Define human authority in policy and check the tools already in use
An AI policy for the people function should identify which decisions affecting a person's job, pay, or standing require human judgment. That gives managers a rule they can apply across products and gives the organization a basis for reviewing how decisions were made.
A useful starting point is to permit defined forms of assistance, such as summarizing records or comparing pay benchmarks, while reserving consequential determinations for an accountable person. The distinction needs care.
“A tool that ranks applicants or filters a candidate pool can shape who receives consideration before a manager makes the final selection.”
Write the policy around that influence as well as the final decision. Apply it to new purchases and to AI features already operating inside existing systems.
Name the decisions the policy governs
Sourcing, screening, selection, performance rating, promotion, compensation, and termination warrant separate treatment. Reading benchmark data to identify anomalies is a different act from setting an individual's rating, even when the same tool supports both.
Specify what AI may do in each category, what requires a human determination, who holds that authority, and what record is kept. Include the criteria a reviewer must consider and a way to question or correct an output. A manager should be able to explain the rule in a staff meeting without referring to a product name.
Organizing the policy this way makes it easier to apply when vendors rename products or add features. The inventory and the policy still need regular review; neither remains current simply because it has been approved.
Separate enforcement priorities from legal obligations
Federal enforcement priorities have changed. Executive Order 14281, issued in April 2025, directed agencies to deprioritize disparate-impact enforcement. The EEOC's National Enforcement Plan for fiscal years 2025 to 2029, adopted in June 2026, does not identify algorithmic discrimination as a separate priority.
Those developments do not by themselves repeal employment discrimination statutes or eliminate private litigation. In Mobley v. Workday, a federal district court granted preliminary certification of an age-discrimination collective in May 2025 over allegations concerning algorithmic applicant screening. That procedural ruling allowed the collective action to advance; it was not a finding that discrimination had occurred.
State and local requirements also matter. New York City's Local Law 144 conditions covered use of automated employment decision tools on a bias audit within the preceding year, public availability of audit information, and required notices. Illinois's Human Rights Act amendments addressing discriminatory AI use and employer notice took effect in January 2026. California's regulations clarify how employment discrimination law applies to automated decision systems and require covered employment records, including automated-decision data, to be retained for at least four years.
For organizations operating in the EU, specified employment uses fall within the AI Act's high-risk categories. Current Commission guidance places the relevant high-risk obligations from December 2, 2027. Prohibitions have applied since February 2025, including workplace emotion inference, subject to the Act's medical and safety exceptions.
Use a common governance baseline with documented requirements for each applicable jurisdiction. Set retention periods by record category and legal obligation; California's minimum is not, by itself, a retention policy for every location.
Keep evidence of meaningful human review
A model's recommendation can influence a decision even when a person formally approves it. The record should show what the reviewer considered, which evidence supported the outcome, and how any material concern was resolved.
“A model’s recommendation can influence a decision even when a person formally approves it.”
Keep that discipline for accepted recommendations as well as overrides. Recording only departures from the model can make routine approvals difficult to explain later. The purpose is to document the judgment exercised, not merely the presence of a human in the workflow.
Audit the tools already running
Review applicant tracking systems, human capital management platforms, and assessment services for AI features, including those activated during upgrades. Establish which features are enabled, what decisions they influence, and who owns their configuration.
Ask vendors which functions use a model, what information it processes, how it has been evaluated for adverse impact, what testing evidence customers receive, and what happens to submitted data. Unanswered questions should remain explicit gaps in the evaluation, with an owner and a decision about whether the proposed use can proceed.
Internal evaluation should use representative, job-relevant cases and examine performance across relevant groups. Historical outcomes can help define test cases, but should not be treated automatically as correct: previous decisions may contain bias. Document the evaluation method, the limitations, and the conditions under which use must change or stop.
Ask peers how they defined human authority over people decisions, what their vendor inventory revealed, and how they adapted the policy across jurisdictions. Connex convenes CHROs and senior HR leaders in Trusted Peer Groups.
Sources:
- EEOC National Enforcement Plan for fiscal years 2025 to 2029
- Executive Order 14281
- Mobley v. Workday order on preliminary collective certification
- New York City automated employment decision tools requirements
- Illinois Human Rights Act
- California Civil Rights Department on automated decision systems
- European Commission AI Act implementation timetable
- EU Artificial Intelligence Act
