California AI Employment Laws: Why Your Business Needs an AI Policy

FEHA / EEO Defense

8 mins read

8 mins read

California AI Employment Laws: Why Your Business Needs an AI Policy

Your hiring software may already be scoring resumes, ranking applicants, or recommending candidates for interviews. And if you don't have a written workplace AI policy governing how those tools get used, you have no documented standard of care to point to when someone challenges the result. 

California has already regulated this as active law since October 2025. Find out what's actually in effect, what a recent court ruling changed, and what your policy needs to cover.

Key Takeaways

  • California's FEHA automated-decision system regulations have been active since October 1, 2025. This is current law, not a future requirement.

  • Employers remain fully liable for discriminatory outcomes from AI tools even when a third-party vendor built and operates the tool.

  • The June 2026 federal court decision allowed significant FEHA claims involving Workday's applicant-screening platform to proceed, reinforcing the principle that employers cannot assume that third-party AI vendors eliminate potential liability.

  • SB 7 (the "No Robo Bosses Act") was vetoed in October 2025, but a separate CPPA rule (ADMT regulations) takes effect January 1, 2027, with different requirements.

  • ADS-related data must be retained for 4 years, and documented anti-bias testing can serve as evidence of reasonable care.

  • A written, attorney-reviewed AI policy with human-review requirements and signed employee acknowledgment serves as your primary defense if a decision is ever challenged.

The California AI Rule Already in Effect (Most Employers Don't Know This)

Since October 1, 2025, California's Civil Rights Council has enforced FEHA regulations governing how employers use "automated-decision systems" (ADS). Any computational process, including AI, that makes or helps make employment decisions. It's binding law right now.

What the regulation requires

Detail

Scope

Applies to hiring, promotion, discipline, termination, and any tool that scores, ranks, or screens applicants/employees

Discrimination standard

Illegal to use ADS that discriminates, intentionally or through disparate impact, based on any FEHA-protected category

Vendor liability

Employers generally remain responsible for employment decisions made using third-party AI tools.

Recordkeeping

ADS-related data (inputs, outputs, criteria used) must be retained for 4 years

Defense value

Documented anti-bias testing is treated as relevant evidence for the employer in a discrimination claim

The detail that catches employers off guard is vendor liability. If your applicant tracking system quietly filters out candidates based on a pattern it learned from historical data, "the vendor built it" is not a defense. California treats that outcome as yours.

For a fuller picture of how FEHA works and where employers are typically exposed, see our guide: What Is FEHA? The California Fair Employment and Housing Act, Explained for Employers.

What the Workday Ruling Just Confirmed for Every California Employer

On June 22, 2026. A federal judge refused to dismiss FEHA claims against Workday, whose AI-based applicant screening tools are used by thousands of employers to filter resumes. The plaintiffs alleged the tools disproportionately screened out older applicants, Black applicants, and applicants with disabilities.

Workday argued FEHA shouldn't apply to screening decisions affecting non-California applicants. The court disagreed because Workday's tools were "designed, developed, maintained, and controlled" from its California headquarters. The court found sufficient nexus to California to allow the claims to proceed.

The lesson for you isn't about Workday specifically. It's this: if you use a third-party AI hiring tool, the tool's California footprint and your use of it can both create exposure regardless of where your applicants are located. Every employer using AI-based screening, scoring, or ranking tools is one discovery request away from being asked the same questions Workday is now answering in court.

Watch: California's next big AI law could cost you thousands, a quick breakdown of where California's AI employment rules are headed next, and why waiting to build a policy gets more expensive the longer you wait.

What SB 7's Veto Means (and Doesn't Mean) for You

California considered a broader law, SB 7, the "No Robo Bosses Act," that would have required notice before using AI in employment decisions and banned reliance on AI for firing or discipline. Governor Newsom vetoed it on October 13, 2025, calling it overly broad.

That veto does not mean California backed off AI regulation. It means:

  • The FEHA ADS regulations above are still fully in effect and remain your primary compliance obligation today.

  • A separate set of rules, the California Privacy Protection Agency's Automated Decisionmaking Technology (ADMT) regulations, takes effect January 1, 2027, and will require risk assessments, transparency notices, and opt-out rights for employers using ADMT in "significant decisions" (hiring, compensation, promotion, discipline, termination).

  • Lawmakers have signaled a narrower version of SB 7 may return in a future session.

In other words: the rules you must follow today (FEHA ADS) and the rules coming in 18 months (CPPA ADMT) are different frameworks with different requirements. A policy built only around today's rules will need updating before 2027, which is why a living, reviewed policy beats a one-time document.

What a Defensible Workplace AI Policy Must Include

A short "use AI responsibly" memo is unlikely to provide meaningful protection if your employment decisions are later challenged. Here's what holds up:

1.

Approved and prohibited tools, named specifically.

List the platforms employees may use for work tasks. Explicitly prohibit anything not on the list. Employees bringing in their own unauthorized AI tools, sometimes called shadow AI, is the exposure most employers never think to address.

2.

Data classification rules.

Name what can never go into an AI tool: client records, personnel files, financial data, trade secrets. Be specific, not general.

3.

Human review requirements for any AI output used in an employment decision.

This is your practical answer to the FEHA ADS regulations. A human who reviews and can override the AI's recommendation is your strongest evidence of "reasonable care" if a decision is ever challenged.

4.

Bias testing documentation.

You don't have to conduct bias audits, but the regulations explicitly treat the presence (or absence) of anti-bias testing as evidence in a discrimination claim. Do the testing, keep the records.

5.

4-year data retention for anything tied to an employment decision.

Match your retention policy to the regulation's actual number, not a guess.

6.

Disciplinary consequences for violations,

applied consistently. A policy nobody enforces is worse than no policy. It shows you knew the risk and did nothing about it.

How to Roll This Out Without a 50-Page Document

You don't need a comprehensive AI governance program on day one. You need a defensible starting point:

1.

Inventory what's already in use.

Ask HR, recruiting, and department heads what AI tools touch hiring, evaluations, scheduling, or discipline, authorized or not.

2.

Identify which tools qualify as an ADS under FEHA.

If it scores, ranks, screens, or recommends regarding an employment benefit, it's covered.

3.

Draft the policy

covering the six elements above, in plain language your managers will actually read.

4.

Have employment counsel review it

before distribution. This is a fast-moving area, and a policy drafted from a template can miss California-specific obligations that don't exist at the federal level.

5.

Distribute with a signed acknowledgment.

That signature is what turns your policy from a document into evidence.

6.

Calendar your next review

for 12 months out, or immediately if you adopt a new AI tool or a new regulation takes effect in your jurisdiction.

If your current policy is nonexistent or hasn't been reviewed since before the October 2025 regulations took effect, that gap is a live risk today. Our FEHA / EEO Defense team reviews AI-related hiring and evaluation practices for exactly this reason before a claim forces the conversation.

 If you'd like your current AI-related hiring or evaluation practices reviewed, DefendMyBiz offers a free 15-minute consultation. Book a call with our employer defense team today.

Frequently Asked Questions

Is there a California law requiring a workplace AI policy right now?

Does using a third-party AI hiring vendor protect my business from liability?

What happened to California's "No Robo Bosses Act"?

How long must California employers keep AI-related hiring records?

Do small businesses need a workplace AI policy?

Disclaimer: The above content is for informational purposes only. This is not legal or tax advice. Laws, IRS guidance, and withholding requirements can change, and outcomes depend on specific facts. You are advised to contact a qualified attorney for any legal advice.