Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page

Who Is Liable for AI Hiring Bias? What HR and Legal Teams Must Know in 2026

⚡ TL;DR
AI hiring tools are facing a legal reckoning in 2026. Courts in Mobley v. Workday have ruled that employers stay liable for discriminatory outcomes even when a vendor built the algorithm — and vendors themselves can now be sued directly. The EEOC treats “the algorithm did it” as no defense, NYC Local Law 144 enforcement is tightening after a critical audit, and the EU AI Act’s high-risk hiring rules have been delayed to December 2027 but not cancelled. HR and legal teams need documented bias audits, vendor contract protections, and human oversight now, not later.

Nearly every HR department now touches artificial intelligence somewhere in the hiring funnel, from resume parsing to candidate ranking to automated interview scoring. That convenience has collided with a wave of litigation and regulatory action that is redefining who is liable for AI hiring bias when a screening tool produces a discriminatory outcome. The question employers and their counsel are now asking is no longer whether an algorithm can discriminate — it is who pays when it does: the company that deployed the tool, or the vendor that built it.

What Is AI Hiring Bias, and Why Is It a Legal Issue Now?

AI hiring bias occurs when an automated screening, ranking, or scoring tool disproportionately rejects candidates from a protected group — such as older workers, people with disabilities, or a particular race or gender — even without any human intending discrimination.

The issue has moved from theoretical to legal because AI hiring tools now process the vast majority of applications before a human ever sees a resume. A tool trained on historical hiring data can absorb and automate patterns of exclusion that existed in a company’s past decisions, then apply those patterns at a scale no individual recruiter ever could. Once that scale is measurable, it becomes discoverable in litigation and auditable by regulators — which is exactly what has happened over the past eighteen months.

Who Is Liable When an AI Hiring Tool Discriminates — Employer or Vendor?

Both can be liable. Courts and regulators are increasingly holding that employers remain responsible for discriminatory outcomes under existing anti-discrimination law, while software vendors can now also face direct claims as an “agent” of the employer.

The clearest signal came from Mobley v. Workday, the most closely watched AI hiring case in the United States. Lead plaintiff Derek Mobley, an applicant over 40 who is Black and has a disability, alleged that Workday’s AI-powered screening tools — Candidate Skills Match and Assessment Connector — rejected him from more than 100 jobs, in some cases within minutes of applying. On June 22, 2026, Judge Rita F. Lin of the Northern District of California allowed most of the claims to proceed, including state-law bias claims that reach the vendor itself, according to reporting from Outsolve. Earlier, in March 2026, the court had already let age-discrimination claims under the ADEA move forward, rejecting Workday’s argument that it was merely a tool provider with no liability exposure of its own.

What Did the Court Rule in Mobley v. Workday?

The court ruled that employers are ultimately responsible for discriminatory outcomes even when third-party AI tools are involved, and that a vendor can be sued directly when its software effectively performs the employer’s hiring decisions.

Workday disclosed that its software processed roughly 1.1 billion job applications since September 2020 — a scale that turned an individual complaint into grounds for nationwide, multi-employer exposure. A separate 2026 filing against Eightfold AI took the theory further: plaintiffs alleged the platform functioned as an unregistered consumer reporting agency under the Fair Credit Reporting Act, a claim about applicant data handling rather than bias. Together, these cases show liability theories expanding well beyond classic disparate-impact claims. Employment counsel tracking this shift can find deeper background through kurums.com’s employment law resources.

What Does the EEOC Require From Employers Using AI Screening Tools?

The EEOC requires employers to treat AI screening as a “selection procedure” subject to the same disparate-impact rules as any other hiring test, regardless of who built the software or how it makes decisions.

The agency’s technical guidance is explicit: outsourcing a decision to an algorithm does not outsource legal responsibility. Employers cannot demonstrate job-relatedness and business necessity after the fact if they never validated the tool before deployment — and “the algorithm did it” is not treated as a valid defense under Title VII, according to employment law analysis from Reddock Law Group. Investigators frequently apply the four-fifths rule as a screening test: if a protected group is selected at less than 80% of the rate of the highest-selected group, that gap is treated as a red flag warranting closer review — one concrete, strategic reason to run selection-rate comparisons before a regulator does it for you.

How Does NYC Local Law 144 Affect Employers Using AI Hiring Tools?

NYC Local Law 144 requires any employer using an automated employment decision tool on a New York City-based role to complete an independent bias audit within the past year, publish a summary of that audit, and give candidates at least ten business days’ notice.

Enforcement was soft for the law’s first two years, but that has changed. A New York City Comptroller audit found the Department of Consumer and Worker Protection’s enforcement had been “ineffective,” documenting that 75% of test calls placed to the city’s 311 hotline about automated employment decision tools were never properly routed, and that an independent review of posted bias audits found at least 17 potential compliance issues where the agency’s own review had flagged only one, according to DLA Piper’s employment law tracker — a gap that signals tighter enforcement ahead, not a reason to relax. Penalties run $500 to $1,500 per violation, with each unnotified candidate and each day of non-compliance counted separately.

How Will the EU AI Act Affect AI Recruitment Tools?

The EU AI Act classifies recruitment, CV filtering, candidate ranking, and performance-evaluation AI as “high-risk” under Annex III, requiring conformity assessments, human oversight, logging, and fundamental rights impact assessments — but the compliance deadline for these employment rules has been pushed back.

The original date for high-risk employment obligations to take effect was August 2, 2026. Following an EU agreement reached in May 2026 and approved by the European Parliament in June 2026, that deadline has been delayed to December 2, 2027, as reported by Ogletree Deakins. Importantly, the delay is a postponement, not a repeal — employment AI remains squarely inside the Act’s high-risk category, in the same regulatory tier as medical devices and critical infrastructure, once the extended clock runs out.

⚠️ Warning: The EU AI Act delay is a scheduling change, not a compliance exemption, and it applies only to the EU timeline — Mobley v. Workday, EEOC enforcement, and NYC Local Law 144 are moving forward on their own clocks right now. Employers that pause AI hiring governance work because of the EU delay will still be exposed to active US litigation, state biometric and algorithmic-decision laws, and city-level audit requirements that carry immediate penalties.

How Widespread Is AI Use in Hiring Right Now?

AI now touches some stage of hiring at the large majority of employers, while formal governance and candidate trust in these tools both lag well behind adoption.

Industry surveys put AI use somewhere in the hiring process at roughly 87% of companies, yet only about 26% of candidates say they trust AI to evaluate them fairly, according to data compiled by industry tracker Employer Branding News — a trust gap that is itself becoming a recruiting and reputational risk, separate from legal exposure. SHRM’s 2026 survey of 1,722 HR professionals found recruiting is the single most common AI use case inside HR at 27% of organizations, yet only 25% of organizations report having a clear, future-proof AI governance policy, and 54% describe their existing policy as too restrictive or too tool-specific to keep up. That governance gap — high adoption, low formal oversight — is precisely the pattern regulators and plaintiffs’ attorneys are targeting, and it is reshaping how recruiting teams evaluate and pilot new tools, a shift explored in kurums.com’s look at how AI-generated resumes are changing how recruiters screen talent in 2026.

What Should HR and Legal Teams Do Now to Reduce Exposure?

HR and legal teams should treat every AI hiring tool as a regulated selection procedure: inventory it, audit it for disparate impact, document human oversight, and negotiate vendor contract terms that allocate liability before deployment rather than after a complaint.

  • Inventory every tool. List every AI system touching sourcing, screening, ranking, interview scoring, or offer decisions, including features bundled inside applicant tracking systems that HR may not think of as “AI.”
  • Run selection-rate audits. Compare selection rates across protected groups using the four-fifths rule as a baseline, and re-run the analysis whenever a vendor updates its model.
  • Secure and publish required bias audits. Where Local Law 144 or a similar state law applies, obtain an independent annual audit, post the public summary, and give candidates the required advance notice.
  • Rewrite vendor contracts. Require vendors to warrant bias testing, share audit data, and indemnify the employer — Mobley v. Workday shows vendors can be sued directly, but that does not remove the employer’s own exposure.
  • Keep a human meaningfully in the loop. Document that a person reviews and can override automated rejections, which regulators and courts treat as evidence against a “fully automated decision” theory of liability.
  • Track jurisdiction-specific deadlines. The EU AI Act’s high-risk employment rules now land December 2, 2027, but city and state deadlines in the US are active today — align a single compliance calendar across HR and legal rather than tracking each law separately.

Building this into a standing process, rather than a one-time review, is the difference between a defensible AI hiring program and one discovered mid-litigation. Centralizing that process is easier with structured internal resources; teams can start from kurums.com’s HR compliance and workforce management resources to build an audit-ready documentation trail.

Frequently Asked Questions

Can an employer be sued if its AI hiring vendor is at fault?

Yes. US courts, including in Mobley v. Workday, have held that employers remain liable for discriminatory hiring outcomes even when a third-party vendor built and operated the AI tool. Using a vendor’s software does not transfer legal responsibility away from the employer.

Can an AI hiring vendor also be held directly liable?

Increasingly, yes. Courts have allowed claims against vendors like Workday to proceed on the theory that the vendor acted as an “agent” of the employer in making hiring decisions, opening a second line of liability beyond the employer alone.

Does NYC Local Law 144 apply to remote roles?

It generally applies when the role is based in New York City or the candidate would regularly report to a New York City location, regardless of where the employer’s headquarters sits. Employers with distributed hiring should map which roles fall under the law rather than assuming it only covers local companies.

Has the EU AI Act’s hiring deadline been cancelled?

No. The original August 2, 2026 deadline for high-risk employment AI obligations has been delayed to December 2, 2027, but the underlying requirements remain in force once that date arrives. Employers operating in the EU should keep preparing rather than treating the delay as a repeal.

What is the fastest first step for a company with no AI hiring governance yet?

Start with a tool inventory and a selection-rate audit using the four-fifths rule, since both can be completed quickly with existing applicant data and immediately reveal whether a red flag exists before a regulator or plaintiff finds it first.

Last updated: August 2026


Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading