New York City did something in 2023 that no other place in America had done: it made bias audits for hiring AI mandatory. Not recommended. Mandatory, with fines of $500 for a first violation and up to $1,500 for each one after that. And every day a non-compliant tool keeps running counts as a separate violation.
The law binds employers. But here is what most vendors miss: your customers cannot comply with it without you. Which means the law lands on your product, your data, and your sales process, even though your name is not in the statute.
What Local Law 144 requires
The law covers what it calls automated employment decision tools: software that substantially assists or replaces discretionary decisions about who gets hired or promoted. Resume screeners, candidate rankers, video interview scoring, assessment algorithms. If the output materially drives the decision, you are likely inside the definition.
An employer or employment agency using such a tool for NYC candidates or employees has three duties. First, the tool must pass an independent bias audit within one year before use: an impartial auditor calculates selection rates and impact ratios by sex and by race or ethnicity. Second, a summary of the audit results must be published on the employer's website. Third, candidates must be told, at least 10 business days before the tool is used on them, that an automated tool is involved, and what job qualifications and characteristics it assesses.
Enforcement sits with the city's Department of Consumer and Worker Protection, and the fines stack daily.
The law binds your customers, and lands on you
Building in one of these categories? Send me one message about what you're building and I'll name the laws you're inside — which documents they demand, and what covers you. Free, usually within a day or two. Start here.
— Santosh
Walk through what your enterprise customer needs to comply: an audit of your tool, run on real data, with impact ratios your tool's logging must be able to produce. A public summary describing your tool's results. A candidate notice that names what your tool assesses.
None of that exists without the vendor's cooperation. So every serious hiring-AI deal with NYC exposure now includes the question: "Give us the audit pack." The vendor who has the audit, the data schema, and the notice template ready closes the deal. The vendor who says "our customers handle their own compliance" watches the deal go to the one who came prepared.
The exposure is not theoretical, and it is not limited to city fines. In 2023, the EEOC settled its first AI hiring discrimination case: iTutorGroup's software automatically rejected older applicants, and the company paid $365,000. Then Mobley v. Workday went further. A federal court let a collective action proceed against Workday's AI screening and accepted that the AI vendor itself, not just the employer, can be sued as if it were making the hiring decision. In January 2026 the court authorized notice to potentially millions of rejected applicants. City fines are the floor here, not the ceiling.
One city, but the pattern is national
Local Law 144 was first. It is no longer alone. Colorado's AI Act treats hiring as a high-risk use and brings impact assessments and consumer notices from 2026. California's Civil Rights Department has finalized regulations on automated decision systems in employment. And Connecticut SB 5 adds written candidate notices from 2027, notices that must name your tool and your data sources.
Build the audit and notice machinery once, for NYC, and you are most of the way ready for all of them. Ignore it, and you re-fight the same compliance battle state by state.
Where you incorporate does not protect you
The familiar trap, one more time: a Delaware C-Corp or Wyoming LLC selling a screening tool used on NYC candidates is inside this law's reach. The duty follows where the candidates are, not where your company is registered. Remote roles that can be filled from New York count too, which for most software companies means: assume you are covered.
Three things to fix before you scale
1. Get audit-ready before a customer asks. An audit needs data: selection rates by sex and race or ethnicity categories, logged in a way an independent auditor can work with. If your product does not capture what the impact-ratio math needs, retrofit that now, in the quiet, not during a deal.
2. Ship the notice pack with the product. A candidate notice template that names the tool and what it assesses, ready for your customer's legal team to adopt. It costs you a page of writing and wins you every deal where the other vendor made the customer draft it themselves.
3. Put change control around the model. The audit covers the tool as it was tested. A model update, a new scoring feature, a changed cutoff can put you outside what the audit examined. Version your models, and define which changes trigger a re-audit. Your release process is now part of your compliance story.
The one-line summary for each founder
Screening and ranking tools: the bias audit is now a sales document. Have it before the customer asks.
Video interview and assessment scoring: "substantially assists the decision" includes you, even if a human clicks the final button.
HR platforms embedding third-party AI: your customers' notices must describe what the tool assesses. That description comes from you.
Everyone in hiring AI: NYC audits today, Colorado impact assessments and Connecticut notices next. One compliance build covers the map.
Local Law 144 looked like a New York quirk in 2023. It turned out to be the template. The vendors who treated the audit as a product feature are now closing enterprise deals with it. The ones who treated it as their customers' problem are finding out that, in the customer's eyes, the vendor without an audit pack is the risk.
Building a hiring or HR AI product? Send me one message about what you're building, and I'll name the rules you're inside.