AI Compliance in HR Isn’t a Tool Problem. It’s a Recognition Data Problem.

In the result of our August newsletter poll, half of you named AI compliance as your pressure point. You’re right about the risk, but could be wrong about where it lives.

In August we asked which of three pressure points your team is actually dealing with. AI compliance exposure took 50%. Manager readiness and recognition displacement split the rest at 25% each.

One month earlier, on the same list, AI compliance finished last at 19%.

Nothing in the law tightened between those two polls. If anything it loosened and each state handles AI compliance in different ways. Colorado’s AI Act, the most demanding state framework in the country, had already slipped its start date to June 30, and on April 27 a federal court enjoined its enforcement pending briefing in xAI v. Weiser. The federal effort to preempt state AI regulation is still moving. Read as a deadline tracker, the vote should have gone down.

It went up because the exposure stopped being theoretical. And the half of you who voted for it are right about the pressure point, but most of the compliance advice aimed at you is pointed at the wrong object. 

The claims are arriving through old law

On June 22, Judge Rita Lin allowed the core discrimination claims in Mobley v. Workday to proceed. The theory that survived: a screening tool that advances and rejects candidates on your behalf can be treated as your agent. Roughly 14,000 people opted into the age-discrimination collective by the March deadline.

The statute they opted in under is the ADEA, passed in 1967.

Preemption reaches state AI statutes. It does not reach Title VII, the ADEA, the ADA, or a collective action already in discovery. Connecticut made the same point in plainer language: under Public Act 26-15, effective October 1, using an automated system is not a defense to a discrimination claim. 

What the rules actually ask you to produce

California’s automated-decision rules under FEHA have been in force since October 2025, and they read less like a technology standard than an operations spec. Meaningful human oversight, by someone trained and empowered to override the system. Four years of records. Absence of bias testing treated as evidence.

Strip out the legal vocabulary and every one of these frameworks asks for two artifacts:

  1. A record of the data behind a decision about a person.
  2. A trained human who reviewed that decision and could have said no.

Neither of those is an AI asset. You cannot buy them from the vendor whose tool is under scrutiny. 

Which is where the other 50% of your poll went

Manager readiness is not a parallel priority to AI compliance. It is the human in “human oversight.” A manager who approves a ranked list without the training or standing to reject it has not provided oversight. They have documented a rubber stamp, and the record is retained for four years.

Recognition and performance data is the other artifact. In July, 26 employees sued a major technology employer over layoff decisions they allege were driven by AI-assisted performance measures, activity monitoring and algorithmic rankings, in a process that disadvantaged people who had taken medical, parental or caregiving leave. The employer’s position is that people made the decisions, not AI. That case turns on the underlying data and the review trail, which is the material most HR teams keep worst.

Here is what we heard, unprompted and repeatedly, across four days in front of roughly 25,000 attendees on the SHRM26 floor: we have three programs and none of them talk to each other, I’m doing everything in spreadsheets, I have no idea if employees are actually using it.

Twelve months ago that was a measurement problem. It is now an evidence problem. 

Where we come down

Inspirus offers recognition and engagement software, so weigh this accordingly. The self-serving version of this argument would be that recognition data is a compliance asset. It isn’t, by default.

Recognition data becomes an input of record the moment it informs who gets promoted, retained or ranked. If it’s feeding those decisions, it has to be governed and reproducible like any other input. If it isn’t feeding them, keep it out of the decision and say so in writing. Both answers are defensible. Not knowing which one is true in your organization is the position that isn’t.

Learn more about Inspirus’ position on AI in recognition here 

The fair pushback

You could reasonably say this is a large-employer problem, or a specific state problem. You don’t run AI screening, you’re not in California or Illinois, and 2027 is soon enough.

But two things undercut that. Recruiting is the most common HR use of AI at 27% of adopting organizations, and it usually arrives inside an applicant tracking system nobody classified as AI. And jurisdiction follows where your candidates live, not where you’re headquartered, so if you have a remote workforce, a different state’s AI employment laws could directly affect you.  

There’s also a readiness number worth sitting with. In SHRM’s 2026 research, 57% of HR professionals working in states with employment AI laws didn’t know those laws existed. Of the 43% who did, only 12% had implemented compliant policies. That’s roughly one in twenty overall, in states that already regulate this, so there is also an awareness problem.  

Two moves this quarter

  1. Inventory the decisions, not the tools. List every employment decision in the last year where a score, ranking or recommendation influenced the outcome. For each one, name the data source and the person who could have overridden it. The gaps are your exposure.
  2. Fund the review layer in your 2027 plan. Manager capability and defensible people data are not soft line items competing with compliance. They are what compliance is made of.

The 50% named the right pressure point. The 25%er’s are how you answer it.

Learn more about how you can you strategically use AI in a recognition program with Inspirus.