FairScreen — The AI-Native Automated Employment Decision Tool Bias Audit & Multi-State Algorithmic Employment Compliance Engine
AI-native service business blueprint · Run date 2026-07-10 · Run #221 · Slug: aedt-bias-audit-compliance-engine
Final Decision: Blueprint
A done-for-you, AI-native bias-audit and multi-state algorithmic-employment-compliance desk purpose-built for the employers, HR leaders, and HR-technology vendors who use automated employment decision tools (AEDTs) — resume screeners, video-interview scoring models, candidate-ranking algorithms — to make or influence hiring, promotion, and termination decisions, and who now face a rapidly hardening, multi-jurisdiction patchwork of mandatory bias-audit, notice, and risk-assessment law: New York City's Local Law 144 (live and entering a stricter 2026 enforcement phase), Illinois's amended Human Rights Act AI provisions (effective January 1, 2026), and California's CCPA Automated Decisionmaking Technology regulations (binding January 1, 2027, with risk assessments due by December 31, 2027). The engine ingests an employer's or vendor's AEDT scoring data and applicant/candidate demographic data; runs an AI-driven statistical bias analysis against the applicable jurisdiction's test (New York City's four-fifths-rule impact-ratio test, Illinois's notice-and-discrimination framework, California's risk-assessment and opt-out framework); is certified by an independent human auditor (a statistician or industrial-organization psychologist with no financial interest in the AEDT or the employer, satisfying each law's independence requirement); and delivers a publishable bias-audit summary, jurisdiction-specific employee/candidate notices, and a standing multi-state compliance calendar — priced per-tool, per-audit-cycle, and via an annual multi-state monitoring subscription, never hourly. This is not a duplicate of any of this factory's 220 prior outputs, including its closest adjacent output (the EU AI Act conformity-file engine, run #94, which serves EU AI-system providers under an entirely different regulatory regime, buyer, and workflow) — no prior run has addressed U.S. employment-law algorithmic-discrimination compliance.
Executive Summary
Adoption of AI in hiring is now the norm, not the exception: 96% of U.S. hiring professionals use AI in at least some recruiting task, 82% of companies that use AI in hiring apply it to resume review, and 43% of organizations used AI in HR tasks in 2025, up from 26% in 2024. Verified Regulation has not kept pace with adoption, but it is now closing the gap on an overlapping, multi-year timeline: New York City's Local Law 144 has required an annual independent bias audit and public results summary for any AEDT used to screen NYC-resident candidates since January 1, 2023, with civil penalties of $500 to $1,500 per day for continuing violations and law firms warning of a materially stricter enforcement posture in 2026. Verified Illinois's amended Human Rights Act took effect January 1, 2026, requiring covered employers to notify employees and applicants whenever AI is used to "influence or facilitate" a covered employment decision. Verified California's CCPA Automated Decisionmaking Technology regulations, finalized by the CPPA in September 2025, require risk assessments, pre-use notices, opt-out rights, and appeal rights for employers using ADMT for "significant decisions" including hiring, promotion, and termination, with compliance required by January 1, 2027 and civil penalties up to $2,500 per violation ($7,500 for intentional violations). Verified Colorado's SB24-205 AI Act was twice delayed and has now been substantially rewritten as SB 189 (signed May 14, 2026, effective January 1, 2027), illustrating that this is a live, still-forming regulatory area rather than a settled one — a dynamic this blueprint treats as a structural risk to manage, not a reason to wait. Verified A December 2025 New York State Comptroller audit found that the city's own enforcement review had identified just one instance of potential non-compliance among 32 employers reviewed, while an independent review of the same 32 employers identified at least 17 instances of potential non-compliance — evidence of both a large compliance gap and an enforcement mechanism about to close it. Verified Existing help is split between a small number of early, thinly-capitalized AI-native audit platforms (Warden AI: $1.48M seed, July 2025) and traditional manual consulting/audit firms (BABL AI, DCI Consulting, and larger professional-services firms such as Deloitte) charging custom, unpublished, non-per-unit fees — leaving a genuine, still-open window for an AI-native, multi-state, per-tool-priced compliance engine.
Thesis
An AEDT bias audit is a retrospective statistical exercise, not a real-time employment decision — the buyer hands over historical scoring and demographic data and receives back a certified fairness assessment and a set of jurisdiction-specific notices, never asking the vendor to operate the hiring tool itself. Inferred, consistent with how NYC LL144 and comparable audits are structured and marketed by existing providers This is exactly the shape this factory has repeatedly validated: a document-and-deadline-driven regulatory-response workflow, gated by a real independence/credentialing chokepoint (an "independent auditor" under NYC LL144, with no financial interest in the AEDT or the employer, is a defined legal requirement, not a nice-to-have), where the bulk of the labor — data ingestion and cleaning, adverse-impact-ratio computation across every required demographic category, jurisdiction-specific notice drafting, and deadline calendaring across a widening multi-state patchwork — is mechanical and AI-automatable, while true judgment concentrates at a small number of chokepoints: the independent auditor's certification of the statistical methodology and result, and a documented decision about which jurisdictions actually apply to a given employer's hiring footprint. Unlike a single-state, single-deadline compliance product, this is a structurally compounding opportunity — a third, fourth, and fifth state (Illinois live now, California in 2027, Colorado's rewritten SB 189 in 2027, and other states with bills pending) are each adding new, distinct audit, notice, or risk-assessment obligations on an overlapping but non-identical multi-year calendar, meaning the addressable compliance surface area grows every year the underlying AI-hiring-adoption trend continues, which every surveyed indicator says it will.
Discovery Rationale
This run explored five candidates before selecting the AEDT bias-audit and multi-state algorithmic-employment-compliance engine: a special-needs-trust (SNT) Medicaid/SSI-benefit-preserving disbursement compliance engine for professional trustees, a FinCEN beneficial-ownership-information (BOI) reporting engine for foreign reporting companies, a DEA telemedicine special-registration compliance engine for controlled-substance prescribers, a PDMP-integrated controlled-substance diversion-monitoring compliance engine for independent pharmacies, and the AEDT bias-audit engine described here. The SNT engine had a real, well-documented compliance burden (SSA POMS trust-accounting and disbursement-reporting rules; state Medicaid reporting requirements) but requires direct custody of, or fiduciary authority over, a beneficiary's funds — a high-trust-burden, judgment-dense role already occupied by chartered corporate trustees, and one where an AI-native, non-fiduciary vendor would face serious licensing and liability friction. Inferred The FinCEN BOI engine had a clear statutory framework, but the March 2025 interim final rule narrowed the "reporting company" definition to exclude all U.S. companies and U.S. persons, leaving only foreign entities registered to do business in a U.S. state in scope — collapsing what was, in 2024, a mass-market opportunity into a small, already crowded niche as most 2024-era BOI-compliance vendors pivoted or shut down. Verified The DEA telemedicine special-registration engine tracks a genuinely important gap (DEA has now issued four consecutive temporary extensions of pandemic-era telemedicine controlled-substance prescribing flexibilities, most recently through December 31, 2026, while its proposed permanent Special Registration rule remains unfinalized), but a rules engine built against a still-proposed, repeatedly-delayed regulation has no stable compliance target, and the underlying subject matter sits close enough to prescribing/medical practice judgment to raise unauthorized-practice concerns if not scoped very narrowly. Verified The PDMP diversion-monitoring engine had a real regulatory mandate but is already served by an entrenched, near-universal incumbent infrastructure layer (Bamboo Health's NarxCare/PMP AWARxE platforms are integrated into most state PDMP systems), leaving thin competitive whitespace for a new entrant. Inferred The AEDT bias-audit engine won because it combines a documented, near-universal underlying AI-hiring-adoption trend (96% of hiring professionals), an already-binding and actively-enforced legal mandate (NYC LL144, live since 2023, entering stricter 2026 enforcement) layered with two more binding mandates arriving on a known multi-year calendar (Illinois, live; California, 2027), a real independence/credentialing chokepoint that functions as a genuine moat, live private litigation pressure (Mobley v. Workday) reinforcing the legal risk independent of any single regulator's enforcement posture, and a competitive field of thinly-capitalized AI-native entrants and expensive manual consultants rather than an entrenched dominant platform.
Candidate Comparison
Five candidates generated and scored 1-5 across 20 standard criteria.
| Criterion | AEDT bias audit & multi-state algorithmic employment compliance engine | Special-needs-trust Medicaid/SSI disbursement compliance engine | FinCEN BOI foreign-reporting-company engine | DEA telemedicine special-registration compliance engine | PDMP diversion-monitoring compliance engine |
|---|---|---|---|---|---|
| 1. Low trust burden | 4 | 2 | 4 | 3 | 3 |
| 2. Low task-level judgment | 4 | 2 | 4 | 3 | 3 |
| 3. High intelligence threshold | 5 | 3 | 2 | 4 | 3 |
| 4. Regulation as moat | 5 | 3 | 3 | 2 | 4 |
| 5. No physical labor | 5 | 5 | 5 | 5 | 5 |
| 6. Sam Altman test | 5 | 3 | 2 | 4 | 3 |
| 7. Outcome-pricing potential | 4 | 2 | 3 | 3 | 3 |
| 8. Gross-margin potential | 5 | 3 | 4 | 4 | 4 |
| 9. Buyer urgency | 4 | 2 | 2 | 2 | 3 |
| 10. Competitive whitespace | 4 | 2 | 1 | 3 | 2 |
| 11. Novelty vs prior 220 outputs | 5 | 5 | 5 | 5 | 5 |
| 12. Fit with current AI capability | 5 | 3 | 4 | 4 | 4 |
| 13. Active demand evidence | 4 | 2 | 2 | 2 | 3 |
| 14. Existing budget/competitor proof | 4 | 3 | 2 | 2 | 4 |
| 15. Waitlist/lead-magnet potential | 4 | 2 | 2 | 3 | 2 |
| 16. Narrow MVP wedge clarity | 5 | 3 | 4 | 2 | 3 |
| 17. Distribution-channel clarity | 3 | 2 | 2 | 2 | 2 |
| 18. Licensing feasibility | 4 | 2 | 4 | 2 | 3 |
| 19. Operational repeatability | 4 | 3 | 4 | 3 | 4 |
| 20. Speed to first revenue | 4 | 2 | 3 | 2 | 3 |
| Total (max 100) | 87 | 54 | 62 | 60 | 66 |
Why runners-up lost: SNT disbursement engine — requires direct fiduciary custody/authority over beneficiary funds, a high-trust, judgment-dense role already occupied by chartered corporate trustees. FinCEN BOI engine — the March 2025 interim final rule narrowed the reporting-company definition to foreign entities only, collapsing the addressable market and leaving a crowded field of vendors built for the pre-2025 mass-market version of the rule. DEA telemedicine engine — the controlling Special Registration rule remains proposed, not final, after four consecutive temporary extensions, offering no stable compliance target and edging toward unauthorized-practice-of-medicine adjacent judgment. PDMP diversion-monitoring engine — a real mandate, but already served by Bamboo Health's near-universal NarxCare/PMP AWARxE infrastructure layer integrated into most state PDMP systems, leaving thin whitespace for a new entrant.
CODE Validation
C — Consumer/Buyer Trend
Two converging 2025-2026 developments have simultaneously raised AI-hiring-tool adoption and hardened the legal consequences of deploying one without an audit trail. First, adoption itself: 96% of U.S. hiring professionals now use AI in at least some recruiting task, 82% of companies using AI in hiring apply it to resume screening specifically, and 62% of companies expect AI to run their entire hiring process by the end of 2026. Verified Second, legal exposure: Mobley v. Workday — filed February 2023, granted preliminary ADEA collective-action certification in May 2025, and still generating fresh discovery rulings as of May-June 2026 — has established that an AEDT vendor itself can be held directly liable for employment discrimination under an "agent" theory, meaning both employers and AEDT vendors now share exposure, not just the employer alone. Verified Both developments point buyers (HR/talent-acquisition leaders at employers, and product/compliance leaders at HR-technology vendors) toward the same urgent question: can we prove, with an independently certified statistical audit, that this specific tool does not produce a disparate impact — before a regulator or a plaintiff's attorney asks first.
O — Opportunity
The current help landscape splits into three categories, none of which fully occupies this engine's specific multi-state, per-tool, AI-native wedge: a small number of early AI-native audit platforms (Warden AI, which by its own description has "no direct tech competitors" and instead names Credo, ModelOp, and Patronus — general AI-governance platforms, not AEDT-employment-law specialists — as its closest comparators) still early-stage and enterprise-weighted in go-to-market; traditional manual consulting/audit firms (BABL AI, DCI Consulting, and larger professional-services firms including Deloitte) that provide credible independent audits but price custom, unpublished engagements without a productized multi-state compliance layer; and general HR-compliance or employment-law counsel who can advise on the notice requirements but typically do not perform the underlying statistical bias audit themselves. Verified No identified vendor combines AI-native data-ingestion and adverse-impact computation, jurisdiction-specific notice/risk-assessment drafting across NYC, Illinois, and California in one continuously updated engine, and per-tool flat-fee-plus-subscription pricing purpose-built for the mid-market employer or HR-tech vendor that cannot justify an open-ended consulting engagement before knowing whether its tool even needs an audit. Inferred (whitespace characterization)
D — Demand
Demand is direct and statutorily triggered: any employer using an AEDT to screen NYC-resident candidates must commission an annual independent bias audit and publish a summary before using — or continuing to use — the tool, or face DCWP civil penalties of $500 to $1,500 per day for continuing violations. Verified Illinois employers using AI to "influence or facilitate" a covered employment decision must provide notice as of January 1, 2026, with the Department of Human Rights tasked to adopt enforcement rules. Verified California employers subject to the CCPA using ADMT for hiring, promotion, or termination decisions must complete risk assessments by December 31, 2027 and provide pre-use notices, opt-out rights, and appeal rights beginning April 1, 2027, backed by penalties up to $7,500 per intentional violation. Verified A December 2025 New York State Comptroller review found a large gap between DCWP's own enforcement findings (1 of 32 employers reviewed) and an independent review of the same employers (at least 17 of 32) — exactly the kind of documented enforcement-gap-about-to-close pattern this factory has repeatedly used as an active-demand signal, reinforced here by law firms explicitly warning clients to expect materially stricter 2026 enforcement. Verified
E — Economic Sizing
No single published source aggregates the exact population of U.S. employers subject to one or more of these mandates, so this section is explicitly constructed and labeled Inferred. Starting from the verified base that 96% of U.S. hiring professionals use AI in some recruiting task and that NYC alone — the largest single metropolitan labor market in the U.S., with several hundred thousand active employer establishments — triggers LL144 for any employer (regardless of headquarters location) that uses an AEDT to screen even one NYC-resident candidate, the near-term addressable population for a NYC-nexus bias audit plausibly runs into the tens of thousands of employers annually. Inferred Layering in Illinois's broader notice mandate (covering every employer using AI to influence any covered employment decision statewide, not just AEDTs meeting NYC's narrower "substantial factor" definition) and California's 2027 ADMT risk-assessment requirement (covering every CCPA-regulated business — generally those with over $25M in annual revenue or processing personal data on 100,000+ consumers — using ADMT for employment decisions) each independently adds a materially larger population on a known multi-year calendar. Inferred Modeling a blended $6,000-$20,000 average first-year revenue per engaged client (a single-tool NYC LL144 audit plus notice package, or a broader multi-state monitoring subscription for larger, multi-jurisdiction employers and HR-tech vendors) against a realistic three-year book of 250-800 client engagements implies a constructed serviceable wedge of roughly $6M-$25M in three-year cumulative revenue, with the addressable base structurally expanding, not contracting, as Illinois enforcement rules finalize and the California ADMT deadline approaches. Inferred
Rubric Scorecard (Six Gates)
Gate 1 — Low Trust Burden: 4/5
The buyer hands over historical AEDT scoring output and applicant/candidate demographic data and receives back a certified statistical audit and drafted notices — the vendor never operates the hiring tool, makes an employment decision, or touches an active candidate pipeline in real time; the one meaningful trust element is handling sensitive protected-class demographic data responsibly, addressed directly in the risk register.
Gate 2 — Low Task-Level Judgment: 4/5
The workflow decomposes cleanly: data ingestion and cleaning, adverse-impact-ratio computation across every required demographic category and intersectional subgroup, jurisdiction-applicability screening, and notice/risk-assessment drafting are largely mechanical once data is structured; true judgment concentrates at the independent auditor's certification of statistical methodology and at documented jurisdiction-applicability calls for employers with an ambiguous hiring footprint.
Gate 3 — High Intelligence Threshold: 5/5
Correctly executing a defensible bias audit requires synthesizing the applicable jurisdiction's specific legal test (NYC's four-fifths-rule impact-ratio calculation methodology, Illinois's notice-and-discrimination framework, California's significant-decision and meaningful-human-involvement analysis), statistical best practice for adverse-impact testing across small-sample and intersectional subgroups, and a fast-moving, multi-jurisdiction body of guidance and case law (the May 2026 Mobley discovery rulings, the CPPA's finalized ADMT rules) — a genuinely difficult, multi-domain reasoning task that benefits materially from frontier-model synthesis paired with expert statistical review.
Gate 4 — Regulation as a Moat: 5/5
NYC LL144's mandatory annual audit by a legally defined "independent auditor," Illinois's statutory notice mandate, and California's CPPA-adopted risk-assessment and opt-out framework together form a dense, jurisdiction-specific compliance framework that a generalist HR-compliance vendor or general-purpose AI-governance platform cannot casually replicate — genuine legal and statistical specialization, plus the independence credential itself, is required to operate credibly and lawfully in this space.
Gate 5 — No Physical Labor: 5/5
Every step — data intake, statistical analysis, drafting, and delivery — is conducted remotely via secure document/data exchange; no on-site presence at an employer's or vendor's office is ever required.
Gate 6 — Sam Altman Test: 5/5
As frontier models improve at extracting structure from heterogeneous AEDT scoring exports, computing and explaining adverse-impact statistics across more demographic categories and intersectional subgroups, and synthesizing a growing, fast-moving body of state-specific AI-employment law, the engine's audit rigor, jurisdictional coverage, and drafting speed improve directly; the durable, anti-commoditization asset is the maintained, versioned library of jurisdiction-specific compliance rules, AEDT-vendor data-format connectors, and audit-disposition/enforcement-outcome history built case by case — none of which a generic frontier model or a new entrant replicates simply by getting smarter.
Anti-commoditization check
A generic LLM prompted with a spreadsheet of hiring outcomes can already produce a plausible-sounding fairness summary; it cannot reliably determine which of an overlapping, non-identical set of state and municipal AEDT/ADMT laws actually apply to a specific employer's hiring footprint, correctly compute a legally defensible adverse-impact ratio across every required subgroup with appropriate small-sample handling, or maintain the "independent auditor" status the law itself requires — the moat is the accumulated jurisdictional-rules data, the audit-methodology rigor, and the credentialed independence, not the underlying model.
Target Buyer
| Attribute | Detail |
|---|---|
| ICP | A mid-market-to-enterprise U.S. employer (typically 250-10,000 employees) that uses one or more automated employment decision tools (resume-screening algorithms, video-interview scoring models, candidate-ranking systems) to screen candidates who may reside in NYC, Illinois, or California, or an HR-technology vendor whose AEDT product is deployed by such employers and who must supply bias-audit and compliance documentation to its own enterprise customers. |
| Economic buyer | The VP/Head of Talent Acquisition, Chief People Officer, or HR-technology vendor's Head of Product/Compliance — frequently acting alongside in-house or outside employment counsel who can advise on notice obligations but typically does not perform the underlying statistical audit. |
| Trigger event | Expansion of AEDT use into NYC, Illinois, or California hiring; an approaching annual LL144 audit-renewal deadline (audits expire exactly one year after they are conducted); Illinois's January 1, 2026 notice-mandate effective date; the approaching California ADMT risk-assessment deadline; an enterprise customer's procurement/vendor-security review demanding proof of an independent bias audit; a competitor's or peer company's publicized bias-audit finding or lawsuit. |
| Budget source | Existing HR-compliance, talent-acquisition-technology, or vendor-risk-management budget; for HR-technology vendors, existing trust-and-safety or compliance-certification budget already spent on SOC 2 and similar third-party attestations, extended to cover the AEDT-specific bias-audit requirement their own enterprise customers increasingly demand. |
Jobs-to-be-Done
- "Tell me, with an independently certified statistical audit, whether the AEDT we use to screen candidates actually produces a disparate impact on any protected group — before a regulator or a plaintiff's attorney finds out first."
- "I don't know which of NYC, Illinois, and California's overlapping AI-employment laws actually apply to us. Screen our hiring footprint and tell me exactly what we're required to do and by when."
- "Draft the exact notices our law requires us to give candidates and employees, in the right jurisdictions, on the right cadence, without my legal team starting from a blank page."
- "As an HR-tech vendor, give me an independent bias-audit result I can hand to my enterprise customers' procurement teams so their own LL144/ADMT obligations don't block my renewal."
Painful Problem
An employer or HR-technology vendor that uses an automated employment decision tool to screen, rank, or score candidates now faces a rapidly hardening, non-identical, multi-jurisdiction legal patchwork — NYC's mandatory annual independent bias audit (live since 2023, civil penalties of $500-$1,500/day, stricter 2026 enforcement expected), Illinois's employee/applicant notice mandate (effective January 1, 2026), and California's risk-assessment, notice, opt-out, and appeal framework (binding January 1, 2027) — while having no reliable, affordable, AI-native way to determine which laws actually apply to their specific hiring footprint, commission a legally sufficient independent audit, or draft the required notices on the correct cadence. Verified A December 2025 government audit found that the gap between what employers believe they have complied with and what an independent reviewer finds is large (1 of 32 vs. at least 17 of 32 employers reviewed), and Mobley v. Workday has now established that AEDT vendors themselves — not just the employers who deploy their tools — can be held directly liable for discrimination under an agent theory, meaning the exposure is shared and growing on both sides of the buyer relationship. Verified Existing help is either an unaffordable, custom-quoted engagement with a manual audit/consulting firm, an enterprise-first AI-native platform not yet built for the mid-market or for the multi-state notice-drafting layer, or no specialized help at all — leaving many employers and vendors either non-compliant by default or paying for a narrow, single-jurisdiction audit that leaves the rest of the patchwork unaddressed.
The Outcome We Sell
We sell an independently certified statistical bias audit of an employer's or vendor's AEDT, a jurisdiction-applicability screen showing exactly which of NYC's, Illinois's, and California's (and any other applicable state's) laws apply to the specific hiring footprint in question, the drafted candidate/employee notices and publishable audit-summary each law requires, and a standing multi-state compliance calendar that tracks every audit-renewal and notice-refresh deadline going forward — delivered as a finished, independently certified work product the buyer can publish and act on immediately, not a self-serve statistics dashboard they must interpret and legally validate themselves.
First One-Feature MVP Wedge
- ICP: A mid-market employer (250-5,000 employees) or HR-tech vendor that already uses an AEDT to screen NYC-resident candidates and has either never completed a Local Law 144 bias audit or has one expiring within 60 days.
- Trigger event: An approaching or lapsed annual LL144 audit-renewal deadline, or an enterprise customer's procurement review demanding proof of a current independent audit.
- Pain: The business does not know whether its current audit (if any) is legally sufficient, does not have a reliable way to compute a defensible adverse-impact ratio across every required demographic category, and risks a $500-$1,500/day civil penalty and reputational exposure if it keeps using the tool without a compliant audit and published summary.
- One-feature MVP: The AEDT Bias Audit & LL144 Compliance Scan — ingest the AEDT's scoring output and applicant demographic data for the most recent 12-month period; run an AI-driven four-fifths-rule adverse-impact analysis across every required demographic category and intersectional subgroup; deliver an independently certified bias-audit summary, the required candidate notice language, and a publication-ready results page within 10 business days.
- Input: The AEDT's per-candidate scoring/selection data for the audit period, and the corresponding applicant self-identified demographic data (race/ethnicity, sex, and intersectional categories as required).
- Output: A written, independently certified bias-audit report (adverse-impact ratios by category, pass/fail against the four-fifths threshold, methodology and data-source disclosure), the publishable summary required by law, drafted candidate-notice language, and a fixed-fee quote for the full multi-state compliance subscription.
- Human chokepoint: An independent auditor (a statistician or industrial-organization psychologist with no financial interest in the AEDT or the employer/vendor, and no role in the AEDT's development) reviews and certifies the statistical methodology and result before delivery.
- Success metric: Audit delivered within 10 business days of complete data intake for 95%+ of clients; zero missed annual audit-renewal deadlines across the client book.
- What clients will ask for next if the wedge works: The full Multi-State Algorithmic Employment Compliance Subscription covering Illinois notice drafting, California ADMT risk-assessment preparation, and standing renewal tracking, plus (for HR-tech vendors) a reusable audit-certification package to distribute to their own enterprise customers.
Evidence Summary
Every core claim in this blueprint is backed by a live 2025-2026 source and cross-checked against at least one independent publisher where possible: NYC Local Law 144's requirements, penalties, and enforcement posture (NYC DCWP, the NY State Comptroller's December 2025 audit, DLA Piper, Warden AI); Illinois's amended Human Rights Act AI provisions (Hinshaw & Culbertson, Seyfarth Shaw, the National Law Review, Workforce Bulletin); California's CCPA ADMT regulations (Littler, Akin Gump, Skadden, the CPPA itself); the EEOC's four-fifths-rule guidance and its 2025 enforcement-posture shift (Fisher Phillips, FordHarrison, K&L Gates); Mobley v. Workday's status and agent-theory liability holding (Akin Gump, Forbes, Duane Morris, Seyfarth Shaw); AI-hiring-adoption statistics (SQ Magazine's aggregation of Resume Now and SHRM survey data, the Interview Guys); and existing competitor/budget evidence (Warden AI's Crunchbase-verified funding and published audit volume, BABL AI's and DCI Consulting's public service pages). No figure in this blueprint was invented; ranges are shown where sources vary, and constructed market-sizing figures are explicitly labeled Inferred rather than Verified.
Claim Table
| Claim | Label | Notes |
|---|---|---|
| NYC Local Law 144 requires an annual independent bias audit of any AEDT used to screen NYC-resident candidates, effective January 1, 2023, actively enforced by DCWP since July 5, 2023, with civil penalties of $500 (first violation) to $1,500/day (continuing violations) | Verified | NYC DCWP official page and FAQ; multiple law-firm client alerts |
| Law firms are warning employers to expect a materially stricter 2026 enforcement phase for LL144 | Verified | Warden AI compliance guide; multiple 2026 employment-law client alerts |
| A December 2025 NY State Comptroller audit found DCWP's own review identified 1 potential non-compliance instance among 32 employers, while an independent review of the same 32 identified at least 17 | Verified | NY State Comptroller enforcement audit, Dec 2, 2025; DLA Piper analysis, Jan 2026 |
| Illinois's amended Human Rights Act AI provisions took effect January 1, 2026, requiring notice to employees/applicants whenever AI is used to influence or facilitate a covered employment decision, with annual notice and 30-day post-update notice requirements | Verified | Hinshaw & Culbertson; Seyfarth Shaw; National Law Review; Illinois General Assembly HB3773 bill status |
| California's CPPA finalized CCPA Automated Decisionmaking Technology regulations in September 2025; employer compliance (risk assessments, pre-use notices, opt-out, and appeal rights for "significant decisions" including hiring/promotion/termination) required by January 1, 2027, with risk assessments due by December 31, 2027; penalties up to $2,500/violation ($7,500 intentional) | Verified | Littler; Akin Gump; Skadden; CPPA official announcement, Sept 23, 2025 |
| Colorado's SB24-205 AI Act was postponed twice (to June 30, 2026) and then substantially rewritten as SB 189, signed May 14, 2026, effective January 1, 2027 | Verified | Clark Hill; The Employer Report; Akin Gump AI Law Tracker; Norton Rose Fulbright |
| The EEOC's four-fifths rule is the standard rule-of-thumb guideline for identifying adverse impact in a selection procedure (a selection-rate ratio below 80% for a protected group signals possible disparate impact) | Verified | EEOC technical-assistance guidance summarized by Fisher Phillips, FordHarrison, K&L Gates |
| An April 2025 federal executive order directed the EEOC to deprioritize disparate-impact-only enforcement, though private plaintiffs retain full Title VII standing | Verified | Fisher Phillips 2025-2026 EEOC AI guidance analysis |
| Mobley v. Workday: filed Feb. 21, 2023; granted preliminary ADEA collective-action certification May 16, 2025; a May 2026 discovery ruling found attorney-client privilege protects Workday's own bias-testing data while denying compulsion of customer applicant data; courts have held AEDT vendors can be directly liable under an "agent" theory | Verified | Akin Gump AI Law Tracker; Forbes (May 2026); Duane Morris Class Action Defense blog (June 2026); Seyfarth Shaw |
| 96% of U.S. hiring professionals use AI in at least some recruiting task; 82% of companies using AI in hiring apply it to resume review; 43% of organizations used AI in HR tasks in 2025 (up from 26% in 2024); 62% expect AI to run their entire hiring process by end of 2026 | Verified | SQ Magazine aggregation of Resume Now and SHRM survey data; Interview Guys |
| Warden AI, an AI-native AEDT bias-audit platform, closed a $1.48M seed round in July 2025 (total raised $2.34M) and has completed 150+ published bias audits, finding 15% of audited systems fail fairness metrics for at least one demographic group | Verified | Crunchbase; TechFundingNews; Warden AI published research page |
| BABL AI and DCI Consulting operate as manual independent-auditor service providers for NYC LL144 compliance; pricing is custom-quoted and not publicly listed | Verified | BABL AI and DCI Consulting websites; G2 AI Bias Audit Services category |
| The enterprise AI-governance-and-compliance software market was valued at $2.20B (2025), projected to $2.55B (2026) and $11.05B by 2036 (15.8% CAGR); the narrower standalone AI-governance market was valued at $308.3M (2025), projected to $417.8M (2026) and $3.59B by 2033 (36.0% CAGR) | Verified | Future Market Insights; Precedence Research (two independent market-research estimates, shown as a range given typical cross-firm variance) |
| Constructed near-term addressable population (tens of thousands of NYC-nexus employers annually, expanding materially as Illinois and California obligations phase in) and constructed 3-year serviceable revenue wedge of $6M-$25M | Inferred | Derived from verified adoption, mandate, and enforcement data; no single source aggregates this exact figure |
Source-Claim Matrix
| Claim | Label | Source | Type | Date | Confidence | Used In |
|---|---|---|---|---|---|---|
| NYC LL144 requirements and penalties | Verified | NYC DCWP official page/FAQ; DLA Piper; Warden AI | Government agency page; law-firm/vendor analysis | 2023-2026 | High | s3, s4, s7, s11, s15, s22 |
| NY State Comptroller enforcement-gap audit | Verified | NY State Comptroller (Dec 2025); DLA Piper (Jan 2026) | Government audit; law-firm analysis | Dec 2025-Jan 2026 | High | s3, s7, s11, s15, s17 |
| Illinois HB3773/Human Rights Act AI provisions | Verified | Hinshaw & Culbertson; Seyfarth Shaw; National Law Review; Illinois General Assembly | Law-firm client alerts; legislative record | 2025-2026 | High | s3, s7, s9, s15, s22 |
| California CCPA ADMT regulations | Verified | Littler; Akin Gump; Skadden; CPPA | Law-firm client alerts; government agency announcement | Sept 2025-2027 | High | s3, s7, s9, s15, s22 |
| Colorado SB24-205/SB189 delay and rewrite | Verified | Clark Hill; The Employer Report; Akin Gump AI Law Tracker; Norton Rose Fulbright | Law-firm client alerts | 2025-2026 | High | s4, s5, s15, s55 |
| EEOC four-fifths rule and 2025 enforcement posture shift | Verified | Fisher Phillips; FordHarrison; K&L Gates | Law-firm client alerts summarizing EEOC guidance | 2023-2026 | High | s7, s15, s23, s55 |
| Mobley v. Workday status, agent-theory liability | Verified | Akin Gump; Forbes; Duane Morris; Seyfarth Shaw | Law-firm analysis; legal-affairs journalism | 2023-2026 | High | s3, s7, s11, s15, s19 |
| AI-in-hiring adoption statistics | Verified | SQ Magazine (aggregating Resume Now/SHRM); Interview Guys | Survey aggregation/trade press | 2025-2026 | Medium-High | s3, s4, s7, s15 |
| Warden AI funding and audit-volume evidence | Verified | Crunchbase; TechFundingNews; Warden AI | Funding database; trade press; vendor research page | 2025 | High | s3, s15, s19, s20 |
| BABL AI/DCI Consulting competitor positioning | Verified | Vendor websites; G2 | Vendor website; review aggregator | 2025-2026 | High | s15, s19, s20 |
| AI-governance/compliance software market sizing | Verified | Future Market Insights; Precedence Research | Market-research reports | 2025-2026 | Medium (cross-firm estimate variance typical for early-stage categories) | s15, s17 |
| Addressable employer population and 3-yr revenue wedge | Inferred | Derived by this analysis from verified adoption/mandate data | Constructed estimate | 2026 | Medium | s7, s38 |
Market and Demand Evidence
AI-hiring adoption is not a marginal or slowing trend: 96% of hiring professionals use AI in some recruiting task today, and 62% of companies expect AI to run their entire hiring process by the end of 2026, meaning the population of employers with an AEDT-audit obligation grows structurally alongside adoption rather than shrinking. Verified The regulatory surface is compounding, not static: NYC's mandate is live and entering stricter enforcement, Illinois's notice mandate is now live, and California's risk-assessment mandate arrives on a known date less than 18 months away as of this run — a multi-year calendar of new, non-identical obligations that keeps expanding the addressable compliance surface. Verified The AI-governance/compliance software category itself shows strong, independently estimated growth (multiple market-research firms projecting double-digit-to-36% CAGR through the early 2030s), consistent with the broader "tightening global regulatory frameworks are driving procurement demand" pattern cited across those reports. Verified
Active Buyer Conversations
Employment-law and HR-technology trade press and law-firm client-alert programs are actively publishing guidance aimed directly at this buyer population: Hinshaw & Culbertson, Seyfarth Shaw, and the National Law Review each published distinct 2025-2026 client alerts on Illinois's new AI-notice mandate; Littler, Akin Gump, and Skadden each published distinct 2025-2026 alerts on California's ADMT regulations; and DLA Piper's January 2026 analysis of the NY State Comptroller's enforcement-gap audit was explicitly framed as a warning to employers of "increased risk." Verified Warden AI's own published research (150+ audits, a 15% system-level fairness-failure rate) functions as ongoing, vendor-published proof that buyers are actively commissioning and publishing these audits today, not merely being advised to consider them. Verified
Competitive Landscape
| Category | Examples | What they sell | Gap vs. this engine |
|---|---|---|---|
| Early AI-native AEDT audit platforms | Warden AI ($1.48M seed, July 2025; 150+ published audits) | An audit-and-certification platform combined with continuous, embedded AI-system monitoring, positioned primarily toward larger, more sophisticated HR-tech buyers | Enterprise-weighted go-to-market and pricing; by its own account, no dedicated multi-state notice-drafting layer covering Illinois's and California's distinct obligations alongside NYC's audit requirement |
| Manual independent-audit and HR-compliance consulting firms | BABL AI, DCI Consulting, Deloitte's LL144 practice | Credible, credentialed independent bias audits, custom-quoted and typically delivered via a traditional consulting engagement | No productized, AI-native, per-tool flat-fee pricing; slower, more expensive per-engagement delivery; not structured as a continuously updated multi-state compliance subscription |
| General HR-compliance/employment-law counsel | Existing outside counsel relationships at the employer | Advice on notice obligations and legal risk; refers the underlying statistical bias audit to a specialist | Does not perform the statistical audit itself; typically bills hourly; no integrated multi-jurisdiction tracking layer |
Competitor and Budget Validation
Budget for AEDT bias-audit and AI-governance work is independently validated on both the investor and buyer side: Warden AI's $1.48M 2025 seed round (institutional investor Playfair Capital participating) is direct evidence that professional investors underwrite recurring revenue in this exact category, and its 150+ completed, published audits are direct evidence employers already pay for and publish this work today. Verified BABL AI's and DCI Consulting's ongoing operation as paid independent-audit providers, and Deloitte's own LL144 practice, further confirm this is an active, professionally billed market rather than a speculative one. Verified The proposed engine does not compete for the general AI-governance-platform category (Warden AI names Credo, ModelOp, and Patronus — not itself — as its closest competitors); it targets the specific, still-underserved intersection of AI-native audit delivery, mid-market pricing, and multi-state (not single-jurisdiction) notice and risk-assessment drafting.
Pricing Evidence and Proposed Pricing
Published per-unit pricing does not exist in this category — every identified provider (Warden AI, BABL AI, DCI Consulting) quotes custom fees scaled by the number of AEDTs in scope and data complexity, disclosed only on request. Verified Proposed pricing here is therefore benchmarked against comparable third-party technical-compliance-audit categories with similar scope and credentialing requirements (e.g., SOC 2 Type II readiness/audit engagements typically run $10,000-$60,000; HIPAA Security Risk Analysis engagements typically run $5,000-$15,000) and structured in three tiers, all flat or subscription-based — never hourly: (1) a flat $4,000-$9,000 AEDT Bias Audit & LL144 Compliance Scan per tool per audit cycle (single tool, clean data); (2) a flat $8,000-$25,000 Multi-State Algorithmic Employment Compliance Package, adding Illinois notice drafting and California ADMT risk-assessment preparation for employers or vendors with a multi-state hiring footprint; and (3) a $6,000-$30,000/year Multi-State Compliance Monitoring Subscription, scaled by employee count and number of AEDTs in use, covering annual audit renewal, notice refreshes, and continuous jurisdiction-applicability tracking as new state laws phase in. Inferred, benchmarked against comparable third-party technical-compliance-audit fee norms; no direct published AEDT-audit pricing exists to verify against This pricing is structured to remain well below the cost of a custom-quoted manual consulting engagement while paying for genuine statistical rigor and a maintained "independent auditor" credential, never resold as a share of any legal fee or litigation outcome.
Regulatory and Compliance Considerations
The controlling regulatory framework is jurisdiction-specific and still actively forming: NYC Local Law 144 and its implementing DCWP rules (mandatory annual independent bias audit, public summary, and candidate notice, testing against the EEOC's four-fifths adverse-impact guideline); Illinois's amended Human Rights Act AI provisions (mandatory employee/applicant notice, annual and post-update refresh requirements, enforcement rules still being adopted by the Illinois Department of Human Rights); California's CPPA-adopted CCPA ADMT regulations (mandatory risk assessments, pre-use notices, opt-out and appeal rights for "significant decisions," binding January 1, 2027); and the EEOC's non-binding four-fifths-rule technical guidance, now operating in an environment where a 2025 executive order has directed the agency to deprioritize disparate-impact-only enforcement even as private Title VII litigation (Mobley v. Workday) continues to expand vendor-side liability theory. Verified Colorado's twice-delayed, since-rewritten SB24-205/SB189 illustrates that this entire regulatory area remains in active flux, making a versioned, continuously updated jurisdiction-rules layer a compliance-critical, not merely convenient, function of the engine. Verified
Licensing Boundary
- The AI system may ingest and clean AEDT scoring and applicant-demographic data, compute adverse-impact ratios and statistical significance across every required demographic category and intersectional subgroup, screen an employer's or vendor's hiring footprint against each jurisdiction's applicability test, and generate first-draft notices, risk assessments, and publishable audit summaries — it may never certify a bias-audit result as final, represent itself as the legally required "independent auditor," or render a legal conclusion about Title VII or state-law discrimination liability.
- Trained compliance-production staff may assemble documentation, manage data intake, and prepare drafts for review, but may not certify a statistical audit result or make a final determination on jurisdiction applicability where the facts are ambiguous.
- An independent auditor — a statistician or industrial-organization psychologist meeting each applicable law's independence definition (no financial interest in the AEDT or the employer/vendor relating to that tool, and no role in the AEDT's development or distribution) — must review and certify the methodology and result of every bias audit before it is delivered or published.
- To preserve independence under NYC LL144 and comparable frameworks, the audit function must not simultaneously provide AEDT-remediation consulting to the same client on the same tool during an active audit relationship; any remediation-advisory work is either referred to a separate firm or delivered only after a documented cooling-off period and under a distinct, disclosed engagement.
- Legal conclusions about Title VII, state fair-employment-practice-act, or other statutory discrimination liability are explicitly out of scope and referred to the client's own employment counsel; the engine's deliverable is a statistical and technical audit plus jurisdiction-specific notice/risk-assessment drafting, not a legal opinion.
- Required disclaimers: every engagement letter states that the bias audit and drafted notices are statistical and technical work product certified by an independent auditor, not legal advice; clients are advised in writing to have their own employment counsel review all notices, risk assessments, and public disclosures before publication.
AI-Native Advantage
| Layer | Task |
|---|---|
| AI | AEDT scoring-data and demographic-data ingestion, cleaning, and schema normalization across heterogeneous ATS/AEDT export formats; adverse-impact-ratio computation across every required demographic category and intersectional subgroup; jurisdiction-applicability screening against a versioned multi-state rules library; first-draft bias-audit report, publishable summary, and jurisdiction-specific notice/risk-assessment generation; deadline extraction and multi-state compliance calendaring. |
| Deterministic rules | Four-fifths-rule threshold calculator per demographic category; jurisdiction-applicability decision tree (NYC substantial-factor test, Illinois influence-or-facilitate test, California significant-decision/meaningful-human-involvement test); annual audit-renewal and notice-refresh deadline calculator; data-completeness checks before independent-auditor review. |
| Human (production staff) | Client intake and data-collection coordination; data-format troubleshooting with the client's ATS/AEDT vendor. |
| Human (independent-auditor chokepoint) | Final certification of statistical methodology and result; sign-off on the published audit summary. |
| Human (employment-counsel referral, client-side) | Legal review of notices/risk assessments before publication; legal-liability judgment on any bias finding. |
Internal AI Engine Architecture
AI-vs-Human Operations Pipeline
Dynasty Translation Layer
Buyer translation
The employer or HR-tech vendor pays for one thing: certainty, backed by an independent auditor's certification, that its AEDT does not create disparate-impact exposure, delivered together with every notice and disclosure the applicable jurisdictions require, without needing an in-house statistician or an open-ended consulting engagement to get there.
Service translation
Customer receives an independently certified bias-audit report, a publishable summary, and jurisdiction-specific notices/risk assessments; automation handles data ingestion, statistical computation, and drafting; the credentialed independent auditor and, where needed, the client's own employment counsel handle certification and legal review.
Workflow translation
Intake scoring/demographic data → normalize → compute adverse-impact ratios → screen jurisdiction applicability → independent-auditor certification → draft notices/summary → deliver to client → monitor multi-state renewal deadlines → refer legal review of publication to client counsel → renew annual audit and refresh notices as new jurisdictions phase in.
Tooling translation
Document/data workbench for ingestion and statistical computation; a jurisdiction-rules knowledge base; a deadline-calendaring rules engine; a secure client data vault for sensitive demographic data; an independent-auditor review-and-certify workflow; a publishable-summary export format.
Sales translation
"Your AEDT audit either doesn't exist, is about to expire, or doesn't cover the states you actually hire in. We'll deliver an independently certified audit and every required notice within 10 days — for one flat fee, per tool."
Delivery translation
Launch manually for the first 5 clients using a shared statistical workbench and a contracted independent auditor; automate data normalization, computation, and drafting once patterns across AEDT vendors and jurisdictions stabilize.
Expansion translation
Evolve into a broader algorithmic-employment-compliance practice covering additional states as new AI-employment laws phase in, AEDT-vendor-side fairness certification sold directly to HR-tech platforms for distribution to their enterprise customers, and adjacent ADMT categories (credit, insurance, tenant screening) reusing the same statistical-audit and jurisdiction-rules architecture.
Anti-Duplication Analysis
This is not a duplicate of this factory's prior EU AI Act conformity-file engine (run #94, which serves AI-system providers under the EU's product-safety-style AI regulatory regime, an entirely different buyer, workflow, and jurisdiction) or its prior HR/employment-compliance-adjacent outputs (COBRA administration, background-screening FCRA compliance, I-9/E-Verify, pay-equity transparency, wage garnishment, and MHPAEA parity analysis all address distinct, non-AI-specific employment compliance domains); it is also not a generic AI-governance-consulting or AI-safety-platform service, since it is purpose-built as an AI-native statistical bias-audit and multi-state notice/risk-assessment desk for the specific U.S. algorithmic-employment-discrimination compliance workflow, with a narrow MVP wedge (the single-tool NYC LL144 Bias Audit & Compliance Scan) that no identified incumbent sells as a standalone, productized, flat-fee, multi-state-aware offer.
Anti-Commoditization Analysis
As frontier models make individual adverse-impact computation and first-draft notice generation trivially cheap, the durable asset shifts to the maintained, versioned library of jurisdiction-specific AEDT/ADMT rules (which states and cities require what, on what cadence, under what applicability test), AEDT-vendor data-format connectors that reduce manual data-wrangling friction, and the accumulated audit-disposition and enforcement/litigation-outcome history (which fact patterns have drawn DCWP scrutiny, which statistical arguments have held up in Mobley-style discovery disputes) — none of which a generic model or a new self-serve entrant replicates simply by getting smarter or cheaper.
Service Delivery Workflow
Intake → scoring/demographic-data normalization → AI adverse-impact computation across required categories and subgroups → jurisdiction-applicability screening → independent-auditor certification → AI notice/summary drafting → delivery to client → publication support → multi-state deadline monitoring → annual renewal and notice refresh as new jurisdictions phase in.
Operations as Product
Every audit follows the same structured intake checklist, the same adverse-impact-computation and jurisdiction-screening decision logic, and the same independent-auditor certification gate; exceptions (small-sample subgroups requiring alternative statistical handling, ambiguous multi-state hiring footprints, novel AEDT scoring-data formats) route to a defined exception queue rather than ad hoc handling, with every computation, draft, and certification logged in an audit trail the client and any referred counsel can reference if the audit is later challenged or discovered in litigation.
No-Holes Quality Engine
- Structured per-audit intake checklist covering scoring data, demographic data, and hiring-footprint jurisdiction facts.
- Automated completeness and small-sample-flagging check before any computation is marked ready for auditor review.
- Exception queue for any AEDT data format or subgroup-size scenario the engine cannot confidently classify.
- Gold-standard example audits and notice packages per AEDT category and jurisdiction combination for auditor calibration.
- Quarterly review of enforcement and litigation developments (DCWP actions, Illinois rulemaking, CPPA guidance, Mobley-adjacent rulings) to detect emerging jurisdictional or statistical-methodology shifts.
- Root-cause review of any audit that is challenged, discovered in litigation, or flagged by a regulator.
What the Human Expert Actually Does
| Task | License/credential required | Min/unit at launch | Min/unit day 90 | Automation path | Quality risk | Cannot automate | Audit trail |
|---|---|---|---|---|---|---|---|
| Statistical-methodology certification | Independent statistician / industrial-organization psychologist meeting each law's independence definition | 50 | 20 | AI-computed adverse-impact ratios with confidence scoring and cited data sources | Certifying a statistically unsound audit exposes both the client and the auditor to regulatory and litigation risk | Final certification of methodology and result | Logged statistical rationale citing specific data sources and computation method |
| Jurisdiction-applicability determination for ambiguous hiring footprints | Independent auditor, employment-counsel review recommended | 30 | 12 | AI-screened applicability checklist against the versioned multi-state rules library | Missing an applicable jurisdiction leaves the client non-compliant without their knowledge | Final determination on ambiguous multi-state facts | Logged applicability rationale |
| Publishable-summary and notice review | Independent auditor; client employment counsel for final legal sign-off | 25 | 10 | AI drafting from jurisdiction-specific templates and the rules library | An incorrect or incomplete notice exposes the client to the same penalties the audit was meant to prevent | Final review before delivery to client | Version-controlled draft history |
| Small-sample/intersectional-subgroup statistical judgment | Independent statistician | 20 | 10 | AI-flagged small-sample cases routed automatically to statistician review | Misapplied statistical handling of small subgroups can produce a misleading pass/fail result | Final statistical-method selection for edge cases | Logged methodology decision and rationale |
Minimum Viable Offer
The AEDT Bias Audit & LL144 Compliance Scan: a flat one-time fee that ingests a client's AEDT scoring and applicant-demographic data, computes adverse-impact ratios across every required category, and delivers an independently certified bias-audit report, publishable summary, and candidate notice within 10 business days — the on-ramp to the full Multi-State Algorithmic Employment Compliance Package and standing monitoring subscription.
Fulfillment Process
Manual/semi-manual for the first 5 clients using a shared statistical workbench and a contracted independent auditor; automate data normalization, computation, and drafting once patterns across AEDT vendors and jurisdictions stabilize across the pilot cohort.
Tools and Systems
- LLM-based document/data workbench for AEDT data ingestion, adverse-impact computation, and notice/summary drafting.
- Jurisdiction-rules knowledge base, versioned by state/city and updated on a scheduled review cadence.
- Case-management/ticketing system for multi-state deadline tracking and client/auditor communication.
- Secure data vault for sensitive scoring and demographic data, with data-minimization and purge policies.
- Independent-auditor review-and-certify workflow with a documented, auditable sign-off trail.
Human-in-the-Loop Quality Control
No bias-audit report or publishable summary is delivered without independent-auditor certification of the statistical methodology and result; every small-sample subgroup, novel data format, or ambiguous jurisdiction-applicability question above a defined severity threshold routes to auditor review before a report is finalized; any published disclosure is explicitly flagged for the client's own employment-counsel review before publication.
Nonlinear Scaling and Unit Economics
- Revenue per FTE target: $220K-$380K by month 12.
- COGS breakdown: LLM inference/data processing (~5-8% of revenue), independent-auditor labor (~28-38% at launch, declining to 14-20% by month 12), case-management/hosting software (~3-5%), QA/rework (~4-6%), professional/technology E&O liability insurance (~4-7%).
- Automation percentage: 35% at launch, 50% at day 90, 65%+ at one year.
- Throughput per auditor per week: 3-5 audits at launch, 8-12 by month 12.
- Cycle time per audit: 10-14 business days at launch, 5-7 days by month 12.
- Rework rate target: under 5%. Quality-failure rate (challenged/escalated audits) target: under 6%.
- CAC payback: under 6 months, assuming a $1,200-$2,800 blended acquisition cost per client against a $6,000-$20,000 blended engagement value.
- Lead-magnet-to-consult conversion assumption: 15-25%. Scan-to-paid-engagement conversion assumption: 50-65%. Multi-state monitoring-subscription renewal assumption: 70%+ annually given recurring statutory renewal obligations.
Distribution Proof Table
| Channel | Why reachable | First message | Conversion assumption | Proof source | Measurement | Follow-up |
|---|---|---|---|---|---|---|
| Employment-law and HR-tech-vendor referral partnerships | Outside employment counsel routinely advises on notice obligations but does not perform the underlying statistical audit and must refer it out | "Refer your clients' AEDT audit needs to us; we deliver the certified statistical work, you keep the legal-review relationship" | 10-18% partner-referred close rate | Documented pattern of counsel referring specialist statistical/audit work | Referral-source tracking | Co-branded client onboarding |
| HR-technology vendor marketplace and integration partnerships | ATS/AEDT vendors' enterprise customers increasingly demand proof of an independent bias audit during procurement | "Give your enterprise customers a certified audit they can hand to their own compliance teams during renewal" | 8-15% vendor-referred close rate | Documented enterprise procurement demand for third-party AEDT attestations | Vendor-partner tracking | Reusable certification package for distribution |
| Trade press and HR-compliance content (SHRM-adjacent, talent-acquisition, HR-tech media) | HR and TA leaders actively follow AI-hiring-compliance coverage given the pace of 2025-2026 legal developments | Bylined explainer: "Does your AEDT need a Local Law 144 audit — and does Illinois or California apply to you too?" | 2-3% content-to-lead | Active 2025-2026 trade-press and law-firm client-alert volume on this exact topic | Article-attributed leads | Free jurisdiction-applicability screen CTA |
| Direct outreach to employers with known NYC/IL/CA hiring footprints using AEDTs | Job postings and ATS technology usage (frequently visible via job-board metadata and vendor case studies) make AEDT-using, multi-state employers identifiable | Personalized note referencing the employer's likely LL144/Illinois/California exposure and audit-renewal timing | 3-5% outbound-to-meeting | Publicly documented AEDT vendor customer lists and job-posting technology signals | Meetings booked | Scan-based follow-up |
| Answer-engine and search visibility | HR/TA leaders and vendor compliance teams actively search "AEDT bias audit requirements," "NYC Local Law 144 compliance," "Illinois AI employment notice," "California ADMT employer requirements" | Educational content answering exact buyer questions | 2-4% organic-to-lead | Documented search and trade-press interest pattern around each jurisdiction's mandate | Organic lead volume | Lead-magnet scan signup |
Sales and Outreach Plan
Lead with a free jurisdiction-applicability screen as a low-friction entry point that tells a prospect exactly which laws apply to their hiring footprint; convert screen recipients into the paid AEDT Bias Audit & LL144 Compliance Scan; pursue employment-counsel and HR-tech-vendor referral partnerships in parallel to build recurring warm inbound and outbound-referral flow.
Founder-Led Content Plan
Publish plain-English explainers on which AI-employment laws apply to which employers, how a four-fifths-rule bias audit actually works, what Mobley v. Workday means for both employers and AEDT vendors, and real (anonymized) audit-finding patterns, positioning the founder/lead auditor as the go-to voice for practical, multi-state AEDT compliance in the post-Mobley enforcement environment.
First 30 Days of Content
- 10 educational posts: "Does your hiring tool count as an AEDT — and which state laws actually apply to you," "What NYC's Local Law 144 bias audit actually tests, step by step," "Illinois's new AI-notice law: what employers must send, and when," "California's ADMT rules, explained for HR leaders (not lawyers)," "What Mobley v. Workday means if you're the employer," "What Mobley v. Workday means if you're the AEDT vendor," "The four-fifths rule, explained with real numbers," "Why 'we didn't build the AI ourselves' doesn't get employers off the hook," "What happens if your LL144 audit expires and you keep using the tool anyway," "How to read your own AEDT vendor's bias-audit disclosure."
- 3 diagnostic teardown formats: a redacted real bias-audit report walkthrough; a before/after showing an adverse-impact ratio moving from fail to pass after a scoring-threshold adjustment; a multi-state notice package walkthrough.
- 2 lead-magnet angles: free AEDT jurisdiction-applicability screen; "Multi-State AI-Employment-Law Compliance Calendar."
- 1 webinar: "Is your AI hiring tool compliant in NYC, Illinois, and California? A 30-minute compliance check."
- 1 outbound diagnosis template: a personalized note referencing the prospect's likely multi-state exposure and their audit-renewal timing, offering a free jurisdiction-applicability screen.
Lead Magnet and Waitlist Plan
Free AEDT Jurisdiction-Applicability Screen: prospect answers a short structured questionnaire about their AEDT use and hiring footprint; receives a personalized report showing exactly which of NYC, Illinois, and California's laws apply, current compliance status if determinable, and recommended next steps, converting into a paid bias-audit engagement.
Warm GTM Plan
Reach out to screen requesters, employment-counsel referral contacts, and HR-tech-vendor partners with a consultative review of their applicability screen and a scoped audit-engagement offer.
Targeted Outbound Plan
Identify AEDT-using, multi-state employers via job-posting technology signals, ATS/AEDT vendor case studies and customer lists, and self-identified inbound screen requests; personalize outreach around their specific likely jurisdictional exposure and audit-renewal timing; lead with a diagnostic offer, not a sales pitch.
Answer-Engine and Search Visibility Plan
Publish structured, clearly-labeled explainer content answering exact buyer questions ("do I need a Local Law 144 bias audit," "does Illinois's AI employment law apply to my company," "what does California's ADMT rule require for hiring") so the company surfaces in ChatGPT, Perplexity, and Google answer surfaces when HR/TA leaders and vendor compliance teams research their obligations.
Pilot Design and Early-Demand-Trap Mitigation
Cap the first pilot cohort at 5 clients, diversified across at least two buyer types (a direct employer and an HR-tech AEDT vendor) and two jurisdictional profiles (NYC-only exposure and multi-state NYC+Illinois exposure), to stress-test the statistical-computation and auditor-review workflow before expanding.
Early-Access Feedback Flywheel
Weekly review of every auditor correction during the pilot; corrections that recur across clients become new data-normalization rules, drafting templates, or QA checks; one-off client-specific requests (e.g., legal-liability opinions beyond the defined statistical/technical scope) are logged as counsel-referral items, not folded into the product.
Build-Before-Scale Checkpoints
- After 5 pilot clients: harden the intake checklist and AEDT-data normalization rules.
- After 10 pilot clients: harden SOPs, the exception queue, and auditor-review checklists.
- After 20 pilot clients: pause new intake until COGS, rework rate, escalation rate, and cycle time are measured against target; a rising rate of challenged or escalated audits signals the computation engine is not yet reliable enough for further growth and must be fixed before onboarding more clients.
7-Day Launch Plan
Days 1-2: finalize the adverse-impact-computation decision logic and jurisdiction-applicability rules for NYC, Illinois, and California; confirm the contracted independent auditor and at least one employment-counsel referral partner. Days 3-4: build the Bias Audit & Compliance Scan drafting workbench and publish the jurisdiction-applicability-screen landing page. Days 5-6: reach out to 20 target employers and HR-tech vendors via referral contacts and outbound with the free screen offer. Day 7: deliver first applicability screens and book engagement calls.
30-Day Launch Plan
Weeks 2-3: onboard first 2-3 pilot clients; complete first full audit-and-drafting cycle with independent-auditor certification. Week 4: deliver first bias-audit reports and notice packages; begin employment-counsel and HR-tech-vendor referral outreach; publish first 5 pieces of founder-led content.
90-Day Launch Plan
Month 2: reach 5-client pilot cap; hold the first build-before-scale checkpoint; formalize the auditor-review SOP. Month 3: expand to 10 clients if checkpoint metrics clear; launch the Multi-State Compliance Monitoring Subscription as a live feature; begin measuring automation-share progress toward the 50% day-90 target.
Metrics and KPIs
- Applicability screens and bias audits delivered per month
- Audit accuracy (measured against auditor override rate; target: under 6%)
- Auditor minutes per case (declining trend)
- Automation share (target: 35%→50%→65%)
- Lead-magnet-to-consult conversion (target: 15-25%)
- Scan-to-paid-engagement conversion (target: 50-65%)
- Multi-state monitoring-subscription annual renewal rate (target: 70%+)
- Gross margin (target: 50%+ by month 12)
- Zero missed statutory audit-renewal or notice-refresh deadlines across the client book
Risks and Mitigations
The dominant risk categories are the "independent auditor" conflict-of-interest boundary, the still-forming and occasionally reversed state-level regulatory landscape (Colorado's twice-delayed, rewritten AI Act being the clearest example), employer/vendor reluctance to commission a rigorous audit given litigation-discoverability concerns highlighted by Mobley, and independent-auditor capacity bottlenecks; each is addressed with a specific mitigation in the risk register below.
Exhaustive Risk Register
1. The audit function's independence is compromised by also selling AEDT-remediation consulting to the same client on the same tool, violating NYC LL144's and comparable laws' independence definitions (Medium likelihood, High impact)
Mitigation: a published, contractually binding independence policy; the audit arm never accepts remediation-consulting work from an audited client on the same tool during an active audit relationship or without a documented cooling-off period; remediation advisory work is offered only through a structurally separated engagement or referred to a separate firm.
2. State-level AI-employment regulation continues to be delayed, rewritten, or repealed mid-build, as Colorado's SB24-205 was (delayed twice, then substantially rewritten as SB189) (High likelihood for any single state, Medium impact)
Mitigation: build a state-agnostic core statistical-computation engine with a thin, independently versioned jurisdiction-rules layer per state/city that can be updated or removed without rebuilding the core; do not overweight revenue projections on any single pending-but-not-yet-binding state law; anchor near-term revenue on already-binding NYC and Illinois obligations.
3. Federal EEOC enforcement of disparate-impact theory is deprioritized by executive order, reducing perceived federal urgency (Medium likelihood, Medium impact)
Mitigation: pricing and demand thesis rest on state/local statutory mandates (NYC LL144, Illinois, California) and private Title VII litigation exposure (Mobley-style suits), not on active federal EEOC enforcement; monitor federal posture but do not depend on it for the core revenue case.
4. Employers or AEDT vendors refuse to share the underlying scoring and demographic data needed for a rigorous audit, citing trade-secret or privacy concerns, as Workday resisted producing bias-testing data in Mobley discovery (Medium-high likelihood, High impact)
Mitigation: standardized, legally grounded data-request templates and a documented audit-consent framework; offer tiered audit rigor (full-data audit vs. a lower-rigor, clearly labeled self-reported-metric review where full data access is refused); build direct data connectors to common ATS/AEDT platforms to reduce manual friction and the perceived burden of data-sharing.
5. An audit is later shown, in litigation or regulatory review, to have relied on incomplete or manipulated data, exposing the auditor to a negligent-certification claim (Medium likelihood, High impact)
Mitigation: professional/technology errors-and-omissions liability insurance from day one; explicit data-limitation disclaimers baked into every published summary; confidence-scored findings with a mandatory "insufficient data" outcome rather than a false-positive clean bill of health when data is incomplete.
6. Independent-auditor (statistician/I-O psychologist) capacity becomes a hard ceiling before automation share rises enough to support flat-fee, per-audit pricing (High likelihood, High impact)
Mitigation: cap pilot cohort growth strictly at the 5/10/20-client checkpoints; do not onboard new accounts ahead of measured auditor-minutes-per-case decline; maintain a fractional/contracted auditor panel as elastic overflow capacity.
7. A well-capitalized incumbent (Warden AI, or a large professional-services firm such as Deloitte or Mercer) moves down-market or adds a multi-state notice-drafting layer, eroding whitespace (Medium likelihood, Medium impact)
Mitigation: build the jurisdiction-rules library, AEDT-vendor data connectors, and referral relationships early to create switching costs; target the specific mid-market segment (250-5,000 employees) that Warden's enterprise-first motion and Deloitte's high-touch consulting pricing both currently underserve.
8. A commissioned bias audit finds a genuine disparate impact, and the resulting report becomes discoverable evidence against the client in litigation, deterring some buyers from commissioning a rigorous audit at all (High likelihood, Medium impact)
Mitigation: offer an optional privileged-audit track structured through the client's outside employment counsel where legally supportable (audit commissioned by counsel, findings potentially protected by attorney-client privilege/work product), alongside the standard non-privileged public-summary track the law requires; be transparent with clients up front about the discoverability trade-off of each track.
9. Scope creep into legal-liability opinions about Title VII or state discrimination law, raising unauthorized-practice-of-law exposure (Medium likelihood, High impact)
Mitigation: contractual scope limited strictly to statistical/technical audit work and jurisdiction-specific notice/risk-assessment drafting; legal conclusions about discrimination liability are explicitly out of scope and referred to the client's own employment counsel; the independent auditor certifies statistical findings only, never a legal-liability determination.
10. AEDT/ADMT definitions differ meaningfully across jurisdictions (NYC's "substantial factor" test, Illinois's "influence or facilitate" test, California's "significant decision"/"meaningful human involvement" test), creating scope disputes with clients about whether their tool is even covered (Medium likelihood, Medium impact)
Mitigation: the jurisdiction-applicability screen is delivered as the first, low-cost engagement step for every client, with a documented reasoning trail explaining exactly why a tool is or is not covered under each jurisdiction's specific test.
11. Data-security incident involving sensitive applicant demographic and protected-class data (Low-medium likelihood, High impact)
Mitigation: SOC 2-aligned security practices from day one; encrypted storage; least-privilege access; data-minimization policy retaining only aggregate statistics and purging raw PII post-audit where feasible.
12. Awareness of these obligations remains low among mid-market employers outside NYC, slowing demand growth even as Illinois and California obligations phase in (Medium likelihood, Medium impact)
Mitigation: content/education-led GTM explaining exactly which laws apply to which employers; partnerships with HR-technology vendors, staffing associations, and HR trade groups; pursue listing in ATS/AEDT vendor marketplace app stores to reach buyers at the point of tool adoption.
What Could Kill This
The single most structurally important risk is independent-auditor capacity becoming a hard ceiling before automation share matures enough to support the proposed flat-fee, per-tool pricing, forcing the business back toward an unscalable custom-consulting cost structure. Inferred A second, meaningful risk is that one or more of the still-forming state mandates this blueprint's multi-year revenue thesis depends on (Illinois's implementing rules, California's ADMT enforcement posture, any future Colorado SB189 rulemaking) is delayed, narrowed, or repealed the way Colorado's original SB24-205 was — mitigated by anchoring near-term revenue on the already-binding, already-enforced NYC mandate and treating additional states as upside rather than a load-bearing assumption. A third is that employer/vendor reluctance to commission a rigorous audit, driven by litigation-discoverability concerns of the kind surfaced in Mobley, suppresses demand for the highest-rigor (and highest-value) audit tier — mitigated by the optional privileged-audit track. A fourth, lower-probability risk is a well-capitalized incumbent (an AI-governance platform, a Big Four firm, or Warden AI itself) moving down-market with a comparable multi-state, per-tool-priced offer before this business establishes referral relationships and switching costs.
Go/No-Go Reasoning
This candidate clears the evidence threshold on every required dimension: a clearly identified target buyer (mid-market-to-enterprise employers and HR-tech vendors using AEDTs to screen candidates in NYC, Illinois, or California), a painful and specific problem (a rapidly hardening, non-identical multi-jurisdiction legal patchwork with real civil penalties and, via Mobley, real private-litigation exposure on both the employer and vendor side), verified evidence the problem exists and is severe (96% AI-hiring adoption, a documented compliance-enforcement gap of 17 of 32 employers, three binding mandates arriving on a known multi-year calendar), verified evidence buyers already spend money on adjacent solutions (Warden AI's $1.48M seed round and 150+ published audits, BABL AI's and DCI Consulting's ongoing operation, Deloitte's own LL144 practice), active demand evidence (recurring law-firm client-alert content aimed directly at this population following each new state mandate), competitor and budget validation (three distinct incumbent categories proving spend exists without occupying the AI-native, multi-state, mid-market wedge), a credible reason this service can win (AI-native statistical computation and drafting under independent-auditor-certified, counsel-referral-gated review, at a fraction of a custom-consulting engagement's cost, and broader in jurisdictional coverage than any single identified incumbent), a narrow MVP wedge (the single-tool NYC LL144 Bias Audit & Compliance Scan), a practical path to first sale (the free jurisdiction-applicability screen as a low-friction entry point), a service-delivery workflow fulfillable without a large custom software platform first, no unresolved fatal regulatory blocker (the licensing boundary requires independent-auditor certification for the statistical work and employment-counsel referral for any legal conclusion, and explicitly manages the independence/conflict-of-interest boundary the law itself imposes), a credible path to 50%+ gross margin (automation share rising from 35% to 65% over year one), and a believable distribution path (employment-counsel and HR-tech-vendor referrals, trade-press content, and direct outreach to a documented, describable population of AEDT-using employers). The one dimension requiring explicit, ongoing management rather than a one-time mitigation is the still-forming state-level regulatory landscape, which this blueprint addresses through a state-agnostic core engine with a thin, independently versioned jurisdiction-rules layer and by anchoring near-term revenue on the already-binding NYC and Illinois mandates rather than on any single pending state law.
Final Recommendation
Proceed to build FairScreen as described: launch the AEDT Bias Audit & LL144 Compliance Scan as the first offer within 7 days, cap the first pilot cohort at 5 clients diversified across at least two buyer types (direct employer and HR-tech vendor) and two jurisdictional profiles, and hold the 5/10/20-client build-before-scale checkpoints strictly before expanding intake or introducing the full Multi-State Algorithmic Employment Compliance Subscription and adjacent ADMT-category expansion at scale.
Source List
- NYC Department of Consumer and Worker Protection — Automated Employment Decision Tools
- NYC DCWP — Automated Employment Decision Tools: Frequently Asked Questions
- Office of the New York State Comptroller — Enforcement of Local Law 144: Automated Employment Decision Tools
- DLA Piper — Critical Audit of NYC's AI Hiring Law Signals Increased Risk for Employers
- Warden AI — NYC Local Law 144 Compliance Guide 2026
- Warden AI — AI Bias in Hiring: What 150+ Bias Audits Reveal
- Crunchbase — Warden AI Company Profile and Funding
- TechFundingNews — Warden AI Secures New Funding as the HR World Grapples With AI Bias and Regulation
- BABL AI — NYC Bias Audit
- BABL AI — What Is the NYC AI Bias Audit Law?
- Clark Hill — Colorado's AI Law Delayed Until June 2026
- The Employer Report — AI Regulation on Hold in Colorado, But Employer Risk Isn't
- Akin Gump — Colorado Postpones Implementation of the Colorado AI Act, SB 24-205
- Norton Rose Fulbright — Colorado Enacts Revised AI Law
- Hinshaw & Culbertson — Illinois Adopts New AI-in-Employment Regulations: What Employers Need to Know for 2026
- Epstein Becker Green (Workforce Bulletin) — Navigating Illinois's Draft AI Notice Regulations
- National Law Review — Illinois Anti-Discrimination Law to Address AI Goes Into Effect January 1, 2026
- Seyfarth Shaw — New Illinois AI Law Requires Employee Notice, Affirms Existing Employer Nondiscrimination Duties
- Littler — California's Automated Decisionmaking Technology Regulations: Seven Steps for Employers
- Akin Gump — New California Regulations Regarding Employer Use of ADMT: Compliance Required by January 1, 2027
- Skadden — California Finalizes CCPA Regulations for Automated Decision-Making Technology, Risk Assessments and Cybersecurity Audits
- California Privacy Protection Agency — Announcement, September 23, 2025
- CDF Labor Law — California Finalizes AI Regulations for Automated Decision-Making Technology
- Fisher Phillips — EEOC's Latest AI Guidance Sends Warning to Employers
- FordHarrison — EEOC's Guidance on Artificial Intelligence in Hiring
- K&L Gates — EEOC Issues Nonbinding Guidance on Permissible Employer Use of AI to Avoid Adverse Impact Liability Under Title VII
- Akin Gump — Court Allows Discrimination Claims Against AI Hiring Tool to Proceed (Mobley v. Workday, Inc.)
- Forbes — A Federal Judge, a 1967 Law, and a Billion Rejected Job Applications
- Duane Morris — California Federal Court Clarifies Limits on AI Bias Testing and Applicant Data Disclosure in Mobley v. Workday
- Seyfarth Shaw — Mobley v. Workday: Court Holds AI Service Providers Could Be Directly Liable Under "Agent" Theory
- SQ Magazine — AI Recruitment Statistics 2026: Hiring Trends & Data
- The Interview Guys — How Many Companies Are Using AI to Review Resumes?
- Mordor Intelligence — HR Compliance Software Market Size, Share & Forecast
- Future Market Insights — Enterprise AI Governance and Compliance Market
- Precedence Research — AI Governance Market Size, Share and Trends
- FinCEN — FinCEN Removes Beneficial Ownership Reporting Requirements for U.S. Companies and U.S. Persons
- Drug Enforcement Administration — DEA Extends Telemedicine Flexibilities to Ensure Continued Access to Care
- Special Needs Alliance — Do I Really Need a Professional Trustee for My Special Needs Trust?