Artificial intelligence has moved into daily work faster than the governance meant to manage it. Human Resources is the function best positioned to close that gap — much as it did when social media first entered the workplace.
The assignment is heavier this time. AI now touches hiring, performance management, compensation, and termination. Those are decisions that already carry legal exposure under Title VII, the Americans with Disabilities Act, the Age Discrimination in Employment Act, and a growing list of state laws. A flawed tool does not create a new kind of discrimination claim. It can create the same claim, at a much larger scale, and with a thinner record of why the decision was made.
Most organizations are still behind on this work. Employee access to generative AI expanded sharply through 2025, while formal AI-use policies and basic access controls lagged. That gap is where HR leadership adds value: pairing legal, IT security, and business priorities into a policy people can actually follow.
A Three-Tier Policy, Matched to the Task
One practical model — the same graduated approach many organizations used for social media — sorts AI use by the risk of the task, not by the brand name of the tool.
Total freedom. Employees may use approved AI tools with minimal restriction for low-risk, non-sensitive work: internal memos, brainstorming, formatting, general research.
Middle of the road. AI use is permitted, but a person has to review the output, and sometimes disclose that AI was used, before it is relied on or shared outside the team. Typical work includes performance summaries, job descriptions, candidate communications, and first-draft policy language.
Very limited. AI use is restricted or prohibited because of legal, ethical, or confidentiality risk, and a human decision is mandatory. This tier covers hiring and termination decisions, disciplinary actions, compensation determinations, and protected employee data.
The point of the first tier is to give employees a default answer for ordinary work. The point of the third is to keep the tightest control on decisions that can trigger a discrimination claim or a confidentiality breach. Each tier should name the approved tools and a safe alternative. A blanket ban tends to push people toward personal accounts rather than stop the use. That pattern — often called shadow AI — is harder to see and harder to defend than sanctioned use on an approved platform.
AI Is Not an Independent Contractor
A recurring question is whether an autonomous or “agentic” system should be managed the way HR manages an independent contractor: a defined scope of work, output standards, and an off-ramp if performance falls short.
The analogy is useful as a mental model. It forces the organization to ask who supervises the system, who reviews the work product, and who is accountable when it errs. It breaks down as a legal model. An independent contractor is a person who can be held liable, who can carry insurance, and whose conduct is governed by a contract. An AI system has none of those attributes. Liability for its output falls back on the employer and, increasingly, on the vendor that built it.
Courts examining AI hiring tools have already treated a software vendor as the employer’s agent for some liability purposes. The more accurate framing is that AI is a tool the organization deploys. It still requires the human accountability, documentation, and oversight HR would expect of any employment decision. It cannot be disciplined, retrained, or fired the way a contractor can.
What AI Does Well in HR — and Where It Creates Risk
The benefits are real, and they scale.
- Large employers use AI to screen and rank applications far faster than manual review.
- Rules-based scoring can apply the same criteria to every candidate, which reduces some forms of ad hoc individual bias.
- Conversational agents now handle high volumes of routine questions on benefits, policy, and leave, which frees HR staff for higher-judgment work.
- Attrition and workforce-planning models can flag flight risk or skills gaps earlier than a quarterly report.
The risks scale with the same automation.
- An algorithm trained on historical hiring data can encode past discriminatory patterns and apply them to every applicant, not just the occasional biased decision.
- Many scoring systems function as a black box. HR then has trouble explaining to a candidate, a regulator, or a court why a particular person was screened out.
- Employee and candidate trust is lowest for high-stakes uses such as compensation.
- Federal agencies treat AI tools used in selection as selection procedures. A disparate outcome can create liability without any intent to discriminate.
The same automation that lets a company screen a million applications can let a flawed model reject qualified candidates before a person notices the pattern.
Where HR Is Actually Using It
Adoption is expanding, and it is uneven. Industry surveys in 2026 still show a gap between executive enthusiasm and front-line deployment: many organizations expect to use AI in HR, and a large share have not deployed it in any meaningful way.
Use is concentrated in recruiting. A large majority of big employers already use AI somewhere in the hiring funnel. Adoption is slower in compensation and employee relations, where an error is harder to reverse.
In rough order of maturity, the common use cases are recruiting and candidate screening; employee self-service and HR helpdesk automation; learning and development personalization; engagement and attrition prediction; and performance-management support. Performance support remains one of the more contested and slowly adopted areas.
A few examples show both the scale and the downside. Unilever has used AI-driven assessments and video-interview analysis on a recruiting funnel that draws well over a million applications a year, and has reported substantial reductions in time-to-hire. IBM’s AskHR agent handles a high volume of internal HR conversations and routine tasks, which is a service-delivery use rather than a hiring use. High-volume hourly employers, including McDonald’s, have used hiring chatbots to manage enormous applicant pools. McDonald’s experience also shows the other side of the ledger: a 2025 security review found a significant vulnerability in its hiring chatbot. Tools that handle candidate data introduce new categories of risk along with the efficiency gain.
The Regulatory Map Is a Patchwork
No federal AI-employment statute exists. Title VII, the ADA, and the ADEA apply to an AI-assisted decision the same way they apply to a human one. The Equal Employment Opportunity Commission has taken the position that “the algorithm did it” is not a defense. In early 2025 the agency also removed its standalone AI hiring guidance and signaled less emphasis on disparate-impact theories. That tension has pushed the near-term checks onto state law and private litigation.
An employer posting one role to candidates in several states can trigger more than one regime.
New York City. Local Law 144 requires an independent annual bias audit of automated employment decision tools used in hiring or promotion, plus candidate notice. It has been in effect since July 2023.
Illinois. Public Act 103-0804 (HB 3773) amended the Illinois Human Rights Act. As of January 1, 2026, it is a civil rights violation to use AI in a way that discriminates in employment, and a separate violation to use AI in an employment decision without notice. The Illinois Department of Human Rights proposed implementing rules in May 2026 and withdrew them on June 2, 2026, with no refiling timeline as of late September. The statute is in force. The notice rules that would tell employers exactly how to comply are not.
Colorado. The original Colorado AI Act was repealed and replaced before its duties became operative. SB 26-189, signed May 14, 2026, is a narrower automated-decision transparency law aimed at consequential decisions, including employment. It is scheduled to take effect January 1, 2027. Enforcement still depends on Attorney General rulemaking, and an April 2026 federal stay has complicated the timeline. Plan for the 2027 framework. Do not build a program around the repealed statute.
California. Regulations under the Fair Employment and Housing Act, effective October 1, 2025, extend existing anti-discrimination rules to automated decision systems used in employment and lengthen retention duties for related data. Separately, Senate Bill 947 — the “No Robo Bosses Act of 2026” — is on Governor Newsom’s desk through September 30, 2026. If signed, it would take effect July 1, 2027, and would bar the use of an automated decision system as the sole basis for discipline or termination. We covered what the bill would require, and what to do before the deadline, in California’s “No Robo Bosses” Bill Heads to Governor Newsom.
Texas. The Texas Responsible Artificial Intelligence Governance Act prohibits AI deployed with intent to discriminate and allows a cure period before enforcement. It took effect January 1, 2026.
Other states, including Washington and New Jersey, are advancing similar bills. The direction of travel is toward disclosure, some form of bias testing, and documented human oversight — as legal requirements in some jurisdictions, and as the safer practice everywhere else.
The case to watch is Mobley v. Workday, a proposed class action in the Northern District of California alleging that Workday’s applicant-screening tools disproportionately filtered out candidates based on age, race, and disability. The court has allowed key claims to proceed even though Workday is a vendor rather than the employer of record, on the theory that a vendor administering screening tools can be treated as the employer’s agent. In June 2026 the court refused to dismiss the California FEHA claims. Plaintiffs moved for class certification in September 2026. Discovery fights over internal bias-testing data are still active. The holding matters for every organization that outsources screening to a third-party platform: the vendor contract does not end the employer’s problem.
The Same Failure Pattern Shows Up Outside HR
AI decision-making carries a common set of risks wherever it is used for consequential decisions.
In HR, the central danger is discriminatory impact at scale, often invisibly. A flawed model can screen out a protected group across every application it touches, long before anyone notices. Because these decisions sit under established anti-discrimination law, the risk translates directly into liability for the employer and, in some cases, the vendor.
The legal profession is a useful parallel. Generative tools produce fabricated case citations and misquoted holdings that sound authoritative. Courts in the United States have issued a large and growing number of sanctions, with penalties moving from small fines toward larger awards and, in some cases, bar discipline. Professional responsibility rules put the duty to verify on the licensed lawyer, not the tool. HR has no bar association, but an AI-generated policy summary, performance narrative, or termination justification carries a similar duty to check the output before anyone relies on it.
Medicine shows a different version of the same problem. Researchers have found that large language models used for diagnostic support can be swayed by irrelevant demographic cues: in controlled studies, adding a patient’s race or sex to an otherwise unchanged clinical case has flipped a recommendation. Patient-safety groups have flagged over-reliance on AI diagnostic tools, without enough weight on clinician judgment, as a 2026 safety concern. A confident-sounding wrong answer can reproduce the error the tool was supposed to reduce.
The pattern also shows up in credit, criminal-justice risk assessment, and insurance underwriting. Across fields, these systems can be confidently wrong, their errors scale rather than stay isolated, and human oversight works only when the reviewer has both the authority and the practical ability to override a bad recommendation.
What Employers Should Do Now
Striking a balance does not require a choice between adoption and legal safety. It requires oversight that scales to the risk of the decision, rather than a blanket ban or unrestricted access. Organizations that govern AI well tend to adopt it faster, and with fewer incidents, than organizations that either ban it or leave it ungoverned.
- Adopt a tiered use policy. Match the level of human review to the stakes of the decision. Name the approved tools, and give people a sanctioned path for ordinary work so they are not pushed onto personal accounts.
- Require human review and a documented rationale for any AI-influenced decision on hiring, discipline, compensation, or termination. No employment decision should rest on an unexplainable score alone. “The manager clicked approve” is not independent review.
- Audit tools for disparate impact before deployment and on a set schedule. Treat a vendor’s fairness assurance as a starting point, not a substitute for testing. Ask what data you will receive if a candidate, an agency, or a plaintiff’s lawyer later wants the basis for a screen-out.
- Track the state patchwork. Notice, audit, and retention duties already differ in New York City, Illinois, California, and Texas, and Colorado’s narrower framework arrives in 2027. A single national posting can trigger more than one of them.
- Build AI literacy in HR and in the manager ranks. Staff need to recognize when a recommendation is unreliable. Managers need a separate track, because they approve many of the highest-stakes calls and because courts and regulators are looking at whether a human genuinely reviewed the output or rubber-stamped it.
- Inventory what you already have. Include vendor platforms, not only tools built in-house. For each system, note whether it scores, ranks, flags, or recommends, and whether that output is effectively driving the decision.
The right process for a 12-person shop using a basic attendance flag is not the right process for a multi-state employer running AI-supported performance management. The tool, the job, and the decision still matter.
Training Is What Makes the Policy Real
A written policy changes little on its own. A signed acknowledgment tells HR that an employee saw the rule. It does not tell HR that behavior changed. The organizations seeing fewer AI-related incidents pair clear guardrails with ongoing, role-specific training — the same lesson HR already learned from social media and data-privacy programs.
Make it role-specific. A generic “here is our AI policy” session teaches people what is banned without teaching them what to do instead, which is what pushes employees toward unsanctioned accounts. A recruiter needs to know how to handle an AI-flagged resume that looks like a false rejection. A manager needs to know what can and cannot go into an AI-assisted performance review. A benefits specialist needs to know which employee data can never be pasted into a public tool. Build the examples from your own tiers and your own tools.
Train the moments that create risk. Rehearse the decision points: how to tell whether a piece of data is safe to enter, how to recognize output that looks confident but is likely wrong, when a request has to be escalated, and how to document that a person reviewed and approved an AI-assisted decision. That is the same verification habit courts are now enforcing against attorneys who file fabricated citations.
Keep it going. Employee use and the tools are both changing quickly. An annual module will not keep pace. Short refreshers tied to a real incident or a new tool rollout give HR a checkpoint to update guidance as state law and vendor products change.
Give managers their own track. Cover how to spot possible disparate impact, how to document the human judgment behind a final call, and how to respond if an employee raises a fairness concern. Substantive review is the point. A procedural sign-off is not.
Involve employees in the guardrails. Pilot feedback, focus groups, or a standing worker advisory role tend to produce rules people trust, because the rules reflect the workflow. Rules people helped shape are the rules they keep. In a union workplace, adoption of these tools is also a bargaining subject, not only a policy rollout.
Taken together, these practices turn a tiered policy from a document into a habit. That is what determines whether an organization captures the efficiency gain without absorbing the legal and reputational risk.





