By the Shadow AI Policy team
HR is the one function where careless AI use stops being a data problem and becomes a discrimination problem. Every other department that pastes something into a chatbot risks a confidentiality breach. HR risks that too — and, on top of it, a protected-class claim, a regulator, and in a growing number of jurisdictions a specific statute written for exactly this conduct.
That is why a generic company-wide AI acceptable use policy is not sufficient for an HR team. The company policy tells everyone not to paste confidential data into unapproved tools. An HR policy has to go further: it has to say which employment decisions may involve an automated tool at all, what has to be disclosed to the person on the other side of that decision, and which categories of employee data are simply out of bounds regardless of which tool is approved.
The fastest way to find out whether you have a problem: ask your recruiters which tools they use to rank, screen, or summarise applicants — including anything bundled into your ATS that turned on by default. Vendors ship AI ranking features into existing products without a new contract, which means an employer can fall inside a bias-audit obligation without ever deciding to adopt an AI tool.
Most AI regulation is horizontal — it applies to AI generally. A small and growing body of law applies specifically to AI used in hiring, promotion, and other employment decisions. These are the ones an HR policy should be written against, with what each actually requires:
Seven rules. A policy that states these explicitly is defensible; one that leaves them to judgement is not.
1. Which employment decisions may involve an automated tool at all. Name them. Sourcing and scheduling are low-risk. Ranking, scoring, screening out, and recommending for promotion or discipline are the high-risk set, and the policy should require a named human decision-maker for each of them — not a human who rubber-stamps a ranked list, but one who can explain the decision without reference to the tool's output.
2. A no-consumer-tools rule for anything involving an identifiable person. The distinction that matters is not ChatGPT versus Claude, it is whether the vendor has contractually committed not to train on your inputs. A free-tier account has made no such commitment.
3. The prohibited-data list — see the next section. This is the single most useful page of an HR AI policy, because it converts an abstract duty into something a coordinator can follow at 4pm on a Friday.
4. The notice duty. Both New York City and Illinois require telling people that AI is in use. Write the notice text once, put it in the policy, and reference it from the job-posting template and the ATS — otherwise it lives in one recruiter's head.
5. An audit and record-keeping rule. If you use an AEDT for NYC-covered roles, the annual independent bias audit and its published summary are obligations with dates attached. Give them an owner and a calendar entry. Everywhere else, keep enough record of what the tool was asked and what a human decided to reconstruct the decision later.
6. A vendor-change trigger. Because ATS and HRIS vendors ship AI features into products you have already bought, the policy needs a rule that a material AI feature turning on is itself a reviewable event. Without it, your compliance posture changes during a release you never read.
7. Rules for AI-drafted employment documents. Offer letters, PIPs, investigation summaries, and termination rationales drafted with AI assistance must be reviewed and owned by a named person. An AI-drafted PIP that misstates a date becomes evidence in a wrongful-termination claim, and "the tool wrote it" has never been a defence.
The categories below should be named in the policy rather than covered by a general "confidential information" clause, because HR staff do not experience them as confidential information — they experience them as the day's work.
The rule to write is not "be careful with these." It is: these do not go into any tool that is not on the approved list, and the approved list for this category is shorter than the approved list for everything else.
Bias audits get the attention because they cost money. Notice is the obligation more employers actually fail, because it requires nothing except remembering — and it is a live requirement in both New York City and Illinois.
Notice is also the cheapest possible good-faith evidence. An employer who disclosed AI use, kept the disclosure consistent across postings, and can produce the policy that required it is in a materially different position from one who did not, whatever the audit shows.
This week: inventory the tools. Ask recruiters and HR business partners what they use, and separately ask your ATS and HRIS vendors in writing which AI features are enabled on your instance. The second question is the one that finds surprises.
This month: write the prohibited-data list and the notice text, and get both in front of employment counsel. These are the two artefacts that do the most work per hour spent.
This quarter: assign an owner to the bias-audit obligation if any covered role touches New York City, and add the vendor-change trigger to your procurement review.
An HR AI policy should name which employment decisions may involve an automated tool and require a named human decision-maker for the high-risk ones (ranking, screening out, promotion, discipline); prohibit consumer-tier tools for anything involving an identifiable person; list the employee-data categories that may never be entered into a general-purpose AI tool; state the notice text given to candidates and employees; assign an owner for bias-audit and record-keeping obligations; treat a vendor turning on a new AI feature as a reviewable event; and require named human ownership of AI-drafted offer letters, PIPs, investigation summaries and termination rationales.
Generally yes, but with conditions that vary by jurisdiction. In New York City, an automated employment decision tool that substantially assists hiring or promotion triggers Local Law 144: an annual independent bias audit, a published summary of results, and notice to candidates. In Illinois, HB 3773 took effect January 1, 2026 and makes it a civil rights violation under the Illinois Human Rights Act to use AI that has the effect of discriminating on a protected characteristic, or to use zip code as a proxy for one, and it requires notice — but it does not mandate a bias audit. Independent of any AI-specific statute, Title VII and the ADA apply everywhere in the United States and do not distinguish between a human and a model as the source of a disparate outcome.
It has been read to reach remote positions tied to a New York City office, so the absence of an NYC worksite is not on its own a reason to conclude the law does not apply. If any covered role is associated with a New York City office, assume the bias-audit and notice obligations are in scope and confirm with employment counsel.
Not into a consumer-tier account. Performance reviews, PIPs, harassment and misconduct investigation material, witness statements, and medical or ADA accommodation records are the highest-sensitivity documents an HR team handles, and several carry statutory confidentiality obligations independent of any AI policy. The distinction that matters is not which model it is but whether the vendor has contractually committed not to train on your inputs and to restrict their use — a commitment a free tier has not made.
In New York City and Illinois, yes. Local Law 144 requires notice to candidates and employees where a covered automated employment decision tool is used, and Illinois HB 3773 requires employers to notify employees and applicants that AI is in use. Notice is also the cheapest good-faith evidence available: write the text once, put it in the policy, and reference it from the job-posting template and the applicant tracking system so it does not depend on an individual recruiter remembering.
Tailored to your industry and the AI tools your team uses. Free preview, $79 one-time or $149/mo with monthly updates.
Generate my policy kit →