Skip to content

Menu

Network by SubjectChannelsBlogsHomeAboutContact
AI Legal Journal logo
Subscribe
Search
Close
PublishersBlogsNetwork by SubjectChannels
Subscribe

ADMT Law Roundup: What Employers Need to Know About Recent ADMT Laws

By Lindsey Tonsager, Libbie Canter, Carolyn Rashby, Jayne Ponder & Bryan Ramirez on August 20, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Employers increasingly rely on automated tools to help make decisions concerning hiring, promotion, discipline, and termination. In response, state legislatures and agencies have begun to regulate uses of these technologies, often referred to as automated decision-making technology (“ADMT”). These laws generally require entities that deploy ADMT in the employment context to, among other requirements, notify affected individuals, disclose how ADMT factors into decisions, and provide rights to appeal or request human review.

This remains a fast-moving area and a hot topic for legislative and regulatory focus, with several states enacting laws this year and additional bills pending. Below, we summarize the key legislative and regulatory ADMT developments that apply in the employment context.

California ADMT and Pending Legislation

In 2025, the California Privacy Protection Agency approved regulations governing the use of ADMT for “significant decisions” concerning consumers, including job applicants, employees, and independent contractors. Pursuant to these rules, beginning January 1, 2027, employers that use ADMT for a “significant decision” (a decision resulting in the provision or denial of employment or independent contracting opportunities including hiring, allocation of work, compensation, and termination) must provide pre-use notice, offer individuals the ability to opt out, and conduct a risk assessment, among other requirements, unless an exception applies. For a more detailed discussion of California’s ADMT regulations, see our prior blog post.

Additionally, the California legislature is considering further restrictions. SB 947 (the “No Robo Bosses Act”) would prohibit employers from relying solely on an automated decision system (“ADS”) to make significant decisions and would require an independent human investigation to corroborate any ADS output. SB 951 (the “AI Job Killer Notice Act”) would require covered employers to give affected workers and certain local entities advance notice, potentially up to 90 days, before a layoff attributable to AI or ADMT. Both bills cleared the Senate and are currently being considered in the Assembly. Employers should continue monitoring both bills for any developments.

Colorado SB 26-189

On May 14, 2026, the Colorado governor signed SB 26-189 into law, repealing and replacing Colorado’s original 2024 Artificial Intelligence Act. The revised law, which takes effect on January 1, 2027, pares back the original’s broader “high-risk artificial intelligence system” framework in favor of a narrower approach focused on ADMT used in consequential decisions. The new law regulates ADMT used to “materially influence” “consequential decisions,” including decisions related to employment or employment opportunity that creates or may create an employer-employee relationship. An ADMT output “materially influences” a consequential decision when it is a non-de minimis factor used in making the decision and affects the outcome, including by ranking, recommending, or otherwise meaningfully altering how the consequential decision is made.

Deployers of ADMT must notify individuals before using the technology to make consequential decisions concerning them. Also, within 30 days of a consequential decision that results in an adverse outcome, deployers must provide a plain-language disclosure of the decision and the role ADMT played in making that decision. In addition, deployers must provide instructions for a simple-to-follow process to request information, and an explanation of the individuals’ rights, including the right to correct inaccurate data, appeal the decision, and request meaningful human review and reconsideration, to the extent “commercially reasonable.” Deployers must retain records that demonstrate compliance for at least three years after the date of the consequential decision, including ADMT version identifiers, changelogs, and documentation of material mitigation changes.

On August 11, 2026, the Colorado Department of Law published a Notice of Proposed Rulemaking and draft ADMT regulations, which will further clarify deployer obligations. The Department is receiving written comments through October 26, 2026, and has scheduled a public hearing on the proposed regulations for October 26, 2026.

Connecticut SB 5

On June 2, 2026, the Connecticut governor signed SB 5, the Connecticut Artificial Intelligence Responsibility and Transparency Act (the “CART Act”) into law. The CART Act’s employment-related provisions apply to automated employment-related decision technology (“AEDT”) developed or deployed on or after October 1, 2027. AEDT is defined as technologies whose output is a “substantial factor” in decisions to hire, fire, promote, discipline, renew employment, or select an individual for training. The law defines “substantial factor” as a constraint, ranking, score, or other factor that meaningfully alters an employment-related outcome. Deployers using AEDT must disclose in plain language when employees or job applicants interact with such technology, unless it would otherwise be obvious to a reasonable person. Additionally, before making employment decisions using AEDT, deployers must provide written notice that AEDT has been deployed, the nature of the decision, the purpose and trade name of the AEDT, the categories of personal data analyzed and how it will be assessed, the sources of that data, and the deployer’s contact information. The Act also amends the Connecticut Fair Employment Practices Act to clarify that an employer’s use of AEDT is not a defense against a discrimination claim.

Delaware HB 380

On June 16, 2026, the Delaware General Assembly passed HB 380, which amended the Delaware Personal Data Privacy Act (“DPDPA”). If enacted, the bill would narrow the DPDPA’s employment-related exemption, which among other things would bring employee, applicant, and contractor data within the DPDPA’s scope when disclosed to any third party as part of a report in connection with a decision that produces legal or similarly significant effects concerning the individual. Among other things, employers and other parties would be required to include contractual terms in agreements with third parties, including to provide notice and information that an individual can request human review of an adverse action unless the opportunity for review is not in the “best interest” of the resident. HB 380 is awaiting the Delaware governor’s signature. If signed, the amendments would take effect on January 1, 2027. For a more detailed discussion of the bill’s consumer privacy requirements, see our prior blog post.

Illinois HB 3773 and Status of Rulemaking

Illinois’ HB 3773, which took effect on January 1, 2026, amended the Illinois Human Rights Act to require employers to notify applicants and employees when AI is used in a broad range of employment decisions, including decisions related to recruitment, hiring, promotion, selection for training, and discharge, among others. The law also prohibits the use of zip codes as a proxy for protected classes and confirms that using AI in a manner that discriminates on the basis of a protected class is unlawful. For further discussion of its key provisions, see our prior blog post.

On May 15, 2026, the Illinois Department of Human Rights (“IDHR”) published proposed rules implementing HB 3773, detailing employers’ notice obligations. However, on June 2, 2026, the IDHR announced that it was temporarily withdrawing the proposed rules to allow for continued collaboration with other state agencies. No revised timeline has been announced. Although the rulemaking process has been paused, employers should continue preparing for compliance with HB 3773 and monitor for the reopening of the comment period.

Next Steps

Given the pace of ADMT legislation, employers should inventory the automated tools currently used in hiring, promotion, discipline, termination, and other consequential employment decisions. They should also assess each state’s applicable notice, opt-out, and human review obligations against upcoming effective dates, many of which take effect on January 1, 2027. Employers should also develop policies and processes to ensure that they are satisfying relevant requirements when using AI in the employment context and considering these requirements when onboarding new tools. California employers should also monitor SB 947 and SB 951 for any developments.

Photo of Lindsey Tonsager Lindsey Tonsager

Lindsey Tonsager helps national and multinational clients in a broad range of industries anticipate and effectively evaluate legal and reputational risks under federal and state data privacy and communications laws.

In addition to assisting clients engage strategically with the Federal Trade Commission, the…

Lindsey Tonsager helps national and multinational clients in a broad range of industries anticipate and effectively evaluate legal and reputational risks under federal and state data privacy and communications laws.

In addition to assisting clients engage strategically with the Federal Trade Commission, the U.S. Congress, and other federal and state regulators on a proactive basis, she has experience helping clients respond to informal investigations and enforcement actions, including by self-regulatory bodies such as the Digital Advertising Alliance and Children’s Advertising Review Unit.

Ms. Tonsager’s practice focuses on helping clients launch new products and services that implicate the laws governing the use of endorsements and testimonials in advertising and social media, the collection of personal information from children and students online, behavioral advertising, e-mail marketing, artificial intelligence the processing of “big data” in the Internet of Things, spectrum policy, online accessibility, compulsory copyright licensing, telecommunications and new technologies.

Ms. Tonsager also conducts privacy and data security diligence in complex corporate transactions and negotiates agreements with third-party service providers to ensure that robust protections are in place to avoid unauthorized access, use, or disclosure of customer data and other types of confidential information. She regularly assists clients in developing clear privacy disclosures and policies―including website and mobile app disclosures, terms of use, and internal social media and privacy-by-design programs.

Read more about Lindsey Tonsager
Show more Show less
Photo of Libbie Canter Libbie Canter

Libbie Canter is a member of the Communications & Media, Data Privacy and Cybersecurity, and Litigation Practice Groups. She represents and advises clients on matters before Congress and various federal agencies, including the Federal Communications Commission and the Federal Trade Commission.  She has…

Libbie Canter is a member of the Communications & Media, Data Privacy and Cybersecurity, and Litigation Practice Groups. She represents and advises clients on matters before Congress and various federal agencies, including the Federal Communications Commission and the Federal Trade Commission.  She has advised clients on a broad range of privacy issues, including data security breach matters, online and mobile marketing, and social networking policies for employers.  Her legislative work focuses on the areas of communications and media, privacy law, and cloud computing policy.

Read more about Libbie Canter
Show more Show less
Photo of Carolyn Rashby Carolyn Rashby

Carolyn Rashby provides business-focused advice and counsel to companies navigating the constantly evolving and overlapping maze of federal, state, and local employment requirements. She conducts workplace investigations and cultural assessments, leads audits regarding employee classification, wage and hour, and I-9 compliance, advises on…

Carolyn Rashby provides business-focused advice and counsel to companies navigating the constantly evolving and overlapping maze of federal, state, and local employment requirements. She conducts workplace investigations and cultural assessments, leads audits regarding employee classification, wage and hour, and I-9 compliance, advises on employment issues arising in corporate transactions, and provides strategic counsel to clients on a wide range of workplace matters, including harassment and #MeToo issues, wage and hour, worker classification, employee accommodations, termination decisions, employment agreements, trade secrets, restrictive covenants, employee handbooks, and personnel policies. Her approach is preventive, while recognizing the need to set clients up for the best possible defense should disputes arise.

Read more about Carolyn Rashby
Show more Show less
Photo of Jayne Ponder Jayne Ponder

Jayne Ponder is an associate in the firm’s Washington, DC office and a member of the Data Privacy and Cybersecurity Practice Group. Jayne’s practice focuses on a broad range of privacy, data security, and technology issues. She provides ongoing privacy and data protection…

Jayne Ponder is an associate in the firm’s Washington, DC office and a member of the Data Privacy and Cybersecurity Practice Group. Jayne’s practice focuses on a broad range of privacy, data security, and technology issues. She provides ongoing privacy and data protection counsel to companies, including on topics related to privacy policies and data practices, the California Consumer Privacy Act, and cyber and data security incident response and preparedness.

Read more about Jayne Ponder
Show more Show less
Photo of Bryan Ramirez Bryan Ramirez

Bryan Ramirez is an associate in the firm’s San Francisco office and is a member of the Data Privacy and Cybersecurity Practice Group. He advises clients on a range of regulatory and compliance issues, including compliance with state privacy laws. Bryan also maintains…

Bryan Ramirez is an associate in the firm’s San Francisco office and is a member of the Data Privacy and Cybersecurity Practice Group. He advises clients on a range of regulatory and compliance issues, including compliance with state privacy laws. Bryan also maintains an active pro bono practice.

Read more about Bryan Ramirez
Show more Show less
  • Posted in:
    International
  • Blog:
    Global Policy Watch
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

LexBlog logo
Copyright © 2026, LexBlog. All Rights Reserved.
Legal content Portal by LexBlog LexBlog Logo