Review copy. Publication details are being completed. This copy is not available for contractual acceptance.
Version 2026-09-14.1 · Permanent link to this version · U.S. legal documents
Version history
- Version 2026-09-14.2 — Prepared 2026-09-14 · Draft — not published
- Version 2026-09-14.1 — Prepared 2026-09-14 · Draft — not published
- Version 2026-09-13.1 — Prepared 2026-09-13 · Draft — not published
1. What these requirements cover
A supplier may host information, run an AI model or provide another part of a hiring service. Evidize LLC is responsible for the legal duties that apply to suppliers it appoints. Your organization is responsible for suppliers it appoints. The requirements depend on the actual service, data and applicable law.
2. Identify the service and its purpose
The parties must identify the supplier and describe the purposes and processing in any contract required by law. A supplier’s role depends on what it actually does: processing on another business’s behalf is different from using information for its own purposes.
The applicable agreement identifies the authorized services. This page does not identify the suppliers currently used or represent that their practices have been independently verified.
3. Use the required contract protections
For covered service-provider, contractor or processor arrangements, the contract must contain the protections described in the Data Agreement. These include the applicable purpose and reuse limits, privacy-request assistance, security, subcontractor terms, and rights to check compliance and remedy unauthorized use. Assistance with audits or risk assessments is required when the relevant law requires it.
A recipient using information as a third party may need different contract terms and notices. It cannot be treated as a service provider merely because the agreement uses that label. AI training or improvement must fit the recipient’s actual role, permitted uses and applicable notices or choices.
4. Information from a covered hiring-AI developer
From January 1, 2027, Colorado’s automated-decision law requires covered developers to give organizations using the covered technology information about intended and known harmful uses, known limitations, training-data categories to the extent known, and instructions for appropriate use, monitoring and human review where applicable. The developer must also provide information reasonably needed for the organization’s required disclosures, subject to the law’s protections for confidential information. If the developer withholds information, it must notify the organization.
For those covered uses, the developer must notify those organizations of material updates and specified changes within a reasonable time. Public release notes can be used if each organization receives direct notice of them. Required developer records must be kept for at least three years, or longer where another law requires. These duties apply to Evidize when it is the covered developer; they do not apply to every hosting or software supplier.
5. Connecticut provider information
For covered employment-technology deployments on or after October 1, 2027, a covered developer must supply information needed for the deployer’s applicable notices. Any required withholding notice must state the fact and basis of withholding. The duties follow Public Act 26-15, sections 8–11. Evidize does not assume the employer’s notice duties merely by supplying this information.
The provider-information document supplies a shared release format. It remains draft until its actual product facts and applicability are verified.
6. Changes and compliance
The responsible party must keep the arrangement within the uses allowed by the applicable law and agreement. If a change triggers new notices, contract terms, assessments or permissions, those requirements must be met at the time the law requires.
California’s service-provider rules give a business rights to check and remedy compliance, and due diligence can affect the business’s liability. They do not require the same independent audit or technical test for every supplier. This document does not add a separate supplier approval process.