
AI Hiring Law: What Changed While You Weren't Looking?
“The way the law is working — the Workday case is exhibit A here — is that vendors are going to be on the hook if their systems are producing biased outcomes. Period.” — Marc Weinstein Episode Overview In this episode I’m joined by Marc Weinstein, an attorney with 27+ years of practice focused on organizations that use tests to make high-stakes decisions about people — licensure, certification, admissions, and employment selection. His work centers on the legal rights of people impacted by AI systems and the organizations that use them. The legal ground under AI hiring is moving fast. In the past few months a state AI law got sued into a rewrite, a court handed down a ruling that shields bias audit data from view, and a new lawsuit opened a line of attack nobody was watching. If you buy, sell, or use AI hiring tools, this episode helps you stay on top of the shifting sands. Topics Discussed & Key Insights 1. First, how to roll: governance before headlines. Marc’s advice starts above the regulations. Your own governance is the key to successful risk mitigation. Get this part right and the rest gets much easier. * Before you track any law, ask why you want to use AI in the first place. If you have good answers, then ask how * Set principles for your organization — not for the whole world, for your organization. Let them drive your use cases, your vendor selection, and your evaluation criteria * Operate by them for real. A policy that lives on paper is worth nothing * Do this and you’re already in compliance with most of the laws that could touch you. Everything below is what’s shifting underneath that foundation 2. Vendor liability is shifting fast — get ready now. For a long time, vendors selling hiring tools got a pass. How the customer used the tool was the customer’s problem. That arrangement is breaking down. * In Mobley v. Workday, the court is letting claims proceed on the theory that the platform acts as an agent of its employer customers — which puts the same federal anti-discrimination laws that apply to employers on the platform * Plaintiffs go where the deep pockets are. Mega vendors like Workday and 8fold are the deep pockets * Employers are still independently on the hook. Vendor liability adds to yours, it doesn’t replace it * Newer legislation points the same direction, and California’s new regulations make bias testing itself evidence in court — more on that below * Since we recorded: the court refused to dismiss most of the remaining claims against Workday. The case keeps moving, and the core theory keeps surviving 3. Bias audit data can be withheld — and that says a lot. A discovery ruling in the Workday case protected the company’s bias testing data from the plaintiffs. Worth sitting with what that means. * The court held the data was privileged because lawyers curated it and the testing was done to provide legal advice — not for business use * Publicly advertising that you conduct bias testing did not waive the privilege * So the people alleging harm from the system may never see the data that would show whether the system harmed them * The bigger question: if the most important evidence about how these tools perform can be shielded, what does accountability actually look like? Proof may have to come from other directions 4. There are new ways to hold these tools accountable. The Eightfold case shows creative lawyering finding routes into AI hiring that didn’t exist a year ago. * The claim is built on the Fair Credit Reporting Act and privacy law — the argument is that AI-generated candidate scores are consumer reports, compiled without the required disclosures and consent * These theories don’t require proving discrimination as a legal element, which makes them easier cases to bring * The target hasn’t changed. It’s still about how these tools treat people. There are just more ways to get there now 5. Colorado is the cautionary tale: get aggressive, get crushed. Colorado passed the most rigorous state AI law in the country — mandatory risk management, impact assessments, a real duty of care. Then it got taken apart. * xAI sued to block the law. The DOJ intervened on xAI’s side — the first time the federal government moved to invalidate a state AI law * The legislature rewrote the law under pressure. The replacement is a notice-and-transparency framework, delayed to January 2027 * The lesson for everyone else: states that regulate AI aggressively are going to get sued by the federal government and the private sector. Plan around that reality 6. Meanwhile, California quietly became the strictest. While everyone watched Colorado, California put real requirements on the books — and nobody has sued to stop them. * Under the FEHA regulations, conducting a documented bias test supports an employer’s defense in discrimination litigation. Not conducting one supports the plaintiff. Records must be kept four years * The privacy agency’s automated decision-making rules take effect January 2027: pre-use notice to applicants and employees, opt-out rights, and the right to demand how a system reached a decision about you * That last one matters. Can anyone actually explain how a frontier AI model reached its decision? For most of these tools, the honest answer is no Final Takeaway The laws will keep shifting. Colorado got rewritten, California’s deadlines are coming, and the courts are redrawing vendor liability case by case. You can’t chase all of it. Build the governance foundation, make vendors show you their evidence — your data, not just their study — and treat every recommendation a machine makes as the decision it really is. Good governance gets you more than 90% of the way there, as long as it’s not just lip service. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit charleshandler.substack.com













