A staffing agency with forty employees licensed a candidate-screening product from a well-known vendor. The product ranked applicants for the agency's clients. It worked, but not quite the way the agency wanted, so the agency's operations director, who was good with the product's configuration tools, spent two weeks adjusting the scoring weights, uploading a few thousand of the agency's past placements as training examples, and renaming the ranked output “TalentMatch Score” for the client-facing reports. Nobody at the agency thought of any of that as building an AI system. They had customized software they paid for, which is what every business does.
That agency has, without meaning to, done three separate things that most 2026 state AI statutes treat as converting a business from the party that uses a tool into the party responsible for having made one. The law calls that classification developer or deployer, and it is the single classification that decides which AI rules apply. It also decides, increasingly, whether your business or your vendor is the one on the hook when the AI produces a discriminatory result.
The situation in September 2026 is that the federal enforcer of hiring discrimination law has quietly stepped back from AI, while state legislatures and private plaintiffs have stepped forward in ways that create more exposure for small businesses using AI hiring tools than existed a year ago. This piece walks through what actually changed, why the shift from federal to state and private enforcement matters more than the headlines suggest, and what to document before your next hiring cycle.
The federal pullback
Under the prior administration, the Equal Employment Opportunity Commission opened an Initiative on Artificial Intelligence and Algorithmic Fairness in 2021, issued technical assistance for employers using AI in 2023, and treated disparate impact from automated screening tools as a live enforcement priority. That posture shifted in April 2025. Executive Order 14281, signed April 23, 2025, directed federal agencies to deprioritize enforcement of statutes and regulations creating disparate impact liability “in all contexts to the maximum degree possible.” By late 2025 the EEOC had removed its AI technical assistance documents. In June 2026 the agency rescinded two longstanding guidance documents on voluntary affirmative action programs.
The federal pullback is real, and it matters at the margins. Businesses that would previously have faced an EEOC investigation for a Title VII disparate impact claim from an AI screening tool are less likely to face one in 2026. What it does not do is repeal the underlying statute. Title VII's disparate impact provisions are codified. Any private plaintiff can still bring a disparate impact claim. Any state agency with its own analog can still enforce one. And AI vendors, as of 2026, are being pulled into those cases as defendants in ways they were not before.
Mobley v. Workday: the vendor as the employer's agent
The most consequential AI-hiring case in the country right now is Mobley v. Workday, in the Northern District of California. Derek Mobley applied for jobs at more than a hundred employers over several years and was rejected by each. He alleged that Workday's applicant-screening product, which those employers were using, was rejecting him because of age, race, and disability in violation of Title VII, the ADEA, and the ADA. Workday's initial defense was that Workday was a software vendor, not an employer, and could not be sued under employment discrimination statutes at all.
The court rejected that defense. In May 2025, the district court granted conditional certification of a nationwide ADEA collective action against Workday on the theory that Workday acted as the employers' agent for purposes of the statute. Subsequent 2026 rulings have refined and extended that theory. The practical result: an AI hiring vendor that plays a decisive role in employment decisions can be sued as an agent of the employer, even though it never technically employed anyone.
That is the doctrine that changes the calculation for a small business using an AI hiring tool. Under the older reading of employment discrimination law, the vendor was one degree removed from the employer, and a plaintiff who wanted to reach the vendor had to plead around that. Under the Mobley reading, the vendor is on the hook alongside the employer for the same claim. That does two things to a small business. It creates a new party the plaintiff can sue, which increases the odds a claim gets filed at all. And it changes what the vendor contract means. If the vendor is going to be a co-defendant, it has a strong interest in shaping the case, which usually means shaping what the employer says and does before and during litigation.
The agency in the opening story crossed it in three ways: by adjusting the scoring weights, by uploading training examples, and by renaming the output for client-facing use. Each of those, standing alone, might be within the deployer role. Together, they moved the agency to the developer side of the line — and made the agency responsible for the underlying system's behavior, not just for using it correctly.
The developer-or-deployer classification and the vendor-as-agent doctrine work in opposite directions. The classification pulls the business toward the vendor's role by counting configuration and customization as development. The agency doctrine pulls the vendor toward the business's role by counting decisive influence as employment. Both pulls end up in the same place, which is that everyone in the chain is exposed.
State laws are the real 2026 story
The federal pullback got the headlines. The state laws did the actual work of expanding exposure. Two are worth understanding in detail because they cover a large share of the country and because they represent the two ways state AI hiring rules typically operate.
Illinois HB 3773 amended the Illinois Human Rights Act effective January 1, 2026. The law makes it a civil rights violation to use AI in a way that has a discriminatory effect on protected classes across the full employment life cycle, from recruitment through termination. It also requires notice to employees and applicants when AI is used in employment decisions. There is a private right of action. The Illinois Department of Human Rights enforces. Penalties include actual damages, attorney's fees, and civil penalties.
Connecticut SB5 regulates automated employment decision tools more broadly, imposing transparency and bias-audit obligations on the deployment of AI in employment decisions. The law is broader in scope than Illinois but includes similar disclosure requirements and creates a similar enforcement structure.
New York City's Local Law 144, which took effect in July 2023, requires annual independent bias audits of automated employment decision tools used to screen candidates. A New York State Comptroller audit released in December 2025 found significant enforcement gaps — many employers subject to the law had not conducted the required audits, and the city was not systematically pursuing them. The gaps do not repeal the law. They mean that a private plaintiff who wants to make a bias-audit case has a stronger factual predicate now than they did a year ago.
Colorado's SB24-205 was scheduled to take effect earlier in 2026 but was suspended in April 2026 after xAI sued and the Department of Justice intervened; the Colorado situation is fluid and the current status is tracked in real time on the /ai-current page. Beyond Illinois, Connecticut, and New York City, several other states have introduced or enacted AI hiring-adjacent legislation. The compliance picture for a business hiring across state lines is now a genuine patchwork.
The new FCRA theory
The 2026 development that most caught employment lawyers off guard is not a Title VII case. It is a January 2026 putative class action alleging that an AI recruiting and “talent intelligence” company violated the federal Fair Credit Reporting Act, the California Investigative Consumer Reporting Agencies Act, and California's Unfair Competition Law. The theory is that the company assembles public information about candidates from across the web to create a proprietary database, then sells prospective employers reports intended to help evaluate candidates — and that in doing so, the company is creating and selling consumer reports without complying with the laws designed to regulate them.
If that theory succeeds, it opens a second front. FCRA claims do not require proof of discrimination. They require proof that a consumer report was assembled and used without the disclosures and consents the statute requires. AI recruiting tools that scrape public data and build candidate profiles are a natural target. Businesses that use those tools are potential co-defendants if the tools qualify as consumer reporting agencies under FCRA.
The four questions to ask before you sign
Whether you are renewing an AI hiring tool contract or signing a new one, the same four questions determine your real exposure.
One: what is my vendor going to argue if we get sued together? The Mobley line of cases makes vendor and employer co-defendants in the same case. Ask your vendor how they have handled prior discrimination claims filed against customers. Ask whether they will indemnify you for claims arising from the tool's output. Read the answer carefully — most vendor indemnities for AI hiring tools have carve-outs that swallow the rule.
Two: does the vendor conduct the bias audits, or do I? If your vendor conducts the audit and you rely on it, you are exposed if the audit was inadequate. If you conduct your own audit, you have more control over the record. Illinois and NYC do not accept “the vendor said the audit was fine” as a defense.
Three: what does the notice to applicants actually say? Illinois requires notice when AI is used in employment decisions. Connecticut requires disclosure. Your notice should say specifically what AI does in your process — screening, ranking, interviewing, all three — and should be given at a point in the process where a plaintiff cannot argue they were unaware.
Four: what do I document about my decision to use this tool? The defense that works: you looked, you acted, and you can prove it. For an AI hiring tool, the record should show that you evaluated alternatives, that you considered the disparate impact question, that you selected this vendor after that consideration, and that you monitor the output for adverse impact on protected classes. The record does not have to be long. It has to exist.
What actually protects you
If you use an AI hiring tool in 2026, the defense that works is not that you did not know how the tool worked. The defense that works is that you knew enough to make a defensible choice, that you documented the choice, and that you can produce the documentation when the case is filed. That means keeping the vendor's bias audit reports, keeping your own monitoring data, keeping the notice you gave applicants, and keeping a short internal memo explaining why you chose the tool you chose. None of that is exotic compliance work. It is a practical audit, applied to hiring.
Frequently Asked Questions
If we use an AI hiring tool but don't customize it, are we still exposed?
Yes. The customization question decides whether you also count as a developer under some state statutes. Even without customization, you are a deployer, and the deployer role carries obligations under Illinois HB 3773, Connecticut SB5, and NYC Local Law 144.
Does the four-fifths rule still apply under Title VII?
Yes. Title VII's disparate impact provisions are codified. EO 14281 changed federal enforcement priorities. It did not repeal the statute, and private plaintiffs can still bring disparate impact claims.
What states have enforceable AI hiring laws right now?
Illinois HB 3773 (January 1, 2026), Connecticut SB5, and New York City's Local Law 144. Additional states have introduced legislation; check /ai-current for the current picture.
What if our vendor is doing the audits — is that enough?
Not by itself. The vendor's audit is a good input. It is not a substitute for your own record showing that you evaluated the tool, monitor its output, and act when adverse impact appears.
Do these rules apply if I have fewer than fifteen employees?
Title VII applies to employers with fifteen or more employees. The ADEA applies to employers with twenty or more. State laws often have different thresholds. Illinois HB 3773 applies to employers regardless of size in some provisions. Check the specific state statute for the threshold that applies to your business.
For ongoing tracking
For every change to state AI hiring laws, federal enforcement posture, and vendor-liability doctrine since this article went to press, see silvertonpublishing.com/ai-current.
This article reflects the AI hiring regulatory landscape as of September 2026. This area is moving quickly at both the state and federal level. Confirm the current status of any specific law before relying on it, and consult employment counsel before implementing changes to your hiring practices. Nothing in this article is legal advice for your specific situation.
This article is for educational purposes only and does not constitute legal, tax, or financial advice. Consult a qualified professional for guidance specific to your situation.