AI in the Workplace: What California Employers Need to Know About Compliance

HR Compliance

AI in the Workplace: What California Employers Need to Know About Compliance

California employers who use AI in hiring, performance management, or employee monitoring face obligations under FEHA, the CCPA, and Labor Code Section 980. Here is what you need to know before your next AI tool goes live.

M
Marlene Solis
••6 min read
AI in the Workplace: What California Employers Need to Know About Compliance

AI in the Workplace: What California Employers Need to Know About Compliance

California employers who use AI tools in hiring, performance management, or employee monitoring are subject to the same anti-discrimination laws that govern human decision-makers — including FEHA, Title VII, and the CCPA. An AI system that produces discriminatory outcomes creates employer liability regardless of whether a human intended the result. Here is what the law requires and what you need to do before your next AI tool goes live.

Why AI and California Employment Law Are Inseparable

AI tools do not operate in a legal vacuum. When an algorithm influences who gets hired, how performance is evaluated, or how employees are monitored, it becomes subject to California's Fair Employment and Housing Act (FEHA) and federal Title VII.

The core problem: AI systems trained on historical data can perpetuate or amplify existing bias. A hiring algorithm trained on your past workforce may systematically screen out women, older workers, or people of color — not because anyone intended it, but because the data reflected past discrimination. Under FEHA, employers are responsible for discriminatory outcomes regardless of whether a human or an algorithm produced them.

California regulators are paying close attention. The California Civil Rights Department (CRD) has made clear that automated decision-making tools are not exempt from FEHA's prohibitions.

Key Compliance Risks California Employers Face

1. Discriminatory Hiring Tools

AI-powered applicant tracking systems and resume screeners can inadvertently filter out protected classes. If your tool scores candidates based on patterns from your existing workforce, and your workforce lacks diversity, the tool will replicate that gap.

What to do: Audit any AI hiring tool for disparate impact before deploying it. Request bias testing documentation from vendors. Keep records of how candidates were evaluated and what criteria the tool applied.

2. Automated Performance Management

AI tools that flag "low productivity" based on keystrokes, mouse movement, or response times can disproportionately penalize employees with disabilities, caregiving responsibilities, or different working styles — creating potential FEHA liability.

What to do: Ensure AI-generated performance data is reviewed by a human manager before any employment action is taken. Document the human review process. Never use an AI output as the sole basis for a termination or demotion.

3. AI-Generated Job Descriptions

AI-written job postings can introduce gendered language, age-coded phrasing, or requirements that screen out protected groups. Terms like "rockstar," "digital native," and "fast-paced environment" can signal bias and create disparate impact exposure.

What to do: Always have a human review AI-generated job descriptions for inclusive language before posting. Remove requirements that are not genuinely essential to the role.

4. Employee Monitoring and Privacy

California's Consumer Privacy Act (CCPA) and Labor Code Section 980 place strict limits on how employers can monitor employees. AI-powered monitoring tools — keystroke loggers, email scanners, productivity trackers — may violate these protections if employees are not properly notified in advance.

Under Labor Code Section 980, employers generally cannot require employees to disclose personal social media credentials or access personal accounts. The CCPA gives employees rights over their personal data, including data collected through workplace monitoring tools.

What to do: Provide written notice to employees before implementing any monitoring technology. Consult with an HR professional or employment attorney before deploying surveillance tools. Review your privacy notices to ensure they cover AI-based data collection.

5. Data Security and Confidentiality

When employees input sensitive company or client data into AI tools like ChatGPT, that data may be used to train future models or stored on third-party servers. This creates real risk for trade secrets, client confidentiality, and HIPAA compliance in healthcare-adjacent businesses.

What to do: Establish a written AI use policy specifying what types of data employees may and may not input into AI tools. Treat AI data handling as a data security issue, not just an HR issue.

What California Employers Should Do Right Now

Develop a Written AI Use Policy

If you do not have one, you need one. A compliant AI use policy should cover:

  • Which AI tools are approved for workplace use
  • What categories of data employees may input into AI systems
  • How AI-generated content must be reviewed before use in employment decisions
  • Who is responsible for auditing AI tools for bias and FEHA compliance
  • How violations of the policy are handled

Train Your Managers

Managers are often the first to adopt new tools — and the least likely to think about compliance implications. Train supervisors on the risks of using AI in performance management, scheduling, and communication without proper human oversight. Under FEHA, a manager who relies on an AI output to make an adverse employment decision without independent review has not insulated the organization from liability.

Audit Existing Tools

If you are already using AI in hiring or HR processes, conduct an audit now. Ask:

  • What data was this tool trained on?
  • Has it been tested for disparate impact against protected classes under FEHA?
  • Who reviews the outputs before employment decisions are made?
  • Is there a documented human review step for every adverse action?

Document Everything

In any FEHA or EEOC proceeding, documentation is your defense. Keep records of how AI tools are used, what decisions they inform, and how human review was applied. If a discrimination claim arises, you will need to demonstrate that a human — not just an algorithm — made the final call.

The Bottom Line for California Employers

AI is not going away. The employers who manage it well will be the ones who adopt these tools with clear policies, proper training, and a documented commitment to human oversight. The employers who struggle will be the ones who assumed AI was neutral, skipped the compliance conversation, and found themselves facing a FEHA complaint or CRD investigation.

If you are unsure whether your current use of AI tools is creating legal exposure, an HR compliance review is a practical first step.

Marlene Solis is the founder of Solis Consulting Management, an HR consulting firm serving California and multi-state employers. She specializes in HR compliance, workplace investigations, and building people-first workplaces.

This article is for informational purposes only and does not constitute legal advice. California employers should consult the California Civil Rights Department (CRD) and qualified employment counsel for guidance specific to their situation.

Explore Topics

#AI#artificial intelligence#HR compliance#California HR#FEHA#CCPA#employment law#workplace technology
M

Written by

Marlene Solis

Content creator and writer sharing insights and stories.