Illinois

Illinois AI Regulations: BIPA, HB 3773, and What They Mean Together

Illinois has two separate AI-relevant statutes on the books, not one, and conflating them is how compliance teams miss real obligations under both.

Both statutes in force; HB 3773 notice rules withdrawn, not yet refiledEffective January 1, 2026
Compliance and HR staff at an Illinois company reviewing biometric and AI hiring policy documents
Photo: Vitaly Gariev via Unsplash

Illinois has two statutes that touch AI, and they have almost nothing in common. One is sixteen years older than the other. One cares what kind of data you're touching; the other cares what kind of decision you're making. One lets an individual sue you directly; the other routes through a state agency first. Search "Illinois AI law" and most of what comes back treats these as a single regime, which is exactly how a compliance team ends up fully covered on one statute and exposed on the other without noticing.

Two statutes, not one

The Biometric Information Privacy Act — BIPA, codified at 740 ILCS 14 — became law in 2008. It has nothing to do with artificial intelligence by design; it was written to govern fingerprint timeclocks and access-control scanners, and it applies to any private entity that possesses a biometric identifier or biometric information, regardless of what technology captured it. A decades-old fingerprint reader and a brand-new AI-powered facial-recognition login trigger identical obligations under BIPA, because the statute's trigger is the data, not the method.

House Bill 3773, by contrast, is squarely an AI statute. Enacted in August 2024 as Public Act 103-0804 and effective January 1, 2026, it amends the Illinois Human Rights Act to regulate how employers use AI in employment decisions — hiring, promotion, discipline, termination, and related calls. It doesn't mention biometrics at all. A company could violate HB 3773 using a resume-ranking model that never touches a photo, video, or voice sample.

Because these two laws arrived sixteen years apart, got written by different legislative sponsors for different reasons, and get enforced through different mechanisms, treating them as one "Illinois AI compliance" project is the single most common mistake a multi-state compliance program makes here. They need to be tracked, and owned, separately.

What BIPA actually requires

BIPA's trigger is narrow and specific: a biometric identifier (retina or iris scan, fingerprint, voiceprint, or scan of facial geometry) or biometric information derived from one of those identifiers. Illinois courts have been clear that a photograph by itself isn't a biometric identifier — but a face-geometry template an AI system extracts from that photograph is, which is exactly the fact pattern that keeps pulling modern AI tools into a 2008 statute.

Before collecting any biometric identifier, a covered entity has to have a written, publicly available policy already in place establishing a retention schedule and destruction guidelines — an Illinois appellate court has specifically held that writing the policy after collection starts doesn't satisfy the requirement. Biometric data has to be destroyed within three years of a person's last interaction with the company, or when the purpose for collecting it has been satisfied, whichever comes first. And the entity needs informed written consent before collection or disclosure; since an August 2024 amendment (SB 2979), an electronic signature satisfies that written-consent requirement, closing off an argument some defendants had tried to make.

BIPA's enforcement edge — and the 2024 change that dulled it a little

What makes BIPA unusually dangerous compared to most privacy statutes is its private right of action: an aggrieved person can sue directly, without filing a complaint with a regulator first, and recover $1,000 per negligent violation or $5,000 per intentional or reckless violation, plus attorneys' fees. Illinois litigation under BIPA has produced some of the largest biometric-privacy exposure in the country.

The same August 2024 amendment that fixed the electronic-signature question also addressed the damages math directly: violations now accrue per person rather than per scan, so repeated scans or collections involving the same individual support one recovery, not a multiplier for every single scan. That change meaningfully caps the most extreme exposure scenarios — the kind that produced nine- and ten-figure verdict estimates in earlier litigation — without eliminating liability. A company that skips the written policy or collects biometric data without consent is still exposed; it just isn't exposed to the same runaway multiplication effect it would have faced before the amendment.

What HB 3773 actually requires

HB 3773 creates three independently actionable civil rights violations under the Illinois Human Rights Act. First, using AI in a way that has the effect of subjecting employees or applicants to discrimination on a protected-class basis in recruitment, hiring, promotion, discipline, termination, or similar decisions — the statutory hook for what's generally discussed as algorithmic bias in a hiring or promotion model. Second, using a zip code as a proxy for a protected class — a standalone prohibition, meaning a regulator doesn't need to separately prove discriminatory effect once zip-code substitution is shown. Third, failing to provide required notice when AI is used in a covered employment decision.

Coverage is broad: the same Illinois Human Rights Act threshold that's applied since a 2019 amendment took effect in July 2020 governs HB 3773 too — any employer with one or more employees working in Illinois during 20 or more calendar weeks in the current or preceding calendar year. There's no 15-employee floor and no small-business carve-out; a five-person Illinois office is covered the same way a thousand-person employer is.

The gap nobody's enforcing yet

Here's the detail that's missing from most compliance checklists built right after HB 3773 passed: the law has been in effect since January 1, 2026, but nobody currently knows exactly what a compliant notice looks like. The statute directs the Illinois Department of Human Rights to adopt rules addressing when notice is required, how much time employers get to provide it, and what form it has to take. IDHR proposed those rules on May 15, 2026 — then withdrew them on June 2, 2026, canceled the public hearing that had been scheduled for June 10, and gave no new timeline, saying the postponement was needed to allow continued coordination with other state agencies.

That leaves employers in an odd position: the underlying statutory duty to notify is unquestionably in force, but its exact contours — the thing a company would actually build a notice template around — are currently undefined by rule. The discriminatory-effect and zip-code-proxy prohibitions aren't affected by this gap; those apply on their own terms regardless of what IDHR eventually decides about notice mechanics. The responsible position for an employer right now is giving AI-use notice in good faith, documenting the choice, and planning to adjust the template once rules actually land — not waiting for a final rule before doing anything at all.

Where the two statutes collide

Take Lakeshore Fulfillment, a hypothetical Illinois warehouse operator that licenses a third-party AI video-interview product to screen applicants for shift-lead roles. The tool records each candidate's responses and scores facial expressions and vocal tone to generate a recommendation the hiring manager sees before deciding.

That single product sits inside both statutes at once. The facial-expression scoring extracts biometric information — a scan of facial geometry — from each recording, which means Lakeshore needs a BIPA-compliant written retention-and-destruction policy in place before the first interview is recorded, plus informed written consent from each candidate. Separately, because the tool's output feeds a hiring decision, Lakeshore also has to make sure the scoring model doesn't produce a discriminatory effect on a protected-class basis, isn't using zip code as a hidden proxy for anything, and that candidates get the HB 3773-required notice that AI is part of the process. A vendor contract that only addresses one of those two statutes — which is common, since the vendor itself may only be thinking about the employment-law side — leaves Lakeshore holding the other half of the exposure alone.

Running compliance for both at once

The practical fix is organizational as much as legal: BIPA and HB 3773 should be two separate workstreams with two separate owners, not one "Illinois AI" checklist. A privacy or security function typically owns BIPA — policy drafting, consent flows, retention tracking — regardless of whether AI is anywhere near the system in question. HR and employment counsel own HB 3773 — notice design, discriminatory-effect testing, zip-code exposure review — regardless of whether the AI system touches biometric data at all. The only place those two owners need to talk to each other is exactly the overlap case above: any AI tool that both processes biometric data and informs an employment decision needs sign-off from both sides before it goes live, not after a complaint arrives. For companies tracking exposure across more than one state, our Texas TRAIGA breakdown and California's fragmented AI regulatory tracks are worth reading alongside this one — no two states are building their AI-employment rules the same way, which is also the throughline of the broader fight over whether federal law can override any of these state statutes.

Frequently asked questions

Is BIPA an AI law?
No. The Illinois Biometric Information Privacy Act was enacted in 2008, more than a decade before today's AI systems existed, and it never mentions artificial intelligence. It regulates any private entity that possesses a biometric identifier or biometric information, full stop — a fingerprint timeclock and a decades-old access-control fingerprint reader trigger it exactly the same way an AI-powered facial-recognition login does. BIPA becomes an "AI law" only in the specific case where an AI system happens to process biometric data.
Does HB 3773 require Illinois employers to get consent before using AI in hiring?
No — it requires notice, not consent. HB 3773 makes it a civil rights violation to use AI in a way that has a discriminatory effect on employment decisions, to use zip codes as a stand-in for a protected class, and to fail to notify employees or applicants when AI is used in specified employment decisions. There's no opt-out and no consent mechanism written into the statute; the obligation is disclosure, not permission.
What are the current notice requirements under HB 3773?
Unsettled, as of this writing. The Illinois Department of Human Rights proposed rules on May 15, 2026 spelling out when, how, and in what form employers must give notice, then withdrew them on June 2, 2026 and canceled the public hearing that had been scheduled for June 10, citing a need for continued coordination with other state agencies. No new rulemaking timeline has been announced. The statutory notice duty itself took effect January 1, 2026 regardless of the missing rules — employers are expected to comply with the underlying obligation in good faith rather than wait for a final regulatory template.
Can one AI system be subject to both BIPA and HB 3773?
Yes, whenever a system both captures biometric data and feeds an employment decision. The clearest example is an AI video-interview tool that scores facial expressions or vocal tone to help a hiring manager rank candidates. That one system needs a BIPA-compliant written policy and consent flow for the biometric capture, and separately has to clear HB 3773's discriminatory-effect, zip-code, and notice obligations for the employment-decision use. Satisfying one statute tells you nothing about whether you've satisfied the other.
Who enforces each law?
BIPA runs on a private right of action — a person can sue directly and recover statutory damages without going through a regulator first. HB 3773 violations are civil rights violations under the Illinois Human Rights Act, which go through the Illinois Department of Human Rights' standard charge-and-investigation process rather than a direct lawsuit in the first instance.

Sources & references

  1. Official source
  2. 740 ILCS 14, Illinois Biometric Information Privacy Act (full text)
  3. LegiScan — Illinois HB 3773 (2023-2024 session), bill text and history
  4. Seyfarth Shaw — Illinois Department of Human Rights Temporarily Withdraws Proposed Rules on Use of Artificial Intelligence in Employment
  5. Greenberg Traurig — BIPA Update: Illinois Limits Liability and Clarifies Electronic Consent for Biometric Data Collection
  6. Morgan Lewis — Illinois Passes New Law to Address AI in the Workplace
  7. Jackson Lewis — Illinois Expands State Human Rights Act to Include Employers with One or More Employees
Compliance counsel reviewing California automated decision-making rules
Photo: Amina Atar via Unsplash

regulations us california

California AI Regulations

California regulates AI through several parallel tracks rather than one comprehensive law: CPPA rulemaking on automated decision-making technology, generative AI disclosure statutes, and employment law amendments.
Governome Editorial Team · 2 min read
Compliance staff at a Texas company reviewing AI system documentation in an office setting
Photo: Vitaly Gariev via Unsplash
TRAIGA (HB 149) took effect January 1, 2026, with a prohibited-practices list and an intent-based liability standard that's deliberately harder to trigger than Colorado's reasonable-care duty. Here's who it covers, what it bans, and how enforcement actually works.
Governome Editorial Team · 8 min read
Attorneys reviewing federal court filings in a lawsuit challenging a state AI law
Photo: Amina Atar via Unsplash
An executive order can't preempt state law by itself. Real preemption needs an act of Congress, a court ruling, or funding leverage coercive enough to force repeal — and the federal government's most advanced attempt at any of the three just got mooted by the state rewriting the law it was suing over.
Governome Editorial Team · 8 min read

risk management

Algorithmic Bias

A systematic pattern in a model's outputs that disadvantages a particular group, arising from training data, feature selection, or optimization choices rather than random error.
Governome Editorial Team · 2 min read