AI in hiring · records and notices · updated
AI impact assessment for hiring
Colorado's 2024 AI Act would have required an annual impact assessment from employers using high-risk AI in hiring. SB 26-189 removed it, along with the risk-management programme, before it took effect. Two California rules still point the same way: the CCPA's regulations require a risk assessment from larger businesses that use automated decisionmaking technology for hiring, from 1 January 2027, and the FEHA rules treat anti-bias testing as evidence. New York City's independent bias audit is a different thing. The worksheet below is a draft for any of them.
Who still asks
- Colorado: no longer. SB 26-189 dropped the impact assessment and the risk-management programme (Epstein Becker Green).
- California CCPA rules: a documented risk assessment before use, with an executive's attestation, submitted to the California Privacy Protection Agency; for CCPA businesses only (Littler).
- California FEHA rules: anti-bias testing, its results and the response to them are relevant to a claim or a defence (Mayer Brown).
- New York City: an independent bias audit, which a worksheet does not replace.
The worksheet
Purpose and use
- What decision is each tool used for, and why use it rather than a person alone?
- Which roles and which stage of hiring?
- What does it output, and how does that output feed the decision?
Data
- Which personal data does it use, and where does each item come from?
- Could any input stand in for a protected characteristic (for example a zip code, a graduation year, a gap in employment)?
- How long is the data kept, by us and by the vendor?
Logic and limits
- What does the vendor say about how it works, its intended uses and its known limitations? Attach their documentation.
- Where should it not be used?
People
- Who reviews its output before a decision, and can they change it?
- How is that reviewer trained, and how do they avoid simply following the output?
- How do applicants ask for an accommodation, a correction or a review?
Testing
- Have outcomes been compared across groups (for example selection rates by sex and by race or ethnicity)? When, by whom, and what was found?
- What was changed as a result?
Weighing it
- What could go wrong for applicants, and how likely is it?
- What safeguards are in place, and do the benefits outweigh the risks?
Sign it off with who prepared it, counsel's review, who approved it, and when it is next due.
All of it, filled in from your own files, free
$ npx --allow-git=root github:agentwares/hiringrecord kit --ats your-ats-export.csvAn inventory of the AI tools in your hiring from your answers and your applicant-tracking export, the notices for each law that applies, the 30-day explanation and the review procedure, a risk-assessment worksheet and what to keep, as dated files with a SHA-256 manifest. Runs on your machine: no account, no upload, no AI. Also a Claude plugin and a local MCP server: github.com/agentwares/hiringrecord.
A continuous, hash-chained record of every hiring decision your AI tools touched, kept for the years the law asks, is not built
It would record each decision as it happens (the tool and its version, the outcome, the reviewer, the explanation sent and its date, review requests and what came of them) in okgate's hash-chained log, keep it three years for Colorado or four for California, track each 30-day clock, and export it for your counsel.
What exists today: the templates on these pages, which you keep yourself. okgate keeps a hash-chained log of the tool calls AI agents make through its proxy, not hiring decisions.
Sources, each read on 9 October 2026
- Epstein Becker Green: Inside Colorado's SB 26-189 (26 May 2026)
- Littler: California's final regulations on automated decisionmaking (26 Sep 2025)
- Mayer Brown: California adopts new employment AI regulations, effective 1 Oct 2025
- NYC Department of Consumer and Worker Protection: automated employment decision tools