AI for Recruiters
Aware · M9 · lesson 9 of 23 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Compliance Risks and Legal Exposure
📖
now learning

Compliance Risks and Legal Exposure

15 min

Deploying AI in recruiting creates legal exposure. You could face EEOC investigations for disparate impact, Fair Credit Reporting Act violations, international regulations (GDPR, EU AI Act), and state laws (NYC Local Law 144). This lesson covers the key legal frameworks you must know and how to minimize risk.

Primary US Legal Frameworks

Title VII of the Civil Rights Act (1964)

Prohibits employment discrimination based on race, color, religion, sex, or national origin. If your AI system creates disparate impact against protected classes, you have Title VII liability. Impact, not intent, matters. Even unintentional discrimination is illegal.

Americans with Disabilities Act (ADA)

Prohibits discrimination based on disability. AI systems that disadvantage candidates with disabilities (e.g., video assessment tools that don't account for deaf/hard-of-hearing candidates) violate ADA. You must provide reasonable accommodations.

Fair Credit Reporting Act (FCRA)

Regulates background checks and third-party assessments. If you use AI to assess candidates (e.g., personality assessment, honesty predictions), you may need to provide disclosure and adverse action procedures under FCRA.

Age Discrimination in Employment Act (ADEA)

Prohibits discrimination against candidates 40+. If your AI system filters or downranks older candidates, you have ADEA liability. Common risk: sourcing tools that prioritize "recent" activity, which correlates with youth.

EEOC & Disparate Impact

Key metric: The four-fifths rule. If selection rate for one group is less than 80% of another group's rate, you have potential disparate impact. Example: if women are screened in at 60% the rate of men (60/80 = .75), you likely have legal liability.

What the EEOC is Doing Now

The EEOC has warned about AI hiring tools and is actively investigating companies. They've stated that AI systems that cause disparate impact create Title VII liability, regardless of intent. Documentation matters: companies with audit evidence perform better in investigations.

How to Defend Against EEOC Claims

  • Document that you tested the AI for bias
  • Document that you monitored outcomes for disparate impact
  • Document that you took corrective action if problems found
  • Show human oversight and ability to override AI
  • Demonstrate business necessity for the AI system

Fair Credit Reporting Act (FCRA) Implications

If you use third-party tools to assess candidates (including AI assessment tools), you may need FCRA compliance:

  • Disclose to candidates that they're being assessed
  • Obtain written consent before running assessments
  • If you take adverse action based on assessment, provide pre-adverse and post-adverse action notices
  • Ensure the assessment provider complies with FCRA

Red flag: If using AI to assess personality, honesty, or other soft skills, you might need FCRA compliance even if the tool isn't a traditional background check.

International Compliance Landscape

EU AI Act

The EU classifies employment AI as "high-risk" and requires: risk assessments, transparency, human oversight, documentation, bias testing. Non-compliance carries fines up to 10 million euros or 2% of global revenue.

GDPR

Privacy regulation (covered in earlier lesson). Key risk: automated decision-making. If AI makes recruiting decisions about EU candidates without human review, you violate GDPR's right to explanation.

State-Specific Laws

NYC Local Law 144

Requires: notice to candidates that automated employment decision tools are used, annual bias audit and public reporting, and candidate rights to explanation and human review. Penalties: up to $1,000 per violation, per day.

Illinois Artificial Intelligence Video Interview Act

If using video interview AI, you must: disclose use to candidates, allow candidates to request human review, maintain records for 3 years. This is narrow but important if you use interview video analysis.

Colorado, Nevada, Utah

Recent or pending laws around AI hiring. Landscape is evolving. Check state-specific requirements if you recruit heavily in these states.

How to Mitigate Legal Risk

1. Document Everything

  • Business necessity: Why did you adopt this AI tool? What problem does it solve?
  • Vendor selection: Why this vendor? What due diligence did you do?
  • Bias testing: Did you test the tool for disparate impact? What were results?
  • Monitoring: How often do you audit outcomes?
  • Corrective action: If you found problems, what did you do?

2. Regular Audits

Quarterly: disparate impact analysis, bias testing, outcome tracking. Annual: comprehensive legal review. This documentation is your best defense in litigation or investigation.

3. Human Oversight

Maintain human judgment in high-stakes decisions. Humans should review and potentially override AI on screening, interviews, offers. This gives you a legal defense ("we had human oversight").

4. Transparency

Tell candidates if AI is used. This builds trust and helps with compliance requirements (GDPR, FCRA, NYC Local Law 144).

5. Legal Review

Before deploying new AI tools, have your legal team review. Are there FCRA implications? GDPR compliance? State-specific laws? Don't guess.

6. Vendor Contracts

Ensure vendor contracts include: data security requirements, bias testing obligations, audit rights, indemnification (vendor covers certain liability). Don't assume vendor indemnifies you for all risk.

Key Takeaway

Key Takeaway

AI in recruiting creates legal exposure: Title VII, ADEA, ADA, FCRA, GDPR, EU AI Act, state laws. Disparate impact liability is real. The EEOC is actively investigating. Your best defense: document everything (bias testing, audits, corrective action), maintain human oversight, ensure vendor compliance, and consult legal. Document early and often. In litigation, your documentation of responsible practices is your strongest defense.

Frequently Asked Questions

What's the difference between disparate treatment and disparate impact?

Disparate treatment: intentional discrimination. Example: "Don't screen women." Disparate impact: neutral policy that harms protected class. Example: AI system screens out women at higher rates, even though no rule mentions gender. Disparate impact is illegal even without intent. AI systems that cause disparate impact are legally risky.

How exposed are we if an EEOC investigation happens?

EEOC can subpoena documents, interview employees, and analyze hiring data. They look for: disparate impact, evidence of discrimination, documentation of bias testing. If you have audit documentation showing you tested for bias and took corrective action, you're in a stronger position. If you deployed AI without testing and can't explain why, you're exposed to findings and remedies (back pay, compensatory damages, policy changes).

Do all AI tools require FCRA compliance?

Not all, but the line is blurry. Traditional background checks clearly need FCRA compliance. But if you're using AI to assess personality, honesty, or other characteristics that affect hiring decisions, FCRA likely applies. When in doubt, assume it applies. The compliance cost (disclosure, consent, adverse action procedures) is minimal compared to FCRA violations.

What should we do if we discover our AI tool violates these laws?

Stop using the tool immediately. Consult legal counsel. Consider voluntary disclosure (reporting the issue to relevant agencies) which can reduce penalties. Audit hiring decisions made with the tool. Consider remedial measures: consider applicants the tool filtered out, adjust offers if necessary. Document everything. Legal counsel should guide next steps, including potential settlements.

Can we get liability insurance for AI recruiting tools?

Some insurers offer "employment practices liability insurance" (EPLI) that might cover some AI-related claims. But coverage is limited and exclusions are common. Insurance doesn't replace responsible practices. Focus on not creating the risk in the first place: test for bias, audit outcomes, maintain human oversight. Insurance is a backstop, not a substitute for compliance.