👥 HR 31 min read

Best AI Tools for HR Professionals in 2026

The tools are the easy part. Knowing which ones make you legally liable is the part most HR guides skip.

By whichaibest.com Team

Quick Answer

The best AI tools for HR in 2026 are Claude for policy and sensitive writing, Gemini if you run on Google Workspace, and ChatGPT as a generalist. All three are low risk for drafting work. Anything that screens or ranks candidates is a different category, legally, and needs auditing before use.

The best AI tools for HR professionals in 2026 are Claude for policy documents and anything with a delicate tone, Gemini if your team already lives in Google Workspace, and ChatGPT as the all-rounder. For drafting, summarising, and communications, any of the three will save you real hours this week.

But HR is not like other functions here, and the reason is worth stating plainly before the tool list. Most AI use in a marketing team is a productivity question. A chunk of AI use in HR is a regulatory question, because you are making decisions about people's livelihoods. Get the split wrong and the tool that saved you four hours becomes the thing you explain to a tribunal.

Which AI tools are actually worth using in HR?

Split them by what they touch, not by feature lists.

HR jobBest toolRisk level
Policy and handbook draftingClaudeLow
Job descriptionsClaude or ChatGPTLow
Difficult employee commsClaudeLow, with review
Meeting notes and summariesGemini in WorkspaceLow, if consent given
Interview question setsAnyLow
CV screening and rankingSpecialist tools onlyHigh, regulated
Video interview scoringSpecialist tools onlyHigh, regulated
Performance or promotion scoringSpecialist tools onlyHigh, regulated

Claude is the pick for HR writing because it handles long documents well and its tone stays measured on sensitive material. Redundancy letters, grievance outcome summaries, performance improvement plans. Our ChatGPT vs Claude comparison goes into where each one wins.

Gemini earns its place through integration rather than raw quality. If your HR team runs on Google Docs, Sheets, and Meet, having AI inside those beats a marginally better model in a separate tab.

ChatGPT remains the strongest generalist and the easiest to get a sceptical team using. Its free tier covers most HR writing volume.

Notice what is not on that list: a general chatbot doing your shortlisting. That's deliberate, and the next few sections explain why.

What can you safely use AI for right now?

Plenty, and this is where the actual time savings live. The safe zone is work where AI produces a draft that a human then owns.

The common thread: none of these decides anything about a specific person. The moment output starts influencing who gets hired, promoted, or let go, you have crossed into the regulated category.

How many HR teams are actually using AI?

Fewer than the noise suggests, and where they're using it is the interesting part.

SHRM surveyed 1,908 HR professionals between 5 and 23 December 2025 for The State of AI in HR 2026 Report. The headline number is lower than most vendor decks imply: 39 percent have adopted AI in HR, with another 7 percent intending to launch this year. Which means 54 percent have not adopted AI in HR and have no plans to, and 31 percent have no AI plans anywhere in the organisation.

So if your team hasn't started, you're in the majority. That's worth saying because a lot of HR content is written to make you feel late.

The outcomes reported by teams that have adopted are genuinely good. 87 percent saw efficiency improvements, 75 percent saw better work quality, and 70 percent reported improvements in creativity. On the fear that usually sits underneath all of this, 77 percent said AI had no impact on their job security and 73 percent said the same about their career prospects.

Now the finding that should stop you, and it lines up uncomfortably with everything in the rest of this article. Here's where AI is actually deployed inside HR, by function:

Read those two ends together. The function where HR teams have deployed AI most heavily is recruiting, which is the single most regulated use case in this entire article. The function where they've deployed it least is compliance, which is the thing that would help them manage that exposure.

That's not a criticism of anyone's judgement. Recruiting has the obvious volume problem, so it's the natural first target, and compliance work is harder to hand to a model. But the gap is the story. Adoption has concentrated precisely where the legal risk is highest, and it's close to absent where the guardrails would be built.

Which is a reasonable argument for reading the next five sections before you expand what you're already doing.

Why is candidate screening the riskiest use case?

Because it is the one regulators actually named, and because the failure mode is invisible.

A biased job description is visible. Someone reads it and says that sounds off. A screening model that quietly ranks one group lower produces no visible artefact at all. You just see a shortlist, and it looks fine, and the people it filtered out never appear anywhere you would look.

Which is why the rules focus here rather than on your handbook drafts. Two jurisdictions have already moved, and a third position matters even more than either.

How biased are screening tools, actually?

Badly enough that the numbers are worth reading twice. And this is the part most compliance write-ups leave out, because it's easier to cite a statute than to say what the tools actually do.

Kyra Wilson and Aylin Caliskan at the University of Washington Information School ran the test properly and presented it at the AAAI/ACM Conference on AI, Ethics and Society on 22 October 2024. The scale matters here: over 550 real resumes against 500 real job listings across nine occupations, with 120 name variations associated with white and Black men and women, producing more than three million resume-to-job comparisons. They tested three open-source models from Mistral AI, Salesforce, and Contextual AI. The work was funded by the US National Institute of Standards and Technology.

What they found:

Two details from that work change what you should do on Monday. Bias got worse when resumes were shorter, which makes sense: strip out the substance and the demographic signal in a name carries more of the weight. And stripping names out doesn't solve it, because school names, word choice, and formatting still carry the signal. The blind-CV fix that works for human reviewers doesn't transfer cleanly to a model.

Now, a fair caveat. These were general-purpose open-source models used for resume ranking, not necessarily the audited commercial products an enterprise HR team buys. A vendor could reasonably say their system is tuned differently, and some are. But that's exactly the claim your bias audit is supposed to test, and it's why the vendor questions further down matter more than the brochure. If a general model behaves like this at three million comparisons, "we use AI to rank candidates" is not a neutral statement about efficiency.

The uncomfortable version: a tool like this doesn't feel biased in use. You get a ranked list, the top candidates look strong, and nothing in your workflow surfaces the people it pushed down. The bias is real, measurable at scale, and completely invisible from the seat you're sitting in.

Does any of this cover disability discrimination?

Yes, and it is a separate legal track from everything in the section above. The bias research and the EEOC guidance already covered here run mostly on race and sex under Title VII. Disability sits under the Americans with Disabilities Act instead, with its own obligations, and a screening tool can be clean on one and expose you badly on the other.

The Justice Department published guidance on this titled Algorithms, Artificial Intelligence, and Disability Discrimination in Hiring on 12 May 2022, alongside a companion document from the EEOC. It is short, it is written for employers rather than lawyers, and most HR teams have never read it.

It names three ways these tools go wrong, and the first one is the least obvious. If a tool predicts good hires by comparing applicants against your current staff, it inherits who you already employ, and people with disabilities have historically been excluded from a great many jobs. The pattern the model learns is partly a record of that exclusion. Second, a tool can screen out someone who is perfectly capable of doing the job. Third, and this is the one that catches video and game-based assessments, a test can end up measuring impaired sensory, manual or speaking skills rather than whether the person can actually do the work.

The tools DOJ specifically names are worth reading against your own stack: online video interviews, computer-based skill tests, facial and voice analysis, interactive games and personality assessments, resume-scoring algorithms, and even targeted placement of job adverts. If you run a gamified assessment or an automated video interview, you are squarely in that list.

Then there is the part that creates work rather than just risk. You are expected to tell applicants what technology is being used and how they will be evaluated, offer an accessible alternative version, and have a clear route for requesting an accommodation, with the request itself not counting against them. The standard for refusing is undue hardship, which is a high bar and not the same as inconvenient.

Read that list again and notice what it implies about the buying decision. Half of it is not something you can bolt on after procurement. If a vendor cannot supply an accessible alternative to their video assessment, no policy you write afterwards fixes that, and the vendor checklist further down is the right place to ask. The question to put to them is not whether the tool is unbiased. It is what the accessible version looks like and who has tested it.

One practical note that costs nothing. The accommodation route only works if candidates know it exists, which means saying so in the invitation rather than burying it. A line explaining what the assessment involves and how to ask for an adjustment does more for your exposure here than most of the audit paperwork, and it is the single cheapest thing on this page.

Is hiring the only high-risk use, or does this cover performance too?

It covers performance too, and that's the part most HR teams have missed. Everything above is about getting people in the door. The rules don't stop there, and neither does the exposure.

Go and read the actual text. Annex III point 4 of the EU AI Act has two limbs, not one. Point 4(a) is the recruitment limb everyone quotes. Point 4(b), published on the Commission's own AI Act Service Desk, covers AI systems used "to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships."

Read that list again slowly. Promotion. Termination. Task allocation. Performance monitoring. Same high-risk tier as your CV screener, same obligations, same deadline. A company can run a careful, audited, well-documented hiring process and then have a manager quietly paste a team's performance notes into a chatbot to decide who goes in a restructure.

And that's not hypothetical. ResumeBuilder.com commissioned a Pollfish survey of 1,342 US full-time managers with direct reports, fielded from 24 June 2025. Of the 65 percent using AI at work, 94 percent said they used it for decisions about their direct reports.

What managers used AI forShare of AI-using managers
Employee development plans94%
Assessing performance91%
Writing performance improvement plans88%
Determining raises78%
Promotions77%
Layoffs66%
Terminations64%

Two more numbers from the same survey land harder than any of those. Only 32 percent of managers using AI to manage people had received formal training on doing it ethically, with 43 percent getting informal guidance and 24 percent getting nothing at all. And 5 percent said they let AI make the call all the time, with another 16 percent saying often.

The tools were exactly what you'd guess: ChatGPT at 53 percent, Microsoft Copilot at 29, Google Gemini at 16. Consumer chat tools, used on named employees, for decisions that end careers.

Why this is worse than a bad screening tool

A screening vendor at least leaves you a trail. There's a contract, a bias audit you can demand, logs, a version history. Shadow use in performance management leaves none of that.

So when someone brings a claim about a promotion or a dismissal, you can't show how the decision was made. You can't show what the model was told, whether protected characteristics leaked in through the free text a manager pasted, or whether the same prompt would have produced a different answer an hour later. Under US law this is not a new category of risk either. Title VII covers promotion, pay, and termination the same way it covers hiring, and the EEOC guidance cited earlier is about selection procedures generally, not job applicants only.

There's also a data protection problem sitting underneath. A manager pasting performance notes into a consumer chatbot is processing employee personal data through a system nobody assessed, with no lawful basis recorded and no retention policy. That's a separate breach from anything in the AI Act, and it's the one most likely to surface first.

What to actually do about it

One honest limit on that survey. It's a commissioned online poll of self-reporting managers, not audited HR records, so treat the exact percentages as directional. But even discounted heavily, the shape holds, and it matches what the regulation clearly anticipated.

Are you already regulated, whatever the AI Act says?

Almost certainly yes. And this is the part HR teams miss while they're busy diarising 2026 and 2027 deadlines.

If you process personal data of people in the EU or UK, Article 22 of the GDPR has applied to you since 2018. It gives a person the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them. Rejecting someone for a job clears that bar comfortably. So does an automated performance rating that drives pay or promotion.

Which means the compliance question isn't only what's coming. It's what you've been doing for the last several years without checking.

The "we have a human in the loop" defence is weaker than most teams think. Nearly everyone says it. Far fewer can evidence it. Spain's data protection authority, the AEPD, has set out what actually counts as human intervention, and it's four things, all of which have to be true at once.

Run your own process against that list honestly. If a recruiter clears 400 algorithmically ranked candidates in an afternoon, they are not exercising meaningful review, and the regulator's position is that a token gesture doesn't take you outside Article 22. That isn't a technicality. It's the whole test.

And your vendor may be in scope alongside you. This is the development most HR teams haven't caught up with.

In SCHUFA Holding (Scoring), Case C-634/21, decided 7 December 2023, the Court of Justice of the European Union looked at a credit agency that produced a score and passed it to lenders, who made the formal lending decision. The agency argued it hadn't decided anything. The Court disagreed. It held that generating the probability value is itself automated individual decision-making under Article 22 "where a third party, to which that probability value is transmitted, draws strongly on that probability value to establish, implement or terminate a contractual relationship with that person." You can read the judgment on EUR-Lex under CELEX 62021CJ0634.

Now map that onto hiring. A vendor scores your candidates. You make the formal call. If your recruiters lean heavily on that ranking, and they usually do because that's what you bought it for, the scoring itself can be the regulated decision. Both of you can be in scope, and "the tool only advises us" stops being a shield the moment your behaviour shows otherwise.

The uncomfortable follow-on is that the more useful your screening tool is, the more legal weight it carries. A ranking nobody follows creates no exposure and no value. One that genuinely drives outcomes creates both.

Three things worth doing regardless of what your AI Act timeline says.

None of this replaces the AI Act work. It sits underneath it, it's already live, and it applies to tools you bought years ago.

What does the EU AI Act mean for HR teams?

It means recruitment is in the highest regulated tier short of an outright ban.

The European Commission's AI Act framework sorts systems into four levels: unacceptable risk, high risk, transparency risk, and minimal risk. AI for employment, worker management, and access to self-employment sits in the high-risk category, with CV-sorting software given as the Commission's own worked example.

High-risk classification brings real obligations. Risk assessment and mitigation, high-quality training datasets specifically to minimise discriminatory outcomes, activity logging for traceability, detailed technical documentation, clear information for deployers, human oversight measures, and robustness and cybersecurity standards.

On timing, be careful, because a lot of published advice is out of date. The Commission's current framework page sets 2 December 2027 as the compliance date for high-risk systems in employment and other sensitive areas. Earlier guidance widely quoted 2 August 2026, and that date moved as part of the Digital Omnibus package that deferred the Annex III obligations. That deferral is now settled rather than pending. The Digital Omnibus on AI entered into force across the EU on 27 July 2026, which locked in 2 December 2027 for Annex III high-risk systems, employment included, and 2 August 2028 for high-risk AI built into physical products. So if your compliance plan still runs to an August 2026 deadline for your CV screener, you can move it. Just move it deliberately, and write down why, because the next person to audit that plan will want to know.

But here's the part that gets lost when everyone fixates on the 2027 date, and it's the part most likely to catch you out. Two sets of AI Act duties already bind you today, and neither moved in the omnibus.

Emotion recognition at work is banned outright. Not high risk, not subject to paperwork. Prohibited. The Commission lists emotion recognition in workplaces and education institutions among the unacceptable-risk practices, and those prohibitions took effect in February 2025. That matters because a slice of the interview-tech market sells exactly this: tools that score candidates on facial expression, tone of voice, or inferred enthusiasm and confidence. If a vendor is pitching you sentiment analysis on interview footage for EU roles, the answer isn't a risk assessment. It's no.

Transparency duties went live in August 2026. The Commission's framework page puts the transparency rules at August 2026, and unlike the Annex III timeline they weren't pushed back. For HR that lands in two obvious places. If a chatbot handles candidate screening conversations or answers employee questions, people have to know they're talking to a machine. And AI-generated content needs to be identifiable. So the recruiting chatbot you switched on last year probably needs a disclosure line at the top of the conversation, not in a policy nobody opens.

Put those two next to the 2027 date and the sequencing is the opposite of what most compliance plans assume. The thing you have longest to prepare for is the CV screener. The things that bind you right now are the emotion-analysis tool you might already be piloting and the chatbot that's already talking to candidates.

Do not read the extension as a reprieve. Building auditable hiring processes takes longer than the paperwork suggests, and the anti-discrimination law underneath all of this already applies today regardless of the AI Act timeline.

Do you have to train your own staff on AI?

If you have any EU footprint, yes. And this is the one that lands on your desk rather than legal's, because staff training is your department.

The section above named two AI Act duties that bind you today. There's a third, and it gets skipped in almost every HR briefing: the AI literacy obligation in Article 4.

The wording is short. Providers and deployers "shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in."

Two dates matter here. Per the European Commission, Article 4 entered into application on 2 February 2025, was amended through the Digital Omnibus on AI in mid July 2026, and supervision and enforcement began on 2 August 2026. So unlike your CV screener, which has until December 2027, this one is already live and already being supervised.

Now the part that takes the pressure off. The Commission is explicit that no specific level of literacy is mandated. There's no certification, no minimum hours, no accredited course you're failing to book. The standard is proportionate, which is why the text lists technical knowledge, experience, education, training and context as the things to weigh. A recruiter using a scheduling chatbot and an analyst tuning a scoring model do not need the same session.

So if a vendor is selling you mandatory AI Act certification for every employee, they're overselling a rule that deliberately avoided setting a bar.

What defensible measures actually look like:

There's a practical upside worth naming. Most of the failure cases elsewhere on this page, the unreviewed screener, the employee data pasted into a consumer chatbot, the sentiment tool nobody flagged as prohibited, are literacy failures before they're compliance failures. Someone didn't know what the tool was doing. Training your team is the cheapest control you have, and it happens to be the one the regulation asks for.

If you're deciding which tools your team should be trained on in the first place, our best AI for small business guide covers the general-purpose options in more depth.

Do you have to tell staff before you switch it on?

Yes. And in some countries telling them isn't enough, because they can stop you.

This is the obligation that catches HR teams who have done everything else right. You can have your risk classification correct, your vendor documentation in order and your bias audit booked, and still be unable to deploy, because you skipped a step that has nothing to do with the tool itself.

Start with the Act. Article 26 sets out what deployers have to do, and paragraph 7 is the one aimed squarely at employers. The European Commission's AI Act Service Desk puts it like this: "Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system."

Read that carefully, because it's narrower than people assume in one direction and broader in another. It's an information duty, not a consent requirement. The Act itself doesn't give your staff a veto. But it does mean the first time your candidates or employees hear about the system cannot be when it's already running.

Now the part the Act leaves to national law, which is where the real teeth are.

Germany is the sharpest example. Section 87(1) no. 6 of the Works Constitution Act, published by the Federal Ministry of Justice at gesetze-im-internet.de, gives the works council co-determination over the introduction and use of technical devices intended to monitor the behaviour or performance of employees. Co-determination is a much stronger word than consultation. It means you can't introduce the system unilaterally, and measures taken without properly involving the works council can be unenforceable.

Two things about that provision surprise people:

Germany is the strongest case rather than the only one. The Netherlands, France and Austria all have works council structures with their own information and consent thresholds, and the Act's own wording defers to "Union and national law and practice", which is a polite way of saying your obligations vary by where your people sit rather than where your headquarters does. The extraterritorial point in the FAQ below applies here too: if you employ people in the EU, this reaches you.

The practical consequence is a project-planning one rather than a paperwork one. Consultation is a gate in front of deployment, not a comms task you slot in after go-live. If your rollout plan has the works council conversation in the same week as launch, the plan is wrong, and finding that out late is how a procured and paid-for system ends up sitting unused.

So build it in early. Tell workers' representatives what the system does, what it can evaluate, and what happens to the output, before the contract rather than after. That is roughly what the Act asks of you anyway, and it is a much cheaper conversation to have while you still have the option of choosing a different vendor.

Do US rules already apply to your hiring tools?

Yes, and unlike the EU timeline, these are live right now.

New York City. Local Law 144 of 2021 covers automated employment decision tools. Per the Department of Consumer and Worker Protection, you cannot use an AEDT unless it has had a bias audit by an independent auditor within the past year, the audit results are publicly available, and candidates or employees resident in the city have been notified about the tool and the qualifications it assesses. The law took effect 1 January 2023 and DCWP enforcement began 5 July 2023.

Now the part that changed recently, and it cuts against how most people have been treating this law. If your read was that Local Law 144 is on the books but nobody's really checking, you were right until about a year ago. That's ending.

The New York State Comptroller published an audit of DCWP's enforcement on 2 December 2025, covering July 2023 through June 2025. It concluded enforcement was ineffective, and the specifics are worth reading:

Read the direction of travel rather than the past scorecard. DCWP agreed to implement most of the recommendations, including better complaint routing, staff training, written handling policies, and enforcement that includes interviewing vendors and asking for tool demonstrations. Penalties run $500 to $1,500 per day for ongoing violations.

So the practical position flipped. An employer who quietly skipped the audit had a decent chance of never hearing about it through 2024. Going into 2026, the agency has been publicly told it's failing and has committed to fixing it. That's usually when enforcement activity picks up, and a two-year record of non-compliance is sitting there waiting to be looked at.

Federally, the EEOC, with an important caveat. In May 2023 the EEOC published technical assistance on assessing adverse impact in software, algorithms, and AI used in employment selection under Title VII. It set out two things worth memorising.

First, employers bear ultimate legal responsibility for hiring decisions, including decisions made or informed by a vendor's automated system. Buying the tool does not move the liability to the seller.

Second, the four-fifths rule is not a safe harbour. The Uniform Guidelines treat a selection rate below 80 percent of the highest group's rate as a signal of substantially different selection. But the guidance stated plainly that compliance with the four-fifths rule does not guarantee a procedure will escape a disparate impact finding. So when a vendor's brochure says "passes the 4/5ths rule," that is a marketing claim, not a legal shield.

Status update: that guidance is no longer on the EEOC site

Following executive action under the new administration, the EEOC removed its AI-related technical assistance documents on 27 January 2025. If you have the old link bookmarked, expect it to fail.

Read what that does and doesn't change. The technical assistance was non-binding. It explained how existing law applies rather than creating new duties. Title VII, the ADEA, and the ADA are statutes and they haven't moved. Disparate impact liability for a discriminatory screening tool still lands on the employer. What you've lost is the federal government's published explanation of how it assesses that, not the underlying exposure.

Put those together and the practical conclusion is uncomfortable but simple. If a tool you bought screens someone out unlawfully, it is your problem, and the vendor's compliance certificate will not save you. The federal guidance being pulled makes that harder to evidence, not safer to ignore.

And this isn't hypothetical. The EEOC has already brought and settled a case exactly like this.

In EEOC v. iTutorGroup, the agency alleged the company's recruitment software was programmed to automatically reject female applicants aged 55 and over and male applicants aged 60 and over. More than 200 qualified applicants were turned down on that basis. iTutorGroup settled in August 2023 under a five-year consent decree, agreeing to pay $365,000, adopt anti-discrimination policies and training, invite the rejected applicants to reapply, and stop asking candidates for their date of birth. The EEOC published the outcome as "iTutorGroup to Pay $365,000 to Settle EEOC Discriminatory Hiring Suit", and it's widely described as the agency's first AI-related hiring discrimination settlement.

Here's the detail worth dwelling on, because it changes who should be worried. What iTutorGroup ran wasn't a neural network or a machine-learning ranker. It was a rule in a piece of software: reject applicants over this age. That's it. No model, no training data, nothing anyone would demo at a conference.

Which tells you the exposure doesn't start when you buy something branded as AI. It starts when software makes or shapes a decision about a person, and that's exactly how California's ADS definition and Illinois's HB 3773 are written too. If you've been assuming these rules only apply once you adopt something sophisticated, the first enforced case in this space was a filter that a competent developer could write in an afternoon.

Which US state laws should you be tracking?

This is where the action moved after the federal guidance came down, and it's now a patchwork rather than a single rule. Four matter most if you hire in the US, and they don't all pull the same direction.

California, live since 1 October 2025. The Civil Rights Council's regulations on automated decision systems under the Fair Employment and Housing Act are in force. An ADS is defined broadly as any computational process that makes or assists an employment decision, which catches resume screeners, targeted job ads, assessments, and interview analytics. Two provisions deserve your attention: employers must retain ADS-related data for four years, and you remain responsible for discriminatory outcomes even when the tool came from a third-party vendor. The regulations also treat anti-bias testing, and its quality, recency, and scope, as relevant evidence supporting a defence. So testing isn't just risk reduction, it's the thing you'd point at in a dispute. The California Civil Rights Council publishes the final text.

Illinois, live since 1 January 2026. HB 3773 amends the Illinois Human Rights Act. Using AI in a way that has the effect of discriminating on a protected characteristic is a civil rights violation, across recruitment, hiring, promotion, training selection, discipline, and discharge. It also specifically bars using zip code as a proxy for race in predictive analytics, which is the single most common way a screening model launders a protected characteristic. Employers must notify applicants and employees when AI is used in these decisions.

Colorado, rewritten from scratch. This one moved more than anywhere else, so ignore any checklist built on the old law. The Colorado AI Act, SB 24-205, was set for 1 February 2026, then pushed to 30 June 2026 by SB 25B-004. It never took effect. Governor Polis signed SB 26-189 on 14 May 2026, which repeals and reenacts the whole thing under a new name, automated decision-making technology, with the substantive duties running from 1 January 2027.

The rewrite matters because it points the opposite way from California and Illinois. Gone are the duty of care, the risk management programme, and the algorithmic impact assessments that made the original law the strictest in the country. What replaces them is lighter and mostly about telling people what happened: notice when an automated system is involved in a consequential decision, a plain-language explanation within 30 days of an adverse outcome, a right to correct wrong personal data, and a right to ask for meaningful human review. Enforcement sits with the Attorney General under the Consumer Protection Act, with rules due by 1 January 2027.

So if you spent 2025 building a Colorado impact-assessment process, that work isn't wasted, it's just no longer required there. The disclosure duties are the ones to build for now.

Texas, live since 1 January 2026. The Texas Responsible Artificial Intelligence Governance Act, HB 149, was signed by Governor Abbott on 22 June 2025 and took effect on 1 January 2026. Most write-ups file it under "another state AI law." It isn't. It runs on a different theory from the other three, and if you hire in Texas you need to know which one you're being judged against.

The operative difference is intent. TRAIGA bars developing or deploying an AI system with the intent to unlawfully discriminate against a protected class. Then it says the quiet part out loud. Section 552.056(c) of the enrolled text reads: "For purposes of this section, a disparate impact is not sufficient by itself to demonstrate an intent to discriminate."

Read that against Illinois, where a tool that has the effect of discriminating is a civil rights violation full stop. Same screening tool, same skewed output, two states, opposite answers. Texas also skips the machinery the other laws lean on. No mandated bias audit, no impact assessment, no applicant notice. Enforcement sits only with the Attorney General, there's no private right of action, and Section 552.104 gives you written notice plus 60 days to cure before the AG can file. The complaint mechanism has to be running by 1 September 2026.

So there's no single pattern to design for any more, and anyone telling you there is hasn't read Texas. What you get instead is a spread. California and Illinois judge you on outcomes, Colorado is moving to disclosure, and Texas judges you on intent and says outcomes alone don't count.

That sounds like it complicates your job. It mostly doesn't, because the spread is one-directional. Build for the strictest rule you're exposed to and you clear the rest by default: an employer running California's four-year retention, Illinois-style notice, and regular bias testing is comfortably inside what Texas asks, which is close to nothing. It does not work in reverse. A programme built to the Texas standard leaves you exposed everywhere else, so don't let a Texas-first vendor tell you a bias audit is optional if you also hire in Chicago or Los Angeles.

The other thing worth keeping in view: broad definitions still catch tools you don't think of as AI, and in the outcome-based states employer liability survives outsourcing. Buying the tool from a vendor doesn't move the risk off your books.

Which Asia-Pacific rules should you be tracking?

Three very different models, and the binding one names hiring explicitly. If you employ anyone in the region, this is the section most HR teams have not looked at yet.

South Korea is the one with teeth. The Framework Act on the Development of Artificial Intelligence and Establishment of Trust passed on 21 January 2025 and took effect on 22 January 2026, according to the Center for Security and Emerging Technology at Georgetown.

It defines a high-impact AI category for systems that substantially affect life, safety or fundamental rights, and the listed sectors include employment and loan assessments alongside healthcare, energy and nuclear facilities. Employment decisions are named, not inferred.

That should sound familiar. It's the same structural move the EU AI Act makes, covered further up this page, and it lands on the same tools: résumé screening, candidate ranking, skills assessment, performance scoring.

Japan went the opposite way. The Act on the Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technologies was adopted on 28 May 2025. As OECD.AI records it, this is a fundamental law setting policy direction rather than compliance rules. It contains no detailed compliance obligations and no penalties. Businesses are expected to align with government principles, and that expectation is not enforced with fines.

Singapore sits between them, voluntarily. IMDA and the PDPC issued the Model AI Governance Framework, first published in 2019 with a second edition in 2020. It's guidance rather than law, built around internal governance structures, human oversight, risk management proportionate to the use case, and transparency with the people affected.

Voluntary is doing real work in that sentence. Nobody fines you for ignoring it. But it's the reference point a regulator, a tribunal or a large client will reach for when asking whether you behaved reasonably, which makes it worth following even though nothing compels you to.

Now the part that actually bites for a multinational team.

One screening tool, deployed once, can sit in three regimes at the same time. Unregulated for your Tokyo hires. Voluntary-guidance territory in Singapore. A high-impact system needing risk management for the Seoul role. Same vendor, same model, same configuration.

And as with the EU, it's generally the location of the role and the candidate that determines what applies, not where your headquarters or your vendor sits. A tool built in California and hosted in Virginia still meets Korean law when you point it at a Korean vacancy.

So, practically:

If you're hiring across the region more broadly, our guide on AI tools for Southeast Asian users covers the practical tooling side, including which services are actually available where.

How do you check an AI hiring tool before you buy?

Ask these before signing, and get the answers in writing rather than on a call.

  1. Show me the bias audit. Not a summary, the actual report, with the date and the auditor's name. If the most recent one is over a year old, it does not meet the NYC standard.
  2. Who audited it? The auditor must be independent. A study run by the vendor's own data team is not an independent audit.
  3. What does the model actually use as inputs? If they will not tell you, you cannot assess proxy discrimination, and you cannot explain the decision to a candidate who asks.
  4. Where does human oversight sit? A human rubber-stamping a ranked list is not oversight. You need a documented point where a person can and does override the output.
  5. What happens to candidate data? Where is it stored, for how long, and is it used to train the vendor's models.
  6. Will you indemnify us? Ask directly. The answer tells you how confident they actually are, and most decline.

If a vendor gets defensive at question one, that is your answer. Good vendors have these documents ready because serious buyers keep asking.

Should you screen out AI-written applications?

No. And if you're already doing it, this is probably the largest piece of undisclosed legal exposure in your hiring process, because it's the one nobody has classified as an AI tool yet.

Start with why the temptation is real, because it is. Robert Half surveyed US HR leaders and published the results on 10 March 2026. Two thirds of them, 67 percent, said reviewing AI-generated applications had slowed their hiring process, with 20 percent reporting delays of more than two weeks. 84 percent of HR teams reported feeling overworked because of the extra review time, and 65 percent of hiring managers said the surge made it harder to verify what a candidate could actually do.

So the pitch writes itself. Run applications through an AI detector, drop the ones that come back flagged, and get your afternoon back. Several vendors will sell you exactly that.

Here's what the detector is actually measuring.

Liang, Yuksekgonul, Mao, Wu and Zou at Stanford tested seven commercial GPT detectors and published in Patterns (2023, vol. 4, article 100779), a peer-reviewed Cell Press journal. They ran the detectors over two sets of writing that were both entirely human: 91 TOEFL essays by non-native English speakers, and 88 essays by US eighth-graders.

The US students came through more or less clean. The non-native writers did not:

The mechanism is perplexity. These tools flag text that is predictable and uses a narrow range of expression, and that describes second-language English writing precisely. The detector is not identifying AI. It is identifying people who learned English as a second language.

The researchers then did something that settles the question. They took the same human-written essays and used ChatGPT to make the word choice sound more native. False positives fell from 61.22 percent to 11.77 percent. Running human writing through an AI made it look more human to the detectors.

Now put that next to everything earlier in this article, because the legal conclusion follows directly and most HR teams haven't drawn it yet.

A detector that decides which applications a recruiter sees is a computational process that assists an employment decision. That is close to a verbatim match for California's ADS definition, which is deliberately broad and already live. Illinois HB 3773 catches it on the same logic, and adds a notification duty. And the practice has a documented, peer-reviewed, measurable disparate impact on people who learned English as a second language, which correlates tightly with national origin, a protected characteristic under Title VII.

Three points from earlier sections land on this at once:

There's also a plain evidentiary problem. If a rejected candidate asks why, and the honest answer is that a tool scored their writing as machine-generated, you have no way to demonstrate the tool was right. The 97.8 percent figure means that with enough detectors in the stack, a flag on a non-native speaker's application is close to expected regardless of who wrote it.

What to do instead, given the workload pressure is genuine:

  1. Say what you allow, in the posting. Most employers now assume AI assistance and don't mind it. Writing that down removes the guessing game for candidates and the detective work for you.
  2. Assess the thing you actually care about. A short structured task or a live conversation tests whether someone can do the job. A polished cover letter never did.
  3. Ask candidates to talk through their own claims. This is what the Robert Half respondents said was actually hard, and a fifteen minute conversation resolves it in a way no detector can.
  4. If a detector is already in your stack, treat it as an AEDT. That means the audit, the notice, and the record retention this article covers. Or remove it, which is simpler and is what we'd suggest.

Worth saying plainly: an AI detector is the only tool in this article with a documented false positive rate above 60 percent against a protected group, and it's also the one most likely to be running in a hiring process today without anyone having classified it as AI at all.

Is the candidate on your video call actually real?

Usually. But "usually" is doing more work than it used to, and this is the hiring risk that flips the rest of this article on its head. Everything above is about your AI treating real candidates unfairly. This one is about candidates using AI to be someone they aren't.

The FBI flagged it early. In a June 2022 public service announcement, its Internet Crime Complaint Center warned of deepfakes and stolen personal data being used to apply for remote jobs, mostly in IT, programming and database roles with access to customer data, financial systems or proprietary information. The giveaway it described is oddly specific: lip movements that don't quite match the audio, and coughs or sneezes that aren't lined up with what's on screen. Some applicants were only caught when the background check came back belonging to someone else entirely.

That was 2022. The tools have got much better since, and the fraud has scaled up with them. On 30 June 2025 the US Department of Justice announced coordinated actions against North Korean remote IT worker schemes, including searches of 29 known or suspected "laptop farms" across 16 states. The workers had used stolen and fake identities to get hired at more than 100 US companies, many of them in the Fortune 500. These weren't sloppy applications that slipped through. They passed interviews, got laptops shipped out, and drew salaries.

And it isn't only state-backed operations. Gartner surveyed 3,000 job candidates in the second quarter of 2025, and 6 percent admitted to interview fraud, either posing as someone else or having someone else pose as them. Its forecast, published on 31 July 2025, is that by 2028 one in four candidate profiles worldwide will be fake. Treat that as a forecast, not a measurement. But the direction isn't in doubt.

Why don't the usual checks catch it?

Because most hiring processes were built to judge ability, not identity. A CV screen, two video rounds and a take-home task tell you whether someone can do the job. None of them tell you whether the person who did the take-home is the person who'll turn up on day one, or whether the face on the call is a face at all.

Remote hiring removed the one step that used to do this for free, which was someone walking into your office. And the free AI tools this article recommends for writing job descriptions will write a flawless CV and cover letter for anyone, in any voice, in seconds. That's also why the AI detector route doesn't help here. Polished writing isn't the signal. A real applicant using ChatGPT on their cover letter and a fake one look the same on paper.

How do you verify identity without creating a new problem?

Move the check to where it matters, and keep it proportionate. A few things that actually work:

If you buy an identity verification tool that matches faces, check what it actually does before it goes live. Under the EU AI Act, Annex III lists remote biometric identification as high risk, but it expressly excludes systems whose sole purpose is to confirm that a person is who they claim to be. A one-to-one check against the ID a candidate gave you sits on the right side of that line. A tool that also scores "engagement" or reads facial expressions for stress drifts into emotion recognition, which is banned at work outright, as the EU AI Act section covers. Vendors bundle these features together more often than you'd think.

And remember the people you're protecting. Most candidates are exactly who they say they are. Build the check so an honest applicant barely notices it, rather than treating every remote hire like a suspect. You're fixing an identity problem, not a trust problem.

Can you paste employee data into ChatGPT?

Usually not, and this is the everyday risk that catches HR teams far more often than the recruitment rules do.

Employee records are personal data under GDPR, Singapore's PDPA, and most equivalent regimes. Pasting a grievance file or a performance record into a consumer chatbot is a disclosure to a third party, and your employees did not consent to it. That holds even when the tool is genuinely good and your intentions are fine.

Three workable positions:

The realistic failure here is not malice. It's a stretched HR manager at 6pm pasting a whole case file in to get a summary. Worth a five-minute team conversation before it happens.

What else do people ask about AI in HR?

Is it legal to use AI to screen job applicants?

Yes, but it is regulated, and the rules bite before you notice. In New York City, Local Law 144 has required an independent bias audit of automated employment decision tools since enforcement began on 5 July 2023, plus published results and candidate notice. In the EU, recruitment AI is classified high risk under the AI Act. Enforcement in NYC was weak until recently, but a New York State Comptroller audit in December 2025 found it ineffective and the city has committed to tightening it. Screening is legal, unaudited screening often is not.

Does the EU AI Act apply if my company is outside the EU?

It can. The Act reaches providers and deployers whose AI output is used in the EU, so hiring for an EU-based role or assessing EU-based candidates can pull you in even from Singapore or the US. If you never recruit into the EU it is unlikely to apply directly, though clients and parent companies increasingly push the same requirements down the chain anyway.

Can AI write job descriptions without bias problems?

Mostly yes, and this is one of the safest HR uses. A job description is not a selection decision, so it sits outside the high-risk category. AI is genuinely useful for flagging coded language and unnecessary requirements that narrow your applicant pool. Read the output before posting, since models still produce inflated requirement lists that quietly screen people out.

Who is liable if an AI hiring tool discriminates?

You are, in most cases. The EEOC's May 2023 guidance said employers bear ultimate legal responsibility for hiring decisions, including ones made or informed by a vendor's system, and that passing the four-fifths rule is not a defence. That guidance was removed from the EEOC site in January 2025, but it was non-binding and only explained existing law. Title VII, the ADEA, and the ADA still apply, and California's FEHA regulations spell out third-party vendor liability explicitly. Buying a tool does not transfer the exposure.

Which free AI tool is best for general HR work?

Claude for anything long or sensitive in tone, like policy drafts, investigation summaries, and difficult employee communications. Gemini if your team already runs on Google Workspace, since the integration saves more time than any model quality difference. Both have workable free tiers. Neither should touch identifiable employee data unless your organisation has approved that specific tool.

If you want the tool-by-tool breakdown without the compliance angle, our sister site covers free AI tools for HR teams. For general business use, our best AI for small business guide and best AI for writing guide cover the same models from a different angle.

Sources: FBI Internet Crime Complaint Center, "Deepfakes and Stolen PII Utilized to Apply for Remote Work Positions" (PSA, 28 June 2022), for the targeted roles, the audio and lip mismatch and the background check discovery. US Department of Justice, "Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote Information Technology Workers' Illicit Revenue Generation Schemes" (30 June 2025), for the 29 laptop farms across 16 states and the more than 100 US companies. Gartner, press release of 31 July 2025, for the 6 percent interview fraud figure from a 2Q25 survey of 3,000 candidates and the one-in-four-by-2028 prediction. European Commission AI Act Service Desk, Annex III point 1(a), for the biometric verification exclusion. Wilson, K. and Caliskan, A., "Gender, Race, and Intersectional Bias in Resume Screening via Language Model Retrieval," Proceedings of the AAAI/ACM Conference on AI, Ethics and Society (AIES 2024), presented 22 October 2024, University of Washington Information School, funded by the US National Institute of Standards and Technology, reported by UW News, for the 550 resumes, 500 job listings, 120 name variations, three million comparisons and the 85, 9, 52, 11, 67 and 15 percent preference figures. European Commission, Regulatory framework for AI, for the risk tiers, high-risk employment classification, obligations, the 2 December 2027 compliance date, the prohibition on emotion recognition in workplaces effective February 2025, and the transparency rules effective August 2026. New York City Department of Consumer and Worker Protection, Automated Employment Decision Tools, for Local Law 144 bias audit and notice requirements, effective 1 January 2023 with enforcement from 5 July 2023. Office of the New York State Comptroller, "Enforcement of Local Law 144, Automated Employment Decision Tools", issued 2 December 2025 covering July 2023 to June 2025, for the ineffective enforcement finding, the 75 percent 311 misrouting rate, the 32 bias audits reviewed with 1 issue found by DCWP against at least 17 found by the Comptroller, and DCWP's commitment to the recommendations. US Equal Employment Opportunity Commission, "Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII", May 2023, for employer liability and the four-fifths rule. That document was removed from the EEOC website on 27 January 2025 following executive action; it was non-binding guidance and the underlying Title VII, ADEA and ADA obligations are unaffected. US Equal Employment Opportunity Commission, "iTutorGroup to Pay $365,000 to Settle EEOC Discriminatory Hiring Suit", August 2023, for the ADEA claim, the automatic rejection of female applicants aged 55 and over and male applicants aged 60 and over, the more than 200 affected applicants, the $365,000 payment and the five-year consent decree terms including the reapplication invitation and the bar on requesting dates of birth. California Civil Rights Council, FEHA automated decision system regulations effective 1 October 2025, for the ADS definition, four-year record retention and third-party vendor liability. Illinois General Assembly, HB 3773, effective 1 January 2026, for the Human Rights Act amendment and the zip code proxy provision. Texas Legislature Online, HB 149, the Texas Responsible Artificial Intelligence Governance Act, signed 22 June 2025 and effective 1 January 2026, for the intent standard, the Section 552.056(c) disparate impact clause, Attorney General exclusive enforcement, the 60-day cure period under Section 552.104, and the 1 September 2026 complaint mechanism deadline. Colorado General Assembly, SB 25B-004, signed 28 August 2025, extending the SB 24-205 effective date to 30 June 2026, and SB 26-189 "Automated Decision-Making Technology," signed 14 May 2026, which repealed and reenacted SB 24-205 before it took effect, with developer and deployer duties and Attorney General rulemaking running to 1 January 2027, for the notice, post-adverse-outcome explanation, correction and human review obligations replacing the original duty of care, risk management and impact assessment regime. SHRM, "The State of AI in HR 2026 Report", based on a survey of 1,908 HR professionals fielded 5 to 23 December 2025, for the 39 percent adoption figure, the 7 percent intending to launch, the 54 percent with no adoption and no plans, the function-level breakdown covering recruiting at 27 percent through compliance at 2 percent or less, and the 87, 75, 70, 77 and 73 percent outcome figures. Liang, W., Yuksekgonul, M., Mao, Y., Wu, E. and Zou, J. (2023), "GPT detectors are biased against non-native English writers," Patterns 4, article 100779, a peer-reviewed Cell Press journal, for the seven detectors tested across 91 TOEFL essays and 88 US eighth-grade essays, the 61.3 percent average false positive rate on non-native writing, the 19.8 percent unanimous and 97.8 percent at-least-one flag rates, and the drop to 11.77 percent after word choice was enhanced. Robert Half, "67% of HR leaders report AI-generated applications are slowing hiring", published 10 March 2026, for the 67 percent slowdown figure, the 20 percent reporting delays over two weeks, the 84 percent overworked figure and the 65 percent skills-verification figure. This article is general information, not legal advice. Regulatory dates move, so confirm against the primary sources before building a compliance plan.