A recent Thompson Coburn webinar, hosted by partner Kacey Riccomini and associate Emma Lapp, explored how the rapid adoption of artificial intelligence (AI) across hiring, HR management, and workforce monitoring is colliding with an increasingly complex and fragmented regulatory environment.
The speakers emphasized that, in the absence of comprehensive federal guidance, states and localities are setting the pace for AI-related employment regulation, which creates significant compliance challenges for multijurisdictional employers. Laws and proposals targeting algorithmic bias, privacy rights, and transparency obligations are expanding quickly, exposing employers to risks under anti-discrimination laws, wage and hour rules, privacy statutes, and the Fair Credit Reporting Act (FCRA).
Kacey and Emma highlighted California’s leadership role, including Civil Rights Council rules addressing AI-driven discrimination (with broad definitions and proxy discrimination theories), CCPA/CPRA privacy rights, and emerging whistleblower protections tied to advanced AI systems. Other jurisdictions—such as Colorado, Illinois, Maryland, New York City, and Texas—are adopting targeted frameworks requiring bias audits, notice and consent mechanisms, and accountability for AI system design and use.
The session concluded with practical guidance for employers implementing AI tools, stressing the importance of governance, vendor oversight, human review, and proactive legal strategy to mitigate evolving risks.
Key Takeaways
- Patchwork AI compliance is accelerating.
With limited federal direction, employers must navigate a rapidly expanding patchwork of state and local AI laws. Proactive, enterprise-wide compliance strategies are essential for managing overlapping and sometimes conflicting requirements.
- California is setting a high compliance bar.
California’s evolving framework imposes broad anti-bias obligations, expansive definitions of harm (including deterred applicants), and significant recordkeeping requirements (at least four years), along with strict privacy rights under CCPA/CPRA.
- State and local laws impose targeted obligations.
Jurisdictions including Colorado, Illinois, Maryland, New York City, and Texas have enacted or proposed laws governing AI in employment, requiring measures such as bias audits, transparency notices, consent for biometric use, and risk management programs to address algorithmic discrimination.
- Strong AI governance is critical.
Employers should closely vet vendors, conduct bias testing, document system performance, and implement policies governing both employer- and employee-driven AI use. Special attention is required for FCRA compliance, biometric and privacy risks, and generative AI issues such as hallucinations, intellectual property exposure, and confidentiality breaches.
- Human oversight remains essential.
AI tools used in hiring, monitoring, and decision-making must include human review to mitigate discrimination risks, ensure accommodations and accessibility, and avoid wage-and-hour pitfalls. Employers should also prepare for emerging issues, including deepfakes and expanded whistleblower protections tied to advanced AI technologies.
View the full webinar here.


