New York City requires an employer using an automated hiring tool to have it audited by an independent auditor, and to publish a summary of the result. Among the jurisdictions examined in this series it is the only one that requires both. In the only official measurement of it located as of August 21, 2026, covering July 2023 through June 2025, the record shows two complaints, no civil penalty, no notice of violation, and no proceeding at the Office of Administrative Trials and Hearings. The auditors expressly disclaimed assurance that the information they received was reliable, accurate, and complete, because mayoral agencies do not provide representation letters.

A companion piece, When the rule is not written down, set out the problem this instrument was built to answer. The records it examines suggest that as the discriminating mechanism in hiring software moves from an explicit rule to a vendor’s ranking function, the group-level evidence a rejected applicant would need stops appearing in the public record. A covered annual audit produces selection rates and impact ratios before anyone sues. What follows is the record of what happened to that requirement.

Other jurisdictions took other routes

New York City is not the only place that has legislated about these tools, and the differences are the point. Illinois amended its Human Rights Act effective January 1, 2026, making it a civil rights violation to use artificial intelligence that has the effect of discriminating on a protected basis, to use zip codes as a proxy for one, or to fail to tell employees the tool is in use. The statute states no measurement duty. It authorizes rules necessary for implementation and enforcement, including but not limited to rules governing notice, but it does not itself prescribe measurement. California has required employers to retain automated-decision system data for four years since October 1, 2025, and its Civil Rights Council answered objections about audit burden by stating that it was imposing no anti-bias testing requirement and no third-party audit requirement. Colorado’s replacement statute takes effect on January 1, 2027 and runs on developer documentation passed to the deployer, internal records kept not less than three years, notice at the point of interaction, and a plain-language explanation within thirty days of an adverse decision; the impact assessments in its predecessor did not survive the reenactment.

The European Union will capture the same tools and will publish something real, but not this. Annex III of the EU AI Act reaches systems used to place targeted job advertisements, filter applications, and evaluate candidates. The duties include logging by design, log retention of at least six months by provider and deployer, notice to workers and their representatives before a system is used at the workplace, and registration by the provider, not the employer, in a database that is genuinely public. What that database shows is the provider, the intended purpose, and a concise description of the system’s inputs and operating logic, with no selection rate, no impact ratio, no demographic breakdown, and no audit result. The fundamental rights impact assessment does not reach ordinary private employers, and the high-risk provider and deployer obligations in Chapter III Sections 1 to 3 do not apply to Annex III systems before December 2, 2027. A system already on the market by then is reached only if it is afterwards subject to significant changes in its design.

The pattern across all of them is the same. The data gets computed, or retained, or described, and it is shown to a regulator, to a worker, to a court, or to nobody. Among the jurisdictions examined here, New York City is the only one that requires the tool to be audited by someone independent and a summary of the result published. The distinction worth keeping is not who measures. It is who checks the measurement, and who is allowed to see it.

Two complaints, no penalty, no proceeding

The New York State Comptroller audited the Department of Consumer and Worker Protection’s enforcement of Local Law 144 and reported on December 2, 2025, covering July 2023 through June 2025. Across those two years, DCWP received two complaints. One fell outside the city’s jurisdiction and required no further steps. DCWP reviewed the other, took limited steps to validate it, requested a sworn declaration from the employer that the tool was not covered, and closed the complaint on receiving it. It recorded no civil penalty, no notice of violation, and no proceeding at the Office of Administrative Trials and Hearings. The audit also describes two demand letters about posting placement, sent after a review of 32 company websites.

The audit’s comparison is the damaging part. DCWP surveyed 32 companies and identified one compliance issue. The Comptroller reviewed the same 32 and identified at least 17 potential violations. Those numbers are not like for like: a potential violation spotted by inspecting a website is not a finding that anyone violated anything, and it does not establish that the company uses a covered tool, which is the jurisdictional predicate. What the comparison shows is the gap between what one reviewer saw and what the other did on the same companies. Nine of 12 test calls placed to 311 never reached DCWP, which is a finding about citywide call routing rather than enforcement will.

Asked to look for non-compliance rather than wait for complaints, the agency declined. DCWP rejected the Comptroller’s proactive-enforcement recommendations 7 and 9, declined recommendation 12 in full, and stated that it had “seen no evidence of widespread non-compliance to warrant such allocation.” It accepted the recommendations covering process, training, and call routing.

There is a defensible account of that record, and it is worth putting as strongly as it can be put. It is this publication’s construction rather than the agency’s own: the rules confine the covered configurations to three and the statute caps a first violation at $500, so low numbers may be what narrow coverage looks like rather than what indifference looks like. The current OATH hearing schedule separately lists $375 for a first violation, $1,350 for a second, and $1,500 for a third or later violation, with higher default amounts for the first two. That account has a gap. The narrowing of covered configurations to three came from DCWP’s own rules, so the agency drew the boundary and then cited the quiet inside it. The rejoinder is the publication’s inference rather than the Comptroller’s finding, and it is this. An agency that declines the proactive checks it was offered has weakened its own reliance on complaint counts as evidence that there is nothing to find.

Independent measurement raises the same question without answering it. In academic work presented at ACM FAccT in 2024, Wright and others monitored 391 employers and found 18 that had posted a bias audit report and 13 that had posted a transparency notice. Those are raw counts against a monitored sample, not a rate against an established population of covered employers. No official source covering enforcement after June 2025 was located as of August 21, 2026, so the measured enforcement record ends there.

New York is not the only null record, and the second one is cleaner. Illinois requires an employer that relies solely on an AI analysis of a recorded video interview to decide whether to grant an in-person interview to report the race and ethnicity of the applicants it advances, does not advance, and hires, and requires the state to tell the Governor and General Assembly each year whether that data discloses racial bias. The department’s own statutory reports answer the question four times. No such data was reported for the twelve months ending November 30, 2022, and none for the twelve-month periods ending November 30, 2023, November 30, 2024, or November 30, 2025. Four consecutive reporting periods produced zero employer submissions. The trigger is narrow, the Act carries no penalty, and no agency is named to enforce it, though the record does not establish why nothing was filed. No report covering a later period was located as of August 27, 2026.

One limit should be stated plainly, because the argument invites the opposite inference. Local Law 144 reaches only employers hiring in New York City. Nothing establishes that the applicant in Harper v. Sirius XM Radio, LLC applied for a covered New York City position, and the preliminarily certified nationwide ADEA collective in Mobley v. Workday, Inc. could not be built out of one city’s audits in any event. The claim is not that the audit would have rescued those plaintiffs. It is that the audit generates selection-rate evidence of the kind a disparate impact claim needs, and that the compliance duty is self-executing: an employer that complies produces the audit whether or not anyone is watching. Whether employers comply when nobody is watching is the question the enforcement record bears on, and it is the question the record answers badly.

What the frameworks describe, one city made binding

Local Law 144’s independent bias audit is a concrete instance of what two published governance instruments describe in general terms: the measure function of the NIST AI Risk Management Framework and the auditable management system of ISO/IEC 42001. Neither imposes a duty to audit a hiring tool. The framework is voluntary and creates no legal duty; the standard is a certifiable management system, and certification against it evidences documented practice rather than a lawful or safe system. Whatever binding force either carries comes from a contract, a regulator, or a procurement condition that adopts it.

New York City converted one measurement practice into law, for one class of tool, with penalties attached. What that produced is the count already given: of 391 employers monitored, 18 had posted an audit report, which is a raw count against a monitored sample and not a compliance rate. What these records do not establish is how often covered employers published a compliant audit, or whether active enforcement would change that. That is the gap worth naming. A duty written into law, with per-day accrual for its audit and publication requirement, has a measured record here of two complaints and no penalty, and no source located establishes a compliance rate among an identified population of covered employers.

Federal enforcement policy turned against disparate impact

While the official record showed no penalty, notice of violation, or tribunal proceeding through June 2025, the federal government changed its position on the theory the audit was built to serve. Executive Order 14281, signed on April 23, 2025, states that it is “the policy of the United States to eliminate the use of disparate-impact liability in all contexts to the maximum degree possible,” and directs that “all agencies shall deprioritize enforcement of all statutes and regulations to the extent they include disparate-impact liability, including but not limited to 42 U.S.C. 2000e-2.” It gave the Attorney General and the EEOC Chair forty-five days to assess pending matters resting on the theory.

What the order does not do is repeal anything. Section 703(k) of Title VII is a statute, it remains on the books, and a private plaintiff may still bring a disparate impact claim under it. An executive order sets enforcement priorities; it does not amend the United States Code. What it changes is federal enforcement priority, and it leaves private claims legally available.

Separately, and without any established connection to that order, several of the agency’s own pages are gone. The EEOC launched an Artificial Intelligence and Algorithmic Fairness Initiative in October 2021, and its Chair named that initiative when the agency announced the EEOC v. iTutorGroup, Inc. filing in May 2022. It no longer has a page. As of August 11, 2026 its address redirects to a URL that returns a not-found error, and the technical assistance documents on adverse impact under Title VII and on the ADA return the same at their published addresses. The 2021 launch announcement and both iTutorGroup releases were still live in the same check, so this is not a site-wide failure. Whether the initiative was formally wound down is not stated anywhere this publication could reach, and pages disappearing is not the same as a rescission.

That is the development that reframes both pieces. The argument has been that proof gets harder as the mechanism becomes less legible, and that the regulatory answer moves the work from the courtroom to a compliance filing. The records continue to support that concern without establishing it. What the past year added is that the enforcer with the pre-suit process the private plaintiff does not have has been directed to treat the theory as a low priority. That leaves the private plaintiff holding a burden the companion piece describes at length, and leaves the instrument that would lighten it where this one found it.

The instrument exists. The reviewed record does not establish how often covered employers complied, or whether enforcement changed behavior.

Practical implications

  1. Do not read a thin enforcement record as a durable measure of exposure. DCWP recorded no penalty through June 2025, and the Comptroller identified at least 17 potential violations among the same 32 companies where the agency identified one compliance issue. Potential violations are not findings, that record covers a single agency across a single two-year window, and nothing official after June 2025 was located as of August 21, 2026. An enforcement posture is a fact about a moment, and this one has an unmeasured year behind it and rests on a record its auditors did not vouch for as complete.

  2. Ask who checks, not only what is required. Illinois wrote a reporting obligation with no penalty and named no agency to enforce it, and the four located reports recorded no employer submissions at all. That is one duty across four reporting periods and it does not generalize on its own, but where a compliance obligation is self-executing the question of who verifies it is the one that decides whether anything happens.

  3. Deprioritized is not repealed. Executive Order 14281 directs agencies to deprioritize disparate-impact enforcement, but section 703(k) of Title VII remains on the books and available to private plaintiffs. An employer reading the federal posture as the end of exposure is reading an enforcement priority as a change in the law.

Case citations and authorities

  • N.Y.C. Admin. Code sections 20-870 to 20-874, added by Local Law No. 144 (N.Y.C. 2021); rules at 6 RCNY sections 5-300 to 5-304.
  • 775 ILCS 5/2-102(L), added by Pub. Act 103-0804; 820 ILCS 42 (Artificial Intelligence Video Interview Act).
  • Cal. Code Regs. tit. 2, section 11013(c); Colo. Sess. Laws 2026, ch. 131 (S.B. 26-189).
  • Regulation (EU) 2024/1689, Annex III point 4, as amended by Regulation (EU) 2026/1744.
  • Exec. Order No. 14281, 90 Fed. Reg. 17537 (Apr. 28, 2025).
  • 42 U.S.C. 2000e-2(k).
  • NIST AI Risk Management Framework (NIST AI 100-1); ISO/IEC 42001:2023.

Disclaimer: AI Lex Intelligence is published for informational purposes only. It does not constitute legal advice, and no attorney-client relationship is formed by reading or receiving this publication. Readers should consult qualified legal counsel about specific legal matters.

AI Lex Intelligence with Zola Valashiya. Independent analysis of artificial intelligence and the law.