For years, criticism of AI hiring tools lived mostly in white papers, op-eds and "AI bias" thought pieces — real concerns, but abstract ones, argued in the register of "here is what could go wrong." In 2026, two live federal cases moved that argument out of the hypothetical. Neither is really about whether an algorithm can be biased in the abstract. Each is about a specific, narrow legal theory, tested against a specific product, in front of a specific judge, with rulings that survived a motion to dismiss. That distinction matters more than it sounds: a complaint is an allegation, but a complaint a judge refuses to throw out is now the law's opinion that the theory might be right, which is a different thing entirely — it opens discovery, and it is what other plaintiffs' lawyers read before filing their own.
The two cases worth understanding — Mobley v. Workday, Inc. and Kistler v. Eightfold AI Inc. — don't overlap much. They attack two different layers of the same kind of product: one goes after what the system does with an applicant's data before anyone sees a score, the other goes after what the system does once it has one. Together they sketch a fuller map of where AI hiring tools are legally exposed than either case does alone.
Mobley v. Workday: the "we just sell the tool" defense didn't fully hold
Mobley v. Workday, Inc., case no. 3:23-cv-00770 in the Northern District of California, has been running since 2023, brought by job applicant Derek Mobley against Workday's applicant-screening tools on behalf of a proposed class. Workday's core defense was structural, not factual: it isn't the employer, it doesn't make hiring decisions, it licenses software to companies that do — so employment discrimination law, written for employers, shouldn't reach a vendor.
On March 6, 2026, U.S. District Judge Rita Lin rejected the cleanest version of that argument. Ruling on Workday's motion to dismiss, she held that applicants can bring disparate-impact age discrimination claims against Workday under the Age Discrimination in Employment Act, declining Workday's argument that Congress's history of unsuccessful attempts to extend the ADEA to job applicants meant the statute didn't cover them. Disparate impact is the theory that matters here — it doesn't require proof that anyone intended to screen out older applicants, only that a facially neutral practice (an algorithmic ranking) produced that effect. According to reporting on the order from HR Dive and the Civil Rights Litigation Clearinghouse's case docket, the ruling was a partial win for both sides: several claims survived, others didn't, and the court set a deadline for plaintiffs to amend.
Plaintiffs did, on March 30, 2026, refiling California state-law and disability-discrimination claims the original complaint hadn't pleaded well enough. That amendment paid off: on June 22, 2026, Judge Lin ruled again, this time allowing an Americans with Disabilities Act claim to proceed for a plaintiff alleging Workday's tools discriminated against her on the basis of asthma and cancer survivorship, and allowing California Fair Employment and Housing Act claims to proceed as well, per HR Dive's coverage and the Duane Morris analysis of the order. Her reasoning on the state-law reach is worth sitting with: because Workday is headquartered in California and its screening AI is designed and maintained there, she found a "sufficient nexus" to California for FEHA to apply — to applicants who may never have set foot in the state, rejected by an employer that may not be based there either. If that reasoning holds up, an AI hiring vendor's home jurisdiction, not the employer's, can end up supplying the applicable law.
Strip away the docket detail and the throughline is: a company that built and hosts the scoring system, but never itself decided to reject anyone, is now defending discrimination claims on the merits, under two different statutory theories, in two different rulings, eight months apart. "We just provide the tool" was a real defense, argued by real lawyers, and it did not make the case go away.
Kistler v. Eightfold AI: a different theory, aimed at a different part of the pipeline
Kistler v. Eightfold AI Inc. is a separate case, filed by a different set of plaintiffs, in a different court, over a different legal theory entirely — and that's the point. Erin Kistler and Sruti Bhaumik, represented by Outten & Golden and Towards Justice, filed the proposed class action on January 20, 2026, in California's Contra Costa County Superior Court; Eightfold removed it to the Northern District of California on March 2, 2026 (case no. 3:26-cv-01768), where it sat at the pleading stage as of this spring, per reporting from Akin Gump, Jones Walker and CDF Labor Law's AI litigation trackers, among others.
The allegations, as reported: Eightfold's platform compiled data on job applicants — not only what candidates submitted, but information pulled from social media profiles, location signals and online activity — scored each applicant on a zero-to-five scale, and in some workflows filtered out low scorers before a human reviewer ever saw them. The claim isn't that the scoring was inaccurate or biased. It's that the Fair Credit Reporting Act, and California's parallel Investigative Consumer Reporting Agencies Act, already have a category for a company that compiles a third party's personal information into a report used for an employment decision: a consumer reporting agency. That status comes with specific obligations — disclosure that a report is being compiled, consent, and a process for the subject to see and dispute what's in it. The complaint alleges Eightfold did none of that. One legal commentary summarized the theory sharply: this case doesn't argue the algorithm was unfair, it argues the algorithm operated in secret.
That's a genuinely different attack surface from Mobley. FCRA and its state cousins don't care whether a scoring model is well-calibrated or whether its outputs correlate with protected characteristics — they regulate what happens before a score exists: where the underlying data came from, and whether the person it describes knew and consented. A hiring tool could have a scrupulously fair, well-documented, statistically unremarkable scoring model and still lose a case built on this theory, if it built that model's inputs from data the applicant never knowingly gave it.
Two tests, and a vendor can pass one and fail the other
Put the two cases side by side and a hiring platform's legal exposure splits into two questions that don't answer each other:
- Once you have a score, what happens to it? Is a below-threshold candidate automatically rejected, at scale, by the same criteria applied to everyone — the exact fact pattern that makes a disparate-impact theory like Mobley's plausible? Or does a human make the final call?
- Before you have a score, where did the inputs come from? Only what the applicant typed into your form, or data compiled from elsewhere without the applicant's knowledge — the fact pattern Kistler is testing under consumer-reporting law?
A vendor can build a genuinely careful answer to question one — transparent criteria, consistent process, a human in the loop — and still be exposed on question two if it sources applicant data from outside what the applicant provided. The reverse is just as true. Neither case's outcome will settle the other's question, because they're not the same question.
What this means for anyone evaluating an AI hiring tool — including us
We'd rather be specific about our own platform here than vague, and we'd rather be specific about the limits of what specificity proves.
On question one — what happens after scoring — NiceHire's screening stages score every candidate against the same fixed criteria: technical, communication and cultural fit, each out of 100, against a threshold an organization configures itself. Every applicant to a role is asked from the same defined question set in the same order (the AI interviewer can ask follow-ups or rephrase a question on request, but it isn't drawing from a different pool of questions candidate to candidate). And when a candidate scores below the configured threshold, the default is not automatic rejection — it routes to pending review for a human to decide, with auto-rejection available as an opt-in a hiring team can turn on per stage, not a default we ship.
We're stating that as a description of how the product is built, not as a legal opinion about Mobley, Kistler, or any other case, and not as a claim that this makes an employer's use of our platform immune from a disparate-impact theory — no vendor gets to make that determination about its own product. NYC Local Law 144 already requires an independent bias audit for automated employment decision tools precisely because self-assessment by the company that built the tool isn't considered credible evidence of fairness, and we agree with the premise: a company describing its own mechanism is not the same thing as a third party auditing its outcomes, and we're not going to blur that line by calling a design choice a guarantee.
On question two — data provenance — the honest answer is that this is exactly the kind of question every organization evaluating an AI hiring vendor should now be asking directly, in writing, before signing anything: does this platform score me on what I submitted, or on things it gathered about me elsewhere? Get the answer in the contract, not the sales deck.
The practical list
If your organization is procuring or already running an AI hiring tool, both of these cases are still developing — expect rulings, not final verdicts, for a while yet. But the questions they've already put in play are ones a procurement process can ask today:
- Default behavior at the rejection point. Does the system reject automatically at scale, or does a human make the final call on anyone the algorithm would otherwise screen out? Ask for the actual default, not the marketing description of it.
- Data provenance. Is every input to the score something the candidate knowingly provided, or does the vendor compile data from other sources? If the latter, ask specifically whether the vendor treats itself as a consumer reporting agency and follows FCRA's disclosure and dispute procedures — Kistler is the fact pattern for what happens when a company doesn't.
- Consistency of process. Is the same defined evaluation applied to every applicant for a role, or does the process vary in ways that would be hard to explain after the fact?
- Whose jurisdiction governs. Judge Lin's "sufficient nexus" reasoning in Mobley is a reminder that a vendor's home state's employment law may end up applying to a hire made somewhere else entirely. Ask where the vendor is headquartered and where its models are built and maintained — it may matter more than where your company is.
- What "audit" actually means. A vendor's own description of its scoring mechanism, however detailed, is not the same as an independent bias audit. If a law in your jurisdiction requires the latter, a data sheet from the vendor does not satisfy it.
Neither Mobley nor Kistler is resolved. Both are worth tracking, because the theories that survive a motion to dismiss this year are the theories other plaintiffs will file on next year — and the fastest way to end up as next year's case is to not have asked these questions this year.
Sources: HR Dive — Workday plaintiffs submit amended complaint; HR Dive — Workday can't shake California AI discrimination claims; Civil Rights Litigation Clearinghouse — Mobley v. Workday, Inc. docket; Duane Morris — motion to dismiss ruling analysis; Akin Gump — Kistler et al. v. Eightfold AI Inc.; Jones Walker — what the Eightfold lawsuit means for employers; CDF Labor Law — AI litigation boundaries; Law.com Radar — Kistler v. Eightfold AI Inc. case card.
Ready to transform your hiring?
See how NiceHire's AI-powered hiring platform works for your team.
Get Started