AI hiring compliance: the evidence layer.
Published July 26, 2026 · OmniStrat AI
To comply with AI-hiring laws in 2026, an employer using AI in interviews or screening must give candidates notice, obtain consent, be able to explain each AI decision, and produce records on request. OmniStrat generates all four automatically: Agora attests the consent, Foundry logs and explains the decision.
What each law requires
| Law | In force | Requires |
|---|---|---|
| Illinois AI Video Interview Act (+ HB 3773) | Feb 2026 / Jan 2026 | Notice, explanation, and consent for AI-analyzed interviews; discriminatory AI use is a civil-rights violation |
| NYC Local Law 144 | Active | Annual bias audits of automated hiring tools, public disclosure; $500–$1,500/day penalties |
| Colorado ADMT law | Jan 2027 | Notice + explanation for consequential automated decisions |
The record you must be able to produce
For any disputed decision: proof the candidate was notified and consented, what the AI evaluated and decided, and evidence none of it was altered afterward. Point tools produce fragments across vendors; the laws assume one coherent record.
How the attested pipeline satisfies it
Run interviews in Agora (schedule, meet, sign in one sealed room. Consent captured cryptographically) and screen via Foundry (every AI decision logged, explainable, tamper-evident). Consent + decision become one verifiable record. The three-vendor stack replaced in the process.
For staffing agencies
Agencies carry this exposure across every client jurisdiction. Attested interview records become a sellable differentiator: every placement ships with an audit-ready file.
The disclosure-and-consent sequence, made concrete
Each of these laws, in its own vocabulary, demands the same sequence: tell the candidate AI is involved, tell them before it evaluates them, obtain consent where required, and be able to prove all three later. The failure mode is rarely the telling — firms add the sentence to an email template — it is the proving. An email that says a disclosure was sent is not evidence the candidate received it before the interview, and a checkbox in an ATS is a database row an administrator can edit.
In an attested pipeline the sequence is captured as events in one hash-chained record: disclosure shown, consent given, interview held, evaluation produced. Each entry is signed and committed to the chain at the moment it happens, so the order of events — which is what these statutes actually turn on — is provable arithmetic rather than reconstructed narrative.
Who carries the exposure
Employers carry the statutory duty, but the practical exposure spreads wider. Staffing agencies run interviews under a client’s name and inherit the obligation to evidence them. HR platforms embed third-party AI scoring and become the party who must explain it. And under NYC’s Local Law 144, the bias-audit obligation attaches to the tool’s use, not to whoever happens to hold the logs. In every configuration the question lands the same way: produce the record of what the candidate was told, when, and what the machine did. The party who can answer from a verifiable record, rather than from an export a vendor prepared for the occasion, is the one who ends the inquiry early.
What the record is made of
The mechanism matters because it is what survives a challenge. Each event in the pipeline — disclosure shown, consent given, interview held, evaluation produced — is Ed25519-signed and committed to a hash chain at the moment it happens, each entry bound to the one before it. A candidate’s lawyer, a city examiner under Local Law 144, or your own counsel can take any record and verify it at the public verifier with no account: re-hash the payload, check the signature, confirm the position. If a date was moved or a consent inserted after the fact, the arithmetic fails. That is the difference between a compliance file and a compliance story.
Consolidate one hiring workflow in 30 days; the records generate themselves. (This page is general information, not legal advice.)
Join the list →