The recent judgment in a California Lawsuit for AI governance violation in hiring software should concern decision-makers for AI governance. The case suggests that AI developers themselves may also face liability alongside deployers if their systems contribute to conflicting outcomes. At the same time, if an AI system relies on personal or sensitive data that creates discriminatory outcomes, regulators will examine not only the algorithm but also how that data was collected, processed, governed and potentially tested.
Let us have a look at the concerns related to both.
AI Governance: Vendor and Deployer
In one of our earlier blogs, I explained how deployers are (unfortunately) clearly liable in case of any AI governance conflict. But the lawsuit in question raises concerns for vendors as well. Here’s how, as per the case, this shared accountability works in practice:
- Shared liability: The case suggests that courts may look beyond the organization deploying AI and examine the vendor’s own role in developing, configuring, or operating the technology. As AI becomes more autonomous in decision-making, responsibility may increasingly be shared across the AI supply chain.
- Bias Testing: The lawsuit suggests that vendors should expect to demonstrate how models were tested, validated, monitored, and governed over time, making AI governance a critical component of legal defense rather than just product quality.
- AI Inventories: As liability potentially extends across the AI supply chain, organizations need a clear inventory of where AI is used, who owns each system, what data it relies on, and what governance activities have been performed. Without this visibility, responding to regulatory inquiries or legal challenges becomes significantly more difficult.
- Data governance becomes part of AI governance: The case reinforces that organizations cannot evaluate AI systems independently of the data they rely on. If biased or incomplete personal data influences AI outcomes, scrutiny is likely to extend to how that data was collected, managed, and governed.
- Need for Transparency: As AI systems play a greater role in business decisions, organizations will increasingly be expected to explain what personal data is used, why it is used, and how it influences automated outcomes. Strong documentation and clear notices can help demonstrate accountability. While not strictly required today, we believe being more transparent is strongly in your best interest.
- Sensitive data demands greater oversight: AI models often infer or amplify patterns related to protected characteristics, even when those characteristics are not explicitly provided. This makes it essential to carefully govern the collection, use, and retention of sensitive and proxy data throughout the AI lifecycle.
Road-Ahead for Heightened AI Scrutiny
Cases like these help us reassess our AI governance efforts to ensure that we uphold the customer’s trust while not compromising our innovation goals. Here’s what we learn for a future strategy.
- Maintain a comprehensive AI inventory: Organizations should maintain an up-to-date inventory of every AI system in use, including internally developed models, third-party tools, and AI agents. Each record should identify ownership, purpose, risk level, and supporting governance documentation to provide visibility across the AI lifecycle.
- Institutionalize AI risk assessments: AI systems, particularly those supporting high-impact decisions such as hiring, lending, or healthcare, should undergo documented risk assessments before deployment and at regular intervals thereafter. Bias testing, human oversight, and continuous monitoring should become standard governance practices rather than one-time compliance exercises.
- Strengthen vendor governance: Organizations should evaluate AI vendors beyond product capabilities. Procurement and vendor management should include reviews of governance practices, model validation, testing methodologies, audit evidence, and contractual accountability to ensure vendors can support regulatory inquiries and legal challenges.
- Strengthen data governance across the AI lifecycle. AI governance teams should ensure that personal data used to train, fine-tune, or operate AI systems is collected lawfully, processed for clearly defined purposes, and governed throughout its lifecycle.
- Improve transparency and documentation. Organizations should maintain clear records describing what personal data their AI systems use, why it is processed, how long it is retained, and what safeguards protect individuals’ rights. Accurate privacy notices and defensible documentation are becoming essential evidence of responsible AI use.
- Apply enhanced controls to sensitive data. AI systems should be regularly reviewed for their use of sensitive information and proxy attributes that could lead to discriminatory outcomes. Organizations should implement data minimization, access controls, retention policies, and periodic reviews to ensure sensitive data is handled responsibly throughout the AI lifecycle.
Age of Shared AI Accountability
More than a legal dispute over hiring software, the California lawsuit is a signal of where AI regulation is headed. Organizations can no longer assume that responsibility ends with the deployer. Regulators and courts are increasingly looking at the entire AI ecosystem, from how models are built and governed to how the underlying data is collected, processed, and protected. Businesses that invest in robust AI governance, and defensible documentation today will be better positioned to manage legal risk, maintain customer trust, and scale AI innovation with confidence.