ComplianceSep 30, 20269 min read

The Hiring Software Is Now a Legal Party to the Decision

A federal court let disparate-impact claims against Workday proceed on an agent theory, Illinois made undisclosed AI use its own civil rights violation, and a California bill requiring human corroboration sits on the governor's desk today. Three separate mechanisms, one direction: the software is now a legal party to the hiring decision.

#AI hiring #employment law #vendor liability #Mobley v Workday #Illinois HB 3773 #California SB 947 #HR compliance #algorithmic discrimination
Ad

For most of the last decade, the legal exposure in AI-assisted hiring sat entirely with the employer. A company bought a screening tool, ran candidates through it, and if the outcome discriminated, the company answered for it — the vendor was, legally speaking, a supplier of software, not a party to the decision. Three developments landing within weeks of each other in 2026 are dismantling that assumption from three different directions at once: a federal court ruling on vendor liability, a state statute that makes silence itself a violation, and a state bill — awaiting a governor's signature or veto on the very day we're publishing this — that would require a human to corroborate what an algorithm decides. None of the three is about NiceHire specifically. All three are about exactly the category of product NiceHire is.

The court case: software as "agent"

Mobley v. Workday has been moving through the Northern District of California since 2023, when Derek Mobley alleged that Workday's applicant-screening technology discriminated against him on the basis of race, age and disability across the roughly 100 jobs he applied for and was rejected from, all of which ran through Workday's platform. The case matters now because of what changed in it this year, not what it started as.

On June 22, 2026, U.S. District Judge Rita Lin issued a ruling that largely denied Workday's motion to dismiss the plaintiffs' amended complaint (Duane Morris Class Action Defense Blog; Seyfarth Shaw). Two pieces of that ruling matter for anyone building or buying this kind of software. First, the court let the disparate-impact claims proceed, holding that plaintiffs had plausibly identified a specific employment practice — the use of an algorithmic screening tool to decide who advances — capable of producing a measurable statistical disparity. Second, and more consequentially, the court accepted the theory that Workday can be treated in law as an "agent" of the employers who use it, because those employers had allegedly delegated their own traditional hiring function — deciding who gets rejected and who moves to interview — to Workday's software. Both sources describe the same holding: the software wasn't just informing the decision, it was, in the court's framing, participating in making it.

That distinction is the whole story. An "agent" can be sued directly for the discriminatory outcome its actions produce, on the same theory that would apply to a staffing agency or a recruiter acting on a company's behalf. A supplier of a tool generally cannot. Mobley doesn't yet settle whether every AI hiring vendor is an agent — the case is still in litigation, with plaintiffs directed to file a further amended complaint and no jury verdict yet in sight — but it establishes that the question is now litigable rather than presumptively answered "no." Every vendor whose product recommends, ranks, or screens out candidates, ourselves included, now operates under a legal theory that didn't reliably exist two years ago.

The statute: notice is now an independent violation

While Mobley works through the courts, Illinois took the regulatory route. Since January 1, 2026, Illinois has treated the discriminatory use of AI in employment decisions and the undisclosed use of AI in those same decisions as two separate civil rights violations under the amended Illinois Human Rights Act (Crowell & Moring; Warden AI). The statute reaches recruitment, hiring, promotion, discharge, discipline and the general terms of employment, and it separately bars using zip code as a proxy for a protected class. The notice provision is the sharper edge, and it's worth stating plainly: a hiring process that produces perfectly even outcomes across every protected class still commits a violation under this law if the employer never told anyone AI was involved in the decision. Outcome and disclosure are decoupled on purpose.

What makes Illinois's law an unusually live case study right now is what happened to the rules meant to define compliance with it. The Illinois Department of Human Rights proposed draft rules spelling out what a compliant AI notice actually has to say and look like on May 15, 2026 — and withdrew them on June 2, 2026, with no announced refiling timeline (Crowell & Moring; Warden AI, both citing the same withdrawal). The underlying statutory duty to disclose has been legally binding for nine months. The regulator's own guidance on how to satisfy it has been withdrawn for four. Employers and vendors are operating a real legal obligation without an official answer to "what does compliant look like," which is a genuinely uncomfortable place for a state law to leave an entire industry — and a preview of what happens when statute outruns rulemaking.

The bill: human corroboration, on the governor's desk today

California's contribution is still being decided as we write this. In October 2025, Governor Newsom vetoed SB 7, the "No Robo Bosses Act," calling its notification requirements "unfocused" and its restrictions overly broad — a bill that would have applied across hiring, promotion, discipline and termination decisions generally. The legislature returned in 2026 with a narrower successor, SB 947, scoped specifically to termination and discipline rather than the full employment lifecycle, and built around a single mechanism: an employer cannot rely solely on an automated decision system to fire or discipline a worker, and where an automated system assists that decision, a human must corroborate the output before it takes effect, with post-use notice to the affected employee (Bloomberg Law; California State Senate). California's legislative session ended September 1, 2026, sending the bill to the governor's desk with a September 30, 2026 deadline to sign, veto, or let it become law by default. That deadline is today. At the time of writing, no decision has been publicly announced, and we're not going to guess one — the more durable fact is the mechanism the bill embodies, not which way one governor's pen moves in the next few hours.

SB 947's narrower scope — termination and discipline, not hiring or screening — matters for reading across to recruiting software specifically. It doesn't regulate the screening step Mobley is about. But the underlying design principle it's built on — a human must corroborate what the algorithm outputs before that output becomes an action taken against a person — is the same principle regulators and courts are converging on from every direction this year, even when the specific statute in front of them hasn't reached hiring yet.

Three different mechanisms, one direction

A court applying decades-old agency law to software behavior. A legislature making disclosure a freestanding duty independent of outcome. Another legislature trying, twice, to require a human check on an automated action. None of these three coordinated with each other — they're a federal court, the Illinois General Assembly, and the California Legislature, each working an entirely separate problem through an entirely separate legal mechanism. That they've converged on the same underlying question — how much of the actual decision did the software make, was anyone told, and did a human check it — in the same twelve months is the more useful signal than any one of the three rulings or statutes read alone.

For a company that builds screening software, that convergence isn't background reading. If the agent theory in Mobley survives further litigation, it applies to any vendor whose product recommends, ranks or screens out candidates — a category NiceHire sits in as squarely as Workday does. We're not going to claim our own architecture resolves a legal question that's still being litigated in front of a federal judge, and we're specifically not going to claim any of the below makes an outcome fair or its evaluation neutral — that's a determination no vendor can credibly self-certify, and we've said so before. What we can point to, narrowly, is that the category of design decision these three developments are scrutinizing — was AI use disclosed, was a human in the loop before an adverse outcome, is the evaluation applied consistently and recorded — happens to be the category our own pipeline was already built around. Every NiceHire AI screening greeting states that the interviewer is AI, in every language the product ships and on every attempt, with no configuration path that removes the disclosure. Auto-rejecting a candidate below the passing threshold is off by default; the default routes a below-threshold result to a human for a decision, not to an automatic rejection, and that's true at every stage in NiceHire's multi-stage pipeline, not only at the AI-screening step. Every candidate for a given role is scored against the same fixed criteria, and a completed screening stores a structured record — the scores, the recommendation, the recorded strengths and gaps — against the application rather than nothing.

None of that is a compliance certification, and none of it is a defense we're offering on Workday's behalf or anyone else's. It's a description of a design choice that predates this year's rulings and statutes, made for reasons that had nothing to do with anticipating them. What 2026 has done is turn that kind of design choice from an internal product decision into something a court, a state regulator, or a state legislature might eventually ask you to prove.

What this means if you're buying, not just building

If you're an employer evaluating AI hiring tools rather than building one, three questions from the year's case law and statutes are worth asking any vendor directly, in writing:

  1. Does the tool disclose itself, unconditionally, to every candidate it interacts with — and can you turn that disclosure off? Illinois has already made the second half of that question its own freestanding violation, independent of whether the tool discriminates.
  2. Can the tool auto-reject a candidate with no human in the sequence, and is that the default or an opt-in? SB 947 doesn't reach hiring yet, but the corroboration principle it's built on is where discipline and termination automation has already been pushed once and is being pushed again.
  3. Does the tool record what it evaluated and why, per candidate — or does it produce a single pass/fail signal with nothing behind it? Mobley's disparate-impact claims survived because plaintiffs could point to a specific, describable employment practice. A tool that can't produce its own record of what practice it actually ran leaves you defending a black box in exactly the posture Workday is now defending one.

None of these three questions require you to trust a vendor's marketing claim. All three are things you can ask to see evidence of, the same way a court and two legislatures are now asking to see evidence of them.

Ad

Ready to transform your hiring?

See how NiceHire's AI-powered hiring platform works for your team.

Get Started

Share this article

Ad

About the Author

NT

NiceHire Team

HR Tech Writer

Ad
Back to all articles
Ad
Support