Skip to main content

AI in the Workplace: Can Algorithms Legally Influence Corporate Layoff Decisions?

Can an algorithm legally decide who gets laid off? A 2026 legal guide covering EEOC enforcement, GDPR, the EU AI Act, and new US state laws — with ver

TechWithSanjay

⚠️ Legal Disclaimer

This article is for general informational purposes only and does not constitute legal advice. Employment law involving AI is evolving rapidly across federal, state, and international jurisdictions, and the specific rules that apply depend on where your company operates, where your employees are located, and the facts of your situation. Laws referenced here, including Colorado's AI Act and Illinois's Human Rights Act amendments, have changed materially during 2025–2026 and may change again. Consult a licensed employment attorney in the relevant jurisdiction before making decisions about AI-assisted workforce actions.

⚡ Quick Answer

AI can legally inform layoff decisions in the US, EU, and UK, but no jurisdiction lets a company hide behind "the algorithm decided." Employers stay liable under existing discrimination law (Title VII, the ADEA, the ADA, FEHA) if an AI tool produces a disparate impact, and a growing patchwork of AI-specific laws layers on extra obligations: impact assessments, employee notice, bias audits, and meaningful human review. As of August 2026, the two biggest live signals to watch are Mobley v. Workday, which is testing whether AI vendors can be held directly liable alongside employers, and a real split between federal enforcement, which has pulled back from disparate-impact theories, and state law, which is moving in the opposite direction.

What Is AI-Assisted Layoff Decision-Making

AI-assisted layoff decision-making refers to any process where software, ranging from a simple scoring spreadsheet formula to a full machine learning model, helps a company decide who to let go during a reduction in force (RIF), restructuring, or reorganization. The AI's role can range from purely informational (surfacing performance data for a human to review) to heavily determinative (auto-ranking employees and generating a termination list that a manager approves with minimal scrutiny). The legal risk generally rises as the AI's role moves from "informing" toward "deciding."

It is important to separate two related but distinct categories: AI-assisted decisions, where a human retains genuine discretion and the final call, and automated decisions, where the outcome is generated with no meaningful human involvement. Regulators in the EU and increasingly in US states treat these categories very differently, with automated decisions triggering stricter obligations.

This distinction is not just academic. Under GDPR Article 22, whether a decision is "solely automated" determines whether an employee has an outright right to object, versus a narrower set of transparency and fairness expectations that apply to human-assisted decisions. Under NYC Local Law 144, whether a tool is a covered "automated employment decision tool" turns partly on how substantially it factors into the ultimate decision relative to other factors a human considers. In other words, the label a company gives its own process, "AI-assisted" versus "automated", carries real legal weight, and companies should be able to back up that label with an honest description of how the tool actually functions in practice, not just how it was marketed by the vendor that built it.

How Companies Might Use AI During Restructuring

In practice, companies typically use AI-driven tools in restructuring for tasks such as ranking employees by performance-review scores, flagging redundant roles based on organizational-chart analysis, predicting which departments are most affected by cost-cutting targets, and modeling severance and cost scenarios. Some HR platforms also use natural-language tools to summarize performance history or generate draft severance communications.

A few common patterns show up repeatedly in enterprise deployments. Workforce-analytics platforms score employees on a composite "value" or "criticality" metric built from performance ratings, project involvement, and manager sentiment, then rank the entire org chart against that score before a restructuring decision is finalized. Skills-mapping tools compare each employee's documented skill set against a forward-looking business plan, flagging people whose skills the company says it will need less of going forward. Attrition-prediction models, originally built to flag flight-risk employees a company wants to retain, are sometimes repurposed in reverse, to identify employees least likely to leave voluntarily and therefore "safe" to target for involuntary separation. Chatbot and generative-AI tools increasingly draft the communications, severance letters, FAQs for affected employees, and internal talking points for managers, once the underlying decision has been made.

None of these uses are inherently unlawful. The legal exposure comes from what data feeds the model, how much weight the output carries in the final decision, and whether the process produces a measurably worse outcome for people in a protected group. A useful mental model is a spectrum: at one end sits a dashboard that simply displays performance data for a human decision-maker to interpret; at the other end sits a fully automated ranking that a manager approves without any real ability to change it. Most real deployments sit somewhere in between, and the exact position on that spectrum is often the single most important fact in any subsequent legal dispute.

Can an Algorithm Legally Recommend Who Gets Laid Off

Yes, an algorithm can legally recommend layoff candidates in virtually every jurisdiction discussed in this guide. What the law regulates is not the existence of the recommendation but its effect and the process around it. A recommendation engine that consistently under-ranks employees over 50, or employees who recently took disability leave, creates legal exposure regardless of whether a human technically clicked "approve" on the final list.

Algorithmic Discrimination

Algorithmic discrimination is discrimination that flows from an automated system's design, training data, or weighting rather than from an individual manager's explicit intent. It can take the form of disparate treatment, where the system is deliberately configured to disadvantage a protected group, or far more commonly, disparate impact, where a facially neutral scoring method produces a statistically skewed outcome. US employment law recognizes both theories, though as covered later in this guide, the federal government's enthusiasm for pursuing disparate-impact claims has shifted meaningfully since early 2025.

Disparate treatment in an AI context usually looks like the iTutorGroup case discussed later: a rule, explicit or effectively hard-coded, that treats a protected characteristic as a disqualifying or penalizing factor. This is the easier case to prove, because the discriminatory logic is often discoverable in the system's configuration or code. Disparate impact is harder to spot and, in practice, far more common in modern AI-driven HR tools, because the discriminatory pattern only becomes visible in the aggregate statistics, not in any single decision. A manager reviewing one employee's file will rarely see anything alarming; it's only when you compare selection rates across hundreds or thousands of employees that the pattern surfaces.

There's also a third, less discussed category relevant to layoffs specifically: disparate impact compounding over time. Because layoff models are often trained on, or benchmarked against, prior rounds of performance and workforce data, a bias introduced in one restructuring cycle can get baked into the training data for the next one, quietly amplifying with each iteration unless someone actively audits for it. This is one reason regulators increasingly ask not just "was this round's outcome fair" but "how does this tool's output compare across the last several cycles."

Example: How a "Neutral" Algorithm Can Create Risk

Imagine a company builds a layoff-scoring model that weighs three inputs: tenure, most recent performance rating, and "flexibility," defined as willingness to relocate or work non-standard hours. None of these inputs mention age, disability, or caregiving status. But tenure correlates with age; performance ratings, if historically shaped by biased managers, can embed racial or gender patterns; and "flexibility" scores often disadvantage employees with disabilities or caregiving responsibilities who cannot relocate on short notice. Run at scale, this facially neutral model can produce a layoff list where older employees, employees with disabilities, and working parents are terminated at meaningfully higher rates than their representation in the workforce, which is the textbook definition of a disparate-impact problem.

Neutral-looking inputs
→
Model scores every employee
→
Statistically skewed output
→
Potential disparate-impact liability

Employment Discrimination Laws

Several long-standing US federal statutes apply fully to AI-assisted decisions even though none of them mention AI: Title VII of the Civil Rights Act of 1964 (race, color, religion, sex, national origin), the Age Discrimination in Employment Act (age 40+), the Americans with Disabilities Act, and the Equal Pay Act. Courts and agencies have consistently treated "we used a vendor's algorithm" as no defense to liability under these statutes; the tool is simply the mechanism, not a separate legal actor exempt from the underlying law.

AI and the EU AI Act

The EU AI Act classifies AI systems used in recruitment, promotion, termination, and task allocation as high-risk. Deployers of high-risk employment AI must complete a conformity assessment, maintain technical documentation and logs, ensure human oversight capable of overriding or disregarding the system's output, inform affected workers before the system is used, and register the system where required. Non-compliance carries substantial penalties tied to global annual turnover, among the highest of any employment-related AI regime in the world.

Practically, this means a European subsidiary of an Indian or US-headquartered company cannot simply import a layoff-scoring tool built and validated for a different market and deploy it in the EU without redoing the compliance work locally. The Act expects the risk-management system to be tailored to the specific deployment context, including the workforce it will actually be used on, not just the vendor's general-purpose validation. Employers should also expect layered obligations: the AI Act governs the tool itself, while GDPR separately governs the personal data the tool processes, so compliance with one does not automatically satisfy the other.

AI and GDPR

Under Article 22 of the GDPR, EU-based employees generally have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them, and termination clearly qualifies. Employers relying on one of GDPR's narrow exceptions (contractual necessity, explicit consent, or authorization under member state law) must still implement safeguards: the right to obtain human intervention, the right to express a point of view, and the right to contest the decision. GDPR's broader transparency principles also require employers to be able to explain, at a meaningful level, the logic behind an automated or AI-assisted employment decision if an employee requests it.

Two practical traps come up often. First, "solely automated" is interpreted functionally, not formally: if a human reviewer exists on paper but doesn't meaningfully engage with the case, regulators can still treat the decision as solely automated for Article 22 purposes. Second, explicit consent is a weak legal basis for an employment decision specifically because of the power imbalance between employer and employee; most data protection authorities view employee consent in this context skeptically, which pushes most employers toward the contractual-necessity or member-state-law exceptions instead, each of which carries its own safeguard requirements.

United States: EEOC and Algorithmic Decision-Making

The Equal Employment Opportunity Commission's position, articulated in technical guidance issued in 2023, is that Title VII, the ADEA, and the ADA apply fully to algorithmic hiring and employment tools, and that using a third-party vendor's software does not shift liability away from the employer. The agency's 2024–2028 Strategic Enforcement Plan explicitly named "algorithmic fairness" as a priority area, and the four-fifths rule, comparing the selection rate for a protected group against the highest-selected group, remains the standard first-pass test for disparate impact in AI-driven selection tools.

That said, the federal enforcement picture has shifted meaningfully since this framework was adopted. In April 2025, an executive order directed federal agencies to deprioritize enforcement built on disparate-impact theories "to the maximum degree possible." Under EEOC Chair Andrea Lucas, the agency's practical enforcement posture through mid-2026 has moved away from aggressive pursuit of disparate-impact-based algorithmic-fairness cases, even though the Strategic Enforcement Plan technically remains on the books. The iTutorGroup settlement described later in this guide remains the agency's marquee AI enforcement result to date, but it predates this policy shift. The practical effect for employers in 2026 is that meaningful legal pressure over AI-driven employment decisions increasingly comes from state regulators and private class-action litigation rather than from active federal disparate-impact enforcement.

State and Local AI Employment Laws

With the federal government's disparate-impact enforcement pulled back, state and local law has become the primary source of AI-specific obligations for US employers.

California: FEHA Automated-Decision-System Regulations

California's Civil Rights Council regulations bringing automated decision systems under the Fair Employment and Housing Act took effect October 1, 2025. They define an ADS broadly, require employers to retain ADS-related records for at least four years, make anti-bias testing (or its absence) explicitly relevant in litigation, and require reasonable accommodation where an ADS evaluates attributes like reaction time or vocal tone that can disadvantage employees with disabilities.

Colorado: AI Act, Substantially Narrowed and Delayed

Colorado's original AI Act (SB 24-205), passed in 2024, was meant to be the country's first comprehensive risk-based AI employment law, requiring annual algorithmic impact assessments and formal risk-management programs. Its effective date has been repeatedly pushed back, from February 2026 to June 30, 2026, and a federal magistrate judge stayed enforcement in April 2026. In May 2026, Colorado enacted SB 189, which replaces most of the original risk-based framework with a narrower transparency-and-disclosure regime and delays the new effective date to January 1, 2027. The revised law drops the duty of care aimed at preventing algorithmic discrimination and the mandatory impact-assessment and risk-management obligations, focusing instead on developer-to-deployer disclosures and a right to meaningful human review of adverse automated decisions. Employers should treat Colorado's regime as still in flux rather than settled.

Illinois: Human Rights Act Amendments

Amendments to the Illinois Human Rights Act (Public Act 103-0804, originating from HB 3773) took effect January 1, 2026. They make it a civil rights violation to use AI, including generative AI, that has the effect of subjecting employees to discrimination, explicitly prohibit using zip codes as a proxy for protected classes, and require notice to employees and applicants when AI is used in covered employment decisions. As of mid-2026, the Illinois Department of Human Rights had proposed implementing rules but temporarily paused that rulemaking process to coordinate with other state agencies, so some notice-requirement specifics are still being finalized.

New York City: Local Law 144

NYC Local Law 144, in effect since 2023, requires covered employers using an "automated employment decision tool" for hiring or promotion within New York City to obtain an independent annual bias audit, publish a summary of the results, and provide advance notice to candidates and employees. It remains one of the more established AI employment laws and a useful benchmark for the audit-and-disclosure model other jurisdictions are now adopting.

JurisdictionStatus as of August 2026Core Requirement
California (FEHA ADS Regs)In effect since Oct 1, 2025Bias testing relevance, 4-year recordkeeping, reasonable accommodation
Colorado (AI Act / SB 189)Delayed to Jan 1, 2027; substantially narrowedDeveloper disclosures, human-review right (impact assessments removed)
Illinois (IHRA amendments)In effect since Jan 1, 2026; rules pendingAnti-discrimination, zip code proxy ban, employee notice
New York City (Local Law 144)In effect since 2023Independent annual bias audit, public summary, candidate notice

Human Oversight

"Human in the loop" is only meaningful if the human has the authority, information, and time to actually change the outcome. Regulators and plaintiffs' attorneys increasingly probe whether a reviewer had access to the underlying data the model used, understood how the score was generated, and had a realistic opportunity to override it, versus simply approving a pre-generated list under time pressure. Superficial "rubber-stamp" review is treated, functionally, as no review at all.

In discovery, this often comes down to a handful of concrete questions a company should be able to answer well before litigation forces the issue: How much time, on average, did a reviewer spend per employee record before approving the recommendation? What percentage of AI-generated recommendations were ever overridden, and for what reasons? Did the reviewer have visibility into the underlying score components, or only a final ranked list with no explanation? A pattern of near-100% approval rates, with little documented reasoning for the rare override, tends to look, to a court, a lot like automation dressed up as human decision-making.

What Data Should Companies Avoid

  • Direct protected-class data (race, age, disability status, pregnancy, religion) as a model input
  • Leave history that reveals medical, disability, or family-care status
  • Immigration or visa status, where not legally required for the decision at hand
  • Union activity or protected concerted activity indicators
  • Salary history in jurisdictions that restrict its use in employment decisions

Data That May Create Hidden Bias

Even without direct protected-class data, several common inputs act as strong proxies and deserve extra scrutiny: zip code (correlates with race and national origin), college attended (correlates with socioeconomic status and, in some contexts, race), gaps in employment history (can correlate with disability, caregiving, or pregnancy), commute distance or relocation willingness (can correlate with disability and caregiving status), and historical performance ratings, if those ratings were themselves shaped by biased managers over time.

How to Audit an AI Layoff System

  • Run the four-fifths rule across every protected class for each round of the selection process
  • Test outcomes across intersectional groups, not just single categories, since impact can hide within intersections
  • Trace every input feature back to whether it is, or could function as, a protected-class proxy
  • Review whether human reviewers actually changed any AI-generated recommendations, and how often
  • Document the audit methodology, results, and any remediation taken
  • Repeat the audit before each major layoff round, not just annually

Who should run the audit matters almost as much as what the audit covers. NYC Local Law 144 requires the bias audit for covered tools to be conducted by an independent auditor, someone who was not involved in developing or deploying the tool. Even where independence isn't a hard legal requirement, as in most internal layoff-decision tools today, building that separation between the team that built the model and the team that audits it produces more credible, defensible results, and avoids the obvious conflict of interest in letting a tool's own developers certify its fairness.

Algorithmic Impact Assessment

An algorithmic impact assessment is a structured, documented evaluation completed before deploying an AI tool for a consequential decision. A solid assessment covers the system's intended purpose and scope, the data used to train and run it, known limitations and error rates, foreseeable discriminatory risks, the mitigation steps taken, and the human-oversight mechanism in place. Even in jurisdictions like Colorado where the formal legal mandate for impact assessments has been narrowed or delayed, completing one remains a strong practical defense in the event of a discrimination claim, since it demonstrates proactive good-faith effort.

A useful way to think about the assessment is as three linked questions, answered in writing, before deployment: what could this system get wrong, who would it get wrong for, and what happens when it does. The first question forces a technical review of error rates and edge cases. The second forces a demographic breakdown of who is most exposed to those errors, which is where proxy variables like zip code or employment gaps usually surface. The third forces the organization to define, before any harm occurs, what the appeal and correction process looks like. Assessments completed only after a tool is already in production, or worse, only after a complaint has been filed, carry far less legal and practical weight than ones completed up front.

What Employees Should Ask

  • Was AI or an automated tool used in this decision, and to what extent?
  • What data was considered, and can I see it?
  • Did a human review the recommendation, and did they have the authority to change it?
  • Was any bias audit or impact assessment conducted, and can a summary be shared?
  • What is the process to appeal or contest the decision?

What HR Teams Should Do Before Using AI

  • Inventory every AI or automated tool touching hiring, performance, or termination decisions
  • Confirm applicable jurisdiction-specific obligations for every location where affected employees are based
  • Complete and document a pre-deployment impact assessment
  • Define and train reviewers on what meaningful human oversight requires
  • Build an employee notice and appeal process before, not after, deployment

AI Vendor Due Diligence

Before adopting a third-party AI tool for workforce decisions, ask the vendor for their most recent independent bias audit results, a clear description of training data sources, documentation of known limitations, and contractual commitments on liability allocation if the tool produces a discriminatory outcome. Given the vendor-liability theory now advancing in Mobley v. Workday, contract terms addressing indemnification and audit cooperation are becoming standard asks in enterprise HR-tech procurement.

Beyond the contract, due diligence should include a hands-on technical review, not just a questionnaire the vendor's sales team fills out. Ask to see the model's performance broken out by demographic group on a representative sample of your own employee population, not just the vendor's generic validation set, since a tool that tests fair on one company's workforce composition can behave very differently on another's. Ask how often the model is retrained, and what process exists to catch a newly introduced bias after a retraining event. And ask what happens contractually if the tool is later found, through litigation or regulatory action, to have produced a discriminatory outcome, specifically who bears the cost of remediation, notice to affected employees, and any resulting settlement or judgment.

Security and Privacy

Layoff-decision data is unusually sensitive: it often combines performance history, compensation, health-related leave records, and demographic data in one place. Companies should apply strict access controls, encrypt data at rest and in transit, and limit retention to what is legally required, since over-retained sensitive HR data is both a security liability and, in GDPR-covered operations, a separate compliance exposure.

Access control deserves particular attention during an active restructuring, when a wider-than-usual group of managers, HR business partners, and outside consultants may need temporary access to sensitive scoring data. Time-limited access grants, full audit logging of who viewed which employee's scores, and a clear data-destruction timeline once the restructuring concludes all reduce both the security surface area and the discoverable footprint if a claim is later filed. Companies that skip this discipline often find, during subsequent litigation discovery, that far more people had access to sensitive scoring data than the process ever intended, which complicates the defense regardless of whether the underlying decision was actually fair.

Can Employees Challenge an AI-Assisted Layoff

Yes. Employees can generally challenge an AI-assisted layoff through the same channels available for any discrimination claim: an internal HR appeal, a charge filed with the EEOC or a state civil rights agency, or private litigation under applicable federal, state, or local law. In the EU, GDPR provides additional avenues, including the right to contest automated decisions and to file complaints with a national data protection authority.

Who Is Responsible

Historically, liability for an employment decision rested squarely with the employer. That assumption is being actively tested. Mobley v. Workday advances the theory that an AI vendor providing applicant- and employee-screening tools can itself be treated as an agent of the employer, and therefore directly liable under federal anti-discrimination statutes, not merely a neutral software provider immune from employment law. As of mid-2026, the presiding court has allowed key claims against the vendor to move past multiple rounds of dismissal motions, a development that, if it holds, would meaningfully reshape how liability is allocated between employers and the AI vendors they rely on.

Commentators have described the emerging pattern as a "pincer movement" around AI hiring and workforce vendors: plaintiffs are pursuing the vendor directly, on an agency theory, at the same time state laws like California's FEHA regulations create recordkeeping and litigation-relevance obligations that make it harder for either the employer or the vendor to claim ignorance of a tool's discriminatory pattern. For an employer, the practical takeaway is that "we outsourced the decision to a vendor" is not a reliable liability shield, and may not even reduce the employer's own exposure, since the employer typically remains the direct employer-of-record regardless of what liability theory eventually prevails against the vendor. For a vendor, the takeaway is that building bias-testing and audit cooperation into the product itself, rather than treating it as a legal afterthought, is becoming a competitive and legal necessity rather than a nice-to-have.

Comparison Table: US vs EU vs UK Approach

For a company operating across these three regions, the practical shape of the compliance obligation looks quite different depending on where an affected employee sits, even when the underlying AI tool is identical. The table below is a high-level orientation, not a substitute for jurisdiction-specific legal advice.

DimensionUnited StatesEuropean UnionUnited Kingdom
Core legal basisTitle VII, ADEA, ADA + a growing state-law patchworkGDPR Article 22 + EU AI Act high-risk rulesUK GDPR + Equality Act 2010
Federal/national enforcement postureEEOC guidance still applies, but disparate-impact enforcement was deprioritized federally in 2025Centralized, high-risk classification with binding technical requirementsSector guidance-driven, less prescriptive than the EU AI Act
Where most pressure comes fromState laws (CA, IL, NYC) and private litigationRegulator enforcement and data-protection authoritiesEmployment tribunals and ICO guidance
Human oversight requirementVaries by state; increasingly expectedMandatory for high-risk systems and Article 22 decisionsExpected under UK GDPR safeguards

Hypothetical Corporate Case Study

Consider a mid-sized software company running a 12% workforce reduction. HR builds a scoring model weighting recent performance ratings, tenure, and role redundancy. An internal audit, run before finalizing the list, finds that employees over 50 are selected for layoff at nearly double the rate of employees under 40, even though none of the model's inputs directly reference age. Digging in, the team finds that "tenure" was functioning as a strong age proxy, and that historical performance ratings for the over-50 cohort were themselves lower on average due to a prior manager's now-departed bias. The company reweights the model, removes raw tenure as an input in favor of role-specific skill assessments, documents the change as part of its impact assessment, and reruns the analysis, closing most of the gap before finalizing the list. This is the kind of proactive audit-and-remediate cycle that regulators in California and the EU explicitly expect to see documented.

Notice what made the difference in this hypothetical: the audit happened before the list was finalized and communicated, not after an affected employee complained. The company also kept a written record of what it found, what it changed, and why, which is precisely the kind of documentation that turns "we tried to be fair" from an unverifiable claim into a defensible fact pattern if a claim is later filed. Companies that skip this step, and only discover the age-proxy problem after a lawsuit is filed, are in a fundamentally weaker legal position even if their underlying intentions were identical.

AI Governance Framework

  • Cross-functional oversight: legal, HR, and data science jointly own AI-employment-tool decisions
  • Pre-deployment impact assessments for every tool touching hiring, performance, or termination
  • Documented, meaningful human-review checkpoints at each decision stage
  • Recurring bias audits, at minimum before each major workforce action
  • A clear employee notice and appeal pathway
  • Vendor contracts addressing audit cooperation, data provenance, and liability allocation

Future of AI in Corporate Workforce Decisions

Expect continued divergence rather than convergence: US federal enforcement is likely to remain comparatively restrained on disparate-impact theories in the near term, while individual states keep legislating in the opposite direction, and private litigation, led by cases like Mobley, increasingly fills the enforcement gap federal agencies have stepped back from. In the EU, the AI Act's high-risk employment obligations will continue to phase in, raising the compliance bar for any company operating in the bloc. The net effect for multinational employers is a widening compliance gap between jurisdictions, making a "comply with the strictest applicable rule everywhere" approach increasingly the pragmatic default.

Three developments are worth watching over the next 12 to 18 months. First, whether Colorado's narrowed SB 189 framework survives its own legislative session intact before its January 1, 2027 effective date, given how many times the state's AI law has already been rewritten. Second, how the Mobley class-certification and vendor-liability questions ultimately resolve, since a final ruling favoring vendor liability would likely trigger a wave of similar claims against other major HR-tech providers. Third, whether Illinois's paused rulemaking on notice requirements resumes with a stricter or more lenient standard than the draft rules initially proposed. Employers building AI governance programs today should design them to be adaptable to any of these outcomes rather than betting heavily on the current state of any single jurisdiction's law.

Common Mistakes

  • Treating "the vendor's AI decided" as a legal shield, when the underlying discrimination law still applies
  • Allowing human review to become a rubber stamp with no real authority to override the model
  • Skipping documentation of impact assessments and audits, leaving no defensible paper trail
  • Assuming a law that hasn't taken effect yet, like Colorado's original AI Act framework, is still the operative standard
  • Failing to test for intersectional disparate impact, not just single-category gaps
  • Assuming a reduced federal enforcement posture means reduced legal risk overall, when state laws and private litigation have simply become the dominant source of exposure
  • Reusing a layoff-scoring model across multiple restructuring rounds without re-auditing, letting bias compound cycle over cycle
  • Granting broad, unlogged access to sensitive scoring data to an expanded group of managers and consultants during a restructuring

Expert Tips

  • Audit before you need to defend, not after a claim is filed
  • Build the employee notice and appeal process into the tool's rollout, not as an afterthought
  • Track every jurisdiction where affected employees are based, since AI employment law is now genuinely local
  • Revisit vendor contracts now, given the direction Mobley v. Workday is pushing vendor liability
  • Treat every impact assessment as a living document, updated whenever the model, its training data, or its weighting changes
  • When in doubt about which jurisdiction's rule applies to a distributed workforce, default to the strictest applicable standard rather than the most convenient one
  • Keep legal, HR, and the data science team in the same room from the start of a tool's design, not just at the compliance sign-off stage

Real-World Case Studies

Resolved

EEOC v. iTutorGroup, Inc.

Jurisdiction
U.S. federal (EEOC, Eastern District of New York)
What happened
The EEOC alleged that iTutorGroup's AI-driven hiring software was programmed to automatically reject female applicants aged 55 and older, and male applicants aged 60 and older.
Legal theory
Age discrimination under the ADEA, applied to an automated screening tool
Outcome
A consent decree was approved on September 8, 2023, with $365,000 paid to the rejected applicant class. It stands as the EEOC's first AI-related employment discrimination settlement.
Lesson for employers
Automated screening criteria can trigger straightforward age-discrimination liability just as easily as a human recruiter's stated preference, and the "it was the software" defense carries no legal weight.
Active / Pending

Mobley v. Workday, Inc.

Jurisdiction
U.S. federal (N.D. California, Case No. 3:23-cv-00770-RFL)
What happened
Filed February 21, 2023, the case alleges that Workday's AI-powered applicant-screening tools discriminated based on race, age, and disability against job applicants, on behalf of a putative nationwide class.
Legal theory
Disparate impact under Title VII, the ADEA, and the ADA, notably targeting the AI vendor directly rather than only the employers who used its software
Status as of August 2026
Active and closely watched. A June 22, 2026 order largely denied Workday's motion to dismiss the plaintiffs' amended complaint, including allowing California FEHA claims to proceed. The case has moved through multiple rounds of dismissal motions and discovery disputes over AI bias testing; class certification proceedings are ongoing. This status should be re-verified before relying on it, since the case is actively developing.
Lesson for employers
The theory that an AI vendor can be treated as directly liable, not just the employer using its tool, has survived early dismissal attempts. Employers relying on third-party hiring or workforce AI should not assume vendor liability insulates them, and vendors should not assume their role is legally neutral.
Active / Pending

ACLU of Colorado v. Intuit / HireVue

Jurisdiction
Colorado Civil Rights Division and EEOC (administrative complaint)
What happened
Filed March 19, 2025, the complaint alleges that Intuit's use of HireVue's AI video-interview platform disadvantaged a deaf, Indigenous employee during a promotion process, including a denied captioning accommodation request and AI-generated feedback criticized as tone-deaf to her disability.
Legal theory
Disability and race discrimination under the ADA, Title VII, and the Colorado Anti-Discrimination Act
Status as of August 2026
Filed as an administrative complaint, not yet adjudicated as of available reporting. HireVue has publicly disputed that its AI-based assessment was actually used in this instance. Current status should be verified before publishing or citing further.
Lesson for employers
Speech- and video-based AI assessment tools carry documented, measurable accuracy gaps for deaf and accented speakers, and denying a reasonable accommodation request compounds that risk into a standalone legal claim.

Frequently Asked Questions

Can employers legally use AI to decide layoffs?

Yes, in most jurisdictions employers can use AI tools to inform layoff decisions, but the employer, and increasingly the AI vendor, remains legally responsible if the tool produces a discriminatory outcome. No major jurisdiction bans AI-assisted layoffs outright; instead, laws regulate how the tool is used, what data it relies on, whether a human reviews the output, and what disclosures are made.

Is AI-assisted termination legal?

AI-assisted termination is legal when it complies with existing anti-discrimination law and any applicable AI-specific statutes. Legality doesn't turn on whether AI was involved, but on whether the outcome treats employees differently based on a protected characteristic, whether human oversight was meaningful, and whether required notices and assessments were completed.

Does human review eliminate AI-related legal liability?

No. Human review reduces risk but doesn't eliminate it. Regulators increasingly scrutinize whether the reviewer had real authority and information to override the algorithm, a superficial approval is treated as no real review at all.

What is algorithmic discrimination?

Discrimination that flows from an automated system's design, training data, or weighting, whether or not it was intentional, assessed under the same disparate-treatment and disparate-impact frameworks courts already use.

What is proxy discrimination?

When a seemingly neutral input, like zip code or an employment gap, correlates strongly with a protected characteristic and reproduces discriminatory outcomes even without directly referencing the protected trait. Illinois's amended Human Rights Act explicitly bans zip codes as an employment-AI proxy.

What does the EEOC say about AI in employment?

EEOC guidance holds that Title VII, the ADEA, and the ADA apply fully to algorithmic employment tools. However, a 2025 executive order directed federal agencies to deprioritize disparate-impact enforcement, so much of the real 2026 enforcement pressure now comes from state law and private litigation rather than active federal cases.

Does GDPR restrict automated employment decisions?

Yes. GDPR Article 22 gives EU employees the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects, which covers termination, and requires safeguards like human intervention and the right to contest the decision.

What does the EU AI Act say about employment-related AI?

It classifies recruitment, promotion, termination, and task-allocation AI as high-risk, requiring risk management, documentation, human oversight, transparency to workers, and registration before deployment.

Can employees find out if AI was used in their layoff?

Increasingly yes: NYC Local Law 144, Illinois's amended Human Rights Act, and California's FEHA regulations all create notice or discovery obligations, and GDPR's transparency rights let EU employees request an explanation.

Can an AI vendor be held legally responsible?

It's actively being tested in court. Mobley v. Workday advances the theory that an AI vendor can be treated as an employer's agent and directly liable; as of mid-2026 key claims against the vendor have survived multiple dismissal motions, though the case is not finally resolved.

What is the four-fifths rule?

A longstanding EEOC guideline: if a protected group's selection rate is less than 80% of the rate for the highest-selected group, that gap is generally treated as evidence of potential disparate impact requiring further justification.

Do state AI employment laws override federal law?

No, they add obligations on top of federal law. Employers with staff across multiple states generally need to meet the strictest applicable state or local requirement for each affected employee.

For related reading on securing the AI systems and identity infrastructure behind these HR platforms, see this practical guide to Zero Trust identity security. If your team is building resilience practices around AI-driven enterprise tools, this cyber resilience skills guide for security engineers is a useful companion piece. Legal and compliance content like this also needs to be discoverable, our multichannel framework for ranking beyond Google covers that in depth. For the structured-data patterns used to mark up this article's schema, see the complete Entity SEO and Advanced Schema Markup guide. And if you want this kind of long-form legal analysis to surface in AI answer engines, not just search, this GEO and AI citations playbook walks through the tactics.

⚠️ Legal Disclaimer (Conclusion)

Nothing in this article constitutes legal advice. AI employment law is changing quickly, Colorado's framework alone has shifted three times in under two years, and the status of active litigation like Mobley v. Workday and the ACLU's complaint against Intuit and HireVue can change at any time. Verify current status before relying on any case or statute described here, and consult a licensed employment attorney for guidance specific to your company and jurisdiction.

Share this article:
TechWithSanjay Digital Products

Explore AI prompt packs, ebooks, templates, and developer resources crafted to accelerate your tech journey.

Browse the Shop →

Written by

TechWithSanjay

Practical AI, technology, programming and cybersecurity guides for students, developers and tech enthusiasts.

About TechWithSanjay →

Go deeper with TechWithSanjay

Explore practical AI resources, digital products and developer guides.

Explore the Shop →

Comments (0)