AI interviews and the law: NYC LL144 and the EU AI Act, explained
If you use AI anywhere in hiring, two regulators have already written rules for you. New York City audits automated hiring tools and makes you publish the results. The European Union classifies recruitment AI as high-risk by default and draws one bright line it will not let you cross. Neither law is exotic, and neither is going away. This post is a plain-language map of what each one requires from an AI interview — not legal advice. Where the rules bite, we quote the source and link it.
NYC Local Law 144: audit it, publish it, tell candidates
New York City’s Local Law 144 governs what it calls an automated employment decision tool (AEDT): software that uses machine learning or similar techniques to substantially assist or replace a human hiring or promotion decision. If a tool scores, ranks, or filters candidates and that output carries real weight in the decision, assume it is in scope.
The law puts three duties on the employer using such a tool:
- An independent bias audit, within one year of use. Before you rely on an AEDT, it must have been through a bias audit by an independent auditor, and that audit has to be no more than a year old. The audit measures selection and scoring rates across sex and race/ethnicity categories and reports the impact ratios.
- A public summary of the results. You must post, in a clear and conspicuous place, the date of the most recent audit and a summary of its results — including the selection or scoring rates and impact ratios it found. Not a claim that you audited; the actual numbers.
- Advance notice to candidates. You must tell candidates and employees that an AEDT will be used, and do it at least 10 business days before it is used, along with the job qualifications it assesses. On request, you disclose the data it collects and your retention policy.
The details and the DCWP’s guidance live on the official page: NYC’s Automated Employment Decision Tools rules.
The spirit is simple, and it is worth saying plainly: you cannot outsource judgment to a black box and shrug. If a tool helps decide who advances, you owe the people it measures an audit, honest numbers, and fair warning. A vendor that cannot hand you the audit inputs, or whose scores you cannot explain, is a vendor that puts you out of compliance.
The EU AI Act: hiring AI is high-risk by default
The EU AI Act — Regulation (EU) 2024/1689 — takes a different route to the same destination. It sorts AI by risk, and it places hiring near the top. Annex III, point 4 names as high-risk any AI system intended for “the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates.” An AI system that evaluates candidates in an interview or a test is squarely inside that description. There is no “we’re just a helper tool” carve-out to hide in.
High-risk is not a ban — it is a set of obligations. For a hiring AI, the ones that matter most are:
- A risk management system (Article 9): identify and mitigate the foreseeable harms the tool can do, across its lifecycle.
- Data and data governance (Article 10): training and evaluation data must be relevant and examined for bias.
- Transparency and information to deployers (Article 13): the people running the system must be told, clearly, what it does and how to use it correctly.
- Human oversight (Article 14): the system must be built so that a person can understand it, override it, and stay in control of the decision.
- Record-keeping (Article 12): automatic logging so a decision can be traced back after the fact.
Read those together and a shape emerges: the AI can inform the decision, but a human has to be able to see the reasoning, keep the controls, and reconstruct what happened. A score you cannot trace and cannot override is exactly the thing this law is built to stop.
The line both laws draw: no inferring what people feel
The EU AI Act does not merely regulate one category of hiring AI — it prohibits it. Article 5(1)(f) bans placing on the market or using AI systems “to infer emotions of a natural person in the areas of workplace and education institutions,” with narrow exceptions only for medical or safety reasons. This is not a high-risk obligation you can satisfy with paperwork. In the workplace, emotion inference is off the table.
That should change how you read a demo. An interview tool that claims to read a candidate’s tone, stress, confidence, or “enthusiasm” from their voice or face is doing emotion inference. Marketed as a feature, it is a legal liability in the EU and a bias risk everywhere else — because tone and “energy” track accent, culture, and nerves far more reliably than they track competence. The law and good hiring practice point the same way here: judge what a candidate said, never how they seemed to feel while saying it.
What to ask any AI interview vendor
You do not need to be a lawyer to pressure-test a tool against both laws. Five questions do most of the work:
- Can every score be traced to specific evidence? A rating with no citation behind it cannot be audited, published, or explained — which is what both laws ask of you.
- Is there a documented human decision point? Article 14 wants oversight that is real, not a rubber stamp. Who makes the call, and can they override the tool?
- Does it analyze voice, face, or emotion — at all? If the honest answer is yes, Article 5(1)(f) is your problem, and so is the bias that comes with it.
- Are rubric and model versions logged? Traceability means knowing which standard and which model produced a given result, months later.
- Can you export the transcript? If you cannot see the raw material a score was built from, you cannot defend the score.
Two of these deserve their own reading. On why evidence has to anchor every rating, see evidence-based scorecards. On why scoring content rather than delivery is what keeps first rounds fair, see what biases first-round interviews.
Where Hure lands
Hure’s answers to that checklist are the architecture, not a compliance patch bolted on later. Every score cites a moment in the transcript. Rubrics are versioned and model versions are recorded, so any result is traceable to the exact standard that produced it. There are no biometrics and no emotion inference, ever — Hure scores the content of what a candidate says, never how they sound or look. And a human always makes the final call; the scorecard exists to make that call comparable and defensible, not to make it for you.
One honest caveat: these laws are young and still moving, enforcement dates are landing in stages, and the details of your situation matter. Treat this as a map, not a ruling — and when the stakes are real, talk to counsel.