As businesses implant AI tools deeper into hiring, the litigation keeps coming – and the courts are expected to fill in the gaps left by the absence of settled precedent. The latest guidance arrives from the Northern District of California, where a magistrate judge has issued a discovery ruling in the closely watched Mobley v. Workday, Inc. litigation that tells employers a great deal about how these cases will be fought.
In Mobley, the putative nationwide collective action alleged that Workday’s AI-based applicant screening system disqualified job seekers aged 40 and older in violation of the Age Discrimination in Employment Act. After the court preliminarily certified the collective action in 2025, the parties turned to discovery: who has to hand over the applicant data needed to prove (or disprove) alleged discrimination?
Summary of Impactful Discovery Ruling
On May 29, 2026, the court denied the plaintiffs’ motion to compel two key categories of evidence.
Notably, the court held that Workday cannot be forced to produce its customers’ applicant data. Under the Federal Rules of Civil Procedure, a party must produce only what is in its “possession, custody, or control.” Because Workday’s Master Subscription Agreement provides that the “Customer [referring to employer that utilized the AI services] owns all right, title and interest to its Customer Content,” the court found Workday lacked the requisite control.
Additionally, the court held Workday’s internal bias-testing data was protected by the attorney-client privilege, because Workday’s lawyers curated the underlying data and used the results to give legal advice. Notably, the court did compel Workday to produce its own EEO-1 and OFCCP records, and it reminded the parties that even imperfect statistical evidence has “at least some probative value” of disparate impact.
Lessons for Employers
For employers deploying AI in hiring, three practical lessons stand out.
Pay close attention to vendor contracts. The ruling turned almost entirely on contractual language – data ownership, storage on isolated tenants, and narrow disclosure provisions. That language shielded the vendor from having to produce the data but employers may need to produce it through a subpoena. Before signing with an AI hiring vendor, employers should consider negotiating clear rights to access and own their own applicant-flow and scoring data, the results of any bias testing, and the vendor’s obligation in litigation and regulatory inquiries.
Conduct periodic testing for disparate impact. In disparate impact cases, motive is irrelevant; a tool adopted to increase diversity can still create liability if its outputs skew against a protected group. Regular, well-documented testing is the best way to catch a problem before a plaintiff or a regulator does.
Recordkeeping is key. Federal and state regulations already require employers to preserve employee records including records related to the application process. Failing to keep adverse-impact data may allow a plaintiff or enforcement agency to infer adverse impact from the gap. In light of recent rulings, it is not sufficient to only preserve the application forms, and related data should also be saved.
As AI becomes standard in hiring and HR, litigation over algorithmic bias will only grow, and courts and regulators are watching. Employers should not assume that outsourcing a hiring function to a vendor outsources the legal risk. The importance of consulting counsel before deploying AI systems in hiring cannot be overstated.
CDF will continue to monitor developments in AI, algorithmic decision-making, and employment litigation. Please contact the author or a member of the AI Practice Group to discuss AI hiring-tool vendor agreements, disparate-impact testing protocols, recordkeeping compliance, or the defense of related investigations and litigation.