Practice Guide · Discrimination & AI

California’s Automated-Decision-Making Rules — An Employee’s Rights Guide

Most of what you will find online about California’s new AI-in-hiring regulations is written for employers — compliance checklists telling companies how to keep their algorithms out of court. This guide is the opposite. It explains what California’s automated-decision-system regulations mean for the worker or applicant who was screened, ranked, scored, or rejected by a machine, and what you can do about it.

Practice Guide
Discrimination
Disability & Accommodation
AI / Automated Decisions
2 Cal. Code Regs. § 11008.1
Gov. Code § 12940
Current as of June 2026

In brief. Effective October 1, 2025, the California Civil Rights Council amended the FEHA employment regulations to address artificial intelligence and “automated-decision systems” (ADS) — the resume screeners, video-interview analyzers, personality and “culture-fit” games, and ranking algorithms employers increasingly use to decide who gets hired, promoted, or kept. The rules do not create a brand-new claim; they make explicit that an employer’s existing duty not to discriminate follows the decision into the machine. If an automated tool harms you because of a protected characteristic — by intent or by lopsided result — the employer (and often the vendor that built or ran the tool) can be liable under the Fair Employment and Housing Act, and the fact that the employer ran “anti-bias testing” is evidence to be weighed, not a free pass. (Cal. Code Regs., tit. 2, §§ 11008.1, 11009, subd. (f).) This guide collects the governing rules and translates each into what it means for you.

1. What the regulations actually do — and why they matter to you

On June 27, 2025, the Office of Administrative Law approved regulations the California Civil Rights Council had developed over several years, and they took effect on October 1, 2025. (Cal. Code Regs., tit. 2, div. 4.1, ch. 5, subch. 2.) The Council did not write a new “AI statute.” It amended the long-standing regulations that interpret the Fair Employment and Housing Act (FEHA, Gov. Code § 12900 et seq.) so that the same antidiscrimination rules that have always governed human hiring decisions apply, in so many words, when the decision is made or assisted by software.

That framing is the most important thing for a worker to understand. You do not need a special “AI claim.” Your claim is the ordinary FEHA claim — discrimination, failure to accommodate, unlawful inquiry, retaliation — and the regulations confirm that an employer cannot escape that claim by outsourcing the decision to an algorithm. As the rules put it, it is unlawful for an employer “to use an automated-decision system or selection criteria (including a qualification standard, employment test, or proxy) that discriminates against an applicant or employee … on a basis protected by the Act.” (Cal. Code Regs., tit. 2, § 11009, subd. (f).) The regulations apply to employers with five or more employees — FEHA’s ordinary coverage threshold. (Id., § 11008, subd. (f).)

Why it matters: automated tools are now embedded in nearly every stage of hiring and management, and they are largely invisible to the person they judge. You may never be told that a model ranked your resume below a keyword cutoff, that a video tool scored your “enthusiasm” from your facial expressions, or that a game measured your reaction time and inferred a disability. The regulations give that invisible decision a legal name and a set of obligations — including a four-year records-retention duty (discussed in Part 6) that can put the model, its inputs, and its outputs in front of a jury.

2. What counts as an “automated-decision system”

The regulations define an automated-decision system as “a computational process that makes a decision or facilitates human decision making regarding an employment benefit.” An ADS “may be derived from and/or use artificial intelligence, machine-learning, algorithms, statistics, and/or other data processing techniques.” (Cal. Code Regs., tit. 2, § 11008.1, subd. (a).) The phrase “facilitates human decision making” is deliberately broad: a tool does not have to make the final call to be covered. A system that screens, scores, or ranks you — leaving a human to rubber-stamp the result — is still an ADS.

The rule then gives concrete examples of what these systems do, and the list reads like a catalogue of modern hiring technology. An ADS includes a system that uses “computer-based assessments or tests, such as questions, puzzles, games, or other challenges” to make predictive assessments, to measure “skills, dexterity, reaction-time,” or to gauge “personality trait, aptitude, attitude, and/or cultural fit,” or to “screen, evaluate, categorize, and/or recommend” candidates. It includes systems that direct “job advertisements or other recruiting materials to targeted groups,” that screen “resumes for particular terms or patterns,” that analyze “facial expression, word choice, and/or voice in online interviews,” and that analyze “applicant data acquired from third parties.” (Cal. Code Regs., tit. 2, § 11008.1, subd. (a)(1)(A)–(E).)

What this means for you. If any of the following touched your application or your job, an ADS was likely involved: an online “assessment” of games or puzzles; a one-way recorded video interview that you suspect was machine-scored; a personality or “culture-fit” questionnaire; an automated resume filter; a gamified skills test; a keystroke-, productivity-, or activity-scoring tool; or an algorithm that built your shift schedule or ranked you against peers. The regulation expressly carves out ordinary office software — word processing, spreadsheets, map navigation, firewalls, spam filters, calculators, and the like — but only so long as those technologies “do not make a decision regarding an employment benefit.” (Id., § 11008.1, subd. (a)(2).) The line is function, not brand name: if the tool is shaping who gets the job, it is in scope.

Two companion definitions matter to your case. An “agent” is anyone “acting on behalf of an employer, directly or indirectly, to exercise a function traditionally exercised by the employer,” including recruitment, screening, hiring, and promotion conducted “in whole or in part through the use of an automated decision system”; an agent “is also an ’employer’” under the Act. (Cal. Code Regs., tit. 2, § 11008, subd. (b).) And a “proxy” is “a characteristic or category closely correlated with a basis protected by the Act.” (Id., § 11008, subd. (m).) Proxy is the heart of algorithmic bias: a model that never sees your race or disability can still discriminate by leaning on a stand-in for it — a ZIP code, a gap in employment, a gaming score, the name of your school. The regulations make a proxy that discriminates just as unlawful as the protected trait itself.

3. The core protection: both intentional bias and biased results count

FEHA reaches discrimination under two theories, and an ADS can violate either. The regulations confirm both apply to automated decisions.

Disparate treatment (intentional discrimination). If a protected characteristic was “a substantial motivating factor” in the denial of an employment benefit, the employer is liable. (Cal. Code Regs., tit. 2, § 11009, subd. (c).) That standard comes from Harris v. City of Santa Monica (2013) 56 Cal.4th 203, which the regulation cites. An employer who configures or deploys a tool knowing it disadvantages a protected group — or who uses a “culture-fit” model designed to reproduce a homogeneous workforce — engages in disparate treatment. Be aware of the defense Harris also recognized: if the employer proves it would have made the same decision anyway for lawful reasons, a disparate-treatment plaintiff’s remedies can be limited (declaratory and injunctive relief and attorney’s fees, rather than damages and reinstatement). (Harris, supra, 56 Cal.4th at pp. 232–241.) That is why the second theory is often the stronger one in algorithm cases.

Disparate impact (biased results, no intent required). A facially neutral tool that produces a substantially lopsided result against a protected group is unlawful unless the employer proves the tool is “job-related … and consistent with business necessity,” and even then the worker can still win by showing a “less discriminatory” alternative. (Cal. Code Regs., tit. 2, §§ 11017, subds. (a), (e), 11009, subd. (f).) California adopts the federal Uniform Guidelines on Employee Selection Procedures (29 C.F.R. § 1607 (1978)) for measuring adverse impact. (Id., § 11017, subd. (a).) The foundational authority is Griggs v. Duke Power Co. (1971) 401 U.S. 424, which held that a neutral practice with a discriminatory effect is unlawful absent business necessity — “good intent or absence of discriminatory intent does not redeem” it. (Griggs, supra, 401 U.S. at p. 432.) Equally useful against an algorithm is Connecticut v. Teal (1982) 457 U.S. 440, which rejected the “bottom-line” defense: an employer cannot justify a discriminatory screening step by pointing to balanced overall hiring numbers. (Teal, supra, 457 U.S. at p. 451.) If a model culls candidates at the resume or assessment stage in a way that disproportionately removes a protected group, Teal says that step is independently actionable even if the eventual hires look diverse.

“Anti-bias testing” is evidence, not a safe harbor. This is the point employer-side checklists soft-pedal, and it is decisive. The regulation makes “evidence, or the lack of evidence, of anti-bias testing or similar proactive efforts” relevant to the claim and to any defense — “including the quality, efficacy, recency, and scope of such effort, the results of such testing or other effort, and the response to the results.” (Cal. Code Regs., tit. 2, § 11009, subd. (f); see also id., § 11020, subd. (a)(6).) Read carefully, that cuts both ways and favors a well-prepared plaintiff. An employer that never audited its tool has handed you evidence of indifference. An employer that did audit, found a disparity, and used the tool anyway has handed you evidence of knowledge. Anti-bias testing is not a defense that ends the case; it is a discoverable record that often proves it.

4. The vendor that built the tool can be on the hook too

Hiring algorithms are usually licensed from third-party vendors, and employers frequently argue that any bias is the software company’s problem, not theirs. The regulations close that gap from both directions. First, they define “agent” to include any person who exercises a traditional employer function — including screening and hiring “through the use of an automated decision system” — and declare that an agent “is also an ’employer’ for purposes of the Act.” (Cal. Code Regs., tit. 2, § 11008, subd. (b).) Second, they reinforce that an employer is liable for the discriminatory acts of its agents. (Id., § 11009, subd. (b).)

This codifies the direction the California Supreme Court took in Raines v. U.S. Healthworks Medical Group (2023) 15 Cal.5th 268, which the Council cites in the regulation’s source notes. (See Cal. Code Regs., tit. 2, § 11008, Note.) Raines held that a business-entity agent that carries out FEHA-regulated activities on an employer’s behalf — there, a company performing pre-employment medical screenings — can itself be directly liable as an “employer” under FEHA. (Raines, supra, 15 Cal.5th at p. 273.) Applied to AI hiring, Raines and the new “agent” definition mean a vendor that screens, scores, or ranks candidates for an employer is not a bystander; it may be a defendant.

What this means for you. Do not assume the only target is the company that rejected you. The screening vendor, the assessment platform, the background-data broker whose “third-party data” fed the model — each may be an agent and therefore an employer under FEHA. That matters for recovery (more solvent defendants), for discovery (the vendor holds the model and the validation studies), and for venue strategy.

5. The disability angle: screen-outs, hidden medical inquiries, and your right to an alternative

Automated assessments are uniquely dangerous to workers with disabilities, and the regulations give this issue special attention. Three protections stand out.

Screen-outs. It is unlawful to use a qualification standard, test, proxy, or other selection criterion — “including but not limited to those administered through the use of an automated-decision system” — that “screens out, tends to screen out, or otherwise has an adverse impact on an applicant or employee with a disability,” unless the criterion is job-related, consistent with business necessity, and there is “no less discriminatory” alternative. (Cal. Code Regs., tit. 2, § 11072, subd. (b)(1).) Notably, you do not need statistics to make this showing: the rule states that “[s]tatistical comparisons … are not required to show that an individual with a disability … is screened out.” (Ibid.) A timed game that penalizes slower motor responses, a video tool that misreads a speech difference or a facial difference, a “personality” screen that flags a psychiatric disability — each can be an unlawful screen-out.

Hidden medical inquiries. An employer may not, before a job offer, ask questions “likely to elicit information about a disability,” and the regulations now make explicit that this prohibition reaches assessments delivered “through the use of an automated-decision system,” including “a test, question, puzzle, game, or other challenge that is likely to elicit information about a disability.” (Cal. Code Regs., tit. 2, §§ 11070, subd. (b)(2), 11071, subd. (e).) In other words, a gamified or personality assessment that functions as a backdoor medical exam can be an unlawful pre-offer medical inquiry — a violation independent of whether you were ultimately rejected.

Your right to accommodation and a human alternative. The regulations repeatedly direct that, to avoid unlawful discrimination, an employer “may need to provide reasonable accommodation” when an ADS measures abilities (skill, dexterity, reaction time) or analyzes “tone of voice, facial expressions or other physical characteristics.” (Cal. Code Regs., tit. 2, § 11016, subds. (c)(5), (d)(1).) Testing conditions must be modified so results “accurately reflect” your job skills “rather than reflecting [your] disability,” and — critically — “[t]he use of an automated-decision system, in the absence of additional process or actions, does not constitute an individualized assessment.” (Id., § 11072, subd. (b)(5) & (b)(5)(F).) That sentence is a gift to applicants: an employer cannot satisfy its individualized-assessment duty by pointing to the algorithm’s output alone. The duty to engage in the interactive process and to offer an alternative, accessible means of assessment survives the machine. For the underlying accommodation framework, see Gelfo v. Lockheed Martin Corp., Nadaf-Rahrov v. Neiman Marcus Group, and Scotch v. Art Institute of California.

The same adverse-impact-plus-accommodation logic appears for age. The regulations create a “presumption of discrimination” whenever a facially neutral practice — “including but not limited to the use of an automated-decision system” — has an adverse impact on applicants or employees 40 or older, and they specifically bar online applications and algorithms that “screen out applicants age 40 and older.” (Cal. Code Regs., tit. 2, §§ 11076, subd. (a), 11079, subd. (c)(1).)

6. The records the employer must keep — and what becomes discoverable

One of the most consequential changes is quiet: the regulations extended the records-retention period from two years to four years, and expressly swept automated-decision data into it. Any personnel or employment record bearing on an employment benefit must be preserved “for a period of … four years,” and the rule now lists “selection criteria, automated-decision system data, and other records” among what must be kept. (Cal. Code Regs., tit. 2, § 11013, subd. (c).) “Automated-Decision System Data” is itself defined broadly to include “[a]ny data used in or resulting from the application of an automated-decision system” — data about applicants and employees, data reflecting decisions and outcomes — and “[a]ny data used to develop or customize” the system. (Id., § 11008.1, subd. (d).)

The retention duty intensifies once a complaint is filed. On notice that a discrimination complaint has been filed, the employer must preserve all relevant records until the matter is finally resolved, and the rule specifies that “records and files relevant to the complaint” expressly “includes automated-decision system data” as well as “applications, forms or test papers completed by the complainant and by all other candidates for the same position.” (Cal. Code Regs., tit. 2, § 11013, subd. (c)(4).)

What this means for you. The model that judged you, the inputs it received, the score it produced, the data used to train or customize it, and any bias-audit results are records the employer is legally obligated to keep — and therefore records you can demand in discovery. Two practical consequences follow. First, a timely preservation demand (a litigation-hold letter) the moment you suspect an ADS was involved locks these materials in place; an employer that lets them disappear after a complaint has been filed faces a spoliation argument. Second, the breadth of the definition means the discoverable universe is not just “your” file but the comparative data — how the tool treated everyone else who applied for the same role — which is exactly the evidence a disparate-impact case is built on.

7. What an affected person can do

Spotting ADS involvement. Employers rarely announce that an algorithm decided your fate. Tell-tale signs include an instantaneous or near-instant rejection; an invitation to a “game-based assessment,” “online assessment,” or one-way recorded video interview; a personality or “work-style” questionnaire; or a rejection that cites no individualized reason. You are entitled to ask the employer, in writing, whether an automated tool was used and to request the basis for the decision. Preserve everything you received — emails, assessment screenshots, the job posting, any score or feedback.

Preserve evidence and demand preservation. Because the employer must retain ADS data for four years and must hold all relevant records once a complaint is filed (§ 11013, subd. (c) & (c)(4)), an early written preservation demand is powerful. It should identify the tool, the role, and the time period, and instruct the employer and any vendor to preserve the model, its inputs and outputs, validation and bias-audit studies, and the comparative applicant data.

The CRD complaint and right-to-sue process. FEHA requires you to exhaust an administrative step before suing. You file a complaint with the California Civil Rights Department (CRD), and you generally have three years from the date of the unlawful practice to do so. (Gov. Code § 12960, subd. (e)(5).) You may request an immediate “right-to-sue” notice and proceed straight to court, or let the CRD investigate. Once the right-to-sue notice issues, you generally have one year to file a civil action in superior court. (Gov. Code § 12965, subd. (c)(1)(D).) These deadlines are strict; calendar them early. (The three-year administrative period reflects AB 9, effective January 1, 2020; conduct that predates that change may be governed by the older one-year period — confirm the operative limitations period for your facts.)

What to demand in discovery. Build the request around the retention rule. At a minimum: the identity and version of every automated tool used; the vendor contracts and any agent/processing agreements; the model’s inputs, features, and weighting (including any proxies); your individual score, ranking, and output; the comparative scores and outcomes for the full applicant pool for the role; all validation studies and “anti-bias testing,” including the data, methodology, results, and what the employer did in response (§ 11009, subd. (f) makes the response itself relevant); and the training and customization data (§ 11008.1, subd. (d)). Expect privilege and trade-secret objections; a protective order usually resolves the latter.

Remedies. A successful FEHA plaintiff may recover back pay and front pay, compensatory damages (including for emotional distress), punitive damages in appropriate cases, injunctive relief (including changes to or discontinuation of the tool), and attorney’s fees and costs. As noted, on a pure disparate-treatment theory the employer’s same-decision showing can limit monetary relief (Harris, supra, 56 Cal.4th 203), which is one more reason to plead and develop the disparate-impact and failure-to-accommodate theories in tandem.

8. Open questions and the other rulebooks

California’s FEHA regulations are not the only law governing automated decisions, and the interactions are still being worked out.

The CPPA’s ADMT privacy rules are a separate regime — do not confuse them. The California Privacy Protection Agency (CPPA), enforcing the California Consumer Privacy Act, finalized its own regulations on “automated decisionmaking technology” (ADMT) in 2025; they were approved by the Office of Administrative Law in September 2025 and take effect January 1, 2026, with the core ADMT obligations phasing in by January 1, 2027. Those rules are about privacy, not discrimination: they give consumers — which can include job applicants and employees — rights to pre-use notice, to opt out of certain ADMT used for “significant decisions” (a category that includes employment), and to access “meaningful information” about the logic and effect of the technology. The CPPA regime can be a complementary source of transparency and a basis to learn how a tool works, but it is administered by a different agency, on a different timeline, and it does not displace your FEHA antidiscrimination rights. Treat them as two tracks that can run together.

Local ordinances — a useful contrast. California’s rules do not (yet) impose the kind of mandatory, published bias-audit regime that New York City adopted. New York City’s Local Law 144, enforced since July 5, 2023, bars use of an “automated employment decision tool” unless it has undergone an independent bias audit within the prior year, the audit results are posted publicly, and candidates receive advance notice and may request an alternative process. California’s approach is different in kind: it does not mandate a public audit, but it makes the presence or absence of bias testing evidence in any discrimination case (§ 11009, subd. (f)). The contrast is worth knowing because a multistate employer’s NYC audit materials may be discoverable and probative in a California case.

Federal law still applies — but federal guidance has receded. Title VII, the ADA, and the ADEA continue to prohibit discriminatory use of algorithmic tools. However, in early 2025 the EEOC removed the technical-assistance documents it had issued on AI under Title VII (2023) and the ADA (2022) from its website as part of a broader change in federal AI policy. The removal of guidance did not change the underlying statutes — the laws still apply — but it means California’s regulations are now among the most developed antidiscrimination rules specific to automated hiring, and state law is the firmer ground for a California worker.

9. Practice pointer for employees and applicants

  • Save everything, immediately. The assessment invitation, the screenshots, the job posting, the rejection email, any score or feedback. These are often the only outward trace of the tool.
  • Ask, in writing, whether an automated tool was used and request the basis for the decision. The question itself documents your diligence and can surface an admission.
  • Send a preservation demand early. The employer must keep ADS data for four years and must preserve all relevant records once a complaint is filed (§ 11013). A litigation-hold letter to the employer — and to the vendor — protects the model, the comparative data, and the audit results.
  • Name the vendor. The screening or assessment company may be an “agent,” and therefore an “employer,” under the rules (§ 11008, subd. (b); Raines). Do not let it hide behind the client.
  • If you have a disability, flag the screen-out and demand an alternative. A timed game, a video analyzer, or a personality screen that disadvantages you may be an unlawful screen-out or a hidden medical inquiry, and the algorithm’s output alone is not an individualized assessment (§§ 11070–11072).
  • Plead both theories. Disparate impact and failure to accommodate are often stronger than intentional-discrimination theory against a “neutral” algorithm, and they sidestep the same-decision limitation on damages.
  • Mind the clock. Generally three years to file with the CRD (Gov. Code § 12960), then one year to sue after the right-to-sue notice (Gov. Code § 12965). Confirm the operative dates for your facts.

Legislative note (current as of July 1, 2026). Senate Bill No. 7 (2025–2026 Reg. Sess.) — the “No Robo Bosses Act,” which would have imposed human-oversight requirements on automated decision systems in employment — was vetoed on October 13, 2025, and is not law; successor legislation may be introduced. Separately, the California Privacy Protection Agency’s automated decisionmaking technology (ADMT) regulations under the CCPA — a distinct regime from the FEHA regulations discussed in this guide — take effect January 1, 2027. This guide addresses the Civil Rights Council’s FEHA automated-decision system regulations only.

Key authorities

  • Cal. Code Regs., tit. 2, § 11008 (definitions of “agent” and “proxy”; agent is also an “employer”).
  • Cal. Code Regs., tit. 2, § 11008.1 (definition of “automated-decision system,” “algorithm,” “artificial intelligence,” “ADS data,” and “machine learning”).
  • Cal. Code Regs., tit. 2, § 11009, subds. (c), (f) (substantial-motivating-factor standard; core ADS prohibition; anti-bias testing as evidence).
  • Cal. Code Regs., tit. 2, § 11013, subds. (c), (c)(4) (four-year retention of ADS data; preservation after a complaint).
  • Cal. Code Regs., tit. 2, §§ 11016, 11017 (pre-employment practices and employee selection by ADS; adverse-impact / business-necessity framework; Uniform Guidelines, 29 C.F.R. § 1607).
  • Cal. Code Regs., tit. 2, §§ 11070–11072 (disability: prohibited inquiries via ADS, ADS as medical inquiry, screen-outs, accommodation, “ADS alone is not an individualized assessment”).
  • Cal. Code Regs., tit. 2, §§ 11076, 11079 (age: presumption of discrimination from neutral ADS adverse impact; online applications screening out applicants 40+).
  • Harris v. City of Santa Monica (2013) 56 Cal.4th 203 (substantial-motivating-factor standard; same-decision defense).
  • Griggs v. Duke Power Co. (1971) 401 U.S. 424 (disparate impact; intent not required).
  • Connecticut v. Teal (1982) 457 U.S. 440 (no “bottom-line” defense; each selection step actionable).
  • Raines v. U.S. Healthworks Medical Group (2023) 15 Cal.5th 268 (business-entity agent directly liable as “employer” under FEHA).
  • Gov. Code §§ 12940, 12960, 12965 (FEHA prohibitions; administrative-filing and right-to-sue deadlines).

Authorities current to June 2026. Browse related decisions in the case index →

Read the official regulatory text (Civil Rights Council)

Not legal advice. This guide is dated legal analysis for general information only and does not create an attorney–client relationship. The law changes: a statute, regulation, or decision discussed here may since have been amended, reversed, overruled, depublished, superseded, limited, or distinguished, and its citability may have changed, after the date shown. Confirm that any authority is current and citable through an independent citator before relying on or citing it. See the full Terms & Conditions.