This article was originally published in June 2023. It has been refreshed with new information.
Can AI technologies increase your business’s vulnerability to anti-discrimination lawsuits?
Proposed legislations regulating AI technologies say an unequivocal yes.
What began as a handful of proposed bills back in 2023 has become an active, enforceable patchwork of state and federal AI employment law. HR teams that assumed they had more runway to prepare are now working against real deadlines.
In 2022, the EEOC reported 73,485 lawsuits filed against businesses. if HR leaders aren’t careful, AI involvement in recruiting can raise that number.
Industry leaders like Sam Altman, Geoffrey Hinton, and Timnit Gebru have voiced concerns about how bias and discrimination can be trained into AI.
This article will define the possible legislative minefield HR teams must navigate to avoid having their AI instruments become diversity, equity, and inclusivity (DEI) or privacy law liabilities.
A solid grasp of what lawmakers have drafted (e.g., The EU AI Act and AI Bill of Rights) to regulate AI technologies can help prepare HR leaders on which AI-driven products will comply with their state and federal regulatory practices.
Can generative AI comply with current DEI and privacy regulations?
AI adoption into the field of HR has always been difficult due to the sensitive data HR professionals work with regularly.
The challenge of employing AI in HR is that the nature of employee relations, workplace investigations, and managing company culture problems are highly contextual and interpreted on a case-by-case basis.
The advent of generative AI instruments like ChatGPT and Bard bridges this gap with their ability to interpret conversations and generate human-like responses, allowing them to learn directly from HR case examples.
Generative AI chatbots can automate HR support cases by learning from each employee-HR interaction to improve future responses.
Personal data like social security numbers, birthdays, demographics, health records, etc., are also challenging because the Privacy Act and HIPAA protect them. AI instruments that analyze these data types are under the same scrutiny as HR professionals to ensure they comply with federal and state laws.
HR compliance software helps businesses understand complex and ever-changing state and federal compliance legislation.
Demand for that kind of help hasn't slowed down. G2's HR Compliance category now tracks 131 products with more than 33,300 verified reviews and an average rating of 4.54 out of 5 as of August 2026 - a sign that HR teams are still actively investing in tools to keep pace with the regulatory pace-setting described in this article.
Even before the generative AI craze was triggered, industry experts were already warning consumers about AI being too biased for real-world application.
The "two states" era of AI-in-hiring law is over. What used to be an early-mover story out of New York City and Illinois is now a genuine multi-state compliance landscape:
In the EMEA and APAC regions, regulations about AI in HR are indirectly impacted by broader regulatory actions around privacy, like the General Data Protection Regulation (GDPR) for the EU and the Digital Personal Data Protection Bill (DPDPB) for Indian businesses.
More US state lawmakers say no, AI can’t comply with DEI and privacy regulations without oversight.
The US is at the forefront of developing innovations in the AI space and is also at the forefront of implementing regulations to reign in the misuse of AI instruments. Congress hasn’t responded yet, but there have been rumblings at the federal level from the White House on what kinds of regulations they would like to see passed.
At the state level, the response has been more robust, if a little eccentric.
What was a wave of roughly 20 proposed bills in 2023 has become a substantial body of enacted law across Illinois, Colorado, California, Connecticut, Texas, and New York City - each with its own scope, enforcement mechanism, and notice requirements. For any multistate employer, this means overlapping obligations rather than a single standard to design around.
Legislations of interest:
The EU Artificial Intelligence Act classifies AI-driven HR software as high-risk.
The EU is responding at the federal level and explicitly states which responsibilities of HR functions are to be protected from poor AI implementation.
Any AI decision making involved in the professional longevity and prosperity of EU citizens is to be heavily scrutinized.
“AI systems used in employment, workers management and access to self-employment, notably for the recruitment and selection of persons, for making decisions on promotion and termination and for task allocation, monitoring or evaluation of persons in work-related contractual relationships, should also be classified as high-risk.”
This proposed Artificial Intelligence Act draft goes so far as to explicitly classify AI technology involved in initiating, promoting, or terminating employees as “high-risk AI systems.” The authors justify this attention by pointing out how these systems can,
“ . . . perpetuate historical patterns of discrimination, for example against women, certain age groups, persons with disabilities, or persons of certain racial or ethnic origins or sexual orientation. AI systems used to monitor the performance and behavior of these persons may also undermine the essence of their fundamental impact on their rights to data protection and privacy.”
The language in this document does not specify the types of AI technologies and what constitutes an AI system. It provides no details on the regulatory body that will audit these technologies and no information on possible repercussions for violations.
If anything, this is legislation at the federal level and will lead to the founding of numerous regulatory agencies and local government regulations.
As of 2026, this is no longer a proposal - and the timeline has shifted since this article was first published. High-risk obligations were originally scheduled to apply from August 2, 2026. Following the EU's "Digital Omnibus" negotiations, that deadline has been provisionally pushed to December 2, 2027 for most high-risk systems, with a further deadline of August 2, 2028 for high-risk AI embedded in regulated products. The delay is not a reprieve from the substance of the law: employment-related AI remains squarely high-risk, and the European Commission's 2026 draft guidance makes clear that tools which source, score, rank, shortlist, or match candidates are considered high-risk whenever they materially influence recruitment outcomes - even if a human makes the final call.
By classifying AI systems involved in HR business functions as high-risk, HR departments must take extra care when adopting these new technologies into their tech stack.
Frequently Asked Questions (FAQs)
Q1. What makes an AI system "high-risk" for HR use?
Under the EU AI Act, AI is high-risk in HR if it materially shapes decisions on recruitment, promotion, termination, task allocation, or worker monitoring - even when a human makes the final call.
Q2. Which US states currently regulate AI in hiring?
Illinois, Colorado, California, Connecticut, and Texas, plus NYC's Local Law 144. Requirements vary - audits, disclosure, or narrower oversight - so multistate employers face overlapping rules, not one standard.
Q3. Does using AI in hiring protect employers from discrimination claims?
Not entirely. Several states, including Connecticut, say automated tools are no defense to a discrimination claim - though bias-testing efforts can count as a mitigating factor.
Q4. What should HR teams do now?
Inventory every AI tool touching hiring, promotion, or monitoring, map it against applicable states/countries, and confirm it can meet upcoming audit and disclosure requirements.
Introducing sophisticated AI systems into HR workflows and tech stacks substantially benefits productivity, efficiency, and innovation.
However, HR teams need to manage a delicate balance between strict legal compliance with a rapidly evolving regulatory environment and maximizing the benefits AI offers to their employees.
HR teams can maximize the benefits of AI systems with a minimum amount of risk by following the expertise provided by HR compliance software.
With EU obligations now delayed rather than cancelled, and US state laws taking effect on a rolling basis through 2027, the safest posture for HR leaders is to build a compliance program now rather than wait for a single deadline. That means inventorying every AI tool touching hiring, promotion, or monitoring decisions, and confirming each one can support the audits, disclosures, and human-oversight requirements that regulators are converging on
These documents have set expectations and standards for future regulatory actions by lawmakers worldwide.
Learn more about the State of HR Analytics in 2026: Why Humans Still Lead