AI Policy Wiki
Dashboard

Inside My Advanced Topics Class 6.2: The Law's Toolkit (and Its Blind Spots) (Farahany, February 2026)

medium confidence · updated 2026-06-06

Surveys the existing legal toolkit applicable to AI personality and risk assessment: Title VII / ADA / ADEA disparate impact, EEOC technical assistance, FCRA, NYC Local Law 144, Illinois AI Video Interview Act, EU AI Act, and the new Mobley v. Workday vendor-liability theory. Each addresses a slice; none addresses the whole. The mathematical-impossibility constraint (Class 9 intro) shapes what any toolkit can do.

Author: Nita Farahany Source: https://nitafarahany.substack.com/p/the-laws-toolkit-and-its-blind-spots Published: February 25, 2026

A class essay by Nita Farahany, published February 25, 2026 as Class 6.2 of her Advanced Topics in AI Law and Policy course, surveying the legal toolkit applicable to AI personality and risk assessment in employment. The essay's organizing argument is that each existing tool addresses one slice of the harm landscape while none addresses the whole, and that the mathematical-impossibility result from the introductory course (Class 9) constrains what any such toolkit can demand.

Summary of argument

Farahany catalogs the federal statutes, agency guidance, state and municipal laws, the EU framework, and the emerging litigation theory that together form the available legal response to AI tools that screen, score, or profile job applicants. The essay treats these as a patchwork: workhorse antidiscrimination statutes reach selection outcomes but not inference or opacity; data-rights and notice regimes reach disclosure but not substance; and the most consequential expansions of liability remain either jurisdiction-specific or unresolved on appeal. Farahany ties the limits of the toolkit back to the introductory course's mathematical-impossibility result, which she presents as the reason no rule can specify a single correct fairness threshold.

Federal antidiscrimination law

The disparate-impact provisions of Title VII, the ADA, and the ADEA are described as the workhorse statutes. Under the burden-shifting structure, a plaintiff must show a statistical disparity in selection rate, the defendant must show a business justification, and the plaintiff may then show an alternative method that achieves the employer's aim without the disparity. The 4/5ths rule (EEOC, 1978) operates as the de facto threshold for identifying disparity.

The EEOC's 2022 and 2023 technical-assistance documents on Title VII and the ADA clarify that AI vendors are not exempt from antidiscrimination law and that reasonable-accommodation duties extend to AI screening tools that disadvantage applicants with disabilities.

The Fair Credit Reporting Act (FCRA) attaches where AI personality assessment draws on third-party data: the consumer-reporting framework then entitles the applicant to disclosures and to dispute inaccurate data. Farahany describes its reach as limited but still operative.

State, municipal, and EU law

NYC Local Law 144 (effective 2023) mandates bias audits for automated employment decision tools (AEDTs), with summary results posted publicly. Farahany notes, drawing on the introductory course's Class 9, that the law deliberately leaves the acceptable impact ratio undefined, on the reasoning that the mathematical-impossibility result means there is no single right answer.

The Illinois AI Video Interview Act (effective 2020) requires applicant notice and consent before AI analysis of video interviews, and requires that demographic data be reported and destroyed.

California's FEHA regulations (October 2025) are characterized by Farahany as the most aggressive US state rule: they extend liability to AI tools used to make or assist employment decisions and impose explicit antidiscrimination requirements on automated decision systems.

Under the EU AI Act, employment-context AI is classified as high risk, triggering conformity assessment, fundamental-rights impact assessment, and transparency obligations. Article 5(1)(f) bans emotion recognition in workplaces and schools categorically.

Vendor liability and Mobley v. Workday

Farahany identifies the vendor-liability theory in Mobley v. Workday as, in her characterization, the most consequential doctrinal innovation in the area. If accepted, the theory would expand the population of AI-discrimination defendants from the deploying employer to the AI vendor itself, and she argues that how it survives appeal will reshape the field.

What the toolkit does not reach

Farahany identifies three harms the existing tools do not address. Inferred-profile harm arises where an inference is made about an applicant but no adverse action follows. Process opacity arises where the applicant never learns what was assessed. Aggregation harm arises where many small decisions compound into systemic exclusion.

Relationships