Est.
FeaturesLong read

EEOC Guidance on AI Hiring Tools and Employer Liability

Employers remain fully liable for AI hiring bias even as federal enforcement retreats.

Reporter · · 13 min read
Cover illustration for “EEOC Guidance on AI Hiring Tools and Employer Liability”
Features · September 18, 2026 · 13 min read · 2,901 words

AI hiring tools promise objectivity: no gut feelings, no hungover recruiter skimming a resume for six seconds, just clean data driving clean decisions. The legal reality runs the other way. An algorithm trained on biased historical data doesn't remove bias from hiring, it automates that bias and applies it at a scale no single recruiter could match. And under Title VII of the Civil Rights Act, that automation doesn't shield the employer from liability, it deepens it.

The disparate impact doctrine is written into the statute itself, in the relevant federal code provision. It's written into the statute itself, in the relevant federal code provision. § 2000e-2(k), and that codification is central to everything else in this piece. An executive order can tell an agency where to point its enforcement budget. It cannot rewrite a law passed by the legislature. So even as the federal agency responsible for workplace discrimination enforcement has spent the last two years pulling back from disparate-impact cases, the underlying statute hasn't moved an inch. Employers who read the retreat as a green light are reading the wrong document.

What Title VII actually prohibits is any selection procedure, whatever form it takes, that produces an unjustified adverse effect on a group protected by the statute (race, sex, national origin, religion, and related categories). That rule doesn't distinguish between a paper-and-pencil test from 1978 and a large language model screening resumes in 2026. A test is a test. And the tool being built and run by an outside vendor changes nothing about who's on the hook: the employer that uses the selection procedure owns its results, full stop. That principle, sometimes called non-delegable liability, is the single most important thing to understand about this entire area of law, because it's the fact most employers get wrong.

The EEOC's own framework treats "selection procedure" broadly enough to cover just about every AI product currently marketed to HR departments: resume scanners that rank applications by keyword, monitoring software that scores employees on keystrokes or other behavioral signals, testing software that spits out a "job fit" number, video-interview analysis tools, hiring chatbots, and personality assessments. And Title VII isn't even the only statute in play. Two other federal statutes covering disability and age discrimination both apply on top of it. An employer evaluating one AI hiring tool is really running a compliance check against three separate federal statutes at once, not one.

What the EEOC's two foundational AI guidance documents said

The EEOC produced two technical-assistance documents that, for a few years, served as the closest thing to an official rulebook on AI hiring tools. The first, released in May 2022, addressed how the ADA applies when employers use software, algorithms, and AI to assess job applicants and employees. The second, from May 2023, addressed Title VII and adverse impact specifically, and it's the more detailed of the two by a wide margin.

The 2023 guidance laid out three positions that still shape how litigation over these tools plays out today. First, an employer using a tool that produces adverse impact has to show the tool actually measures something the job requires and does so with documented, defensible validity. Second, if an employer considered a less discriminatory version of the algorithm during implementation and chose not to adopt it, that decision itself can create liability, and this pattern appears repeatedly in active lawsuits. Third, the guidance restated the non-delegation principle: the employer answers for the outcome even when a vendor designed and runs the tool.

Both documents were issued during a period when the EEOC had launched an AI and Algorithmic Fairness Initiative. That initiative has effectively wound down, and both documents have since been pulled from the EEOC's website. Neither fact makes them irrelevant. They describe how a federal statute functions, not how an agency feels about enforcing it in a given administration, and courts and plaintiffs' attorneys keep citing the reasoning regardless of what's still hosted on eeoc.gov. The 2023 guidance's language on less discriminatory alternatives, in particular, has become a load-bearing argument in ongoing litigation, Mobley v. Workday among them.

The 2025-2026 federal policy reversal

Executive Order 14281, titled "Restoring Equality of Opportunity and Meritocracy" and signed April 23, 2025, directed federal agencies, the workplace discrimination enforcement agency and the federal government's legal department included, to deprioritize enforcement built on disparate-impact theory "in all contexts to the maximum degree possible." That's a sweeping instruction. Legally, though, it is an instruction about where an agency points its resources, not an amendment to Title VII. The statute's disparate-impact provision remains exactly as codified. Congress wrote it; an executive order doesn't get to unwrite it.

What followed at the agency level was fast. EEOC Acting Chair Andrea Lucas removed both AI technical-assistance documents from the agency's website in 2025 and set aside the prior Strategic Enforcement Plan, which had covered fiscal years 2024 through 2028. Then, on June 4, 2026, the EEOC approved a new National Enforcement Plan covering fiscal years 2025 through 2029, which rescinds and replaces that earlier plan. The new plan prioritizes intentional discrimination and explicitly disclaims EEOC litigation built on disparate-impact theories. It goes further than a simple deprioritization, too, shifting the agency's focus squarely toward intentional discrimination theories and handing employers new risks they didn't have to weigh under the prior plan. Compare that to the plan it replaced, which had named AI, machine learning, automated recruiting tools, and screening practices with disproportionate effects as explicit enforcement priorities. All of that is now off the agency's list.

Treating reduced federal enforcement as reduced legal exposure is a misreading that gets employers in trouble. Those are not the same thing, and confusing them ignores three enforcement channels that keep running at full speed regardless of what the EEOC prioritizes. Private plaintiffs can sue directly under Title VII, the ADEA, and the ADA without any agency involvement. State attorneys general and state civil rights agencies keep their own authority to investigate and sue. And a growing set of state and local AI-specific statutes carry their own enforcement mechanisms, independent of anything happening in Washington. Layer onto that the federal government's simultaneous push to curb state-level AI regulation, and employers end up squeezed from two directions at once: less federal enforcement on one side, an uncertain and contested patchwork of state law on the other.

How disparate impact analysis works when applied to an AI hiring tool

Disparate impact claims run on a three-step, burden-shifting framework, and the mechanics of each step matter more than the label.

Step one belongs to the plaintiff. The plaintiff has to show a statistical disparity: the AI tool screens out or disadvantages a protected group at a meaningfully higher rate than others. The standard starting measure here is the four-fifths rule: if a protected group's selection rate falls below 80% of the rate for the highest-selected group, it signals adverse impact. Say a screening tool selects a substantially higher share of white applicants than Black applicants, producing a ratio that falls well under the 80% threshold, that gap is enough to flag the tool for scrutiny. The rule traces back to the Uniform Guidelines on Employee Selection Procedures, first issued in 1978, and it applies to an AI resume screener exactly the way it applied to a written test administered on paper decades ago. The math doesn't care what decade the tool was built in.

Step two shifts the burden to the employer, who has to prove the tool measures something the job actually requires, predicts performance with documented validity, and serves a real business purpose rather than a convenient one. That requires validation studies, not vendor marketing copy.

Step three hands the burden back to the plaintiff, who can still win by showing a less discriminatory alternative exists, one that's equally effective, produces less adverse impact, and would have been feasible for the employer to adopt. And if the employer considered that alternative during implementation and passed on it anyway, that decision can become the liability itself.

The four-fifths rule has a known weakness: with small sample sizes it can throw off false signals in either direction. Courts and agencies also lean on statistical significance testing to check whether an observed gap reflects a real pattern rather than noise in a limited dataset.

Beneath all of this sits the fact that an AI system trained on historical hiring data reproduces the patterns in that data. An AI system trained on historical hiring data from a workforce that wasn't diverse to begin with learns to replicate whatever pattern produced that workforce, even when no protected characteristic is fed into the model directly. Zip codes, college names, gaps in employment history, even certain phrasing patterns, can all function as stand-ins for race, sex, or age without the tool ever "seeing" those categories explicitly. Academic research testing commercial large-language-model resume screeners has found the tools systematically favored white-associated names over Black-associated names in testing. That finding is now part of the public evidentiary record that courts, legislators, and regulators cite when the question of algorithmic bias comes up.

None of this is static, either. A tool that produced clean, non-discriminatory outcomes in 2023 can start showing bias in 2026 simply because the underlying model changed, or the applicant pool feeding it changed, or both. That's model drift, and it means ongoing monitoring is a necessary, continuous part of a compliance program. It's the compliance program.

ADA obligations that AI hiring tools trigger independently of Title VII

Title VII gets most of the attention, but the ADA creates its own separate exposure, and it does so through three distinct mechanisms.

The first is straightforward screening out: a video-interview platform that scores candidates down for atypical speech patterns, unusual eye contact, or facial expressions tied to a disability, autism spectrum disorder being the clearest example, ends up penalizing disability-related traits directly, whether the tool's designers intended that or not.

The second is subtler. The ADA restricts disability-related inquiries and medical examinations before a job offer is made, and an AI tool that assesses psychological traits, behavioral patterns, or emotional states can cross into that territory even if it never asks a candidate a single question about a diagnosed condition. Assessing someone's mood or affect through a webcam and calling it a "personality score" doesn't necessarily take it out of that regulated category.

The third is a failure to accommodate within an AI-driven process. Joint guidance from the DOJ and EEOC makes clear that the obligation to provide reasonable accommodations doesn't evaporate just because a third-party vendor built the tool and didn't design it with accommodations in mind.

Certain product categories carry more of this risk than others. Video-interview AI can penalize speech differences or atypical eye contact. Timed assessments disadvantage candidates who need extended time as an accommodation. Gamified tests can be effectively inaccessible to candidates with certain motor or cognitive disabilities. Chatbots may fail candidates using screen readers or other assistive technology. The EEOC's 2022 technical-assistance document remains the most detailed public articulation of how these risks play out, even with the document removed from the agency's site. The practical fix looks less like a legal disclaimer and more like a design choice: offer accommodations, including alternative evaluation formats, before a candidate has to ask for one, and say so explicitly in whatever disclosure accompanies the AI tool. And the same non-delegation logic from Title VII applies here too. The employer has to provide the accommodation even if the vendor who built the tool never designed one in.

Mobley v. Workday and its significance to every employer using AI hiring tools

Derek Mobley alleges he was rejected from more than 100 jobs by employers using Workday's AI-driven applicant screening tools, and his suit, filed as a federal class and collective action in the Northern District of California, claims systematic discrimination on the basis of race, age, and disability. Workday's tools are used by more than 11,000 organizations, and plaintiffs describe a potential class covering roughly 1.1 billion rejected applications.

The rulings have piled up fast. In May 2025, the court conditionally certified the ADEA claims as a collective action, covering hiring decisions run through Workday's AI systems going back to 2020. In July 2025, Workday was ordered to identify which employers had enabled its HiredScore AI screening features. Then, on March 6, 2026, the court issued a ruling with real teeth: it rejected Workday's argument that the ADEA doesn't cover job applicants at all, refusing to dismiss on that basis. And on June 22, 2026, the court granted Workday's latest motion to dismiss in part and denied it in part, letting California FEHA claims and a proxy-discrimination disability claim survive while sex-based claims were added to the case. What started as a race, age, and disability case now spans race, sex, age, and disability all at once.

The theory doing the most damage to Workday's defense is what Judge Rita Lin has framed as an agent theory: a vendor performing core hiring functions, screening, ranking, recommending candidates, on an employer's behalf can be treated as an extension of that employer, and directly liable under Title VII, the ADEA, and the ADA in its own right. For the more than 10,000 employers running Workday's AI hiring tools, that theory means liability doesn't stop at the vendor's door. It compounds, with both the employer and the vendor potentially exposed for the same rejected application.

The discovery fights show how deep courts are willing to dig. Plaintiffs have sought extensive discovery into the internal workings of Workday's AI screening products, including bias testing data, methodology documents, and internal communications. That level of demanded disclosure is itself a warning to any employer running an AI hiring tool: if a lawsuit reaches discovery, the tool's internals are not off-limits just because a vendor built them. Workday has sought to shield some of its bias-testing data as attorney work product, but the bar for that protection is higher than most legal teams assume. Courts scrutinize whether such protection is genuine or whether the work would have been conducted regardless of litigation.

None of these rulings has found anyone liable for anything yet. What they've done, over and over, is refuse to let Workday out of the case early, and each refusal reinforces the exact framework laid out above: non-delegable employer responsibility, vendor exposure as an agent, and a disparate-impact analysis that doesn't care whether the tool was built in-house or bought off the shelf.

EEOC v. iTutorGroup already shows what happens when discriminatory logic gets baked directly into a tool's code rather than emerging as a side effect of biased training data. The allegation was that iTutorGroup's automated hiring system was programmed to reject female applicants aged 55 or older and male applicants aged 60 or older automatically, no human review, no exceptions. The case settled for $365,000, and that number now functions as a rough benchmark for what tool-specific age discrimination claims can cost, even under an enforcement regime far more aggressive than the one running today.

A newer front opened in January 2026, when plaintiffs Erin Kistler and Sruti Bhaumik filed a class action against Eightfold AI, and this one is a data-law claim rather than a bias claim. It's a data-law claim, built on the theory that Eightfold's platform functions as an unregistered consumer reporting agency under the Fair Credit Reporting Act. The complaint alleges the platform compiles social media activity, location data, and other online behavior, then scores candidates on a 0-to-5 "likelihood of success" scale, sometimes tagging them with labels like "team player" or "introvert," all before a human recruiter ever looks at the file, without the disclosures, consent process, or dispute rights the FCRA requires of a consumer reporting agency. No discrimination has to be proven for that claim to stick. The exposure comes entirely from how the data was collected and disclosed, not from what the algorithm decided to do with it.

A separate January 2026 class action pushed a similar background-check theory against another AI recruiting and "talent intelligence" company, alleging the company builds a proprietary database from public information about candidates and sells reports to prospective employers without complying with consumer-reporting rules. Same statute, same underlying theory, different company. Put together with Eightfold, the pattern is a second and third legal front running entirely apart from Title VII: an AI hiring vendor and its employer-customers can now face exposure across civil rights law, consumer reporting law, and state privacy law, all from the same underlying tool and the same underlying data pipeline.

State laws now doing the enforcement work the federal government has stepped back from

Federal enforcement is pulling back at the exact moment private litigation and state law are stepping into the gap it leaves behind. That's the structural shift employers need to plan around: fewer cases initiated by the federal enforcement agency doesn't mean fewer cases. It means the cases move to different courtrooms, brought by different plaintiffs, under different statutes, some federal and some built entirely at the state level. An employer weighing whether an AI hiring tool is defensible can no longer check that box by pointing to what the EEOC currently prioritizes. The statute hasn't changed, the courts are still applying it, and the states are writing their own rules on top of it.

Sources

  1. EEOC AI Hiring Guidance: Key Employer Compliance Rules - Warden AI
  2. EEOC AI Hiring Guidance 2026 & Federal AI Laws | EmployArmor
  3. AI Hiring Discrimination Lawsuits: EEOC Enforcement 2026
  4. EEOC AI Hiring Enforcement: What HR Teams Must Know in 2026 - TheComplyGuide
  5. You Are Responsible for Your AI: What Employers Need to Know About EEOC Scrutiny of Hiring and Promotion Algorithms
  6. EEOC Issues Title VII Guidance on Employer Use of AI, Other Algorithmic Decision-Making Tools | Insights | Mayer Brown
  7. eeoc.gov
  8. prevuehr.com

More in Features