← Back to blog
VendorsNYC Local Law 144EU AI ActLiability

"Our Vendor Handles Compliance." The Four Words That Won't Save You.

PeopleNotResumes··4 min read

It is one of the most reasonable-sounding assumptions in hiring, and one of the most expensive. You bought the software, the vendor is the expert, so surely the vendor takes care of the legal side. It feels obvious. It is also, in almost every case, wrong.

Here is the uncomfortable truth about NYC Local Law 144 and the EU AI Act: the obligations attach to the company using the tool, not the company selling it. That means you. A vendor can be a genuinely helpful partner, but it cannot absorb a responsibility the law places squarely on the employer.

Why the responsibility can't transfer

Local Law 144 requires the employer to complete an independent bias audit, publish the results, and notify candidates. Nothing in the law lets you hand those duties to your vendor. The EU AI Act does split obligations between the provider that builds a tool and the deployer that uses it, but the deployer, which is what most employers are, still carries its own non-transferable duties around oversight, monitoring, and transparency.

So the vendor's promise to "handle compliance" is, at best, marketing shorthand for "our tool won't make it harder." At worst, it is a misunderstanding that leaves you exposed while you believe you are covered.

The part that catches people off guard

Here is the twist that surprises even careful buyers. Under Local Law 144, your bias audit has to be run by an independent party, one with no role in building, selling, or using the tool. Your vendor built and sells the tool. That disqualifies them from being your auditor.

So not only can the vendor not carry your compliance, the vendor is specifically barred from doing the one piece of it that feels most technical. They can hand over the underlying data. They cannot sign the audit. You need an independent third party for that. We unpack the full split in Vendor vs. Deployer: Who Is Responsible for AI Hiring Compliance?.

What to actually ask your vendor

The goal is not to distrust your vendor. It is to use them correctly. A good vendor relationship makes your compliance easier, and the way to set that up is to ask, before you sign: Will you provide the bias audit data an independent auditor needs? Will you cooperate with an auditor we choose? Can you give us technical documentation for the jurisdictions we operate in? A vendor who answers those easily is a keeper. A vendor who bristles is telling you something.

The bottom line

If you take one thing from this: buying compliant software is not the same as being compliant. The tool can help. The obligation is yours. The companies that get caught out are usually not careless, they just trusted four comforting words a little too far.

Want to know exactly which compliance duties are yours versus your vendors'? A Compliance Score produces a clear responsibility map across your whole stack.