Employers using artificial intelligence across the employment lifecycle remain fully liable for discrimination, even when third-party vendors supply the tools. Federal statutes such as Title VII, the Americans with Disabilities Act, and the Age Discrimination in Employment Act are technology-neutral - the same legal frameworks that governed paper tests now apply to algorithmic screening, scheduling, and performance evaluation systems. At least four states and localities have layered additional AI-specific compliance obligations on top of this federal baseline, and the first major case testing vendor liability, Mobley v. Workday, is moving forward in federal court.
The employer owns the outcome, not the algorithm
No federal law gives an employer a pass because a vendor made or influenced the challenged decision. Under Title VII, an AI screening tool that creates a disparate impact on a protected class triggers the same burden as any facially neutral criterion: the employer must show the tool is job-related and consistent with business necessity. The ADA prohibits selection criteria that screen out individuals with disabilities and requires reasonable accommodations for the assessment itself. An employer that deploys a psychometric AI test without confirming it can accommodate disabled applicants inherits the full range of ADA exposure. The ADEA applies the same logic when automated decisions disproportionately exclude older workers.
Courts are testing an agent theory of liability. In Mobley v. Workday, Inc., a plaintiff alleged he submitted over 150 job applications through the Workday platform and received no human response. A July 2024 ruling allowed claims against Workday to proceed on the theory that employer-clients delegated traditional screening functions to Workday's AI. The court conditionally certified an ADEA collective action in May 2025. For employers, the implication is direct: those who contracted with Workday may also face liability for the AI's decisions, absent rare indemnification provisions covering the full cost of such suits.
A patchwork of state and local laws
As of September 2026, several jurisdictions impose AI-specific employment rules beyond federal anti-discrimination law.
- Illinois: Public Act 103-0804, effective January 1, 2026, prohibits using AI in recruitment, hiring, promotion, discipline, and other employment decisions in a way that discriminates based on protected classes or uses zip codes as a proxy. Employers must notify employees and applicants when AI is used. The Illinois Department of Human Rights postponed rulemaking to collaborate with other agencies, but the underlying law remains enforceable.
- New York City: Local Law 144 requires employers using automated employment decision tools to conduct an annual independent bias audit, publicly post the results, provide candidates with at least 10 business days' notice before using the tool, and offer an alternative selection process or accommodation upon request. The DCWP handles enforcement.
- California: The CPPA approved final regulations on automated decision-making technology that took effect January 1, 2026, with ADMT-specific compliance beginning January 1, 2027. The rules cover ADMT used to replace human decision-making in hiring, compensation, promotion, and discipline. Employers must provide notice, opt-out options, an appeal process, access to information about ADMT use, and risk assessments.
- Colorado: A newly amended law effective January 1, 2027, requires pre-use notice, post-adverse-outcome disclosures including a right to human review, data correction rights, records retention, and meaningful human review rather than the prior law's risk-management programs.
Risk beyond hiring: timekeeping, surveillance, and generative AI
Automated timekeeping, productivity scoring, and scheduling systems create wage-and-hour exposure when they fail to capture all compensable working time. Employers must count all time during which an employee is suffered or permitted to work, regardless of whether an algorithm recognizes the activity as productive. Algorithmic monitoring of communications, location, and productivity can also implicate the National Labor Relations Act if surveillance chills protected organizing or concerted complaints. Some states, including Maine, have enacted employee surveillance laws that limit monitoring scope.
Generative AI introduces operational challenges across employment functions. Employers use it to draft job advertisements, interview questions, performance reviews, disciplinary memoranda, investigation summaries, and termination rationales. Each use carries risk: AI-generated language can introduce inconsistencies or inadvertent bias; large language models can fabricate facts, legal citations, and performance data; and inputting confidential personnel data or privileged communications into a third-party AI platform risks waiver of privilege and violation of confidentiality obligations. The U.S. Department of Commerce published an AI-at-work guide in April 2026 recommending employers limit generative AI to approved purposes, prohibit confidential data input, require fact and citation checks, conduct bias reviews, and preserve human judgment in final decisions.
An open question remains whether vendor-generated candidate reports based on AI analysis - personality assessments, social-media screening, or predictive scoring - qualify as consumer reports under the Fair Credit Reporting Act. If they do, the FCRA's disclosure, authorization, and adverse-action notice requirements would apply. No court has established a definitive rule.
A practical compliance framework
Employers can begin building governance infrastructure with seven steps:
- Inventory all AI tools and shadow AI. Catalog every AI-enabled tool used in employment decisions, including those adopted by individual departments or managers without approval. Shadow AI represents one of the largest compliance risks employers face.
- Classify by jurisdiction, use, decision impact, and data. Map each tool to the states and localities where it operates, the employment decisions it affects, and the categories of personal data it processes.
- Assign a human decision-maker. For every AI-informed employment decision, designate a manager with authority and practical ability to review, override, and document the final decision.
- Audit and test for adverse impact. Conduct regular adverse-impact analyses across protected classes and confirm AI assessments are accessible to individuals with disabilities.
- Build notice, accommodation, and appeal workflows. Develop standard processes for pre-use notice, accommodation requests, and appeals related to adverse decisions.
- Review and revise vendor contracts. Agreements should address transparency into design and training data, access to audit data, change-notification obligations, cooperation with bias audits, indemnification for discriminatory outcomes, data security, and data retention.
- Adopt an AI use policy and training program. Draft clear policies governing employee use of generative AI, including approved tools, prohibited uses, output verification requirements, and reporting for misuse. Provide training on approved tools and offer an enterprise tool to discourage shadow AI.
Why this matters for legal, HR, and government professionals
The compliance window before California and Colorado's ADMT-specific rules take effect in 2027 is narrowing. Mobley demonstrates that discrimination claims can reach both AI vendors and the employers that delegate decisions to them. State regulators are building enforcement regimens now. For legal and HR leaders managing multi-state workforces, the immediate priority is an inventory of every AI tool touching employment decisions - including the unapproved ones operating below the radar - paired with a vendor contract review that addresses audit access and indemnification. Government professionals monitoring enforcement trends should watch how the agent theory of liability develops in the Mobley collective action and whether the FCRA question around AI-generated candidate reports produces a definitive ruling.
Your membership also unlocks: