When You Outsource The Process But Not The Risk
Why TA should care that the next headline lawsuit could have their company’s name on it
There’s a conversation happening in TA leadership meetings right now that sounds something like this: “Our ATS uses AI to rank candidates but we use x vendor, so we’re fine.”
But it might not be fine and many organisations are oblivious, because they haven’t actually checked.
Recruitment has quietly become one of the most algorithmically-mediated functions in the business, and yet one of the least audited. That combination is not sustainable mainly because it is increasingly illegal.
The lawsuit that should be on every TA leader’s desk
Mobley v. Workday is a critical case based on allegations that Workday’s AI-driven applicant screening tools systematically discriminate against job seekers on the basis of age (over 40), race, and disability. The class action maintains that ATS are automatically rejecting qualified candidates before a human ever sees them. They claim that proxy bias embedded into the system replicates user preferences of the organisation. The case is important not because Workday is uniquely at fault, but because it establishes a principle regulators and plaintiffs’ lawyers are now actively testing. The outcome could be that the customer (the employer using it) is still liable for the downsides of a vendor’s AI tool.
If the system discriminates, the company that deployed it is exposed, regardless of who built the algorithm.
The impact of this will depend on your role. If you’re in TA leadership, it means
“we outsourced the process, not the liability.” If you’re in legal or compliance, it means your vendor contracts and your actual audit trail are about to matter a great deal more than they used to.
It’s bigger than resume screening
Recruitment platforms now have the capability to rank candidates before a recruiter ever opens an application. This is not to say that an algorithm rejects a candidate before a human sees a CV, because ATS are programmed by people. Recruiters insist they check all levels of resumes regardless of how they are ranked, but as they are increasingly inundated by huge numbers of CVs - do they check every single one? If am not so sure. I have colleagues reporting 4000 submissions for one open role.
Not unsurprisingly, talented people increasingly think they are being filtered out by something they can’t see, argue with, or appeal to. This narrative is not helped by unscrupulous “career coaches” who prey on this concern to sell ATS “optimised” resumes.
Other platforms have been accused of allegedly scraping candidates’ social media activity to construct hidden “suitability scores” that quietly shape who gets forward momentum. This has already triggered legal action, and, just as damaging in the long run, is the measurable erosion of candidate trust.
And the exposure doesn’t stop at the point of hire. Generative AI is now drafting performance feedback, recommending learning pathways, and shaping workforce planning decisions. Early signals suggest not everyone is being treated equitably here either, particularly in who gets access to upskilling opportunities.
So it’s not just about how an employee is doing now, but how they are projected to perform by an algorithmic assessment.
Predictive models are identifying “high-potential” employees using historical data that may itself encode whose potential got recognised in the past. And productivity measurement tools used to inform layoff decisions are, in some documented cases, failing to account for authorised leave of absence taken by employees in protected groups, turning a legally protected leave into an unintended risk factor for job loss.
The pattern underneath all of this
Algorithms are no longer administrative back-office tools managing processes and quietly sorting resumes and other digital files into folders. Without human oversight they have the potential to shape who is hired, promoted, developed, heard, and, in the case of layoff and investigation tools, which employees are protected. Many are losing trust in decisions they have no ability to appeal, because increasingly, there’s no human decision to question. It’s hard to argue with an AI score.
This is a structural problem because in most organisations, governance frameworks were never designed for a workplace where decisions are made by machines. DEI policy, employee relations processes, grievance procedures, even most compliance training, all of it assumes a human decision-maker at the point of judgment. That assumption is now not always correct at key points in people’s careers when they can matter most.
DE&I 2.0
The result is a widening gap between how organisations say they manage fairness and accountability, and how workplace decisions are actually being reached. That gap is exactly where lawsuits, regulatory findings, and reputational damage live.
This is why DE&I needs to evolve into what I’d call DE&I 2.0 : an approach that builds on traditional DE&I foundations but extends governance beyond human behaviour to cover algorithmic decision-making, auditing model outputs for disparate impact, building appeal routes for AI-influenced decisions, and holding vendors to the same scrutiny as internal processes. It’s not a rebrand of DE&I; it’s an extension of it to cover decision-makers that aren’t human.
This isn’t only a legal problem, it’s a trust problem
After years spent helping organisations build genuinely inclusive workplaces, what’s striking now is how easily the human consequences get lost in the technical conversation. It’s easy to talk about audit methodologies and four-fifths ratios
More importantly we need to be checking if any qualified person may have been silently filtered out of a job they were right for. Or if someone may has been denied a stretch opportunity they were eligible for because a model didn’t recognise their potential. We have to factor in if someone on protected leave was highlighted as as a “productivity risk” when they were on maternity leave because the layoff model doesn’t have access to that information.
These aren’t one off cases. As AI agents take on more of the work of recruitment, performance management, employee communications, workforce planning, and even workplace investigations, organisations need governance that assures fairness across both human and machine decision-makers, not governance that quietly stops at the edge of the algorithm.
What “before you’re a headline” actually looks like
The organisations that avoid becoming the next case study won’t be the ones with the most sophisticated AI. They’ll be the ones who can answer these questions with confidence today:
Do we know, precisely, every point in our hiring and talent pipeline where an AI system is making or influencing a decision?
Have we tested those systems for disparate impact with real statistical rigour, not a vendor’s assurance letter?
Can we see individual candidate-level scores, or are we trusting code?
Do candidates and employees know when AI is involved in a decision about them, and do they have a real route to challenge it?
If we were served discovery tomorrow, could we produce an audit trail proving we checked, or would we be explaining why we never looked?
If the honest answer to any of these is “not sure,” that uncertainty is the risk rather than the AI itself, the not knowing.
The bar has quietly shifted from “did we cause harm on purpose” to “did we take reasonable steps to find out if we might be causing harm .” Workday’s case is a preview of what will become standard scrutiny in the next few years and organisations delaying guardrails aren’t postponing the legal risk, only the compliance work. The businesses that won’t be in the headlines are the ones seeing these lawsuits as a warning, rather than “not my problem.”
If your organisation hasn’t yet audited the AI systems shaping who gets hired, promoted, developed, or let go, that’s the starting point. They are not compliance checkboxes, but the first honest look at who the winners and losers are in your system.
If you are not sure where your organisation sits and have no idea what questions to ask - schedule a no-obligation stategy call



