Securafy AI Lab

AI Hiring Laws in Illinois, California and Colorado: 2026 Guide

Written by Ric Hall | Sep 30, 2026, 2:59:59 PM

Illinois, California and Colorado have each passed a separate AI hiring law in the past thirteen months, and the three took effect on three different dates with three different standards for what counts as a violation. Illinois requires notice to applicants and employees starting January 1, 2026. California made employers liable for vendor tools starting October 1, 2025. Colorado's disclosure rules take effect January 1, 2027. Meeting one state's rule does not protect you in the other two.

If your company uses software to screen resumes, score interviews, rank candidates or flag employees for discipline, you are already operating inside this patchwork, whether your HR team has updated a single policy or not. We see this most often with mid-market employers running an applicant tracking system that quietly added AI scoring as a feature update rather than a deliberate purchase. Nobody in legal or IT signed off on it, and nobody flagged that the feature now falls under three separate state notice requirements. Here is what changed in each state, what is still unsettled, and how to build one program that holds up everywhere you have employees.

Why Did Federal AI Hiring Guidance Disappear?

The EEOC pulled its AI employment guidance from its website in January 2025, days after President Trump signed Executive Order 14179, which directed federal agencies to roll back AI policies viewed as barriers to innovation. Title VII and the Americans with Disabilities Act still apply to algorithm-assisted hiring decisions. What disappeared was the EEOC's specific technical direction on how those laws apply to scoring, ranking and screening tools.

That gap is why three state legislatures moved on their own timelines instead of waiting for federal clarity, and why a policy your HR team wrote in 2024 is already out of date. Employers used to be able to point to a single federal framework and call it a day. That option is gone, and it is not coming back soon, which means the compliance floor for AI hiring tools is now set state by state, by whichever legislature moves first. You need a standing reference that gets updated as the rules change, not a document sitting untouched in a shared drive since the last time someone asked about this.

What Does Illinois Require Now?

Illinois requires notice whenever AI plays a role in a covered employment decision, and it bans using zip code as a stand-in for a protected class. House Bill 3773, signed as Public Act 103-0804, amended the Illinois Human Rights Act and took effect January 1, 2026. It covers recruitment, hiring, promotion, discharge, discipline and any other term or condition of employment where AI factors into the outcome.

The compliance picture is messier than the statute alone suggests. The Illinois Department of Human Rights withdrew its proposed rules on how the notice requirement should work in practice on June 2, 2026, and has not given a new timeline. That does not put your obligation on hold. The underlying statutory duty to notify applicants and employees has applied since January 1 regardless of whether implementing rules exist. If you are waiting for Springfield to spell out exactly what a compliant notice looks like, you are already behind.

In practice, this means your talent acquisition team needs a notice built into every job posting and application flow that uses AI screening, not a line buried in an employee handbook nobody reads at intake. It also means your vendor addendum needs to say who is responsible for updating that notice language when the rules eventually get finalized. Waiting for a final rule before you touch either document just guarantees a scramble later.

What Changed With California's Automated-Decision Rules?

California now holds you responsible for a discriminatory outcome from an AI hiring tool even when a vendor built and trained the model. The Civil Rights Council's automated-decision-system regulations took effect October 1, 2025, and apply broadly to California employers, with no minimum size carve-out for the automated-decision provisions themselves.

The regulations define an automated-decision system to cover resume screening software, interview scoring tools, skills assessments and promotion algorithms, essentially anything that makes or substantially assists a decision about an employment benefit. They also add an agency theory to California's Fair Employment and Housing Act, so pointing to a vendor's model as the source of a biased outcome does not shield you from liability. Employers must retain ADS-related records, including scoring data and testing results, for four years, which means your vendor contracts need to spell out who keeps what and for how long before you sign anything new. Our cybersecurity buyer's guide covers the vendor accountability questions worth asking before any AI tool touches employee data.

The agency theory is the part employers underestimate. If you use a staffing agency or a third-party recruiter that runs its own AI screening on your behalf, their tool's discriminatory outcome is now your exposure too, not just theirs. That changes how you should be writing staffing agreements, not just software licenses, and it is worth a specific conversation with any outside recruiting partner about what their tool actually does with candidate data.

Where Does Colorado's Law Land Now?

Colorado replaced its original AI Act with a narrower disclosure framework, and the new deadline is January 1, 2027. SB 26-189, signed May 14, 2026, drops the duty-of-care and formal impact-assessment requirements from the first version of the law and replaces them with pre-use notice, post-decision disclosure and a right to request human review for consequential decisions, including employment.

A later effective date is not a reason to wait. Employers must give a plain-language explanation within thirty days of an adverse decision under the new framework, along with a three-year records retention duty. Treat the extra runway as time to test a program against the two states already enforcing their rules, so Colorado's requirements land on a system you have already run, not a blank page.

The pivot away from the original Colorado AI Act matters beyond that state's borders. Colorado's first version leaned on a European-style duty-of-care model, and its replacement with a lighter disclosure framework is a signal that other states drafting their own bills are watching what survives legal and business pushback. Do not assume every future state law will mirror Illinois or California. Build your program around the specific obligations, not a guess at what a "typical" AI employment law will require.

Is This Only A Legal Compliance Problem?

No. A hiring tool can satisfy every notice requirement in Illinois and every recordkeeping duty in California and still fail a basic security review if nobody has checked whether it logs its own decisions or whether a vendor update silently changed how it scores candidates.

California's four-year recordkeeping duty and Illinois's notice requirement are legal obligations on paper, but meeting them in practice is an operational control problem. You need a record of which model version made which decision, logs that cannot be edited after the fact, and a change-management process that flags when a vendor pushes a model update. Running a cybersecurity assessment against the tools that touch hiring decisions is the fastest way to find out which of your systems already produce that trail and which do not.

What Does A Program That Works In All Three States Look Like?

Building one governance program to the strictest applicable standard costs less than maintaining three separate policies, and it protects you when a fourth state passes its own law next year. Start by identifying which tools you already use actually touch a regulated decision, because most companies cannot answer that question without checking first.

Ownership matters as much as the checklist itself. Legal should own the notice language and the regulatory tracking, IT and security should own the audit trail and vendor technical review, and HR should own the human-in-the-loop step that keeps a final call out of the algorithm's hands alone. When those three groups run separate projects on separate timelines, you end up with a notice that says one thing and a tool that does another, which is worse than having no notice at all because it is evidence you knew and did not follow through.

A defensible program includes:

  • Written notice to candidates and employees whenever AI materially factors into a hiring, promotion, discipline or discharge decision
  • A vendor contract clause requiring your AI providers to disclose what data they use to score candidates and to support your recordkeeping obligations for at least four years
  • A documented human review step for any decision an automated tool influences, so no employment action rests on the tool's output alone
  • A quarterly review of what your scoring tools weigh, checking for proxies like zip code, school name or employment gaps that can stand in for a protected characteristic
  • An audit trail that can reconstruct, after the fact, exactly what data a tool used and what it recommended for any single decision

Our AI governance services build this as one workstream instead of splitting it between legal and IT, because a policy legal wrote and IT never implemented protects nobody.

The table below shows where each state stands as this article was written. Treat it as a floor, not a ceiling. Building to the strictest column, not the most lenient one, is the only version of this that scales as more states pass their own rules.

State Governing law Effective date Core employer obligation
Illinois HB 3773 (Illinois Human Rights Act amendment) January 1, 2026 Notice to applicants and employees, plus a ban on zip code as a protected-class proxy
California Civil Rights Council automated-decision-system regulations October 1, 2025 Agency liability for vendor tools, plus four-year recordkeeping
Colorado SB 26-189 (replacing the original Colorado AI Act) January 1, 2027 Pre-use notice and post-decision disclosure for consequential automated decisions

Where To Go From Here

Three states now have three different answers to what counts as a compliant AI hiring decision, and the fastest way to fall behind is treating this as a one-time policy update instead of an ongoing operational one. Pick one hiring tool you use today and find out whether it can actually produce the audit trail these laws require.

If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.

If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.