Artificial intelligence (AI) regulations differ in form but converge when protecting those the technology affects most. In this Q&A, Fran and Francesco explore what employers should know with respect to employee AI protections globally—frameworks, compliance risks, transparency, and accountability—and what actions international businesses need to take now.
Francesco Rotondi, M.Sc., Ph.D., is the founder and managing partner of LabLaw–Rotondi & Partners Law Firm, the leading Italian law firm in labor law and industrial relations. For more than 30 years, he has advised major Italian and multinational companies on labor law, industrial relations, large reorganizations, and the transformation and innovation of workplaces.
Frances M. Green, J.D., LL.M., Cybersecurity and Data Privacy, is an attorney at Epstein Becker Green. A seasoned trial lawyer with recognized expertise in data privacy, cybersecurity, and AI governance, Fran guides global clients through the fast-evolving legal landscape of workforce management and data protection — and the high-stakes opportunities and risks of designing and deploying artificial intelligence (AI), from consumer tools to every stage of the employment life cycle.
How do recruitment and hiring practices involving AI differ across the four frameworks of Italy, the European Union (EU), China, and the United States from a legal standpoint?
Italy and the EU. The European approach opens with a seemingly simple premise: the use of AI throughout recruitment practices can actively determine the gain or loss of a professional opportunity, with respect to both the firm and the individual.
The EU AI Act, Regulation (EU) 2024/1689, treats systems used to screen applications, rank candidates, or assess suitability as high-risk. Employers are allowed to utilize such tools, with an expectation regarding the awareness and understanding of the system’s evaluation mechanisms, algorithms, and outputs. Human oversight and monitoring ought to be ensured. The General Data Protection Regulation (GDPR) adds protection where profiling or automated processing significantly affects a candidate. Italy follows this logic within its employment-law framework. Legislative Decree No. 152/1997, as amended in 2022, establishes that when automated systems affect recruitment or employment management, sensitive data must be protected and treated appropriately as defined by data-protection directives.
Merely disclosing AI use is not sufficient. Employers are expected to clearly explain what the system assesses, how its output is utilized and the duties of the respective responsibility-bearing human. Law No. 132/2025 confirms this principle: AI may assist the decision-making process, but ultimately it cannot replace human professional judgment throughout HR processes.
China. This common theme of AI enablement, but not ultimate decision making, is reflected in China’s focus on data and algorithmic fairness. Under the Personal Information Protection Law, automated decisions must be transparent, fair, and open to explanation and/or challenge whereby an individual’s professional status and human condition are impacted.
Notwithstanding differences in emphasis, a common principle appears to be applied: the platform may be envisioned, operated, and maintained globally, provided that all notices, evaluation criteria, and review procedures are adapted to comply and conform with local requirements.
How this impact may be effectively governed and incorporated into a coherent, balanced, and comprehensive regulatory framework is receiving increasing and thoughtful attention from public institutions and industry organizations worldwide, including the Italian National Council for Economics and Labour (CNEL), the Italian Ministry of Labour and Social Policies, Officina Risorse Umane (ORU) Human Resources Workshop, and numerous specialized think tanks.
United States. In the United States, AI in one form or another has become embedded in nearly every stage of the recruitment and hiring lifecycle—from resume screening and candidate ranking to video interview analysis and automated assessments. But as adoption has accelerated, so has regulation, and the throughline across the emerging patchwork of federal, state, and local requirements is unmistakable: AI may assist employment decisions, but it may not replace human judgment. Employers remain fully accountable for the outcomes their tools produce, and regulators are increasingly demanding that a human being remain meaningfully “in the loop.”
This foundation follows longstanding civil rights law. The Equal Employment Opportunity Commission (EEOC) has affirmed that AI tools fall within Title VII enforcement and that long-standing civil rights statutes remain fully applicable to AI-driven employment decisions, with or without new federal legislation. In other words, an employer cannot outsource liability to an algorithm or its vendor. If an AI screening tool produces disparate treatment of an individual employee or a disparate or adverse discriminatory impact on a protected class of applicants or employees, the employer that deployed it bears the legal consequences—which is precisely why documented human review of AI-influenced decisions has become a compliance imperative rather than a best practice. State and local laws in many U.S. jurisdictions now make that oversight obligation explicit.
The practical takeaway for employers operating in the U.S., and within the global environment, is that human oversight cannot be nominal. A recruiter who rubber-stamps an algorithm’s rankings is not “oversight” in the eyes of regulators or plaintiffs’ counsel. Meaningful oversight means trained personnel who understand what the tool measures and its limitations, who exercise independent judgment on individual candidates, who have genuine authority to depart from the AI’s recommendation, and whose review is documented. Employers should inventory their AI hiring tools, interrogate vendor claims about bias testing, build notice and opt-out mechanisms where required, and — above all—design “decision workflows” in which the AI informs, and a human decides.
What are some of the biggest compliance risks businesses face when using algorithmic management and employee monitoring tools across these jurisdictions?
Monitoring of employees within the workplace has become an increasingly vexing trend hastened by the advent of the hybrid or remote workplace. From recruitment and onboarding to performance management and promotion as well as termination decisions, AI has been utilized at greater frequency with the hope of increased efficiency and objectivity in the ultimate decision. Indeed, although two things can be true at the same time—greater efficiency and objectivity—the ineluctable fact is that AI within those decisions are fraught with risk. The greatest compliance risk is that a legitimate management tool may be challenged as a system of pervasive monitoring or automated control, beyond the realm of human awareness. A platform can be designed accordingly to allocate work and measure productivity, whilst simultaneously collecting information about movements, communications, and behavior.
United States. Currently in the U.S., among states regulating an employer’s use of AI tools or systems, employee monitoring can result in claims of wrongful termination, illegal bias, common law privacy and violations of state laws, such as the Illinois Biometric Information Privacy Act (BIPA) that prohibits the collection of biometric identifiers of employees—such as fingerprints, retinal scans or other forms of gathering of sensitive personal information including facial recognition. Biometric intrusion claims continue to be one the fastest growing categories of employee monitoring challenges and states have reacted accordingly to protect employees, with almost a dozen states, at least, either enacting such statues or considering them in legislative sessions.
In addition to legislative restraints on AI monitoring in the workplace, employees are challenging in U.S. courts their employer’s use of AI tools not only in recruitment and onboarding (see, e.g., Mobley v Workday) but in termination decisions. Recently, AI monitoring metrics generated by Meta and alleged to be the basis for a reduction in force have resulted in a class action litigation filed in U.S. federal court in July 2026.
In that case, filed in California, Does 1 through 26 v. Meta Platforms Inc., 26 current and former Meta employees subject to a scheduled layoff allege that the company relied on AI-assisted monitoring and evaluation systems—including productivity scores, AI “token usage” metrics, and internal ranking platforms—in selecting employees for termination. The aggrieved employees assert claims under Title VII of the Civil Rights Act, the Family and Medical Leave Act, and the Americans with Disabilities Act, arguing that AI metrics enabled bias against employees with disabilities, employees on medical leave, and caregivers, and that Meta failed to audit the systems for bias as required under recently adopted California and New York City AI employment regulations. Meta denies that AI made the layoff decisions, and the case is still pending.
The significance of the case lies in its theory: plaintiffs do not contend that AI acted autonomously, but that AI-assisted surveillance data contaminated a human decision-making process with hidden bias. Employers can expect this framing to recur wherever monitoring outputs feed discipline, performance management, or reduction-in-force selection.
Europe. In Europe, much like the U.S., human oversight and decision making must be consistent, tangible, and identifiable, most defensively through a traceable and documented process and regulated framework. The mere confirmation of an automatically generated result cannot be synonymous with oversight and cannot result in a significant employment decision without a human overseer who can be accountable for the ultimate conclusions. The reviewer must understand the generated output and be in a position to adjust, disregard or terminate the system if necessary. Additionally, the EU AI Act prohibits workplace emotion-recognition systems, with limited, restricted exceptions.
Italy. Italy’s AI Act further strengthens the safeguards afforded to employees while placing greater responsibility on employers that deploy AI systems in the workplace. In particular, the use of such systems must remain consistent with the protection of human dignity, personal data, and the fundamental rights of workers, while ensuring transparency, human oversight, and clear accountability throughout the decision-making process. Employers must therefore be able to explain how AI-supported decisions are reached and to ensure that technology assists—rather than replaces—meaningful human judgment, especially where decisions may materially affect an individual’s employment.
Further protection is afforded under Article 4 of the Italian Workers’ Statute. Where an AI-enabled tool is capable of monitoring employees or reconstructing their activities, its introduction may require a prior agreement with employee representatives or, failing that, authorization from the competent Labour Inspectorate. The legal and compliance risks become particularly acute where the information collected or generated by the system may influence remuneration, promotion, disciplinary measures, or termination of employment. An opaque algorithmic score should therefore never, by itself, determine a decision capable of materially affecting an employee’s working life.
United States. This is not dissimilar to the prohibitions under the U.S. National Labor Relations Act (NLRA). Section 7 guarantees employees—union and non-union alike—the right to engage in concerted activities for mutual aid or protection, and Section 8(a)(1) makes it an unfair labor practice for an employer to interfere with, restrain, or coerce employees in the exercise of those rights. Surveillance doctrine under these provisions long predates AI, but the technology has sharpened the stakes considerably. Thus employee monitoring remains a viable basis for unfair labor practice charges and union election objections under decades of settled doctrine.
China. China’s answer to AI employee monitoring, meanwhile, is a two-layer regime—the Algorithm Recommendations Provisions discipline the design of algorithmic management where delivered as a platform service (Article 20’s worker-welfare mandates), while the Personal Information Protection Law disciplines the data side for all employers through necessity, minimization, separate consent for biometric and location inputs, and impact assessments. Although neither layer prohibits monitoring outright, both make undisclosed, disproportionate, or biometric-heavy monitoring legally hazardous.
How do transparency and accountability obligations for AI systems compare across these four different legal frameworks, and what should international employers be doing now to prepare?
Transparency requires more than simply stating that AI is being used. Employers should explain why a system was selected, what data it uses, which decisions it supports, and who reviews its results.
Europe. In Europe, the EU AI Act and the GDPR require documented governance. Companies must assess risks, assign responsibilities, ensure human oversight, and keep records demonstrating compliance. The employer remains responsible even when a provider supplies the system.
Italy. Italy adds an additional dimension: responsibility extends to occupational health and safety with a human-centered perspective of the regulation. Legislative Decree No. 81/2008 is relevant when AI affects workloads, work pace, work methods, or psychosocial risks. Employers should evaluate technical reliability and changes in working conditions.
This anthropocentric approach has attracted growing attention within CNEL, reflecting an increasing awareness that AI governance, the protection of workers’ health and safety, and the organization of work are inextricably intertwined and must therefore be addressed within a coherent and integrated framework.
China. China emphasizes preventive controls according to the Personal Information Protection Law (PIPL), the Data Security Law, and the Cybersecurity Law. Companies need to know where the data is stored, who can access it, and whether automated decisions can be explained and reviewed.
United States. Transparency and accountability under current U.S. state AI laws and federal government agency frameworks operate as a mutually reinforcing loop in current state AI statutes. Transparency mechanisms—notice to applicants, disclosure of what the tool measures, published bias audit results—are not ends in themselves; they exist to create accountability. Notice tells a rejected candidate that AI was involved, which enables her to ask questions, request an alternative process, or bring a claim. A published audit summary under NYC Local Law 144 provides regulators with a documentary record against which the employer’s actual outcomes can be tested. In that sense, transparency is the evidentiary infrastructure of accountability as the employer becomes responsible for the decision process. Conversely, accountability requirements drive transparency inward—recordkeeping, risk assessments, and impact analyses force employers to understand their own tools well enough to document them, which may be the first time an organization genuinely scrutinizes what its vendor’s algorithm is doing. California’s Civil Rights Council regulations make this explicit by treating the presence or absence of bias testing as relevant evidence in a discrimination claim.
Unlike the EU AI Act, which imposes substantive ex ante product-safety obligations (conformity assessments, human oversight by design, prohibited practices), most U.S. state laws are procedurally oriented. They rarely ban tools or prescribe how algorithms must work. Instead, they layer disclosure duties (Illinois HB 3773, Colorado SB 26-189's notice obligations, California's automated decision-making technology (ADMT) pre-use notices), audit or assessment duties (Local Law 144's independent bias audits, California's risk assessments), and liability (Illinois folding AI into the Human Rights Act; the EEOC's position that Title VII applies regardless). (For a full overview of these developments, see EBG's State AI Law Tracker.) The theory is essentially disclosure-based regulation in the securities-law tradition: sunlight plus existing liability rules will discipline behavior. That's a distinctly American regulatory instinct.
Conclusion
The direction of the current AI laws in global jurisdictions appears aligned: greater transparency, clearer accountability, and meaningful human oversight. For multinational employers, the most effective model is a single global framework with local safeguards: mapping systems, assigning responsibility, reviewing suppliers, limiting data collection, and establishing effective human review.
Governing AI does not mean slowing down innovation. It means ensuring that technology is designed and deployed with compliant and measurable guardrails and that decisions affecting impacting employee livelihood are understandable, verifiable, and administered with responsible human oversight.
About the Authors:
Francesco Rotondi, M.Sc., Ph.D., is the founder and managing partner of LabLaw – Rotondi & Partners Law Firm, the leading Italian law firm in labor law and industrial relations. He is an Expert Advisor of the National Council for Economics and Labour (CNEL), where he chairs the Permanent Observatory on Health and Safety at Work.
Francesco serves as an Expert at the Ministry of Labour and Social Policies and is an adjunct professor of Labor Law at LIUC – Carlo Cattaneo University and Scientific Director of Work on Work and ORU (Officina Risorse Umane) – Human Resources Workshop, a think hub platform dedicated to innovation in HR and the future of work.
For more than 30 years, he has advised major Italian and multinational companies on labor law, industrial relations, large reorganizations, and the transformation and innovation of workplaces. A regular speaker and author, Francesco is consistently recognized among Italy’s leading employment lawyers by Chambers Europe, The Legal 500, and other major international legal directories.
Frances M. Green, J.D., LL.M., Cybersecurity and Data Privacy, is an attorney at Epstein Becker Green. A seasoned trial lawyer with recognized expertise in data privacy, cybersecurity, and AI governance, Fran guides global clients through the fast-evolving legal landscape of workforce management and data protection — and the high-stakes opportunities and risks of designing and deploying artificial intelligence (AI), from consumer tools to every stage of the employment life cycle.
Fran regularly advises on automated employment decision tools (AEDTs) and algorithmic bias, AI bias audits and testing protocols, and emerging AI and privacy statutes across US jurisdictions, as well as federal and state agency guidance, the EU AI Act, cross-border compliance, workplace monitoring, and cybersecurity preparedness. She has extensive experience designing enterprise AI governance frameworks, counseling on AI acceptable use and literacy programs, and guiding organizations through privacy risk assessments and regulatory change.
Deeply engaged in the professional community shaping responsible AI, Fran is a member of the Society of Actuaries AI Safety Institute Consortium and is privileged to serve as a working group member of the NIST Artificial Intelligence Consortium.
Fran counsels executives and boards across industries including finance, insurance, retail, manufacturing, and healthcare, pairing courtroom-tested judgment with practical, business- minded advice. Fran is certified by the International Association of Privacy Professionals as an Artificial Intelligence Governance Professional and a Certified Information Privacy Manager.
Epstein Becker Green Staff Attorney Ann W. Parks contributed to the preparation of this article.




.png)