The context

Derek Mobley is a Black man over 40 with disclosed diagnoses of depression and anxiety. Over two years he applied to more than eighty positions at companies including Intuit, Nvidia and Citi. Each company used Workday’s applicant tracking system for initial screening. Each rejected him.

Mobley filed suit in August 2023 in the Northern District of California. The claim was not that any individual employer discriminated. The claim was that Workday’s AI-assisted screening tools were systematically filtering him out on the basis of his race, age and disability across every company he applied to. The suit named Workday as the defendant, not the employers.

In February 2024, Judge Rita Lin denied Workday’s motion to dismiss. A federal court held, for the first time, that a third-party AI hiring tool vendor could be liable as an “agent” under Title VII of the Civil Rights Act, the Age Discrimination in Employment Act (ADEA) and the Americans with Disabilities Act (ADA). Workday’s defense was that it is a software vendor, not an employer. The court found that Workday’s tools exercise a function historically belonging to employers (initial applicant screening) and that Workday exercises meaningful control over how that function operates.

The case had not reached trial as of this writing. But the “agent” theory has survived the motion to dismiss threshold. That is the durable result.

The three failures, and what each one actually cost

Every company named in the complaint made the same three mistakes. The cost to prevent any one of them was measured in hours. The cost of not preventing them is now measured in legal exposure.

FailureWhen it happenedPrevention costCost of not preventing
No adverse impact data in vendor RFPVendor selection, 2021-20222-4 hours: add 7 questions to existing RFPFederal lawsuit, 2023; defense costs estimated $500k-2M+
No demographic rejection monitoringGo-live through 20231 analyst-day per quarter2+ years of undetected discrimination across 80+ candidates; reputational exposure
No indemnification clause for AI screening decisionsContract signing, 2021-2022One legal redline pass, 2-4 hoursNo contractual recovery from Workday for defense costs or damages

The four steps below close all three gaps. Download the printable checklist to fill in with your team: AI Hiring Tool Control Checklist (PDF, 6 pages).

Step 1: Audit your next vendor before you sign

See also: How do you audit an AI system?

The seven questions below belong in every RFP for an AI hiring tool. They take 20 minutes to add. A vendor who refuses to answer questions 1, 2, or 4 is a disqualifying response.

#Add this to your RFP
1Provide your adverse impact analysis for AI screening for the 12 months ending [current month], showing pass rates by race, sex, age bracket (over/under 40), and disability status against your customers’ applicant pools.
2What is your retest cadence after a model update that could affect bias? Provide results from your last three model updates.
3List every configuration parameter available to deployment teams that could affect candidate scoring or ranking.
4Describe your training data. What percentage was supplied by existing customers? What was the demographic composition of historical hiring decisions in that data?
5What is your process for notifying customers of material model updates? Define “material” in writing.
6Have any customers raised a bias concern with your ATS AI tools in the past 24 months? How was each one resolved?
7Will you commit to a contractual adverse impact testing requirement, with results shared annually?

If you are in an active contract with an AI hiring tool vendor and have never asked these questions, ask them now in writing. The response, or the absence of a response, is relevant if a claim is ever made.

Step 2: Audit your contract for the indemnification gap

Procurement and legal sign-off is part of your AI governance structure.

Standard enterprise SaaS contracts contain a limitation of liability clause and an indemnification carve-out. Together, these two clauses mean that even if your vendor’s AI tool produced discriminatory results, the vendor likely has no contractual obligation to cover your defense costs or damages. Most HR procurement teams do not catch this because they are checking a contract for SLA and data residency, not for civil rights liability.

Contract clauseWhat the standard SaaS contract saysWhat you need insteadVendor resistance
Limitation of liabilityCapped at fees paid in prior 12 monthsUncapped for discrimination claims arising from vendor AI decisionsHigh
Indemnification scopeExcludes discrimination and civil rights claimsCovers claims arising from the vendor’s AI screening decisionsVery high
Model update notificationNo obligation30 days written notice before any material model updateMedium
Bias testingNo obligationAnnual adverse impact analysis delivered to customerLow-Medium
Configuration audit trailVendor owns and controls recordsCustomer right to retrieve full configuration history on requestLow
Training data disclosureConfidential, no disclosureAnnual disclosure of demographic composition of training dataHigh

Very high resistance clauses are negotiable on contracts above approximately $500k annual value. Below that threshold, alternative leverage points include: a mutual right to terminate if adverse impact thresholds are breached; a pricing reduction clause tied to bias test results; or a requirement that the vendor provide bias insurance documentation.

If your contract is already signed and contains none of these clauses, flag it to legal as a known risk and negotiate them into the next renewal.

Step 3: Run the four-fifths rule on your current ATS data

The Uniform Guidelines on Employee Selection Procedures (EEOC, 1978) require any employment selection procedure to be validated against adverse impact. The four-fifths rule is the standard threshold. It applies to AI screening tools. Here is how to run it.

The formula: selection rate for group X ÷ selection rate for highest-selected group

If the result is below 0.80, you have a four-fifths rule breach that requires review.

Step-by-step:

  1. Pull from your ATS: total applicants and screening pass-throughs for the last 12 months, broken down by race, sex, age (over/under 40), and disability status (if disclosed).
  2. Calculate selection rate for each group: passed screen ÷ total applicants in group.
  3. Identify the group with the highest selection rate.
  4. Divide each other group’s selection rate by the highest. Flag any ratio below 0.80.
  5. If you find a breach: document it immediately, involve legal, and determine whether the breach existed in prior periods.

What a breach looks like in practice:

GroupApplicantsPassed screenSelection rateRatio to highestCompliant?
White1,20036030.0%1.00 (reference)Yes
Asian3008729.0%0.97Yes
Hispanic2406225.8%0.86Yes
Black1803620.0%0.67No (threshold: 0.80)
Over 404009624.0%0.80Borderline (review)
Disability disclosed60915.0%0.50No (threshold: 0.80)

The 0.67 and 0.50 ratios in this example are exactly the pattern Mobley alleges. If data like this exists in Workday’s customer dashboards and no one acted on it, that is relevant to the liability question.

Do not run this calculation once. Run it quarterly and log the results. The log becomes your documented monitoring record.

Step 4: Set up the three monitoring checkpoints

Adverse impact monitoring for an AI hiring tool is not a model performance problem. It is a data analysis task. One person, one day per quarter, three numbers to check.

CheckpointWhat to measureThresholdAction if triggered
Screening stageRejection rate by demographic group, four-fifths ruleAny ratio below 0.80Suspend AI screening, involve legal, run root cause
Configuration driftHave any screening parameters changed since last review?Any undocumented changeDocument the change, require review sign-off retrospectively
Vendor model updatesDid the vendor update their model since last quarter?Any update without documented re-testRequest updated bias analysis from vendor before next screening cycle

The three checkpoints take under two hours if your ATS has a reporting export. If your ATS does not expose rejection data by demographic group, that absence is itself a finding: you are operating a screening system you cannot audit.

Step 5: Brief your recruiting team on what AI can and cannot decide

This briefing is the practical implementation of an AI acceptable use policy for your recruiting function.

The legal exposure in this case is not only about the vendor. It is about whether your team understood the tool, used it within its intended scope, and had a human override path. If you cannot answer yes to all three, your team is exposed, not just your vendor.

Run this briefing with every recruiter who uses the ATS. It takes thirty minutes. Document that you ran it and when.

TopicWhat to tell your teamWhat your team should be able to say back
What the AI screening tool does”It ranks or filters candidates based on signals in the application. It is not making the hiring decision. You are.""I use it as a first sort. The final shortlist is mine.”
What it cannot see”It cannot see photos, names, or demographic data directly. But it can pick up proxies: graduation year, address, school name. These can correlate with protected characteristics.""I know the output can be biased even if the input looks neutral.”
When to override”If a candidate does not pass the AI filter but you have reason to believe they are qualified, you can and should flag them for review. Document why.""I know the override path and I have used it.”
What to report”If you see a pattern in rejections that concerns you (a role where all shortlisted candidates look similar), report it to your manager. That is how we detect bias before it becomes a claim.""I know who to tell if something looks off.”
Who owns the outcome”If a rejected candidate files a discrimination claim, they are claiming the decision was discriminatory. The AI ranked them out. You used that ranking. Both are relevant. The company is liable.""The decision is mine. I cannot say the software did it.”

The question that tells you if your team is ready: Ask each recruiter: “If a candidate complained that our AI screening tool treated them unfairly, what would you do?” If the answer is not “I would escalate to HR and document the candidates’s information and the AI output immediately,” your team is not briefed.

What to check quarterly, assigned by role

Adverse impact monitoring only works if someone owns each task. This is the assignment table.

TaskOwnerFrequencyOutput
Pull ATS rejection data by demographic groupHR analyst or TA opsQuarterlySpreadsheet with four-fifths ratios by role and group
Run four-fifths rule calculationHR analystQuarterlyFlag any ratio below 0.80 to HR director + legal
Review ATS configuration for undocumented changesHR systems adminQuarterlyWritten confirmation: “No changes since last review” or change log
Request bias analysis from vendorHR director or procurementAnnually (or after any vendor model update notification)Vendor’s adverse impact report, logged and filed
Review recruiter override logHR directorQuarterlyCount of overrides by recruiter and role; flag any role where overrides are zero
Legal sign-off on monitoring resultsEmployment counselAnnuallyWritten sign-off that monitoring program meets EEOC standards

If any of these tasks has no owner, it is not happening. Assign names, not job titles.

What discovery will force into the open

If this case reaches discovery, Workday will need to produce three categories of documentation that most AI vendors have not been required to make public. The answers will define the liability landscape for the industry.

Training data composition. Workday’s screening models are almost certainly trained in part on historical hiring data contributed by Workday customers. If that data reflects prior discriminatory hiring patterns (and the EEOC’s enforcement history suggests this is common), the model encoded those patterns at training time. The bias may have been imported from the companies’ own historical decisions and then applied back to them.

Model update logs and internal testing records. Discovery will establish whether Workday ran adverse impact testing on its models before deployment, and what the results showed. If internal testing identified disparate impact and the company deployed regardless, that is materially different from the bias being undetected.

Per-customer configuration audit trails. The defendant companies configured Workday’s ATS. What signals they weighted, and whether those configurations changed over time, is the kind of documentation most HR teams do not maintain. The inability to produce it is not neutral: it demonstrates the companies were running a system with material effects on candidates without any mechanism to understand what it was doing.

The concentration problem

Mobley applied to more than eighty companies. Each used Workday. Each rejected him. This is not eighty independent hiring decisions. It is one algorithm applied eighty times.

When three or four ATS platforms cover most of the enterprise hiring market, a single discriminatory pattern in one of them does not produce one adverse outcome. It produces a market-wide barrier. The candidate cannot self-select away from the biased system because they do not know which systems their prospective employers use.

The litigation addresses one plaintiff and one defendant. It does not address the structural question: what remedy is appropriate when the harm is market-wide and the information asymmetry is total? That question requires a regulatory answer, not a legal one. The FTC, EEOC, and CFPB have all indicated interest in algorithmic discrimination. The Workday case will be exhibit one in those proceedings.

Where this leaves HR directors

The court’s theory is simple: you selected the tool, you deployed it, you delegated the screening function to a vendor. You cannot delegate the legal obligation that goes with that function. The “we just used the software” defense does not survive the agency theory the court accepted.

The EU AI Act adds a parallel obligation for companies with European operations. Under Annex III, AI systems used in recruitment and employment are classified as high-risk, requiring conformity assessment, bias monitoring and human oversight before deployment. EU-based HR directors face that requirement now, regardless of how Mobley v. Workday resolves in US courts.

The companies in this case made defensible operational decisions with the information they had at the time. What they did not do was ask who was responsible for what the AI decided. Adding that question to the RFP, the contract review, and the quarterly operations review is the entire correction.


Sources: Complaint, Mobley v. Workday Inc., No. 3:23-cv-04146 (N.D. Cal., filed Aug. 10, 2023). Order denying motion to dismiss, Feb. 26, 2024. EEOC, “Uniform Guidelines on Employee Selection Procedures” (1978). EEOC, “Technical Assistance on Artificial Intelligence and the Americans with Disabilities Act” (2023). SHRM, “Workday AI Lawsuit: A Wake-Up Call for HR” (2024). EU AI Act, Annex III (2024).