US States Set New Rules for Automated Workplace Decisions

US States Set New Rules for Automated Workplace Decisions

Desiree Sainthrope stands at the vanguard of the legal community, serving as a definitive voice on the complex intersection of global trade, intellectual property, and the rapidly shifting landscape of artificial intelligence. As a seasoned legal expert with a mastery of trade agreements and global compliance, she has spent years deciphering the fine print of international regulations to protect corporate interests. Her current focus has shifted toward the heavy regulatory weight now falling on employers as state governments move to restrict and monitor automated decision-making technology. With several major legislative deadlines approaching in 2027, her insights provide a necessary roadmap for organizations trying to balance innovation with the high stakes of modern compliance.

This discussion explores the evolving legal frameworks governing automated tools in the workplace, covering everything from mandatory human oversight to the strict notice requirements emerging across the United States. We delve into the specific legislative movements in California, Colorado, Connecticut, and Illinois, examining how terms like “substantial factor” and “significant decisions” are being redefined to protect workers from algorithmic bias. The conversation also highlights the practical steps employers must take to remain compliant, including the daunting task of maintaining multi-year record logs and providing plain-language disclosures to affected individuals.

With so many organizations currently relying on automated tools for critical functions like hiring, work allocation, and compensation, what are the most immediate challenges companies face as they try to align their operations with these new legal standards?

The immediate challenge for any organization right now is the sheer speed at which the regulatory floor is shifting beneath them. We are seeing a move away from the “wild west” of algorithmic automation toward a period of intense scrutiny, particularly with California’s privacy regulations set to fully impact significant decisions by January 1, 2027. Employers must understand that “significant decisions” are no longer just about who gets the job; they encompass the entire lifecycle of employment, including how work is allocated and how compensation is calculated. To stay ahead, companies have to provide pre-use notices and offer clear opt-out rights, which creates a logistical hurdle for HR departments that have spent years streamlining these processes through automation. It feels like a massive pivot where the efficiency of a machine must now be tempered by the deliberate, often slower, pace of human transparency.

California is currently considering even more stringent measures like the “No Robo Bosses Act” and the “AI Job Killer Notice Act.” How would these specific pieces of legislation change the day-to-day reality for managers and HR professionals?

If SB 947, the “No Robo Bosses Act,” passes the Assembly, it will fundamentally dismantle the idea of fully autonomous management. Managers would be legally prohibited from relying solely on an automated decision system to make significant moves like terminations or promotions; they would be required to conduct an independent human investigation to verify every single output the system generates. It adds a layer of manual labor that many companies haven’t budgeted for, effectively requiring a human “safety check” for every algorithmic recommendation. Furthermore, the “AI Job Killer Notice Act” introduces a profound emotional and administrative weight by requiring a potential 90-day advance notice for layoffs that are even partially attributable to AI. This isn’t just about paperwork; it’s about a 90-day period of tension and transparency that changes how companies plan their technological transitions and how they communicate with their workforce.

Colorado recently overhauled its approach to artificial intelligence with SB 26-189. Could you explain the significance of the “materially influence” standard and what it means for how companies must document their decision-making?

Colorado has moved toward a very specific, high-resolution framework that targets any technology used to “materially influence” a consequential decision. Under the law taking effect on January 1, 2027, if an automated tool acts as a non-de minimis factor—meaning it ranks, recommends, or meaningfully alters the outcome of a hiring or employment decision—it falls under strict oversight. The most striking requirement is the three-year record retention rule, where deployers must keep detailed logs of ADMT versions, changelogs, and documentation of any material changes made to mitigate risks. This creates a sensory overload of data management for companies, as they must be ready to provide a plain-language disclosure of an adverse decision within 30 days of it happening. It is no longer enough to say “the computer said so”; you have to be able to explain the “why” and the “how” in a way that an average person can understand and potentially appeal.

Connecticut’s “CART Act” introduces the term “substantial factor” regarding automated employment-related decision technology. How does this definition broaden the scope of what employers need to disclose to their staff?

The CART Act, which focuses on technology developed or deployed on or after October 1, 2027, uses the “substantial factor” definition to capture any score or ranking that meaningfully alters an employment outcome. This effectively casts a very wide net, dragging almost any performance-tracking or resume-scanning software into the light of mandatory disclosure. Employers are now tasked with providing written notice that includes the purpose of the tool, its trade name, and exactly what categories of personal data are being analyzed. There is a certain vulnerability in this level of transparency, as companies have to reveal the “secret sauce” of their internal evaluations to both applicants and current employees. Moreover, the law explicitly states that using these tools is no defense against a discrimination claim, which puts the legal burden of proof firmly back on the shoulders of the employer, regardless of how sophisticated their AI might be.

Illinois has already implemented changes through HB 3773 that directly target bias, such as the ban on using zip codes as a proxy. What does the current pause in rulemaking mean for employers who are trying to comply with these rules today?

Even though the Illinois Department of Human Rights temporarily withdrew its proposed rules in June 2026 to collaborate with other agencies, the underlying law is already in effect as of January 1, 2026. This creates a state of “informed waiting” where employers are legally obligated to notify workers about AI use but lack the granular procedural roadmap that the finalized rules would provide. The ban on using zip codes as a proxy for protected classes is a clear signal that the state is looking for hidden biases that machines often overlook or inadvertently amplify. I tell my clients that they cannot afford to wait for the rulemaking to resume; they must proactively audit their AI models now to ensure they aren’t using data points that correlate with race or other protected characteristics. The silence from the state agencies should be treated as the calm before a very significant enforcement storm.

With Delaware also moving to narrow its employment-related exemptions and mandate human review, what practical advice do you have for companies that operate across multiple state lines?

The most practical step is to move toward a “highest common denominator” approach to compliance, because trying to manage different notice periods and disclosure formats for every state is a recipe for disaster. If Delaware’s HB 380 is signed and takes effect on January 1, 2027, companies will need to bake notice and human review rights directly into their third-party contracts, ensuring that an individual can request a review unless it isn’t in their “best interest.” I recommend that employers start by inventorying every single automated tool they use, from the simplest scheduling software to the most complex predictive hiring algorithms. Once you have that inventory, you need to map out which tools affect “consequential decisions” and begin drafting universal disclosure templates that satisfy the strictest requirements, like Colorado’s 30-day window or Connecticut’s detailed data-source listing. It’s about building a robust, centralized compliance infrastructure that can withstand the specific pressures of any individual state’s legal climate.

What is your forecast for the evolution of ADMT regulations as we look toward 2027 and beyond?

I anticipate that the “human-in-the-loop” requirement will become the absolute gold standard for employment law across the country, effectively ending the era of “set it and forget it” automation. We are moving toward a 2027 landscape where the legal definition of a “manager” will essentially include the role of an “algorithmic auditor” who must be capable of explaining and justifying machine-generated scores. We will likely see a surge in litigation centered around the “right to appeal” and “meaningful human review,” as employees and their counsel test the limits of what constitutes a “commercially reasonable” reconsideration. For businesses, this means that the cost of implementing AI will no longer just be the subscription fee to a software vendor; it will also include the significant, ongoing cost of human oversight and the rigorous maintenance of three-year data trails. The future of work is not just automated; it is audited, and only the companies that embrace this transparency will survive the regulatory transition.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later