You've heard about automated employment decision tools coming under state regulation. Your legal team sent a summary. Your vendor reassured you. Amid this, you've likely absorbed several dangerous assumptions about what compliance actually requires.
These myths persist because the regulatory landscape for automated decision-making technology in employment is complex. Five states have distinct frameworks taking effect by January 2027, each with different definitions, triggers, and obligations. Compliance officers often try to match these requirements to familiar privacy frameworks, filling gaps with guesses. Those guesses become organizational assumptions, leading to compliance failures.
Here's what you need to know.
Myth 1: "We're fine as long as a human makes the final decision"
Reality: Human involvement doesn't exempt you from ADMT obligations. Several states explicitly reject the "human-in-the-loop" defense.
Connecticut's CART Act defines automated employment-related decision technology as any system whose output is a "substantial factor" in employment decisions. This includes constraints, rankings, scores, or other factors that meaningfully alter an employment outcome. If your hiring manager reviews the top five candidates an algorithm ranked, that ranking is a substantial factor, even if the manager makes the final choice.
California's regulations require pre-use notice and risk assessments when ADMT is used for "significant decisions," regardless of human review. Colorado's SB 26-189 applies when ADMT "materially influences" a consequential decision, defined as a non-de minimis factor affecting the outcome, including by ranking or recommending.
Connecticut's CART Act explicitly amends the Connecticut Fair Employment Practices Act to clarify that using automated employment-related decision technology is not a defense against a discrimination claim. Human review doesn't insulate you from liability.
Myth 2: "These laws only apply to hiring algorithms"
Reality: The scope extends across the employment lifecycle, and some states regulate decisions you might not consider "consequential."
Illinois HB 3773 requires notice when AI is used in recruitment, hiring, promotion, selection for training, and discharge. Colorado's definition of consequential decisions includes any decision that creates or may create an employer-employee relationship. California covers hiring, work allocation, compensation, and termination decisions.
That "allocation of work" language matters. If you use automated scheduling tools that assign shifts based on performance metrics, availability algorithms, or demand forecasting, you're making decisions about who gets hours and income. If your system routes customer service tickets to agents based on skill scores, that's work allocation. These are common scenarios that trigger disclosure obligations.
Delaware's HB 380, if enacted, would narrow the employment exemption in the Delaware Personal Data Privacy Act when employee or contractor data is disclosed to third parties as part of a report connected to a decision producing legal or similarly significant effects. This includes performance management platforms, background check services, and workforce analytics vendors.
Myth 3: "Compliance is just about sending a notice"
Reality: Notice is just the beginning. The harder obligations involve risk assessment, documentation retention, and operationalizing appeal rights.
California requires deployers to conduct risk assessments for ADMT used in significant decisions. You need to evaluate the system's potential adverse impacts before deployment, not after a complaint.
Colorado requires deployers to retain compliance records for at least three years after each consequential decision, including ADMT version identifiers, changelogs, and documentation of material mitigation changes. If you make a termination decision on March 15, 2027, you need to preserve which version of the tool you used, what changes were made to the model, and how you addressed identified risks. This requires version control and change management at the individual decision level.
Colorado also requires deployers to provide "commercially reasonable" meaningful human review and reconsideration rights. You need a process for someone to request review, a way to correct inaccurate data, and a mechanism to appeal the decision. "Commercially reasonable" is a judgment call likely to be tested in enforcement actions, but it's not satisfied by a generic HR email inbox.
Myth 4: "We can use the same compliance approach in every state"
Reality: Definitions, triggers, and timelines differ enough that you need state-specific implementation plans.
California's "significant decision" standard focuses on provision or denial of employment opportunities. Colorado's "consequential decision" includes decisions that create legal or similarly significant effects. Connecticut's "substantial factor" test asks whether the output meaningfully alters an outcome. Illinois requires notice for AI use in a broad range of employment decisions without defining a materiality threshold.
The timing requirements differ, too. California requires pre-use notice before ADMT deployment. Colorado requires notice before using the technology and a separate disclosure within 30 days of an adverse outcome. Connecticut requires notice before making employment decisions using AEDT, unless it would be obvious to a reasonable person that they're interacting with the technology.
All three major frameworks take effect on January 1, 2027, meaning you're building parallel compliance programs on the same deadline. You can't template this.
Myth 5: "Our vendor handles compliance"
Reality: You're the deployer, and deployer obligations aren't delegable.
The regulations distinguish between developers (who build ADMT) and deployers (who use it to make employment decisions). You're the deployer. You're responsible for notice, risk assessment, documentation, and appeal processes, even if your vendor built the algorithm.
Delaware's HB 380 would require deployers to include contractual terms with third parties to provide notice and human review opportunities. This is a procurement requirement, not just a vendor assurance. You need to audit what your contracts actually say about compliance responsibilities.
Connecticut requires deployers to disclose the trade name of the AEDT, the categories of personal data analyzed, how it will be assessed, and the sources of that data. If your vendor considers that information proprietary, you have a contract problem, not a compliance solution.
What to do instead
Start with an inventory of automated tools used in any employment decision: applicant tracking systems, resume screening tools, scheduling software, performance dashboards, promotion ranking models, and termination risk scores. For each tool, identify which states' definitions it triggers.
Map your current notice practices against each state's requirements. California wants pre-use notice. Colorado wants pre-use notice plus post-decision disclosure for adverse outcomes. Connecticut wants pre-decision notice with specific content elements. You need different templates.
Build documentation workflows that capture what Colorado requires: version identifiers, changelogs, and mitigation documentation tied to individual decisions. If you can't produce that record three years later, you're not compliant.
Design your appeal and human review process before someone requests it. What does "meaningful human review" look like in your organization? Who conducts it? What authority do they have to override the automated output? How do you correct inaccurate data in the source system?
If you're waiting for final regulations before you act, you're already behind. California's rules are final. Colorado published draft regulations in August 2026 with a comment deadline in October. Connecticut's CART Act is law. Illinois paused rulemaking in June 2026, but the statute is in effect. The uncertainty you're waiting to resolve won't resolve before January 1, 2027.
[REFERENCE URLS]





