What the Workday AI Hiring Lawsuit Means for Every ATS
Mobley v. Workday allowed claims against an AI hiring vendor to proceed. What the case raises about delegated screening functions and oversight.
Ernest Bursa
In Mobley v. Workday, a federal court allowed some discrimination claims against the hiring software vendor to proceed on an agency theory. This was not a finding that Workday discriminated or is liable; Workday denies wrongdoing. The case concerns the hiring functions allegedly delegated to the vendor, not a rule making every ATS vendor an employer’s agent.
For ATS buyers, the practical question is what the software actually does, who can oversee its use, and which duties each party carries. Human review and documentation can support that work without guaranteeing legal protection.
This article is general information, not legal advice. Talk to employment counsel about your specific situation.
The lawsuit that put every ATS on notice
Mobley v. Workday is a federal lawsuit alleging that Workday’s AI-based applicant-recommendation system disproportionately screens out applicants by age, race, and disability. It matters to every hiring team because a court has now allowed the case to proceed against the software vendor itself, not only the employers.
The opt-in deadline for the notice stage was March 7, 2026. Procedural decisions allowing claims to proceed must be distinguished from findings on the merits.
What is Mobley v. Workday?
Mobley v. Workday is a discrimination lawsuit filed in 2023 by Derek Mobley, who alleged that Workday’s AI screening tools rejected him from roughly 100 job applications, claiming a near-zero success rate getting past the initial automated screen. He sued under Title VII, the Americans with Disabilities Act (ADA), and the Age Discrimination in Employment Act (ADEA).
Two rulings made the case a landmark:
- July 12, 2024: the court let claims proceed that Workday, a software vendor and not the employer, can be held directly liable as an “agent” of its employer-customers.
- May 16, 2025: the court conditionally certified a nationwide ADEA collective action covering “all individuals aged 40 and over who, from September 24, 2020 through the present, applied for job opportunities using Workday’s job application platform and were denied employment recommendations.”
The scale is staggering. In court filings, Workday represented that 1.1 billion applications were rejected using its tools during the relevant period, and the court acknowledged the collective could reach “hundreds of millions” of people.
One critical caveat: Workday denies wrongdoing, and the procedural orders described here are not findings of liability. Nothing here says Workday discriminated. What the court did was decide these claims are plausible enough to go forward, and that the vendor cannot hide behind “we just sell software.”
The “agent” theory: why your vendor can be liable
The legal core of the case is the “agent” theory, and it is the part every ATS buyer should understand. Federal anti-discrimination statutes reach not just employers but their “agents.” The question was whether a software vendor can be an agent. The court said yes, when the software makes or recommends the reject-or-advance decision.
Judge Rita Lin held that the complaint “plausibly alleges that Workday’s customers delegated their traditional function of rejecting candidates or advancing them to the interview stage to Workday.” The legal upshot is direct: when a vendor’s software performs the screening decision, the vendor steps into the employer’s shoes for discrimination liability.
How this differs from “it’s just a tool”
The court drew a sharp line between a passive tool and an active decision-maker. A spreadsheet that stores applicant data is a tool. Software that ranks candidates and recommends who to reject is something else. As the court put it, “Workday does qualify as an agent because its tools are alleged to perform a traditional hiring function of rejecting candidates at the screening stage and recommending who to advance.”
This is the design pattern on trial. The risk is not “using AI in hiring.” The risk is delegating the human judgment of who advances to a black box that nobody can explain, audit, or override. If your ATS auto-rejects applicants with no human review and no decision record, you have recreated the exact fact pattern the court found plausible enough to litigate, and your vendor may now share liability with you.
It’s not just Workday: Eightfold and the FCRA front
The Workday case opened the door, and other theories are walking through it. On July 7, 2025, the court expanded the Mobley collective to include applicants processed using Workday’s HiredScore AI features, and ordered Workday to identify customers who enabled them. The scope keeps widening.
A separate case opens an entirely new legal front. In Kistler et al. v. Eightfold AI Inc., filed January 20, 2026 in California and removed to federal court, plaintiffs allege Eightfold’s model scrapes “billions of data points” to produce hidden candidate “reports” and rankings. The claimed violation is not discrimination law at all. It is the Fair Credit Reporting Act (FCRA) and California’s ICRAA, the laws that govern consumer reports.
The framing is memorable: a candidate ranked on “likelihood of success” using scraped web and social data they never saw may be the subject of a consumer report used for employment, which is not necessarily a credit report. Whether a particular product falls within the statutes is a legal question. FCRA requires disclosure, consent, and a right to dispute. An AI screening tool that ranks people on data they cannot see or correct now faces a second, independent liability theory.
Lessons from EEOC v. iTutorGroup
None of this is hypothetical. In a consent decree approved in September 2023, iTutorGroup paid $365,000 to settle EEOC claims that its hiring software automatically rejected female applicants aged 55 or older and male applicants aged 60 or older. It was widely called the EEOC’s first AI-hiring discrimination settlement.
The EEOC alleged that iTutorGroup programmed the age-based rejection rules. This example concerns automated rules, not necessarily a language model, and does not establish that discriminatory automation is unintentional.
The bias is real, and it’s measurable
The legal theories rest on a factual claim: that AI screening tools produce biased outcomes. The strongest evidence is not anecdotal. It is experimental.
A 2025 Brookings study tested AI resume screening across three large language model embedding systems, comparing roughly 554 resumes against 571 job descriptions, generating about 40,000 comparisons per model. The results were stark:
- White-associated names were preferred 85.1% of the time, versus 8.6% for Black-associated names.
- Men’s names were favored 51.9% of the time, versus 11.1% for women’s names.
- In the harshest intersectional comparison, Black men’s resumes were selected 0% as often as white men’s.
The point of a name-swap study is that the only thing changing is the name. The bias lives in the model, not the user. Which means an employer who trusts an unaudited AI screen is not removing human bias. They are scaling a different bias and stripping out the human judgment that might have caught it.
The regulatory squeeze: EU AI Act and the US state patchwork
Even as federal US enforcement softened, the law tightened elsewhere. Hiring teams now face a patchwork that varies by where their applicants live, not just where the company is headquartered.
The EU AI Act classifies recruitment and candidate-selection AI as high-risk. High-risk obligations include risk assessment, documentation, bias testing, human oversight, and transparency, with fines up to EUR 15 million or 3% of global turnover. It applies extraterritorially to anyone whose AI output affects people in the EU. Update, September 6, 2026: the AI Omnibus entered into force on July 27, 2026, moving Annex III high-risk obligations to December 2, 2027. See the European Commission update.
US states are not waiting. As of mid-2026, the map includes:
| Jurisdiction | Requirement | Status |
|---|---|---|
| New York City (Local Law 144) | Annual independent bias audit plus 10-business-day applicant notice for automated employment decision tools | In effect |
| Illinois (HB 3773) | Amends the Human Rights Act; notice of AI use in employment | Effective Jan 1, 2026 |
| Colorado (SB 24-205) | High-risk AI rules for consequential decisions | Effective June 30, 2026 |
Federal rollback is not a safe harbor
It is tempting to read the 2025 federal pullback as permission. The EEOC removed its AI guidance documents in January 2025, and Executive Order 14281 directed agencies to deprioritize disparate-impact enforcement that April. But removing guidance does not repeal the statutes. Title VII, the ADA, and the ADEA still create private rights of action, and those private suits are exactly the engine driving Mobley. The risk shifted from regulators to litigants and the states. It did not go away.
Opaque auto-discard vs. a defensible AI hiring stack
Here is the reframe that matters: AI in hiring is not the liability. Opaque, unaccountable AI in hiring is the liability. The Workday and Eightfold pattern, the auto-discard pipeline with no human and no record, is what courts are scrutinizing. The defensible alternative is an AI-native ATS that is explainable, human-in-the-loop, logged, and disclosed by design.
Six design principles separate the two:
- Explainable scoring. Candidates are scored against named, human-defined criteria, not a hidden model. You can show your work.
- Human-in-the-loop. A person makes the reject-or-advance call. AI assists; it does not decide.
- Decision logging. Every rejection captures a reason. Overrides require a structured justification. You build a defensible trail as you go.
- Reversibility and cool-off. Rejections are not instant and irreversible. There is a window to catch mistakes.
- Disclosure. Candidates are told AI assists in screening, in line with NYC Local Law 144 and EU AI Act transparency.
- Bias testing. Scoring outputs can be exported and checked for adverse impact, periodically, not just when you get sued.
If you are evaluating an AI-native ATS, these six principles are your checklist. Ask any vendor to demonstrate each one. The ones that cannot are selling you the design pattern that is currently on trial.
What Kit Provides and What Your Team Must Establish
Kit supports named evaluation criteria, reviews, rejection reasons, and stage history. These records help reconstruct a process; they do not establish fairness or legal compliance by themselves.
Automation depends on configuration. Voting and stage conditions can trigger further actions, and authorized AI tools through MCP can change applications. Kit should not be described as read-only AI with a separate human click guaranteed before every state change.
Kit supports reversing rejections and delaying rejection notifications. A notification delay does not postpone the rejection state itself. Check permissions and process settings before enabling automation.
Your team must establish retention, access, export, candidate notices, and oversight procedures. Database records are not a guarantee of immutable archives or a statutory retention period. Product features do not provide a legal safe harbor, conformity certificate, or completed bias audit.
A practical checklist for any AI-native ATS
Whatever tool you use, you can reduce your exposure today. Run your current stack against this list:
- Explainable scoring. Can you produce, for any candidate, the criteria and scores that drove the decision? If the answer is “the model decided,” that is the problem.
- Human-in-the-loop at the reject gate. Does a person review before anyone is auto-rejected? Auto-advance is far less risky than auto-reject.
- Decision logs. Is there a durable record of why each candidate was rejected, including any override?
- Cool-off and reversibility. Can you catch and reverse a mistaken rejection before it reaches the candidate?
- Disclosure. Do you tell candidates that AI assists in screening, where the law requires it?
- Periodic bias testing. Can you export scoring data and run an adverse-impact check by age, race, and gender?
- Vendor terms. Does your contract address who is liable if the tool produces biased outcomes?
Fair, structured evaluation is not only a legal posture. It is also a better hiring process, the same reason structured code assignments beat gut-feel interviews and why ethical, candidate-respecting recruiting wins better candidates.
The takeaway
Mobley v. Workday did not outlaw AI in hiring. It made one thing clear: if your software decides who gets rejected, and nobody can explain or override that decision, your vendor and your company share the exposure. The defensible path is not to abandon AI. It is to keep a human accountable, make the scoring explainable, log the decisions, and disclose the tooling. The bias is real and measurable, the regulatory squeeze is tightening across the EU and the states, and the federal rollback is not a safe harbor.
Build the auditability in from the start, and AI becomes an asset in your hiring, not a liability waiting for a subpoena.
If you want to see what human-in-the-loop, explainable hiring looks like in software, start a free trial of Kit and walk a candidate through the pipeline yourself.
Related articles
Try Kit for 30 days.
Hiring, security reports, and training in one account, for teams where none of it is a full-time job. Free for 30 days, card required. Cancel before it ends and you pay nothing.
Get started free