Skip to content
Adrythm
AI and automation

Automated employment decision tool

AEDT / NYC Local Law 144 / AI hiring bias audit

In short

An automated employment decision tool is software that helps decide who gets hired or promoted, such as a system that scans resumes for key words. New York City's Local Law 144 bars employers from using one unless it had a bias audit within a year, the results are public, and candidates were notified.

The law is Local Law 144 of 2021, and New York City's Department of Consumer and Worker Protection began enforcing it on July 5, 2023. The duty falls on employers and employment agencies, the organizations using the tool.

It sets three conditions. The tool must have had a bias audit within one year of its use. Information about that audit must be publicly available. Certain notices must go to employees or job candidates, and the department has clarified that the notice comes 10 business days before the tool is used.

The New York State Comptroller's audit of the law describes the kinds of tools in use. They include scanning resumes for key words to pick the most qualified candidates, scanning a candidate's online presence, and analyzing video interviews. The department can impose civil penalties of $500 to $1,500 per day for violations.

Enforcement has been light. The Comptroller's audit covered July 2023 through June 2025, and the department received only two complaints about these tools in that time. It surveyed 32 companies and found a single issue of non-compliance. The auditors reviewed the same companies and identified at least 17 instances of potential non-compliance.

In practice

A staffing agency in New York City turns on a feature in its applicant tracking software that scores applicants against each job. A scoring feature like that can bring the software under the law. Before relying on it, the agency needs a bias audit from within the past year, a public summary of the results, and notices to candidates 10 business days ahead.

Why it matters to you

The requirement names the business using the tool, whoever built it. A scoring feature that arrived inside ordinary hiring software can still call for the audit, the public posting and the notices. Penalties are counted per day, and light enforcement so far does not change who carries the obligation.

What to ask or check

  1. 01Does any feature in your hiring software score, rank or screen candidates?
  2. 02When was the tool's most recent bias audit, and where is the summary posted?
  3. 03How are candidates notified, and does the notice go out at least 10 business days before the tool is used?

What people get wrong

That the software vendor carries the legal duty. Local Law 144 prohibits employers and employment agencies from using the tool without the audit, the public information and the notices.

Red flags

  • A hiring product that ranks or screens candidates and has no bias audit summary to show.

Explainability

Explainability is being able to say how an AI system reached a decision. NIST separates three questions: transparency answers what happened, explainability answers how, and interpretability answers why it meant what it did. A global explanation describes the model. Only a local one answers a customer.

Model drift

Model drift is an AI system getting worse without anyone changing it. Microsoft names the causes plainly: data distribution changes, training-serving skew, data quality problems, shifts in environments and consumer behavior changes can all make a model stale. NIST sets the bar over the entire lifetime of the system, not at launch.

Training data

Training data is what a model learned from. The question owners ask is whether their own data joins it, and there is no single answer: OWASP names three separate stages, pre-training, fine-tuning and embedding. A commitment worth having names the stage and comes in writing.

AI agent

An AI agent is a model that has been granted the ability to take actions, not just produce text. OWASP says the damage one can do comes from three grants: excessive functionality, excessive permissions and excessive autonomy. What it is allowed to do matters more than how good it is.

Retrieval augmented generation

Retrieval augmented generation is how an AI answers from your documents without being trained on them. OWASP describes it as combining a pre-trained model with external knowledge sources at answer time. So the documents sit in a store the system reads from, and who can read that store is the question.

Hallucination

A hallucination is AI output that sounds right and is not. OWASP describes the model filling gaps in its training data using statistical patterns, without understanding the content, so the answer can be fluent and unfounded at once. Its own first example is an airline that was successfully sued over its chatbot.

Want this explained against your own numbers?

Twenty minutes, a straight answer, and no follow-up sequence if you decide not to work with us.