Disparate Impact After the Federal Retreat: Why AI Hiring Risk Went Up, Not Down
A quieter federal agency is not the same thing as a narrower law. Employers who read the 2025 enforcement shift as permission to stop testing their screening tools removed the one artifact that would have defended them in the venue where these cases are actually being brought.
What Actually Changed, and What Did Not
In 2025 the federal executive branch directed agencies to deprioritize disparate-impact theories of liability, and agency guidance addressing AI in employment decisions was pulled from circulation. Those are real changes with real effects: fewer commissioner charges built on statistical impact, fewer systemic investigations of screening tools, and less published guidance to point to when designing a programme.
Three things did not change. Title VII still contains the disparate-impact provision Congress codified — an enforcement-priority memorandum cannot repeal statutory text. Private plaintiffs still have a right of action, and they file on their own schedule. And state civil rights law, which in several jurisdictions is broader than the federal floor, continued to operate and in fact expanded during the same period. The practical effect for an employer is that the enforcement channel most likely to reach you was never the one that got quieter.
Three Layers of Exposure, Ranked by Likelihood
Private and class litigation
The most probable route to a claim. Plaintiff-side firms have built AI-specific practices, screening rejections generate large identifiable classes cheaply, and the discovery target — a tool, its scores, and its outcomes — is more tractable than a decade of manager decisions.
State statutes and regulators
NYC's bias audit and candidate notice duties, Illinois' human rights amendment addressing AI in employment decisions, Colorado's algorithmic discrimination regime for consequential decisions, and California's FEHA regulations on automated decision systems. Several carry their own penalties and none depend on federal priorities.
Federal agency action
Narrowed for disparate-impact theory, but not eliminated, and priorities are a policy choice that a later administration reverses with a memorandum. Intentional-discrimination theories were never deprioritized, and a tool that uses or proxies a protected characteristic is not safe under any enforcement posture.
The Vendor Is No Longer Standing Outside
The comfortable division of labour — the employer makes the decision, the vendor sells a tool — is eroding from both directions. Courts have allowed the theory that a screening provider whose product performs the rejection acts as the employer's agent for discrimination purposes, which puts the vendor in the caption. Separately, state AI statutes increasingly impose direct duties on developers: documentation, impact disclosures, and notification when a system is found to cause algorithmic discrimination. HR tech companies that market "automatic" and "hands-off" screening are writing the plaintiff's agency argument in their own copy.
What Employers and HR Tech Should Do Now
- ☐Inventory every tool that screens, ranks, scores, matches, or schedules candidates — including features inside your ATS you did not procure separately
- ☐For each, record what it measures, what data it was built on, and whether a human materially reviews its output before a rejection
- ☐Identify which states your applicants are in, not just where your offices are — several duties follow the candidate
- ☐Flag any tool touching video, voice, or facial analysis for separate biometric review
- ☐Run adverse impact analysis on real selection outcomes, by stage, not just on vendor-supplied benchmarks
- ☐Use the four-fifths rule as a screen, not a verdict; significance testing matters where volumes are large
- ☐Where an impact appears, document the business-necessity case and whether a less discriminatory alternative exists — that second question is what the statute turns on
- ☐Involve counsel early where privilege over the analysis matters to you
- ☐Publish the candidate notices the applicable state and city rules require, before the tool runs
- ☐Commission independent bias audits where mandated, and publish the summary where publication is required
- ☐Provide the accommodation and alternative-process path, and make sure it is reachable from the application flow
- ☐Retain applications, scores, and outcomes for the full applicable recordkeeping period
- ☐Secure information rights over model documentation, testing results, and change notice from every screening vendor
- ☐Allocate liability and indemnity for discrimination claims explicitly rather than leaving it to a general clause
- ☐If you are the vendor: review marketing that describes the tool as making decisions without human involvement
- ☐Re-run the whole review when a vendor changes models — your last audit describes a system that may no longer exist
Your application flow is public evidence
Candidate notices, accommodation paths, and audit summaries all live on pages anyone can load — including a plaintiff's counsel. RatedWithAI scans your public pages and reports what is missing, unreachable, or unusable before someone else documents it.
Scan Your Site for Free →Frequently Asked Questions
We only operate in states with no AI hiring statute. Are we clear?
Not clear, and possibly not accurate about the premise. Title VII and state civil rights statutes of general application still cover you, and disparate-impact claims predate any AI-specific law by decades. The AI statutes add notice, audit, and documentation duties — they are not the source of the underlying liability. Remote hiring also scrambles the geography question: where your applicants sit can matter more than where you are incorporated.
Our vendor says the tool is bias-tested. Is that a defence?
It is a starting point and not a defence on its own. A vendor's test runs on the vendor's population and configuration; yours may differ in applicant pool, cutoffs, weighting, and the stages around the tool. Ask what data the test used, which groups were analysed, what the thresholds were, and when it was last run against the model version you are actually calling. Then run your own analysis on your own outcomes.
What if adverse impact shows up and we cannot remove it?
Then the statutory question becomes whether the practice is job-related and consistent with business necessity, and whether a less discriminatory alternative with comparable validity exists. That second prong is where defences most often fail with AI tools, because alternatives are usually available — a different threshold, a different feature set, a different weighting, or human review at the affected stage. Document the alternatives you examined and why you chose what you chose.
Where should a team with two hours start?
Write the inventory. Most organisations cannot currently list every automated step between an application arriving and a human reading it, and everything else in this article depends on that list. Once it exists, the highest-value next step is pulling selection-rate data by stage for the last twelve months — you will usually know within an afternoon whether you have a problem worth resourcing.
This article is general information, not legal advice. Enforcement posture and state requirements change; confirm the current position for your jurisdictions with counsel before relying on any of it.