AI Governance in HR: Why Employers Are Liable for AI Decisions — And What the Workday Lawsuit Teaches Executives
AI has officially crossed the threshold from “interesting HR tech” to regulated employer liability. It is now embedded in hiring platforms, HRIS systems, screening tools, performance management software, and even everyday productivity tools like Copilot and Gemini. And while vendors market these tools as “intelligent,” “bias‑reducing,” or “automated,” the legal reality is simple: Employers — not vendors — are liable for every AI‑influenced HR decision.
The Workday lawsuit made this point unmistakably clear — and it should be a wake‑up call for every employer using AI in hiring, screening, or performance management.
The Workday Lawsuit: A Case Study in AI‑Driven Discrimination Exposure
In the Workday case, plaintiffs alleged that Workday’s AI‑driven screening tools disproportionately rejected applicants based on protected characteristics — including race, age, and disability. The lawsuit didn’t just target Workday. It targeted employers using Workday’s tools, because the law treats AI as an extension of the employer’s decision‑making.
This is the critical takeaway: AI does not shield employers from discrimination claims. It increases exposure.
Courts and regulators do not care whether the bias originated in the algorithm, the dataset, or the vendor’s design. If your organization uses the tool, you own the outcome.
This is exactly where HR compliance breaks down — because most HR teams are not trained to evaluate algorithmic risk, audit AI systems, or interpret EEOC guidance on automated decision‑making.
Protect Your Company From AI‑Driven Liability — Contact us today to book a CHRO governance review.
AI Governance Is Now a Core HR Compliance Requirement — And Regulators Are Explicitly Targeting Employer Use of AI
AI governance is no longer optional. It is now a regulated HR compliance obligation, and regulators have made this point unmistakably clear. Employers cannot rely on vendor assurances, marketing language, or “AI expertise” to protect them. The legal system has already shifted, and HR leaders must shift with it.
EEOC Guidance: Employers Are Liable for Algorithmic Bias — Not Vendors
The EEOC has issued formal guidance stating that employers are responsible for ensuring that any algorithm, screening tool, or automated decision‑making system does not create disparate impact. The agency has been explicit: “The vendor told us it was compliant” is not a defense. Employers must demonstrate how the tool was evaluated, monitored, and overridden when necessary. If an algorithm screens out candidates in a way that harms a protected class, the employer is treated as though a human made that decision. This is the legal foundation behind the Workday lawsuit — and it is only the beginning. See this publication on the EEOC’s role in monitoring Employer AI use.
State Automated Decision‑Making Laws: Bias Audits, Transparency Notices, and Human Review Requirements
States and cities have moved even faster than federal regulators. Automated decision‑making laws in New York City, California, Colorado, and Illinois now require:
annual bias audits,
public disclosure of audit results,
transparency notices to applicants,
human‑review safeguards for AI‑enabled hiring tools.
NYC’s AEDT law requires employers to conduct annual bias audits and publish the results. California and Colorado are implementing similar frameworks. These laws apply to employers, not vendors — and they apply even when employers do not realize AI is embedded in their HR systems.
Multi‑State Compliance: AI Rules Now Mirror Wage‑and‑Hour and Leave Law Complexity
Because employees are distributed across states, employers must manage overlapping and sometimes contradictory AI rules. A workflow that is legal in one state may violate automated decision‑making laws in another. This mirrors the complexity of wage‑and‑hour rules, leave laws, and harassment prevention — but with far higher litigation exposure because AI decisions are often undocumented, unreviewed, and misunderstood. The first challenge many employers face is determining which jurisdictions are applicable to their workflows. Employers operating with remote employees (even intermittently remote), regional sales teams, remote contractors, or using cloud-based AI systems, should confer with their legal counsel to determine all applicable jurisdictions prior to constructing AI workflows or policies.
AI governance must be built into your HR infrastructure. It cannot be bolted on as a generic policy and an afterthought.
Poor AI Governance is simply one area of employer risk. Visit CHRO’s Compliance Corner to see real summaries of recently filed lawsuits against employers.
Courts Treat AI Decisions as Employer Decisions — No Exceptions
Courts have already made the legal position clear: AI is not a separate actor. If an algorithm screens out candidates, misinterprets medical documentation, or generates biased performance summaries, the employer is treated as though a human made that decision. In litigation, “the system did it” is viewed the same as “HR did it.”
This is why the Workday lawsuit resonated so strongly. It demonstrated that employers cannot outsource judgment to AI and then claim neutrality. AI is treated as an extension of the employer’s judgment — and the employer owns the consequences.
Does your HR team have the experience to lead your AI governance effort? If not, contact CHRO to book a discovery call.
Why AI‑Driven Discrimination Claims Blindside Employers: HR Focuses on Intent, But the Law Doesn’t
Most HR teams are trained to look for intentional discrimination — the manager who treats someone differently, the inappropriate comment, the inconsistent discipline. What they rarely think about is disparate impact, where a facially neutral practice disproportionately harms a protected group even when no one intended it.
AI systems are almost always disparate impact cases, not disparate treatment cases, because algorithms apply the same rules to everyone and still produce statistically discriminatory outcomes. This is exactly why AI‑driven claims blindside employers: they don’t start as single‑plaintiff disputes. They start as systemic harm, which is the legal foundation for class actions.
And here’s the part executives never see coming — when a class action is treated as a single “claim” under an EPLI policy, it is often subject to single‑claim limits, not aggregate limits. That means a class of hundreds or thousands of rejected applicants may be covered under the same limit as one individual complaint. If the class is large enough, the employer is exposed to massive uninsured financial loss, even if they believed they had “good coverage.” AI‑driven disparate impact claims are not just compliance failures; they are insurance‑structure failures that can financially devastate an organization.
See this article on The Legal Risks AI Can’t Manage for Most HR Teams.
AI Use You Don’t See Is the AI That Hurts You
Executives often assume “AI” refers only to the ATS or screening tool. In reality, AI is now:
embedded in HRIS, ATS, and performance systems,
integrated into productivity tools like Copilot and Gemini,
used informally by HR staff to draft emails, performance reviews, documentation, and investigation summaries.
This matters because: Even integrated AI — Copilot, Gemini, and similar tools — can be used in ways that produce discriminatory outcomes.
If HR staff are:
asking AI to “summarize performance concerns,”
using AI to “draft a termination memo,”
relying on AI to “flag problematic employees,”
feeding AI incomplete or biased inputs,
asking AI to respond to employee questions and concerns
then the output reflects their bias, and the employer owns the result.
You cannot govern AI if you don’t know:
which tools HR is using,
what prompts they’re using,
what decisions those outputs influence.
AI governance starts with visibility. Visibility starts with senior HR personnel or leadership exploring HR and management’s full use of AI tools. Next leadership needs to explore the complete scope of risk through use of the current use model. Finally, leadership needs to craft a comprehensive AI-use policy and accompanying workflows to ensure employees limit their AI use to sanctioned methods and tools. Periodically, employers need to revisit this policy to ensure it’s still current and applicable. If you don’t have faith in your current HR leadership and managers to lead this effort, contact CHRO for assistance.
The Hidden Risk: Employees Becoming Lazy with AI
AI misuse isn’t always malicious. Sometimes it’s laziness.
Employees — including HR — are increasingly:
letting AI draft emails they barely skim,
copying AI‑generated documentation without verifying accuracy,
using AI to “summarize” employee issues without context,
relying on AI to write performance reviews or disciplinary notes.
This is dangerous because:
AI outputs must be proofed with the same rigor as human work — or more.
Unproofed AI content misstates facts, exaggerates issues, omits critical context, introduces bias, creates inconsistent documentation, and undermines legal defensibility. AI is not a shortcut. It is a risk multiplier when used carelessly and an understaffed and overworked HR department is more likely to use AI carelessly, simply because of the time constraints under which they are operating. See this article on supporting your overworked HR Team.
The People Configuring AI Bring Their Bias With Them
AI systems do not configure themselves. Humans do.
If the people:
choosing the AI tools,
setting filters,
defining “qualified” vs “unqualified,”
building scoring models,
writing prompts and workflows
carry unexamined bias, they will encode that bias into the system.
One way to surface this is requiring key HR and tech staff responsible for AI configuration to complete implicit attitudes tests for unconscious bias. Not because the test is perfect, but because it forces self‑awareness and signals that AI configuration is a high‑risk, high‑responsibility function. These tests often give people an ahaa moment including highlighting same-sex or same-race biases. Unless you are aware of your biases, you cannot be proactive about managing them. Internal bias might be an uncomfortable discovery, but being named as the wrongdoer in a public lawsuit is much more uncomfortable, and that discomfort lasts for a much longer time.
Why Off‑the‑Shelf AI Policies Are Dangerous and Ineffective
Executives often ask: “Can’t we just download an AI policy template?” No — and here’s why.
Off‑the‑shelf policies do not match your actual tools, workflows, or risk profile. They do not address multi‑state automated decision‑making laws. They do not integrate with your HR infrastructure. They create a false sense of security because they exist on paper but do not govern actual behavior. They fail in litigation because they do not produce the documentation courts require. They assume HR has the expertise to manage AI. And they ignore contract restrictions — including client contracts and government contracts — that may explicitly limit or prohibit AI use.
If HR uses AI in ways that violate these contracts, the organization is exposed to breach‑of‑contract claims, regulatory penalties, loss of government funding, and termination of client relationships.
Templates never address this. In my experience, most off the shelf policies usually use a lot of words to say very little that is actually meaningful or usable. If you have a policy that is essentially useless, or that employees don’t understand, this can be more dangerous than having no policy at all.
The Most Dangerous Trend: Employers Supplementing HR Expertise with AI Expertise
A growing number of employers believe they can “close the HR expertise gap” by supplementing inexperienced HR teams with AI expertise — hiring data scientists, AI specialists, or tech‑forward staff who understand algorithms but have no grounding in HR compliance, employment law, or the realities of HR decision‑making.
On paper, it looks innovative. In practice, it is one of the most dangerous moves an employer can make.
AI expertise is not HR expertise. AI expertise is not legal expertise. AI expertise is not compliance expertise. AI is a valuable tool in an experienced HR professional’s hands. But AI leads to a false sense of security for inexperienced HR staff, and employers end up paying the price for this.
AI experts do not know what questions matter in an EEOC investigation, a termination meeting, a reasonable accommodation analysis, or a multi‑state compliance audit. They do not challenge AI when it gives misleading information because they do not know the HR or legal standards. They misconfigure systems because they lack HR context. They violate client and government contracts because they do not know to check them. And they cannot identify bias because they do not understand how bias manifests in HR decision‑making.
This is how employers end up in Workday‑style lawsuits — not because the AI is malicious, but because the humans configuring it lacked the HR and legal expertise to understand the implications of their decisions. AI is helpful but it is a poor substitute for experience. See this article on When HR Outsourcing Makes Sense for a Growing Business to identify when to get supplemental support for your HR team. Contact CHRO for a discovery call.
AI Governance Requires HR Expertise + Legal Expertise + Operational Expertise
AI governance is not a technical project. It is not an IT initiative. It is not a policy you download from the internet.
It is a cross‑functional compliance framework that requires:
HR expertise to understand workflows, decision‑points, documentation, ADA/FMLA/USERRA, discrimination law, and manager behavior.
Legal expertise to interpret EEOC guidance, state automated decision‑making laws, federal discrimination standards, contract restrictions, vendor liability disclaimers, and litigation exposure.
Operational expertise to ensure systems integrate correctly, workflows reflect reality, managers follow the process, documentation is consistent, audits are conducted, and risk is monitored.
Without that alignment, employers are supplementing HR expertise with AI expertise and believing they’ve solved the problem — when in reality, they’ve created a new one.
This is exactly where Outsourced CHRO support becomes essential: not to “manage AI,” but to ensure that AI is governed within a defensible HR compliance infrastructure that inexperienced HR teams and AI specialists simply cannot build on their own. Contact CHRO for a confidential consultation.
The Bottom Line on AI and HR
AI is not a shortcut. AI is not a compliance shield. AI is not a replacement for HR expertise. AI is a risk multiplier, and the Workday lawsuit is the warning shot every employer should pay attention to.
If your organization is using AI‑enabled HR tools without a governance framework, relying on off‑the‑shelf policies, supplementing HR expertise with AI expertise, ignoring contract restrictions, or allowing employees to use AI without proofing the output, you are already exposed.
AI governance requires:
experience,
legal alignment,
HR infrastructure,
multi‑state compliance expertise,
and executive‑level HR leadership.
This is exactly where Outsourced CHRO support becomes essential. Strengthen Your Managers and HR Team with Executive‑Level CHRO Support — Contact us today to book Your confidential consultation.
FAQ: AI Governance, Employer Liability, and HR Technology
1. Are employers really liable for AI‑driven HR decisions?
Yes. Even when AI tools are built and sold by vendors, employers remain fully responsible for any discriminatory, biased, or unlawful outcomes produced by those systems. The Workday lawsuit made this point unmistakably clear.
2. What did the Workday lawsuit show HR leaders and executives?
It demonstrated that AI‑driven screening tools can create discriminatory outcomes — and that employers cannot shift blame to the vendor. If your HR technology influences hiring, screening, or performance decisions, you are accountable for its behavior.
3. Does using AI reduce bias in hiring?
Not automatically. AI can replicate or amplify existing bias if not governed properly. Without a structured governance framework, employers risk unintentionally deploying biased algorithms.
4. What HR systems typically use AI today?
Hiring platforms, HRIS systems, screening tools, performance management software, and even everyday productivity tools like Copilot and Gemini now embed AI in their workflows.
5. How can employers reduce AI‑related legal exposure?
By implementing an AI governance framework that includes policy controls, audit processes, documentation standards, and CHRO‑level oversight. Governance must be proactive, not reactive.
6. Do small and mid‑sized companies need AI governance?
Absolutely. Liability applies regardless of company size in many states. Smaller organizations often face greater risk because they rely heavily on vendor tools without internal compliance leadership.
7. What is an AI governance framework?
A structured set of policies, controls, and review processes that ensure AI‑influenced HR decisions are compliant, defensible, and aligned with federal and state regulations.
8. How does Outsourced CHRO support help with AI governance?
An Outsourced CHRO provides executive‑level oversight, builds compliant workflows, trains managers, and ensures your HR team is protected from AI‑driven risk — without requiring you to hire a full‑time CHRO.