Does the California AI hiring law apply to you?
A guide for HR and legal teams. About 6 minutes.
If you use software to source, screen, rank, or shortlist candidates, and any of those candidates could be hired in California, the answer is probably yes. California did not pass a standalone AI statute. Instead it folded automated hiring tools into the Fair Employment and Housing Act, the state's core anti-discrimination law, through new regulations that are in force today.
This page is a plain-English check of whether those rules reach you and what to do about it. It is not legal advice, and it does not assume you have a compliance team.
The short answer
You are likely covered if you employ five or more people and a tool, model, or vendor system plays any part in a hiring or other employment decision that affects someone in California. California's Civil Rights Council adopted regulations that make it unlawful to use an automated-decision system in a way that discriminates on a protected basis, and they took effect on 1 October 2025. They run through the existing Fair Employment and Housing Act, so they attach to almost every employer already covered by that law.
Because these rules live inside an existing civil rights framework rather than a separate AI law, there is no new agency and no separate registration. Enforcement runs through the same complaints and investigations the Civil Rights Department already handles.
What counts as an automated-decision system
The regulations define an automated-decision system, or ADS, broadly. It is a computational process that makes a decision or facilitates human decision making about an employment benefit. The definition is explicit that such a system may be derived from or use artificial intelligence, machine learning, algorithms, statistics, or other data-processing techniques.
Read that twice, because the reach is wider than "AI" as most people picture it. A resume-screening filter, a scoring or ranking model, a video-interview analyzer, and a targeted-advertising system that decides who even sees a job can all be automated-decision systems under this definition. The test is not whether the vendor markets it as AI. The test is whether the system contributes to a decision about a person.
What the regulations require
The core rule is a prohibition, not a checklist: it is unlawful to use an automated-decision system in a way that discriminates against an applicant or employee on a basis the Fair Employment and Housing Act protects. That reaches discriminatory effect, not only intent. A tool you did not build, configured the way the vendor shipped it, can put you on the wrong side of the line if its outputs skew against a protected group.
Two practical duties follow from how the regulations are written.
- Keep the records. The regulations extend the standard retention period to automated-decision data. Employers must keep the relevant records, including ADS data and the selection and applicant information tied to it, for at least four years. If you cannot show what a system did and how, you cannot defend how it was used.
- Expect your testing to matter. The regulations treat whether, and how well, you tested a system for bias as relevant to a discrimination claim. Anti-bias testing is not a safe harbor that makes a tool "compliant," but the presence or absence of it, and its quality, can count for or against you.
Vendors do not absorb the duty
One of the most misread parts of these rules is who is on the hook. The regulations define an agent to include those who exercise a function traditionally exercised by the employer, such as recruiting, screening, or hiring, even when they do it through an automated-decision system. An outside vendor that performs those functions on your behalf can be reached directly.
That does not move the duty off you. It means the obligation can attach to both you and the third party running the tool. A vendor telling you their system is fine is not the same as evidence that your use of it was lawful, and it is your use that gets examined. Get the substance in writing and keep it.
What this is not
There is still no single federal AI hiring law, so California sits on top of existing federal anti-discrimination rules, not in place of them. These regulations do not certify any tool as "compliant," and no vendor can hand you that certificate. What the rules reward is the same thing across every jurisdiction writing its own version: knowing where AI touches your decisions, checking for discriminatory effect, and keeping the evidence that you did.
California is one state in a moving patchwork. New York City is enforced today, Illinois came into force in 2026, and other states are drafting their own rules on different timelines. The work that survives the next change is the inventory and the evidence, not any single form.
What to do now
- Map where AI touches hiring. List every tool, vendor, and model that sources, screens, scores, ranks, or analyzes candidates for California roles. You cannot comply with what you have not inventoried.
- Confirm the four-year record trail. For each system, make sure you can retain the automated-decision data and the related selection and applicant records for at least four years, and that you actually keep them.
- Ask your vendors the discrimination question in writing. Request their bias testing, the protected-class effects they measure, and how they document results. Keep the answers, because a vendor assurance is not your defense.
- Treat targeted advertising and sourcing as in scope. A system that decides who sees your job, not only who advances, can be an automated-decision system here. Do not stop the inventory at the screening stage.
- Confirm coverage with counsel if you are unsure. Whether a specific role, applicant, or tool falls under these regulations is a legal question, and the protected-class analysis is where a lawyer earns the fee.
Not sure which of these touches you? The free 2-minute check at signato.ai/quiz sorts it by where you actually hire. When you are ready to build the inventory and the record trail, the Signato toolkit gives you the templates to do it once and reuse them as the patchwork grows.
This page is general information, not legal advice. For how these regulations apply to your specific tools and roles, consult qualified counsel.
The fastest first step is to check your own use against the law, tool by tool. The free two-minute self-assessment shows where your hiring stack stands. No email needed to see your result.
Take the free AI Hiring Risk Self-AssessmentReady to put the diligence on paper? The Signato Compliance Toolkit includes editable templates built on these obligations (US$ 99, one-time).
Running an operation with internal walls, in law, private equity, wealth, or a family office? Signato also builds the information-barrier chamber that verifies every AI output before it leaves, all local. Free 30-day trial.
Track this as it hardens. One brief a week on AI hiring rules, EU and US: each claim traced to the primary source, what is settled, what is still open, what to do next.
Free. No spam. Unsubscribe anytime.
This is educational material and a starting point, not legal advice. Whether a particular tool is covered, and which obligations apply to your organisation, depend on the facts of that tool and on the rules in force where you operate. For your situation, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.
Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.