Reducing AI Bias: What the Law Now Requires

Last Updated: September 10, 2026 | By Mihail Sebastian | Laws of AI

AI bias is now a compliance problem, not just an ethics debate. What the EU AI Act, NYC Local Law 144, and discrimination law require of your systems.

Reducing AI Bias: What the Law Now Requires
Photo by Nonsap Visuals on Unsplash

A recruiting team deploys a tool that ranks every applicant before a human sees a name. A lender’s model decides who gets credit and on what terms. Five years ago, a biased result from either system was an ethics problem: embarrassing, debated in principle, punished mostly by headlines.

In 2026 it is a compliance problem. The EU regulates both uses as high-risk AI. New York City requires the hiring tool to pass an independent audit every year, and US credit law requires the lender to give the rejected applicant specific reasons, model or no model.

The ethics did not stop mattering. But the question organizations must now answer has changed from “is this fair?” to “can you prove it?”, and the second question comes with deadlines and penalties attached.

What the Law Actually Requires

The EU AI Act entered into force in August 2024, and its main high-risk obligations apply since August 2026. AI used for recruitment, credit scoring, and access to essential services sits squarely in the high-risk tier. Those systems must run under a risk management process, meet data governance requirements, carry technical documentation and human oversight, and pass a conformity assessment before they reach the market.

The Act’s reach does not stop at Europe’s borders. It applies to providers and deployers anywhere when the system’s output is used in the EU, which is why a US vendor selling a screening tool to a German customer carries the same obligations as a European one.

New York City got there earlier. Local Law 144, enforced since July 2023, requires an employer using an automated tool to screen candidates for jobs in the city to have the tool bias-audited by an independent auditor before use, and annually after. The audit computes selection rates by sex and by race or ethnicity, the employer publishes a summary of the results, and candidates must be told the tool is in use.

The older laws never left. The Equal Credit Opportunity Act requires lenders to give applicants specific reasons for adverse action, and US regulators have made clear that a complex model does not excuse a vague answer. Employment discrimination law applies to an algorithm’s decisions exactly as it applies to a recruiter’s, and buying the tool does not outsource the liability.

The states are moving in the same direction. Colorado enacted an AI statute in 2024 aimed at algorithmic discrimination in consequential decisions such as hiring and lending, the broadest state law of its kind so far.

Where Bias Enters

None of these laws require intent, and that is the point. The documented failures were not programmed; they were learned. Bias in AI is a systematic tilt in a model’s outputs, and it enters through the data, the labels, and the proxies long before anyone writes a discriminatory rule.

The data carries history. Amazon’s experimental resume screener, reported by Reuters in 2018, was trained on about a decade of resumes submitted to the company, most of them from men. The model learned that male-associated signals predicted success, penalized resumes containing the word “women’s”, and downgraded graduates of two all-women’s colleges; Amazon said the tool never rated real candidates and abandoned it.

The label is the subtler entry point. A 2019 study in Science examined a widely used US healthcare algorithm that scored patients for extra-care programs: it was treated as a measure of medical need but trained to predict healthcare costs. Less money had been spent on Black patients than on equally sick white patients, so at the same risk score, Black patients were sicker, and fewer qualified for the extra care.

Then there is the question of what counts as fair at all. In 2016, ProPublica reported that COMPAS, a risk tool some US courts used, labeled Black defendants who did not go on to reoffend as high-risk at roughly twice the rate of white defendants; the developer replied that a given score meant the same reoffending rate regardless of race. Both readings fit the data, and researchers proved that when groups differ in base rates, no score satisfies both fairness definitions at once, so every deployed system chooses which unfairness it tolerates.

One more trap deserves naming: deleting the protected attribute fixes nothing. Postal codes, school names, and spending patterns carry the same signal, which is why “we don’t collect race” has never survived an audit as a defense.

What Organizations That Pass Audits Actually Do

The organizations that clear these requirements without drama share a set of habits, and none of them is exotic.

They measure outcomes by group, not in aggregate. Overall accuracy hides disparities, so they disaggregate selection rates, approval rates, and error rates across demographic groups, before deployment and continuously after. This is precisely what a Local Law 144 audit computes, so a team that already measures it holds no surprises for the auditor.

They document where the data came from. Data provenance, what was collected, from whom, over what period, and what history it encodes, is both an EU AI Act data-governance requirement and the fastest way to spot an Amazon-style skew before training. They pair it with an impact assessment that asks who the system decides about and what a wrong decision costs that person.

They separate the fixing from the grading. Internal teams test, adjust thresholds or reweight data, and retest until the disparity shrinks; then an independent AI audit verifies the result against the applicable standard and puts it on the record. The fix-and-retest loop is engineering; the audit is evidence.

And they are honest about the limit. Bias cannot be fully eliminated, because it enters through data, proxies, and design choices, and no technique removes every source. Regulators do not demand a bias-free model; they demand proof that you measure it, reduce it, and notice when it drifts.

The Agentic Wrinkle

Everything above assumes the model produces a score that a person then acts on. Increasingly it does not. AI agents now screen candidates, price policies, and approve transactions end to end, and a biased output that once waited for human sign-off becomes a biased action executed at machine speed.

The bias itself is no worse, but the exposure is. A skewed score reviewed by a loan officer produces one questionable recommendation; the same score inside an agent with approval authority produces a pattern of completed decisions before anyone looks. That is excessive agency compounding a fairness defect: the agent holds more autonomy than its error rate deserves.

The controls follow from that. Actions that are hard to undo, an approval, a rejection, a price, get a human gate or a cap; everything the agent does gets logged well enough that a disparity found in month three can be traced to its cause rather than reconstructed from complaints. Group-level outcome monitoring belongs in the agent’s telemetry from day one, not in the post-incident review.

The legal analysis does not change, which is the uncomfortable part. Adverse-action duties, audit obligations, and discrimination law attach to the decision regardless of how automatically it was executed, so the organizations deploying agents in regulated decisions are the ones that need the measurement discipline most.

Bias used to be the topic of the ethics panel. It is now a line item in the audit plan, and the organizations treating it that way, measured, documented, and independently checked, are the ones for whom the ethics conversation gets easier too.

Frequently Asked Questions

Written by

Mihail Sebastian

Mihail Sebastian

Editor, AI Guv

Mihail works in AI and writes about artificial intelligence topics for people who need to understand it without building it. He comes from more than 20 years of product design in startups.

Read the Governor's Letter

Stay ahead with Governor's Letter, the newsletter delivering expert insights, AI updates, and curated knowledge directly to your inbox.

By subscribing to the Governor's Letter, you consent to receive emails from AI Guv.
We respect your privacy - read our Privacy Policy to learn how we protect your information.