The hiring process is undergoing a profound transformation, driven by rapid advancements in technology and a dynamic legal environment. Employers are increasingly reliant on background screening tools, but recent developments in legislation and court interpretations are reshaping how these tools can be used and the associated risks. Robert T. Quackenboss, a partner, and Evangeline C. Paschal, counsel with the law firm Hunton, highlight critical questions employers must address to ensure compliance and mitigate potential liabilities. These shifts, impacting frameworks like the Fair Credit Reporting Act (FCRA) and Title VII of the Civil Rights Act of 1964, necessitate a proactive and informed approach to candidate evaluation.
The AI Frontier: Are Candidate Profiles "Consumer Reports"?
A significant emerging legal theory under the FCRA posits that artificial intelligence (AI) hiring tools, such as sophisticated resume sorters and applicant tracking systems, may be generating "consumer reports." This assertion, if upheld, would designate the vendors developing these AI platforms as "consumer reporting agencies," subject to stringent FCRA regulations.
This complex issue is at the heart of the lawsuit Kistler v. Eightfold AI Inc. In this case, the plaintiff contends that Eightfold AI’s widely used software compiles and assesses a broad spectrum of candidate information, including data aggregated from third-party sources. The AI then constructs a "talent profile," assigning scores and rankings to applicants. The core of the plaintiff’s argument is that these functionalities meet the definition of "consumer reports" as defined by the FCRA.
Eightfold AI, in its defense, has filed a motion to dismiss, asserting that its business model involves licensing software to employers, akin to analytics companies like FICO that provide algorithms to credit bureaus. However, the implications for employers are substantial. Should the plaintiff’s interpretation prevail, the use of AI software that gathers and analyzes applicant data from diverse third-party platforms, such as professional networking sites like LinkedIn and various job boards, could trigger FCRA’s mandatory disclosure and notification requirements. These requirements typically include providing applicants with notice of the background check, obtaining their written consent, and furnishing them with copies of any reports before adverse action is taken. The potential for widespread application of this theory underscores the need for employers to scrutinize the data sources and functionalities of their AI-powered hiring tools.
The integration of AI in recruitment is not new, with tools designed to streamline the initial stages of hiring by sifting through vast numbers of applications. However, the legal classification of the outputs of these systems as "consumer reports" represents a paradigm shift. Previously, such tools were often viewed as internal assessment mechanisms. The Kistler case challenges this perception, suggesting that the aggregation and interpretation of external data points transform these AI outputs into reports that may fall under FCRA’s purview. This development is particularly pertinent given the increasing reliance on AI for candidate sourcing and pre-screening, a trend accelerated by the digital transformation of the workforce.
Timing is Everything: When Applicants Must Be Notified of Adverse Action
Another evolving interpretation of the FCRA centers on the precise timing of an employer’s issuance of the pre-adverse action notification. While the FCRA’s text mandates that employers provide this notice "before taking any adverse action based in whole or in part" on a background report, some plaintiffs are now arguing for an immediate notification requirement. Their contention is that applicants have a right to be informed the moment an employer receives a background report that raises concerns, asserting that any delay constitutes a "concrete injury." This alleged injury stems from the applicant being purportedly deprived of the opportunity to promptly rectify any inaccuracies in their record or to pursue alternative employment avenues before a hiring decision is finalized.
Employers, however, often have practical reasons for not issuing the pre-adverse action notice immediately. One common practice is to conduct an individualized assessment to contextualize information within a background report before alerting the applicant about a potential adverse employment decision. While this approach generally aligns with the statutory language of the FCRA, it has recently attracted unconventional claims. These claims suggest an implied right to immediate pre-adverse action notification, enabling applicants to provide context or withdraw their candidacy to explore other prospects.
This new theory draws parallels from a line of cases where unsuccessful applicants pursued FCRA claims after companies allegedly failed to provide required pre-adverse action notices in a timely manner, even when the background reports themselves were accurate. This suggests that the perceived timeliness of the notification, not just its content or the accuracy of the report, is becoming a focal point of litigation.
In light of these emerging theories, employers may find it prudent to issue the pre-adverse action notice promptly upon receipt of a background check report. This practice, even if the employer intends to conduct further review and investigation before reaching a final hiring decision, could help mitigate the risk of attracting claims related to delayed notification. The rationale is that demonstrating a swift and transparent process, even if the ultimate decision is delayed, could be viewed favorably by courts and regulatory bodies. The legal landscape here is fluid, and what was once considered standard practice is now being re-examined through the lens of applicant rights and potential procedural harms.
Disparate Impact Theory Under Scrutiny: A Shift in Civil Rights Enforcement?
For decades, a primary legal challenge against employer criminal background check programs has been the argument that such programs have an adverse "disparate impact" on racial and ethnic minorities, thereby violating Title VII of the Civil Rights Act of 1964. Disparate impact occurs when a seemingly neutral policy disproportionately affects individuals with protected characteristics, such as race or ethnicity, even in the absence of any discriminatory intent. This theory has been a cornerstone for the U.S. Equal Employment Opportunity Commission (EEOC) and plaintiffs’ class-action attorneys, leading to significant judgments against employers.
However, a significant legal shift began in April 2025 with Executive Order 14281, issued by President Donald J. Trump. This executive order declared that the theory of disparate-impact liability is unconstitutional, arguing that it "undermines civil-rights laws by mandating discrimination to achieve predetermined, race-oriented outcomes." The order directed federal agencies, including the EEOC, to de-prioritize legal challenges that rely on disparate-impact theory. Further reinforcing this stance, on June 9, the U.S. Department of Justice (DOJ) issued a Memorandum Opinion finding that the EEOC’s traditional guidance for analyzing disparate impact claims was "similarly unconstitutional."
While these developments do not eliminate disparate impact as a theory in private litigation outright, they signal a coordinated effort to challenge its application. The involvement of the DOJ and EEOC in articulating these arguments suggests a potential pathway towards U.S. Supreme Court review.
The implications for plaintiffs’ class-action attorneys are considerable. Disparate impact has been a fundamental tool in their practice, and its potential diminishment or dissolution could significantly impact pending and future cases. Furthermore, the EEOC’s reduced emphasis on investigating disparate impact charges means plaintiffs can no longer rely on this no-cost method to test the viability of their claims before committing to expensive litigation.
In response to these developments, the plaintiffs’ bar has begun to adapt their legal strategies. New pleadings are increasingly incorporating claims of intentional discrimination, or disparate treatment, under Title VII alongside disparate impact claims. This dual-pronged approach aims to provide a fallback option should disparate impact theory be significantly curtailed or overturned during the course of litigation. For defendants, this presents an opportunity to challenge the pleadings and underlying evidence supporting both causes of action, potentially leading to more complex and protracted legal battles. The future of disparate impact litigation is uncertain, but the current trajectory indicates a significant challenge to a long-standing legal doctrine.
Biometric Data and Identity Screening: New Legal Frontiers
The increasing prevalence of identity screening – the process of verifying that a job applicant is who they claim to be – is introducing new legal risks for employers. The rise of AI-powered tools has unfortunately coincided with a significant increase in reported cases of identity fraud and misrepresentation among job seekers. In response, employers are turning to a growing number of identity screening vendors, many of whom employ biometric tools to confirm applicant identities.
However, in the haste to bring these identity screening solutions to market, both vendors and employers can inadvertently overlook critical privacy and biometric information laws. Examples of such concerns have surfaced in legal actions, such as the allegations raised against identity screening tools under Illinois’s Biometric Information Privacy Act (BIPA) in cases like McGowan, et al. v. Veriff Inc., et al. Similar allegations were also part of the Kistler et al. v. Eightfold AI Inc. lawsuit, as previously discussed. These cases highlight the potential for biometric data collection and processing, even within the context of identity verification for employment, to trigger strict regulatory compliance obligations.
Illinois’s BIPA, for instance, requires private entities to obtain informed written consent from individuals before collecting their biometric identifiers, such as fingerprints or facial scans. It also mandates specific policies for data retention and destruction. Violations of BIPA can lead to significant statutory damages, making compliance a critical concern for any employer utilizing biometric screening.
The challenges employers face in simultaneously screening for identity confirmation and criminal background information are mounting. The interconnectedness of these processes, often facilitated by third-party vendors, necessitates a comprehensive understanding of the legal landscape. Employers are strongly advised to consult with legal counsel to review their current tools, vendors, and internal processes. This proactive step is essential to identify and manage all potential legal exposures and compliance obligations, ensuring that the pursuit of a secure and qualified workforce does not inadvertently lead to regulatory penalties or costly litigation. The intersection of technology, identity verification, and privacy law presents a complex and evolving challenge for modern HR departments.
