Skip to content
AI & legal work

You bought the screening tool. You own the discrimination claim.

The sales deck says the tool removes bias from hiring. Perhaps it does. What matters legally is narrower and much less comfortable: a thing that filters applicants is a selection procedure, the employer running it is the respondent when someone complains, and the defence to that complaint is evidence about how the filter was built and tested — evidence that sits on the vendor's servers, under the vendor's confidentiality terms, and is almost never in the contract you were sent.

11 min readPublished How we write these

The short version

  • Title VII liability lands on the employer that uses the screen, not the vendor that built it. Under 42 U.S.C. § 2000e-2(k), a facially neutral practice that causes disparate impact is unlawful unless the employer proves it is job related and consistent with business necessity — and that proof is validation evidence the employer almost never holds.
  • Federal agency guidance has been withdrawn; the cause of action has not. The EEOC removed its AI technical assistance documents in January 2025 and Executive Order 14281 directs agencies to deprioritise disparate impact. Private plaintiffs, state regulators and state statutes are untouched by both.
  • New York City's bias-audit duty turns on a narrow definition: the tool's output must be used alone, weighted above every other criterion, or to overrule a human. Where it applies, each day of use without a current audit is a separate violation.
  • Where the tool reads a face or a voice, biometric privacy is a second and independent claim. Illinois BIPA carries liquidated damages of $1,000 or $5,000 per person plus fees, and a private right of action that does not require any discrimination at all.

Two employers buy the same résumé-ranking product in the same month. One never hears about it again. The other gets a charge from a rejected applicant, asks the vendor for the study behind the ranking model, and finds a marketing white paper, an analysis confidential to the vendor, and a contract silent on producing either. Nothing about the tool differed. The paperwork did.

The law that reaches the tool is older than the tool

No gap in employment discrimination law let AI through. Title VII covers a practice, not a state of mind: under 42 U.S.C. § 2000e-2(k)(1)(A), a complainant who shows an employment practice "causes a disparate impact on the basis of race, color, religion, sex, or national origin" shifts the burden to the employer to show it is "job related for the position in question and consistent with business necessity". A résumé filter is a practice, and so is a video-interview score.

Two consequences follow that small employers get wrong. Nobody has to prove the tool intended anything, or that you did. And the second half of that burden is yours and evidentiary: not whether the vendor believes the model is job related, but whether you can show it when asked. Section 2000e-2(k)(1)(B) adds that you must answer for each element of the process, unless the elements "are not capable of separation for analysis".

Neither axis decides on its own

How the output is used

Selection rates across groups

Roughly even

Visibly uneven

Weighed with other things

Quiet, for now

No impact to explain, probably outside New York City's definition. Keep the numbers anyway; they prove it later.

Title VII still bites

The impact came from the screen. A human sign-off on the survivors does not make it job related.

The score decides

Audit still owed

The city duties turn on how decisive the output is, not how the numbers came out.

Both at once

A validation burden no brochure discharges, with the city and state notice duties on top.

The cell people misprice is top-right: a human reviewer changes which statutes apply, not whether Title VII does.

Federal enforcement has retreated. The cause of action has not.

Anything written before 2025 about EEOC guidance on AI is history. In January 2025 the Commission removed its May 2023 technical assistance on adverse impact in software, algorithms and AI under Title VII, and its May 2022 companion on the ADA. The Department of Labor removed its 2024 field bulletin and the OFCCP contractor guidance. The URLs return 404. A withdrawn document is not authority.

Executive Order 14281, signed 23 April 2025, goes further: it states a policy "to eliminate the use of disparate-impact liability in all contexts to the maximum degree possible" and directs agencies to deprioritise enforcement of it. That instrument directs the executive branch. It does not amend § 2000e-2(k), bind a court, or reach a private plaintiff, a state civil rights agency or a state statute.

The Uniform Guidelines on Employee Selection Procedures at 29 CFR Part 1607 are still in the Code of Federal Regulations, and the EEOC's regulatory agenda lists their rescission at the final rule stage. That is a projection, not a rule — and it is the reason to know where else the Guidelines live.

Validation is the defence, and you are not the one holding it

Section 1607.3(A) states the rule the framework hangs on: a selection procedure with adverse impact "will be considered to be discriminatory" unless it has been validated. Section 1607.5(A) recognises three ways — criterion-related, content and construct validity — each a documented study, not an assertion. Section 1607.4(D) is the test everyone quotes: a selection rate below four-fifths of the best-performing group's "will generally be regarded by the Federal enforcement agencies as evidence of adverse impact".

When you are buying rather than building, § 1607.7 matters most. You may borrow another study only where the evidence clearly demonstrates validity, where your incumbents and the study's "perform substantially the same major work behaviors", and where it includes a test-fairness analysis for each group significant in your labour market. A study run on national data for another job family does not transport to your five-person operations team. Those conditions are the questions for the salesperson.

Section 2000e-2(l) closes one route out. It is unlawful to "adjust the scores of, use different cutoff scores for, or otherwise alter the results of" an employment-related test on the basis of a protected characteristic. An impact ratio below four-fifths cannot be fixed by moving the pass mark. The lawful responses: change the screen, show it is job related, or adopt an equally valid alternative with less impact — which § 1607.3(B) says you should be doing anyway.

Video and game assessments hit the ADA before anything else

The ADA problem is separate and often arrives first. Under 42 U.S.C. § 12112(b)(6) a qualification standard or test that "screen[s] out or tend[s] to screen out" people with disabilities is unlawful unless job related and consistent with business necessity. Section 12112(b)(7) adds a duty to administer tests so results reflect what the test purports to measure rather than an impaired sensory, manual or speaking skill. An assessment scoring reaction time, a video tool reading facial expression, a chat exercise timing typing: each is a plausible (b)(7) problem before anyone looks at outcomes.

Then the inquiry rule. Section 12112(d)(2) bars a medical examination or any inquiry into whether an applicant has a disability before an offer, and California's § 11071(a) mirrors it, defining a psychological examination as any "procedure or test that seeks information about an individual's physical or mental conditions or health". A culture-fit personality assessment can cross that line: if the tool infers a mental health condition, its output is what the statute prohibits collecting at that stage — the boundary in what an employer may ask about your health.

The control is an accommodation route that exists. New Jersey's December 2025 rules are the clearest worked example: N.J.A.C. 13:16-3.2(c) warns that facial-analysis technology tested predominantly on people without disabilities may score interviewees with darker skin, with disabilities, or wearing religious headwear lower simply because it cannot read them, and that a screen turning on schedule availability must carry a route to request an accommodation. Age differs: 29 CFR § 1625.7 puts both burdens on the employer to establish a reasonable factor other than age.

Which of the newer statutes actually reaches you

WhereWhat switches it onWhat it makes you do
New York CityOutput used alone, weighted above every other criterion, or to overrule a human — for a city job or promotionAn independent bias audit within the last twelve months, the summary published on your site, and ten business days' notice to the candidate
IllinoisAI in a covered employment decision from 1 January 2026; separately, AI analysis of a video interview for an Illinois-based postNotice before use and no zip code as a proxy; for video, disclosure, an explanation and consent before the interview
CaliforniaAn automated-decision system used by an employer with five or more employees, or by its agentNo discriminatory screen or proxy, an accommodation route, and four years' retention of the system data and selection criteria
New JerseyAny software or process that aims to automate, aid or replace a hiring judgementThe Uniform Guidelines applied to every characteristic the state protects, and adequate testing before use
MarylandFacial recognition used to create a facial template during an interviewA plain-language waiver signed by the applicant, naming them and the interview date
TexasDeveloping or deploying an AI system with intent to discriminate unlawfullyNothing extra for an uneven outcome alone — it turns on intent, not impact
What is not here: any general federal registration, audit or notice duty for hiring AI.

New York City deserves the closest reading: employers assume it covers them when it does not, then miss it when it does. Local Law 144 applies only to an "automated employment decision tool", and 6 RCNY § 5-300 narrows "substantially assist or replace discretionary decision making" to three cases: relying solely on the output, weighting it above every other criterion, or using it to overrule conclusions reached another way. A ranking one recruiter glances at among five factors is outside it. A ranking that sets the interview cut-off is inside it — and § 20-872 makes each day of use a separate violation, at up to $500 for the first and $500 to $1,500 thereafter.

Inside it, § 5-302 requires the audit to run on historical data from real use, and § 5-304(a) requires the notice to say how to ask for an alternative process or an accommodation. Diary the twelve-month expiry in the deadline tracker — the daily counter starts when it lapses.

What actually changes next

  1. 1 Oct 2026

    Connecticut, first tranche

    Public Act 26-15 amends the discrimination provisions and requires layoff notices to say whether AI was involved.

  2. 1 Jan 2027

    Colorado, second attempt

    SB 26-189: notice at the point of interaction, a plain-language explanation within 30 days of an adverse decision, and a route to human review.

  3. Jan 2027 (projected)

    The federal Guidelines leave the CFR

    The EEOC agenda targets final action in November 2026 to rescind 29 CFR Part 1607. California and New Jersey have adopted it as their own.

  4. 1 Oct 2027

    Connecticut, applicant notice

    Written notice naming the tool, its purpose and the data categories read, before the decision is made.

Only the first is a live obligation today. The rest are dates to diary, and the last two could move.

Face and voice data are a separate claim with their own damages

If the tool builds a scan of face geometry or a voiceprint, biometric privacy applies even where nothing discriminatory happened. Illinois is the one to plan around: 740 ILCS 14/15(b) forbids a private entity from collecting a biometric identifier unless it first tells the subject in writing that it is collecting one, the specific purpose and the length of term, and obtains a written release. Section 20 gives liquidated damages of $1,000 for a negligent violation or $5,000 for a reckless or intentional one, plus fees — and, unusually, a private right of action.

SB 2979 reduced that exposure in August 2024, limiting a claimant to one recovery per type of violation for the same identifier collected the same way, and confirming the release can be signed electronically. The step is small and the failure expensive: notice and release must exist before the first capture and must name the purpose and the retention period — facts you need from the vendor first.

Maryland runs a narrower version. Section 3-717 of the Labor and Employment Article bars an employer from using a facial recognition service to create a facial template during an interview unless the applicant signs a plain-language waiver giving their name, the interview date, their consent, and whether they read it. Most failures are employers who never realised the interview platform was doing it.

What to get from the vendor before you sign

This part is within your control: it is a contract problem, not a technology one. The charge, the audit letter and the state complaint will name you. Litigation is testing whether a vendor can be liable alongside an employer — in Mobley v. Workday the Northern District of California allowed claims to proceed on the theory that a screening provider acts as the employer's agent, and in June 2026 declined to dismiss the state-law claims — but a win there adds a defendant rather than removing one.

The five things worth negotiating for

The screening tool agreement

Ranked by how much they help when a charge lands — not the order they appear in the vendor's terms.

Two of those need saying plainly. Confidentiality clauses are the usual obstacle to the first two, and the fix is a carve-out permitting disclosure to a regulator, a court and your own counsel — negotiate it into the SaaS agreement or the service agreement. And an indemnity is a reimbursement promise, not a transfer of legal responsibility: vendor indemnities are usually drafted for intellectual property claims and say nothing about employment discrimination. Applicant data going out to an auditor needs its own confidentiality agreement.

Start from a contract you can add these to

Free full text. Screening tools are almost always bought on the vendor's paper; your own draft is what turns "that is our standard agreement" into a negotiation.

Open

The controls that hold whichever way the law moves

Read the last eighteen months as deregulation and you misread what moved. Enforcement priorities changed; the statute did not, the state layer thickened, and two states wrote the federal validation guidelines into their own law as the federal agency moved to withdraw them. The exposure changed address — to private plaintiffs and state regulators, who do not announce their priorities in advance.

The durable controls are the boring ones, the same in every jurisdiction above. Know which decision the tool actually makes, in practice rather than in the policy. Keep the selection numbers by group from the day you switch it on: a four-fifths calculation you can run in an afternoon is the difference between answering a charge and discovering the answer during it. Publish an accommodation route and staff it. Get the validation evidence and the cooperation duty into the contract while you still have something the vendor wants — all of it cheaper before the first complaint than after.

Sources

General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.

Frequently asked

If the vendor's tool discriminates, is my company liable?

Yes. Title VII, the ADA and the ADEA attach to the employer using the selection procedure, and 42 U.S.C. § 2000e-2(k) puts the burden of showing a screen is job related and consistent with business necessity on the employer. A vendor may now also be sued alongside you on an agency theory, and an indemnity may reimburse your costs, but neither removes your name from the charge or your obligation to justify the screen.

Do I need a bias audit to use AI résumé screening?

Only where a statute requires one. There is no general federal audit duty. New York City requires an independent bias audit within the last twelve months, published on your site, but only where the tool's output is used alone, weighted above every other criterion, or to overrule a human. Elsewhere, testing is not a formal requirement but is the evidence that answers a disparate-impact claim, and several states treat its absence as relevant.

Does having a human review the AI's shortlist protect me?

Partly, and not in the way people expect. It can take a tool outside New York City's definition, which is drafted around how decisive the output is. It does not answer Title VII, because disparate impact attaches to the practice that thinned the applicant pool, not to who chose among the survivors. A careful review of a shortlist an unvalidated filter produced leaves the filter unexamined.

Can an AI video interview ask about health or disability?

Not before an offer. 42 U.S.C. § 12112(d)(2) bars pre-offer medical examinations and disability-related inquiries, and California defines a psychological examination as any procedure seeking information about mental or physical health. A personality or wellbeing assessment that infers a condition can cross that line even where no question mentions health. Separately, a test measuring reaction time or facial expression risks screening out disabled applicants under § 12112(b)(6) and (b)(7).

The EEOC took its AI guidance down. Did the rules change?

The guidance changed; the law did not. The Commission removed its 2022 and 2023 AI technical assistance documents in January 2025, and Executive Order 14281 directs agencies to deprioritise disparate-impact enforcement. Neither amends the statute, binds a court, or reaches a private plaintiff or a state agency. Several states have since codified the same standards themselves, so in California, New Jersey and Illinois the practical requirements went up rather than down.

Do the whole thing on your phone

Draft it, check it for risk, rewrite the clauses you do not like, sign it and send it — without opening a laptop.

  • 136 templates across 12 categories
  • AI review in plain English
  • Free every month — 3 documents, 2 reviews
Download on theApp Store
Free to download · no account

iPhone, iPad, Mac & Vision Pro · iOS 15.6+ · 76.1 MB
Premium from $1.99/week