FairScreen — The AI-Native Automated Employment Decision Tool Bias Audit & Multi-State Algorithmic Employment Compliance Engine

AI-native service business blueprint · Run date 2026-07-10 · Run #221 · Slug: aedt-bias-audit-compliance-engine

Final Decision: Blueprint

GO — BLUEPRINT

A done-for-you, AI-native bias-audit and multi-state algorithmic-employment-compliance desk purpose-built for the employers, HR leaders, and HR-technology vendors who use automated employment decision tools (AEDTs) — resume screeners, video-interview scoring models, candidate-ranking algorithms — to make or influence hiring, promotion, and termination decisions, and who now face a rapidly hardening, multi-jurisdiction patchwork of mandatory bias-audit, notice, and risk-assessment law: New York City's Local Law 144 (live and entering a stricter 2026 enforcement phase), Illinois's amended Human Rights Act AI provisions (effective January 1, 2026), and California's CCPA Automated Decisionmaking Technology regulations (binding January 1, 2027, with risk assessments due by December 31, 2027). The engine ingests an employer's or vendor's AEDT scoring data and applicant/candidate demographic data; runs an AI-driven statistical bias analysis against the applicable jurisdiction's test (New York City's four-fifths-rule impact-ratio test, Illinois's notice-and-discrimination framework, California's risk-assessment and opt-out framework); is certified by an independent human auditor (a statistician or industrial-organization psychologist with no financial interest in the AEDT or the employer, satisfying each law's independence requirement); and delivers a publishable bias-audit summary, jurisdiction-specific employee/candidate notices, and a standing multi-state compliance calendar — priced per-tool, per-audit-cycle, and via an annual multi-state monitoring subscription, never hourly. This is not a duplicate of any of this factory's 220 prior outputs, including its closest adjacent output (the EU AI Act conformity-file engine, run #94, which serves EU AI-system providers under an entirely different regulatory regime, buyer, and workflow) — no prior run has addressed U.S. employment-law algorithmic-discrimination compliance.

Executive Summary

96%
U.S. hiring professionals who use AI in at least some recruiting task, incl. resume screening Verified
$500-$1,500/day
NYC DCWP civil penalty range under Local Law 144, per violation, per day for continuing non-compliance Verified
17 of 32
Employers with potential Local Law 144 non-compliance found by an independent review, vs. 1 flagged by the city agency's own audit Verified
3 binding mandates by 2027
NYC (live 2023), Illinois (live Jan 1, 2026), California (binding Jan 1, 2027) — each with a distinct bias-audit, notice, or risk-assessment obligation Verified
$1.48M
Seed round closed July 2025 by Warden AI, the leading AI-native AEDT bias-audit platform, evidencing investor-validated budget in this category Verified
15%
Share of audited AI hiring systems found to fail fairness metrics for at least one demographic group across 150+ published Warden AI bias audits Verified

Adoption of AI in hiring is now the norm, not the exception: 96% of U.S. hiring professionals use AI in at least some recruiting task, 82% of companies that use AI in hiring apply it to resume review, and 43% of organizations used AI in HR tasks in 2025, up from 26% in 2024. Verified Regulation has not kept pace with adoption, but it is now closing the gap on an overlapping, multi-year timeline: New York City's Local Law 144 has required an annual independent bias audit and public results summary for any AEDT used to screen NYC-resident candidates since January 1, 2023, with civil penalties of $500 to $1,500 per day for continuing violations and law firms warning of a materially stricter enforcement posture in 2026. Verified Illinois's amended Human Rights Act took effect January 1, 2026, requiring covered employers to notify employees and applicants whenever AI is used to "influence or facilitate" a covered employment decision. Verified California's CCPA Automated Decisionmaking Technology regulations, finalized by the CPPA in September 2025, require risk assessments, pre-use notices, opt-out rights, and appeal rights for employers using ADMT for "significant decisions" including hiring, promotion, and termination, with compliance required by January 1, 2027 and civil penalties up to $2,500 per violation ($7,500 for intentional violations). Verified Colorado's SB24-205 AI Act was twice delayed and has now been substantially rewritten as SB 189 (signed May 14, 2026, effective January 1, 2027), illustrating that this is a live, still-forming regulatory area rather than a settled one — a dynamic this blueprint treats as a structural risk to manage, not a reason to wait. Verified A December 2025 New York State Comptroller audit found that the city's own enforcement review had identified just one instance of potential non-compliance among 32 employers reviewed, while an independent review of the same 32 employers identified at least 17 instances of potential non-compliance — evidence of both a large compliance gap and an enforcement mechanism about to close it. Verified Existing help is split between a small number of early, thinly-capitalized AI-native audit platforms (Warden AI: $1.48M seed, July 2025) and traditional manual consulting/audit firms (BABL AI, DCI Consulting, and larger professional-services firms such as Deloitte) charging custom, unpublished, non-per-unit fees — leaving a genuine, still-open window for an AI-native, multi-state, per-tool-priced compliance engine.

Thesis

An AEDT bias audit is a retrospective statistical exercise, not a real-time employment decision — the buyer hands over historical scoring and demographic data and receives back a certified fairness assessment and a set of jurisdiction-specific notices, never asking the vendor to operate the hiring tool itself. Inferred, consistent with how NYC LL144 and comparable audits are structured and marketed by existing providers This is exactly the shape this factory has repeatedly validated: a document-and-deadline-driven regulatory-response workflow, gated by a real independence/credentialing chokepoint (an "independent auditor" under NYC LL144, with no financial interest in the AEDT or the employer, is a defined legal requirement, not a nice-to-have), where the bulk of the labor — data ingestion and cleaning, adverse-impact-ratio computation across every required demographic category, jurisdiction-specific notice drafting, and deadline calendaring across a widening multi-state patchwork — is mechanical and AI-automatable, while true judgment concentrates at a small number of chokepoints: the independent auditor's certification of the statistical methodology and result, and a documented decision about which jurisdictions actually apply to a given employer's hiring footprint. Unlike a single-state, single-deadline compliance product, this is a structurally compounding opportunity — a third, fourth, and fifth state (Illinois live now, California in 2027, Colorado's rewritten SB 189 in 2027, and other states with bills pending) are each adding new, distinct audit, notice, or risk-assessment obligations on an overlapping but non-identical multi-year calendar, meaning the addressable compliance surface area grows every year the underlying AI-hiring-adoption trend continues, which every surveyed indicator says it will.

Discovery Rationale

This run explored five candidates before selecting the AEDT bias-audit and multi-state algorithmic-employment-compliance engine: a special-needs-trust (SNT) Medicaid/SSI-benefit-preserving disbursement compliance engine for professional trustees, a FinCEN beneficial-ownership-information (BOI) reporting engine for foreign reporting companies, a DEA telemedicine special-registration compliance engine for controlled-substance prescribers, a PDMP-integrated controlled-substance diversion-monitoring compliance engine for independent pharmacies, and the AEDT bias-audit engine described here. The SNT engine had a real, well-documented compliance burden (SSA POMS trust-accounting and disbursement-reporting rules; state Medicaid reporting requirements) but requires direct custody of, or fiduciary authority over, a beneficiary's funds — a high-trust-burden, judgment-dense role already occupied by chartered corporate trustees, and one where an AI-native, non-fiduciary vendor would face serious licensing and liability friction. Inferred The FinCEN BOI engine had a clear statutory framework, but the March 2025 interim final rule narrowed the "reporting company" definition to exclude all U.S. companies and U.S. persons, leaving only foreign entities registered to do business in a U.S. state in scope — collapsing what was, in 2024, a mass-market opportunity into a small, already crowded niche as most 2024-era BOI-compliance vendors pivoted or shut down. Verified The DEA telemedicine special-registration engine tracks a genuinely important gap (DEA has now issued four consecutive temporary extensions of pandemic-era telemedicine controlled-substance prescribing flexibilities, most recently through December 31, 2026, while its proposed permanent Special Registration rule remains unfinalized), but a rules engine built against a still-proposed, repeatedly-delayed regulation has no stable compliance target, and the underlying subject matter sits close enough to prescribing/medical practice judgment to raise unauthorized-practice concerns if not scoped very narrowly. Verified The PDMP diversion-monitoring engine had a real regulatory mandate but is already served by an entrenched, near-universal incumbent infrastructure layer (Bamboo Health's NarxCare/PMP AWARxE platforms are integrated into most state PDMP systems), leaving thin competitive whitespace for a new entrant. Inferred The AEDT bias-audit engine won because it combines a documented, near-universal underlying AI-hiring-adoption trend (96% of hiring professionals), an already-binding and actively-enforced legal mandate (NYC LL144, live since 2023, entering stricter 2026 enforcement) layered with two more binding mandates arriving on a known multi-year calendar (Illinois, live; California, 2027), a real independence/credentialing chokepoint that functions as a genuine moat, live private litigation pressure (Mobley v. Workday) reinforcing the legal risk independent of any single regulator's enforcement posture, and a competitive field of thinly-capitalized AI-native entrants and expensive manual consultants rather than an entrenched dominant platform.

Candidate Comparison

Five candidates generated and scored 1-5 across 20 standard criteria.

CriterionAEDT bias audit & multi-state algorithmic employment compliance engineSpecial-needs-trust Medicaid/SSI disbursement compliance engineFinCEN BOI foreign-reporting-company engineDEA telemedicine special-registration compliance enginePDMP diversion-monitoring compliance engine
1. Low trust burden42433
2. Low task-level judgment42433
3. High intelligence threshold53243
4. Regulation as moat53324
5. No physical labor55555
6. Sam Altman test53243
7. Outcome-pricing potential42333
8. Gross-margin potential53444
9. Buyer urgency42223
10. Competitive whitespace42132
11. Novelty vs prior 220 outputs55555
12. Fit with current AI capability53444
13. Active demand evidence42223
14. Existing budget/competitor proof43224
15. Waitlist/lead-magnet potential42232
16. Narrow MVP wedge clarity53423
17. Distribution-channel clarity32222
18. Licensing feasibility42423
19. Operational repeatability43434
20. Speed to first revenue42323
Total (max 100)8754626066

Why runners-up lost: SNT disbursement engine — requires direct fiduciary custody/authority over beneficiary funds, a high-trust, judgment-dense role already occupied by chartered corporate trustees. FinCEN BOI engine — the March 2025 interim final rule narrowed the reporting-company definition to foreign entities only, collapsing the addressable market and leaving a crowded field of vendors built for the pre-2025 mass-market version of the rule. DEA telemedicine engine — the controlling Special Registration rule remains proposed, not final, after four consecutive temporary extensions, offering no stable compliance target and edging toward unauthorized-practice-of-medicine adjacent judgment. PDMP diversion-monitoring engine — a real mandate, but already served by Bamboo Health's near-universal NarxCare/PMP AWARxE infrastructure layer integrated into most state PDMP systems, leaving thin whitespace for a new entrant.

CODE Validation

C — Consumer/Buyer Trend

Two converging 2025-2026 developments have simultaneously raised AI-hiring-tool adoption and hardened the legal consequences of deploying one without an audit trail. First, adoption itself: 96% of U.S. hiring professionals now use AI in at least some recruiting task, 82% of companies using AI in hiring apply it to resume screening specifically, and 62% of companies expect AI to run their entire hiring process by the end of 2026. Verified Second, legal exposure: Mobley v. Workday — filed February 2023, granted preliminary ADEA collective-action certification in May 2025, and still generating fresh discovery rulings as of May-June 2026 — has established that an AEDT vendor itself can be held directly liable for employment discrimination under an "agent" theory, meaning both employers and AEDT vendors now share exposure, not just the employer alone. Verified Both developments point buyers (HR/talent-acquisition leaders at employers, and product/compliance leaders at HR-technology vendors) toward the same urgent question: can we prove, with an independently certified statistical audit, that this specific tool does not produce a disparate impact — before a regulator or a plaintiff's attorney asks first.

O — Opportunity

The current help landscape splits into three categories, none of which fully occupies this engine's specific multi-state, per-tool, AI-native wedge: a small number of early AI-native audit platforms (Warden AI, which by its own description has "no direct tech competitors" and instead names Credo, ModelOp, and Patronus — general AI-governance platforms, not AEDT-employment-law specialists — as its closest comparators) still early-stage and enterprise-weighted in go-to-market; traditional manual consulting/audit firms (BABL AI, DCI Consulting, and larger professional-services firms including Deloitte) that provide credible independent audits but price custom, unpublished engagements without a productized multi-state compliance layer; and general HR-compliance or employment-law counsel who can advise on the notice requirements but typically do not perform the underlying statistical bias audit themselves. Verified No identified vendor combines AI-native data-ingestion and adverse-impact computation, jurisdiction-specific notice/risk-assessment drafting across NYC, Illinois, and California in one continuously updated engine, and per-tool flat-fee-plus-subscription pricing purpose-built for the mid-market employer or HR-tech vendor that cannot justify an open-ended consulting engagement before knowing whether its tool even needs an audit. Inferred (whitespace characterization)

D — Demand

Demand is direct and statutorily triggered: any employer using an AEDT to screen NYC-resident candidates must commission an annual independent bias audit and publish a summary before using — or continuing to use — the tool, or face DCWP civil penalties of $500 to $1,500 per day for continuing violations. Verified Illinois employers using AI to "influence or facilitate" a covered employment decision must provide notice as of January 1, 2026, with the Department of Human Rights tasked to adopt enforcement rules. Verified California employers subject to the CCPA using ADMT for hiring, promotion, or termination decisions must complete risk assessments by December 31, 2027 and provide pre-use notices, opt-out rights, and appeal rights beginning April 1, 2027, backed by penalties up to $7,500 per intentional violation. Verified A December 2025 New York State Comptroller review found a large gap between DCWP's own enforcement findings (1 of 32 employers reviewed) and an independent review of the same employers (at least 17 of 32) — exactly the kind of documented enforcement-gap-about-to-close pattern this factory has repeatedly used as an active-demand signal, reinforced here by law firms explicitly warning clients to expect materially stricter 2026 enforcement. Verified

E — Economic Sizing

No single published source aggregates the exact population of U.S. employers subject to one or more of these mandates, so this section is explicitly constructed and labeled Inferred. Starting from the verified base that 96% of U.S. hiring professionals use AI in some recruiting task and that NYC alone — the largest single metropolitan labor market in the U.S., with several hundred thousand active employer establishments — triggers LL144 for any employer (regardless of headquarters location) that uses an AEDT to screen even one NYC-resident candidate, the near-term addressable population for a NYC-nexus bias audit plausibly runs into the tens of thousands of employers annually. Inferred Layering in Illinois's broader notice mandate (covering every employer using AI to influence any covered employment decision statewide, not just AEDTs meeting NYC's narrower "substantial factor" definition) and California's 2027 ADMT risk-assessment requirement (covering every CCPA-regulated business — generally those with over $25M in annual revenue or processing personal data on 100,000+ consumers — using ADMT for employment decisions) each independently adds a materially larger population on a known multi-year calendar. Inferred Modeling a blended $6,000-$20,000 average first-year revenue per engaged client (a single-tool NYC LL144 audit plus notice package, or a broader multi-state monitoring subscription for larger, multi-jurisdiction employers and HR-tech vendors) against a realistic three-year book of 250-800 client engagements implies a constructed serviceable wedge of roughly $6M-$25M in three-year cumulative revenue, with the addressable base structurally expanding, not contracting, as Illinois enforcement rules finalize and the California ADMT deadline approaches. Inferred

Rubric Scorecard (Six Gates)

Gate 1 — Low Trust Burden: 4/5

The buyer hands over historical AEDT scoring output and applicant/candidate demographic data and receives back a certified statistical audit and drafted notices — the vendor never operates the hiring tool, makes an employment decision, or touches an active candidate pipeline in real time; the one meaningful trust element is handling sensitive protected-class demographic data responsibly, addressed directly in the risk register.

Gate 2 — Low Task-Level Judgment: 4/5

The workflow decomposes cleanly: data ingestion and cleaning, adverse-impact-ratio computation across every required demographic category and intersectional subgroup, jurisdiction-applicability screening, and notice/risk-assessment drafting are largely mechanical once data is structured; true judgment concentrates at the independent auditor's certification of statistical methodology and at documented jurisdiction-applicability calls for employers with an ambiguous hiring footprint.

Gate 3 — High Intelligence Threshold: 5/5

Correctly executing a defensible bias audit requires synthesizing the applicable jurisdiction's specific legal test (NYC's four-fifths-rule impact-ratio calculation methodology, Illinois's notice-and-discrimination framework, California's significant-decision and meaningful-human-involvement analysis), statistical best practice for adverse-impact testing across small-sample and intersectional subgroups, and a fast-moving, multi-jurisdiction body of guidance and case law (the May 2026 Mobley discovery rulings, the CPPA's finalized ADMT rules) — a genuinely difficult, multi-domain reasoning task that benefits materially from frontier-model synthesis paired with expert statistical review.

Gate 4 — Regulation as a Moat: 5/5

NYC LL144's mandatory annual audit by a legally defined "independent auditor," Illinois's statutory notice mandate, and California's CPPA-adopted risk-assessment and opt-out framework together form a dense, jurisdiction-specific compliance framework that a generalist HR-compliance vendor or general-purpose AI-governance platform cannot casually replicate — genuine legal and statistical specialization, plus the independence credential itself, is required to operate credibly and lawfully in this space.

Gate 5 — No Physical Labor: 5/5

Every step — data intake, statistical analysis, drafting, and delivery — is conducted remotely via secure document/data exchange; no on-site presence at an employer's or vendor's office is ever required.

Gate 6 — Sam Altman Test: 5/5

As frontier models improve at extracting structure from heterogeneous AEDT scoring exports, computing and explaining adverse-impact statistics across more demographic categories and intersectional subgroups, and synthesizing a growing, fast-moving body of state-specific AI-employment law, the engine's audit rigor, jurisdictional coverage, and drafting speed improve directly; the durable, anti-commoditization asset is the maintained, versioned library of jurisdiction-specific compliance rules, AEDT-vendor data-format connectors, and audit-disposition/enforcement-outcome history built case by case — none of which a generic frontier model or a new entrant replicates simply by getting smarter.

Anti-commoditization check

A generic LLM prompted with a spreadsheet of hiring outcomes can already produce a plausible-sounding fairness summary; it cannot reliably determine which of an overlapping, non-identical set of state and municipal AEDT/ADMT laws actually apply to a specific employer's hiring footprint, correctly compute a legally defensible adverse-impact ratio across every required subgroup with appropriate small-sample handling, or maintain the "independent auditor" status the law itself requires — the moat is the accumulated jurisdictional-rules data, the audit-methodology rigor, and the credentialed independence, not the underlying model.

Target Buyer

AttributeDetail
ICPA mid-market-to-enterprise U.S. employer (typically 250-10,000 employees) that uses one or more automated employment decision tools (resume-screening algorithms, video-interview scoring models, candidate-ranking systems) to screen candidates who may reside in NYC, Illinois, or California, or an HR-technology vendor whose AEDT product is deployed by such employers and who must supply bias-audit and compliance documentation to its own enterprise customers.
Economic buyerThe VP/Head of Talent Acquisition, Chief People Officer, or HR-technology vendor's Head of Product/Compliance — frequently acting alongside in-house or outside employment counsel who can advise on notice obligations but typically does not perform the underlying statistical audit.
Trigger eventExpansion of AEDT use into NYC, Illinois, or California hiring; an approaching annual LL144 audit-renewal deadline (audits expire exactly one year after they are conducted); Illinois's January 1, 2026 notice-mandate effective date; the approaching California ADMT risk-assessment deadline; an enterprise customer's procurement/vendor-security review demanding proof of an independent bias audit; a competitor's or peer company's publicized bias-audit finding or lawsuit.
Budget sourceExisting HR-compliance, talent-acquisition-technology, or vendor-risk-management budget; for HR-technology vendors, existing trust-and-safety or compliance-certification budget already spent on SOC 2 and similar third-party attestations, extended to cover the AEDT-specific bias-audit requirement their own enterprise customers increasingly demand.

Jobs-to-be-Done

Painful Problem

An employer or HR-technology vendor that uses an automated employment decision tool to screen, rank, or score candidates now faces a rapidly hardening, non-identical, multi-jurisdiction legal patchwork — NYC's mandatory annual independent bias audit (live since 2023, civil penalties of $500-$1,500/day, stricter 2026 enforcement expected), Illinois's employee/applicant notice mandate (effective January 1, 2026), and California's risk-assessment, notice, opt-out, and appeal framework (binding January 1, 2027) — while having no reliable, affordable, AI-native way to determine which laws actually apply to their specific hiring footprint, commission a legally sufficient independent audit, or draft the required notices on the correct cadence. Verified A December 2025 government audit found that the gap between what employers believe they have complied with and what an independent reviewer finds is large (1 of 32 vs. at least 17 of 32 employers reviewed), and Mobley v. Workday has now established that AEDT vendors themselves — not just the employers who deploy their tools — can be held directly liable for discrimination under an agent theory, meaning the exposure is shared and growing on both sides of the buyer relationship. Verified Existing help is either an unaffordable, custom-quoted engagement with a manual audit/consulting firm, an enterprise-first AI-native platform not yet built for the mid-market or for the multi-state notice-drafting layer, or no specialized help at all — leaving many employers and vendors either non-compliant by default or paying for a narrow, single-jurisdiction audit that leaves the rest of the patchwork unaddressed.

The Outcome We Sell

We sell an independently certified statistical bias audit of an employer's or vendor's AEDT, a jurisdiction-applicability screen showing exactly which of NYC's, Illinois's, and California's (and any other applicable state's) laws apply to the specific hiring footprint in question, the drafted candidate/employee notices and publishable audit-summary each law requires, and a standing multi-state compliance calendar that tracks every audit-renewal and notice-refresh deadline going forward — delivered as a finished, independently certified work product the buyer can publish and act on immediately, not a self-serve statistics dashboard they must interpret and legally validate themselves.

First One-Feature MVP Wedge

Evidence Summary

Every core claim in this blueprint is backed by a live 2025-2026 source and cross-checked against at least one independent publisher where possible: NYC Local Law 144's requirements, penalties, and enforcement posture (NYC DCWP, the NY State Comptroller's December 2025 audit, DLA Piper, Warden AI); Illinois's amended Human Rights Act AI provisions (Hinshaw & Culbertson, Seyfarth Shaw, the National Law Review, Workforce Bulletin); California's CCPA ADMT regulations (Littler, Akin Gump, Skadden, the CPPA itself); the EEOC's four-fifths-rule guidance and its 2025 enforcement-posture shift (Fisher Phillips, FordHarrison, K&L Gates); Mobley v. Workday's status and agent-theory liability holding (Akin Gump, Forbes, Duane Morris, Seyfarth Shaw); AI-hiring-adoption statistics (SQ Magazine's aggregation of Resume Now and SHRM survey data, the Interview Guys); and existing competitor/budget evidence (Warden AI's Crunchbase-verified funding and published audit volume, BABL AI's and DCI Consulting's public service pages). No figure in this blueprint was invented; ranges are shown where sources vary, and constructed market-sizing figures are explicitly labeled Inferred rather than Verified.

Claim Table

ClaimLabelNotes
NYC Local Law 144 requires an annual independent bias audit of any AEDT used to screen NYC-resident candidates, effective January 1, 2023, actively enforced by DCWP since July 5, 2023, with civil penalties of $500 (first violation) to $1,500/day (continuing violations)VerifiedNYC DCWP official page and FAQ; multiple law-firm client alerts
Law firms are warning employers to expect a materially stricter 2026 enforcement phase for LL144VerifiedWarden AI compliance guide; multiple 2026 employment-law client alerts
A December 2025 NY State Comptroller audit found DCWP's own review identified 1 potential non-compliance instance among 32 employers, while an independent review of the same 32 identified at least 17VerifiedNY State Comptroller enforcement audit, Dec 2, 2025; DLA Piper analysis, Jan 2026
Illinois's amended Human Rights Act AI provisions took effect January 1, 2026, requiring notice to employees/applicants whenever AI is used to influence or facilitate a covered employment decision, with annual notice and 30-day post-update notice requirementsVerifiedHinshaw & Culbertson; Seyfarth Shaw; National Law Review; Illinois General Assembly HB3773 bill status
California's CPPA finalized CCPA Automated Decisionmaking Technology regulations in September 2025; employer compliance (risk assessments, pre-use notices, opt-out, and appeal rights for "significant decisions" including hiring/promotion/termination) required by January 1, 2027, with risk assessments due by December 31, 2027; penalties up to $2,500/violation ($7,500 intentional)VerifiedLittler; Akin Gump; Skadden; CPPA official announcement, Sept 23, 2025
Colorado's SB24-205 AI Act was postponed twice (to June 30, 2026) and then substantially rewritten as SB 189, signed May 14, 2026, effective January 1, 2027VerifiedClark Hill; The Employer Report; Akin Gump AI Law Tracker; Norton Rose Fulbright
The EEOC's four-fifths rule is the standard rule-of-thumb guideline for identifying adverse impact in a selection procedure (a selection-rate ratio below 80% for a protected group signals possible disparate impact)VerifiedEEOC technical-assistance guidance summarized by Fisher Phillips, FordHarrison, K&L Gates
An April 2025 federal executive order directed the EEOC to deprioritize disparate-impact-only enforcement, though private plaintiffs retain full Title VII standingVerifiedFisher Phillips 2025-2026 EEOC AI guidance analysis
Mobley v. Workday: filed Feb. 21, 2023; granted preliminary ADEA collective-action certification May 16, 2025; a May 2026 discovery ruling found attorney-client privilege protects Workday's own bias-testing data while denying compulsion of customer applicant data; courts have held AEDT vendors can be directly liable under an "agent" theoryVerifiedAkin Gump AI Law Tracker; Forbes (May 2026); Duane Morris Class Action Defense blog (June 2026); Seyfarth Shaw
96% of U.S. hiring professionals use AI in at least some recruiting task; 82% of companies using AI in hiring apply it to resume review; 43% of organizations used AI in HR tasks in 2025 (up from 26% in 2024); 62% expect AI to run their entire hiring process by end of 2026VerifiedSQ Magazine aggregation of Resume Now and SHRM survey data; Interview Guys
Warden AI, an AI-native AEDT bias-audit platform, closed a $1.48M seed round in July 2025 (total raised $2.34M) and has completed 150+ published bias audits, finding 15% of audited systems fail fairness metrics for at least one demographic groupVerifiedCrunchbase; TechFundingNews; Warden AI published research page
BABL AI and DCI Consulting operate as manual independent-auditor service providers for NYC LL144 compliance; pricing is custom-quoted and not publicly listedVerifiedBABL AI and DCI Consulting websites; G2 AI Bias Audit Services category
The enterprise AI-governance-and-compliance software market was valued at $2.20B (2025), projected to $2.55B (2026) and $11.05B by 2036 (15.8% CAGR); the narrower standalone AI-governance market was valued at $308.3M (2025), projected to $417.8M (2026) and $3.59B by 2033 (36.0% CAGR)VerifiedFuture Market Insights; Precedence Research (two independent market-research estimates, shown as a range given typical cross-firm variance)
Constructed near-term addressable population (tens of thousands of NYC-nexus employers annually, expanding materially as Illinois and California obligations phase in) and constructed 3-year serviceable revenue wedge of $6M-$25MInferredDerived from verified adoption, mandate, and enforcement data; no single source aggregates this exact figure

Source-Claim Matrix

ClaimLabelSourceTypeDateConfidenceUsed In
NYC LL144 requirements and penaltiesVerifiedNYC DCWP official page/FAQ; DLA Piper; Warden AIGovernment agency page; law-firm/vendor analysis2023-2026Highs3, s4, s7, s11, s15, s22
NY State Comptroller enforcement-gap auditVerifiedNY State Comptroller (Dec 2025); DLA Piper (Jan 2026)Government audit; law-firm analysisDec 2025-Jan 2026Highs3, s7, s11, s15, s17
Illinois HB3773/Human Rights Act AI provisionsVerifiedHinshaw & Culbertson; Seyfarth Shaw; National Law Review; Illinois General AssemblyLaw-firm client alerts; legislative record2025-2026Highs3, s7, s9, s15, s22
California CCPA ADMT regulationsVerifiedLittler; Akin Gump; Skadden; CPPALaw-firm client alerts; government agency announcementSept 2025-2027Highs3, s7, s9, s15, s22
Colorado SB24-205/SB189 delay and rewriteVerifiedClark Hill; The Employer Report; Akin Gump AI Law Tracker; Norton Rose FulbrightLaw-firm client alerts2025-2026Highs4, s5, s15, s55
EEOC four-fifths rule and 2025 enforcement posture shiftVerifiedFisher Phillips; FordHarrison; K&L GatesLaw-firm client alerts summarizing EEOC guidance2023-2026Highs7, s15, s23, s55
Mobley v. Workday status, agent-theory liabilityVerifiedAkin Gump; Forbes; Duane Morris; Seyfarth ShawLaw-firm analysis; legal-affairs journalism2023-2026Highs3, s7, s11, s15, s19
AI-in-hiring adoption statisticsVerifiedSQ Magazine (aggregating Resume Now/SHRM); Interview GuysSurvey aggregation/trade press2025-2026Medium-Highs3, s4, s7, s15
Warden AI funding and audit-volume evidenceVerifiedCrunchbase; TechFundingNews; Warden AIFunding database; trade press; vendor research page2025Highs3, s15, s19, s20
BABL AI/DCI Consulting competitor positioningVerifiedVendor websites; G2Vendor website; review aggregator2025-2026Highs15, s19, s20
AI-governance/compliance software market sizingVerifiedFuture Market Insights; Precedence ResearchMarket-research reports2025-2026Medium (cross-firm estimate variance typical for early-stage categories)s15, s17
Addressable employer population and 3-yr revenue wedgeInferredDerived by this analysis from verified adoption/mandate dataConstructed estimate2026Mediums7, s38

Market and Demand Evidence

AI-hiring adoption is not a marginal or slowing trend: 96% of hiring professionals use AI in some recruiting task today, and 62% of companies expect AI to run their entire hiring process by the end of 2026, meaning the population of employers with an AEDT-audit obligation grows structurally alongside adoption rather than shrinking. Verified The regulatory surface is compounding, not static: NYC's mandate is live and entering stricter enforcement, Illinois's notice mandate is now live, and California's risk-assessment mandate arrives on a known date less than 18 months away as of this run — a multi-year calendar of new, non-identical obligations that keeps expanding the addressable compliance surface. Verified The AI-governance/compliance software category itself shows strong, independently estimated growth (multiple market-research firms projecting double-digit-to-36% CAGR through the early 2030s), consistent with the broader "tightening global regulatory frameworks are driving procurement demand" pattern cited across those reports. Verified

Active Buyer Conversations

Employment-law and HR-technology trade press and law-firm client-alert programs are actively publishing guidance aimed directly at this buyer population: Hinshaw & Culbertson, Seyfarth Shaw, and the National Law Review each published distinct 2025-2026 client alerts on Illinois's new AI-notice mandate; Littler, Akin Gump, and Skadden each published distinct 2025-2026 alerts on California's ADMT regulations; and DLA Piper's January 2026 analysis of the NY State Comptroller's enforcement-gap audit was explicitly framed as a warning to employers of "increased risk." Verified Warden AI's own published research (150+ audits, a 15% system-level fairness-failure rate) functions as ongoing, vendor-published proof that buyers are actively commissioning and publishing these audits today, not merely being advised to consider them. Verified

Competitive Landscape

CategoryExamplesWhat they sellGap vs. this engine
Early AI-native AEDT audit platformsWarden AI ($1.48M seed, July 2025; 150+ published audits)An audit-and-certification platform combined with continuous, embedded AI-system monitoring, positioned primarily toward larger, more sophisticated HR-tech buyersEnterprise-weighted go-to-market and pricing; by its own account, no dedicated multi-state notice-drafting layer covering Illinois's and California's distinct obligations alongside NYC's audit requirement
Manual independent-audit and HR-compliance consulting firmsBABL AI, DCI Consulting, Deloitte's LL144 practiceCredible, credentialed independent bias audits, custom-quoted and typically delivered via a traditional consulting engagementNo productized, AI-native, per-tool flat-fee pricing; slower, more expensive per-engagement delivery; not structured as a continuously updated multi-state compliance subscription
General HR-compliance/employment-law counselExisting outside counsel relationships at the employerAdvice on notice obligations and legal risk; refers the underlying statistical bias audit to a specialistDoes not perform the statistical audit itself; typically bills hourly; no integrated multi-jurisdiction tracking layer

Competitor and Budget Validation

Budget for AEDT bias-audit and AI-governance work is independently validated on both the investor and buyer side: Warden AI's $1.48M 2025 seed round (institutional investor Playfair Capital participating) is direct evidence that professional investors underwrite recurring revenue in this exact category, and its 150+ completed, published audits are direct evidence employers already pay for and publish this work today. Verified BABL AI's and DCI Consulting's ongoing operation as paid independent-audit providers, and Deloitte's own LL144 practice, further confirm this is an active, professionally billed market rather than a speculative one. Verified The proposed engine does not compete for the general AI-governance-platform category (Warden AI names Credo, ModelOp, and Patronus — not itself — as its closest competitors); it targets the specific, still-underserved intersection of AI-native audit delivery, mid-market pricing, and multi-state (not single-jurisdiction) notice and risk-assessment drafting.

Pricing Evidence and Proposed Pricing

Published per-unit pricing does not exist in this category — every identified provider (Warden AI, BABL AI, DCI Consulting) quotes custom fees scaled by the number of AEDTs in scope and data complexity, disclosed only on request. Verified Proposed pricing here is therefore benchmarked against comparable third-party technical-compliance-audit categories with similar scope and credentialing requirements (e.g., SOC 2 Type II readiness/audit engagements typically run $10,000-$60,000; HIPAA Security Risk Analysis engagements typically run $5,000-$15,000) and structured in three tiers, all flat or subscription-based — never hourly: (1) a flat $4,000-$9,000 AEDT Bias Audit & LL144 Compliance Scan per tool per audit cycle (single tool, clean data); (2) a flat $8,000-$25,000 Multi-State Algorithmic Employment Compliance Package, adding Illinois notice drafting and California ADMT risk-assessment preparation for employers or vendors with a multi-state hiring footprint; and (3) a $6,000-$30,000/year Multi-State Compliance Monitoring Subscription, scaled by employee count and number of AEDTs in use, covering annual audit renewal, notice refreshes, and continuous jurisdiction-applicability tracking as new state laws phase in. Inferred, benchmarked against comparable third-party technical-compliance-audit fee norms; no direct published AEDT-audit pricing exists to verify against This pricing is structured to remain well below the cost of a custom-quoted manual consulting engagement while paying for genuine statistical rigor and a maintained "independent auditor" credential, never resold as a share of any legal fee or litigation outcome.

Regulatory and Compliance Considerations

The controlling regulatory framework is jurisdiction-specific and still actively forming: NYC Local Law 144 and its implementing DCWP rules (mandatory annual independent bias audit, public summary, and candidate notice, testing against the EEOC's four-fifths adverse-impact guideline); Illinois's amended Human Rights Act AI provisions (mandatory employee/applicant notice, annual and post-update refresh requirements, enforcement rules still being adopted by the Illinois Department of Human Rights); California's CPPA-adopted CCPA ADMT regulations (mandatory risk assessments, pre-use notices, opt-out and appeal rights for "significant decisions," binding January 1, 2027); and the EEOC's non-binding four-fifths-rule technical guidance, now operating in an environment where a 2025 executive order has directed the agency to deprioritize disparate-impact-only enforcement even as private Title VII litigation (Mobley v. Workday) continues to expand vendor-side liability theory. Verified Colorado's twice-delayed, since-rewritten SB24-205/SB189 illustrates that this entire regulatory area remains in active flux, making a versioned, continuously updated jurisdiction-rules layer a compliance-critical, not merely convenient, function of the engine. Verified

Licensing Boundary

AI-Native Advantage

LayerTask
AIAEDT scoring-data and demographic-data ingestion, cleaning, and schema normalization across heterogeneous ATS/AEDT export formats; adverse-impact-ratio computation across every required demographic category and intersectional subgroup; jurisdiction-applicability screening against a versioned multi-state rules library; first-draft bias-audit report, publishable summary, and jurisdiction-specific notice/risk-assessment generation; deadline extraction and multi-state compliance calendaring.
Deterministic rulesFour-fifths-rule threshold calculator per demographic category; jurisdiction-applicability decision tree (NYC substantial-factor test, Illinois influence-or-facilitate test, California significant-decision/meaningful-human-involvement test); annual audit-renewal and notice-refresh deadline calculator; data-completeness checks before independent-auditor review.
Human (production staff)Client intake and data-collection coordination; data-format troubleshooting with the client's ATS/AEDT vendor.
Human (independent-auditor chokepoint)Final certification of statistical methodology and result; sign-off on the published audit summary.
Human (employment-counsel referral, client-side)Legal review of notices/risk assessments before publication; legal-liability judgment on any bias finding.

Internal AI Engine Architecture

1. IntakeAEDT scoring output and applicant/candidate demographic data ingested per client, per tool, per audit cycle.
2. NormalizationStandardize heterogeneous ATS/AEDT export formats into a common analysis schema.
3. Retrieval/KnowledgeVersioned library of jurisdiction-specific AEDT/ADMT rules (NYC, Illinois, California, and emerging states), EEOC four-fifths guidance, and enforcement/litigation disposition history (Mobley and comparable matters).
4. AI WorkbenchAdverse-impact-ratio computation, jurisdiction-applicability screening, notice/risk-assessment drafting, audit-summary generation.
5. Deterministic RulesFour-fifths-threshold calculator; jurisdiction decision tree; annual renewal/notice-refresh deadline calculator; data-completeness checks.
6. Human Chokepoint (Independent Auditor)Certification of statistical methodology and result; sign-off on publishable summary.
7. QACompleteness and consistency check on every deliverable before release.
8. DeliveryCertified bias-audit report, publishable summary, drafted notices/risk assessments, multi-state compliance calendar.
9. Learning LoopAuditor corrections and enforcement/litigation outcomes feed back into the jurisdiction-rules library and drafting templates.
10. Model PortabilityRetrieval and rules layers are model-agnostic; the underlying LLM can be swapped without rebuilding the engine.

AI-vs-Human Operations Pipeline

IntakeAI-assisted, human-confirmed
Adverse-impact computationAI-generated
Statistical-methodology certificationHuman (independent auditor)
Notice/risk-assessment draftingAI-generated
Multi-state deadline monitoringAI-tracked, human-verified
Legal review of published disclosuresHuman (client's employment counsel, referred)
Publishable-summary preparationAI-generated, human-reviewed

Dynasty Translation Layer

Buyer translation

The employer or HR-tech vendor pays for one thing: certainty, backed by an independent auditor's certification, that its AEDT does not create disparate-impact exposure, delivered together with every notice and disclosure the applicable jurisdictions require, without needing an in-house statistician or an open-ended consulting engagement to get there.

Service translation

Customer receives an independently certified bias-audit report, a publishable summary, and jurisdiction-specific notices/risk assessments; automation handles data ingestion, statistical computation, and drafting; the credentialed independent auditor and, where needed, the client's own employment counsel handle certification and legal review.

Workflow translation

Intake scoring/demographic data → normalize → compute adverse-impact ratios → screen jurisdiction applicability → independent-auditor certification → draft notices/summary → deliver to client → monitor multi-state renewal deadlines → refer legal review of publication to client counsel → renew annual audit and refresh notices as new jurisdictions phase in.

Tooling translation

Document/data workbench for ingestion and statistical computation; a jurisdiction-rules knowledge base; a deadline-calendaring rules engine; a secure client data vault for sensitive demographic data; an independent-auditor review-and-certify workflow; a publishable-summary export format.

Sales translation

"Your AEDT audit either doesn't exist, is about to expire, or doesn't cover the states you actually hire in. We'll deliver an independently certified audit and every required notice within 10 days — for one flat fee, per tool."

Delivery translation

Launch manually for the first 5 clients using a shared statistical workbench and a contracted independent auditor; automate data normalization, computation, and drafting once patterns across AEDT vendors and jurisdictions stabilize.

Expansion translation

Evolve into a broader algorithmic-employment-compliance practice covering additional states as new AI-employment laws phase in, AEDT-vendor-side fairness certification sold directly to HR-tech platforms for distribution to their enterprise customers, and adjacent ADMT categories (credit, insurance, tenant screening) reusing the same statistical-audit and jurisdiction-rules architecture.

Anti-Duplication Analysis

This is not a duplicate of this factory's prior EU AI Act conformity-file engine (run #94, which serves AI-system providers under the EU's product-safety-style AI regulatory regime, an entirely different buyer, workflow, and jurisdiction) or its prior HR/employment-compliance-adjacent outputs (COBRA administration, background-screening FCRA compliance, I-9/E-Verify, pay-equity transparency, wage garnishment, and MHPAEA parity analysis all address distinct, non-AI-specific employment compliance domains); it is also not a generic AI-governance-consulting or AI-safety-platform service, since it is purpose-built as an AI-native statistical bias-audit and multi-state notice/risk-assessment desk for the specific U.S. algorithmic-employment-discrimination compliance workflow, with a narrow MVP wedge (the single-tool NYC LL144 Bias Audit & Compliance Scan) that no identified incumbent sells as a standalone, productized, flat-fee, multi-state-aware offer.

Anti-Commoditization Analysis

As frontier models make individual adverse-impact computation and first-draft notice generation trivially cheap, the durable asset shifts to the maintained, versioned library of jurisdiction-specific AEDT/ADMT rules (which states and cities require what, on what cadence, under what applicability test), AEDT-vendor data-format connectors that reduce manual data-wrangling friction, and the accumulated audit-disposition and enforcement/litigation-outcome history (which fact patterns have drawn DCWP scrutiny, which statistical arguments have held up in Mobley-style discovery disputes) — none of which a generic model or a new self-serve entrant replicates simply by getting smarter or cheaper.

Service Delivery Workflow

Intake → scoring/demographic-data normalization → AI adverse-impact computation across required categories and subgroups → jurisdiction-applicability screening → independent-auditor certification → AI notice/summary drafting → delivery to client → publication support → multi-state deadline monitoring → annual renewal and notice refresh as new jurisdictions phase in.

Operations as Product

Every audit follows the same structured intake checklist, the same adverse-impact-computation and jurisdiction-screening decision logic, and the same independent-auditor certification gate; exceptions (small-sample subgroups requiring alternative statistical handling, ambiguous multi-state hiring footprints, novel AEDT scoring-data formats) route to a defined exception queue rather than ad hoc handling, with every computation, draft, and certification logged in an audit trail the client and any referred counsel can reference if the audit is later challenged or discovered in litigation.

No-Holes Quality Engine

What the Human Expert Actually Does

TaskLicense/credential requiredMin/unit at launchMin/unit day 90Automation pathQuality riskCannot automateAudit trail
Statistical-methodology certificationIndependent statistician / industrial-organization psychologist meeting each law's independence definition5020AI-computed adverse-impact ratios with confidence scoring and cited data sourcesCertifying a statistically unsound audit exposes both the client and the auditor to regulatory and litigation riskFinal certification of methodology and resultLogged statistical rationale citing specific data sources and computation method
Jurisdiction-applicability determination for ambiguous hiring footprintsIndependent auditor, employment-counsel review recommended3012AI-screened applicability checklist against the versioned multi-state rules libraryMissing an applicable jurisdiction leaves the client non-compliant without their knowledgeFinal determination on ambiguous multi-state factsLogged applicability rationale
Publishable-summary and notice reviewIndependent auditor; client employment counsel for final legal sign-off2510AI drafting from jurisdiction-specific templates and the rules libraryAn incorrect or incomplete notice exposes the client to the same penalties the audit was meant to preventFinal review before delivery to clientVersion-controlled draft history
Small-sample/intersectional-subgroup statistical judgmentIndependent statistician2010AI-flagged small-sample cases routed automatically to statistician reviewMisapplied statistical handling of small subgroups can produce a misleading pass/fail resultFinal statistical-method selection for edge casesLogged methodology decision and rationale

Minimum Viable Offer

The AEDT Bias Audit & LL144 Compliance Scan: a flat one-time fee that ingests a client's AEDT scoring and applicant-demographic data, computes adverse-impact ratios across every required category, and delivers an independently certified bias-audit report, publishable summary, and candidate notice within 10 business days — the on-ramp to the full Multi-State Algorithmic Employment Compliance Package and standing monitoring subscription.

Fulfillment Process

Manual/semi-manual for the first 5 clients using a shared statistical workbench and a contracted independent auditor; automate data normalization, computation, and drafting once patterns across AEDT vendors and jurisdictions stabilize across the pilot cohort.

Tools and Systems

Human-in-the-Loop Quality Control

No bias-audit report or publishable summary is delivered without independent-auditor certification of the statistical methodology and result; every small-sample subgroup, novel data format, or ambiguous jurisdiction-applicability question above a defined severity threshold routes to auditor review before a report is finalized; any published disclosure is explicitly flagged for the client's own employment-counsel review before publication.

Nonlinear Scaling and Unit Economics

50%+
Target gross margin by month 12
35%→65%
Automation share, launch to month 12
$6,000-$20,000
Blended average first-year revenue per engaged client
250-800
Target 3-year client engagement volume

Distribution Proof Table

ChannelWhy reachableFirst messageConversion assumptionProof sourceMeasurementFollow-up
Employment-law and HR-tech-vendor referral partnershipsOutside employment counsel routinely advises on notice obligations but does not perform the underlying statistical audit and must refer it out"Refer your clients' AEDT audit needs to us; we deliver the certified statistical work, you keep the legal-review relationship"10-18% partner-referred close rateDocumented pattern of counsel referring specialist statistical/audit workReferral-source trackingCo-branded client onboarding
HR-technology vendor marketplace and integration partnershipsATS/AEDT vendors' enterprise customers increasingly demand proof of an independent bias audit during procurement"Give your enterprise customers a certified audit they can hand to their own compliance teams during renewal"8-15% vendor-referred close rateDocumented enterprise procurement demand for third-party AEDT attestationsVendor-partner trackingReusable certification package for distribution
Trade press and HR-compliance content (SHRM-adjacent, talent-acquisition, HR-tech media)HR and TA leaders actively follow AI-hiring-compliance coverage given the pace of 2025-2026 legal developmentsBylined explainer: "Does your AEDT need a Local Law 144 audit — and does Illinois or California apply to you too?"2-3% content-to-leadActive 2025-2026 trade-press and law-firm client-alert volume on this exact topicArticle-attributed leadsFree jurisdiction-applicability screen CTA
Direct outreach to employers with known NYC/IL/CA hiring footprints using AEDTsJob postings and ATS technology usage (frequently visible via job-board metadata and vendor case studies) make AEDT-using, multi-state employers identifiablePersonalized note referencing the employer's likely LL144/Illinois/California exposure and audit-renewal timing3-5% outbound-to-meetingPublicly documented AEDT vendor customer lists and job-posting technology signalsMeetings bookedScan-based follow-up
Answer-engine and search visibilityHR/TA leaders and vendor compliance teams actively search "AEDT bias audit requirements," "NYC Local Law 144 compliance," "Illinois AI employment notice," "California ADMT employer requirements"Educational content answering exact buyer questions2-4% organic-to-leadDocumented search and trade-press interest pattern around each jurisdiction's mandateOrganic lead volumeLead-magnet scan signup

Sales and Outreach Plan

Lead with a free jurisdiction-applicability screen as a low-friction entry point that tells a prospect exactly which laws apply to their hiring footprint; convert screen recipients into the paid AEDT Bias Audit & LL144 Compliance Scan; pursue employment-counsel and HR-tech-vendor referral partnerships in parallel to build recurring warm inbound and outbound-referral flow.

Founder-Led Content Plan

Publish plain-English explainers on which AI-employment laws apply to which employers, how a four-fifths-rule bias audit actually works, what Mobley v. Workday means for both employers and AEDT vendors, and real (anonymized) audit-finding patterns, positioning the founder/lead auditor as the go-to voice for practical, multi-state AEDT compliance in the post-Mobley enforcement environment.

First 30 Days of Content

Lead Magnet and Waitlist Plan

Free AEDT Jurisdiction-Applicability Screen: prospect answers a short structured questionnaire about their AEDT use and hiring footprint; receives a personalized report showing exactly which of NYC, Illinois, and California's laws apply, current compliance status if determinable, and recommended next steps, converting into a paid bias-audit engagement.

Warm GTM Plan

Reach out to screen requesters, employment-counsel referral contacts, and HR-tech-vendor partners with a consultative review of their applicability screen and a scoped audit-engagement offer.

Targeted Outbound Plan

Identify AEDT-using, multi-state employers via job-posting technology signals, ATS/AEDT vendor case studies and customer lists, and self-identified inbound screen requests; personalize outreach around their specific likely jurisdictional exposure and audit-renewal timing; lead with a diagnostic offer, not a sales pitch.

Answer-Engine and Search Visibility Plan

Publish structured, clearly-labeled explainer content answering exact buyer questions ("do I need a Local Law 144 bias audit," "does Illinois's AI employment law apply to my company," "what does California's ADMT rule require for hiring") so the company surfaces in ChatGPT, Perplexity, and Google answer surfaces when HR/TA leaders and vendor compliance teams research their obligations.

Pilot Design and Early-Demand-Trap Mitigation

Cap the first pilot cohort at 5 clients, diversified across at least two buyer types (a direct employer and an HR-tech AEDT vendor) and two jurisdictional profiles (NYC-only exposure and multi-state NYC+Illinois exposure), to stress-test the statistical-computation and auditor-review workflow before expanding.

Early-Access Feedback Flywheel

Weekly review of every auditor correction during the pilot; corrections that recur across clients become new data-normalization rules, drafting templates, or QA checks; one-off client-specific requests (e.g., legal-liability opinions beyond the defined statistical/technical scope) are logged as counsel-referral items, not folded into the product.

Build-Before-Scale Checkpoints

7-Day Launch Plan

Days 1-2: finalize the adverse-impact-computation decision logic and jurisdiction-applicability rules for NYC, Illinois, and California; confirm the contracted independent auditor and at least one employment-counsel referral partner. Days 3-4: build the Bias Audit & Compliance Scan drafting workbench and publish the jurisdiction-applicability-screen landing page. Days 5-6: reach out to 20 target employers and HR-tech vendors via referral contacts and outbound with the free screen offer. Day 7: deliver first applicability screens and book engagement calls.

30-Day Launch Plan

Weeks 2-3: onboard first 2-3 pilot clients; complete first full audit-and-drafting cycle with independent-auditor certification. Week 4: deliver first bias-audit reports and notice packages; begin employment-counsel and HR-tech-vendor referral outreach; publish first 5 pieces of founder-led content.

90-Day Launch Plan

Month 2: reach 5-client pilot cap; hold the first build-before-scale checkpoint; formalize the auditor-review SOP. Month 3: expand to 10 clients if checkpoint metrics clear; launch the Multi-State Compliance Monitoring Subscription as a live feature; begin measuring automation-share progress toward the 50% day-90 target.

Metrics and KPIs

Risks and Mitigations

The dominant risk categories are the "independent auditor" conflict-of-interest boundary, the still-forming and occasionally reversed state-level regulatory landscape (Colorado's twice-delayed, rewritten AI Act being the clearest example), employer/vendor reluctance to commission a rigorous audit given litigation-discoverability concerns highlighted by Mobley, and independent-auditor capacity bottlenecks; each is addressed with a specific mitigation in the risk register below.

Exhaustive Risk Register

1. The audit function's independence is compromised by also selling AEDT-remediation consulting to the same client on the same tool, violating NYC LL144's and comparable laws' independence definitions (Medium likelihood, High impact)

Mitigation: a published, contractually binding independence policy; the audit arm never accepts remediation-consulting work from an audited client on the same tool during an active audit relationship or without a documented cooling-off period; remediation advisory work is offered only through a structurally separated engagement or referred to a separate firm.

2. State-level AI-employment regulation continues to be delayed, rewritten, or repealed mid-build, as Colorado's SB24-205 was (delayed twice, then substantially rewritten as SB189) (High likelihood for any single state, Medium impact)

Mitigation: build a state-agnostic core statistical-computation engine with a thin, independently versioned jurisdiction-rules layer per state/city that can be updated or removed without rebuilding the core; do not overweight revenue projections on any single pending-but-not-yet-binding state law; anchor near-term revenue on already-binding NYC and Illinois obligations.

3. Federal EEOC enforcement of disparate-impact theory is deprioritized by executive order, reducing perceived federal urgency (Medium likelihood, Medium impact)

Mitigation: pricing and demand thesis rest on state/local statutory mandates (NYC LL144, Illinois, California) and private Title VII litigation exposure (Mobley-style suits), not on active federal EEOC enforcement; monitor federal posture but do not depend on it for the core revenue case.

4. Employers or AEDT vendors refuse to share the underlying scoring and demographic data needed for a rigorous audit, citing trade-secret or privacy concerns, as Workday resisted producing bias-testing data in Mobley discovery (Medium-high likelihood, High impact)

Mitigation: standardized, legally grounded data-request templates and a documented audit-consent framework; offer tiered audit rigor (full-data audit vs. a lower-rigor, clearly labeled self-reported-metric review where full data access is refused); build direct data connectors to common ATS/AEDT platforms to reduce manual friction and the perceived burden of data-sharing.

5. An audit is later shown, in litigation or regulatory review, to have relied on incomplete or manipulated data, exposing the auditor to a negligent-certification claim (Medium likelihood, High impact)

Mitigation: professional/technology errors-and-omissions liability insurance from day one; explicit data-limitation disclaimers baked into every published summary; confidence-scored findings with a mandatory "insufficient data" outcome rather than a false-positive clean bill of health when data is incomplete.

6. Independent-auditor (statistician/I-O psychologist) capacity becomes a hard ceiling before automation share rises enough to support flat-fee, per-audit pricing (High likelihood, High impact)

Mitigation: cap pilot cohort growth strictly at the 5/10/20-client checkpoints; do not onboard new accounts ahead of measured auditor-minutes-per-case decline; maintain a fractional/contracted auditor panel as elastic overflow capacity.

7. A well-capitalized incumbent (Warden AI, or a large professional-services firm such as Deloitte or Mercer) moves down-market or adds a multi-state notice-drafting layer, eroding whitespace (Medium likelihood, Medium impact)

Mitigation: build the jurisdiction-rules library, AEDT-vendor data connectors, and referral relationships early to create switching costs; target the specific mid-market segment (250-5,000 employees) that Warden's enterprise-first motion and Deloitte's high-touch consulting pricing both currently underserve.

8. A commissioned bias audit finds a genuine disparate impact, and the resulting report becomes discoverable evidence against the client in litigation, deterring some buyers from commissioning a rigorous audit at all (High likelihood, Medium impact)

Mitigation: offer an optional privileged-audit track structured through the client's outside employment counsel where legally supportable (audit commissioned by counsel, findings potentially protected by attorney-client privilege/work product), alongside the standard non-privileged public-summary track the law requires; be transparent with clients up front about the discoverability trade-off of each track.

9. Scope creep into legal-liability opinions about Title VII or state discrimination law, raising unauthorized-practice-of-law exposure (Medium likelihood, High impact)

Mitigation: contractual scope limited strictly to statistical/technical audit work and jurisdiction-specific notice/risk-assessment drafting; legal conclusions about discrimination liability are explicitly out of scope and referred to the client's own employment counsel; the independent auditor certifies statistical findings only, never a legal-liability determination.

10. AEDT/ADMT definitions differ meaningfully across jurisdictions (NYC's "substantial factor" test, Illinois's "influence or facilitate" test, California's "significant decision"/"meaningful human involvement" test), creating scope disputes with clients about whether their tool is even covered (Medium likelihood, Medium impact)

Mitigation: the jurisdiction-applicability screen is delivered as the first, low-cost engagement step for every client, with a documented reasoning trail explaining exactly why a tool is or is not covered under each jurisdiction's specific test.

11. Data-security incident involving sensitive applicant demographic and protected-class data (Low-medium likelihood, High impact)

Mitigation: SOC 2-aligned security practices from day one; encrypted storage; least-privilege access; data-minimization policy retaining only aggregate statistics and purging raw PII post-audit where feasible.

12. Awareness of these obligations remains low among mid-market employers outside NYC, slowing demand growth even as Illinois and California obligations phase in (Medium likelihood, Medium impact)

Mitigation: content/education-led GTM explaining exactly which laws apply to which employers; partnerships with HR-technology vendors, staffing associations, and HR trade groups; pursue listing in ATS/AEDT vendor marketplace app stores to reach buyers at the point of tool adoption.

What Could Kill This

The single most structurally important risk is independent-auditor capacity becoming a hard ceiling before automation share matures enough to support the proposed flat-fee, per-tool pricing, forcing the business back toward an unscalable custom-consulting cost structure. Inferred A second, meaningful risk is that one or more of the still-forming state mandates this blueprint's multi-year revenue thesis depends on (Illinois's implementing rules, California's ADMT enforcement posture, any future Colorado SB189 rulemaking) is delayed, narrowed, or repealed the way Colorado's original SB24-205 was — mitigated by anchoring near-term revenue on the already-binding, already-enforced NYC mandate and treating additional states as upside rather than a load-bearing assumption. A third is that employer/vendor reluctance to commission a rigorous audit, driven by litigation-discoverability concerns of the kind surfaced in Mobley, suppresses demand for the highest-rigor (and highest-value) audit tier — mitigated by the optional privileged-audit track. A fourth, lower-probability risk is a well-capitalized incumbent (an AI-governance platform, a Big Four firm, or Warden AI itself) moving down-market with a comparable multi-state, per-tool-priced offer before this business establishes referral relationships and switching costs.

Go/No-Go Reasoning

This candidate clears the evidence threshold on every required dimension: a clearly identified target buyer (mid-market-to-enterprise employers and HR-tech vendors using AEDTs to screen candidates in NYC, Illinois, or California), a painful and specific problem (a rapidly hardening, non-identical multi-jurisdiction legal patchwork with real civil penalties and, via Mobley, real private-litigation exposure on both the employer and vendor side), verified evidence the problem exists and is severe (96% AI-hiring adoption, a documented compliance-enforcement gap of 17 of 32 employers, three binding mandates arriving on a known multi-year calendar), verified evidence buyers already spend money on adjacent solutions (Warden AI's $1.48M seed round and 150+ published audits, BABL AI's and DCI Consulting's ongoing operation, Deloitte's own LL144 practice), active demand evidence (recurring law-firm client-alert content aimed directly at this population following each new state mandate), competitor and budget validation (three distinct incumbent categories proving spend exists without occupying the AI-native, multi-state, mid-market wedge), a credible reason this service can win (AI-native statistical computation and drafting under independent-auditor-certified, counsel-referral-gated review, at a fraction of a custom-consulting engagement's cost, and broader in jurisdictional coverage than any single identified incumbent), a narrow MVP wedge (the single-tool NYC LL144 Bias Audit & Compliance Scan), a practical path to first sale (the free jurisdiction-applicability screen as a low-friction entry point), a service-delivery workflow fulfillable without a large custom software platform first, no unresolved fatal regulatory blocker (the licensing boundary requires independent-auditor certification for the statistical work and employment-counsel referral for any legal conclusion, and explicitly manages the independence/conflict-of-interest boundary the law itself imposes), a credible path to 50%+ gross margin (automation share rising from 35% to 65% over year one), and a believable distribution path (employment-counsel and HR-tech-vendor referrals, trade-press content, and direct outreach to a documented, describable population of AEDT-using employers). The one dimension requiring explicit, ongoing management rather than a one-time mitigation is the still-forming state-level regulatory landscape, which this blueprint addresses through a state-agnostic core engine with a thin, independently versioned jurisdiction-rules layer and by anchoring near-term revenue on the already-binding NYC and Illinois mandates rather than on any single pending state law.

Final Recommendation

Proceed to build FairScreen as described: launch the AEDT Bias Audit & LL144 Compliance Scan as the first offer within 7 days, cap the first pilot cohort at 5 clients diversified across at least two buyer types (direct employer and HR-tech vendor) and two jurisdictional profiles, and hold the 5/10/20-client build-before-scale checkpoints strictly before expanding intake or introducing the full Multi-State Algorithmic Employment Compliance Subscription and adjacent ADMT-category expansion at scale.

Source List