US State AI & Privacy Laws

NYC Local Law 144

New York City Local Law 144 of 2021 on Automated Employment Decision Tools (NYC Admin. Code §§ 20-870 to 20-874)

The first US law to regulate AI hiring tools directly: annual independent bias audits, public posting of results, and advance notice to candidates before an automated employment decision tool is used on them.

New York City (jobs and promotions located in NYC, wherever the employer or tool vendor is based)Enacted 2021; enforced since July 5, 2023Verified 2026-08-31

What it means for AI and data privacy

NYC Local Law 144 prohibits employers and employment agencies from using an automated employment decision tool (AEDT) to screen candidates or employees for NYC jobs or promotions unless the tool has passed an independent bias audit within the past year, a summary of the audit results is publicly posted, and each candidate receives notice at least 10 business days before the tool is used on them. An AEDT is any computational process driven by machine learning, statistical modeling, or data analytics that issues a simplified output (a score, ranking, classification, or recommendation) that substantially assists or replaces discretionary hiring or promotion decisions. The law is about discrimination, but complying with it forces a data discipline most HR teams lack: knowing exactly which AI tools touch candidate data, and controlling what happens when recruiters paste resumes and candidate details into general-purpose AI tools that were never audited. Penalties start at $500 and reach $1,500 per subsequent violation, and each day of use and each candidate denied notice can count as a separate violation.

Who it applies to

  • Employers and employment agencies using AEDTs for jobs or promotions located in New York City
  • Remote and hybrid roles tied to an NYC office, regardless of where the employer is headquartered
  • HR technology vendors whose screening, ranking, or matching tools are used on NYC candidates
  • Recruiters and hiring managers whose everyday AI use, such as asking a chatbot to rank resumes, can create an unaudited AEDT in practice

Enforcement and penalties

The DCWP enforces the law with civil penalties of $500 for a first violation and $500 to $1,500 for each subsequent violation. The multiplication is what makes it expensive: using an unaudited tool counts as a separate violation for each day of use, and failing to give the required notice counts per candidate. A tool used for a month across hundreds of applicants compounds quickly. A December 2025 New York State Comptroller audit criticized DCWP's enforcement as ineffective, and the agency has since formalized its enforcement procedures, so the credible expectation is more enforcement, not less. The law does not create a private right of action for its own requirements, but audit results and notice failures feed discrimination claims under city, state, and federal law.

Key provisions for AI and data privacy

NYC Admin. Code § 20-870 (definitions)

What counts as an automated employment decision tool

An AEDT is a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues a simplified output (score, classification, ranking, or recommendation) used to substantially assist or replace discretionary decision-making in employment decisions. DCWP rules clarify that substantially assist includes relying on the output as the primary factor or using it to overrule human conclusions.

The definition captures more than purpose-built HR software. A general-purpose AI tool becomes an AEDT in function when a recruiter asks it to score or shortlist candidates and the output drives the decision. Organizations need an inventory of every place AI output touches hiring, including informal chatbot use, because the audit and notice obligations attach to the use, not to the vendor's product category.

NYC Admin. Code § 20-871(a) and 6 RCNY § 5-301 (bias audit)

Annual independent bias audit before use

An AEDT may not be used unless it has undergone a bias audit by an independent auditor no more than one year before use. The audit must calculate selection or scoring rates and impact ratios across sex and race/ethnicity categories, using the employer's historical data where available.

For organizations using AI on candidate data, this means every screening tool needs a current, independent audit on file, refreshed annually, and the data pipeline feeding the tool must be clean enough to compute impact ratios by demographic category. It also means an ad hoc AI workflow a recruiter invented cannot be audited, because nobody knows it exists: discovering actual AI use in hiring is a precondition of compliance.

NYC Admin. Code § 20-871(b) (published results)

Public posting of audit results

Before using an AEDT, the employer or agency must publicly post on its website a summary of the most recent bias audit results, including selection rates and impact ratios, and the distribution date of the tool.

Publication turns bias metrics into public, citable evidence. Organizations should assume plaintiffs' counsel, journalists, and regulators read these postings and compare them across years. That raises the stakes on data quality: what candidate data enters the tool, how categories are recorded, and whether the posted numbers can be reproduced from the underlying records.

NYC Admin. Code § 20-871(b)(2) and 6 RCNY § 5-303 (candidate notice)

Notice to candidates 10 business days before use

Candidates and employees who reside in NYC must be told, at least 10 business days before the AEDT is used, that an AEDT will assess them, which job qualifications and characteristics it will use, and how to request an alternative selection process or accommodation. Information about the tool's data sources and retention policy must be available on request.

Notice obligations assume the employer knows which tools will run before screening starts, which is incompatible with recruiters improvising with unapproved AI mid-process. The data-source and retention disclosure also forces the employer to know what its vendors keep. Candidate resumes and personal details pasted into a consumer chatbot sit outside every one of these commitments: no notice was given, no retention policy applies, and no audit covered it.

Practical compliance steps

  1. 1Inventory every tool and workflow where AI output influences screening, ranking, interviewing, or promotion for NYC roles, including informal chatbot use by recruiters
  2. 2Classify which of those uses meet the AEDT definition, and stop or formalize the ones that were never procured or audited
  3. 3Commission an independent bias audit for each in-scope tool and calendar the annual refresh
  4. 4Publish the audit summary on the careers site and build candidate notice, at least 10 business days ahead, into the application workflow
  5. 5Restrict candidate PII from entering unapproved AI tools, with a technical control at the point of entry rather than policy alone
  6. 6Document data sources and retention for each AEDT so candidate requests can be answered within the required timelines
  7. 7Recheck scope whenever a role, vendor, or AI feature changes, since an added scoring feature can pull an existing tool into the law

How Sanitized AI maps to this

AEDT scope and inventory (§ 20-870)

Administrators can see which AI tools recruiting staff actually use in the browser, surfacing the informal screening workflows that would otherwise operate as unaudited AEDTs nobody inventoried.

Bias audit integrity (§ 20-871(a))

Keeping candidate data out of unapproved tools confines screening to the audited toolset, so the published audit actually describes how candidates are assessed in practice.

Candidate notice and data disclosure (§ 20-871(b))

Candidate names, contact details, and resume identifiers are caught and redacted in prompts before staff submit them to general-purpose AI tools, preventing candidate data flows the employer never disclosed and cannot account for.

Enforcement readiness

Usage and interception reporting gives the employer documented evidence of which tools handled candidate data and which flows were blocked, the record a DCWP inquiry or discrimination claim will ask for.

Frequently asked questions

What counts as an automated employment decision tool under NYC Local Law 144?

Any computational process using machine learning, statistical modeling, data analytics, or AI that produces a simplified output, such as a score, ranking, classification, or recommendation, that substantially assists or replaces human judgment in hiring or promotion decisions for NYC jobs. Resume screeners, candidate-ranking systems, and scored video interviews are classic examples. Tools that merely organize applications without scoring or recommending generally fall outside, but adding a ranking feature can pull a tool in.

Does Local Law 144 apply to remote jobs?

It applies when the job or promotion is located in New York City, which DCWP guidance reads to include remote positions associated with an NYC office as well as candidates who are NYC residents receiving notice. An employer headquartered elsewhere still falls under the law when screening for NYC-based roles, and cautious employers apply the notice-and-audit regime to any pipeline that plausibly touches NYC.

What are the penalties for violating NYC Local Law 144?

Civil penalties of $500 for a first violation and $500 to $1,500 for each subsequent one, enforced by the Department of Consumer and Worker Protection. Each day an unaudited or unposted tool is used is a separate violation, and each candidate who did not receive notice can count separately, so exposure scales with hiring volume. Violations also make attractive evidence in discrimination litigation, which is where the larger financial risk usually sits.

Is it a violation to paste candidate resumes into ChatGPT?

Pasting alone is not what the law regulates, but using a general-purpose chatbot to score, rank, or shortlist candidates for an NYC role puts you in AEDT territory with none of the required compliance: no independent bias audit, no published results, no 10-business-day notice. It also sends candidate personal information to a tool with no negotiated retention terms. Most employers respond by restricting candidate PII from unapproved AI tools and confining screening to audited platforms.

Who can perform the independent bias audit?

An independent auditor: a person or group that was not involved in using, developing, or distributing the tool, has no employment relationship with the employer or vendor, and no direct financial interest in either. The audit must be no more than a year old at the time of use and must compute selection rates and impact ratios by sex and race/ethnicity categories. The employer using the tool, not just the vendor, is responsible for ensuring a compliant audit exists.

Does a vendor's bias audit cover my company?

Sometimes, but the obligation stays yours. DCWP rules allow an employer to rely on an audit conducted using historical data from multiple employers, provided the employer supplied its own data if it had any, or the tool has never been used before. You still must verify the audit is current and independent, post the summary yourself, and give your own candidates notice. A vendor's marketing claim of compliance is not an audit on file.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards