Nobody Put Age in the Model. The Model Found It Anyway.
Race and sex bias audits are now routine in AI hiring. Age almost never gets its own cut of the data — which is strange, because age is the protected characteristic a resume leaks most reliably. A graduation year is a birth year with a four-year error bar.
Why Age Is the Easiest Protected Class for a Model to Reconstruct
Vendors have spent years scrubbing names, photos, addresses and school names from resumes to defeat race and sex inference. Almost none of that touches age. A resume is, structurally, a dated document. It is a chronological list of when things happened to a person, and the earliest date on it is a very good estimate of when that person entered the workforce.
You do not need a feature called age. A gradient-boosted model with access to the following will find it without being asked:
- Graduation year — the single strongest proxy. Even when the parser drops it, degree sequencing usually restores the ordering.
- Total years of experience — often computed by the parser itself and handed to the ranker as a numeric feature.
- Employer names that no longer exist — a stint at a company acquired in 2004 dates the candidate precisely.
- Legacy technology keywords — COBOL, Flash, ColdFusion, on-prem Exchange, jQuery. The model does not know these are old; it knows they co-occur with candidates the historic data rejected.
- Resume length and formatting conventions — two-page resumes, objective statements, full mailing addresses, aol.com and sbcglobal.net domains.
- Recency of certifications — the absence of a credential earned in the last three years reads as staleness to a model and as age to a plaintiff's expert.
The important part: removing the obvious proxies does not remove the inference. When you strip graduation year, the model reweights onto the correlated remainder. Redaction moves the signal; it rarely deletes it. The only way to know what happened is to measure the output by age band, which requires collecting age data you may have deliberately avoided collecting.
The ADEA Is Not Title VII, and the Difference Cuts Both Ways
Teams that built their bias-audit programme around race and sex tend to assume the age analysis is the same test with a different column. It is not.
Smith v. City of Jackson confirmed disparate-impact claims under the ADEA, and Meacham v. Knolls put the burden of proving a reasonable factor other than age on the employer. So the employer must affirmatively justify the practice — but the standard is reasonableness, not business necessity. A genuinely job-related experience requirement can survive here that might not survive under Title VII.
The statute protects workers 40 and over. A 52-year-old rejected in favour of a 44-year-old can still state a claim — the comparator need only be significantly younger, not outside the protected class. Audits that bucket everyone 40+ into one group will miss exactly this pattern.
Many state fair-employment statutes protect from age 18 or 21, apply to smaller employers than the ADEA's 20-employee floor, and allow damages the ADEA does not. New York, New Jersey and California all reach conduct the federal statute would not.
Gross v. FBL Financial requires but-for causation for intentional age discrimination, which is harder than Title VII's motivating-factor standard. This is why plaintiffs' counsel in algorithmic cases lean on the impact theory — and why your impact numbers are the exposure.
Where the Screening Actually Happens
Most age-bias reviews start at the resume ranker. By then, several earlier filters have already run — and those filters are usually owned by marketing, not HR.
Paid social and programmatic job ads optimise toward users who resemble prior applicants. No age range is selected; the optimiser infers one. Older users simply never see the posting, and they never appear in any applicant-flow report because they never applied.
Recruiter-side AI that surfaces 'similar profiles' to a seed candidate reproduces the seed's demographic profile. Boolean strings with maximum-experience caps or 'recent grad' phrasing do it explicitly.
Application forms that require a graduation year, ask for date of birth for 'background check pre-fill', or hard-fail candidates above an experience ceiling. These are the cleanest documentary evidence a plaintiff can get.
The stage everyone audits. Worth auditing — but if stages 1 through 3 already removed the older applicants, the ranker's output will look clean while the funnel is badly skewed.
Timed cognitive tests, typing-speed gates, and speech-cadence scoring all correlate with age. Timed components additionally raise ADA reasonable-accommodation questions for age-correlated conditions.
A funnel measured only from "application submitted" onward cannot detect stage-one exclusion by construction. If you buy paid distribution for roles, the impression-side demographics are part of your hiring record whether or not you have ever pulled them.
What an Age-Specific Audit Has to Do Differently
Report selection rates for 40–49, 50–59 and 60+ separately against the under-40 rate. A single 40+ bucket routinely hides a severe 55+ effect behind a healthy 41-year-old cohort.
The 80% rule is a screening heuristic, not a legal safe harbour. For small applicant pools it produces false alarms and false comfort in both directions; pair it with a Fisher exact or Z-test on the pooled numbers.
Enumerate every feature reaching the model and mark each as age-correlated, plausibly correlated, or clean. Graduation year, years-of-experience and employer-era keywords should be flagged in writing. This document is also your RFOA groundwork.
Generate pairs identical except for date shifts of 15–25 years and run them through the live pipeline. Divergence in score is the cleanest internal evidence of proxy learning — and it needs no candidate age data at all.
The RFOA defence turns on whether the factor was reasonable and job-related in practice. Contemporaneous documentation of why a screen exists is worth far more than a reconstruction produced after a charge is filed.
EEOC recordkeeping rules reach applicant data, and the ADEA has its own retention requirements. Ranked model outputs, thresholds and version history are discoverable. Deleting them mid-dispute is a much worse problem than the underlying disparity.
The Vendor Question
Employers using third-party screening tools keep arriving at the same hope: that the vendor absorbs the liability. It does not work that way. The employer made the employment decision. The vendor's exposure is additional, not substitutive — and courts have been willing to treat a screening vendor as an agent of the employer where the vendor's tool performs the rejection.
Practically, this means three things in your vendor contracts: a right to receive age-banded impact statistics on your own applicant flow, a right to audit or to receive an independent audit, and notice when the model is retrained. A model that was audited in Q1 and retrained in Q3 has not been audited.
Check what your hiring pages actually disclose
Careers pages, application forms and job postings are the public, indexable surface of your hiring process — and the first thing a plaintiff's counsel reads. RatedWithAI scans your live pages for compliance and accessibility exposure in under a minute.
Scan Your Site for Free →Frequently Asked Questions
Does the ADEA apply to AI hiring tools at all?
Yes. The statute regulates employment decisions affecting workers 40 and over, not the method used to reach them. An automated ranker that rejects older applicants at a lower rate is the employer's rejection. Using a vendor's model does not move the decision out of the statute.
Can applicants bring a disparate impact age claim?
They can. Smith v. City of Jackson recognised disparate-impact claims under the ADEA, and Meacham v. Knolls placed the burden of establishing a reasonable factor other than age on the employer. The RFOA standard is more forgiving than Title VII's business-necessity test, but the employer carries it — and reliance on a vendor's accuracy claim has not been enough on its own.
We removed graduation years from resumes. Are we clear?
No. Redaction removes one proxy, and the model redistributes weight onto correlated features it still has: years of experience, employer era, technology vocabulary, certification recency. The only way to know whether age signal survived is to measure outcomes by age band or run matched-pair synthetic resumes through the live pipeline.
Is a maximum-years-of-experience filter lawful?
It is very hard to defend. Experience ceilings and phrasing like 'digital native' or 'recent graduate' have been treated by the EEOC as age-based screening. A minimum requirement genuinely tied to the role is a different matter and is ordinarily defensible; a maximum usually has no explanation other than age or expected salary, and expected salary is itself age-correlated.
We do not collect applicant age. Doesn't that protect us?
It protects you from nothing and costs you the ability to detect the problem. Not collecting age does not stop the model inferring it, and it does not stop a plaintiff's expert reconstructing it from the same resume fields your model used. Voluntary, separated self-identification data used only for aggregate impact testing is the standard approach.
Does NYC Local Law 144 cover age?
Local Law 144's required bias audit covers sex and race/ethnicity categories, and their intersections. Age is not part of the mandated audit. Passing a Local Law 144 audit therefore says nothing about your ADEA exposure — a gap many HR tech teams have not noticed.