Skip to content
MAYFLOWER SPECIALTYMayflower Specialty

Risk

AI in Hiring: Discrimination Claims, New Rules and EPL Coverage

Updated 12 minute readBy Mayflower Specialty

Employers that use AI to screen, rank or interview candidates can be liable for the discrimination those tools cause, and in Mobley v. Workday a federal court has allowed age discrimination claims to proceed against the software vendor as well. Rules in New York City, Illinois, California and Colorado add notice, audit and record-keeping duties on top of federal law. Whether an employment practices liability (EPL) policy responds depends on its wording, and a policy that is silent on AI or excludes it may leave the employer to fund its own defense.

How Do AI Hiring Tools Lead to Discrimination Claims?

AI hiring tools lead to discrimination claims mainly through disparate impact: a screening or scoring model that rejects one protected group at a higher rate than others can breach federal and state law even when nobody intended the result.

Definition

Disparate impact

Disparate impact is discrimination that results from a neutral-looking practice, such as a screening rule or a scoring model, that disadvantages a protected group and cannot be justified by the needs of the job. Intent is not required, which is why the leading AI hiring claims rely on it.

Claims tend to arise in three ways. The first is the proxy problem: a model trained on past hiring decisions can learn to favor stand-ins for race, sex or age, such as a zip code, a school or a graduation date, which is the theory behind Harper v. Sirius XM, discussed below. The second is disability, because video and game-based assessments can disadvantage candidates with disabilities, and California’s regulations state that an automated assessment that elicits information about a disability may be an unlawful medical inquiry [2]. The third is a newer theory that treats a vendor’s candidate scores as consumer reports under the Fair Credit Reporting Act (FCRA) [3], which allows statutory damages of $100 to $1,000 per consumer for willful violations, plus punitive damages and attorney’s fees [4].

The consequence for the business is scale, because a biased model repeats its error on every applicant it scores and the realistic worst case is an expensive class action. It is therefore best to find a skewed tool through internal testing before a plaintiff finds it in discovery.

What Are the Main AI Hiring Discrimination Lawsuits?

The main AI hiring discrimination lawsuit is Mobley v. Workday, in which a federal court has allowed age discrimination claims against an HR software vendor to proceed as a nationwide collective action. It follows the EEOC’s 2023 settlement with iTutorGroup, and newer claims have since been brought over race proxies, video interviews and candidate scoring, one of which a court dismissed in September 2026.

Mobley v. Workday

The plaintiff alleges that employers using Workday’s screening tools rejected him for more than 100 positions, and he sued Workday itself in the Northern District of California. On July 12th 2024 the court rejected the theory that Workday was an employment agency but let the claims proceed on the theory that it acted as the employers’ agent, because they had allegedly delegated to its tools their “traditional function of rejecting candidates or advancing them to the interview stage” [5]. Most of the rulings since then have gone against Workday, with the exception of a dispute over discovery:

DateRuling
May 16th 2025The court conditionally certified a nationwide collective of applicants aged 40 and over under the Age Discrimination in Employment Act (ADEA) [6]
July 2025The court extended the collective to applicants screened with Workday’s HiredScore AI features [6]
March 6th 2026The court rejected Workday’s argument that the ADEA’s disparate impact protections do not extend to job applicants [8]
May 29th 2026A magistrate judge held that Workday did not have to produce its customers’ applicant data, because its contract gave the customers ownership of that data, and that its bias testing was privileged because its lawyers had curated the underlying data [7]
June 22nd 2026The court largely denied Workday’s motion to dismiss the third amended complaint [8]
June 24th 2026The district judge upheld the magistrate judge’s discovery ruling [24]

The applicant question remains contested, because the Seventh Circuit held in 2019 that the ADEA does not authorize disparate impact claims by outside job applicants [25], so an employer’s exposure to age claims of this kind can depend on where it is sued. The wider lesson is that one vendor’s tool can pull many employers’ applicants into a single action while the data needed to defend each decision sits with the employer, so it is worth confirming now that the employer can retrieve that data.

EEOC v. iTutorGroup

The EEOC alleged that iTutorGroup’s application software automatically rejected female applicants aged 55 or older and male applicants aged 60 or older, screening out more than 200 qualified applicants. The company agreed to pay $365,000 and accept at least 5 years of EEOC monitoring in a settlement announced on September 11th 2023 [9]. The EEOC’s announcement calls the tool “tutor application software” and does not describe it as AI, which shows that an employer answers for any automated rule that screens on a protected characteristic, whatever the technology is called.

Claims Over Proxies, Video Interviews and Candidate Scores

Harper v. Sirius XM, filed in the Eastern District of Michigan on August 4th 2025, alleged that an applicant tracking system used schools, zip codes and employment history as proxies for race to reject the plaintiff from about 150 positions, and brought race claims under Title VII and Section 1981 as a proposed class action [1]. On September 30th 2026 the court dismissed the complaint without prejudice, finding that it identified no comparator group and no facts about other applicants and so did not plausibly show either intentional discrimination or a disparate impact [23].

Charges filed by the ACLU of Colorado on March 19th 2025 allege that a deaf and Indigenous Intuit employee was rejected for a promotion after an AI video interview, for which she was refused human-generated captions; both Intuit and HireVue call the complaint “entirely without merit”, and HireVue says Intuit did not use a HireVue AI-based assessment [10]. Separately, two applicants sued Eightfold AI in California state court on January 20th 2026, alleging that its 0-5 scores of a candidate’s predicted “likelihood of success” are consumer reports [3]. The case moved to federal court in the Northern District of California in March 2026, where it remained pending as of late September 2026 [26].

The Harper ruling suggests that a claim built on general allegations about proxies can fail early unless the plaintiff points to an actual disparity. The other two matters remain unresolved; they test disability and consumer reporting theories against common hiring tools, so employers should review their accommodation routes and how their vendors score candidates without waiting for a ruling.

Is the Employer or the AI Vendor Liable?

Both the employer and the vendor can be liable: the employer answers for its hiring decisions whichever tool it uses, and Mobley shows that a vendor can also face direct claims when employers delegate screening to its software. A contract does not remove the employer’s own liability to applicants, but it can decide who bears the cost.

The agency theory matters to employers too, because the more a tool rejects candidates without human review, the stronger the argument that the software is making the employer’s decision. Colorado’s SB 26-189, signed on May 14th 2026, will require developers from January 1st 2027 to give deployers documentation of a tool’s intended uses and known limitations, and it sets out how fault is allocated between developers and deployers in discrimination cases [11].

Until the law settles, the vendor contract sets the allocation, and four of its terms carry most of the weight:

Contract termWhat to check
IndemnityWhether the vendor indemnifies the employer for discrimination claims, and whether a liability cap empties that promise
Data accessWhether the employer can export its own applicant and scoring data, which the Mobley court treated as the employer’s under the vendor contract rather than the vendor’s to produce [7]
Audit supportWhether the vendor will support bias audits of its tool
InsuranceWhether the vendor’s insurance can stand behind its indemnity

An indemnity is worth little if the vendor cannot pay it or the employer cannot get the data it needs to defend itself, so it is best to negotiate all four terms together at the next contract renewal.

Which Laws Regulate AI in Hiring?

Federal discrimination law applies to every AI hiring tool, and state and city rules add duties such as bias audits in New York City, notice in Illinois, record-keeping in California and explanation rights in Colorado from January 1st 2027. The table below summarizes the rules that matter most for hiring, the glossary defines the terms they use, and the guide to AI laws that create liability covers the wider set.

Definition

Automated employment decision tool

An automated employment decision tool (AEDT) is software that uses machine learning, statistics or AI to produce a score, classification or recommendation that substantially assists or replaces human judgment in employment decisions. New York City’s Local Law 144 regulates such tools.

RuleWhat it requires of employersIn force
Title VII, the ADEA and the ADA (federal)No discrimination by protected trait, including through practices with a disparate impact (though courts disagree on whether the ADEA extends this to outside job applicants [25]), and reasonable accommodation for disabilityNow
New York City Local Law 144An independent bias audit within one year before use, a public summary and candidate notice 10 business days before use [12]; fines of up to $500 for a first violation and $500 to $1,500 for later ones [13]Enforced since July 5th 2023
Illinois Human Rights Act, as amended by HB 3773No use of AI with a discriminatory effect in covered employment decisions, and notice when AI is used [14]January 1st 2026
Illinois Artificial Intelligence Video Interview ActNotice, explanation and consent before AI analyzes a video interview, and deletion within 30 days on request [15]January 1st 2020
California FEHA regulations on automated-decision systemsDiscriminatory automated decisions may violate FEHA, and automated-decision data must be kept for 4 years [2]; anti-bias testing, or its absence, may be weighed [8]October 1st 2025
California SB 947No discipline or termination based solely on an automated decision system, and human corroboration where one is primarily relied on [16]July 1st 2027
Colorado SB 26-189Notice when automated decision-making technology is used in employment and other consequential decisions, an explanation of an adverse decision within 30 days and a right to human review, enforced by the attorney general with no new private right of action [11]January 1st 2027
EU AI ActAI used for recruitment and worker management, such as CV-sorting software, is classed as high-risk [17]December 2nd 2027

Federal enforcement has stepped back: the EEOC removed its AI technical assistance on January 27th 2025 [18], and Executive Order 14281 of April 23rd 2025 set a policy of eliminating disparate-impact liability “to the maximum degree possible” [19]. Neither amends Title VII, the ADEA or the ADA, and private plaintiffs continue to sue, so reduced federal enforcement is no reason to relax controls.

Definition

Bias audit

A bias audit is an impartial evaluation by an independent auditor that tests whether an automated hiring tool has a disparate impact on candidates by sex, race or ethnicity. New York City requires one within the year before an employer uses such a tool, with a public summary of the results.

City enforcement has been light as well: a New York State Comptroller audit released on December 2nd 2025 found that the city identified a single compliance issue among 32 companies, while the auditors found at least 17 potential instances among the same companies [20]. The larger risk is therefore litigation, in which a published bias audit is public evidence of how a tool performs and a missing one suggests the employer did not look.

Does EPL Insurance Cover AI Hiring Discrimination Claims?

A standard employment practices liability policy may respond to a discrimination claim over an AI hiring tool, because the claim is still a discrimination claim by an applicant or employee. Whether it does depends on the wording, and four features of an EPL form can remove or reduce that cover, each of which is worth raising with a broker before renewal:

  1. AI exclusions and silent AI: Insurers have begun adding AI exclusions to management liability forms. Hunton Andrews Kurth reported in May 2025 that W. R. Berkley had introduced one for D&O, E&O and fiduciary liability that removes cover for claims “based upon, arising out of, or attributable to” any actual or alleged use, deployment or development of AI [21], and Insurance Business, citing the Financial Times, reported in November 2025 that AIG, Great American and W. R. Berkley had sought regulatory approval to limit liability for AI-related claims [22]. Wording that broad in an EPL form would reach almost any AI hiring claim, while a form that says nothing about AI (silent AI) leaves the answer to argument after the claim arrives.
  2. Consumer reporting claims: If the Eightfold theory succeeds, some screening claims will arrive as FCRA class actions, and EPL forms differ on whether they cover claims under consumer reporting statutes.
  3. Fines, audits and remediation: City penalties, the cost of a bias audit commissioned after a complaint and the cost of changing a tool under a settlement may fall outside the definition of loss.
  4. Scale and timing: One tool used for years can produce a collective action spanning many policy periods, which related-claims wording on a claims-made-and-reported form may treat as a single claim under one limit and one retention, so a limit sized for individual charges may prove thin.

Affirmative AI coverage deals with AI in the policy wording itself rather than leaving the question to argument. Mayflower Specialty writes AI Employment Practices Liability (AI-EPL) for employment claims arising from AI used in hiring, promotion, discipline and other workforce decisions. Where a company wants to keep its EPL program, Mayflower’s AI DIC Excess is a difference-in-conditions layer written to sit over existing D&O, EPL and E&O policies where they are silent on AI or exclude it. Both are written on a claims-made-and-reported basis on A- (Excellent) AM Best rated paper backed by global reinsurers, placed through brokers and underwritten on the applicant’s AI governance, and whether a particular claim is covered depends on the policy wording.

HR technology vendors can ask their broker about AI Professional Liability (AI-E&O), which is written for claims arising from AI-enabled products and services, although whether it would respond to an applicant’s discrimination claim against a vendor also depends on the wording. For employers, the practical step is to ask the broker before renewal how the current EPL form handles each of the four points above.

How Can Employers Reduce AI Hiring Risk?

Employers reduce AI hiring risk by testing tools for disparate impact, keeping a person in rejection decisions, telling candidates when AI is used and holding vendors to contract terms on data, testing and indemnity.

  • Bias testing: Test selection rates by sex, race, ethnicity and age before launch and at intervals, under counsel’s direction where privilege matters [7].
  • Human review: Let a trained person see and overturn automated rejections; from July 1st 2027 California will bar employers from relying solely on an automated decision system to discipline or dismiss workers and will require a person to corroborate decisions that rely primarily on one [16].
  • Notices and alternatives: Give the notices that New York City, Illinois and, from 2027, Colorado require, and offer an alternative assessment or accommodation for candidates with disabilities.
  • Records: Keep applicant data, scores, model versions and audit results for at least 4 years, as California requires.
  • Vendor due diligence: Ask each vendor for its bias testing, its documentation of known limitations and evidence of its insurance.

These controls also matter at underwriting, because Mayflower underwrites on the applicant’s AI governance: its application requires an AI system inventory and an AI governance policy and lists bias audit results among the recommended documents. An employer that has these controls in place is therefore better prepared to apply, and the guide to how underwriters assess AI risk explains what else to gather.

What Should Employers Do Now?

The recommended course of action is to treat AI hiring risk as a compliance project that ends with an insurance check, starting well before the next EPL renewal.

  1. Inventory the tools: HR and procurement list every system that screens, ranks, scores or interviews people, including AI features inside larger HR platforms, which the HiredScore ruling shows can count.
  2. Map the rules: Legal matches each tool to the jurisdictions where candidates are located and confirms the required audits, notices and records.
  3. Test and fix: Legal commissions disparate impact testing, and HR changes or retires any tool with a gap the business cannot justify.
  4. Renegotiate vendor contracts: Procurement and legal raise the four contract terms above at the next renewal.
  5. Read the EPL policy: Risk management asks the broker whether the form has an AI exclusion, whether it covers applicants, how it treats FCRA claims and audit costs, and how its limit would hold up against a collective action.

If the answers reveal a gap, the options are to negotiate the wording with the current insurer, add affirmative cover such as AI-EPL or place an AI DIC Excess layer over the existing program. Employers in that position can start an AI-EPL quote directly or through their broker, and it is a good idea to start soon, because the governance documents an application needs can take weeks to assemble.

Frequently Asked Questions

Can employers be sued for AI hiring bias?

Employers can be sued for AI hiring bias, because Title VII, the ADEA, the ADA and state law can make them liable for discrimination caused by the hiring tools they use, including vendors' tools. The leading claims allege disparate impact, which does not require intent, although a plaintiff must still plead facts showing a disparity. The EEOC settled an automated age-rejection case with iTutorGroup for $365,000 in 2023, and private suits such as Mobley v. Workday are in court.

Is the AI vendor liable for hiring discrimination?

An AI vendor can be liable for hiring discrimination in some circumstances. In Mobley v. Workday a federal court in California allowed claims to proceed in July 2024 on the theory that the vendor acted as an agent of the employers that delegated screening decisions to its tools, and in May 2025 it conditionally certified a nationwide age collective. Vendor liability does not remove the employer's own liability, so contracts should address indemnity, data access and audit cooperation.

Does EPLI cover AI hiring discrimination claims?

An EPL policy may respond to an AI hiring discrimination claim, because it is still a discrimination claim, but the answer depends on the wording. Insurers have begun adding AI exclusions to management liability forms, and EPL policies vary on consumer reporting claims, fines and audit costs. Employers should check each renewal for new AI wording and consider affirmative AI coverage, such as an AI-EPL module or a DIC layer, where the program is silent or excludes AI.

What is a bias audit under NYC Local Law 144?

A bias audit under New York City's Local Law 144 is an impartial evaluation by an independent auditor that tests whether an automated employment decision tool has a disparate impact on candidates by sex, race or ethnicity. Employers must have one completed within the year before using the tool, publish a summary of the results and notify candidates 10 business days before use. Fines run up to $500 for a first violation and $500 to $1,500 for later ones.

Do employers have to tell candidates they use AI?

Employers must tell candidates about AI use in several jurisdictions. New York City requires notice 10 business days before an automated employment decision tool is used, Illinois has required notice of AI use in employment decisions since January 1st 2026, and Illinois also requires notice and consent before AI analyzes a video interview. Colorado will require notice at the point of interaction from January 1st 2027, so one notice policy across all locations is the simplest approach.

Does the Colorado AI Act apply to hiring?

Colorado's rules will apply to hiring from January 1st 2027, but under a replacement law, because Colorado repealed and replaced its 2024 AI Act before it took effect. The replacement, SB 26-189, signed on May 14th 2026, covers automated decision-making technology used in consequential decisions, including employment. Deployers must give notice, explain an adverse decision within 30 days and allow a request for human review. The attorney general enforces the law, which creates no new private right of action.

Sources

  1. [1]Another Employer Faces AI Hiring Bias Lawsuit: 10 Actions You Can Take to Prevent AI Litigation (Harper v. Sirius XM), Fisher Phillips, August 15th 2025
  2. [2]Civil Rights Council Secures Approval for Regulations to Protect Against Employment Discrimination Related to Artificial Intelligence, California Civil Rights Department, June 30th 2025
  3. [3]Job Applicants Sue AI Screening Company for FCRA Violations: 5 Key Takeaways for Employers (Kistler v. Eightfold AI), Fisher Phillips, January 26th 2026
  4. [4]15 U.S.C. § 1681n: Civil liability for willful noncompliance (Fair Credit Reporting Act), Legal Information Institute, Cornell Law School
  5. [5]Job Applicant's Algorithmic Bias Discrimination Lawsuit Survives Motion to Dismiss (Mobley v. Workday), Proskauer Rose, Law and the Workplace, July 25th 2024
  6. [6]Mobley v. Workday, Inc., No. 3:23-cv-00770 (N.D. Cal.): case summary and docket, Civil Rights Litigation Clearinghouse, December 17th 2025
  7. [7]AI Hiring Litigation: Key Lessons for Employers, CDF Labor Law, August 27th 2026
  8. [8]Workplace AI Regulation in 2026: How Employers Can Navigate the Changing Legal Landscape, Epstein Becker Green, September 1st 2026
  9. [9]iTutorGroup to Pay $365,000 to Settle EEOC Discriminatory Hiring Suit, U.S. Equal Employment Opportunity Commission, September 11th 2023
  10. [10]AI hiring software was biased against deaf employees, ACLU alleges in ADA case, HR Dive, March 24th 2025
  11. [11]Colorado SB26-189: automated decision-making technology in consequential decisions, bill summary and history, Colorado General Assembly, May 14th 2026
  12. [12]Automated Employment Decision Tools (AEDT), NYC Department of Consumer and Worker Protection
  13. [13]Local Law 144 of 2021 (Int. 1894-2020): automated employment decision tools, New York City Council
  14. [14]Illinois Department of Human Rights Withdraws Proposed AI in Employment Rules, Burke, Warren, MacKay & Serritella, June 16th 2026
  15. [15]2020: An HR Odyssey: Illinois Enacts the Artificial Intelligence Video Interview Act, Amundsen Davis, November 26th 2019
  16. [16]California SB 947 (Chapter 859, Statutes of 2026): employment and automated decision systems, California Legislative Information, September 30th 2026
  17. [17]AI Act: regulatory framework for artificial intelligence, European Commission
  18. [18]The Changing Landscape of AI: Federal Guidance for Employers Reverses Course With New Administration, K&L Gates, January 31st 2025
  19. [19]Executive Order 14281: Restoring Equality of Opportunity and Meritocracy, 90 FR 17537, Federal Register, via govinfo.gov, April 28th 2025
  20. [20]Enforcement of Local Law 144: Automated Employment Decision Tools, Office of the New York State Comptroller, December 2nd 2025
  21. [21]The Continued Proliferation of AI Exclusions, Hunton Andrews Kurth, Insurance Recovery Blog, May 28th 2025
  22. [22]Major insurers seek approval to limit liability for AI-related claims: report, Insurance Business, November 24th 2025
  23. [23]Harper v. Sirius XM Radio, LLC, No. 2:25-cv-12403 (E.D. Mich.): order granting motion for judgment on the pleadings, U.S. District Court for the Eastern District of Michigan, via CourtListener, September 30th 2026
  24. [24]The Black Box Stays Partially Closed: A Win for the Defense in the Mobley Discovery Fight, Houston Harbaugh, August 18th 2026
  25. [25]Seventh Circuit Rules Age Bias Protections Don't Extend to Prospective Employees for Disparate Impact Claims (Kleber v. CareFusion), Littler Mendelson, January 28th 2019
  26. [26]Kistler v. Eightfold AI Inc., No. 26-cv-01768 (N.D. Cal.): docket, CourtListener

Next step

Put Affirmative AI Coverage in Front of Your Board

Apply online and underwriting will respond within 48 hours, or send a short note if you would rather talk first.