New York's Own Auditor Says AI Hiring Law Enforcement Isn't Working. That's Worse News for Indian Vendors, Not Better.
New York’s Own Auditor Says AI Hiring Law Enforcement Isn’t Working. That’s Worse News for Indian Vendors, Not Better.
On December 2, 2025, the New York State Comptroller released an audit of how the city’s Department of Consumer and Worker Protection has been enforcing Local Law 144 — the rule requiring bias audits for automated hiring tools. The finding: DCWP received only two complaints during the audit period and surveyed 32 companies’ bias-audit disclosures, flagging just one compliance issue. When the state’s own auditors reviewed the same 32 companies, they found at least 17 instances of potential non-compliance.
That gap — one issue found by the regulator versus seventeen found by an outside audit — is the headline. Most compliance coverage of this story reads it as good news for vendors: the cop isn’t watching closely, so relax. That reading gets it backwards.
Weak Enforcement Is a Leading Indicator, Not a Free Pass
Regulators that get publicly called out for under-enforcing a law don’t usually respond by quietly dropping it. They respond by tightening it, because the alternative is a second audit next year with the same embarrassing gap. DCWP has already committed to implementing most of the Comptroller’s recommendations — which means the companies that treated LL144 as a checkbox because enforcement was toothless are the ones most exposed when enforcement stops being toothless. Civil penalties under the law already run $500 to $1,500 per day per violation, and every day a tool runs without a valid audit counts as a separate violation; a stricter enforcement posture makes that number a live risk instead of a theoretical one.
This isn’t just a New York story. It’s evidence for a pattern that shows up in every AI-hiring jurisdiction with a disclosure or audit requirement on the books: the gap between “law exists” and “law is enforced” closes faster than vendors expect, and it closes retroactively — the audit trail a regulator asks for covers the period before enforcement tightened, not just after.
Why an India-Based Vendor Should Care About a New York City Law
We don’t sell into New York City. Most Indian AI screening vendors don’t, directly. But that’s the wrong lens. Global Capability Centres headquartered in Bangalore, Hyderabad, and Pune increasingly report into US and EU parent companies whose own procurement and legal teams are watching exactly this kind of enforcement news — and when a parent company’s compliance team gets nervous about AI hiring tools anywhere in its portfolio, the question flows downstream to every subsidiary using an AI screening vendor, regardless of which city’s law technically applies.
SHRM’s own 2025 survey found that 88% of HR leaders already see AI screening as a compliance risk — before this audit made the enforcement gap public. A story like the DCWP audit doesn’t create that anxiety. It confirms it, and confirmed anxiety travels into procurement conversations a lot faster than abstract anxiety does.
New York isn’t the only jurisdiction building this pattern, either. The EU AI Act already classifies hiring tools as high-risk, with its own audit and documentation obligations. Illinois’ HB 3773 took effect January 1, 2026, requiring employers to notify candidates whenever AI is used in a hiring decision. None of these laws reach India directly. All of them reach the multinational clients Indian GCCs and IT-services vendors sell into, which means the compliance bar an Indian AI screening vendor has to clear isn’t set by Indian law — it’s set by whichever of its customers’ jurisdictions has the strictest active enforcement environment that quarter.
What “Audit-Ready” Honestly Means Right Now
We’ll say the uncomfortable part plainly: HireQwik has not published an independent third-party bias audit. Almost no India-market AI screening vendor has, because the regulatory requirement to do so doesn’t exist here yet. What we have built is a screening decision that never rests on a single signal — an LLM evaluates what a candidate said, a separate audio-analysis layer evaluates how they said it, and both have to agree before the system recommends a reject. That’s a narrower claim than “audited,” and we’d rather make the narrower claim honestly than the bigger one we can’t back up.
If you’re evaluating an AI screening vendor right now — Indian or otherwise — the DCWP audit gives you a concrete question to ask that most vendors haven’t been asked yet: not “are you compliant with Local Law 144,” but “if a regulator investigated your last 32 customers the way New York’s auditors just did, how many issues would they find that your own compliance dashboard missed?” The vendors who can answer that plainly are the ones worth shortlisting. For more on what a defensible audit trail actually needs to contain, see the seven questions your legal team will ask.
For vendors, the practical response to a story like this isn’t a press release about compliance readiness. It’s going back through the last quarter’s rejected candidates and checking whether you could actually reconstruct, for each one, what evidence produced the decision. If that reconstruction takes a support ticket and three days instead of an export button, that’s the gap a stricter enforcement environment will find first — and it’s cheaper to close it now, on your own schedule, than during a customer’s compliance review on theirs.
Weak enforcement bought the industry time. It didn’t buy exemption. Talk to us if you want to see what an honest answer to that question looks like for your own screening process.
See HireQwik in action
Book a 30-minute demo — bring a live JD and we'll screen your own candidates against it.