The EEOC, OFCCP, and Emerging AI Hiring Regulations
Overview
An EEOC investigator opens your company's hiring data for the past two years. The data shows that after you implemented an AI hiring system, your hiring rates changed. White candidates: 5% hired. Black candidates: 2.5% hired. Women: 3.5% hired. Men: 5.8% hired.
The ratios show significant disparity. The investigator asks: Do you have documentation that you tested this system for bias before deployment? Can you explain how the system works? Do you understand what it was doing?
You have documentation. You tested the system. You didn't find the bias because you didn't test for it correctly. Or you found it and didn't fully address it. Or you didn't understand what the system was doing.
Now you're in an investigation defending your AI hiring practices. The burden of proof is on you, not them. You need to show that your system is fair, that you tested it, that you understand how it works.
This is the rubber hitting the road, actual regulatory enforcement that will determine whether your AI practices are acceptable.
Purpose
You need to know what the EEOC and OFCCP expect from AI systems and from you. You need to understand what documentation you need to have. You need to know what happens if regulators investigate your AI hiring practices. You need to be prepared to defend your system if they ask.
The stakes here are concrete. EEOC can open investigations. OFCCP can conduct audits. State regulators can impose fines. This is enforcement, not guidance.
Why This Matters for HR Professionals
EEOC can investigate your hiring practices. OFCCP can audit your AI system as part of federal contractor compliance. State regulators can impose fines. If your AI hiring system has discriminatory outcomes, regulators will notice. They will investigate.
The burden of proof is on you, not them. You need to show that your system is fair, that you tested it, that you understand how it works. You need documentation. You need evidence. You need to be able to defend your system.
This is where being intentional about AI use pays dividends. If you tested, documented, and monitored, you can defend yourself. If you didn't, you're in trouble.
EEOC Expectations: What They Look For
The EEOC's position on AI hiring is clear and consistent: You're responsible for discrimination, even if AI did it.
Key EEOC positions:
- AI systems that result in adverse impact (significantly different hiring rates by protected class) violate Title VII
- Employers must be able to explain how the system works and why it makes particular decisions
- Employers should document testing for adverse impact
- Employers should understand the training data and potential biases
- Human judgment in hiring decisions is important
What EEOC looks for in investigations:
They analyze hiring outcomes by race, gender, age, disability for jobs where your system was used. They look for adverse impact (4/5 rule disparities).
They ask for your documentation: Do you have testing records? Do you have validation studies? Do you have evidence that you assessed the system for bias?
They want to understand: Can you explain how the system works? What is it doing? What data is it using? How is it making decisions?
They evaluate: Is the system a "black box" you can't explain? Or can you articulate how it works at a reasonable level?
They investigate: What were hiring decisions before implementation? What changed after?
The key issue:
If EEOC investigates your hiring and finds adverse impact (significantly different hiring rates by protected class), you have a problem. You'll need to prove the system is job-related and valid. You'll need to show it predicts job performance. If you can't prove that, you're liable for discrimination.
Important: EEOC is actively investigating AI hiring discrimination. If you're using AI in hiring, you should assume you might be investigated. Be prepared.
OFCCP Audits: What Federal Contractors Need to Know
If your company is a federal contractor (which many companies are, any company with government contracts is likely a federal contractor), the OFCCP audits your hiring practices for compliance with affirmative action rules.
The OFCCP is increasingly asking about AI systems. If they conduct an audit and you're using AI in hiring, they will ask.
What OFCCP might ask about AI:
- Do you use AI in hiring? How?
- Have you tested the system for adverse impact?
- What are your hiring rates by race/gender for jobs where AI is used?
- Can you explain how the system works?
- Do you have records of validation testing?
- Do you have records of human decisions?
What you need to show:
- That you've validated the system (it actually predicts job performance)
- That it doesn't have adverse impact
- That you understand how it works
- That human decision-makers are involved in hiring
- That you can explain hiring decisions
If OFCCP finds issues, they can require:
- Stopping use of the system immediately
- Hiring goals to remedy past discrimination
- Detailed documentation going forward
- Regular auditing and monitoring
- Potential back pay for affected candidates
Real scenario:
A federal contractor was using an AI hiring system. OFCCP audited and found that the system had resulted in 40% fewer women being hired for technical roles compared to pre-AI hiring rates. OFCCP required them to stop using the system, implement hiring goals to remedy past discrimination, and conduct quarterly audits for two years.
State-Level AI Hiring Regulations
Multiple states are implementing or proposing AI hiring regulations. The landscape is evolving.
New York (NYC Local Law 144), Effective 2023
What's required:
- Before using an AI hiring tool, you need a third-party audit for bias
- Annual audits required
- Disclosure to candidates that AI was used
- If audits find material harm on any protected class, you must disclose that too
- Penalties: Up to $1,000 per day per violation
What this means:
- If you're using an AI hiring tool in NYC, you need third-party bias audit before deployment
- You need ongoing annual audits
- You must tell candidates you used AI
- If the audits show bias, you must disclose that
Real scenario:
A company using an AI hiring tool in NYC for recruiting engineers was required to get a third-party audit. The audit found that the system had 8% less positive evaluation rate for women than men. The company was required to disclose this material bias to candidates. They're now working to fix the system or stop using it.
Colorado AI Act, Effective 2025
Colorado's AI rules address AI in employment decisions more broadly:
- Risk assessment required for "high-risk" AI in employment decisions (hiring, firing, advancement)
- Transparency about AI use
- Opt-out mechanisms where possible
- Reasonable care to avoid discrimination
Illinois (Proposed)
Illinois is considering legislation that would require:
- Disclosure of AI use in hiring to candidates
- Consent from candidates to use AI in screening
- Right to request human review of AI decisions
California (Existing and Proposed)
California's CCPA affects AI hiring:
- Disclosure of AI use that affects hiring
- Employee rights to know how their data is used
- Right to deletion and opt-out
Action for you:
Research the regulations in the states where you operate. Consult employment counsel. Compliance is jurisdiction-specific and evolving.
What You Need to Document: The Complete Defense
If regulators investigate your AI hiring practices, they'll want documentation. This is what to have ready:
1. System Description (Written and Detailed)
- What does the system actually do? (In plain language, not vendor marketing)
- How does it work? (What are the inputs? What does it output?)
- What data does it use? (Job performance ratings, previous hiring data, etc.)
- How is it trained? (What methodology? What period of data?)
- Who built it? (Internal team, external vendor, hybrid?)
- If from a vendor, which vendor? What's their background?
- Have you reviewed the system's documentation and training data?
Write this down clearly. You should be able to explain this to an EEOC investigator without your vendor present.
2. Validation Testing (Evidence of Job-Relatedness)
The most important question regulators ask: Does this system actually predict job performance?
- Did you test whether the system predicts on-the-job success?
- What's the correlation between system recommendation and actual job performance?
- Did you validate on your own data or rely on vendor validation?
- How many people did you validate on? (Sample size matters)
- What were the results? (Keep the actual reports)
- If you found the system predicts poorly, what did you do?
This is your evidence that the system is job-related, not just discriminatory.
3. Adverse Impact Testing (Pre and Post Deployment)
Before you deploy and ongoing:
- What are hiring rates by protected class (race, gender, age, disability)?
- Is there significant disparity? Calculate the 4/5 rule.
- If you found adverse impact, what was your response?
- Did you deploy anyway? If yes, document why you thought that was acceptable.
- What mitigations did you put in place?
Keep spreadsheets. Keep analysis. Document your decision-making.
4. Bias Assessment (Multiple Methods)
Did you assess the system for bias? What methods?
- Test with diverse candidate profiles (same qualifications, different names/backgrounds)
- Analyze features the system uses, do any correlate with protected classes?
- Review cases where the system screened out candidates who passed human review
- Analyze long-term hiring patterns, did diversity change after you deployed the system?
What were your findings? What did you do about them?
5. Decision Records (Traceability)
- Which candidates went through the system?
- What did the system recommend for each?
- What was the human decision for each?
- Can you trace hiring outcomes back to system recommendations?
- Did humans override the system? When? Why?
You need to be able to say: "We hired this person. Here's what the system recommended. Here's why we made that decision."
6. Audit and Compliance Documentation
- Did you do internal audits? Keep the results.
- Did you get a third-party audit? Keep the report.
- Annual testing results. Keep them.
- Any regulatory contacts or concerns? Document your response.
- What corrective actions did you take if problems were found?
7. Human Review Records (Proof of Real Review)
- Who was responsible for reviewing AI recommendations?
- What was the review process?
- Did reviewers ever disagree with the system? How often? (If zero, that's a red flag that review wasn't real)
- What was the reasoning when they disagreed?
- Do you have evidence that reviewers actually understood the system and could make independent judgments?
Document that real human judgment happened.
8. Training and Competency
- Did you train people on how to use the system?
- Can the people using the system explain how it works?
- Do they understand the risks and limitations?
Regulators will talk to your team. They'll ask: "How does this system work?" If your HR staff can't explain it, that's a problem.
Red Flags: When Regulators Will Be Concerned
If you have any of these, you're at high risk in an investigation:
- You use AI in hiring but haven't tested for adverse impact
- You can't explain how the system works beyond vendor marketing language
- You have significant hiring disparities but no explanation
- You don't have documentation of validation or testing
- You're unaware of what your system is actually doing
- You've received complaints about hiring discrimination
- You can't produce records of who was screened by AI and why
- You implemented the system based on vendor assurance but didn't test it
- You found adverse impact but continued using the system
- Human reviewers always agree with the AI (rubber-stamping)
- You don't have a DPA with the vendor
What to Do Monday Morning
Document your AI hiring system thoroughly
- Create a clear written description of what it does, how it works, what data it uses
- This should be something you could hand to an investigator
Test for adverse impact
- Analyze hiring outcomes by protected class for jobs where AI is used
- Calculate 4/5 rule disparities
- Document results
- Document any issues found
Get third-party audit (if required)
- If you're in NYC or Colorado, get the required audit
- For other jurisdictions, consider getting one anyway, shows you took steps
Prepare for investigation
- Assume you might be investigated
- Can you explain your system?
- Do you have documentation?
- Do you have evidence of testing?
Consult employment counsel
- Have legal review your AI hiring system
- Get written guidance on compliance
- Get approval to use the systems you're using
- Keep that legal guidance as documentation
Commit to ongoing monitoring
- Plan regular testing and validation
- Assign someone responsibility
- Set up quarterly or annual review schedule
Create a paper trail
- Document everything
- Decisions, testing, reasoning, human review
- This is your evidence if regulators investigate
Key Takeaways
- Know that EEOC holds you responsible for AI hiring discrimination
- Understand OFCCP audit expectations if you're a federal contractor
- Comply with state-specific AI hiring regulations (NYC, Colorado, others)
- Document testing, validation, adverse impact analysis, and decision records
- Be prepared to explain and defend your AI system to regulators
- Assume you might be investigated and prepare accordingly
FAQ
Q: If we outsource hiring to a vendor using their AI, are we still responsible?
A: Yes. You're responsible for discrimination regardless of who implemented the system. Using a vendor doesn't shield you from liability.
Q: What if we have human review of AI recommendations?
A: That helps, but only if it's real review. If humans are just rubber-stamping, you still have an automated system. Real review means reviewers actually evaluate and sometimes override.
Q: How much testing do we need to do before deployment?
A: Enough to have confidence in fairness. Baseline: Test on past hiring data (1-2 years). Analyze outcomes by demographic group. Look for disparities. Document methodology and results.
Q: What if we find adverse impact during testing?
A: Don't ignore it. Investigate why it's happening. Fix the system or stop using it. Continuing to use a system you know is discriminatory is asking for legal trouble.
Q: Does a third-party audit make us safe?
A: It helps. An audit shows you took steps to verify fairness. It's evidence of due diligence. But it doesn't eliminate liability. If the system discriminates, you're still liable. An audit is part of the defense, not a shield.
Q: Should we disclose AI use to candidates even if not required by law?
A: Yes. Transparency is generally good practice. It's required in NYC and some other jurisdictions anyway. Being transparent about how you evaluate candidates builds trust.
Q: What if the vendor says the system is "unbiased"?
A: Test it yourself. Vendor claims aren't evidence. Your testing is. Don't rely on vendor assurance, verify independently.
What's Next
You understand the legal and regulatory landscape for AI hiring. In the final chapter, we'll address responsible AI from an ethical standpoint, bias, transparency, accountability, and your personal responsibility as an HR professional using AI.
Skill.re