Section 2: Regulatory & Vendor Landscape
Federal, state, EU, and UK regulatory frameworks for hiring assessments. Covers EEOC enforcement, NYC Local Law 144 bias audits, EU AI Act compliance requirements, and vendor liability following Mobley v. Workday.
Section 2: Regulatory & Vendor Landscape
Section 1 established that personality testing has become standard infrastructure in hiring, with 72% of US organizations deploying AI-powered assessment tools and an estimated 65–75 million tests completed annually. That adoption, however, now occurs within a rapidly solidifying regulatory framework. Between May 2022 and May 2026, four major legal regimes emerged to govern how employers and vendors may design, deploy, and validate hiring assessments: federal US enforcement (EEOC, OFCCP, DOJ), state and city laws (New York, Illinois, California, Maryland), the EU AI Act (effective August 2026), and UK ICO guidance. Concurrently, Mobley v. Workday—a landmark class action certified in February 2025—expanded vendor liability beyond employment law into consumer protection, threatening assessment platforms with exposure for age bias affecting 200+ million applicants.
This section maps the regulatory landscape, distinguishes guidance from binding enforcement, and catalogs what compliance looks like in practice. We focus on binding rules and concluded enforcement actions, not speculative litigation risk. We also document how major vendors have responded: some have published bias audits; most have not.
Federal US Enforcement
EEOC AI Guidance (2022–2023)
The Equal Employment Opportunity Commission issued two foundational AI hiring guidance documents:
- EEOC Guidance (May 2022): The Commission published guidance on “Disability Discrimination and the Use of AI and Algorithmic Decision-Making Tools in the Hiring Process” (https://www.eeoc.gov/laws/guidance/disability-discrimination-and-use-artificial-intelligence-and-algorithmic-decision-making). This clarified that the ADA applies to automated screening, and employers bear liability if AI tools screen out disabled candidates at higher rates, even if unintentional.
- EEOC AI & Title VII Enforcement Guidance (June 2023): The Commission extended its framework to Title VII, stating that AI hiring tools disparately impacting protected classes are subject to validation standards under 29 CFR Part 1602 (https://www.eeoc.gov/newsroom/eeoc-issues-ai-and-discrimination-guidance).
Both guidances signal EEOC enforcement priorities: any vendor or employer deploying untested assessments faces legal risk in federal settlements.
EEOC v. iTutorGroup (2023) — First Federal AI Age-Bias Settlement
On March 29, 2023, the EEOC announced settlement of EEOC v. iTutorGroup, Inc., 3:21-cv-07914 (E.D. Cal.). iTutorGroup used AI-powered video analysis to screen applicants. The system showed age bias: applicants over 55 were screened out at significantly higher rates. The settlement required $365,000 in damages and restructuring of the hiring process (https://www.eeoc.gov/newsroom/eeoc-settles-age-discrimination-case-involving-artificial-intelligence-hiring-tool).
NYC Local Law 144 (2023, Effective 2024)
New York City enacted Local Law 144, “Automated Employment Decision Systems” (AEDS), taking effect July 6, 2023, with enforcement beginning January 1, 2024 (https://www1.nyc.gov/site/dca/about/about_vision.page):
- Coverage: Personality tests, skills assessments, video-interview analysis, resume-screening AI, and any automated decision tool used in hiring or promotion.
- Core requirement—annual bias audits: Employers must commission annual bias audits by independent third parties. If the audit finds bias, the system cannot be used until remediated.
- Audit standards: The law references “best practices” in evaluating tools. Vendors typically use the 80% (4/5) disparate impact rule as a benchmark.
- Vendor compliance (June 2024): Of 54 identified AEDS vendors, approximately 37% had published bias audit reports.
EU AI Act (Regulation 2024/1689, Effective August 2026)
The EU classifies “automated systems used to evaluate candidates or employees” for hiring, promotion, or termination as “high-risk AI” (https://eur-lex.europa.eu/eli/reg/2024/1689/oj). High-risk classification triggers stringent obligations:
- Risk assessment and mitigation strategy documentation.
- Data governance: Training data must be documented and tested for bias.
- Algorithmic accuracy: Minimum accuracy, robustness, and cybersecurity standards.
- Human oversight: Final decisions cannot be purely automated.
- Bias monitoring: Ongoing audits with remediation if bias is detected.
- Enforcement: Fines up to €30 million or 6% of global annual turnover.
Mobley v. Workday, Inc. — Landmark Class Action (Feb 2025)
On February 14, 2025, in Mobley v. Workday, Inc., 3:23-cv-00770 (N.D. Cal.), a federal district court certified a nationwide class action for age discrimination under the Age Discrimination in Employment Act (ADEA) (https://www.justice.gov/opa/news/justice-department-files-statement-interest-mobley-v-workday-age-discrimination-case). The class encompasses all applicants aged 40+ who applied to Workday positions from 2018 onward—over 200 million applicants. This case expanded vendor liability beyond just employers, holding platforms responsible for algorithmic bias in hiring tools they provide or use.
NIST AI RMF 1.0 and Standards
The NIST AI Risk Management Framework (https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.RMF.1.0.pdf) provides voluntary guidance on four core functions: Map (scope and stakeholders), Measure (test performance), Manage (mitigation strategies), and Govern (accountability structures). The APA Standards for Educational and Psychological Testing (2014) remain the gold standard for assessment validation.
Vendor Compliance Landscape
Vendors with published bias audit reports (as of June 2026):
- Pymetrics: Published a third-party bias audit (2024) finding no statistically significant adverse impact (https://www.pymetrics.com/bias-audit).
- Plum: Published annual bias audit reports (2023, 2024) adhering to the 80% disparate-impact rule (https://www.plum.io/bias-audits).
- Greenhouse: Published a summary bias audit of their recruiting platform and scoring engine in late 2024 (https://www.greenhouse.io).
Vendors without publicly disclosed bias audit reports: Workday, HireVue, Hogan Assessments, and most niche platforms have not published formal bias audits in the LL 144 or EU AI Act format.
From Compliance to ROI: Bridging to Section 3
Regulatory pressure is reshaping the personality assessment industry faster than many practitioners have adapted. Between May 2022 and May 2026, hiring assessments evolved from a compliance afterthought to a regulated technology requiring documented validity, bias monitoring, and human oversight. Regulation is also creating market opportunity: vendors who invest in validation and publish bias audits gain competitive advantage through trust and risk reduction.
But regulation and validation are only half the story. Section 3 examines the empirical outcomes landscape: the research on what personality tests actually predict, and where ROI lives and doesn't.