Yes, when they’re built for human oversight. The AI runs a structured screening interview and surfaces signal, a person makes every hiring decision, and the tool never rejects a candidate on its own. AI interviews become a legal risk when an opaque system screens people out with no human review and no independent bias audit behind it.
The people who adopt AI interviews are usually the ones who end up defending the choice to a legal or HR partner. That partner wants to know which laws apply, what a defensible setup looks like, and what to require of a vendor before you sign.
Are AI interviews legal?
No law in the United States or the EU bans AI interviews outright. What the law governs is how you use them: whether candidates are told, whether the tool has been audited for bias, and whether a person, not the software, makes the call. Used that way, AI screening interviews are legal today across every major jurisdiction.
Where the real compliance risk comes from
Most AI hiring lawsuits and regulator actions come down to one idea: disparate impact. A tool can look neutral and still screen out candidates of one race, gender, or age group at a higher rate, and under US law the employer is responsible for that outcome whether or not anyone intended it.
The federal benchmark is the four-fifths rule: if one group passes a screen at less than 80% of the rate of the highest-scoring group, that gap is treated as evidence of adverse impact. An AI interview that scores and ranks candidates is exactly the kind of tool that can produce that gap at scale, across thousands of applicants, before anyone notices.
Low candidate trust is the other half of the problem. In Greenhouse’s 2026 survey, only 8% of job seekers said they think AI makes hiring fairer. Candidates and regulators both start from doubt, and a bias-audited, human-reviewed process is resolves that doubt.
The laws that govern AI in hiring
A handful of laws now govern AI in hiring directly, with more taking effect over the next two years. They vary in the details, but the core requirements are consistent: be transparent with candidates, audit for bias, and keep a person in the decision.
NYC Local Law 144
As of 2026, New York City requires any employer using an automated employment decision tool to have it independently audited for bias within the past year, publish a summary of that audit, and notify candidates at least 10 business days before they’re screened.
The rule is enforced by the NYC Department of Consumer and Worker Protection. Penalties run up to $500 for a first violation and $500 to $1,500 for each one after, and every day a non-compliant tool is used can count separately.
Illinois
Illinois requires employers that use AI to analyze recorded video interviews to notify applicants first, explain how the AI works, get their consent, and delete the recording within 30 days on request. That is the AI Video Interview Act, in force since 2020.
Illinois went further in 2026: a new provision of the state Human Rights Act, effective January 1, 2026, makes it a civil rights violation to use AI in hiring in a way that discriminates against a protected group, or to use a candidate’s zip code as a stand-in for one. Employers also have to tell candidates when AI is being used.
Colorado
Colorado has passed the broadest state AI law, and its main employer requirements now take effect January 1, 2027. The original 2024 law was delayed, then replaced in May 2026 by a new act that reset both the timeline and the rules.
Starting in 2027, a company using automated decision technology for an employment decision has to give candidates notice, provide a plain-language explanation within 30 days of an adverse decision, allow access to and correction of personal data, and offer a human review of the outcome. Employment is named explicitly as a covered decision.
EU AI Act
For employers hiring in the EU, the AI Act treats hiring and worker-management systems as high-risk, and the obligations that come with that are currently set to apply from December 2, 2027.
The Act entered into force in 2024 and applies in stages: bans on certain practices took effect in early 2025, and transparency rules follow in 2026. The high-risk rules, the category that covers AI used to recruit, screen, or evaluate workers, are the ones employers care about most.
Following a 2026 agreement to simplify the Act, the European Commission’s current timeline sets those high-risk employment obligations to apply from December 2, 2027. That date reflects a political agreement reached in May 2026 and could still shift before it’s final, so treat it as the Commission’s current position rather than a settled deadline. When they apply, the high-risk rules call for human oversight, risk management, documentation, logging, and transparency about how the system works.
EEOC and Title VII (US federal)
At the federal level there is no AI-specific hiring law, but Title VII of the Civil Rights Act already applies: if an AI screening tool produces a discriminatory outcome, the employer is liable, exactly as they would be for any other selection procedure.
The Equal Employment Opportunity Commission’s guidance on AI under Title VII, and its guidance on AI under the Americans with Disabilities Act, both remain published and in effect as of mid-2026. A federal executive order on AI from the prior administration was revoked in January 2025, but that changed policy direction, not the underlying law.
The EEOC has said that when technology automates the discrimination, the employer is still responsible. Keeping a person in the decision is how you manage that responsibility.
Other laws worth knowing
A few more are now in force or close to it:
- California’s civil rights regulations on automated decision systems took effect in October 2025 and require employers to keep AI-related hiring records for four years.
- Maryland requires a candidate’s written consent before an employer uses facial-recognition analysis in an interview.
- Ontario now requires employers to disclose in a job posting when AI is used to screen applicants, which matters for anyone hiring in Canada.
- Texas passed a broad AI governance law in 2026, but it specifically excludes the employment context, so it’s not an AI-hiring rule despite how it is sometimes described.
At a glance: regulation-to-control table
As of July 2026, here is how the major requirements line up against a compliant setup.
| Law | What it requires | Main effective date | A compliant setup includes | Primary source |
|---|---|---|---|---|
| NYC Local Law 144 | Independent bias audit within the past year, published audit summary, candidate notice 10 business days out | In effect | Published third-party bias audit; candidate-notice step | NYC Dept. of Consumer & Worker Protection |
| Illinois AI Video Interview Act | Notice, explanation, consent, deletion within 30 days on request | In effect | Consent and disclosure step; deletion on request | Illinois General Assembly |
| Illinois Human Rights Act (AI provision) | No discriminatory-effect AI in hiring; no zip-code proxy; notify candidates | January 1, 2026 | Human-in-the-loop decisions; bias audit; disclosure | Illinois General Assembly |
| Colorado AI Act | Notice, plain-language explanation, human review of adverse decisions, records | January 1, 2027 | Human review of outcomes; candidate notice; audit-ready records | Colorado General Assembly |
| EU AI Act (high-risk employment) | Human oversight, risk management, documentation, logging, transparency | December 2, 2027 (current EC timeline) | Human oversight; documentation; audit-ready logs | European Commission |
| Title VII / EEOC (US federal) | No disparate impact; employer liable for the tool’s outcomes | In effect | Bias audit; human-in-the-loop; adverse-impact monitoring | EEOC; 42 U.S.C. 2000e-2 |
| California (FEHA automated-decision rules) | No discriminatory automated decisions; keep records four years | October 1, 2025 | Bias audit; four-year record retention | California Civil Rights Department |
What an independent bias audit actually is
A bias audit tests whether a hiring tool produces different outcomes for different demographic groups, run against real or representative candidate data. A vendor can run its own internal fairness tests and report that everything looks fine, and many do. An independent third-party audit is different: an outside firm examines the tool and publishes the result, so you are not relying on the vendor’s own account of itself.
Across AI interview vendors, some publish a current third-party audit you can actually read. Others describe audits they’ve run but do not make the document available. NYC Local Law 144 does not ask whether a vendor believes its tool is fair; it asks for a published, independent audit. Ask for the document itself, not just a reassurance that one exists.
Does the AI make the decision?
No, at least not in a compliant setup, and not with BrightHire Screen. The AI conducts a structured screening interview and surfaces signal for a recruiter to review. A person decides if a candidate moves forward or not.
A person making that call is the most important compliance control you have. BrightHire Screen doesn’t auto-disposition candidates, remove anyone from consideration, or recommend who to advance. It also doesn’t train on your candidate data.
The questions your legal and HR partners will ask
When a compliance or HR partner reviews an AI interview tool, the same questions come up almost every time. Have the answers ready, or send this list to a vendor and ask for answers in writing.
- Does the AI reject anyone on its own, or does a human make every decision? With Screen, a person makes every advancement and rejection decision.
- Has the tool had an independent bias audit, and can we see it? Look for a current third-party audit you can read, not a self-certification.
- What data is collected, how long is it kept, and is it used to train the vendor’s models? BrightHire offers a zero-data-retention option and does not train on customer data. [SME: standard retention periods to quote here]
- How are candidates told, and how does opt-out work, including someone who opts out partway through? Confirm the disclosure step and how a mid-process opt-out is handled, including deletion of anything already recorded. [SME: confirm Screen’s opt-out-across-rounds behavior]
- Which laws apply to us, given where we hire, and how does a vendor’s tool address each one? Check the regulation table above for the first part, then ask the vendor directly for the second.
- Can the vendor provide an AI privacy impact assessment, along with SOC 2, GDPR, and CCPA documentation? Legal teams routinely ask for these by name; have them ready.
- Does the vendor align its AI governance to the NIST AI Risk Management Framework or ISO/IEC 42001? Both are voluntary frameworks rather than laws, but alignment shows a vendor takes governance seriously.
Data privacy and security
For a security review, here is the baseline BrightHire meets: SOC 2 Type II, GDPR, and CCPA compliance, a zero-data-retention option, and candidate consent and opt-out built in. The AI does not train on your candidate data.
Disclosing AI interviews without losing candidates
Disclosure is both a legal requirement in several places and a trust problem everywhere. In Greenhouse’s 2026 survey, 70% of candidates who had done an AI interview said it was not clearly disclosed to them. That gap is both a legal problem and a trust problem: several of these laws now require candidates to be informed.
The interview format matters even more than the disclosure. In a 2026 University of Exeter working paper that randomized more than 3,000 applicants, moving from a live interview to a one-way, asynchronous format more than halved the number of applicants who completed the process. This included the most qualified among them, and the falloff was largest for women.
A format that pushes one protected group out of your pipeline at a higher rate is a fairness problem in its own right, even though those candidates are withdrawing rather than being rejected. A two-way conversation that a candidate experiences as a real interview, clearly disclosed up front, keeps far more people in the process than a recorded monologue they did not expect.
How BrightHire Screen is built for compliance
Screen is designed around human oversight from the start. The AI runs a structured screening interview, scores answers against the criteria your team defined, and hands a recruiter the evidence to review. A person makes every decision. Around that sit independent third-party bias audits, audit-ready records of each interview, SOC 2 Type II, GDPR, and CCPA compliance, a zero-data-retention option, and no training on your data.
Compliance is the fifth of the seven pillars of the quality of hiring system that BrightHire builds toward: the Trust and Compliance pillar.
reviewed BrightHire’s approach to fair hiring and said: “BrightHire is an invaluable tool for supporting a fair and compliant hiring process. It ensures that employers have complete and accurate records, that candidates are considered consistently, and gives employers the ability to ensure interviews are conducted properly.” An outside legal read carries weight a vendor’s own description can’t. It’s the same reason the bias audits above are independent and third-party instead of self-run.
AI interview compliance – FAQ
Are AI interviews legal?
Yes. No US or EU law bans them. They are legal when candidates are informed, the tool has an independent bias audit, and a person makes the hiring decision.
Can AI reject a candidate automatically?
It should not, and with BrightHire Screen it does not. Screen surfaces signal for a recruiter; a person makes every advancement and rejection decision. A tool that auto-rejects candidates is where most legal risk begins.
Do AI interviews comply with NYC Local Law 144?
They can. The law requires an independent bias audit within the past year, a published audit summary, and candidate notice at least 10 business days before use. Confirm your vendor provides a current, readable audit.
Does the EU AI Act apply to AI interviews?
Yes. The Act treats AI used to recruit, screen, or evaluate workers as high-risk. Under the European Commission’s current timeline, those employment obligations are set to apply from December 2, 2027.
What is a bias audit for AI hiring?
It is an independent test of whether a hiring tool produces different outcomes across demographic groups. The audit that counts is run by an outside firm and published, not self-certified by the vendor.
Do humans review AI interview results?
In a compliant setup, yes. The AI provides an assessment; a recruiter reviews the evidence and decides. With BrightHire Screen, every hire, pass, or rejection is a human decision.
Is AI interview data secure?
Look for SOC 2 Type II, GDPR, and CCPA compliance, a data-retention or zero-retention option, and a commitment not to train on your candidate data. BrightHire meets each of these.
Do I have to tell candidates it is an AI interview?
In several places, yes, and everywhere it is good practice. Illinois, the EU AI Act, and Ontario all require disclosure, and clear disclosure also protects candidate trust and your funnel.





