New York City has the only binding AI-specific hiring statute in the United States with a live enforcement regime and a penalty that accrues daily. It has applied since 1 January 2023, enforcement began on 5 July 2023, and until recently almost nothing happened.
On 2 December 2025 the New York State Comptroller published report 2024-N-6, an audit of how the Department of Consumer and Worker Protection enforces Local Law 144. It covered July 2023 to June 2025 and concluded that the enforcement system is ineffective. Two findings carry the report. Auditors placed test calls to 311 about automated employment decision tools and roughly three quarters were misrouted and never reached DCWP. And on substance: DCWP had reviewed the publicly posted bias audits of 32 companies and identified one instance of non-compliance. The Comptroller's staff reviewed the same 32 and identified seventeen.
DCWP has agreed to implement most of the recommendations, has signed a memorandum of understanding with the Office of Technology and Innovation for technical support, and has adopted an internal Enforcement Workbook. Employment counsel have been telling clients since January 2026 to expect more investigations and higher cumulative penalties.
So the useful question is no longer whether this law is enforced. It is what a deployer will need to produce when someone actually looks, and that question gets harder when the tool being audited is an agent.
Does Local Law 144 apply to an AI hiring agent?
The law binds employers and employment agencies using an automated employment decision tool to substantially assist or replace discretionary decision making for hiring or promotion, where the position is located in New York City. Coverage turns on where the job is, not where the candidate or the vendor sits.
An automated employment decision tool is a computational process derived from machine learning, statistical modelling, data analytics or artificial intelligence that issues a simplified output, meaning a score, classification or recommendation, used to substantially assist or replace discretionary decision making for employment decisions that impact natural persons.
The phrase carrying the weight is "substantially assist or replace," and DCWP's rules at 6 RCNY § 5-300 give it three limbs. A tool substantially assists where its output is relied on solely, where it is one of a set of criteria and is weighted more than any other single criterion, or where it is used to overrule conclusions derived from other factors including human decision-making.
The second limb is where agent deployments land without anyone noticing. Teams routinely believe that adding a human reviewer takes them outside the definition. It does not, if the agent's score is the heaviest single input into what that reviewer decides. And an agent that orders a queue, surfacing some candidates and burying others, is weighting its own output above everything else by construction, whatever the reviewer believes they are doing.
The third limb catches the opposite arrangement. An agent that re-ranks a recruiter's shortlist, or that overrides a human call, is substantially replacing discretionary decision making even though a person decided first.
Who can perform a bias audit under Local Law 144?
Not you, and not your vendor. An independent auditor under 6 RCNY § 5-300 is a person or group capable of exercising objective and impartial judgment, and the definition excludes anyone who is or was involved in using, developing or distributing the tool, and anyone holding an employment relationship with, or a direct or material indirect financial interest in, the employer, the employment agency or the vendor.
This provision decides whether a compliance feature means anything.
A great many governance platforms offer bias testing, and a great many agent stacks now carry a field recording that a bias check was performed. Neither evidences the obligation in Section 20-871(a)(1), because the party performing the check is a party the definition disqualifies. A deployer's own record that it tested its own tool proves that testing happened. It does not prove an independent audit happened, and those are different facts about different people.
If a vendor tells you their product satisfies the Local Law 144 bias audit, the question to ask is who the auditor is. If the answer is the product, the answer is no. DCWP maintains no approved list of auditors, so choosing one is the employer's responsibility and the employer's exposure.
What the audit must contain sits in 6 RCNY §§ 5-301 and 5-302. It calculates selection rates, or scoring rates where the tool scores rather than selects, for each sex category, each race and ethnicity category, and each intersection of the two. It computes impact ratios, each group's rate divided by the highest group's rate. The four-fifths figure familiar from EEOC practice is the conventional reference point, though the rules themselves set no passing threshold; the obligation is to measure and publish, not to pass. It records the number of individuals who fell into an unknown category.
On data the rule is stricter than it is usually described. A bias audit must use historical data from the tool's own use. Test data is permitted only where there is insufficient historical data to conduct a statistically significant audit, and where test data is used the summary must explain why historical data was not used and describe how the test data was generated and obtained.
The audit must be no more than one year old at the time the tool is used. That is a rolling condition on use, not an annual event on a calendar, and the distinction matters more for agents than for anything else.
What must be published, and where?
Section 20-871(a)(2), with 6 RCNY § 5-303, requires a summary of the most recent bias audit to be publicly available on the employment section of the employer's or agency's website before the tool is used, carrying the audit date and the distribution date, and remaining posted for at least six months after the tool's latest use for an employment decision.
This is the obligation most often skipped and the easiest to check, because checking it requires no discovery. You look at the website.
It is also the mechanism that makes the rest of the law work, and the Comptroller's audit shows what happens when it does not. Asked how DCWP identifies non-compliance, officials explained that where an employer does not post its audit and does not issue notices, non-compliance is difficult to identify at all. Read that carefully. The law's enforcement depends on employers publishing the evidence of their own compliance, which means the employers most likely to be caught are the ones already trying. That is the gap the Comptroller told DCWP to close, and the Enforcement Workbook and the OTI agreement are the beginning of closing it.
For a deployer running several tools, or one tool across several roles, publication multiplies where the audit does not. A summary describes a tool as used, and a tool used differently in two contexts may need two sets of numbers.
What notice must candidates receive?
Section 20-871(b), with 6 RCNY § 5-304, requires notice to candidates and employees who reside in New York City at least ten business days before the tool is used, stating that an automated employment decision tool will be used, identifying the job qualifications and characteristics it will assess, and explaining how to request an alternative selection process or an accommodation.
Ten business days is roughly two weeks, and it is before use rather than at application. For continuous intake the practical answer is that the notice lives on the job posting and the careers page, which the rules permit.
A second duty runs alongside the notice. Under 6 RCNY § 5-304(d) the employer must post, on the employment section of its website, the type of data collected for the tool, the source of that data and its data retention policy, together with instructions for requesting the same information in writing. A written request must be answered within thirty days. Those are calendar days, not business days: where this law means business days, as it does for the ten-day notice in the same rule, it says so.
Two details are easy to get wrong. The alternative-process right is a right to request, not a right to receive; the rules state in terms that nothing in them requires an employer to provide an alternative selection process. And the residency test is the candidate's while the coverage test is the job's, so a New York City role attracts the obligation regardless of where any particular applicant lives.
Notice failures are counted separately from use violations under Section 20-872, which is where exposure compounds fastest for a high-volume pipeline.
What does Local Law 144 not require?
No right to an explanation. No right to human review. No obligation to disclose an individual candidate's result. And no requirement that the tool be accurate, only that its disparate impact be measured and published.
That last point surprises people arriving from a European frame. Local Law 144 is a disclosure statute wearing a fairness statute's clothes. It does not prohibit a tool with a poor impact ratio. It requires you to measure the ratio, publish it, and tell candidates the tool exists. What happens after that belongs to Title VII, to the New York City Human Rights Law, and to whoever reads your published summary. The collective action against Workday over AI-assisted screening, Mobley v. Workday, travels under discrimination law rather than under any AI statute, which is exactly the route a published summary feeds. There is no private right of action under Local Law 144 itself, which is precisely why the published numbers matter: they become a document a claimant already holds when they sue under something else.
Compare the EU AI Act, where employment sits in Annex III and the obligations run to risk management, human oversight and record-keeping, or India's DPDP framework, where section 8(3) requires the data underlying a decision affecting a person to be complete and accurate. Those regimes ask what your system does. Local Law 144 asks what your system's outcomes look like in aggregate, and then asks you to say so in public.
Colorado has taken a third road. SB 26-189, which replaced the earlier SB 24-205 in May 2026 and takes effect on 1 January 2027, drops the bias-audit model in favour of disclosure plus a human-review pathway for adverse decisions. Anyone building a hiring agent for the US market is now designing against two different theories of what fairness regulation is for.
What happens when the agent changes faster than the audit?
Here is the problem specific to agents, and the one no commentary addresses. A bias audit is a point-in-time artifact. It measures rates produced by a particular system against a particular dataset, and it is good for a year. That model fitted the tool the law was drafted against: a screener with a trained model, retrained occasionally, changed deliberately.
An agent is not that. Its behaviour is a function of a base model the vendor updates on its own schedule, a system prompt the team edits, a retrieval layer whose contents shift as documents change, and a tool set that grows. Any one of those can move selection rates, and none of them looks like a change to "the AEDT" in the sense a compliance calendar tracks.
So a deployer can hold an audit that is eleven months old, valid on its face, describing a system that no longer exists. Nothing in the law addresses this, because the law did not contemplate it. The rules contemplate historical data drawn from the tool's own use, which assumes a stable tool over which history accumulates.
The workable answer is evidential rather than legal. If your agent is audited on historical data, that audit is only as meaningful as your ability to say which version of the system produced the history. That means recording, per decision, the model and version that produced it, the configuration in force, and what the agent actually read before it scored. Those are the same audit trail fields the other frameworks converge on. Without them, you cannot tell an auditor which runs belong to the system under audit, and you cannot tell DCWP whether the published impact ratio describes the tool you are using today.
The same records answer the harder question that arrives with a complaint. When a candidate asks why they were screened out, your position under Local Law 144 is that you owe them no explanation. That position is legally sound and commercially useless if you cannot reconstruct the decision for yourself.
What are the penalties?
Section 20-872 sets a civil penalty of up to $500 for a first violation and for each additional violation occurring on the same day as the first, then between $500 and $1,500 for each subsequent violation. Each day an AEDT is used in violation of Section 20-871(a) is a separate violation, and each failure to provide a required notice under Section 20-871(b) is a separate violation again.
The figures are not the exposure; the accrual is. A tool used without a current audit for a quarter is not a five-hundred-dollar problem. Add separate notice violations across a high-volume pipeline and the arithmetic gets worse quickly.
One further development, often confused with an amendment. Local Law 25 of 2026, enacted on 17 January 2026, directs city agencies to study and report on algorithmic tools affecting municipal employees. It does not change the bias-audit, publication or notice requirements for private employers.
What should a deployer be able to produce?
Four things, and only one of them is a document. An independent auditor's report no more than a year old, from someone with no relationship to you or your vendor. A published summary on the employment section of your website, dated, carrying the source and explanation of the data used, the number of applicants or candidates, the selection or scoring rates, the impact ratios, the intersectional figures, and the unknown-category count. A notice that went out at least ten business days before use, naming the qualifications assessed and the route to request an alternative. And the records that let you say which version of your system produced the decisions the audit measured.
The first three are compliance. The fourth is what keeps the first three true a year from now, and it is the one an agent makes hard and a regulator has not yet asked for.
Truveil produces the records described here, and cites Local Law 144 where an automated tool screens candidates or employees for a New York City role.