Mobley v. Workday: AI Hiring Bias Goes to Court
Mobley v. Workday is a federal lawsuit alleging that Workday's AI-powered applicant screening tools discriminated against job seekers based on race, age, and disability. Filed in the Northern District of California, the case matters because a judge allowed it to proceed on the theory that Workday can be held liable as an "agent" of the employers that use its software, not just as a neutral vendor. In May 2025, the court granted conditional certification of a nationwide collective action for the age-discrimination claims, expanding the matter from one plaintiff to a group Workday itself estimated could reach hundreds of millions of rejected applicants.
The case is the clearest test yet of whether the company that builds and sells hiring algorithms carries legal exposure when those algorithms produce discriminatory outcomes. For executives deploying AI in recruiting, the answer reshapes how vendor contracts, audit obligations, and compliance budgets should be built.
What is the Workday AI bias lawsuit about?
Derek Mobley, the named plaintiff, applied to more than 100 jobs over roughly seven years through employers that use Workday's applicant-tracking and screening software. He is Black, over 40, and has anxiety and depression. He says he was rejected from every position, often within hours or minutes of applying, and alleges that Workday's algorithmic tools screened him out in a pattern that tracks his protected characteristics.
The legal claims rest on three federal anti-discrimination statutes:
Title VII of the Civil Rights Act of 1964 prohibits employment discrimination based on race, color, religion, sex, and national origin.
The Age Discrimination in Employment Act (ADEA) protects workers 40 and older.
The Americans with Disabilities Act (ADA) prohibits discrimination against qualified individuals with disabilities.
The core theory is disparate impact: a facially neutral screening tool can violate these laws if it produces a statistically worse outcome for a protected group and the employer cannot show the criteria are job-related and consistent with business necessity. Mobley argues that Workday's tools, trained on historical hiring data, learned and reproduced the biases embedded in that data.
Why does Workday's role as a vendor matter?
Most discrimination suits target the employer who made the hiring decision. Mobley v. Workday is different because it names the software vendor itself as a defendant. Workday's defense argued it is not an "employer," "employment agency," or "agent" under the relevant statutes, and therefore cannot be liable for hiring decisions its customers make.
The court rejected that framing for the agency theory. The judge reasoned that when an employer delegates a core hiring function, such as screening and rejecting applicants, to a vendor's algorithm, the vendor can act as the employer's agent and inherit the legal duties that come with that function. The EEOC, which backed the agency theory in an amicus brief, drew an analogy to tax-preparation rules: software can count as a tax preparer when it does more than provide mechanical assistance. By the same logic, a tool that decides which applicants advance is doing more than assisting. This is the holding that gives the case weight beyond its specific facts. If Workday performs the rejecting, Workday can be sued for how it rejects.
The distinction the court drew is between a tool that hands an employer information and one that exercises judgment the employer would otherwise exercise itself. A system that scores, ranks, and filters candidates and returns a subset the employer is steered to advance participates in the decision. That reading does not depend on any feature of Workday's product; it turns on what the software is functionally doing, so any vendor whose tool performs the same screening function faces the same exposure.
How did the court rule in Mobley v. Workday?
The case was filed in the Northern District of California in 2023 and has moved through several rulings. The procedural history matters because each step widened the exposure.
Stage: Complaint (2023)
What happened: Mobley filed a lawsuit against Workday alleging discrimination through AI-based candidate screening.
Why it matters: It became the first major lawsuit to directly name an AI vendor for alleged hiring discrimination.
Stage: First dismissal
What happened: The court dismissed the initial complaint but granted Mobley permission to amend it.
Why it matters: The ruling indicated that the legal claims could potentially succeed if supported by a stronger complaint.
Stage: Ruling (July 2024)
What happened: The court allowed the case to proceed under an agency theory.
Why it matters: The decision established that an AI vendor could potentially be treated as an employer's agent for discrimination claims.
Stage: EEOC involvement
What happened: The EEOC filed an amicus brief supporting the agency theory.
Why it matters: The federal employment regulator endorsed the legal framework allowing AI vendors to face potential liability.
Stage: Conditional certification (May 2025)
What happened: The court conditionally certified a nationwide collective action under the Age Discrimination in Employment Act (ADEA).
Why it matters: The case expanded from a single plaintiff to a collective action representing applicants aged 40 and older.
The July 2024 ruling is the doctrinal turning point: it let the disparate-impact claims for race, age, and disability proceed on the theory that Workday could be liable as an employer's agent rather than a neutral vendor. The May 2025 conditional certification then scaled the matter. Other applicants over 40 who were rejected through Workday's tools can be notified and opt in. In its filings, Workday represented that more than a billion applications were rejected through its tools during the relevant period, so the collective could reach hundreds of millions of members. This certification is procedural and ongoing, not a final judgment, but it converts a single-plaintiff dispute into systemic litigation risk.
What is disparate impact and why is it the center of the case?
Disparate impact is a discrimination theory that does not require proof of intent. A plaintiff shows that a neutral practice, here an algorithmic screen, falls more harshly on a protected group. The burden then shifts to the defendant to prove the practice is job-related and consistent with business necessity, and even if it clears that bar, the plaintiff can still win by showing a less discriminatory alternative existed.
This theory fits AI screening tools because:
Models train on historical hiring data that already reflects who was hired and promoted in the past.
A tool built to find candidates who resemble past successful hires will reproduce the demographic profile of past hires.
The output looks objective and data-driven, which can hide the bias built into the training set.
The mechanics of how a training set can encode bias are covered in more depth in our analysis of how AI resume screening introduces bias.
Why does Mobley v. Workday matter for companies using AI in hiring?
The case changes the risk calculation for both the vendors who build hiring AI and the employers who buy it. Neither can assume the other absorbs all the legal exposure.
For employers, the longstanding rule still holds: you are responsible for your hiring outcomes even when a third-party tool produces them. EEOC technical guidance states that an employer using an algorithmic decision tool can be liable under Title VII if the tool causes a disparate impact, and that the employer generally cannot shift that responsibility to the vendor.
For vendors, Mobley removes the assumption of immunity. The agency theory means a tool provider can be pulled directly into litigation, face discovery into its model design and training data, and bear settlement or judgment costs.
What would vendor "agent" liability mean for AI screening companies?
If the agency theory holds through a final judgment, the consequences for screening vendors are broad. None are settled, because the case is still being litigated, but the exposure they describe already shapes how careful vendors operate.
Direct naming in suits. A vendor becomes a named defendant rather than a third party the employer points to, which changes who pays for defense counsel.
Discovery into the model. A vendor sued as an agent can be ordered to produce training data, feature lists, scoring logic, and validation studies, so material treated as proprietary becomes evidence.
Aggregated exposure across customers. A single screening engine used by thousands of employers can generate one consolidated claim, the dynamic the ADEA collective here illustrates.
Audit pressure. The absence of a bias audit becomes a fact a plaintiff can use, so vendors that cannot show they tested for adverse impact carry more risk than those that can.
What is the legal and regulatory backdrop?
Mobley does not stand alone. It sits inside a fast-moving body of law and enforcement aimed at automated employment decisions:
NYC Local Law 144 requires employers using automated employment decision tools to conduct an independent bias audit and publish the results. Enforcement began on July 5, 2023.
EEOC technical guidance under Title VII and the ADA confirms that AI hiring tools are subject to existing anti-discrimination law and that disparate-impact analysis applies.
The EU AI Act classifies AI systems used in employment, including recruitment and candidate evaluation, as "high-risk" under Annex III, triggering conformity, documentation, and human-oversight obligations.
The Illinois Artificial Intelligence Video Interview Act, effective January 2020, requires notice and consent when AI analyzes video interviews.
The Colorado AI Act (SB 24-205) establishes consumer protections against algorithmic discrimination in high-risk AI systems, including those used in employment decisions.
Enforcement actions outside the courtroom point the same direction. The iTutorGroup EEOC settlement (2023) resolved claims that recruiting software automatically rejected older applicants, and the company agreed to pay $365,000. Years earlier, Amazon scrapped an internal AI recruiting tool around 2018 after finding it down-ranked resumes that included signals associated with women, such as the word "women's." Neither set binding precedent on vendor liability, but both show that biased hiring algorithms produce real consequences.
How can executives reduce AI hiring discrimination risk?
The defensible position is not to abandon AI in recruiting. It is to govern it the way any high-stakes decision system gets governed: with testing, documentation, and accountability that holds up under discovery.
What should a compliance program for hiring AI include?
A practical program addresses the tool, the contract, and ongoing monitoring. The table below maps common gaps to the controls that close them.
Risk area: Disparate impact in screening.
Control to put in place: Perform a four-fifths rule or other statistical adverse impact analysis before deployment and continue monitoring throughout the model's lifecycle.
Risk area: Unaudited third-party tools.
Control to put in place: Require vendors to provide independent bias audit results as part of contractual obligations.
Risk area: Opaque model logic.
Control to put in place: Obtain documentation describing the training data sources, features used, model behavior, and known limitations.
Risk area: No human review.
Control to put in place: Ensure a qualified human reviews adverse employment decisions and has genuine authority to override AI recommendations.
Risk area: Jurisdiction-specific rules.
Control to put in place: Map compliance obligations under NYC Local Law 144, Illinois laws, the Colorado AI Act, and the EU AI Act to every location where hiring occurs.
Risk area: Vendor finger-pointing.
Control to put in place: Include indemnification provisions and audit cooperation requirements in vendor contracts to clearly define compliance responsibilities.
What are the immediate next steps for a hiring team?
For organizations that already use or plan to use AI in recruiting, the priority actions are concrete:
Inventory every automated tool touching the hiring funnel, including resume parsers, sourcing tools, video-interview analyzers, and ranking algorithms.
Request bias-audit documentation from each vendor and treat its absence as a red flag.
Run an internal adverse-impact analysis on your own hiring outcomes by race, sex, age, and disability status where data allows.
Document business necessity for any screening criterion that produces a demographic skew you decide to keep.
Insert a human decision-maker into adverse-action steps and train that person to override the tool when warranted.
Review vendor contracts for audit cooperation, indemnification, and data-access rights you would need if you were sued.
Track the litigation so your policy moves with the law rather than behind it.
Frequently asked questions
Is Mobley v. Workday a class action?
Not in the traditional sense. In May 2025 the court granted conditional certification of a collective action under the Age Discrimination in Employment Act, which uses an opt-in mechanism rather than the opt-out class structure of a Rule 23 class action. Applicants 40 and older who were rejected through Workday's tools can receive notice and choose to join. The race and disability claims proceed on their own tracks.
Did Workday lose the lawsuit?
No. As of this writing the case has not been decided on the merits. The notable rulings are procedural: the court refused to dismiss the case and allowed it to proceed on the theory that Workday can be an employer's agent. Workday denies that its tools discriminate. A ruling that a case may continue is not a finding that the defendant did anything unlawful.
Can an AI vendor be sued for hiring discrimination?
Mobley v. Workday indicates yes, at least under the agency theory the court accepted. When an employer delegates a core hiring function such as screening to a vendor's algorithm, that vendor can be treated as the employer's agent and held to the same anti-discrimination duties. This breaks from the assumption that software providers are shielded from employment-discrimination claims.
Does using an AI hiring tool transfer my legal liability to the vendor?
No. EEOC guidance is direct on this point: an employer remains responsible for discriminatory hiring outcomes even when a third-party tool produces them. Mobley adds that the vendor may also face liability, but that does not subtract the employer's. Both can be on the hook at once, which is why contractual indemnification and independent auditing matter.