Quick Hits
- Employers need to keep track of two diverging regulatory tracks: the EU AI Act, with transparency obligations enforceable as of August 2, 2026, and further high-risk AI restrictions from 2 December 2027; and the UK’s Data (Use and Access) Act 2025.
- The EU AI Act is a floor, not a ceiling: individual member states layer their own obligations on top.
- U.S. state-by-state AI related employment laws in Illinois, California, New York City, and Colorado are now active or taking effect through 2027, even with a nonregulatory approach at the federal level.
- Similar to the United States, Canada has a province-by-province approach to AI regulation. Quebec, in particular, has passed comprehensive privacy laws that specifically address automated decision-making technologies (ADMT) and the processing of personal information. Each province has a standalone human rights statute that, if violated, can lead to sanctions, and in some provinces, punitive damages in addition to general employment and privacy laws.
- A jurisdiction-by-jurisdiction compliance strategy is no longer sustainable for employers whose AI tools and employee data cross borders; a single, harmonised framework calibrated to the strictest applicable standard is more efficient and lower-risk.
European Union
Under the EU AI Act, the EU’s landmark regulation governing the development and use of AI systems, AI tools used for employment-related decisions, such as recruitment, candidate screening, performance evaluation, task allocation, worker monitoring, and decisions on promotion or termination, are deemed “high-risk”. From 2 December 2027, following a sixteen-month extension agreed under the EU’s “Digital Omnibus” simplification package, these high-risk AI systems will need to satisfy full compliance obligations before they can be placed on the market or put into service. These obligations will include transparency requirements, risk assessment, risk mitigation measures, human oversight, and technical documentation.
The transparency requirements under Article 50 of the EU AI Act took effect on 2 August 2026, requiring organisations to disclose when individuals are interacting with an AI system. A related obligation to label AI-generated or manipulated content, such as deepfake images, audio, or video, as artificially generated was deferred under the Digital Omnibus package and now takes effect on 2 December 2026.
The EU AI Act sets an EU-wide floor, but employers must also navigate member state-specific overlays. In France, for example, to comply with the French labor law, employers must inform and consult the works council (Comité Social et Économique, or CSE) before introducing any new technology, including AI tools, that affects working conditions, employment, or health and safety under Article L. 2312-8 of the Labour Code. Recent case law, including a Paris Court of Appeal decision of 21 May 2026, confirms that deploying such tools without consultation, even during a pilot phase, can lead to a court-ordered suspension of the rollout. Separately, the Commission Nationale de l’Informatique et des Libertés (CNIL)—France’s data protection authority—requires a data protection impact assessment for AI used in recruitment and has announced targeted enforcement action on algorithmic recruitment and performance-evaluation tools in 2026. Employers rolling out AI tools across the EU should expect this kind of national variation and plan for it accordingly, rather than assuming that EU AI Act compliance alone is sufficient in every member state.
United Kingdom
Although the UK has no standalone AI statute, the Data (Use and Access) Act 2025 (the DUA Act) comes closest to a regulatory framework. Section 80 of the DUA Act, which came into force on 5 February 2026, replaced Article 22 of the UK GDPR, fundamentally shifting the UK’s legal approach from a general prohibition with narrow exceptions to a more permissive framework backed by mandatory procedural safeguards.
On 31 March 2026, the Information Commissioner’s Office (ICO) published its ‘Recruitment Rewired’ report, detailing key findings and guidance on the use of automated decision-making (ADM) in recruitment. The ICO’s research revealed an unconscious over-reliance on ADM among employers, a lack of human involvement and monitoring, and gaps in bias testing that the research concluded could amplify historical discrimination embedded in these systems. Compliance with the revised regime under the DUA Act requires detailed mapping and interrogation of the decision-making process, documenting human involvement, and adopting robust safeguards.
United States
At the federal level, there is currently no comprehensive AI legislation, and the current administration has favoured a permissive, deregulatory approach. In response, several states have enacted significant AI legislation to introduce certainty into this regulatory vacuum, resulting in ongoing tension between state and federal approaches. As of the time of writing, there has been no ruling on federal preemption.
The key frameworks are as follows:
New York City enacted Local Law 144, one of the first and most restrictive U.S. laws to directly regulate AI in the recruitment process. It does not allow employers to use automated employment decision tools (AEDT) for hiring, promotion, or termination, unless the tool has undergone an independent annual bias audit and the results have been publicly disclosed. Employers must also notify candidates at least ten business days before an AEDT is used, with instructions for requesting an alternative process. Civil penalties start at $500 for a first violation and rise to $500 to $1,500 for each subsequent violation, with each day of continued noncompliance treated as a separate violation.
In Illinois, HB 3773 was signed into law in 2024 and took effect on 1 January 2026, extending the Illinois Human Rights Act to prevent employers from using AI in a way that discriminates against employees or prospective employees on account of their protected characteristics, regardless of intent. The law also prohibits using zip codes as a proxy for protected classes or race and requires employers to notify employees and applicants whenever AI is used in recruitment, hiring, promotion, discharge, discipline, or other employment decisions. While the Illinois Department of Human Rights temporarily withdrew its draft implementing rules in June 2026, the underlying statutory obligations under HB 3773 remain active.
In California, the California Privacy Protection Agency (CPPA) finalised regulations in September 2025, effective 1 January 2026. These new guidelines require covered businesses to provide notice and access rights when automated decision-making technology is used for significant decisions, including employment decisions such as hiring, termination, and compensation. Separate privacy risk assessment rules, also effective 1 January 2026, are triggered when ADMT is used for significant decisions concerning consumers, including employees in certain contexts. In addition, on September 30, 2026, California Governor Gavin Newsom signed into law a package of bills targeting the use of AI in the workplace.
In Colorado, SB 26-189 was signed into law in May 2026, repealing and replacing the earlier SB 24-205, and takes effect on 1 January 2027. Under the new statute, covered employers must disclose the use of AI in the recruitment process and, within thirty days, provide a description of the automated decision-making technology’s role in any adverse, consequential decision. They must offer an opportunity for human review and allow individuals to request corrections to factually incorrect personal data used by the tool. Employers should note that enforcement may be further delayed by a pending constitutional challenge to Colorado’s predecessor AI law, in which the U.S. Department of Justice has intervened in support of an artificial intelligence company, and which has led the attorney general to state that enforcement of SB 26-189 will also be paused pending its outcome.
The momentum of state regulation can be evidenced through the December 2025 New York State Comptroller audit, which found that the NYC Department of Consumer and Worker Protection (DCWP) had been enforcing NYC Local Law 144 ineffectively; firms are expecting tighter enforcement through 2026 and beyond.
As of September 2026, legislators in several states, including Washington, New Jersey, and Texas, are seeking to replicate the requirements imposed under NYC Local Law 144.
Canada
Canada has no dedicated federal AI statute. The proposed Artificial Intelligence and Data Act (AIDA), which would have introduced federal obligations for high-impact AI systems, died on the order paper when Parliament was prorogued in January 2025 and has not been reintroduced. However, AI use in the employment context is governed principally through targeted provincial legislation and existing general law. In Ontario, the Working for Workers Four Act, 2024 amended the Employment Standards Act, 2000 to require employers with 25 or more employees to disclose, in every publicly advertised job posting, whether AI is used to screen, assess, or select applicants, a requirement that took effect January 1, 2026.
In Quebec, the Act respecting the protection of personal information in the private sector regulates any decision made exclusively on the basis of automated processing of personal information. Where such a decision significantly affects an individual, the organization must inform the individual that the decision was automated and, on request, explain the personal information used and the principal factors and parameters that led to the decision, and must give the individual the opportunity to submit observations to a staff member in a position to review the decision. Before deploying such a system, organizations must conduct a privacy impact assessment (PIA); if the organization cannot demonstrate through that assessment that the risks are mitigated and that the decision is explainable, the tool cannot be adopted compliantly. Penalties under the Quebec Privacy Act can range from 2 percent to 4 percent of global revenue. Because each province has a human rights code prohibiting discrimination on the basis of protected characteristics, together with a designated tribunal to enforce it, employees who believe they have been adversely affected by an AI-driven decision based on a protected ground have recourse available to them throughout Canada. “
Key Takeaways
In effect, wherever an employer uses AI to hire, monitor, or manage people, that employer is responsible for understanding its risks, ensuring human oversight, establishing transparency and preventing discrimination. AI tools also frequently graft onto other regulated areas, such as electronic monitoring, video surveillance, or audio recording and transcription, so a tool assessing employee productivity is necessarily also a monitoring tool and must be evaluated under that lens as well. Because these obligations diverge by jurisdiction, even though the underlying AI tools and data flows typically do not, employers with a multijurisdictional footprint need a coordinated compliance strategy rather than a series of disconnected local fixes.
Employers operating with a view to maintaining multijurisdictional AI and data compliance may want to consider the following:
- mapping where AI tools and employee data actually operate, rather than assuming compliance obligations stop at the home jurisdiction;
- benchmarking existing AI governance and employee notices against the strictest applicable standard across the EU, UK, relevant U.S. states, and Canada, rather than the most lenient; and
- building a single, coordinated AI and data compliance framework, rather than treating each jurisdiction’s obligations as a standalone project.
Ogletree Deakins’ Artificial Intelligence and Innovation Practice Group, Cross-Border Practice Group, and Cybersecurity and Privacy Practice Group, working across our U.S., UK, European, and Canadian offices, will continue to monitor developments and provide updates on the Artificial Intelligence and Innovation, Cross-Border, and Cybersecurity and Privacy blogs as additional information becomes available.
In addition, the Ogletree Deakins Client Portal provides subscribers with timely updates on state laws related to artificial intelligence, including automated employment decisions. Premium-level subscribers have access to comprehensive law summaries, policies, and templates. Snapshots and Updates are complimentary for all registered client users. For more information on the Client Portal or a Client Portal subscription, please email clientportal@ogletree.com.
Follow and Subscribe
LinkedIn | Instagram | Webinars | Podcasts