August 20, 2026
the-patchwork-of-ai-regulation-states-chart-divergent-paths-for-workplace-technology

As artificial intelligence rapidly integrates into nearly every facet of the modern workplace—from recruiting and hiring to performance management, discipline, and workforce analytics—state lawmakers across the United States are grappling with how to regulate its use. The response, however, is far from uniform. A complex and evolving landscape is emerging, characterized by a spectrum of approaches ranging from direct legislative intervention to reliance on existing legal frameworks, creating a significant compliance challenge for employers operating in multiple jurisdictions.

The adoption of AI in employment is no longer a futuristic concept but a present-day reality. Companies are increasingly leveraging AI-powered tools to streamline processes, enhance efficiency, and gain deeper insights into their workforce. These technologies can analyze resumes, conduct initial candidate screenings, monitor employee productivity, optimize scheduling, identify potential disciplinary issues, and even assist in promotion decisions. The potential benefits are substantial, promising to reduce bias, improve decision-making accuracy, and free up human resources for more strategic tasks. However, the rapid deployment of these powerful tools has also ignited concerns about algorithmic bias, transparency, privacy, and the potential for discriminatory outcomes.

In response to these growing concerns, states are enacting a variety of laws, creating a fragmented regulatory environment. Some states have taken a proactive stance, enacting legislation specifically targeting the use of AI in employment decisions. These laws often mandate transparency, require bias audits, and establish protocols for consent and human oversight. Other states have opted for a more indirect approach, focusing on broader privacy regulations, consumer-facing chatbot rules, or restrictions on AI in the public sector, which may indirectly impact workplace AI but do not directly regulate employer use. A significant number of states, meanwhile, have yet to enact any AI-specific employment laws, leaving employers to navigate the existing web of federal and state anti-discrimination, labor, privacy, and other general statutes. This patchwork of regulations presents a substantial compliance hurdle for businesses, particularly those with a national footprint.

The Regulatory Spectrum: Categorizing State Approaches

To understand the varied responses, states can be broadly categorized based on their legislative actions concerning AI in employment. This categorization helps illuminate the different levels of direct regulation and the specific areas of focus for each state.

  • Direct AI Employment-Decision Law (Enacted): These states have passed laws or regulations that directly govern how employers can use AI, automated decision tools, or similar computational processes in employment decisions. This includes hiring, promotions, disciplinary actions, and other employment-related outcomes. In these jurisdictions, the use of AI in HR itself is the primary object of regulation, rather than being indirectly affected by broader legal frameworks.

  • General AI/Privacy Law – Employment Largely Exempted: In these states, broader laws concerning consumer privacy, automated decision-making, or AI disclosure have been enacted. However, these laws often contain carve-outs for employment-related data or employer HR functions, meaning they generally do not impose direct workplace AI regulations on most private employers, though they may be relevant for broader compliance.

  • Government/Public-Sector AI Policy Only: These states have enacted AI-related requirements that specifically apply to government agencies, public bodies, or public employers. While these laws may mandate policies, governance measures, or human review within the public sector, they do not impose broad workplace AI obligations on private companies.

  • AI Companion Chatbot / Minor-Safety Law: These states have passed laws focused on consumer-facing AI chatbots or youth safety, typically requiring disclosures or imposing restrictions on certain chatbot interactions. While part of the broader AI regulatory landscape, these laws generally exclude or do not meaningfully regulate internal employer HR tools.

  • Licensed Mental-Health AI Restriction: This category includes states that have enacted sector-specific laws limiting AI use by licensed mental health professionals, healthcare providers, or other regulated entities. These laws are not general employment AI statutes but can directly affect employers in healthcare, counseling, education, or behavioral health settings.

  • No Dedicated State AI-Employment Law: These states have not yet enacted any laws specifically regulating employer use of AI in employment decisions. Employers in these states are still bound by existing federal and state legal frameworks, including anti-discrimination, disability accommodation, wage and hour, privacy, labor, biometric, and unfair or deceptive practices laws, even without an AI-specific statute.

  • Pending Legislation Only: In these states, bills addressing employer AI use have been introduced or are under consideration but have not yet been enacted. These states are crucial to monitor, as they may soon transition into one of the enacted-law categories, but for now, employers are governed by existing laws.

States Leading the Charge: Direct AI Employment Regulation

A growing number of states are stepping forward with direct regulations designed to govern the use of AI in employment. These laws aim to ensure fairness, transparency, and accountability in AI-driven HR processes.

California: A Comprehensive Framework

California has emerged as a leader in establishing a broad AI-employment framework through regulations under the Fair Employment and Housing Act (FEHA), with significant provisions taking effect in October 2025. These rules apply to any business with at least five employees, provided at least one is located in California. The scope extends beyond sophisticated AI systems to encompass any computational process that assists in making decisions about hiring, promotions, discipline, or other employment benefits.

The California regulations are designed to capture tools that merely influence, rather than outright make, employment decisions. This includes technologies such as resume screeners, scoring tools, productivity and behavioral scoring systems, and scheduling algorithms. A key component of California’s approach is its embrace of disparate-impact principles. Automated decision systems that appear neutral on their face but disproportionately affect applicants or employees based on protected characteristics are deemed impermissible unless the employer can demonstrate that the practice is job-related and consistent with business necessity. Furthermore, the law makes it clear that employers cannot evade responsibility by outsourcing to vendors; both the vendor and the employer can be held liable if the AI tool is discriminatory.

Adding another layer of complexity, California’s robust privacy regime, the California Consumer Privacy Act (CCPA), now also extends to automated decision-making technology. Effective January 1, 2026, businesses are required to conduct risk assessments before utilizing automated decision-making technology for significant employment decisions or when its use presents a significant risk to employees, such as inferring intelligence, aptitude, performance, reliability, or location through systematic observation. This dual approach underscores California’s commitment to regulating AI’s impact on both employment and data privacy.

Connecticut: Function-Based Regulation

Connecticut’s Artificial Intelligence Responsibility and Transparency Act targets employers doing business in the state, employing individuals there, or accepting job applications from Connecticut residents, if they deploy automated employment-related decision technology. The law’s applicability hinges on the function of the AI tool rather than its label. If an AI tool does not "meaningfully alter" an employment-related decision, the statute’s requirements do not apply.

Starting October 1, 2026, the use of automated employment-related decision processes that result in an adverse employment decision based on a protected status will be considered a violation of the Connecticut Fair Employment Practices Act. The statute also clarifies that the use of automated employment-related decision technology does not serve as a defense against a discrimination complaint. Employers filing WARN Act notices must also disclose to the Connecticut Department of Labor whether layoffs are linked to AI or other technological changes. A subsequent phase, beginning October 1, 2027, will require employers using automated employment decision tools intended to interact with applicants or employees to provide plain-language notification that they are interacting with technology.

Illinois: Pioneering Video Interview Analysis and Broader Protections

Illinois has been an early adopter of AI regulation in the employment context. Its Artificial Intelligence Video Interview Act, effective January 2020, specifically addresses employers’ use of AI to analyze asynchronous video interviews for Illinois-based positions. The law targets applicant-submitted videos rather than live, human-led interviews.

Before requesting such a video interview, employers are required to notify the applicant that AI may be used, explain how the AI functions and what general characteristics it evaluates, and obtain the applicant’s explicit consent. The statute explicitly prohibits employers from using AI to evaluate applicants who have not consented.

Building on this foundation, Illinois has expanded its regulatory reach. Effective January 1, 2026, HB 3773 amends the Illinois Human Rights Act to prohibit employers from using AI that has a discriminatory effect in recruitment, hiring, promotion, renewal of employment, training, discharge, discipline, tenure, and other employment conditions. This amendment recognizes disparate impact, not just discriminatory intent, and also prohibits the use of zip codes as a proxy for protected classes. Furthermore, employers are required to notify employees and applicants about the use of AI in covered employment contexts through workplace postings and employee handbooks.

New Jersey: Algorithmic Discrimination Guidance

New Jersey’s Division on Civil Rights has issued clear guidance on algorithmic discrimination, emphasizing that automated employment decision tools are subject to the same disparate-impact analysis as human decision-making under the New Jersey Law Against Discrimination. The state explicitly states that employers cannot transfer compliance risks to the vendors who develop these tools, underscoring employer accountability.

New York City: A High Bar for Hiring Tools

New York City’s Local Law 144 has set a significant benchmark for AI hiring laws, with enforcement commencing in July 2023. This law applies based on the location of the candidate or employee, not the employer’s headquarters, meaning it can impact remote hiring even for companies without a physical presence in the city. Before employing a covered automated employment decision tool, employers and employment agencies must conduct a bias audit within the preceding year, publish a summary of the most recent audit on their website, and notify candidates about the tool’s use, its purpose, and the data collected.

Texas: Intent-Focused Approach

Texas has adopted a distinct approach, focusing on intentional discrimination rather than solely disparate impact. The Texas Responsible Artificial Intelligence Governance Act applies broadly to entities doing business in Texas, producing products or services used by Texas residents, or developing or deploying AI systems within the state. For employers, the law prohibits the development and deployment of AI systems that intentionally discriminate against protected classes in violation of state or federal law. The statute explicitly states that disparate impact alone is insufficient to establish a violation, signaling a clear intent-focused enforcement strategy.

Tangential Regulations: AI’s Ripple Effect

Beyond direct employment AI laws, several states have enacted legislation that, while not exclusively focused on workplace AI, has significant implications for employers utilizing AI technologies.

State vs. federal AI law: The map (and takeaways) every HR executive needs to study today

Arkansas: Protecting Likeness and Public Sector AI Governance

Arkansas Act 159, enacted in February 2025, broadens the definitions of "likeness" and "photograph" to include AI-generated reproductions. This has practical consequences for employers using AI-generated employee testimonial videos, AI-voiced advertisements, or digitally altered staff images, necessitating explicit consent for the recreation of an individual’s likeness or voice.

Furthermore, Arkansas Act 848, signed in April 2025, mandates public employers to establish formal policies governing AI and automated decision tool usage. The law requires employee training, public accessibility of policies upon request, and human final review for AI used in applicant screening, performance scoring, or disciplinary decision support.

Maine: Surveillance and Mental Health AI

Maine’s L.D. 61, enacted in January 2026, regulates employer surveillance and applies to all Maine employers regardless of size. Although not drafted as an AI statute, the law broadly defines surveillance to encompass AI-driven keystroke monitoring, productivity scoring software, biometric monitoring, and similar algorithmic tracking tools. Employers using surveillance must inform job applicants during interviews and provide annual written notice to affected employees. The law also prohibits requiring employees to install surveillance tools on personal devices without permission, and employees may refuse such requests.

Maine also enacted House Bill 1397, which regulates AI use in certain mental health services. While permitting AI for administrative tasks like scheduling and billing, it prohibits licensed mental health providers from using AI to deliver therapy, make independent clinical decisions, or generate unsupervised therapeutic recommendations.

Maryland: Facial Recognition Consent

Maryland’s Facial Recognition in Employment Interviews Law restricts the use of facial recognition technology by employers during applicant interviews. An employer cannot create a facial template during an interview unless the applicant provides consent. While the statute does not explicitly use the term "artificial intelligence," it was enacted in response to AI-driven hiring assessments that analyze facial movements and vocal patterns.

Massachusetts: Attorney General Guidance on Discrimination

Massachusetts has not enacted a standalone AI employment statute. However, guidance from the Attorney General applies the state’s anti-discrimination law directly to AI systems. This guidance prohibits developers, suppliers, and users of AI systems from deploying technology that discriminates based on legally protected characteristics, including algorithmic decision-making that relies on discriminatory inputs or produces discriminatory results. This means Massachusetts employers cannot use AI in hiring if it has the purpose or effect of disfavoring individuals or groups based on protected characteristics.

Nevada: AI Restrictions in Public Schools

Nevada’s AB 406, effective July 1, 2025, prohibits public schools from using AI to perform the functions and duties of school counselors, psychologists, and social workers related to mental health. While not a general employment law, it has direct implications for employers in education and mental-health-adjacent sectors considering AI for roles traditionally held by licensed professionals.

Tennessee: The ELVIS Act and Likeness Protection

Tennessee’s ELVIS Act, enforced since July 1, 2024, has significant implications for employers using AI-generated voice and likeness technology. Employers could face liability if they use AI to create marketing materials, training videos, IVR systems, or internal communications featuring a cloned voice or likeness of an identifiable person without proper authorization. This law underscores the need for careful consideration of consent and intellectual property rights when employing generative AI for employee or public-facing content.

Sector-Specific Regulations: Targeted Interventions

In addition to broad employment AI laws, several states have implemented sector-specific regulations that may directly impact employers in fields like healthcare and behavioral health.

Louisiana, for example, requires healthcare providers to verbally notify patients before recording visits for AI transcription, effective August 1, 2026. Oregon has enacted legislation restricting the use of protected nursing titles to market or label AI products in healthcare settings. Rhode Island has implemented coordinated laws that restrict AI’s role in therapeutic decision-making, mandate written consent for AI recording or transcription in therapy, and impose related documentation obligations. These sector-specific rules highlight a trend towards tailored AI governance based on the unique risks and considerations within particular industries.

Emerging Legislation: What to Watch

The regulatory landscape for AI in employment is continuously evolving, with several states considering or preparing to implement new legislation.

Colorado: Transparency and Human Review

Colorado’s SB 26-189, though enacted, is not yet effective and is subject to litigation and rulemaking. Scheduled for January 1, 2027, this law aims for a transparency-focused model that includes pre-use notice, post-adverse-outcome disclosure, and a right to seek human review or reconsideration of adverse decisions. The law also establishes a comparative-fault framework between AI developers and deployers and clarifies that contractual provisions cannot shield parties from liability for their own discriminatory actions.

Delaware: Privacy Law Expansion

Delaware’s HB 380, passed in June 2026 and slated to take effect January 1, 2027, proposes to bring certain AI uses in resume screening, interview scoring, and workforce analytics under Delaware’s privacy law. This expansion would affect how employers process sensitive employment-related data through AI.

Massachusetts: The FAIR Act’s Ambitious Proposal

The proposed FAIR Act in Massachusetts, still pending in committee, seeks to implement stringent AI governance. If enacted, it would mandate annual independent third-party audits, public disclosure of these audits, strict consent and notice requirements, meaningful human oversight, and a ban on emotion and gait recognition technology.

Michigan: Prohibiting Automated Decision Tools

Michigan’s Responsible Artificial Intelligence Security for Employees Act, introduced in February 2026, remains under consideration. As drafted, it would largely prohibit employers from using automated decision tools for employment-related decisions, with limited exceptions for high-volume application screening or job skills assessments.

New York: Reporting on AI’s Workforce Impact

New York’s S8706-B proposes a new Labor Law section requiring covered businesses to report annually to the Department of Labor on AI’s impact on hiring and workforce changes. These reports would include data on displaced employees, reduced hours, new hires, unfilled positions due to AI, and descriptions of AI objectives, human oversight, data usage, and risk mitigation measures.

Employer Takeaways: Navigating the Evolving Landscape

The rapid proliferation of state-level AI regulations presents a complex and dynamic challenge for employers. As this legal framework continues to expand and shift, businesses must adopt a proactive and adaptable approach to ensure compliance and mitigate risks.

  • Inventory AI Tools: A comprehensive audit of all AI and automated decision tools used across the entire employment lifecycle is the crucial first step. This includes understanding the purpose, functionality, and data inputs of each tool.

  • State-by-State Review: Given the uneven regulatory landscape, employers must meticulously review the specific AI laws and regulations applicable in each state where they operate or employ individuals. This involves understanding enacted laws, pending legislation, and relevant guidance from state agencies.

  • Vendor Due Diligence: For employers relying on third-party AI vendors, it is essential to scrutinize vendor contracts and agreements. Employers should ensure that vendor tools meet state-specific compliance requirements and that contractual provisions clearly delineate responsibilities and liabilities, particularly concerning data privacy and non-discrimination.

  • Focus on Transparency and Consent: Many emerging regulations emphasize transparency and the need for explicit consent from employees and applicants. Employers should be prepared to provide clear and understandable information about how AI tools are used and to obtain necessary permissions before deploying these technologies in high-stakes decision-making processes.

  • Human Oversight and Bias Testing: The importance of human review and bias testing is a recurring theme in AI regulation. Employers should establish protocols for meaningful human oversight of AI-driven decisions and implement regular bias audits to identify and address potential discriminatory outcomes.

  • Impact Assessments: In an increasing number of jurisdictions, employers may be required to conduct impact assessments to evaluate the potential risks and consequences of using AI in employment decisions. This proactive analysis can help identify and mitigate potential legal and ethical challenges.

Conclusion: A Future of Regulated AI in the Workplace

The state-law framework governing workplace AI is rapidly expanding and doing so in an uneven manner. Employers are not only confronting AI-specific employment laws but also an array of adjacent rules concerning discrimination, privacy, surveillance, biometrics, and other worker-facing technology applications. Even in states without a dedicated workplace AI statute, employers remain subject to existing federal and state legal frameworks, including anti-discrimination, privacy, and related laws, which can be applied to AI-driven employment practices.

The trajectory is clear: AI in the workplace will increasingly operate within a regulated environment. The key for employers moving forward is to remain informed, adaptable, and committed to responsible AI deployment. By proactively inventorying their AI tools, understanding state-specific obligations, rigorously vetting vendor arrangements, and confirming where notice, consent, human review, bias testing, or impact assessments are required, businesses can navigate this evolving landscape and ensure that the integration of AI in their operations is both efficient and equitable. The challenge lies not only in compliance but in fostering a culture of responsible innovation where technology serves to enhance fairness and opportunity for all employees.