
- NY State auditors reviewed the same 32 companies NYC had already checked for AI hiring bias.
The city found 1 violation.
The state found 17.
As of Dec 2025, the city agreed to start hunting for violations instead of waiting for complaints. "Null compliance" is over. 🧵 - The trap: a company hiring in NYC, Chicago, Denver, Austin, London and the EU is now under six overlapping AI-hiring (AEDT) regimes.
Three went live in the last year. Three go hot before August 2026. - Already live:
• Illinois HB 3773 — Jan 1, 2026
• Texas TRAIGA — Jan 1, 2026
• California FEHA ADS rules — Oct 1, 2025
About to go hot:
• Colorado SB 24-205 — June 30
• EU AI Act (recruitment = high-risk) — Aug 2
• NYC's new proactive enforcement - And they openly contradict each other.
Illinois bans zip codes as a proxy for protected class.
The EU AI Act demands "representative" training data — which often needs exactly that geographic coverage.
Strip zip codes, fail the EU. Keep them, fail Illinois. - Texas rejected disparate impact entirely — only intent counts. NYC and California act on disparate impact. And TX and CO give no private right of action, so your real exposure shifts state to state.
A single "universal bias audit" doesn't exist. We stopped pretending otherwise. - Then the vendor problem.
In Mobley v. Workday, Judge Rita Lin held an AI hiring tool can be directly liable as your "agent" when it filters or recommends candidates.
The 2024 memo saying "our vendor swears it's not an AEDT" is now a plaintiff's discovery exhibit. - New front, Jan 2026: Kistler v. Eightfold asks whether AI hiring platforms are FCRA "consumer reporting agencies."
The claim: 1.5B data points scraped, candidates scored 0–5, no notice or dispute process.
If it lands, every scored candidate is owed an adverse-action notice. - Security is a hiring-compliance problem now too.
June 2025: McDonald's McHire (built on Paradox) exposed ~64M applicant records. Root cause — an admin account with the password "123456" and no MFA.
The compliance stack doesn't care the weak link was your vendor. - And LL144 audits don't even test the case that's coming.
ACLU's complaint over a Deaf applicant points at speech-to-text bias — top research models still hit ~8% word error on impaired speech, multiples of the standard benchmark. A separate ADA theory most stacks own none of. - The math: one unaudited AEDT in NYC runs up to $1,500/day/violation — ~$547K/year/tool. EU exposure reaches €35M or 7% of global turnover.
Big 4 charges $500K+ and doesn't build. Software vendors ship one methodology. The gap is a specialist who audits AND builds. - If you run AEDTs across multiple states, what's your move when two regimes flatly contradict — pick the strictest standard everywhere, or build per-jurisdiction? This genuinely splits rooms. #AIhiring #LL144
- We mapped all six regimes, the conflicts, and the live litigation into one operator's playbook for CHROs and GCs: https://veriprajna.com/solutions/ai-hiring-compliance