โ†
AI for HR Certification
Aware ยท M9 ยท lesson 9 of 18 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Employment Law Meets AI: What HR Must Know Now
๐Ÿ“–
now learning

Employment Law Meets AI: What HR Must Know Now

15 min

Overview

A hiring manager uses an AI system to screen resumes. The system is trained on your company's past hires. Over five years, the system has learned your historical hiring patterns perfectly. Including the bias.

The system is now 95% accurate at replicating what your hiring managers did in the past. But your past hiring managers were more likely to hire men than women for technical roles. Your past hiring managers disproportionately hired from certain universities. Your past hiring managers had subtle biases that the AI has learned and amplified.

Now you're using AI that replicates your biases, faster and at scale. An EEOC investigator looks at hiring data and finds women are getting hired at significantly lower rates after your AI system was implemented. They ask: Did you test for this? Did you understand what your system was doing? Did you know it was discriminating?

The law is very clear on this: You're liable. The system doesn't shield you from liability. You created it. You deployed it. You're responsible.

Purpose

You need to understand the legal landscape so you can use AI in HR responsibly and protect your organization from liability. This isn't legal advice. I'm not a lawyer. But you need to know what laws apply to you, what risks exist, and what you need to document. You need to understand that AI use has legal implications and regulatory exposure that you must navigate.

Why This Matters for HR Professionals

Using AI in employment decisions creates legal exposure. If an AI system discriminates, you're liable. If you fail to disclose AI use where required, you might be liable. If you make employment decisions based on biased AI, you're liable. The system doesn't shield you. You created it or chose to use it. You're the one accountable.

The good news: Understanding the law and complying is manageable. The bad news: It requires actual work. Not hard work, but real work. You need to test systems, document decisions, understand implications, and maintain human judgment in the loop.

The EEOC and AI

The Equal Employment Opportunity Commission has published guidance on AI in hiring. The principles are straightforward:

  • AI systems that result in adverse impact (significantly different outcomes by protected class) are problematic and potentially discriminatory
    - You must be able to explain how the system works and defend it against discrimination claims
    - You should test AI systems for adverse impact before deployment
    - You're liable for discrimination even if the system did it automatically

The EEOC's position: If your AI hiring system results in women being hired at significantly lower rates than men, you have a problem. You need to be able to explain why. You need to show you tested for this. You need records of how the system made decisions.

Practically, this means:
- If you use AI in hiring, you need to document that you've tested it for adverse impact against protected classes (race, gender, age, disability)
- You need to be able to explain how the system works at a high level (not necessarily every technical detail, but you should understand it)
- You need records of hiring decisions for EEOC investigations
- You need to be able to show human review of AI recommendations

OFCCP and Federal Contractor Compliance

If your company is a federal contractor (meaning you have government contracts), the Office of Federal Contract Compliance Programs audits your hiring practices for compliance with affirmative action rules.

The OFCCP is increasingly asking about AI:

What OFCCP might ask about AI:
- Do you use AI in hiring? How?
- Have you tested the system for adverse impact?
- What are your hiring rates by race and gender for jobs where AI is used?
- Can you explain how the system works?
- Do you have records of validation testing?

What you need to show:
- That you've validated the system (it actually predicts job performance, not just replicating past biases)
- That it doesn't have adverse impact
- That you understand how it works
- That human decision-makers are involved in hiring

If OFCCP finds issues, they can require:
- Stopping use of the system
- Hiring goals to remedy past discrimination
- Detailed documentation going forward
- Regular auditing

Important: If you're a federal contractor, OFCCP audits compliance. If you're using AI in hiring, they will ask about it. You need to be prepared to answer.

Regulation at the State and Local Level

NYC has rules. Colorado has rules. Illinois is considering rules. California has broader privacy rules that affect AI use. The regulatory landscape is fragmented and evolving. You need to know what applies to you.

NYC Local Law 144 (Effective 2023)

If you're using AI hiring tools and recruiting in NYC:
- Third-party bias audit required before using the tool
- Annual audits required after implementation
- Disclosure to candidates that AI was used in screening
- If audits find material harm to any protected class, you must disclose that too
- Penalties: Up to $1,000 per day per violation

Practically, this means if you're using an AI hiring tool and you have NYC candidates, you need a third-party audit showing the tool doesn't have material bias. You need to tell candidates you used AI. You need to follow ongoing compliance.

Colorado AI Act (Effective 2025)

Colorado's AI rules address AI in employment. They require:
- Risk assessment for "high-risk" AI in employment decisions (hiring, firing, advancement)
- Transparency about AI use
- Opt-out mechanisms where possible
- Reasonable care to avoid discrimination

Practically: If you use AI in employment decisions, you need to assess risk. If it's high-risk, you need transparency and opt-out options.

Illinois (Proposed)

Illinois is considering legislation that would require:
- Disclosure of AI use in hiring
- Consent from candidates to use AI
- Right to request human review instead of AI screening

California (Existing and Proposed)

California's CCPA gives employees certain rights:
- Right to know when AI is being used on their data
- Right to deletion requests
- Right to opt-out in some cases

California's AB 375 and related laws address AI and discrimination more broadly.

Action: Know what states you operate in. Research the regulations. Consult legal counsel. Compliance is jurisdiction-specific.

Adverse Impact and Disparate Impact Analysis

This is the key legal concept. If an AI system results in significantly different employment outcomes across demographic groups, you have adverse impact.

Example of Adverse Impact:

Your AI resume screening results in:
- White candidates: 5% hired
- Black candidates: 2% hired
- Women: 3% hired
- Men: 6% hired

That's adverse impact. The system is producing discriminatory outcomes. Under the law, you're liable even if the discrimination wasn't intentional. The system was intentionally used by you.

The legal standard: If the hiring rate for any protected group is less than 80% of the highest-hiring group (the "4/5 rule"), you might have adverse impact that requires justification.

In the example above:
- Black candidates: 2/5 = 40% (of the highest rate), potential problem
- Women: 3/6 = 50% (of the highest rate), potential problem

These disparities are significant enough that EEOC would likely investigate.

Important: Adverse impact is a legal standard. If your AI system's outcomes show significant disparities, you have legal exposure. You need to investigate, document, and either fix the system or stop using it.

Automated Decision-Making

Many regulations reference "automated employment decisions." This means decisions made entirely by an algorithm without human review. Under GDPR Article 22 and similar regulations, employees have the right not to be subject to decisions based solely on automated processing.

If you have human review of AI recommendations, technically it's not fully automated. But if the human review is just rubber-stamping (the reviewer never disagrees, just clicks approve), it's effectively automated.

Practically: You need real human judgment in employment decisions. Not just a checkbox that says "reviewed by human." Actual human review with actual judgment. Someone who can say "The AI recommends this, but I disagree because..."

What You Actually Need to Do: The Compliance Checklist

This is the work you can't skip. Following this checklist shows regulators that you took AI compliance seriously.

For any AI system used in employment decisions:

  • Understand what the system does (non-negotiable)
    - How does the system actually work? Can you explain it?
    - What's it trained on? What data was used?
    - What patterns is it identifying or using?
    - What data does it require? Where does that data come from?
    - Who built it (internal team or external vendor)?
    - If vendor-built, what validation have they done?

Document this in writing. This is your starting point for explaining the system to regulators or employees.

  • Test for adverse impact (required, documented)
    - Run the system on past hiring data (at least 1-2 years)
    - Analyze outcomes by protected class: race, gender, age, disability, and any others relevant to your jurisdiction
    - Calculate hiring rates by group: What percentage of each group was hired?
    - Use the 4/5 rule: Is any group's rate below 80% of the highest group's rate?
    - Document everything: your methodology, data source, findings

This testing is not optional. It's the baseline for legal compliance.


  • Assess for bias and fairness concerns (systematic)
    - Beyond disparate impact analysis, think about proxy variables
    - What features is the system using that might correlate with protected classes?
    - Run bias testing with diverse candidate profiles if applicable
    - Document what you find, even if it's not at the disparate impact threshold

  • Document everything (thorough)
    - Keep records of testing, methodology, and results
    - Keep records of what you found and what concerns exist
    - Document your decisions: Will you use this system? Under what conditions? With what mitigations?
    - If you use the system, document that you've addressed known risks
    - Keep records of human review of AI recommendations
    - Keep hiring data and records of decisions made

This documentation is your legal defense. Without it, you're vulnerable.


  • Disclose to candidates and employees (where legally required, generally good practice)
    - Check your jurisdiction: NYC requires disclosure. Colorado may. Others are coming.
    - Regardless of legal requirements, transparency is generally better than secrecy
    - Tell candidates if AI was used in their screening/hiring
    - Tell employees if AI is being used in performance management, advancement, or other decisions
    - Explain what the AI does, how it affects them, and how to request human review

  • Have real human review in place (not rubber-stamping)
    - Don't just have humans approve AI recommendations
    - Have humans actually review and apply judgment
    - Humans should be able to disagree with the system and do so
    - Track whether humans override the system (if they never do, your review isn't real)
    - For critical decisions, have more than one human review

  • Audit regularly (ongoing)
    - Test system performance quarterly or annually
    - Is the system still working as you expected?
    - Are adverse impact issues emerging over time?
    - Have hiring patterns changed since you deployed the system?
    - Are certain groups being screened out more than before?
    - Be ready to adjust, mitigate, or stop using the system if problems emerge

  • Keep legal counsel involved (ongoing)
    - Have employment counsel review your AI systems
    - Get written guidance on compliance
    - Get approval to use the systems you're using
    - Consult before deploying major new systems
    - Have counsel review your testing and documentation
    - Know what your legal exposure is

This checklist is not aspirational. This is baseline. If you're not doing these things, you're at legal risk.

  • Using AI to make hiring/firing/promotion decisions without documented human review
    - Using AI that you haven't tested for adverse impact
    - Failing to disclose AI use to candidates or employees (where required by law)
    - Using AI on protected class data to predict performance or risk
    - Making termination decisions based on AI "flight risk" predictions
    - Not documenting your testing or your decision-making process
    - Not being able to explain how your system works
    - Continuing to use a system after finding adverse impact

If you see any of these in your organization, address it now. Don't wait for an EEOC complaint to force the issue.

What to Do Monday Morning


  • List every AI system that makes or informs employment decisions
    - Hiring systems
    - Promotion systems
    - Termination systems
    - Performance systems
    - Compensation systems
    - Any others?

  • For each system, determine:
    - Is this NYC-regulated? Colorado-regulated? GDPR-applicable?
    - Does it have federal contractor (OFCCP) implications?
    - Does it affect protected classes?

  • Check for adverse impact
    - For systems used in hiring, analyze outcomes by demographic group
    - Is there significant disparity?
    - Calculate the 4/5 rule ratio

  • Get legal review
    - Have employment counsel review your AI use for compliance
    - Get written guidance
    - Get approval to use the systems you're using

  • Document
    - Create documentation of testing, results, reasoning
    - Create documentation of human review processes
    - Keep records of decisions

  • Disclose
    - If required in your jurisdiction, disclose AI use to candidates/employees
    - Develop disclosure language

  • Plan ongoing monitoring
    - Set up regular testing and auditing
    - Assign someone to monitor compliance

Key Takeaways

  • Know the regulations that apply to your jurisdiction and your AI use
    - Test AI systems for adverse impact before and after deployment
    - Document everything: testing, outcomes, decisions, reasoning, human review
    - Keep humans in decision-making with real judgment
    - Consult employment counsel on AI system compliance
    - Understand that you're liable for discrimination regardless of who built the system

FAQ

Q: If we have human review of AI recommendations, are we safe?
A: Not if the human review is just rubber-stamping. Real human review means the reviewer can and does disagree with the system sometimes. If the reviewer always agrees, you don't have real human review.

Q: Do we need to tell candidates we used AI?
A: Depends on jurisdiction. NYC requires disclosure. Other jurisdictions might eventually. But transparency is generally good practice and builds trust. Consider disclosing even if not required.

Q: If the AI system is from a vendor, are we still liable?
A: Yes. You're liable for discrimination even if a vendor's system created it. The vendor doesn't shield you from liability. You chose to use it.

Q: What if we test the system and find adverse impact?
A: You need to fix it or stop using it. Continuing to use a system you know has adverse impact is asking for legal trouble. Fix it through additional training, changing thresholds, adding human review, or stop using it.

Q: How much testing do we need to do?
A: Enough to have confidence in the system's fairness. If you're using it on 100 hires a year, testing a sample of 20 from past years should be baseline. For higher-stakes decisions, test more extensively.

Q: What if we can't explain how the system works?
A: Then you probably shouldn't be using it. You need to be able to explain at a high level how it works, what data it uses, what it's optimizing for. If the vendor says "It's a black box, we can't explain it," that's a red flag.

What's Next

You understand the legal landscape. In the next lesson, we'll address employee data privacy, what data you can and can't put into AI tools, and how to protect employee privacy while complying with GDPR, CCPA, and similar laws.