conversational ai in hr
AI Automation

Conversational AI in HR: Your Chatbot Is Now Regulated

Conversational AI in HR splits into two use cases with completely different risk profiles, and most vendors sell them as one product. An internal assistant that answers questions about leave balances and benefits enrolment is low-risk automation. A candidate-facing chatbot that asks qualifying questions and routes applicants is very likely an automated employment decision tool under New York City law and a machine-based system influencing employment decisions under Illinois law, which means bias audits, published results, and advance notice to candidates. In a SHRM survey of more than 1,900 HR professionals, 57% of those in states with workforce AI regulations were not aware of the rules, and only 12% had taken steps to comply.

That gap is the most important fact about HR chatbots right now, and it is not on any vendor’s product page.

Where adoption actually is

HR lags the rest of the business, which surprises people who read the vendor coverage. From the same SHRM data:

  • 39% of organisations have implemented AI in HR functions, against 62% using AI somewhere in the business
  • 7% plan to implement this year, and 31% have no plans at all
  • Within HR, recruiting leads at 27%, HR technology at 21%, learning and development at 17%
  • 56% of HR functions do not formally measure the success of their AI investments, and only 16% use ROI as a metric

Self-reported outcomes are positive: 87% report improved efficiency, 75% improved work quality, 70% increased creativity. Read those alongside the 56% who do not measure anything, and it is clear most of that is impression rather than result. Job displacement is reported by just 7%, while 39% report shifted responsibilities and 24% report new roles created.

On governance, 49% have policies regulating employee AI use, and only about a quarter of those believe their policy is future-proof.

The two use cases, and why the split matters

Employee service. Answering policy questions, checking leave balances, starting an expense claim, guiding open enrolment, routing an IT or payroll ticket. This is where conversational AI in HR works best and carries the least legal exposure. The queries are repetitive, the correct answers exist in documents you already own, and nobody’s employment is being decided. If you are starting, start here.

Candidate and employee decisioning. Screening chatbots that ask qualifying questions, rank responses, schedule only some applicants, or route candidates into or out of a process. Also anything touching promotion, performance, or termination. This is regulated activity in a growing number of jurisdictions, and the conversational interface does not change that. If the bot’s output influences who advances, it is a decision tool wearing a friendly interface.

Vendors rarely draw this line for you, because the same platform usually does both and the compliance obligations attach to how you deploy it, not to what they sold you.

What the law currently requires

This is a fast-moving area and some of it is in active litigation, so treat the table below as a starting point for a conversation with your employment counsel rather than as advice. I am not a lawyer.

Rule In force Core obligations
NYC Local Law 144 5 July 2023 Independent bias audit before deployment, audit results published, candidate notice at least ten business days before use, disclosure of the job qualifications being assessed
Illinois HB 3773 1 January 2026 Prohibits discriminatory AI use across the full employment life cycle from recruitment through termination; requires notifying applicants and employees when AI influences decisions; private right of action; draft regulations propose four-year recordkeeping
Texas TRAIGA 1 January 2026 Prohibits developing or deploying AI with intent to discriminate; 60-day cure period; intent-based, so a narrower standard than Illinois
Colorado AI Act Enforcement stayed 27 April 2026 Risk management policies, annual impact assessments, consumer-facing disclosures, notification to the state Attorney General within 90 days of discovering algorithmic discrimination. Currently unenforceable pending litigation

Two points that matter more than the table.

Illinois is the significant one, because it covers the entire employment life cycle rather than hiring alone, and because it carries a private right of action. A candidate or employee can sue directly. NYC’s law is enforced by a city agency, which is a materially different risk profile from a plaintiff’s bar.

Colorado’s situation is genuinely unsettled. Enforcement was stayed on 27 April 2026 pending X.AI LLC v. Weiser (No. 1:26-cv-01515, D. Colo.), filed 9 April 2026, in which the Department of Justice intervened. Do not plan around Colorado being either dead or alive. Check its status before you rely on either assumption, because this will have moved since publication.

You cannot fully push the risk onto the vendor

The instinct is to treat this as the vendor’s problem, since they built the model. That theory is being tested and it is not going well.

Mobley v. Workday, in the Northern District of California, alleges that Workday’s AI-powered applicant screening systematically discriminated on the basis of age, race, sex, and disability. It is the first significant test of whether a vendor can be held liable under federal anti-discrimination statutes for tools its customers deploy. A separate suit against Eightfold AI advances a different theory, that AI employment tools should fall under the Fair Credit Reporting Act, which would bring a whole additional disclosure and dispute regime with it.

Whichever way those land, the practical position for an employer is unchanged: you are the one making the employment decision, and the notice and audit obligations in NYC and Illinois attach to you. A vendor indemnity is worth having and is not a compliance strategy.

Do not count on federal preemption

There is a real push to consolidate this patchwork, and it has not landed. Executive Order 14365, signed in December 2025, directed the Department of Justice to establish an AI Litigation Task Force to challenge state AI laws it considered burdensome, and a White House national AI legislative framework in March 2026 recommended broad federal preemption. A proposed ten-year moratorium on state and local AI regulation was stripped out of the One Big Beautiful Bill Act in mid-2025 after bipartisan opposition.

So the direction of travel is toward federal consolidation and the current state of the law is a patchwork with at least one statute carrying a private right of action. Build for the patchwork.

A deployment sequence that does not create problems

  1. Start with employee service, not recruiting. Leave balances, benefits questions, policy lookup, ticket routing. Real savings, minimal legal surface, and it teaches your team how the technology behaves before anything consequential rides on it.
  2. Write down whether the bot influences a decision. One sentence per deployment. If the answer is yes or unclear, treat it as a decision tool. Screening, ranking, and selective scheduling all count.
  3. Inventory where your applicants and employees are located, not where you are. NYC’s law follows the job location; Illinois follows the employment relationship. A remote role can pull in several regimes at once.
  4. Commission the bias audit before launch, not after a complaint. NYC requires it to be independent and published. Retrofitting an audit onto a live tool is more expensive and reads badly.
  5. Build the notice into the flow. Ten business days’ advance notice, plus disclosure of the qualifications being assessed. This is a product requirement, not a legal afterthought, and it is easier to design in than to bolt on.
  6. Keep records for four years. Illinois draft regulations propose it, and it is a sensible baseline regardless of jurisdiction.
  7. Keep a human in the rejection path. Whatever the law requires, a bot that ends candidacies without review is the deployment that generates the complaint.
  8. Measure something. Given 56% of HR functions measure nothing, deciding your target number in advance puts you ahead of most peers and gives you a defensible record of intent.

On the build side, our comparison of chatbot development frameworks covers the technical options if you are evaluating platforms, and our guide to AI operations automation is useful for the employee-service workflows that should come first.

Questions for a vendor

  • Has this tool been through an independent bias audit, and can I see it? Not a fairness whitepaper. An audit.
  • Does your product generate the candidate notice and qualification disclosure, or is that on me?
  • What exactly does the model use to rank or route a candidate? If they cannot tell you, you cannot disclose it, and disclosure is required.
  • Can I turn off ranking and keep the conversational interface? This is the single most useful configuration question, because it lets you keep the UX benefit and drop most of the legal exposure.
  • What is your indemnity position on discrimination claims arising from your model?
  • How long do you retain conversation transcripts, and can I export them? You may need four years of them.

That fourth question is the one to lead with. A great deal of what makes recruiting chatbots appealing, faster response to applicants, availability outside business hours, consistent information, has nothing to do with automated screening. You can generally have the first set without the second, and the compliance difference is substantial.

The bottom line

Conversational AI in HR is a good deployment for employee service and a regulated one for anything touching hiring or employment decisions. The 57% unawareness figure suggests most teams have not made that distinction yet, and Illinois added a private right of action on 1 January 2026.

Draw the line yourself, in writing, before your vendor draws it for you. And run the hiring side past employment counsel, because nothing above is a substitute for that.

Leave a Reply

Your email address will not be published. Required fields are marked *