400 AI Bills. One Architecture Buyers Can Actually Inspect.
What architecture can prove, and which legal duties still require process and counsel

No single deployment architecture guarantees compliance with every AI hiring law. A customer-controlled, auditable system can make evidence, data flows, human review, and decision records easier to inspect, but employers still need jurisdiction-specific notices, audits, policies, retention practices, and legal review. Colorado's replacement ADMT law principally applies beginning January 1, 2027.
Legal status and source-check scope
- Sources checked: July 16, 2026
- Next source check: August 15, 2026
- Legal review: No completed legal review is recorded. Legal interpretation remains pending.
- Jurisdictions covered: New York City, Illinois, Colorado, and United States federal employment guidance
This article is a high-level product and architecture analysis. It is not legal advice. Applicability depends on the tool, the employment decision, the jurisdiction, and how an organization operates the system.
Change log: This update replaces the prior Colorado section based on SB 24-205. Colorado enacted SB 26-189 on May 14, 2026, and its principal requirements begin January 1, 2027. Rulemaking is ongoing.
Your legal team isn't blocking AI hiring tools because they don't understand the technology.
They're blocking them because they understand it perfectly.
A candidate record can move from an applicant tracking system to a vendor environment, then to a model provider, then back into a recruiter's workflow. Each movement creates another data flow, recipient, contract, permission boundary, and retention question. Legal and security teams have to reconstruct that chain before they can approve the tool.
AI hiring compliance cannot be reduced to a hosting diagram. The law may require a bias audit, a public summary, notice, consent, deletion, documentation, human review, or records. Architecture determines whether the organization can inspect and operate those duties with reliable evidence.
That distinction matters. A customer-controlled system can make compliance work easier to perform and prove. Counsel still has to determine what applies.
What the current rules say
Three cited laws cover different conduct.
NYC Local Law 144 addresses automated employment decision tools used by employers and employment agencies. The Illinois statute covers employers that ask applicants for recorded video interviews and use AI to analyze those videos. Colorado's new law covers automated decision-making technology used to materially influence consequential decisions, including employment.
They share concerns about visibility and accountability, but their duties are not interchangeable. A buyer needs a jurisdiction map before building a control map.
NYC requires an audit, public results, and notices
New York City's official page states that an employer or employment agency cannot use a covered automated employment decision tool unless the tool has undergone a bias audit within one year of use, information about the audit is publicly available, and required notices have been given to employees or candidates.
Those are separate obligations.
The audit asks whether the covered tool has been examined using the method required by the city rule. The public-summary duty asks whether the required results are accessible. The notice duty asks whether the affected person received the required information before the tool was used.
A private deployment does not perform an independent bias audit by itself. It can give an authorized auditor controlled access to the records needed for the analysis. It can also connect the relevant tool version, job category, scoring output, and workflow record so the organization knows which system the published summary describes.
The same separation applies to notice. A workflow can deliver and log a notice. The employer remains responsible for its content, timing, and applicability.
Illinois regulates a defined video-interview use
The Illinois Artificial Intelligence Video Interview Act is narrower than a general AI hiring law. It applies when an employer asks applicants for recorded video interviews and uses AI to analyze those videos for positions based in Illinois.
Before the interview, the employer must notify the applicant that AI may be used, explain how the AI works and the general types of characteristics it evaluates, and obtain consent. The employer may not use the AI analysis for an applicant who has not consented.
The Act also limits sharing of applicant videos to people whose expertise or technology is necessary to evaluate fitness for the position. After a written deletion request, the employer has 30 days to delete the interviews and direct other recipients to delete their copies, including electronically generated backups.
A separate reporting provision applies when an employer relies solely on the AI analysis to decide who receives an in-person interview. In that circumstance, the employer must collect and report specified race and ethnicity data.
The architecture question is concrete: can the employer identify every recipient of the video, record the applicant's notice and consent, locate every copy, execute a deletion request, and prove what happened? A VPC boundary may reduce the number of recipients while every statutory duty remains.
Colorado replaced its earlier framework
Colorado SB 26-189 was signed on May 14, 2026. It repeals and reenacts the provisions created by SB 24-205 with a revised automated decision-making technology framework. The Colorado Attorney General's rulemaking page says the new law and its provisions go into effect January 1, 2027.
For covered technology, the official enacted summary describes duties for developers and deployers.
Developers must provide technical documentation covering intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. They must also notify deployers of material updates or modifications.
Deployers have notice duties at the point of interaction. After a covered system produces an adverse consequential decision, the deployer must provide a plain-language description of the technology's role within 30 days. Consumers can request the personal data used by the technology, correction of factually inaccurate data, meaningful human review, and reconsideration.
Developers and deployers must retain records needed to demonstrate compliance for at least three years. The Attorney General is directed to adopt rules that clarify parts of the post-adverse-outcome disclosure process, so implementation details may change as rulemaking proceeds.
The enacted law creates Attorney General enforcement through the Colorado Consumer Protection Act and creates no new private right of action.
This is why freshness belongs inside the content model. The original version of this article described SB 24-205 and a 2026 date. A static legal claim became stale when the legislature replaced the framework. Legal content needs a last-reviewed date, a next review, primary sources, and a visible change log.
EEOC guidance and the 80% rule
Federal employment law remains relevant when employers use algorithmic selection procedures. The EEOC's Uniform Guidelines questions and answers are guidance that explains how the agencies interpret and apply the Uniform Guidelines. They are not a new AI statute.
The familiar four-fifths measure compares a group's selection rate with the rate for the group with the highest selection rate. The EEOC calls the 80% measure a rule of thumb. Its guidance says the measure is not a legal definition and is not controlling in every circumstance. Smaller differences may still matter when they are statistically and practically significant, while a ratio below the threshold does not decide the ultimate question of unlawful discrimination.
A dashboard that displays one ratio cannot issue the legal conclusion. The buyer needs the underlying cohort definition, selection stages, sample sizes, tool version, job context, and validation evidence. Counsel and qualified reviewers then decide what the results mean.
What architecture can prove
The strongest AI hiring compliance architecture creates a connected evidence chain.
It records which source systems supplied data, which fields the system was allowed to use, which model and policy versions were active, what recommendation was produced, and what explanation accompanied it. It shows whether a human approved, edited, or rejected the proposed workflow. If an action was executed, it records the writeback into the existing enterprise system.
Nodes calls that record a Decision Trace. It is queryable: what happened, where, why, what reasoning the system produced, and what input a human supplied.
That trace helps answer practical review questions:
- Which version of the system evaluated this person?
- Which data sources and permissions were active?
- Which notice or consent record was associated with the workflow?
- Did a human review the recommendation before execution?
- Which system received the approved action?
- Can the organization retrieve the same evidence after a complaint, audit, or internal review?
Deployment boundaries matter too. Nodes is designed to be VPC-resident and single-tenant, with customer-owned weights and no data egress. The data stays. The intelligence layer reads across it. Buyers can inspect the current boundary on the Nodes architecture page and review the available controls on the security and compliance page.
These properties reduce evidence dependency on a vendor's external environment. They do not decide whether the system falls within a statute, whether an audit method is sufficient, or whether a particular decision was lawful.
What architecture cannot decide
Architecture cannot determine which jurisdictions apply to a role. It cannot appoint an independent auditor, write a legally sufficient notice without approved policy, decide whether a requested alternative process is required, or interpret an adverse-impact result for counsel.
It also cannot turn a human-review button into meaningful human review. The reviewer needs authority, relevant evidence, enough time, and a process for reconsideration. A logged approval is useful only when the operating policy gives that approval substance.
The same rule applies to data control. Keeping data inside a customer environment can reduce movement and improve access control. The organization still needs retention schedules, deletion procedures, role-based permissions, incident handling, and a documented basis for each use.
The architecture is the evidence surface. Compliance is the organization's legal and operating judgment applied to that evidence.
The buyer's inspection packet
A serious review should ask for five connected artifacts.
A scope map. Identify the roles, locations, decisions, and tools that may trigger NYC, Illinois, Colorado, federal, or other requirements. Separate enacted law from proposed legislation and guidance.
A data-flow map. Show every system, processor, model endpoint, storage location, recipient, and writeback. The diagram should match the deployed product rather than a generic security deck.
A decision record. Reconstruct one representative workflow from source data through recommendation, human action, and execution. The record should identify versions, permissions, and timestamps.
A control record. Show how notices, consent, access, correction, deletion, audit support, human review, and retention are configured and monitored. Product capability and customer configuration should be labeled separately.
A freshness record. Record the primary source, date checked, next review date, review owner, and changes since the last legal assessment. Colorado's 2026 replacement law shows why this cannot live in an undated sales document.
The CISO buyer guide provides a broader set of architecture and security questions. The related pieces on signing an AI contract without reading the code and the second signer extend the review into procurement and approval design.
The useful category is not compliant AI by declaration. It is inspectable AI: systems that give legal, security, compliance, and business owners the evidence and control required to make their own decision.
Sources
- Colorado General Assembly: SB 26-189 enacted summary
- Colorado Attorney General: automated decision-making technology rulemaking
- NYC Department of Consumer and Worker Protection: automated employment decision tools
- Illinois General Assembly: Artificial Intelligence Video Interview Act
- EEOC: Uniform Guidelines questions and answers
Naman Puri is the Head of SEO and Answer Engine Optimization at Nodes.