In eight months, Washington moved to sweep aside state AI laws, Colorado repealed its landmark act before it ever took effect, and Brussels pushed its biggest deadline back sixteen months. It feels like breathing room. For employers using AI in hiring, it’s the opposite.
In May, Colorado repealed the most ambitious AI law in the country — before a single company ever had to comply with it. Weeks later, the European Union moved its biggest AI deadline back by sixteen months. And since December, the Justice Department has been under presidential orders to challenge state AI laws in court — through a litigation task force built for exactly that purpose.
If your organization uses AI anywhere in hiring — a resume screener, a video-interview scorer, the “talent matching” feature that came bundled inside your HR platform — you could be forgiven for reading those headlines and concluding that the pressure is off.
That conclusion is wrong, and it is wrong in a way that eventually lands on your desk.
Here is the actual situation in one sentence: the rules governing AI in employment did not get lighter this year — they got faster, and the risk moved from the regulators you were watching to the statutes and plaintiffs you weren’t.
The Deregulation You Read About
The headlines are real. It’s worth being precise about what happened, because the details are where the false comfort lives.
On December 11, 2025, the White House issued an executive order directing the Justice Department to challenge state AI laws, naming Colorado’s algorithmic-discrimination act as the template of what it wants gone. In April, DOJ intervened in a lawsuit against that Colorado law; within days, Colorado’s attorney general agreed not to enforce it while the legislature worked. In May, the legislature repealed the act outright and replaced it with a narrower disclosure-based law. In Brussels, the EU’s “digital omnibus” package — given final approval by the Council on June 29 — pushed the AI Act’s high-risk obligations for hiring and workforce-management systems from August 2026 to December 2, 2027. Meanwhile, the EEOC’s technical guidance on AI in hiring came off the agency’s website back in January 2025 and has never been replaced.
Read quickly, that’s a deregulation story. Read carefully, three facts change the picture.
First, no court has struck down any state AI law. The Colorado pause was a negotiated litigation posture, not a ruling. Every state statute on the books remains fully mandatory, and the constitutional questions are unresolved.
Second, the federal retreat touched agency enforcement — not the underlying statutes. Title VII, the ADA, and the ADEA still say what they said. When an executive order deprioritizes disparate-impact enforcement, it changes what the government files. It does not change what a plaintiff’s lawyer can file, and the plaintiffs’ bar has noticed the vacuum.
Third, the loudest deadline that “moved” was never the one closest to you.
The Regulation Nobody Is Reading About
While attention followed the federal fight, the ground floor quietly filled in.
Since January 1 of this year, Illinois law has made it a civil-rights violation for an employer to use AI that has a discriminatory effect in recruitment, hiring, promotion, discipline, or discharge — no intent required — with notice obligations to applicants and employees. Since October 2025, California’s civil-rights regulations have explicitly covered automated-decision systems, treated your vendors as your agents, and required four years of record retention around AI-assisted employment decisions. New York City has required annual independent bias audits and ten-business-day advance notice to candidates since 2023 — and a December 2025 state comptroller audit criticizing the city’s near-dormant enforcement is precisely the kind of pressure that turns a sleepy statute into an active one. Texas’s new AI law took effect January 1 with an intent-based standard and exclusive attorney-general enforcement.
And the EU deadline that didn’t move is the near one: this August 2, the AI Act’s transparency obligations take effect, alongside the enforcement machinery and penalty regime. If your systems interact with people in the EU, disclosure duties arrive on schedule even though the high-risk program slipped to 2027.
Notice the pattern. Nothing on this list is proposed, pending, or theoretical. All of it is live law, and almost none of it made national headlines — because none of it arrived with a press conference. It arrived the way employment law usually does: statute by statute, effective date by effective date, while everyone watched the louder story.
Why “We Did a Compliance Review” Is the New Exposure
Here is the part I find most consequential for executives, and it isn’t any single law.
Of the five biggest dates on a 2025-vintage AI compliance calendar, three have since moved — one twice. Colorado’s effective date shifted, then the law itself was repealed and replaced with different duties starting January 1, 2027. The EU’s hiring-AI deadline moved sixteen months. California’s synthetic-content law was delayed by amendment. In the same window, brand-new obligations in Illinois, Texas, and California quietly came online.
That means an AI compliance review completed in mid-2025 — a genuinely diligent one, done by good lawyers — now misstates the law in both directions. It tells you to prepare for obligations that no longer exist on that timeline, and it says nothing about obligations that now bind you. The problem isn’t that anyone did bad work. The problem is that the work has a shelf life, and the shelf life is currently about one quarter.
This is the structural insight of the moment: AI employment regulation has become a stream, not a snapshot. Organizations that treat it as a snapshot will keep paying for expensive documents that are obsolete before the invoice clears.
The 2027 Wave Makes This Year the Cheap Year
There is a second reason the current lull is misleading: it precedes the most concentrated set of deadlines yet.
On January 1, 2027, Colorado’s replacement law and California’s automated-decisionmaking rules both take effect — pre-use notices, adverse-decision notices, human-review and opt-out rights, with HR data squarely covered. Connecticut’s employment provisions follow in October 2027. The EU’s full high-risk regime for hiring systems lands December 2, 2027.
Individually, each is manageable. Together, they describe one operational capability: know every place AI touches an employment decision, tell people about it before and after, test it, keep the records, and give a human meaningful control. An employer who builds that workflow once — to the strictest applicable standard — will satisfy substantially all of these regimes at marginal additional cost. An employer who waits until each effective date will build it four times under deadline pressure, at four prices.
The second half of 2026 is when that build is cheap. The first deadlines arrive January 1 — the window is measured in months, not years.
Five Moves That Hold Up Whichever Way the Law Breaks
The honest advice, given the volatility, is not “comply with everything.” It’s to build the small set of capabilities that every version of the future requires.
1. Inventory where algorithms touch employment decisions. Include the features embedded in tools you didn’t buy for that purpose — screening and ranking functions inside your ATS count, whether or not anyone calls them AI.
2. Put your vendors on the hook. California already treats vendor tools as your agents, and every pending regime follows that logic. Ask vendors for their testing evidence and audit artifacts; contract for the right to get them. A vendor grading its own homework is not assurance.
3. Standardize notice once. Candidate and employee notices built to the strictest current standard will substantially satisfy the rest. Retrofitting notices jurisdiction by jurisdiction is the expensive path.
4. Test, and document why. Illinois’s effects-based standard makes outcome testing the core defense; California makes your testing history relevant evidence; Texas makes documented intent decisive. Three different theories, one answer: test your tools and write down what you found and fixed.
5. Put the map on a rhythm, not a shelf. Assign one owner. Re-verify quarterly against primary sources. The organizations that handle this well over the next two years will not be the ones with the thickest binders — they’ll be the ones who notice changes while their options are still open.
The Map Will Move Again
Every claim in this article was checked against primary sources — statutes, regulators, and official publications — in the week before publication. I can tell you from maintaining that verification log: some of what’s written here will need updating within the quarter. That is not a caveat. That is the point.
The executives who get caught over the next two years won’t be the ones who ignored AI regulation. They’ll be the ones who checked once, filed the memo, and assumed the map held still.
If you want to see what the current map actually looks like for your organization, Meridian maintains the AI Governance Atlas — a continuously verified tracker of every AI employment rule, effective date, and enforcement development that touches U.S. and EU employers. The fastest way to use it: bring your hiring-tool list to a 30-minute conversation and leave knowing which of these dates are yours. No charge, and it’s useful whether or not we ever work together.
Frequently Asked Questions
Is the Colorado AI Act still in effect?
No. Colorado repealed its 2024 AI Act in May 2026 — before it ever took effect — and replaced it with SB 26-189, a narrower disclosure-based law. The new obligations, including pre-use notice and adverse-decision notice for AI-assisted employment decisions, take effect January 1, 2027.
Which U.S. states currently regulate AI in hiring?
As of mid-2026, live obligations exist in Illinois (discriminatory-effect ban and notice duty, effective January 1, 2026), California (civil-rights regulations covering automated-decision systems since October 2025), New York City (annual bias audits and candidate notice under Local Law 144), Texas (intent-based statute effective January 1, 2026), and Maryland (facial-recognition consent in interviews). Colorado and Connecticut obligations arrive in 2027.
Does the EU AI Act apply to U.S. companies?
Yes, if their AI systems or outputs are used in the EU. Transparency obligations take effect August 2, 2026. The full high-risk regime for hiring and workforce-management systems was postponed to December 2, 2027 by the EU’s 2026 omnibus package.
Did federal deregulation end AI hiring lawsuits?
No. Executive actions changed federal agency enforcement priorities, but Title VII, the ADA, and the ADEA are unchanged — private plaintiffs can still bring both disparate-treatment and disparate-impact claims over AI hiring tools.
How often should employers update their AI compliance position?
Quarterly, at minimum, in the current environment. Three of the five biggest deadlines on a 2025 compliance calendar have moved since late 2025, while new state obligations took effect. A one-time review now misstates the law within about a quarter.
This article provides general information about legal and regulatory developments. It is not legal advice, and reading it does not create an attorney-client or advisory relationship. Consult qualified employment counsel about your organization’s specific obligations.