For three years, the story about legal risk in AI hiring has been a bias story: does the algorithm discriminate, and can a plaintiff prove it. Two cases working their way through federal court in California in 2026 are quietly rewriting that story. One of them is still nominally about bias. The other isn't about bias at all — and that second case may end up mattering more, because it doesn't ask a court to decide whether an algorithm is unfair. It asks whether an employer's AI vendor was required to tell candidates it was scoring them in the first place.
Mobley v. Workday: the vendor becomes a defendant
Mobley v. Workday has been running since 2023, but 2026 is the year it stopped being a single plaintiff's claim and started looking like a structural threat to how AI hiring vendors are sold. The case alleges that Workday's applicant-screening tools disproportionately screened out candidates by age, and on May 16, 2025, Judge Rita Lin of the U.S. District Court for the Northern District of California granted conditional certification of a nationwide collective action under the Age Discrimination in Employment Act, covering applicants 40 and older who applied through Workday's platform since September 24, 2020 (SHRM; PR Newswire). Notice went out to that collective, with a response deadline of March 7, 2026.
The legally consequential part isn't the age claim itself — it's who the court said could be sued over it. Workday argued it was "just a software provider," supplying a tool that employers configured and used; employers, not Workday, made the actual hiring decisions. The court rejected that framing, finding Workday sufficiently involved in the screening process to be treated as an agent of the employers deploying its tool for purposes of discrimination liability (HH Law; SocialTalent). That is the holding every HR-tech vendor's general counsel has had to read twice. It means "we only built the scoring tool, the employer decided what to do with the score" is not, on its own, a liability shield.
Through the rest of 2026 the case kept widening rather than narrowing. Plaintiffs asked the court to certify four additional proposed subclasses — covering race, sex, disability and the original age claim — with a class-certification hearing now scheduled for March 9, 2027 (Lawyer Monthly). Workday tried to get the age ruling kicked up to the Ninth Circuit on an interlocutory appeal; the court denied that request on July 2, 2026, and discovery has continued since (No Boiler; AI Lawsuit Tracker). Nothing here is resolved — there has been no finding that Workday's tool actually discriminated, and the company disputes the claims. What is resolved, provisionally, is the much bigger question of scope: a vendor whose software scores candidates can be a proper defendant in a discrimination suit, not just a witness against its own customer.
Kistler v. Eightfold: a different theory, and it skips bias entirely
The second case is the more interesting one precisely because it takes a completely different route to the same destination. On January 20, 2026, two California job seekers, Erin Kistler and Sruti Bhaumik, filed a proposed class action against Eightfold AI — backed by former EEOC chair Jenny Yang and the nonprofit Towards Justice — in Contra Costa County Superior Court, later removed to the Northern District of California (Fortune; Inside Tech Law).
The complaint alleges that Eightfold's platform compiles data on applicants — including, the plaintiffs say, profiles built from data points on more than a billion workers, drawn from sources like social media, location signals, and device and cookie tracking — into a 0-to-5 "Match Score" that is handed to employers, with low-scoring applicants screened out before a human ever reviews the file. Crucially, the plaintiffs say applicants were never told this profiling and scoring was happening, never shown the resulting report, and never given a chance to dispute anything in it (National Law Review; Jones Walker).
Here is the part that makes this case worth watching even if you have no opinion on Eightfold specifically: the lawsuit does not claim the Match Score is biased, inaccurate, or unfair. It claims the score is a "consumer report" in the legal sense defined by the Fair Credit Reporting Act — the same category of document that covers background checks and credit reports — and that Eightfold, by compiling and furnishing it without the FCRA's disclosure, consent, copy, and dispute-rights requirements (and California's parallel Investigative Consumer Reporting Agencies Act), is operating as an unlicensed consumer reporting agency. Eightfold's position, laid out in an April 20, 2026 motion to dismiss that remains fully briefed and awaiting a ruling, is that it licenses software to employers rather than selling reports, and is therefore not a consumer reporting agency at all under the statute (Fox Rothschild; Open Class Actions). Nobody yet knows who's right. But notice what the plaintiffs didn't have to prove to get this far: nothing about accuracy, nothing about disparate impact on a protected group, nothing a statistician would need to model. The theory is secrecy itself, independent of whether the secret score was any good.
Two different legal theories, one shared practical answer
Line these two cases up and a pattern appears that neither case states on its own. Mobley says a vendor can be liable as a participant in a decision it helped automate — "we're just the scoring engine" doesn't end the inquiry. Kistler says the scoring itself can be an unlawful act if candidates were never told it was happening and never given the report. Neither case has been decided. Both could still be dismissed, settled, or narrowed into something much smaller than the headlines suggest. But between them they are pointing at the same two practical requirements, arrived at from opposite directions: tell the candidate when AI is evaluating them, and don't let the automated score be the only thing deciding whether they get a human's attention.
That pattern is worth naming on its own terms, separate from how either case resolves, because it reframes what "AI hiring compliance" is actually about in 2026. For three years the compliance conversation centered on bias testing — adverse-impact ratios, protected-class statistics, the kind of audit NYC's Local Law 144 popularized. That work still matters and neither of these cases makes it less necessary. But Kistler in particular shows a second front that bias testing does nothing to address: a perfectly fair, perfectly accurate score is still a legal problem if nobody disclosed it existed. Disclosure and human review aren't bias mitigations. They're a different category of obligation, and 2026 is the year litigation made that distinction concrete instead of theoretical.
Where we draw our own line, narrowly
We built NiceHire's AI screening with exactly this distinction in mind, and we want to be precise about what that means and doesn't mean. It is not a claim that our scoring is unbiased, accurate, or legally risk-free — nobody can credibly self-certify that, and we aren't going to pretend otherwise. It's two narrower, mechanism-level facts.
First: every AI screening greeting NiceHire generates identifies the interviewer as an AI — in every language we ship, on both a first attempt and a reconnect after a dropped call, and whether an organization is using a default greeting or a customized one. That disclosure runs through a single function every greeting path calls; a custom or template greeting can change the wording, but it cannot suppress the disclosure line itself. That's the same gap Kistler puts at the center of its case against Eightfold — "the candidate was never told" — addressed as a structural default rather than a policy we'd need to remember to follow each time.
Second: when a candidate's score falls below the passing threshold an employer set, NiceHire's default behavior is not to reject them automatically. It routes them to pending review for a human decision. Automatic rejection exists as an option, but it's opt-in per pipeline stage, not the default. That doesn't resolve the liability question Mobley raises about vendors — a human-in-the-loop default is a design choice, not a legal defense, and we're not claiming otherwise. But it does mean the specific fact pattern at the center of that case — software doing the rejecting with no person involved — isn't what happens by default on our platform.
Neither fact is a certification. Neither is an accuracy or fairness claim. Both are falsifiable statements about what the code does today, and we'd rather state them that narrowly than borrow the weight of two unresolved lawsuits to imply more than that.
What this means if you're the one buying
If you're evaluating an AI hiring tool in late 2026, both cases suggest the same two questions are worth asking before you ask about accuracy:
- Does the candidate get told, every time, in every language and every retry path, that they're talking to or being scored by AI — and can that disclosure be switched off by a custom greeting or template? If the answer to the second half is yes, you have the exact fact pattern Kistler is testing.
- What happens by default to a candidate who scores below your threshold — rejected automatically, or routed to a person? If it's automatic rejection by default, you have the exact fact pattern Mobley is testing, and you're the employer named in that kind of suit, not just the vendor.
Neither question requires you to resolve what either court will eventually decide. They just require you to know what your own tool does today, in the specific places litigation in 2026 has shown plaintiffs will look first.
Ready to transform your hiring?
See how NiceHire's AI-powered hiring platform works for your team.
Get Started