HR August 17, 2026 9 min read

AI Policy for HR: Ethical Use Rules, Hiring Laws, and Employee Data

By the Shadow AI Policy team

HR is the one function where careless AI use stops being a data problem and becomes a discrimination problem. Every other department that pastes something into a chatbot risks a confidentiality breach. HR risks that too — and, on top of it, a protected-class claim, a regulator, and in a growing number of jurisdictions a specific statute written for exactly this conduct.

That is why a generic company-wide AI acceptable use policy is not sufficient for an HR team. The company policy tells everyone not to paste confidential data into unapproved tools. An HR policy has to go further: it has to say which employment decisions may involve an automated tool at all, what has to be disclosed to the person on the other side of that decision, and which categories of employee data are simply out of bounds regardless of which tool is approved.

The fastest way to find out whether you have a problem: ask your recruiters which tools they use to rank, screen, or summarise applicants — including anything bundled into your ATS that turned on by default. Vendors ship AI ranking features into existing products without a new contract, which means an employer can fall inside a bias-audit obligation without ever deciding to adopt an AI tool.

The laws that specifically govern AI in employment decisions

Most AI regulation is horizontal — it applies to AI generally. A small and growing body of law applies specifically to AI used in hiring, promotion, and other employment decisions. These are the ones an HR policy should be written against, with what each actually requires:

  1. New York City · roles located in NYC Local Law 144 of 2021 — Automated Employment Decision Tools

    Effective January 1, 2023, with enforcement from July 5, 2023. If an automated employment decision tool substantially assists a hiring or promotion decision, the employer must commission an independent bias audit annually, publish a summary of the results, and give notice to candidates and employees. Penalties run from $500 to $1,500 per violation, and each day of continued use has been treated as a separate violation. It has been read to reach remote roles tied to a New York City office, so "we don't have an NYC location" is not on its own an answer.

  2. Illinois · effective January 1, 2026 HB 3773 — amendment to the Illinois Human Rights Act

    Signed August 9, 2024 and in force since the start of this year. It makes it a civil rights violation to use AI that has the effect of discriminating on a protected characteristic in recruitment, hiring, promotion, discipline, discharge, or other terms of employment — and separately to use zip code as a proxy for a protected class. It also requires employers to notify employees and applicants that AI is being used. Note the difference from New York City: Illinois does not mandate a bias audit. It mandates a non-discriminatory outcome and notice. An audit is how a prudent employer demonstrates the first of those, not a statutory checkbox.

  3. Colorado · currently stayed SB 24-205, the Colorado AI Act

    A federal court froze the Act weeks before its June 30 start date, so the specific compliance deadline is on hold. Read that narrowly. As we covered in our May 7 briefing, the stay suspends Colorado's obligations — it does nothing to federal anti-discrimination exposure, which was always the larger risk.

  4. European Union · staged deadlines EU AI Act

    High-risk employment AI obligations were deferred to December 2027, a 16-month slip from the original date. But August 2, 2026 was not a non-event: general-purpose AI and chatbot transparency obligations activated on schedule. See our June 25 briefing for what still applies in the meantime.

  5. United States · everywhere, already Title VII and the Americans with Disabilities Act

    The most important entry on this list, and the one most often left off it. Federal anti-discrimination law does not care whether a human or a model produced the disparate outcome. An AI screening tool that filters out applicants with employment gaps, or that penalises a non-standard interview cadence, can create exposure under statutes that long predate any AI-specific rule — in every state, with no effective date to wait for.

What an ethical AI use policy for HR must cover

Seven rules. A policy that states these explicitly is defensible; one that leaves them to judgement is not.

1. Which employment decisions may involve an automated tool at all. Name them. Sourcing and scheduling are low-risk. Ranking, scoring, screening out, and recommending for promotion or discipline are the high-risk set, and the policy should require a named human decision-maker for each of them — not a human who rubber-stamps a ranked list, but one who can explain the decision without reference to the tool's output.

2. A no-consumer-tools rule for anything involving an identifiable person. The distinction that matters is not ChatGPT versus Claude, it is whether the vendor has contractually committed not to train on your inputs. A free-tier account has made no such commitment.

3. The prohibited-data list — see the next section. This is the single most useful page of an HR AI policy, because it converts an abstract duty into something a coordinator can follow at 4pm on a Friday.

4. The notice duty. Both New York City and Illinois require telling people that AI is in use. Write the notice text once, put it in the policy, and reference it from the job-posting template and the ATS — otherwise it lives in one recruiter's head.

5. An audit and record-keeping rule. If you use an AEDT for NYC-covered roles, the annual independent bias audit and its published summary are obligations with dates attached. Give them an owner and a calendar entry. Everywhere else, keep enough record of what the tool was asked and what a human decided to reconstruct the decision later.

6. A vendor-change trigger. Because ATS and HRIS vendors ship AI features into products you have already bought, the policy needs a rule that a material AI feature turning on is itself a reviewable event. Without it, your compliance posture changes during a release you never read.

7. Rules for AI-drafted employment documents. Offer letters, PIPs, investigation summaries, and termination rationales drafted with AI assistance must be reviewed and owned by a named person. An AI-drafted PIP that misstates a date becomes evidence in a wrongful-termination claim, and "the tool wrote it" has never been a defence.

Employee data that must never enter a general-purpose AI tool

The categories below should be named in the policy rather than covered by a general "confidential information" clause, because HR staff do not experience them as confidential information — they experience them as the day's work.

The rule to write is not "be careful with these." It is: these do not go into any tool that is not on the approved list, and the approved list for this category is shorter than the approved list for everything else.

The notice duty is the requirement most HR teams miss

Bias audits get the attention because they cost money. Notice is the obligation more employers actually fail, because it requires nothing except remembering — and it is a live requirement in both New York City and Illinois.

Notice is also the cheapest possible good-faith evidence. An employer who disclosed AI use, kept the disclosure consistent across postings, and can produce the policy that required it is in a materially different position from one who did not, whatever the audit shows.

What to implement first

This week: inventory the tools. Ask recruiters and HR business partners what they use, and separately ask your ATS and HRIS vendors in writing which AI features are enabled on your instance. The second question is the one that finds surprises.

This month: write the prohibited-data list and the notice text, and get both in front of employment counsel. These are the two artefacts that do the most work per hour spent.

This quarter: assign an owner to the bias-audit obligation if any covered role touches New York City, and add the vendor-change trigger to your procurement review.

Common questions

What should an ethical AI use policy for HR include?

An HR AI policy should name which employment decisions may involve an automated tool and require a named human decision-maker for the high-risk ones (ranking, screening out, promotion, discipline); prohibit consumer-tier tools for anything involving an identifiable person; list the employee-data categories that may never be entered into a general-purpose AI tool; state the notice text given to candidates and employees; assign an owner for bias-audit and record-keeping obligations; treat a vendor turning on a new AI feature as a reviewable event; and require named human ownership of AI-drafted offer letters, PIPs, investigation summaries and termination rationales.

Is it legal to use AI to screen job applicants?

Generally yes, but with conditions that vary by jurisdiction. In New York City, an automated employment decision tool that substantially assists hiring or promotion triggers Local Law 144: an annual independent bias audit, a published summary of results, and notice to candidates. In Illinois, HB 3773 took effect January 1, 2026 and makes it a civil rights violation under the Illinois Human Rights Act to use AI that has the effect of discriminating on a protected characteristic, or to use zip code as a proxy for one, and it requires notice — but it does not mandate a bias audit. Independent of any AI-specific statute, Title VII and the ADA apply everywhere in the United States and do not distinguish between a human and a model as the source of a disparate outcome.

Does NYC Local Law 144 apply to remote roles?

It has been read to reach remote positions tied to a New York City office, so the absence of an NYC worksite is not on its own a reason to conclude the law does not apply. If any covered role is associated with a New York City office, assume the bias-audit and notice obligations are in scope and confirm with employment counsel.

Can HR put performance reviews or investigation notes into ChatGPT?

Not into a consumer-tier account. Performance reviews, PIPs, harassment and misconduct investigation material, witness statements, and medical or ADA accommodation records are the highest-sensitivity documents an HR team handles, and several carry statutory confidentiality obligations independent of any AI policy. The distinction that matters is not which model it is but whether the vendor has contractually committed not to train on your inputs and to restrict their use — a commitment a free tier has not made.

Do we have to tell candidates we are using AI?

In New York City and Illinois, yes. Local Law 144 requires notice to candidates and employees where a covered automated employment decision tool is used, and Illinois HB 3773 requires employers to notify employees and applicants that AI is in use. Notice is also the cheapest good-faith evidence available: write the text once, put it in the policy, and reference it from the job-posting template and the applicant tracking system so it does not depend on an individual recruiter remembering.

Generate your AI policy in 10 minutes

Tailored to your industry and the AI tools your team uses. Free preview, $79 one-time or $149/mo with monthly updates.

Generate my policy kit →