Skip to the main content.

How to Use AI in Hiring Without Creating Legal Risk

A practical guide to using AI in hiring responsibly — current 2026 lawsuits, state laws, and a concrete framework HR leaders can follow to avoid legal exposure.

If your applicant tracking system, resume screener, or video interview platform has "AI" anywhere in its marketing, you already have legal exposure you may not be tracking. Not because AI in hiring is inherently illegal — it isn't — but because the regulatory and legal landscape around it has moved faster than most HR teams' policies have. This page is meant to be the one place you can come back to for the current state of that landscape, and a practical framework for using AI in hiring without ending up as the next cautionary case study.

Why This Is Urgent Right Now

For years, "AI hiring bias" was mostly a theoretical concern raised in conference keynotes. That's no longer true. In early 2026, a federal judge allowed age discrimination claims to move forward in Mobley v. Workday — a case brought by a job seeker who was rejected from over a hundred positions at companies using Workday's screening tools, often within minutes of applying. The claim isn't that anyone intentionally programmed the system to discriminate; it's that the tool's outcomes disproportionately screened out applicants over 40, regardless of intent. A second case, Swanson v. IBM, filed in May 2026, extends the theory further — arguing that an employer's own internal use of AI, not just a vendor's tool, produced an age-discriminatory rejection.

The detail that should worry every HR leader most is what the EEOC has said about all of this: "the algorithm did it" is not a legal defense under Title VII. If a vendor's tool discriminates, the employer using it is still liable. Outsourcing the decision to software does not outsource the accountability.

 

The Regulatory Landscape You're Actually Operating Under

Unlike a lot of employment law, AI hiring regulation right now is not one national standard — it's a patchwork that's growing faster than most compliance teams can track, especially since the federal government pulled back its own AI hiring guidance this year, leaving states to write their own rules. Here's what's actually in force or newly effective as of 2026:

New York City — Local Law 144.

If you use an Automated Employment Decision Tool (AEDT) to screen, rank, or shortlist candidates for a role based in NYC, you're required to obtain an independent bias audit — conducted by a third party, not the vendor — within the past year, publish a public summary of the results on your website, and give candidates at least ten business days' notice before the tool is used on them. Penalties run $500 to $1,500 per violation, and each unnotified candidate and each day of non-compliance can count separately.

Colorado's AI Act.

Effective in mid-2026, this law requires any company deploying a "high-risk" AI system — hiring tools included — to take "reasonable care" to protect people from algorithmic discrimination. That standard is intentionally broad, which means the practical compliance bar is demonstrating you did real diligence, not just that nothing bad happened.

Illinois

Amendments to the state's Human Rights Act now specifically prohibit using AI in a way that results in discrimination, with particular attention paid to generative AI tools — a direct response to how quickly generative AI got folded into resume screening and candidate communication.

The federal picture

With federal AI hiring guidance pulled back this year, there is currently no single national standard filling the gap — which means multi-state employers are compliance-managing a moving target across several state lines at once, not one clear federal bar.

A Practical Framework for Using AI Responsibly


None of this means you should abandon AI in your hiring process — plenty of it is genuinely useful. It means you need a deliberate framework instead of trusting a vendor's marketing page. Here's the one we'd actually recommend.

Start with validation, not automation.

Before you ask what a tool automates, ask what it's validated against. A resume-screening or scoring tool should be able to show you real predictive validity data and, ideally, its own adverse impact studies — not just a demo of how fast it works. Speed without validated science is exactly the profile of tool showing up in 2026's lawsuits.

Never let AI make the final call alone.

The single clearest lesson from Mobley v. Workday is what happens when rejection decisions happen without meaningful human review. A defensible process uses AI to inform and prioritize, with a human accountable for the actual decision — not a human rubber-stamping whatever the algorithm already decided.

Audit your vendors, not just your own tools

The EEOC has made clear that using a third-party tool doesn't transfer your liability to that vendor. If you haven't asked your ATS or screening vendor for their bias audit methodology and results, that's the first phone call to make this week — regardless of whether you're required to by law in your specific location.

Build in disclosure by default

Even outside jurisdictions that legally require it, telling candidates when and how AI is being used builds trust and reduces the reputational and legal risk of candidates discovering it after the fact. NYC's ten-day notice requirement is a reasonable floor to adopt everywhere you hire, not just where it's mandatory.

Document everything.

Which tool, which version, what it was used for, what the audit results were, when candidates were notified. If a claim like Mobley's or Swanson's ever lands on your desk, the difference between a quick resolution and a prolonged, expensive one is almost always the quality of your documentation trail.

Prefer tools built on transparent, validated science over black boxes.

This is where something like the Predictive Index stands apart from a lot of newer AI hiring tools — it's built on decades of validated behavioral science with transparent, defined constructs, not a proprietary algorithm nobody can fully explain. That's not a marketing point, it's a genuine risk-reduction one: a tool you can explain is a tool you can defend.

 

Where This Leaves You


The honest takeaway is that "AI in hiring" isn't the risk category — unvalidated, opaque, unaudited AI making unreviewed decisions is. Treat every AI hiring tool the way you'd treat any other high-stakes vendor: ask for its receipts, keep a human accountable for the outcome, tell candidates what's happening, and write all of it down. Do that, and AI can genuinely make your hiring process faster and fairer. Skip it, and you're one rejected candidate away from being the next name in a lawsuit like the ones above.

If you want help auditing where your current hiring stack stands on any of this — from your ATS's screening logic to whether your assessments are actually validated — get in touch and we'll walk through it with you.

 

Learn More about Predictive Index Hire

PI Hire
 

Predictive Index Hire Demo

See Predictive Index Hire in action. In this short demo, we'll show you how PI Hire helps you build data-driven job targets, evaluate candidates more objectively, and make better hiring decisions with confidence. Whether you're new to Predictive Index or looking to get more value from the platform, this walkthrough will help you understand how PI Hire can improve the quality and consistency of your hiring process.