Preserving Attorney-Client Privilege Over Your AI Bias Audit
FEHA / EEO Defense

A federal magistrate judge just drew the clearest line yet on when an AI bias audit stays protected from discovery and when it doesn't, and the distinction has nothing to do with whether a lawyer's name is on the file. In a May 2026 discovery order in Mobley v. Workday, the court shielded Workday's bias-testing data under the attorney-client privilege while ordering the company to hand over separate compliance records from the same period.
The attorney-client privilege bias audit question isn't about having a lawyer involved. It's about why the audit exists in the first place. Here's exactly what the ruling requires and how to structure your own audit to survive the same scrutiny.
Key Takeaways
In Mobley v. Workday (May 29, 2026), a federal court protected AI bias-testing data under the attorney-client privilege because counsel curated the data, the purpose was to obtain legal advice, and the results weren't shared with regulators.
The same order compelled production of the company's EEO-1 and OFCCP compliance records, proof that privilege depends on the document's actual purpose.
Bias testing conducted primarily as an ordinary business, engineering, or regulatory-compliance function generally enjoys a weaker privilege, even when counsel is involved.
Sharing bias-testing results with regulators, vendors, or broadly across your organization can waive privilege entirely.
FEHA's separate ADS recordkeeping requirement (4-year retention) should be tracked independently from a privileged bias audit, conflating the two risks producing records you intended to protect.
Documenting the audit's legal-advice purpose from the outset and keeping legal content separate from business recommendations preserve privilege if challenged later.
What the Court Actually Decided
In Mobley, et al. v. Workday, Inc. (Case No. 23-CV-00770, N.D. Cal.), Magistrate Judge Laurel Beeler resolved a discovery dispute at the center of the closely watched AI hiring discrimination case. Plaintiffs sought to compel production of Workday's internal AI bias-testing data. The court denied the motion, finding the data protected by the attorney-client privilege, but the reasoning is where the real guidance lies.
The court held the data was privileged because Workday showed three specific things, not just that a lawyer was somewhere in the loop:
Workday's attorneys curated the underlying data used in the bias testing, not merely reviewed results a technical team had already generated.
The overall purpose of the testing was to provide legal advice, not to serve an ordinary business function.
The results were never submitted to a regulatory body or otherwise used outside the privileged relationship.
The court explicitly rejected the plaintiffs' counterarguments that the testing served a business purpose or that the underlying code was too technical to be a legal work product. As the order put it, Workday had shown "more than mere direction by its attorneys," a meaningfully higher bar than simply having counsel nominally supervise the process.
The Part Most Coverage Leaves Out: What Wasn't Protected
This detail makes the ruling genuinely instructive rather than just reassuring. In the same order, the court granted a separate motion compelling Workday to produce its own EEO-1 reports and OFCCP compliance documents.
Those records weren't privileged because they weren't created to obtain legal advice. They were standard regulatory compliance filings, prepared and used as such.
Document Type | Outcome | Why |
|---|---|---|
Bias-testing data | Protected by privilege | Attorney-curated; purpose was legal advice; never submitted to regulators |
EEO-1 / OFCCP compliance records | Ordered produced | Standard compliance filings, not created for legal advice purposes |
The lesson isn't "get a lawyer involved, and everything is protected." It's that the same company, in the same case, got two completely different discovery outcomes for two different types of internal documentation because one was structured around obtaining legal advice and the other was an ordinary business compliance function. That distinction determines whether your own AI bias audit survives a discovery fight.
Privilege Does Not Mean the Underlying Facts Disappear
Attorney-client privilege generally protects qualifying confidential communications and materials reflecting legal advice; it does not make every underlying business fact privileged. Mobley is unusual because the court found that the particular bias-testing data itself was protected, given the attorneys' role in curating it and using it to provide legal advice.
That does not mean an employer can label ordinary HR data, hiring outcomes, applicant records, or other business records as privileged simply by asking counsel to review them. The way the information was created, selected, and used remains critical.
What This Means for Structuring Your Own Audit
The practical rule emerging from Mobley is direct: bias testing conducted at counsel's direction, for legal advice, can remain privileged. Bias testing run as a routine business or compliance function likely will not, even if an attorney's name appears somewhere in the process.
1.
Counsel needs to direct the audit's design, not just receive its output.
A technical team that runs standard tests and forwards the results to a lawyer for review doesn't meet the Mobley standard. Counsel should help curate which data is tested and how, before testing begins.
2.
Document that the purpose is legal advice, not business optimization.
If your audit doubles as a marketing claim ("our AI is bias-tested") or a routine QA function, that dual purpose weakens the privilege argument. Courts look at the audit's actual, primary purpose.
3.
Keep the results out of regulatory submissions and general business circulation.
The moment bias-testing results are shared outside the privileged relationship with a regulator or a vendor, or broadly across your organization, that disclosure can waive the protection entirely.
4.
Don't conflate your bias audit with your standard compliance recordkeeping.
FEHA's Automated-Decision System regulations already require you to retain ADS-related records for four years, independent of any privilege question. Keep that recordkeeping obligation separate from your privileged legal audit. Our guide on California's AI hiring regulations and FEHA's recordkeeping requirements covers that separate obligation in detail.
5.
Label everything consistently from the start.
Mark materials "Attorney-Client Privileged and Confidential" from the moment they're created, and keep legal-advice content separate from operational recommendations in the same document. Courts weigh whether a document's primary purpose was legal advice, and mixed-purpose documents are the most common way privilege gets lost.
Privilege Does Not Make the Underlying AI Risk Go Away
A privileged audit is not a compliance exemption. It does not make a discriminatory hiring practice lawful, eliminate FEHA or federal discrimination exposure, or replace the employer's separate recordkeeping obligations.
Its purpose is narrower: to allow counsel to assess legal risk and advise the company without assuming that every resulting legal analysis will automatically become evidence in later litigation.
If your business uses AI-assisted hiring or evaluation tools and hasn't structured bias testing under privilege, that gap is worth closing before, not after, a claim surfaces. Our FEHA/EEO Defense team structures this kind of privileged review by working with counsel from the outset, rather than reviewing results that a technical team has already generated independently.
Conclusion
In Mobley v. Workday, a federal court protected AI bias-testing data under attorney-client privilege because the company's attorneys curated the data, the testing's purpose was to provide legal advice, and the results were never submitted to regulators, while ordering the same company to produce separate compliance records that lacked those same characteristics. The distinction wasn't whether a lawyer was involved; it was whether the audit was genuinely structured from the start to obtain legal advice rather than to serve an ordinary business function.
If your AI bias audit is going to survive a discovery challenge, counsel needs to direct its design and data curation before testing begins. The audit's documented purpose must be legal advice, and its results must remain within the privileged relationship.
If your business needs its AI bias testing structured under privilege, DefendMyBiz offers a paid 1-hour consultation. Book a call with our employer defense team today.
Frequently Asked Questions
What are the four elements of attorney-client privilege?
What is a bias audit?
What destroys attorney-client privilege over an AI bias audit?
Does having a lawyer review my bias-testing results make them privileged?
Is an AI bias audit protected by attorney-client privilege?
Disclaimer: The above content is for informational purposes only. This is not legal or tax advice. Laws, IRS guidance, and withholding requirements can change, and outcomes depend on specific facts. You are advised to contact a qualified attorney for any legal advice.


