ComplianceAug 31, 20269 min read

When the Screening Tool Becomes the Defendant: What Mobley v. Workday and the Eightfold FCRA Suit Mean for AI Hiring Vendors

Two US cases test whether an AI hiring vendor — not just the employer that bought its software — can be sued directly. Mobley v. Workday established a screening vendor can be liable as an employer's “agent”; Kistler v. Eightfold AI argues a scoring platform is an unregistered credit-reporting agency under the FCRA. Neither is decided, but both target the hidden score. We cover where the cases stand, and where NiceHire's own scoring and rejection defaults sit against the same questions.

#AI hiring #employment law #FCRA #EEOC #Workday #Eightfold AI #hiring compliance #AI vendor liability #HR tech
Ad

For most of the AI-hiring compliance conversation, the defendant in the room has been the employer. Bias audits, disclosure duties, human-oversight requirements — nearly every rule written since 2023 has been addressed to the company doing the hiring, on the assumption that whatever software it bought was just a tool, and the buyer carries the legal risk. Two US cases moving through the courts this year are testing whether that assumption holds. Neither is decided. Both are worth understanding now, because they attack the same target — the scoring system itself — from two different directions in the law, and they are starting to converge on the same demand: the vendor doesn't get to stay invisible.

Mobley v. Workday: the vendor as "agent"

Mobley v. Workday, Inc., No. 3:23-cv-00770, has been in the Northern District of California since 2023, and it has produced the single most consequential ruling in AI-hiring law to date: a court holding that an AI vendor — not just its employer-customers — can be sued directly for employment discrimination.

The theory is "agent" liability. Workday's screening customers delegate a traditional hiring function — rejecting applicants — to Workday's algorithmic tools. The court's reasoning, laid out in 2024, was that a company acting as an agent of employers on that function falls within the definition of "employer" under Title VII, the ADEA and the ADA, and can be sued as one. The EEOC filed a proposed amicus brief on April 9, 2024 backing that theory. It is a narrower legal proposition than it sounds — a separate "employment agency" theory in the same complaint was rejected — but the agent theory survived, and it is the reason this case has kept moving instead of ending in 2024.

Three things have happened since that make the exposure concrete rather than theoretical:

  • May 16, 2025 — the court granted preliminary certification of a collective action on the ADEA claim, opening the case to applicants aged 40 and over who were screened through Workday's tools going back to September 2020. A court-authorized opt-in notice period followed, reported open as of January 2026.
  • March 6, 2026 — the court rejected Workday's argument that ADEA disparate-impact protections apply only to employees and not to job applicants, closing off what had been one of Workday's stronger remaining defenses.
  • May 28, 2026 — the court ruled that Workday's internal AI bias-testing data may, in part, be shielded from discovery by attorney-client privilege — a ruling that cuts the other way for plaintiffs and will shape how future defendants structure their own bias audits.
  • June 22, 2026 — the court denied in part Workday's motion to dismiss the plaintiffs' California Fair Employment and Housing Act claims, rejecting Workday's argument that FEHA shouldn't apply because many collective members live outside California; the court held the nexus to California is Workday's own headquarters, where the screening tools are designed and operated. An ADA proxy-discrimination claim survived the same motion.

None of this is a verdict. A ruling denying a motion to dismiss means the claims are legally viable enough to proceed to discovery and, eventually, trial or settlement — not that discrimination has been proven. But three years in, the case has answered the one question every AI-hiring vendor wanted answered in its favor and didn't get: whether the entity that built the filter can be sued for what the filter did, separately from the employer that bought it.

Kistler v. Eightfold AI: the FCRA angle

A newer case takes a completely different statute at the same problem. Kistler v. Eightfold AI Inc., No. C26-00214, was filed in California Superior Court on January 20, 2026, by applicants Erin Kistler and Sruti Bhaumik. It doesn't allege discrimination. It alleges that Eightfold's AI hiring platform is functioning as an unregistered consumer reporting agency under the federal Fair Credit Reporting Act — the same statute that governs the credit-check and background-check industry.

Eightfold's product generates a "Match Score," ranking candidates from 0 to 5 in half-point increments based on an assessed likelihood of success for a role, built from data the complaint says includes resumes, social-media and professional-network profiles, location data and online activity. According to the complaint, that score is compiled and handed to employer-clients to rank and filter applicants — in some cases, plaintiffs allege, before a person reviews the application at all — with no disclosure to the applicant that the scoring happened, no consent obtained, and no mechanism to see or dispute the underlying data.

The legal move is to argue that a Match Score is functionally a "consumer report" used for employment purposes, and that a company compiling one is a consumer reporting agency whether or not it calls itself one. If that argument succeeds, it would import a well-established compliance regime — one background-check vendors have operated under for decades — onto AI scoring products that were not built with it in mind: a permissible-purpose requirement before pulling data, clear disclosure and written authorization from the applicant, a pre-adverse-action notice with a copy of the report before any rejection, a waiting period, a post-adverse-action notice naming the reporting agency, and a right for the applicant to access and dispute inaccurate information. Eightfold's reported position is the opposite characterization: that it is a service provider processing data on behalf of its employer-clients, not an independent reporting agency, and that a Match Score is not a "consumer report" in the statutory sense. That is precisely the question the case will decide, and it has not been decided yet.

Two statutes, one target

Discrimination law and credit-reporting law rarely show up in the same sentence, but read together these two cases are pointed at the same structural feature: a score, generated by a vendor, that a candidate never sees, cannot dispute, and that can end their candidacy before a human looks at the application. Mobley asks whether the vendor that builds that score can be sued as an employer when the score discriminates. Kistler asks whether the vendor that builds that score has to follow the disclosure-and-dispute rules that already govern every other kind of automated profile used to make an employment decision. Neither theory needs the other to succeed, but if either one lands, the practical requirement on every vendor selling a ranking or scoring tool converges on the same short list: tell the candidate a score exists, let them see and correct what it's built on, and don't let it reject someone with nobody accountable for the decision.

For a hiring team evaluating vendors right now, that list is a usable procurement checklist, independent of how either case is ultimately resolved:

  1. Ask whether the tool can reject a candidate with no human in the loop, and what the default is. "Configurable" is not the same as "off by default" — ask which one you're buying.
  2. Ask what data the score is built from, and whether that goes beyond what the candidate submitted — resumes and applications are one thing; scraped social profiles and inferred traits are a different, and now more litigated, thing.
  3. Ask whether a candidate can see their own score and the criteria behind it, and whether there's any path to flag or correct bad underlying data.
  4. Ask who the vendor thinks is liable if the score discriminates or gets something wrong — a vendor that has thought about Mobley has an answer; one that hasn't is a bigger exposure than its contract implies.

Where NiceHire stands

We build and sell exactly the kind of tool this litigation is about — AI resume vetting and AI screening interviews — so it would be strange to write this piece without saying where we sit against our own checklist, in the tense our code actually supports today, not a roadmap tense.

Every candidate NiceHire screens is scored against the same published criteria — technical fit, communication, and cultural fit, each out of 100 — against a passing threshold each employer sets for their own pipeline. Auto-rejecting a candidate below that threshold is off by default: unless an organization deliberately opts a stage into automatic rejection, a below-threshold candidate is routed to pending review for a human to decide, not silently filtered out. That is a design choice about who a rejection is attributable to, not a claim that NiceHire is immune from the theories above — we are not a party to either case, we hold no position on how a court should resolve them, and nothing here should be read as legal advice for how another vendor's product would fare under the same analysis.

The honest summary, for us and for anyone reading this to evaluate a vendor: the era in which a scoring algorithm could be a black box between a resume and a rejection, answerable to no one, is the thing currently being tested in two courts at once. Whichever way Mobley and Kistler land, "the algorithm did it" is not going to be an answer that satisfies a judge, and it shouldn't satisfy a hiring team either.


Sources: Civil Rights Litigation Clearinghouse — Mobley v. Workday, Inc. case record; Seyfarth Shaw — "Mobley v. Workday: Court Holds AI Service Providers Could Be Directly Liable... Under 'Agent' Theory"; Seyfarth Shaw — "EEOC Argues Vendors Using AI Tools Are Subject to Title VII, the ADA and ADEA"; Forbes — "Applied For A Job Through Workday? Court-Authorized Opt-In Is Now Open"; Forbes — "A Federal Judge, A 1967 Law And A Billion Rejected Job Applications"; Duane Morris Class Action Defense Blog — "California Federal Court Clarifies Limits On AI Bias Testing And Applicant Data Disclosure In Mobley v. Workday"; HR Dive — "Workday can't shake California AI discrimination claims"; Akin Gump — "AI Hiring Platform Faces FCRA Class Action Over Data Use: Kistler et al. v. Eightfold AI Inc."; FindLaw — "Proposed Class-Action Lawsuit Targets Eightfold's AI Hiring Platform"; ClassAction.org — "Lawsuit Claims Eightfold AI Unlawfully Collects Job Applicants' Data"; Fisher Phillips — "Job Applicants Sue AI Screening Company for FCRA Violations: 5 Key Takeaways"; Sterling — "Adverse Action Best Practices Under the FCRA". Case citations: Mobley v. Workday, Inc., No. 3:23-cv-00770 (N.D. Cal.); Kistler et al. v. Eightfold AI Inc., No. C26-00214 (Cal. Super. Ct.).

Ad

Ready to transform your hiring?

See how NiceHire's AI-powered hiring platform works for your team.

Get Started

Share this article

Ad

About the Author

NT

NiceHire Team

HR Tech Writer

Ad
Back to all articles
Ad
Support