Employers increasingly rely on automated tools to help make decisions concerning hiring, promotion, discipline, and termination. In response, state legislatures and agencies have begun to regulate uses of these technologies, often referred to as automated decision-making technology (“ADMT”). These laws generally require entities that deploy ADMT in the employment context to, among other requirements, notify affected individuals, disclose how ADMT factors into decisions, and provide rights to appeal or request human review.

This remains a fast-moving area and a hot topic for legislative and regulatory focus, with several states enacting laws this year and additional bills pending. Below, we summarize the key legislative and regulatory ADMT developments that apply in the employment context.

California ADMT and Pending Legislation

In 2025, the California Privacy Protection Agency approved regulations governing the use of ADMT for “significant decisions” concerning consumers, including job applicants, employees, and independent contractors. Pursuant to these rules, beginning January 1, 2027, employers that use ADMT for a “significant decision” (a decision resulting in the provision or denial of employment or independent contracting opportunities including hiring, allocation of work, compensation, and termination) must provide pre-use notice, offer individuals the ability to opt out, and conduct a risk assessment, among other requirements, unless an exception applies. For a more detailed discussion of California’s ADMT regulations, see our prior blog post.

Additionally, the California legislature is considering further restrictions. SB 947 (the “No Robo Bosses Act”) would prohibit employers from relying solely on an automated decision system (“ADS”) to make significant decisions and would require an independent human investigation to corroborate any ADS output. SB 951 (the “AI Job Killer Notice Act”) would require covered employers to give affected workers and certain local entities advance notice, potentially up to 90 days, before a layoff attributable to AI or ADMT. Both bills cleared the Senate and are currently being considered in the Assembly. Employers should continue monitoring both bills for any developments.

Colorado SB 26-189

On May 14, 2026, the Colorado governor signed SB 26-189 into law, repealing and replacing Colorado’s original 2024 Artificial Intelligence Act. The revised law, which takes effect on January 1, 2027, pares back the original’s broader “high-risk artificial intelligence system” framework in favor of a narrower approach focused on ADMT used in consequential decisions. The new law regulates ADMT used to “materially influence” “consequential decisions,” including decisions related to employment or employment opportunity that creates or may create an employer-employee relationship. An ADMT output “materially influences” a consequential decision when it is a non-de minimis factor used in making the decision and affects the outcome, including by ranking, recommending, or otherwise meaningfully altering how the consequential decision is made.

Deployers of ADMT must notify individuals before using the technology to make consequential decisions concerning them. Also, within 30 days of a consequential decision that results in an adverse outcome, deployers must provide a plain-language disclosure of the decision and the role ADMT played in making that decision. In addition, deployers must provide instructions for a simple-to-follow process to request information, and an explanation of the individuals’ rights, including the right to correct inaccurate data, appeal the decision, and request meaningful human review and reconsideration, to the extent “commercially reasonable.” Deployers must retain records that demonstrate compliance for at least three years after the date of the consequential decision, including ADMT version identifiers, changelogs, and documentation of material mitigation changes.

On August 11, 2026, the Colorado Department of Law published a Notice of Proposed Rulemaking and draft ADMT regulations, which will further clarify deployer obligations. The Department is receiving written comments through October 26, 2026, and has scheduled a public hearing on the proposed regulations for October 26, 2026.

Connecticut SB 5

On June 2, 2026, the Connecticut governor signed SB 5, the Connecticut Artificial Intelligence Responsibility and Transparency Act (the “CART Act”) into law. The CART Act’s employment-related provisions apply to automated employment-related decision technology (“AEDT”) developed or deployed on or after October 1, 2027. AEDT is defined as technologies whose output is a “substantial factor” in decisions to hire, fire, promote, discipline, renew employment, or select an individual for training. The law defines “substantial factor” as a constraint, ranking, score, or other factor that meaningfully alters an employment-related outcome. Deployers using AEDT must disclose in plain language when employees or job applicants interact with such technology, unless it would otherwise be obvious to a reasonable person. Additionally, before making employment decisions using AEDT, deployers must provide written notice that AEDT has been deployed, the nature of the decision, the purpose and trade name of the AEDT, the categories of personal data analyzed and how it will be assessed, the sources of that data, and the deployer’s contact information. The Act also amends the Connecticut Fair Employment Practices Act to clarify that an employer’s use of AEDT is not a defense against a discrimination claim.

Delaware HB 380

On June 16, 2026, the Delaware General Assembly passed HB 380, which amended the Delaware Personal Data Privacy Act (“DPDPA”). If enacted, the bill would narrow the DPDPA’s employment-related exemption, which among other things would bring employee, applicant, and contractor data within the DPDPA’s scope when disclosed to any third party as part of a report in connection with a decision that produces legal or similarly significant effects concerning the individual. Among other things, employers and other parties would be required to include contractual terms in agreements with third parties, including to provide notice and information that an individual can request human review of an adverse action unless the opportunity for review is not in the “best interest” of the resident. HB 380 is awaiting the Delaware governor’s signature. If signed, the amendments would take effect on January 1, 2027. For a more detailed discussion of the bill’s consumer privacy requirements, see our prior blog post.

Illinois HB 3773 and Status of Rulemaking

Illinois’ HB 3773, which took effect on January 1, 2026, amended the Illinois Human Rights Act to require employers to notify applicants and employees when AI is used in a broad range of employment decisions, including decisions related to recruitment, hiring, promotion, selection for training, and discharge, among others. The law also prohibits the use of zip codes as a proxy for protected classes and confirms that using AI in a manner that discriminates on the basis of a protected class is unlawful. For further discussion of its key provisions, see our prior blog post.

On May 15, 2026, the Illinois Department of Human Rights (“IDHR”) published proposed rules implementing HB 3773, detailing employers’ notice obligations. However, on June 2, 2026, the IDHR announced that it was temporarily withdrawing the proposed rules to allow for continued collaboration with other state agencies. No revised timeline has been announced. Although the rulemaking process has been paused, employers should continue preparing for compliance with HB 3773 and monitor for the reopening of the comment period.

Next Steps

Given the pace of ADMT legislation, employers should inventory the automated tools currently used in hiring, promotion, discipline, termination, and other consequential employment decisions. They should also assess each state’s applicable notice, opt-out, and human review obligations against upcoming effective dates, many of which take effect on January 1, 2027. Employers should also develop policies and processes to ensure that they are satisfying relevant requirements when using AI in the employment context and considering these requirements when onboarding new tools. California employers should also monitor SB 947 and SB 951 for any developments.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Lindsey Tonsager Lindsey Tonsager

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their…

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their strategic and proactive engagement with the Federal Trade Commission, the U.S. Congress, the California Privacy Protection Agency, and State Attorneys General on proposed changes to data protection laws, and regularly represents clients in responding to investigations and enforcement actions involving their privacy and information security practices.

Lindsey’s practice focuses on helping clients launch new products and services that implicate the laws governing the use of artificial intelligence; data processing for robotics, autonomous vehicles, and other connected devices; biometrics; online advertising; the collection of personal information from children, teens, and students online; e-mail marketing; disclosures of video viewing information; and new technologies.

Lindsey also assesses privacy and data security risks in complex corporate transactions where personal data is a critical asset or data processing risks are otherwise material. In light of a dynamic regulatory environment where new state, federal, and international data protection laws are always on the horizon and enforcement priorities are shifting, she focuses on designing risk-based global privacy programs for clients that can keep pace with evolving legal requirements and efficiently leverage the clients’ existing privacy policies and practices. She conducts data protection assessments to benchmark against legal requirements and industry trends and proposes practical risk mitigation measures.

Photo of Libbie Canter Libbie Canter

Libbie Canter represents a wide variety of multinational companies on managing privacy, cyber security, and artificial intelligence risks, including helping clients with their most complex privacy challenges and the development of governance frameworks and processes to comply with U.S. and global privacy laws.

Libbie Canter represents a wide variety of multinational companies on managing privacy, cyber security, and artificial intelligence risks, including helping clients with their most complex privacy challenges and the development of governance frameworks and processes to comply with U.S. and global privacy laws. She routinely supports clients on their efforts to launch new products and services involving emerging technologies, and she has assisted dozens of clients with their efforts to prepare for and comply with federal and state laws, including the California Consumer Privacy Act, the Colorado AI Act, and other state laws. As part of her practice, she also regularly represents clients in strategic transactions involving personal data, cybersecurity, and artificial intelligence risk and represents clients in enforcement and litigation postures.

Libbie represents clients across industries, but she also has deep expertise in advising clients in highly-regulated sectors, including financial services and digital health companies. She counsels these companies — and their technology and advertising partners — on how to address legacy regulatory issues and the cutting edge issues that have emerged with industry innovations and data collaborations.

Chambers USA 2025 ranks Libbie in Band 3 Nationwide for both Privacy & Data Security: Privacy and Privacy & Data Security: Healthcare. Chambers USA notes, Libbie is “incredibly sharp and really thorough. She can do the nitty-gritty, in-the-weeds legal work incredibly well but she also can think of a bigger-picture business context and help to think through practical solutions.”

Photo of Carolyn Rashby Carolyn Rashby

Carolyn Rashby provides business-focused advice and counsel to companies navigating the constantly evolving and overlapping maze of federal, state, and local employment requirements. Carolyn’s approach is preventive, while recognizing the need to set clients up for the best possible defense should disputes arise.…

Carolyn Rashby provides business-focused advice and counsel to companies navigating the constantly evolving and overlapping maze of federal, state, and local employment requirements. Carolyn’s approach is preventive, while recognizing the need to set clients up for the best possible defense should disputes arise.

As a senior member of Covington’s Institutional Culture and Social Responsibility Practice Group, Carolyn has co-led significant investigations into workplace culture, DEI issues, and reports of sexual misconduct and workplace harassment.

As an employment lawyer with over two decades of experience, Carolyn focuses on a wide range of compliance and regulatory matters for employers, including:

Conducting audits regarding employee classification and pay equity
Advising on employment issues arising in corporate transactions
Strategic counseling on a wide range of issues including discrimination and harassment, wages and hours, worker classification, workplace accommodations and leave management, performance management and termination decisions, workplace violence, employment agreements, trade secrets, restrictive covenants, employee handbooks, and personnel policies
Drafting employment contracts and offer letters, separation agreements, NDAs, and other employment agreements
Advising on employee privacy matters, including under the California Consumer Privacy Act
Providing guidance on use of AI in the workplace and development of related policies
Leading anti-harassment and other workplace-related trainings, for employees, executives, and boards

Carolyn also works frequently with the firm’s white collar, privacy, employee benefits and executive compensation, corporate, government contracts, and cybersecurity practice groups to ensure that all potential employment issues are addressed in matters handled by these groups.

Photo of Jayne Ponder Jayne Ponder

Jayne Ponder provides strategic advice to national and multinational companies across industries on existing and emerging data privacy, cybersecurity, and artificial intelligence laws and regulations.

Jayne’s practice focuses on helping clients launch and improve products and services that involve laws governing data privacy…

Jayne Ponder provides strategic advice to national and multinational companies across industries on existing and emerging data privacy, cybersecurity, and artificial intelligence laws and regulations.

Jayne’s practice focuses on helping clients launch and improve products and services that involve laws governing data privacy, artificial intelligence, sensitive data and biometrics, marketing and online advertising, connected devices, and social media. For example, Jayne regularly advises clients on the California Consumer Privacy Act, Colorado AI Act, and the developing patchwork of U.S. state data privacy and artificial intelligence laws. She advises clients on drafting consumer notices, designing consent flows and consumer choices, drafting and negotiating commercial terms, building consumer rights processes, and undertaking data protection impact assessments. In addition, she routinely partners with clients on the development of risk-based privacy and artificial intelligence governance programs that reflect the dynamic regulatory environment and incorporate practical mitigation measures.

Jayne routinely represents clients in enforcement actions brought by the Federal Trade Commission and state attorneys general, particularly in areas related to data privacy, artificial intelligence, advertising, and cybersecurity. Additionally, she helps clients to advance advocacy in rulemaking processes led by federal and state regulators on data privacy, cybersecurity, and artificial intelligence topics.

As part of her practice, Jayne also advises companies on cybersecurity incident preparedness and response, including by drafting, revising, and testing incident response plans, conducting cybersecurity gap assessments, engaging vendors, and analyzing obligations under breach notification laws following an incident.

Jayne maintains an active pro bono practice, including assisting small and nonprofit entities with data privacy topics and elder estate planning.

Photo of Bryan Ramirez Bryan Ramirez

Bryan Ramirez is an associate in the firm’s San Francisco office and is a member of the Data Privacy and Cybersecurity Practice Group. He advises clients on a range of regulatory and compliance issues, including compliance with state privacy laws. Bryan also maintains…

Bryan Ramirez is an associate in the firm’s San Francisco office and is a member of the Data Privacy and Cybersecurity Practice Group. He advises clients on a range of regulatory and compliance issues, including compliance with state privacy laws. Bryan also maintains an active pro bono practice.