07AI implementation
HR and hiring AI implementation, inside the new AI hiring laws
Every other page in this section is an argument about money. This one is not. You can automate sales badly and lose deals. You can automate support badly and annoy customers. If you automate hiring badly, in New York City or anywhere you employ people in the European Union, your problem is a law rather than a customer.
01
Hiring is the function where the law arrived first
The two regimes are at different stages, and it is worth being precise about which is which. In New York City the rules are in force now and have been enforced since 5 July 2023. In the European Union the equivalent duties are written and adopted but not yet applicable: they apply from 2 December 2027, which is later than the date most compliance checklists still carry.
What does not differ between them is where the exposure sits. It sits with you as the employer, not with whichever vendor sold you the screening tool.
That is the whole reason this page reads differently from the others.
02
What automates cleanly
- 01
Scheduling. Interview coordination across several calendars, time zones, panel members and reschedules is pure logistics. It has no protected characteristics in it, no ranking of people, and no decision. It is the safest and often the largest single win in the whole function.
- 02
Onboarding. Offer paperwork, right-to-work document collection, equipment requests, system access, first-week schedules, policy acknowledgements and the chasing that goes with all of it. Same reasoning: administrative, auditable, no judgment about a person.
- 03
Answering candidate and employee questions. Where an application stands, how much leave is left, what the parental policy says, when payroll runs. High volume, repetitive, and it frees a small HR team from being a search engine for its own handbook.
- 04
Job description drafting. A first draft a person edits, checked for language that narrows the applicant pool without meaning to.
None of the above sorts, scores or ranks a human being. That line is the one that matters.
03
Résumé screening: the high-risk step
Screening is what most people mean by AI in hiring, and it is the part with real exposure.
A screening tool learns from your past hiring decisions. If those decisions were skewed, the tool learns the skew and applies it faster and more consistently than any human panel managed. The bias is not introduced by the software. It is inherited, scaled, and made harder to see, because it now arrives as a score with a number next to it.
This is not a theoretical worry. It is the specific harm both of the laws below were written to address.

04
NYC Local Law 144
If you use an automated tool to substantially help decide who gets hired or promoted for a role in New York City, the law puts the duties on you, the employer, and they apply whether the tool was bought or built. The rules were adopted by the New York City Department of Consumer and Worker Protection in April 2023 and have been enforced since 5 July 2023. What the rule actually requires:
- 01
A bias audit no more than one year old. The rule does not order an annual audit in the abstract. It conditions use: you may not use, or continue to use, the tool if more than one year has passed since its most recent bias audit. The difference is worth holding on to. Stop using the tool and you owe no audit at all. Keep using it and the clock is always running, which makes this an operational duty rather than a calendar item.
- 02
An auditor independent of both you and the tool. The rule specifically rules out anyone tied to a vendor that developed or distributed the tool. A report the vendor wrote about the vendor's own product does not discharge this. This is the requirement that surprises buyers most.
- 03
A published summary of the results. The date of the most recent bias audit and a summary of its results, on the employment section of your website, clearly and conspicuously. The summary has to carry the source and explanation of the data, the number of individuals in unknown categories, the selection or scoring rates, and the impact ratios for all categories. That is a real publication, not a line saying an audit happened.
- 04
At least 10 business days of notice to candidates before the tool is used, which can be given by notice on your website, in the job posting, or by mail or email.
On liability, the rule is structural rather than a matter of interpretation: it prohibits employers and employment agencies from using an automated employment decision tool unless these conditions are met, and it treats the vendor as a separate party by barring vendor-linked auditors from being independent. The duty runs to whoever deploys the tool.
05
The EU AI Act
If you hire, select or manage people in the European Union, the EU AI Act classifies recruitment and employment decision systems as high risk. That classification has not changed. The date it starts to bite has. The date moved, and most checklists still carry the old one. These obligations were originally set to apply from 2 August 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026, deferred them. The European Commission states that the rules for systems used in high risk areas, including employment, "will apply from 2 December 2027". High risk AI embedded in regulated products under a different annex moves to 2 August 2028. We are attributing that date to the European Commission's own regulatory framework page, because that is where we read it. The Official Journal text would not open for us, so we are not going to write a sentence that implies we read it there. What a deferral does and does not mean. If you built a plan around 2 August 2026, you were not misinformed and nothing you did is wasted. The deadline moved after the obligations had been written, which is an unusual thing for a law to do to the people who prepared for it, so three things are worth stating plainly:
- 01
The duties did not change, only the date they attach. Nothing in the substance was softened.
- 02
Anything you already put in place still does its job. Human oversight of a hiring tool, logs you can produce, and a written reason for every ranking were all worth having before any law asked for them, and they are what you would be asked to show if a candidate complained tomorrow under any other body of law.
- 03
A date that moved once can move again, in either direction, because a deferral is a legislative decision rather than a fact about the technology. It is worth re-checking rather than filing and forgetting.
06
What high risk brings when it applies. The duties that fall on the deployer, meaning the employer rather than only the provider that built the tool:
- 01
Meaningful human oversight. A named person able to understand the output, override it, and decline to use it. Someone clicking approve on a ranked list they cannot interrogate is not oversight. The requirement asks for competence, training and authority, which are three separate things and it is usually the third that is missing.
- 02
Record keeping. Automatically generated logs, retained for at least six months.
- 03
Telling the people affected. Where the deployer is an employer, workers' representatives and the affected workers are informed before a high risk system is put into use at the workplace.
- 04
Accuracy, robustness and data governance duties on the system itself, with evidence that they were met.
Two jurisdictions, one practical consequence: if you cannot explain, in writing, why a candidate was ranked where they were ranked, you should not be running the tool. New York City asks you to publish evidence about that now. The European Union will ask you for it from December 2027. The build that satisfies both is the same build, which is why the later date is not a reason to wait.
07
What stays with people in hiring
This is a short list and we do not negotiate on it.
- 01
No automated rejection. Software may sort, flag and prepare. A human being decides that another human being is not moving forward, and that person is named in the record.
- 02
No inferring protected characteristics. Not race, not age, not disability, not pregnancy, not religion, not sexual orientation, and not through a proxy like a postcode, a graduation year, a name, or a gap in employment.
- 03
No video or voice analysis that scores personality, emotion or "fit". The claimed science is contested, the disability discrimination exposure is serious, and we will not build it.
- 04
No scraping social media to score candidates.
- 05
No unexplainable scoring. If the tool cannot produce the reasons behind a score in language a rejected candidate could be shown, it does not go in.
- 06
No opaque monitoring of existing employees dressed up as an HR automation.
If what you want is a tool that quietly filters the pile faster and never has to justify itself, Praxis is the wrong firm and we will say so on the first call rather than the third.
08
What this typically runs on
Usually the applicant tracking system already in place, which tends to be Greenhouse, Lever, Workable or Ashby, alongside BambooHR, Rippling or Workday on the HR side. The compliance duties above attach to how the tool is used, not to which logo is on it. A platform being widely adopted does not transfer the obligation away from you.
For the governance side of this, the firm's AI ethics and governance practice is the related page.
Questions
What should you know before the first call?
- Is it legal to use AI to screen resumes?
- It is legal in most places and regulated in some of them. In New York City, using an automated employment decision tool triggers duties under Local Law 144: a bias audit no more than one year old, conducted by an auditor independent of both the employer and the tool's vendor, a published summary of the results, and at least 10 business days of notice to candidates. In the European Union, recruitment and employment decision systems are classified as high risk under the EU AI Act, which brings human oversight, logging and transparency duties that apply from 2 December 2027. In both cases the duties fall on the employer using the tool.
- Did the EU AI Act hiring rules take effect in August 2026?
- No, they were deferred. High risk obligations for employment and recruitment systems were originally due to apply from 2 August 2026, and Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026, moved them to 2 December 2027. The European Commission states that rules for systems used in high risk areas including employment will apply from that date. The obligations themselves were not changed or weakened, only the date from which they apply, so anything an employer put in place for the original deadline still does its job.
- Who is liable if an AI hiring tool discriminates, the employer or the vendor?
- The employer. New York City's Local Law 144 prohibits employers and employment agencies from using an automated employment decision tool unless its conditions are met, and the EU AI Act places a distinct set of duties on the deployer of a high risk system rather than only on the provider that built it. A vendor's assurance that its product is fair is a commercial promise, not a legal defence, and it does not move the obligation off the employer.
- What does an independent bias audit involve under Local Law 144?
- It is an assessment of the tool's selection or scoring rates and impact ratios across sex and race or ethnicity categories, and it must be carried out by a party independent of both the employer and the tool's vendor. The employer then publishes a summary of the results and the date of the most recent audit on the employment section of its website, including the source and explanation of the data and the number of individuals in unknown categories. A report the vendor produced about its own product does not satisfy the requirement, and an audit more than a year old does not support continued use of the tool.
- Can AI reject a job candidate automatically?
- It should not, and we will not build it that way. Automated systems can sort, flag and prepare a shortlist, but the decision that a person is not moving forward should be made and recorded by a named human being. Automated rejection is also the hardest configuration to defend under both the New York City rules and the EU AI Act's high risk requirements, because it is the configuration where nobody can produce a person who understood the output and could have overridden it.
- Which parts of hiring are safe to automate?
- Interview scheduling, onboarding paperwork, document collection, equipment and system access requests, policy acknowledgements, and answering routine candidate or employee questions. None of these sorts, scores or ranks a person, which is what keeps them outside the scope of the automated employment decision rules in New York City and outside the high risk classification in the EU AI Act. They are also usually the largest single time win in the function, which is a happy coincidence rather than a compromise.
- Do these rules apply to a small company?
- The New York City obligations attach to the use of the tool for a role in the city, not to company size, so a small employer running a screening tool is generally in scope on the same basis as a large one. The EU AI Act's high risk duties attach to what the system is used for rather than to headcount, and they apply from 2 December 2027. That is a large compliance load for a small team, which is why a small employer is usually better served automating scheduling and onboarding first and leaving screening alone.
Where this leads
This page is one part of the whole offer: AI across the whole business.
Start with a free consultation
Tell us how a candidate moves from application to first day today, and where you hire. We will tell you which of it can be automated cleanly, which parts the hiring rules now bind, and what we would build first. The call costs nothing and ends with a plain list either way.
No obligation · a scoping conversation first