Using AI to Screen Resumes? What to Tell Applicants in 2026

Using ChatGPT to screen resumes? New 2026 state laws (Illinois, NYC, Colorado) can require you to tell applicants. The plain-English compliance guide.

You run a small business. A job post pulled in 300 applications, so you did the sensible thing: you asked ChatGPT to help sort them, flag the strongest, and draft your outreach. It saved you a full day. What almost nobody tells you is that in 2026, depending on where your applicants live, doing that may come with a legal duty to tell them you used AI.

This isn’t a scare piece, and you almost certainly don’t need a lawyer on retainer. But a quiet wave of state and international laws now governs AI in hiring, and they’re written for exactly your situation: the owner or “HR-of-one” who started using AI without a compliance department to flag the rules. Here’s the plain-English version — what the laws actually say, what you have to do, and the one-line fix that covers most of it.

What just changed

For years, “AI in hiring” law meant giant enterprise recruiting platforms. In 2026 that flipped. New rules increasingly focus on the employer using the tool — which now includes the small business that just uses ChatGPT. The common thread across all of them is not a ban. It’s transparency and human oversight: if AI meaningfully shapes who gets hired, you generally have to disclose it and keep a human genuinely in charge of the decision.

Crucially, there’s a difference between drafting and deciding. Using AI to write a job description or clean up your interview questions is low-risk. Using AI to rank, filter, score, or reject candidates is the activity these laws care about — because that’s where a biased or opaque system can quietly harm real people.

Illinois HB 3773
In force Jan 1, 2026. Notify applicants when AI helps make a hiring decision. Generally applies to employers with 15+ staff.
NYC Local Law 144
Enforced since 2023. If AI substantially drives screening: bias audit + notice 10 business days ahead + an opt-out.
Colorado AI Act
In flux — start date pushed to mid-2026, enforcement paused, a replacement due in 2027. Monitor, don't panic.
EU AI Act
Hiring AI is 'high-risk.' Core duties land Aug 2, 2026 — and it applies even to US firms hiring EU-based candidates.
watch AI in hiring — the 2026 rules that may touch a small employer act now

The state-by-state map (kept simple)

Illinois — the fresh one. House Bill 3773 amended the Illinois Human Rights Act, effective January 1, 2026. Two things: you can’t use AI in a way that discriminates against protected classes (or by ZIP code), and you must notify employees and applicants when AI is used to help make an employment decision. Failure to give notice is itself a civil-rights violation. The Human Rights Act generally covers employers with 15 or more employees, so the very smallest shops may sit below the threshold — but once you’re covered, the notice duty applies no matter your size.

New York City — the established one. Local Law 144 has been enforced since July 2023. It’s narrower than people assume: it kicks in when a tool “substantially assists or replaces” a discretionary hiring or promotion decision. If yours does, you need a bias audit within the past year, a public summary of the results, and notice to candidates at least 10 business days before you use it — plus a way for them to request an alternative process.

Colorado — the one in limbo. The Colorado AI Act (SB 24-205) was set to be the most comprehensive, but its start date slipped from February 2026 to June 30, 2026, enforcement was stayed in April 2026, and a replacement framework (SB 26-189) is scheduled for January 1, 2027. Translation: don’t build your whole process around it yet, but if you hire in Colorado, keep an eye on it.

The EU — the one that reaches across the ocean. The EU AI Act classifies recruitment and candidate-evaluation AI as “high-risk,” with core obligations landing August 2, 2026: risk management, human oversight, and disclosure to affected workers and candidates (Article 26). Like GDPR, it’s extraterritorial — if your AI’s output is used to evaluate someone in the EU, it can apply even if your business is entirely in the US.

NYC’s Automated Employment Decision Tools law page explaining bias-audit and candidate-notice rules NYC’s Local Law 144 has required bias audits and candidate notice since 2023. Source: NYC DCWP

What you actually have to do

The good news: none of these laws ban you from using ChatGPT to help with hiring. They ask you to use it responsibly and openly. For most small employers, four habits cover the great majority of the risk.

Responsible AI hiring in four steps
Disclose it one line in the job post
AI assists, never decides
A human reviews every rejection
Keep a simple record
Not legal advice—but this covers the core of what every one of the 2026 rules is asking for.
  1. Disclose it. Add one plain sentence to your job posts and application pages, such as: “We use AI-assisted tools to help review applications. A member of our team reviews every candidate, and you can request a review without AI — just email us.” That single line satisfies the spirit of nearly all the notice rules.

  2. Let AI assist — never auto-reject. Use it to summarize, organize, and surface candidates for your review. Don’t let it send rejections on its own. The instant AI is the thing that decides who’s out, you’ve stepped into the high-risk zone these laws target.

  3. Put a human on every screen-out. Before anyone is rejected on an AI-influenced basis, a person should look. This is both the legal expectation (a right to human review runs through all four regimes) and simply good hiring — AI happily filters out strong, non-traditional candidates on keyword mismatches.

  4. Keep a simple record. A short note of what tool you used, for what, and the fact that a human reviewed outcomes. If you’re ever asked, “reasonable oversight” is much easier to show with a paper trail than without one.

A copy-paste screening prompt that bakes this in: “Summarize each résumé against these must-have skills: [list]. Flag candidates who clearly meet them and note who’s borderline and why. Do not reject anyone — I’ll review every one, including the borderline and no-match candidates.”

What this means for you

If you’re a solo owner or HR-of-one using ChatGPT casually: you probably don’t need to stop. Add the disclosure line, keep yourself as the decision-maker, and you’ve handled most of it. If you’re under 15 employees and hiring only in states without a specific law, your duty is lighter — but the disclosure habit is cheap insurance as more states follow.

If you hire in Illinois, NYC, or the EU: treat disclosure and human review as non-negotiable now. NYC’s bias-audit rule specifically bites if your tool “substantially” drives screening — so keep AI in the assist seat.

If you’re scaling up and considering a dedicated AI hiring tool: that’s a bigger step than casual ChatGPT use. Vendor tools that score and rank candidates are squarely “high-risk,” and you inherit audit and documentation duties. Ask any vendor for their bias-audit results before you buy.

What this doesn’t mean

Let’s clear up the panic myths:

  • It doesn’t mean you can’t use AI to hire. Every one of these laws permits AI-assisted hiring with disclosure and oversight. None bans ChatGPT.
  • It doesn’t mean drafting a job post is regulated. Using AI to write a posting or polish interview questions isn’t the “decision” activity the laws target. Screening and ranking is.
  • It doesn’t mean Colorado’s rules are live. They’re delayed and being rewritten — don’t over-build for a stayed law.
  • This isn’t legal advice. Laws vary by state and change fast (Colorado is proof). For a real hiring program at any scale, confirm your specific obligations with an employment attorney.

The bottom line

Using AI to help with hiring is legal, sensible, and — for a small team drowning in applications — genuinely worth it. The 2026 rules don’t take that away. They ask for something reasonable: tell people, keep a human in charge, and don’t let a model quietly reject candidates on its own. Add one disclosure line, keep yourself as the decider, jot down what you did, and you’ve covered the heart of it.

The bigger win is knowing how to use AI well across your whole business — where it saves you real time and where it needs a human hand on the wheel. That’s exactly what our ChatGPT for Business and AI Fundamentals courses teach, in plain language for owners who don’t have a compliance team. (And if you’re worried about the other side of AI hiring — spotting AI-generated résumés from candidates — we covered that here.)

Already using AI to screen? Add the one-line disclosure to your next job post today. It’s the cheapest compliance you’ll ever do.


Sources

Build Real AI Skills

Step-by-step courses with quizzes and certificates for your resume