PAN Lab example
Workday AI screening
One model across thousands of employers and testing no one can see
Workday's AI screens applicants for thousands of employers. A lawsuit alleges age discrimination, and a court ruled Workday need not hand over its bias testing.
See more
Workday, Inc. makes an applicant-tracking platform, software that employers use to receive and manage job applications. Its AI features screen applicants and make recommendations inside the hiring pipelines of thousands of employers at once. Because every employer uses the same features, one flaw they learn can repeat wherever the platform is used.
The lawsuit
Mobley v. Workday is a federal collective action in the Northern District of California, case number 3:23-cv-00770. In a collective action, people with similar claims can opt in to join one lawsuit.
The lawsuit alleges that screening on Workday's platform discriminated against applicants because of their age. The lead plaintiff reported more than one hundred rejections across employers using Workday's platform.
The lawsuit claims Workday is directly liable as the employers' agent, not merely a supplier of a tool. An agent is a party that acts on someone else's behalf. The lawsuit claims Workday acted for the employers, so it can be held liable too.
Workday asked the court to throw out that claim early. In July 2024 the court refused. In May 2025, Judge Rita Lin preliminarily approved a nationwide collective under the Age Discrimination in Employment Act. It covers applicants aged 40 and over since September 24, 2020. As of January 2026, the court-authorized period to opt in was open.
What the court has and has not decided
These are procedural rulings and allegations. The lawsuit is ongoing, and the sources contain no finding that Workday's features discriminated. This case must not be read as a verdict. It matters for what it shows about how the screening is governed, whatever the outcome.
The testing no one outside can see
In 2026, Magistrate Judge Beeler held Workday's internal bias-testing data protected by attorney-client privilege, because lawyers had curated it, meaning selected and organized it. The ruling came in discovery, the stage of a lawsuit where each side must hand over evidence.
So the testing exists, and it is legally unreachable from outside. Outside Workday, the sources name the federal court as the one party with any reach into that record. Its 2026 ruling declined that reach, on grounds of privilege.
The case file calls this a different problem from having no test. A missing test is a known gap. A shielded test is an unknown. From outside, no one can tell whether the features were tested and passed, tested and failed, or tested with the result set aside.
Who is accountable
Each employer sets up and uses the features, and Workday builds them. When an applicant is harmed, each can point to the part the other controls. So an applicant harmed by the screen can find the employer pointing at Workday's features, and Workday pointing at the employer's setup.
Under 2023 guidance from the US Equal Employment Opportunity Commission, an employer stays liable even when a vendor built the tool. The commission removed that guidance from its website in early 2025. Archived copies remain, and the underlying law, Title VII of the Civil Rights Act of 1964, still applies. The lawsuit tests whether Workday is liable too, as the employers' agent.
What vendors disclose
A 2020 academic study by Manish Raghavan and colleagues reviewed the public claims of 18 vendors of pre-employment assessments. The case file reads it as showing that vendors' claims about validation and reducing bias are often unverifiable from outside. Validation is evidence that an assessment measures what it claims to. The case file calls Workday's shielded testing the acute form of that wider problem.
What this case asks
When one screening model serves many employers, the question is not only whether it is fair. It is also who is accountable, across how many employers at once, and whether anyone outside can see the testing. The case file's answer is that the testing often exists, is claimed, and cannot be verified.
What the available tools can and cannot address
A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. A tool closes a pathway when mistakes stop passing along it. The work along it may go on.
This case has a budget of 9 units. A pressure is a strain on the deployment that you can switch on or off, and this case opens with one on. It is named Second model is a clone: a model brought in to check the first shares its blind spots. Here it stands for one vendor's model repeating the same blind spots at every employer. Explore (No Targets) sets no targets. The other three levels ask for mistakes to be self-correcting, meaning caught and corrected rather than building on one another.
Under Service Targets Only, the targets can be met in many ways: 69 sets of tools, or 189 ways once stronger settings are counted. No tool meets them alone. The cheapest way costs 4 units: Escalate checks with Mark AI-written records. Several pairs cost 5 units, such as Mark AI-written records with Store less data.
Lingering effects are effects that stay after their cause is gone, and the Lab opens with them on. With lingering effects turned off in the Dynamics menu, Peer sharing rules with Mark AI-written records also meets them for 4 units.
Service and Safety Targets also asks you to close every failure pathway, among other targets. Eight pathways are open before any tool is used. The first four are Recommendations shown to recruiters, Employer and Workday responsibility, Employer sets up the screen, and Employer decisions recorded. The other four are Workday's changes recorded, Applicant data used by the features, Screening history read, and One model across thousands of employers.
Under Service and Safety Targets and under All Governance Targets, this case is not fully addressable with the available tools. No tool offered here acts on the pathway named Employer sets up the screen. All 394 combinations of tools and settings that fit the budget were checked, and each leaves that pathway open.
More is not better here. Using every tool at its strongest setting costs 32 units, well over the budget of 9. Even then, Employer sets up the screen stays open. No tool here changes the court's privilege ruling either, which belongs to the court.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Vendor-screening-class multiplied across employers network: 5 components and 11 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
Show all 5 assumptions
- assumed
The network assumes that how widely the platform is used, not one employer's use, sets how far a mistake can repeat. The sources describe one vendor's screening features working inside thousands of employers at once. The lead plaintiff reported more than one hundred rejections across employers using that one platform. The network also assumes more screening than employers' recruiters can review by hand. The recommendations multiply with the platform, while each employer staffs only its own recruiting team. The network adds no extra part for this. What sets this case apart is how the platform spreads and how Workday and employers split responsibility.
- baseline
This network follows the pattern the Workday case file documents, where one vendor's features stand between many employers and their applicants. It does not reconstruct Workday's actual platform. The lawsuit is ongoing. It claims Workday is liable as the employers' agent, a party acting on their behalf. In 2024 the court refused Workday's early request to throw out that claim. In 2025 the court preliminarily approved a nationwide collective, a group of applicants who can opt in to the age-discrimination claim. These are procedural rulings and allegations, not a finding of discrimination. Nothing in the network is a verdict.
- assumed
The network draws the spread across employers as one pathway, named One model across thousands of employers. The same features screen for thousands of employers, so one learned flaw can repeat at all of them. That holds even though each is a separate legal employer. The network draws the split of responsibility as a second pathway, between employers' recruiters and Workday. When an applicant is harmed, each can point to the part the other controls.
- baseline
The network draws the shielded testing as a check, named Outside read of the bias testing. A 2026 ruling in the lawsuit held Workday's internal bias-testing data protected by attorney-client privilege, because lawyers had curated it, meaning selected and organized it. So the testing record exists and is legally unreachable from outside. That differs from having no test. No one outside can tell whether the testing was done and passed, done and failed, or its result set aside. The case file sets this against a 2020 survey of assessment vendors' public claims. It reads that survey as showing their claims about validation and reducing bias are often unverifiable from outside.
- assumed
No applicant outcome and no allegation is decided here. The network shows how mistakes move among organizations, and applicants are outside it. The lawsuit's claims, the court's approval of the collective of applicants, and the privilege ruling come from the case file. They are ongoing proceedings, not findings, and the network computes none of them.
What this example does not show
Show all 2 limitations
- This example does not show what happened to any applicant, and it decides no allegation. It shows how mistakes move among Workday's features, employers' recruiters, Workday, the applicant record, and an independent auditor. Applicants are outside the network. The lawsuit's claims, the court's approval of the collective of applicants, and the privilege ruling come from the case file as ongoing proceedings, not findings. The network computes none of them.
- The lawsuit is ongoing, and its claim that a vendor can be liable as the employers' agent is new. An agent is a party that acts on someone else's behalf. The rulings so far are procedural. The court refused Workday's early request to throw out the claim, and preliminarily approved a collective of applicants. It also held the testing privileged. Nothing here finds that Workday discriminated. The network draws how Workday and employers split responsibility, not a verdict.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
An applicant-tracking platform whose AI screening and recommendation features operate inside thousands of employers' hiring pipelines at once is the subject of a live federal collective action testing whether the vendor is directly liable as the employers' agent. On the litigation record, the court sustained the agent theory at the dismissal stage in 2024 and preliminarily certified a nationwide age-discrimination collective in 2025, covering applicants forty and over since September 2020, on a record in which the lead plaintiff reported more than one hundred rejections across employers using the platform. The litigation is ongoing and nothing here is an adjudicated finding of discrimination; these are allegations and procedural rulings, not a verdict.
empirical- Reference Mobley v. Workday, Inc., No. 3:23-cv-00770 (N.D. Cal.): agent-theory vendor liability (2024), preliminary nationwide ADEA collective certification (2025), bias-testing privilege ruling (2026); via Holland & Knight LLP analysis. https://www.hklaw.com/en/insights/publications/2025/05/federal-court-allows-collective-action-lawsuit-over-alleged
A 2026 discovery ruling in the same matter held the vendor's internal bias-testing data privileged because counsel had curated it — meaning the testing record exists and is legally unreachable, a configuration in which audit opacity is not the absence of testing but testing shielded from external verification. The case surfaces two further structural facts: a single vendor's screening model multiplied across many employer boundaries, so one learned defect can propagate as widely as the platform, and accountability diffusion between deployer and vendor, each holding part of the governance the other points to, against a survey backdrop showing assessment vendors' validation and bias-mitigation claims are often unverifiable from outside.
empirical- Academic Raghavan, M., Barocas, S., Kleinberg, J., & Levy, K. (2020). Mitigating Bias in Algorithmic Hiring: Evaluating Claims and Practices. In Proceedings of FAT* '20, 469-481. https://doi.org/10.1145/3351095.3372828 https://arxiv.org/abs/1906.09208
- Government U.S. EEOC (2023, May 18). Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII. Technical assistance document (removed from eeoc.gov early 2025; archived). https://web.archive.org/web/20250102220802/https://www.eeoc.gov/laws/guidance/select-issues-assessing-adverse-impact-software-algorithms-and-artificial
Where this connects
Institutional pressures in this domain
- Workload surge — Demand outruns staffing; per-case attention shrinks and review becomes triage.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Hiring & employment screening AI domain page.
Levers available here and the patterns behind them
- Mark AI-written records — Provenance labeling
- Peer sharing rules — Peer-edge governance
- Gate vendor updates — Vendor quality gate
- Review on schedule — Oversight cadence & retrospectives
- Check with a second model — Cross-model verification
- Escalate checks — State-feedback vigilance
- Store less data — Data minimization
- Upgrade model — Improve the model
Documented case histories
- Vendor screening across thousands of employers (litigation live)
- A resume screener that learned the past's bias
- Graduate-hiring AI with its audits on the record
- HireVue video assessment (vendor layer)
- The 1959 statute and the integrity video screen (Baker v. CVS Health)
- An internal promotion, a recorded screen, and a captioning request (D.K. charges against Intuit and HireVue)
- Aon pre-hire assessment suite (vendor's own tables)
- The cooperative audit: a paid source-code examination, and what happened to its verdict
- McHire and the 64-million-record custody exposure
- SiriusXM's iCIMS applicant screening
- Checkr gig-economy background screening
- The rule with no number to disclose
- The account goes dark at nine; the reason arrives on day twenty-six
- iTutorGroup Tutor Application Screen
- Meta Job-Ad Delivery: the guardrail and the layer below