Applied Oversight

Insights · AI hiring litigation

Your AI hiring vendor can make you a defendant

If you bought an AI tool to screen job applicants, you probably assumed the vendor carries the legal risk that comes with it. Two 2026 cases say otherwise. In one, a federal court is letting rejected job seekers sue an AI hiring platform directly, as the employer's agent — a sign that using a vendor doesn't move the legal risk off you and onto them. In the other, applicants argue the platform's AI scores are "consumer reports," a label that would put a stack of federal duties on every company that uses them. Different theories, one lesson: the liability stays with you.

Who this touches

If your company uses software to help decide who gets hired, promoted, or screened out, this is about you. That means résumé-ranking inside your applicant-tracking system, a personality or skills assessment, or the "fit" score you may never look at too closely. California employers are the most exposed today, but the two theories below reach further than California: one covers any California employer with five or more employees, the other is federal and applies wherever you hire. If a person is affected by the tool and never learns why, you're in the zone these cases are testing.

What the law actually says

Start with discrimination. California's employment regulations, effective October 1, 2025, say that anyone who handles recruitment, screening, or hiring for an employer — "including when such activities are conducted in whole or in part through the use of an automated decision system" — is also an employer under the Fair Employment and Housing Act (2 CCR §11008(b)). Read that twice. The regulation treats your screening vendor's decisions as your decisions. "The algorithm did it" is not a defense; it's a description of your own hiring process.

That principle is already being litigated, though from the other direction. In Mobley v. Workday (N.D. Cal.), it's the vendor that got pulled into court. On June 22, 2026, the judge held that Workday can be directly liable under FEHA for "its own engagement in FEHA-regulated activities on the employer's behalf," and let discrimination claims under FEHA and the Americans with Disabilities Act proceed. (The age-discrimination piece had already been certified as a collective action that reportedly drew around 14,000 opt-ins.) The employer-customers aren't defendants in that case — but that's the point. If a court will treat the screening tool as enough of a hiring function to make the vendor an employer, the regulation that keeps you one (§11008(b)) is not theoretical. The risk doesn't relocate to the vendor. It reaches both of you.

The second theory is the one most employers miss. In Kistler v. Eightfold AI, filed in California in January 2026, applicants allege the platform scored them on a 0-to-5 scale and discarded low scorers before a human ever looked — and that those scores are consumer reports under the Fair Credit Reporting Act. If a court agrees, the consequences don't stop at the vendor. The FCRA puts duties on the employer who uses a consumer report: a standalone disclosure, the applicant's written authorization, and a specific pre-adverse-action and adverse-action notice sequence before and after you turn someone down based on it. Most companies running AI screening have none of that in place, because they never thought of an AI score as a background report.

What a covered company should do

  1. Inventory every tool that touches a hiring decision. You can't manage exposure you haven't listed. Include the scoring features buried inside platforms you bought for something else.
  2. Get the vendor's bias testing in writing. California treats "evidence, or the lack of evidence, of anti-bias testing" as central to any discrimination claim or defense (2 CCR §11009(f)). Ask for the quality, scope, recency, and results of that testing, and what the vendor changed in response. If they won't share it, that silence becomes yours.
  3. Build the FCRA notice workflow now, before a court rules. That means a standalone disclosure, the applicant's written authorization, and the two-step adverse-action notices. It's routine background-check compliance applied to a new kind of report, and it's cheap next to the Eightfold theory landing.
  4. Keep the records a regulator or a plaintiff will ask for. California now requires four years of employment records, expressly including automated-decision-system data (2 CCR §11013). Here, retention is your evidence.
  5. Put a real human in the loop with real authority. You want someone who can see the inputs and overturn the outcome, not a reviewer who rubber-stamps the score. That's what turns "the algorithm decided" back into a defensible human decision.

The honest part

Neither case is won. Mobley has cleared early hurdles and reached its collective stage, but it hasn't been decided on the merits. The Eightfold consumer-report theory is genuinely novel — no court has yet held that an AI hiring score is a consumer report, and it may not survive. So the claim here isn't that you'll be liable. It's that the legal machinery to hold employers responsible for their AI hiring tools already sits in the statutes, and plaintiffs have started pulling the levers. The steps above are worth taking now because they're the same steps whether these particular cases win or lose.

The through-line is short. You can outsource the software. You can't outsource the liability.

This article is educational commentary and is not legal advice. Statutory and regulatory claims trace to primary text; the litigation summaries are drawn from the court filings and independent practitioner analyses of the dockets.

Ten minutes of questions.
A one-page map of your AI obligations.

Get your free exposure scan