On the same day the Department of Labor finished dismantling a 60-year-old federal contractor compliance regime, a California federal judge let a class action against an AI meeting assistant move forward on the theory that the vendor itself, not just the employer who used it, can be sued directly. HR leaders waiting for regulators to hand them a clear rulebook for AI in the workplace should stop waiting. Courts are writing it instead, one lawsuit at a time, and that is a worse system for compliance planning than the one it is replacing.

The pattern, not the headline

On August 21, the Office of Federal Contract Compliance Programs finalized three rules rescinding the affirmative action requirements built on Executive Order 11246, plus the numeric hiring goals tied to disability and veteran status under Section 503 and VEVRAA. That is a genuine retreat from proactive federal oversight of how employers use hiring processes, including AI-assisted ones, to sort candidates by protected characteristics.

The same week, a federal court in In re Otter.AI Privacy Litigation let plaintiffs proceed against an AI notetaker as a third-party eavesdropper for retaining and repurposing recorded meetings. It is the latest in a run of rulings this publication has covered treating AI vendors as direct legal targets rather than tools shielded by the employer who deployed them, alongside the Mobley v. Workday screening-bias case and the Justice Department’s PERM settlement with OpenAI over hiring discrimination. Put the two stories together and the shape is unmistakable: the federal government is stepping back from setting rules for how AI gets used on people decisions, and the courts are stepping into the vacuum, case by case, employer by employer.

Advertisement

HRTech Your brand belongs here. Reach the decision-makers who read HRTech every day. Premium placements across the site and newsletter. Advertise with us

Why that is not good news

A regulator writing a rule tells every employer, in advance, what the line is. A court deciding a motion to dismiss tells one company, after the fact, that it crossed a line nobody had drawn yet. Litigation-driven accountability is slower, more expensive to discover, and wildly inconsistent: an AI notetaker practice that survives a motion to dismiss in one circuit can lose outright in another, and an employer only finds out which rule applies to them after they have already been sued. Compliance teams built entire programs around OFCCP’s utilization goals and EO 11246 audits precisely because they were legible in advance. Nothing replacing them offers that.

The strongest counter-argument

The fair objection is that this is not actually new: courts have always been a check on employer conduct, civil rights litigation predates any of this year’s AI rulings, and a lighter regulatory touch simply returns the balance to where it sat before EO 11246-era rulemaking expanded it. On that view, HR is not facing a new risk, just a familiar one reasserting itself now that a specific layer of federal rulemaking has receded.

That argument understates how different the current wave of litigation actually is. Mobley, the Otter.ai case and the OpenAI settlement are not ordinary employment discrimination suits against an employer’s own decision. They test whether the software vendor itself, a party HR typically treats as a procurement decision rather than a legal one, can be held liable for what its product does with employee and candidate data. Procurement teams that vetted AI vendors on price, integration and accuracy now have to vet them on litigation exposure too, and that is a genuinely new compliance surface, not a reversion to an old one.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

There is also a scale argument the “nothing new here” view misses. Traditional employment litigation targets one employer’s decision about one employee. A ruling against an AI vendor’s data practices potentially exposes every customer of that vendor at once, because the conduct at issue, what the software does with recordings or applicant data by default, is identical across every deployment. That is closer to a product liability exposure than a conventional discrimination claim, and it means HR’s vendor contracts, not just its own hiring practices, are now part of the company’s litigation surface.

What HR should actually do

Do not wait for OFCCP’s successor or a federal AI-in-employment law to arrive before building a vendor risk framework. Ask every AI vendor touching hiring, meetings or performance data three questions directly: what happens to the data after the interaction ends, has the vendor itself been named as a defendant in privacy or discrimination litigation, and does the contract indemnify the employer or leave it exposed alongside the vendor. Regulators used to answer the first question for HR in advance. For now, courts are answering it after the fact, one company at a time, and the only rational response is to stop treating the absence of a new rule as the absence of risk.

Source: Federal Register