The Rules on AI Keep Changing. The Principle Shouldn’t.

Colorado had passed one of the most ambitious laws anywhere governing how AI can be used in decisions about people — hiring, promotion, pay, performance. It was due to take effect this month. Instead, in the space of a few weeks, it was challenged in court, paused, and then rewritten into a narrower law that won’t arrive until 2027.

Meanwhile, other rules are already here. California now regulates how employers use automated tools in employment decisions. Illinois requires companies to tell employees when AI is involved in decisions about them. Closer to home for many of us, Ontario now requires employers to disclose in job postings when AI is used to screen, assess, or select candidates. And the EU — whose AI Act has been phasing in since 2024 — just agreed to push back its own employment-related AI rules to late 2027.

Different countries. Different rules. Constant revision.

But underneath all of it, every one of these frameworks is circling the same simple idea:

When a decision affects someone’s career, a human should be meaningfully involved — and people deserve to know how that decision was made.

We find it telling that the world is busy writing laws for that. Not because the laws are wrong. Because of what made them feel necessary.

How we got here

Over the past two years, organizations of every size have moved quickly to bring AI into their people processes. Screening applications. Summarizing performance. Highlighting patterns in engagement and attrition.

Much of it genuinely helps. We use AI every day in our own work at HumanLI, and we’re optimistic about it. When technology takes over the transactional load, people teams finally get time for the work that matters most — coaching managers, designing better roles, having the honest conversations.

But in the rush, something subtle can shift. It rarely happens deliberately, and it’s rarely anyone’s fault.

“The system recommended it” quietly starts to feel like an answer.

A rejection nobody quite wrote. A rating nobody can fully explain. A decision that technically had a human in the loop — but not a human who truly owned it.

No bad intentions required. Just speed, scale, and a tool that makes it easy to move on to the next thing.

What people can and cannot accept

Here’s what more than two decades in HR has taught us:

People can accept a tough decision. They can accept not getting the role, the rating, the promotion. What they struggle to accept is a decision no one is willing to stand behind.

The moment an employee or candidate senses that no human really looked, really weighed, really decided — trust doesn’t erode slowly. It breaks.

And once trust breaks in people processes, everything else gets harder. Engagement programs, performance frameworks, retention efforts — all of them start underperforming, no matter how well-designed they are.

AI can process a thousand applications in a minute. It cannot sit across from someone and explain why.

That part is still ours. And honestly, that’s good news — it’s the part most of us got into this work for.

A question worth asking — wherever you operate

Here’s the trap in all this regulatory movement: treating it as a compliance problem. Waiting for the final rules. Letting legal own it.

The rules will keep changing. Colorado just proved that — and so did Brussels. What shouldn’t change is the principle — and principles live in culture, not in statutes.

So if your organization is bringing AI anywhere near hiring, promotions, pay, or performance, here’s a question worth raising at your next leadership meeting — regardless of which laws apply to you:

For every decision these tools touch, can we name the human who owns it?

Not the vendor. Not the algorithm. Not “the process.” A name.

If the answer takes more than a few seconds, that’s a useful starting point. In practice, three things help:

  1. Know where AI is influencing people decisions today. Including the tools individual managers may have adopted on their own. In most organizations, the real footprint is larger than leadership assumes — not from bad intent, simply from how fast these tools have spread.
  2. Build ownership, not just oversight. “A human reviews it” is not the same as “a human owns it.” Ownership means someone understands the decision well enough to explain it to the person affected — and is willing to.
  3. Prepare managers for the conversation, not just the tool. Most AI training teaches people how to use the system. Very little teaches them how to stand behind its outputs — or push back on them. That capability gap will matter far more than any single regulation.

The bigger point

Regulation, in its imperfect and ever-shifting way, is catching up to something good people practice has always known: technology can inform a decision about a person. It cannot absorb responsibility for one.

The organizations that get this right won’t treat human involvement as a box to tick when the rules finally settle. They’ll treat it as what it has always been — the thing that makes people stay, trust, and do their best work.

The laws will keep being rewritten.

The principle shouldn’t need to be.

HumanLI helps growing organizations build people practices that scale — with the right balance of technology, structure, and human judgment. This article is a practitioner’s perspective, not legal advice; if you’re assessing compliance obligations, please consult qualified counsel in your jurisdiction. And if you’re thinking through AI in your people processes, we’d love to compare notes, contact us.