AI Assurance Institute Logo AI Assurance Institute

Who Can Be Liable - and Why Mobley v. Workday Matters

AI in Recruitment


AI Risk Management

Article 4 of 6

In traditional hiring disputes, the employer is the usual defendant. The employer chose the process, rejected the candidate, and controlled the decision. AI recruitment tools complicate that picture. When a platform scores, ranks or automatically screens applicants for many companies, candidates and regulators start asking a second question: can the software vendor also be liable?

That question is at the centre of Mobley v. Workday, the most closely watched US case on AI hiring discrimination and vendor liability.

The case in brief

Derek Mobley alleges that Workday's AI-powered applicant screening tools discriminated against him and others on the basis of race, age and disability. He says he applied for more than 100 jobs through systems using Workday's technology and was rejected each time, in circumstances he attributes to the screening tools rather than to individual human review by each employer.

Importantly, he sued Workday, the vendor, not only the employers who used the software. Workday's position, in essence, has been that employers control hiring decisions and outcomes. The plaintiffs argue that Workday's tools perform core hiring functions - scoring, sorting, ranking and screening - at scale, and that this makes Workday more than a passive software provider.

Why the court's approach matters

In 2024, a federal court allowed key claims to proceed on the theory that Workday could be treated as an employer or agent for anti-discrimination law purposes because of the role its tools play in screening and referral-like functions. The US Equal Employment Opportunity Commission filed an amicus brief supporting the idea that entities which substantially perform traditional hiring functions through algorithmic tools should not escape the reach of federal discrimination law merely because they are technology vendors.

The case is still ongoing. Discovery disputes, class and collective issues, and the merits of the bias allegations remain contested. Nothing about an intermediate ruling makes Workday finally liable. What matters for organisations watching the case is the liability theory: that the designer and operator of an AI screening system may itself be a proper defendant when that system effectively decides who gets seen by a human and who does not.

If that theory holds, the risk profile of HR technology vendors changes. So does the risk profile of employers who rely on those tools without adequate oversight, contractual protection, or evidence that the system is fair and job-related.

How this differs from iTutorGroup

iTutorGroup was comparatively straightforward. The EEOC alleged that recruitment software was programmed to reject older applicants. The employer/operator context was clearer, and the case settled.

Mobley v. Workday is more structural. It asks whether a widely used platform that sits between candidates and many employers can be accountable under discrimination law for the screening outcomes its AI produces. That is why employers, vendors, insurers and compliance teams are following it even before final judgment.

Points that may prove significant going forward

Even while the case continues, several themes already shape the debate:

Function over labels

Calling a system "software" or "a recommendation engine" may matter less than what it actually does. If it systematically screens people out of contention, courts may treat that as a hiring practice.

Vendor exposure

Vendors may face direct claims, not only contractual disputes with employer customers. That raises the importance of bias testing, documentation, customer controls, and clarity about who can configure thresholds and filters.

Employer residual risk

Even if vendors are drawn into litigation, employers are unlikely to become spectators. They select the tool, set requirements, and often control how automated rejection is used. Discrimination law generally still reaches the entity that denies employment.

Evidence and transparency

Plaintiffs need data on how screening works and who is affected. Defendants resist disclosure of proprietary models and detailed application data. Future cases will likely turn on what records exist, what audits were done, and what can be proven about disparate impact.

Regulatory interest

The EEOC's participation signalled that algorithmic hiring is an enforcement priority under existing discrimination statutes, not only under future AI-specific laws.

How the same split looks under the GDPR

Mobley is a US discrimination case. It is not EU law. The same commercial pattern - one platform scoring candidates for many employers - still has to be allocated under the GDPR.

The employer that opens the vacancy and decides who is hired is normally the controller. The vendor that hosts the scoring engine is normally a processor and may only process candidate data on documented instructions under Article 28. That allocation fails if the vendor determines its own purposes: for example training models on customer candidate data, or setting rejection logic the employer cannot see or change. In those cases the vendor may be a joint controller, or a controller in its own right, for that part of the processing.

Labels in a contract do not settle the point. What matters is who decides the purposes and essential means. A candidate can complain about either party. The employer cannot answer "speak to the vendor" and stop there.

Access requests across a vendor platform

Under Article 15 the candidate usually asks the employer. The request covers the application file, the score or rank, and, where Article 22 is engaged, meaningful information about the logic involved. The vendor, as processor, must assist. If the employer cannot retrieve a score, a feature list or an explanation because the platform will not release it, the processing arrangement is not adequate.

That is the EU version of the evidence fight described above. Plaintiffs in US litigation seek discovery of how screening works. Candidates in the EU can use an access request and, if needed, a complaint to a supervisory authority. Trade-secret claims can limit how much model detail is disclosed. They do not cancel the candidate's right to their own data and to a usable account of how they were assessed.

Provider, deployer and fundamental rights under the AI Act

The AI Act uses different words for the same split. The organisation that places the screening system on the market, or puts it into service under its own name, is the provider. The organisation that uses the system under the provider's instructions is the deployer. Article 25 can treat a deployer as a provider if it puts its name on the system, substantially modifies it, or changes its intended purpose.

Recruitment systems in Annex III are high-risk in the cases the Annex describes. Providers carry the heavier set of duties, including a quality management system under Article 17. Deployers still have Article 26 duties: follow the instructions for use, assign competent human oversight, monitor operation, and keep logs under their control. Neither role is a spectator.

Article 27 requires a fundamental rights impact assessment before first use for specified deployers of Annex III systems: bodies governed by public law, private entities providing public services, and deployers of the credit and insurance systems in Annex III, points 5(b) and 5(c). A private employer is not automatically inside Article 27. Public employers, and private bodies delivering public services, often are. Where a FRIA is required, it must look at the real screening process, including what the vendor's model does and what the employer can still override.

From 9 December 2026 the revised Product Liability Directive also treats software and AI as products. That can put the manufacturer - often the provider - into a strict-liability frame if a defect causes covered harm. The next articles return to what organisations should do, and how these EU regimes sit together with hiring discrimination law.

What to do with an ongoing case

Because Mobley is not finally decided, articles and policies should describe it carefully: allegations, procedural rulings, and contested theories - not as settled law. Its value today is as a warning about the direction of liability arguments.

For employers and vendors, the practical message is already usable. If an AI system materially determines who is rejected or ranked, both the organisation using it and the organisation supplying it should assume that discrimination law may reach the practice. Waiting for a final judgment before examining screening logic, audit trails and human oversight is a choice to carry risk blind.