AI Governance, Risk & Red Teaming
Capable · M9 · lesson 9 of 22 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Candidate-Facing AI Disclosures - NYC LL 144 and EU AI Act Annex III §4
📖
now learning

Candidate-Facing AI Disclosures - NYC LL 144 and EU AI Act Annex III §4

15 min

A candidate in Queens opens a job posting at 10:14 a.m. on a Tuesday. By 10:16 a.m. she has read three paragraphs of marketing copy, scrolled past a list of benefits, and noticed a small italicized notice at the bottom of the posting: "We use AI-driven tools in the screening process." That sentence, alone, does not satisfy NYC Local Law 144. It does not satisfy the EU AI Act Annex III §4 deployer-information requirement. It does not satisfy the Illinois AI Video Interview Act. It would not survive the December 2025 NY State Comptroller audit's substantive 2026 review bar. What that posting needs is a structured candidate-facing disclosure stack: the 10-business-day notice with required content; the public-facing bias-audit summary on the careers webpage with per-category numbers; and the alternative-assessment offer that invites a request for a non-AI selection path. Lesson 32 is the drafting workshop. By the end you have three production-ready templates, the candidate notice, the bias-audit summary, and the alternative-assessment offer, aligned to NYC LL 144, the EU AI Act Annex III §4 employment overlay, and the seven adjacent regimes that touch the same hiring funnel. The L2 artifact is a per-jurisdiction candidate-disclosure template library that the Head of Talent Acquisition, the Responsible AI Officer, the Employment Counsel, and the DPO can all sign off on without rewriting each other's work.

The Three Candidate-Facing Disclosure Artifacts

Every NYC employer that deploys an AEDT for a job posted in New York City, or for a candidate residing in NYC, must produce three distinct candidate-facing artifacts. They are sometimes conflated, often produced by different teams, and routinely fail substantive 2026 DCWP review when any one is missing or under-specified:

  • The 10-business-day candidate notice. A pre-deployment notification provided to each candidate at least ten business days before the AEDT is used, in at least one of three channels (job posting, careers webpage, individual notification). Content-specified by the DCWP rule.
  • The public-facing bias-audit summary. A prominent post on the employer's careers webpage summarizing the most recent independent bias audit's methodology and numerical results. Content-specified by the DCWP rule.
  • The alternative-assessment offer. An invitation and operational pathway for the candidate to request an alternative selection process, most commonly required as a disability accommodation under the ADA and the NYC Human Rights Law, but increasingly offered as a default option in defensive practice.

The three artifacts overlap in source data, the same bias audit underpins both the notice's substance and the summary's numbers, but they live on different surfaces, target different audiences, and answer different questions. The defensible design is a shared evidence base feeding three differently-surfaced artifacts, with one refresh cadence updating all three.

What the EU AI Act Annex III §4 overlay adds: Article 26(6) requires deployers of high-risk workplace AI to inform workers' representatives and affected workers before deployment. Article 26(7), applicable from December 2, 2027 for stand-alone Annex III §4 systems and immediately for public-body deployers, requires a Fundamental Rights Impact Assessment. Article 50(1) requires that candidates interacting with an AI chatbot be told they are interacting with AI unless it is obvious. Article 86 grants individuals a right to explanation for decisions taken on the basis of high-risk AI output producing legal or similarly significant effects. The LL-144-only template is one regime short; the template addressing both covers the same fact pattern with overlapping language.

The 10-Business-Day Candidate Notice - A Drafting Workshop

The DCWP rule (RCNY Title 6, §5-301) specifies the notice content. The notice must inform the candidate that an AEDT will be used; identify the job qualifications and characteristics it will assess; describe the data collected; identify the data source; describe the retention policy; and inform the candidate of the right to request an alternative selection process or reasonable accommodation. Three channels are permitted: job posting; careers webpage; direct individual notification (email, letter, or in-application notice). The 10-business-day clock starts on receipt and runs against the AEDT's use, not the application deadline.

The minimum-viable template, tunable to the specific AEDT:

AI in our hiring process - what you need to know before applying

[Employer name] uses an Automated Employment Decision Tool (AEDT) in connection with applications for [job title or category]. Under New York City Local Law 144, we are required to provide you with this notice at least ten business days before the AEDT is used to assist with the hiring decision for your application.

What the AEDT does. The tool [name and brief description of vendor-shipped or in-house tool] assesses the following job-related characteristics: [list the specific qualifications and characteristics the AEDT evaluates, e.g., relevant work experience as described in your resume; alignment of your skills with the job description; performance on the structured assessment exercise]. The tool produces a [score / classification / recommendation] that supports, but does not replace, human review by our recruiting team.

What data we collect. The tool processes the following information you provide: [list categories, e.g., resume content; cover letter; structured assessment responses; recorded video-interview responses (if applicable); responses to skills tests]. We do not use [list non-collected data, e.g., protected characteristics inferred from your name or photo, biometric data unless you explicitly consent under separate notice].

Where the data comes from. The data source is [your application submitted directly to us / your application submitted via our ATS provider / your structured assessment responses captured by our vendor]. We do not purchase candidate data from third-party data brokers for this hiring process.

How long we retain the data. We retain your application data and AEDT processing records for [retention period, e.g., 24 months after the hiring decision] in accordance with our Candidate Privacy Notice [link] and applicable law (including EEOC record-retention rules and our LL 144 audit-supporting obligations).

Your right to request an alternative selection process. You have the right to request that your application be evaluated through an alternative selection process, for example, a human-only review without AEDT scoring, including as a reasonable accommodation under the Americans with Disabilities Act or the NYC Human Rights Law. To make this request, contact [HR Accommodations Coordinator name, email, and phone]. We will respond to your request within [response window, e.g., five business days] and the alternative selection process will not affect your standing in the candidate pool.

Bias-audit summary. A summary of the most recent independent bias audit of this AEDT is published at [URL to public bias-audit summary on careers webpage]. The summary includes per-category headcounts, selection rates, and impact ratios.

Questions or concerns. Contact [Talent Acquisition contact] or file a complaint with the NYC Department of Consumer and Worker Protection at nyc.gov/dca.

Several drafting decisions are load-bearing. The "what the AEDT does" paragraph must be specific, generic language fails 2026 DCWP review. The "what data we collect" paragraph must enumerate categories, not gesture at them. The "alternative selection process" paragraph must name a contact (not a generic mailbox) and commit to a response timeline. The bias-audit summary URL must be live and satisfy per-category-numbers. The retention policy must reflect actual retention behavior, not aspirational policy.

Multi-Language Considerations for NYC's Candidate Pool

NYC's candidate pool is among the most linguistically diverse in the country. The DCWP rule does not mandate translation of the LL 144 notice, but the NYC Human Rights Law and the NYC Language Access Law create adjacent obligations for public-facing employer materials. Defensive practice points to translating the notice into the city's top-tier languages: Spanish, Mandarin Chinese, Russian, Bengali, Haitian Creole, Korean, Arabic, French. The Mayor's Office of Immigrant Affairs Language Access guidance identifies the priority languages. For employers with a substantial NYC candidate pool, multi-language deployment is the defensible default.

Translation is not a one-time event. Each notice update (new AEDT version, new data category, new retention rule) triggers updates to all language versions. The L2 template library includes version-controlled variants with a single source-of-truth English document and a translation cadence triggered off source updates.

Three-Channel Delivery - Why One Is Not Enough

The DCWP rule permits any of three channels, but defensible practice deploys all three. The job-posting embed catches candidates who apply directly from a job board or search-engine result. The careers-webpage post catches candidates who navigate to the employer's site. The in-application notice (delivered at submission or via post-submission email) catches every applicant individually and creates a per-candidate audit record of receipt, which DCWP's 2026 substantive review treats as the strongest evidence of compliance. The audit log preserved by the ATS captures the per-candidate timestamp.

The 10-business-day clock matters. A candidate scored the same day as application fails the requirement, even with a careers-page notice live for months. The compliant pattern: notice received at minimum 10 business days before scoring. For rolling-application postings, the careers-page-permanent post plus in-application notice satisfies this provided scoring is scheduled at least 10 business days after submission. For batch-scored postings, the scheduler must enforce the 10-business-day floor against the latest applicant in each batch.

The Public-Facing Bias-Audit Summary - A Drafting Workshop

The DCWP rule requires the bias-audit summary to be posted in a "prominent location" on the public-facing employment section of the employer's website, and to remain there for at least six months after the most recent date of AEDT use. Content specified: the date of the most recent audit; the source and explanation of the data used; the number of individuals assessed in each demographic category; selection rates per category; impact ratios per category; distribution date of the audit. The 2026 enforcement posture treats single-line "audit passed" summaries as substantively non-compliant.

The minimum-viable template, tunable to the specific AEDT:

[Employer name] - AEDT Bias Audit Summary
Published: [date]; covering the audit dated [audit date]; auditor: [independent auditor name and firm]

Scope. This summary covers the bias audit of [AEDT name and version], which [employer name] uses to assist with hiring decisions for [job category or categories]. The audit was conducted by [independent auditor name], who is independent of the AEDT vendor and of [employer name] within the meaning of the DCWP rule (independence attestation on file).

Methodology. The auditor computed selection rates and impact ratios by sex (male, female, non-binary where data permits), by race/ethnicity (the seven EEO-1 categories: Black or African American, Hispanic or Latino, White, Asian, Native Hawaiian or Pacific Islander, American Indian or Alaska Native, Two or More Races), and by intersectional sex × race/ethnicity combinations where the sample size supported statistically meaningful comparison (N ≥ [threshold]). The four-fifths rule (EEOC Uniform Guidelines, 1978) was applied: selection rate for each group divided by the selection rate for the highest-selecting group; impact ratio below 0.80 triggers an adverse-impact inference. Data was sourced from [historical candidate data spanning DD-MM-YYYY through DD-MM-YYYY / test data with rationale: ...]. Missing data was handled by [listwise deletion / inferred from name where consent obtained / etc.]. Statistical significance was assessed using [test name] at α = [value].

Demographic data table. Total candidates assessed: [N]. Distribution date: [date the AEDT result was distributed in the hiring funnel].

CategoryHeadcountSelectedSelection rateImpact ratio
Male[N][N][%]1.00 (reference)
Female[N][N][%][ratio]
Non-binary[N][N][%][ratio]
White[N][N][%]1.00 (reference)
Black or African American[N][N][%][ratio]
Hispanic or Latino[N][N][%][ratio]
Asian[N][N][%][ratio]
Native Hawaiian or Pacific Islander[N][N][%][ratio]
American Indian or Alaska Native[N][N][%][ratio]
Two or More Races[N][N][%][ratio]

Intersectional results. [Table or narrative covering sex × race/ethnicity cross-tabs where N ≥ threshold.]

Findings and remediation. [Narrative, e.g., "Female impact ratio 0.78 falls below the 0.80 threshold. Black female intersectional impact ratio 0.62 falls substantially below the threshold. [Employer name] has implemented the following remediation: model retraining on de-biased training data scheduled for [date]; recruiter calibration training completed [date]; quarterly impact-ratio recomputation through [date] until ratios stabilize above 0.85."]

Next audit. The next independent bias audit is scheduled for [date]. Quarterly impact-ratio recomputations between audits are published at [URL].

Contact. Questions about this summary: [contact email]. Complaints: NYC Department of Consumer and Worker Protection, nyc.gov/dca.

Drafting decisions mirror the notice. Specificity is the operational requirement. Per-category numbers, not aggregate summaries, are mandatory. Methodology disclosure must be substantive, not boilerplate. Intersectional analysis must appear where the sample supports it. Remediation must be described where adverse impact is found; publishing impact ratios below 0.80 without describing remediation is the worst defensive posture. The "next audit" date and quarterly-recomputation cadence make the summary a living document.

"Prominent location" is the second routinely-failed element. A summary linked from a careers-page footer two clicks below the fold does not satisfy "prominent." DCWP's 2026 review treats deep burial as substantive non-compliance. Defensible placement is a top-level link from the careers landing page, one click from any job posting using the AEDT. The URL should be stable so links from notices and the compliance brief remain valid.

The Alternative-Assessment Offer - A Drafting Workshop

LL 144 requires the notice to inform the candidate of the right to request an alternative selection process or reasonable accommodation. The ADA and the NYC Human Rights Law independently require reasonable accommodation where a disability would otherwise prevent equal participation. The intersection, a candidate requesting an alternative selection process because of a disability the AEDT does not accommodate, is the legally-protected baseline. Defensible practice extends the offer to any candidate requesting a non-AI selection path; operational cost is low and defensive value (against LL 144 enforcement and adjacent civil claims) is high.

The minimum-viable template:

Alternative selection process - your options

[Employer name] offers candidates the option to request an alternative selection process for the [job title or category] role. The alternative selection process consists of [description, e.g., a paper-based screening of your resume and cover letter, evaluated by two members of our recruiting team without AEDT scoring; followed by the same interview and assessment stages as the standard process]. The alternative selection process does not affect your standing in the candidate pool: candidates who complete the alternative process are evaluated against the same job criteria as candidates who complete the standard process, and progress through the same hiring stages.

When to request the alternative process. You may request the alternative process for any reason. Common reasons include: a disability that affects your interaction with AI-scored assessments; a religious or cultural objection to AI-driven evaluation; a preference for human review. You do not need to disclose your reason to make the request.

How to submit a request. Email [HR Accommodations Coordinator, email] with the subject line "Alternative selection process request, [job title], [your name]". Include your application reference number if you have one. We will respond within [response window, e.g., five business days] confirming receipt and outlining the next steps.

Reasonable accommodation requests under the ADA and NYC Human Rights Law. If your request is connected to a disability, we will process it under our reasonable accommodation procedures, which include an interactive process to identify accommodations that enable equal participation. We may request medical documentation to support the accommodation as permitted by law. The accommodation will be provided unless it would impose an undue hardship.

Confidentiality. Requests for an alternative process or accommodation are kept confidential within the recruiting and accommodations teams; they are not shared with hiring managers and they do not affect the substantive evaluation of your candidacy.

Questions. Contact [HR Accommodations Coordinator name, email, and phone].

Three design choices distinguish the defensible offer from the perfunctory one. First, the alternative process must be described concretely, "human-only review by two recruiters" is meaningful; "an alternative will be provided" is not. Second, the response timeline must be committed in writing and tracked operationally; the L2 implementation includes an SLA dashboard. Third, confidentiality must be honored operationally, accommodation-request data siloed from the hiring-manager ATS view, with audit logs preserving the boundary.

The Article 86 EU AI Act overlay (right to explanation for individual automated decisions) extends the alternative-assessment thinking. The L2 library should include an explanation template: a structured response describing the AEDT's input features, the weight assigned to each, the reason for the score, and the candidate's recourse options. Design it paired with the alternative-assessment offer.

Annex III §4 Employment Overlay - What the EU AI Act Adds

Annex III §4 classifies AI systems used in employment as high-risk: recruitment or selection (including targeted job advertisements, filtering applications, evaluating candidates); decisions affecting terms of work-related relationships, promotion, or termination; task allocation based on individual behavior or personal traits; monitoring and evaluating performance and behavior. The list maps onto LL 144 AEDT scope plus performance management, employment-monitoring, and task-allocation systems central to modern HR-tech.

Deployer obligations touching candidate-facing disclosure concentrate in Articles 26 and 50. Provider obligations (Articles 8-21) sit upstream and feed the deployer's evidence base via Article 13 instructions for use. High-risk classification triggers Article 14 human-oversight design, which the candidate-notice and alternative-assessment templates operationalize.

Article 26 - Deployer Obligations

Article 26(1) requires using the system per provider instructions. Article 26(3) requires operational monitoring and incident notification to the provider. Article 26(4) requires representative input data. Article 26(5) requires record-keeping. Article 26(6), the candidate-facing piece, requires informing workers' representatives and affected workers before deployment; for hiring, "affected workers" reads onto candidates and the candidate notice is the operational mechanism. Article 26(7) requires the FRIA for certain deployer categories. Article 26(11) requires cooperation with competent authorities, the same evidence base supports regulator inquiries.

Article 50(1) - Chatbot Disclosure

Article 50(1) requires natural persons interacting with an AI system designed to interact with humans (the "chatbot" pattern) be informed of that fact, unless obvious from context. The hiring application covers conversational-AI screeners, where candidates interact with an AI agent that asks structured questions and feeds the assessment into the AEDT. The candidate notice should include explicit Article 50(1) language where the AEDT includes a conversational-AI front end: "Some stages of this process involve interaction with an AI agent rather than a human recruiter. The AI agent will identify itself at the start of any conversation."

Article 86 - Right to Explanation

Article 86 grants individuals affected by a decision taken on the basis of high-risk AI system output that produces legal or similarly significant effects a right to obtain a clear and meaningful explanation of the role of the AI system in the decision and the main elements of the decision taken. For hiring decisions, which produce significant effects on the candidate's employment prospects, the right applies. The L2 candidate-disclosure template library should include an explanation template invocable on candidate request, structured around: the features the AEDT used; the relative weight of those features; the resulting score or classification; the threshold and the candidate's relationship to it; and the candidate's recourse options (alternative assessment, accommodation request, complaint channels).

Articles 13 and 14 - Provider Information and Human Oversight

Article 13 requires providers to supply instructions for use that allow the deployer to interpret outputs, identify capabilities and limitations, and design human-oversight measures. Without them, the deployer cannot adequately specify the AEDT in the notice or design the alternative-assessment process. The procurement playbook requires Article 13 instructions as a contract deliverable; their absence signals vendor non-readiness for EU deployment.

Article 14 requires high-risk AI systems to be designed for effective natural-person oversight. For hiring AEDTs, the operational expression is the human reviewer in the loop: the recruiter who evaluates the score and applies judgment, the accommodations coordinator, the bias-audit reviewer. The notice's "supports, but does not replace, human review" language is the surface expression of Article 14, and operational reality must match the surface claim.

Cross-Jurisdiction Overlay - One Disclosure Stack, Eight Regulators

A multi-jurisdiction employer faces overlapping candidate-disclosure obligations. The defensible design, covered in lesson 015's compliance-brief template, produces one source-of-truth disclosure stack with jurisdiction-specific overlays rather than per-jurisdiction silos. The stack:

  • NYC Local Law 144, Annual bias audit; 10-business-day candidate notice; public bias-audit summary; alternative-assessment offer. Enforced by DCWP under the 2026 post-Comptroller posture.
  • EU AI Act Annex III §4, Article 26(6) information to workers' representatives and affected workers; Article 26(7) FRIA (Dec 2, 2027 for stand-alone Annex III; immediate for public-body deployers); Article 50(1) chatbot disclosure; Article 86 right to explanation; Article 13/14 provider instructions and human oversight.
  • Texas TRAIGA HB 149, Intent-based discrimination prohibition for AI used in consequential decisions; effective January 1, 2026. Adds an intent-screening documentation requirement that overlaps the LL 144 methodology disclosure.
  • Colorado SB 24-205 / SB 189: SB 24-205 federally stayed (April 27, 2026); SB 189 replacement legislation pending (effective January 1, 2027 if signed). The disclosure stack should accommodate re-applicability without redesign.
  • Illinois AI Video Interview Act, Pre-interview notice; explicit candidate consent; data-retention limits. The candidate notice template's data-collection paragraph must satisfy Illinois consent language for video-interview AI.
  • Maryland Facial Recognition Hiring Act (HB 1202), Pre-employment facial-recognition consent. Where the AEDT includes facial analysis (video-interview emotion AI, identity verification), Maryland's consent language must be added.
  • California state-law overlay, Civil Rights Department draft regulations on automated decision-making in employment (under review through 2026). Design the notice to absorb California-specific language as the regulations finalize.
  • EEOC Title VII, Federal disparate-impact analysis applies to all AEDTs; the bias-audit summary's per-category numbers feed the disparate-impact analysis. The alternative-assessment offer supports the less-discriminatory-alternative defense.

The template library design: one English-language source-of-truth notice with placeholder slots for jurisdiction-specific language; one bias-audit summary template capturing all DCWP-mandated numerical elements with overlay sections for EU FRIA evidence references; one alternative-assessment offer with the EU Article 86 explanation extension; and one operational workflow routing candidates through the correct combination by jurisdiction and AEDT modality (text, video, facial analysis, chatbot). The L2 artifact is this entire stack as a library, not a single document.

Refresh Cadence - Disclosures Are Living Documents

The single most common 2026 enforcement finding for employers with otherwise-compliant disclosures is staleness. A bias-audit summary published in January 2025 with January 2025 numbers, still live in January 2026, fails the "most recent audit" requirement. A candidate notice that references the 2024 AEDT version when the vendor has shipped a 2026 version with new input features fails the specificity requirement. A bias-audit summary that does not reflect the impact-ratio drift detected in the most recent quarterly recomputation fails the substantive accuracy requirement. The defensible refresh cadence operates on four triggers:

  • Annual at minimum. The independent bias audit refreshes annually; the summary refreshes at the same cadence with the new numbers, methodology updates, and remediation status. The candidate notice refreshes annually to reflect any changes in the AEDT version, data categories, or retention rules.
  • On bias-audit results. Where the audit reveals adverse impact, the summary must reflect the finding plus the remediation plan; the notice may require update if remediation changes the data collected or the qualifications assessed.
  • On regulatory developments. A new DCWP rule clarification, a new EU AI Act delegated act, a new Texas TRAIGA enforcement guidance, or a new EEOC guidance triggers a review cycle. The L2 governance calendar tracks regulator publication schedules and triggers reviews on publication.
  • On candidate feedback. Substantive candidate questions or complaints, about confusing notice language, about an unresponsive accommodation contact, about a difficult-to-find bias-audit summary, trigger an iteration cycle. The L2 implementation tracks candidate-facing complaints as a continuous-improvement input.

The refresh cadence requires owners. Talent Acquisition owns the notice's operational delivery; the Responsible AI Officer owns the summary's substantive content; Employment Counsel owns the alternative-assessment offer's legal review; the DPO owns cross-jurisdiction overlay coordination. The L2 governance artifact names these owners and the trigger-driven review cadence in writing.

Six Common Disclosure-Drafting Mistakes

Mistake 1 - Vague Notice Language

"We use AI in hiring" is not a candidate notice. "We use machine learning tools to screen candidates" is not a candidate notice. The DCWP-compliant notice names the AEDT, describes what it assesses, enumerates the data categories collected, identifies the data source, describes retention, and identifies the alternative-assessment contact. Generic language fails substantive 2026 review.

Mistake 2 - Missing One of the Three Notification Channels

An employer that posts the notice on the careers page but omits the in-application notice loses the per-candidate audit record of receipt. An employer that includes the notice in individual emails but omits the job-posting embed fails to reach candidates who apply directly from job-board search results. The defensible practice uses all three channels for redundancy and audit-record completeness.

Mistake 3 - Insufficient Detail on Data Collected

"We collect data from your application" is not the data-disclosure paragraph. The DCWP-compliant version enumerates the categories (resume content, cover letter, structured assessment responses, video-interview recordings if applicable, skills-test responses) and what is not collected (protected characteristics, biometric data without separate consent). The Article 13 EU overlay extends the enumeration to the AEDT's input feature engineering: what derived features the tool computes from the raw data, where those features come from in the source data, and what the resulting feature vector looks like in plain English.

Mistake 4 - No Alternative-Assessment Process

An employer that references the right to request an alternative process in the notice but has not designed and operationalized the alternative process fails on the operational side. When the first candidate request arrives, the employer has nothing to offer. The defensible practice designs and dry-runs the alternative process before publishing the notice; the L2 artifact includes the operational workflow (request intake, accommodation interactive process, alternative-process scheduling, response timeline tracking, confidentiality controls).

Mistake 5 - Static Disclosures Without Refresh

A disclosure stack published in 2024 and untouched through 2026 fails on the "most recent audit" requirement, on the AEDT-version specificity requirement, and on the regulatory-development tracking requirement. The L2 implementation builds the refresh cadence into the governance calendar with named owners and trigger-driven review cycles.

Mistake 6 - Missing Cross-Jurisdiction Overlay

An employer that produces an LL 144 candidate notice and posts it for NYC candidates while running a separate Illinois-only video-interview consent flow, a separate California disclosure, and no EU AI Act overlay accumulates inconsistent evidence across regimes. The DCWP-required language and the Illinois-required consent language do not contradict each other; the defensible design integrates them into a single template with jurisdiction-specific blocks rather than producing them as separate artifacts.

The L2 Artifact - A Per-Jurisdiction Candidate-Disclosure Template Library

The L2 deliverable is not a single document. It is a template library that the Talent Acquisition team can deploy at posting time, the Responsible AI Officer can audit at refresh time, and the Employment Counsel can defend at regulator-inquiry time. The library contains:

  • The source-of-truth candidate notice in English, with jurisdiction-specific overlay blocks for NYC LL 144, EU Annex III §4, Texas TRAIGA, Illinois AI VIA, Maryland HB 1202, California (as regulations finalize). Each AEDT in the inventory has its own instantiation; the source-of-truth document is the editable master.
  • Multi-language variants of the source-of-truth notice in NYC's priority languages (Spanish, Mandarin, Russian, Bengali, Haitian Creole, Korean, Arabic, French), with translation-update triggers off the English source.
  • The bias-audit summary template with the DCWP-mandated structure (date, methodology, demographic data table with per-category headcounts/selection-rates/impact-ratios, intersectional results, findings and remediation, next audit, contact). One instance per AEDT with quarterly impact-ratio recomputation slots.
  • The alternative-assessment offer template with the operational workflow (request intake, accommodation interactive process, alternative-process design, response timeline tracking, confidentiality controls). One instance per AEDT, with the Article 86 EU explanation extension where deployment includes EU candidates.
  • The three-channel delivery configuration for the ATS: the job-posting embed code, the careers-webpage CMS template, the in-application notice trigger, plus the per-candidate audit-record schema preserving receipt timestamps.
  • The refresh cadence calendar with named owners, trigger definitions, and review-cycle SLAs.
  • The complaint-channel routing for the DCWP intake form, the EEOC channel, the FTC channel, and the state-specific channels where applicable.

The library is version-controlled in the governance repository alongside the LL 144 compliance brief, the AI vendor risk policy, the AI model inventory, and the AI intake form. A single AEDT inventory entry links to: the model card; the vendor risk assessment; the bias-audit artifacts; the candidate-disclosure stack; the cross-jurisdiction overlay; and the next-review calendar. Audit-cost reduction is real; regulator-inquiry response time is measured in hours, not days; candidate-experience consistency is preserved across postings and jurisdictions.

Aligning the Disclosure Stack With ISO 42001 and NIST AI RMF

The candidate-disclosure stack maps cleanly onto ISO/IEC 42001:2023 Annex A controls and NIST AI RMF 1.0 functions. The candidate notice and the alternative-assessment offer together satisfy ISO 42001 Annex A control A.9.3 (information for interested parties), and overlap with A.9.4 (reporting concerns). The bias-audit summary's publication satisfies A.6.2 (AI system impact criteria) when scoped to the employment use case, and overlaps with A.9.2 (information for affected persons). The NIST AI RMF mapping: candidate notice satisfies function Govern 5.1 ("Organizational policies and processes are in place to address AI risks arising from third-party software"), the bias-audit summary satisfies Measure 2.11 ("Fairness and bias are evaluated and documented"), and the alternative-assessment offer satisfies Manage 3.2 ("Mechanisms for redressing impacted parties are implemented"). The refresh cadence satisfies Manage 4.1 (post-deployment monitoring).

Write the disclosure stack once. Cite it across NYC LL 144 + EU AI Act Annex III §4 + Texas TRAIGA + Illinois AI VIA + Maryland HB 1202 + California overlay + EEOC Title VII + ISO 42001 A.6.2/A.9.2/A.9.3/A.9.4 + NIST AI RMF Govern 5.1/Measure 2.11/Manage 3.2/Manage 4.1. The audit-cost reduction is real. The candidate-experience consistency is real. The L2 template library is the artifact that makes both possible.

Key Takeaways

  • Three distinct disclosure artifacts. The 10-business-day candidate notice; the public-facing bias-audit summary on the careers webpage; the alternative-assessment offer. Conflating them is the most common drafting mistake. Treating them as silos is the second.
  • The 10-business-day notice requires specificity. Name the AEDT; describe what it assesses; enumerate the data categories collected; identify the data source; describe retention; name the alternative-assessment contact. Generic "we use AI in hiring" disclosures fail substantive 2026 DCWP review.
  • Deploy all three notification channels. Job-posting embed + careers-webpage post + in-application notice. The in-application notice creates the per-candidate audit record of receipt that the 2026 enforcement posture treats as the strongest compliance evidence.
  • Multi-language deployment is the NYC defensive default. Spanish, Mandarin, Russian, Bengali, Haitian Creole, Korean, Arabic, French at minimum. Version-controlled translations triggered by English source updates.
  • The bias-audit summary needs the numbers. Per-category headcounts, selection rates, impact ratios; intersectional cross-tabs where N supports them; substantive methodology disclosure; remediation status where adverse impact is found; next-audit date. Single-line "audit passed" summaries fail substantive review.
  • "Prominent location" means prominent. Top-level link from the careers landing page; one click from any AEDT-using job posting; stable URL across years. Deep burial in footers is a substantive non-compliance finding under 2026 enforcement.
  • The alternative-assessment offer must be operational. Concrete description of the alternative process; named contact; committed response timeline; confidentiality controls. Design and dry-run before publishing the notice that references it.
  • EU AI Act Annex III §4 extends the obligations. Article 26(6) information to workers' representatives and affected workers; Article 26(7) FRIA (Dec 2, 2027 stand-alone; immediate for public bodies); Article 50(1) chatbot disclosure; Article 86 right to explanation; Article 13/14 provider instructions and human oversight.
  • Cross-jurisdiction overlay is a stack. NYC LL 144 + EU Annex III §4 + Texas TRAIGA + Colorado SB 24-205/SB 189 + Illinois AI VIA + Maryland HB 1202 + California + EEOC Title VII. One template library with jurisdiction-specific overlay blocks beats per-jurisdiction silos.
  • Refresh cadence on four triggers. Annual at minimum; on bias-audit results; on regulatory developments; on candidate feedback. Named owners; trigger-driven review SLAs. Static disclosures are stale disclosures and stale disclosures fail substantive review.
  • The L2 artifact is a per-jurisdiction template library. Source-of-truth candidate notice with overlay blocks; multi-language variants; bias-audit summary template; alternative-assessment offer template; three-channel delivery configuration; refresh cadence calendar; complaint-channel routing. Version-controlled in the governance repository alongside the LL 144 compliance brief, the AI vendor risk policy, and the AI model inventory.