denied AI-based assessment was used; Intuit denies wrongdoing.
The accuracy data doesn't require the lawsuit to settle to be actionable. The 2025 Interspeech Speech Accessibility Project Challenge — over 400 hours from more than 500 speakers with speech disabilities — showed top models at 8.11% word-error rate on impaired speech, multiples of standard English benchmarks. Whisper's multilingual average is roughly three times higher than its English performance. A workflow that treats speech fluency as a quality signal is testing something other than job-relevant ability for a non-trivial population of applicants. LL144 doesn't test this. The ADA theory is different, the documentation requirement is different, and the testing discipline is different.
The security question came into focus for me after the McHire/Paradox disclosure in June 2025. Ian Carroll and Sam Curry found that McDonald's hiring platform, built on Paradox.ai's "Olivia" chatbot, had exposed records of approximately 64 million applicants — through a 2019 test account with username and password both set to "123456," and an insecure direct object reference that allowed iterating through applicant IDs. The exposed data included interview transcripts with Olivia. The GDPR and CCPA breach notification obligations and the class action exposure that flows from a breach at that scale dwarf any individual LL144 penalty.
My working assumption after that disclosure: the CISO needs to be a stakeholder in AEDT procurement and the compliance program needs a vendor security review discipline. A program that tests for bias but doesn't review the attack surface of each third-party platform is testing one liability theory while leaving another fully open.
Where the Compliance Program Actually Stalls

The version of this problem I see most often in practice is an organization that has done the bias audit work — has a DCI or ORCAA methodology audit, at the $50,000 to $200,000 annual cost, knows what a four-fifths ratio is — and is now facing three things simultaneously: a June 30 Colorado deadline for a risk-management program that the audit vendor wasn't scoped to build, a Mobley discovery production that their outside counsel can't fully assess without knowing every AEDT in the stack, and a GC who has just realized that the Illinois-EU proxy conflict isn't in any document their vendor has produced.
The AI Hiring Compliance infrastructure we built at Veriprajna starts from the AEDT inventory — mapping every tool that touches a hiring decision, which jurisdictions it operates in, what it's been audited for, and what remains open. From there, the work is filling in the gaps the existing audit program didn't cover: the cross-jurisdiction reconciliation, the Colorado SB 24-205 documentation, the accessibility testing, the vendor security review, and the Kistler-theory exposure assessment for any platform that scores candidates from scraped data.
The gap isn't that the existing auditors did poor work. DCI and ORCAA run rigorous methodology. The gap is that the existing audit program was scoped to a single methodology and a single jurisdiction, and the legal landscape now requires something that spans all of them.
What I Keep Coming Back To
The question the NY State Comptroller's audit is really asking — and the question I keep returning to when I think about where this lands for buyers — is documentary. Can your organization produce, on short notice, a coherent written account of every AEDT in your hiring stack, what each one was tested for, under which legal theory, and for which jurisdictions? That's the audit methodology the Comptroller used, not employer self-attestation. 31 of 32 companies couldn't answer it.
That's not a bias audit failure. It's an inventory and documentation failure. And it's fixable, but it requires treating the compliance program as an architecture with multiple components — not as a single-vendor, single-methodology, annual-report deliverable.
The Illinois-EU conflict I described to that CHRO and her GC — the one where no vendor had a reconciled methodology — is the piece I find most people aren't expecting. I'd be curious how your legal or compliance team has approached it, if they've gotten there. What's the specific place your program is stalled? Visit veriprajna.com/solutions/ai-hiring-compliance if the documentation architecture question is what's most live for you right now.
The GC on that call still doesn't have a vendor answer. I suspect his counterpart at a lot of other companies doesn't either.