AI & Hiring Compliance
Aptimal, Inc.
Last updated: 07/23/2026
Why This Page Exists
Aptimal is used to make decisions about people's careers. That places it inside a fast-moving and inconsistent body of U.S. law governing artificial intelligence in employment.
This page explains how responsibility is divided between Aptimal and the employers who use it, and what we provide to support your compliance. It is written for the buyer's legal and HR teams as much as for candidates.
This page is informational and is not legal advice. The law here is unsettled and changing. Confirm your obligations with your own counsel.
1. Who Is Responsible for What
You are the employer. You decide to run the hiring process, what data to collect, what questions to ask, what score thresholds to set, and — critically — what decision to make about each candidate. Under essentially every framework below, the substantive obligations fall on the employer as the deployer of the tool.
We are the vendor. We build and operate the platform. Under several frameworks we are a "developer" of automated decision-making technology, which carries its own duties around documentation and disclosure to deployers. We do not make hiring decisions, and we do not use candidate data for our own purposes.
What this means practically: we cannot make you compliant, and we do not warrant that your use of the Services is compliant. What we can do is give you the documentation, data, and product controls you need to comply. Sections 4 and 5 set out what we provide.
2. Federal Law — Applies Everywhere, Always
These apply regardless of state and are the oldest and most consequential exposure.
Title VII, the ADA, and the ADEA. Selection procedures that disproportionately exclude candidates on a protected basis can create disparate impact liability even where there is no intent to discriminate, unless the procedure is job-related and consistent with business necessity. A scoring model is a selection procedure.
Uniform Guidelines on Employee Selection Procedures (UGESP). Where a selection procedure has adverse impact, employers are expected to have validation evidence. The "four-fifths rule" is a rule of thumb for flagging adverse impact, not a safe harbor.
Americans with Disabilities Act. Timed or free-text assessments can disadvantage candidates with disabilities. Employers must provide reasonable accommodations and should offer an accessible alternative process. Assessments must not screen out disability or function as a disability-related inquiry.
Fair Credit Reporting Act. Background checks ordered through Aptimal are furnished by Checkr, Inc., a consumer reporting agency. Aptimal is not a consumer reporting agency. You are responsible for standalone disclosure, written authorization, pre-adverse action notice with a copy of the report and the summary of rights, a reasonable waiting period, and adverse action notice.
EEOC recordkeeping. Application records must generally be retained for one year from the record or personnel action, whichever is later.
3. State and Local Law
The U.S. has no comprehensive federal AI statute. Obligations sit in state law, and the map changes frequently. Below is our understanding as of the date above.
New York City — Local Law 144
Applies to automated employment decision tools used to screen candidates for jobs in New York City. Requires an independent bias audit within the preceding year, publication of a summary of results, and advance notice to candidates (generally at least 10 business days) identifying the qualifications and characteristics assessed, with the opportunity to request an alternative process or accommodation.
California
Two separate regimes apply, from two different agencies.
Civil Rights Department / Civil Rights Council regulations (effective October 1, 2025) address automated decision systems under the Fair Employment and Housing Act. They make the presence or absence of anti-bias testing explicitly relevant to a discrimination claim, and impose extended recordkeeping for automated decision system data.
CPPA regulations on automated decision-making technology (compliance required January 1, 2027) apply where ADMT is used to make a "significant decision," which expressly includes employment. Where they apply, employers must provide a pre-use notice, respond to access requests with meaningful information about the logic, key parameters, and effects of the ADMT, and offer an opt-out — subject to exceptions, including where a human appeal process is available. A risk assessment must be conducted, with existing processing assessed by December 31, 2027.
California is significant for a second reason: it is the main state whose comprehensive privacy law does not exempt job applicants. Most other state privacy laws do.
Illinois
The Artificial Intelligence Video Interview Act requires notice, explanation, consent, and deletion-on-request where AI analyzes video interviews. Amendments to the Illinois Human Rights Act (effective January 1, 2026) require disclosure when AI is used for employment decisions and prohibit use of AI that has a discriminatory effect or that uses ZIP code as a proxy for a protected class.
Colorado
Colorado's original AI Act was repealed before taking effect and replaced by SB 26-189, signed May 14, 2026 and effective January 1, 2027. The replacement is substantially narrower. It applies to automated decision-making technology that materially influences major employment decisions and requires:
- clear notice to individuals
- a structured adverse action and human review process
- retention of relevant records for at least three years
It allocates liability between developers and deployers on a fault basis, voids certain indemnification clauses between them, and is enforceable only by the Colorado Attorney General — there is no private right of action.
Texas
Texas enacted AI legislation effective January 1, 2026 addressing the development and deployment of AI systems, including provisions relevant to discriminatory use. Aptimal is a Delaware corporation with its registered agent in Delaware, with operations in all states, and is beholden to Delaware and federal law first and foremost.
Other states
Several states enacted or expanded AI-in-employment requirements during the 2026 legislative session, with obligations extending beyond disclosure into auditing, reporting, and affirmative anti-discrimination duties. We update this page as material changes take effect.
A note on federal preemption
An executive order issued in December 2025 established a Department of Justice task force to challenge state AI laws on preemption and constitutional grounds, and litigation is underway. This does not currently suspend any state law. Our position, and the prevailing guidance, is to plan for compliance with state law as written unless and until a statute or court decision changes it.
4. What We Provide On Request
- Documentation of what the scoring does — the inputs, the general logic, and the intended effect — to support pre-use notices, access explanations, and risk assessments
- Configurable human review controls, so adverse decisions can require human confirmation before taking effect
- Audit logging of who reviewed what and when, supporting recordkeeping obligations
- Candidate notice templates you can adapt to your jurisdictions
- A signed Data Processing Addendum and current subprocessor list
- Security documentation for your vendor review
5. What You Must Do
- Determine which laws apply to you based on where your roles are located and where your candidates reside
- Apply meaningful human review before any adverse decision — a person with authority and competence to change the outcome, not a rubber stamp
- Obtain bias audits where required, and publish results where required
- Give candidates required notice before assessment, and offer alternative processes or accommodations
- Conduct risk and impact assessments where required
- Validate your own selection criteria — the thresholds and requirements you configure are yours
- Retain records for the periods your jurisdictions require
- Comply with the FCRA for any background check you order
6. Our Design Commitments
- We do not train models on your data. Our AI subprocessors are contractually prohibited from training on data we send them.
- We do not solicit protected characteristics. The Services do not ask candidates for them, and customers are contractually prohibited from configuring them to.
- We do not sell candidate data. Ever, to anyone.
- We publish our subprocessors and give 30 days' notice before changes.
7. Geographic Scope
The Services are offered in the United States only and are intended for U.S.-based employers hiring for U.S.-based roles. We do not currently support GDPR or UK GDPR compliance. If you need to process candidate data for individuals located in the EEA, the UK, or Switzerland, contact us before doing so.
8. Contact
Questions from customers, candidates, regulators, or security teams:
Aptimal Inc.
Email us: support@aptimal.ai
Registered Agent: Legalinc Corporate Services Inc.
131 Continental Dr Suite 305 Newark, DE, 19713 US