AI did not create a legal vacuum in hiring. It added new systems to decisions already governed by employment, disability, privacy, consumer-reporting, and civil-rights law.

The legal map is still fragmented, and several dates changed after this article was first published. This review is current as of September 13, 2026 and is not legal advice. It distinguishes allegations from findings, settlement facts from general rules, and future effective dates from current obligations.

Mobley v. Workday remains active litigation

Mobley v. Workday is important because it tests when a software provider may face liability for its role in employer hiring decisions. It is also easy to misstate.

The plaintiffs allege that Workday’s systems discriminated on the basis of protected characteristics and that Workday functioned as an agent of employers. Workday disputes the allegations. A complaint describes what plaintiffs allege; it is not a judicial finding that the system made any particular decision or discriminated.

The EEOC filed an amicus brief in April 2024 arguing that a software vendor can qualify as an employer’s agent when delegated authority affects employment decisions. The court later allowed parts of the case to proceed, but procedural survival is not a final merits judgment.

The litigation continued in 2026. A July 1, 2026 district-court order addressed which allegations remained in an amended complaint after a motion to dismiss and strike. The order expressly notes that Workday did not concede the truth of the plaintiffs’ allegations. Readers should not convert those allegations into facts about how every Workday customer configures or uses the platform.

The durable procurement lesson is narrower: a vendor’s legal role may depend on the authority it exercises, not only the label in the contract. Employers and vendors need a clear record of who defines criteria, configures thresholds, generates recommendations, sends rejections, reviews exceptions, and controls the data.

iTutorGroup shows existing law reaching automation

The strongest U.S. enforcement fact is the iTutorGroup settlement. The EEOC said in September 2023 that the companies agreed to pay $365,000 and provide other relief after the agency alleged their application software automatically rejected female applicants aged 55 or older and male applicants aged 60 or older. The agency said more than 200 U.S.-based applicants were affected.

This was a settlement, not a trial verdict. It still establishes three useful points:

  1. Existing age and sex discrimination law applies when software executes the rule.
  2. A simple programmed cutoff can create legal exposure without a complex model.
  3. Employers need to test ordinary filters and knockout questions, not only products marketed as AI.

The case does not support fictional applicants, private settlement details, or a per-applicant liability formula for other disputes.

Federal duties attach to the employment decision

At the federal level, the central question is whether a covered employment practice discriminates under laws such as Title VII, the Americans with Disabilities Act, or the Age Discrimination in Employment Act. A vendor certification does not replace an employer’s duty.

Disparate treatment and disparate impact are different legal theories. An employer can create risk through an explicitly discriminatory rule, as alleged in iTutorGroup, or through a neutral practice that disproportionately screens out a protected group without sufficient legal justification. The elements and defenses depend on the statute and facts.

Disability requires special operational attention. The EEOC’s Artificial Intelligence and the ADA resource explains that a tool can screen out a qualified applicant because of a disability or fail to provide a reasonable accommodation. Timed games, video or voice analysis, keyboard-based productivity measures, and inaccessible application flows can measure interaction with the tool instead of ability to perform the job.

The accommodation route must be visible before failure. Recruiters and support staff need authority to pause an automatic path, offer an alternative format, and prevent the system from treating the accommodation itself as a negative signal.

New York City creates an audit and notice test

New York City’s Local Law 144 applies to covered automated employment decision tools used in hiring or promotion. The city’s official AEDT page describes the bias-audit, publication, and notice requirements. Enforcement began July 5, 2023.

Coverage is not determined by the word AI. The city’s FAQ focuses on the role of the tool in substantially assisting or replacing discretionary decision-making under the rule’s definitions.

A buyer should therefore document:

  • the exact output the tool produces;
  • whether it ranks, scores, classifies, recommends, or rejects;
  • how decision-makers use the output;
  • when the latest audit occurred;
  • which data and categories were included;
  • where the public summary appears;
  • how and when notice is delivered;
  • what alternative process is available.

An audit that covers a vendor’s default model may not cover an employer’s thresholds, data, role mix, or local configuration. Scope belongs beside the audit result.

California makes automated systems part of employment discrimination rules

California’s Civil Rights Department says employment regulations regarding automated decision systems took effect October 1, 2025. The rules clarify that use of an automated decision system may violate state law if it harms an applicant or employee based on a protected characteristic. They also address automated-decision-system data and a minimum four-year record-retention period for covered employment records.

The department’s rulemaking page separately records contractor modifications effective April 1, 2026. These dates and scopes should not be merged.

The practical effect is that employers need to preserve more than final disposition codes. Criteria, scores, source data, reviewer action, and system changes may be relevant to an investigation.

California privacy obligations can also apply to applicant and employee data. The legal analysis depends on the information, business, notice, purpose, and rights involved. A careers-site privacy notice should match the actual recruiting stack, including processors and model providers.

Colorado now points to 2027

Colorado’s AI law originally produced a different implementation calendar. The Colorado Attorney General’s current AI page says revised requirements for high-risk AI systems used in consequential decisions take effect January 1, 2027, with rulemaking under way.

Employers should not treat draft rules as final or an old deadline as current. They can still prepare the same operational foundation: use-case inventory, impact assessment, notice, risk management, human appeal, documentation, and incident process.

Whether a recruiting use is covered depends on the statutory and final regulatory definitions. Counsel should map the specific decision and parties rather than assume all recruiting software has the same status.

EU rules combine data protection and product governance

EU hiring compliance involves at least two distinct layers: GDPR governs personal-data processing, while the AI Act adds obligations for defined AI systems and roles.

The European Commission’s high-risk system guidance identifies specified employment uses within Annex III. Following the AI Omnibus, those high-risk rules apply from December 2, 2027. Requirements include risk management, data governance, documentation, logs, information for deployers, human oversight, accuracy, robustness, and cybersecurity.

The date change does not erase current GDPR duties. The European Commission’s individual-rights page explains the right relating to decisions based solely on automated processing that produce legal or similarly significant effects, subject to defined exceptions and safeguards. The European Data Protection Board’s automated decision-making guidelines provide further interpretation.

Do not reduce GDPR to a blanket ban on algorithms. Analyze purpose, lawful basis, transparency, data minimization, retention, security, data-subject rights, international transfer, and whether a decision is solely automated and significantly affects the person.

Biometric and identity tools create a separate data boundary

Candidate verification can reduce impersonation risk, but it can also introduce identity documents, selfies, face geometry, device data, and failure signals into the hiring process.

Illinois’ Biometric Information Privacy Act includes notice, consent, retention, disclosure, and security obligations for covered biometric identifiers and information. The statute’s definitions matter. A photograph and a scan of face geometry are not treated identically.

Procurement should ask whether the system merely compares submitted images, derives a biometric template, retains it, sends it to a subprocessor, or reuses it for another purpose. It should also measure false failures and provide manual review. Fraud prevention does not remove discrimination, disability, or privacy duties.

Vendor responsibility and employer responsibility coexist

The employer usually controls the decision and candidate relationship. The vendor may control product design, default models, training data, model updates, subprocessors, and technical logs. The contract should allocate tasks without pretending one party can transfer all legal responsibility to the other.

Require a responsibility matrix:

ControlEmployerVendorShared evidence
job criteria and necessityapprovedocument supported inputssigned configuration
model and rule behaviorreview usedisclose relevant behavior and limitsversion record
validationconfirm role and populationprovide technical evidenceapproved report
candidate noticedeliver in workflowsupport accurate content and triggersnotice log
accommodation and appealown responseenable alternative path and reviewcase record
monitoringreview outcomesexpose metrics and drift signalsrecurring report
incident responseinvestigate employment effectinvestigate technical causejoint timeline
retention and deletiondefine policyexecute and prove controlsexport and deletion receipt

A statement that a system is “bias free” or “fully compliant” is not a substitute for this evidence.

Compliance work should follow the decision lifecycle

Before procurement, classify the use, jurisdictions, data, decision effect, and autonomy. During diligence, collect validation, security, privacy, audit, accessibility, and model-change evidence. During implementation, test the actual configuration and candidate journey. After launch, monitor outcomes and investigate exceptions. At renewal, reassess scope, changes, and unresolved incidents.

The audit trail should connect:

  1. approved job requirements;
  2. candidate inputs and source;
  3. model, rule, prompt, or threshold version;
  4. output and confidence where available;
  5. human review and override;
  6. notice and accommodation;
  7. final disposition;
  8. later correction, appeal, or complaint.

This is the evidence an employer needs when a candidate, regulator, auditor, works council, or court asks what happened.

There is no defensible universal dollar amount for AI hiring compliance. Cost varies with jurisdictions, use cases, hiring volume, data complexity, number of vendors, internal capability, and how much remediation is required.

Budget categories are more reliable than invented market ranges:

  • legal and privacy analysis;
  • data-flow and system inventory;
  • validation and audit;
  • accessibility and accommodation;
  • logging and evidence export;
  • security and subprocessor review;
  • notice and rights operations;
  • monitoring, incident response, and retraining;
  • contract negotiation and exit support.

The cost of a control should be compared with the scope and consequence of the decision, not with a sensational statutory maximum. Penalty provisions have definitions, tiers, defenses, enforcement discretion, and procedural context.

The practical conclusion is firm without exaggeration. AI hiring systems participate in decisions about access to work. Existing law already reaches those decisions, local and state rules add specific controls, and the EU high-risk regime adds a broader product-governance layer from 2027. Employers need evidence about the actual workflow, not comfort from a product label.