The AI Exposure Scan · Sample deliverable
This is what you get.
A complete sample snapshot for a fictional company, exactly as we deliver it: one page a decision-maker can act on, with the citations behind every line in the appendix. Yours is built from your scan answers within two business days.
AI Exposure Snapshot — Meridian Staffing
Summary
Three jurisdictions reach Meridian today or within 12 months: Illinois (live since January 1, 2026: the résumé scorer is covered by the state's effect-based AI-discrimination standard and its employee-notice duty), the EU (live since February 2025: the shortlists your Irish client receives make your screening output "used in the EU," which triggers the AI Act's baseline duties regardless of where Meridian sits), and Colorado (the ADMT Act's consumer duties arrive January 1, 2027). Federal civil-rights law applies throughout: Title VII and the ADA reach AI hiring tools today, and the 2025 withdrawal of agency guidance changed enforcement posture, not the statutes.
Alert
Chatbot screening determination needed (low effort, do it now). Your support chatbot is almost certainly excluded from Colorado's Chatbot Safety Act under the customer-service exclusion. But the exclusion has technical conditions, and the determination should exist in writing before the law's duties begin (C.R.S. § 6-1-1701(3.5), (15.5); duties from Jan 1, 2027).
Jurisdictions
Compliance calendar
- LIVEIllinois: effect-based discrimination standard, ZIP-code-proxy ban, employee notice (775 ILCS 5/2-102(L)) · EU: staff AI literacy + prohibited-practices screen (AI Act Arts. 4, 5)
- AUG 2 2026EU chatbot disclosure (AI Act Art. 50); applies if EU visitors interact with your site bot — confirm audience
- JAN 1 2027Colorado ADMT duties: pre-use notice, 30-day adverse-outcome explanation, human review on request, developer documentation at procurement (SB 26-189) · chatbot exclusion conditions take legal effect (HB 26-1263)
- DEC 2 2027EU high-risk deployer duties for the résumé scorer (AI Act Art. 26): use per provider instructions, trained oversight, input-data controls, log retention, worker and candidate notices
Obligations by control area
- Notices & disclosures · 4 obligations · nearest: IL employee notice (live)
- Human review & oversight · 2 obligations · nearest: CO human review (Jan 1, 2027)
- Bias testing & input review · 2 obligations · nearest: IL effect standard + ZIP-proxy ban (live)
- Training & literacy · 1 obligation · live (EU Art. 4)
- Vendor documentation & diligence · 2 obligations · nearest: CO developer docs (Jan 1, 2027)
- Screening determinations · 2 obligations: chatbot exclusion (write it down now) + EU prohibited-practices screen (live)
The single next step
Appendix — every obligation, cited
Illinois (live since Jan 1, 2026)
- 775 ILCS 5/2-102(L)(1)Using AI that has the effect of discriminating in covered employment decisions is a civil rights violation. No intent required; bias testing is the only way to know where the résumé scorer stands. Evidence a regulator would ask for: testing records and your response to findings.
- 775 ILCS 5/2-102(L)(1)ZIP codes may not be used as a proxy for protected classes. This reaches the data fields the model uses, so the question goes to your ATS vendor, in writing.
- 775 ILCS 5/2-102(L)(2)Employees and applicants must be told AI is used in covered decisions. The implementing rules are postponed, so the statutory duty stands without them; a plain-language notice in postings, the application flow, and the handbook satisfies its core demand. Evidence: the notice text and when and where it was delivered.
European Union (baseline live since Feb 2, 2025)
- Reg. (EU) 2024/1689, Art. 4Staff who operate AI systems need adequate AI literacy. Evidence: a training record naming who, what, and when.
- Art. 5The AI portfolio must be screened against the prohibited-practices list (none expected to apply at Meridian; the screen itself is the obligation and should be documented).
- Art. 50 (from Aug 2, 2026)Chatbots must disclose they are AI to the people interacting with them. Applies if EU visitors use your site bot; confirming your bot's audience is part of the determination.
- Art. 26 (from Dec 2, 2027)High-risk deployer duties for the résumé scorer (employment AI whose output is used in the EU): operate per the provider's instructions, assign trained human oversight with real authority, control input data quality, keep logs at least six months, and notify workers and affected candidates.
Colorado (duties from Jan 1, 2027)
- SB 26-189, pillar 1Consumers get pre-use notice that an ADMT participates in a consequential decision. Evidence: notice language and delivery proof.
- SB 26-189, pillar 2Adverse outcomes get a plain-language explanation within 30 days: the decision, the ADMT's role, the personal data used, and the consumer's rights.
- SB 26-189, pillar 3Meaningful human review on request: a trained reviewer with authority to approve, modify, or override, who considers primary evidence and does not default to the system's output.
- SB 26-189, pillar 4Developer documentation (intended uses, training-data categories, known limitations); for Meridian this is a procurement duty: require it from the ATS vendor.
- C.R.S. § 6-1-1701(3.5), (15.5)Chatbot applicability screen: covered services are public, companion-style conversational AI; customer-service and transactional bots are excluded, subject to technical conditions. The written determination is the deliverable here.
Federal (unchanged by the 2025 guidance rollback)
- Title VII · ADADiscrimination law reaches AI hiring tools today, enforced privately and by states even where agency guidance was withdrawn. The Illinois bias-testing work above is also your federal defense posture.