Workflow · July 20, 2026
Draft a Class-Action Risk Memo for Your AI Hiring Tool Stack
The task
In-house counsel and outside employment lawyers are being asked — often on short notice — to assess class-action exposure from the AI screening, sourcing, and video-interview tools HR has quietly rolled out. The deliverable is a privileged risk memo naming the tools, the theories of liability, the vendor-contract gaps, and the mitigations you want HR to make this quarter. This workflow turns a vendor inventory into a defensible first draft you can redline before it leaves your desk.
Before AI
The manual version: pull the vendor list from procurement, read three or four recent complaints (Mobley v. Workday, the Eightfold FCRA suit, the various BIPA video-interview cases), skim EEOC and state guidance, then draft section by section. Realistically 4-6 hours if you already know the caselaw, more if you're briefing yourself for the first time. Most of that is structural — organizing what you already know into memo shape — which is exactly what an LLM handles well.
For background on why this is landing on legal's desk now, see the corporate counsel survey coverage in HR Executive and the ABA's overview of algorithmic bias litigation trends in employment screening.
The workflow
Step 1 — Turn the vendor inventory into a structured risk table.
Paste your HR-provided list of AI hiring tools (name, function, jurisdictions where used, protected-class data touched). The prompt below tags each tool with likely theories of liability.
You are a senior employment litigation attorney drafting a privileged, attorney-work-product risk assessment for in-house counsel. The user will provide a list of AI/algorithmic tools currently used in the company's hiring funnel. For each tool, produce a row in a markdown table with these columns: 1. Tool & vendor 2. Hiring-funnel stage (sourcing / screening / assessment / interview / offer) 3. Protected-class inputs or proxies (age, race, disability, national origin, gender — flag proxies like ZIP, school, gaps in employment, voice/facial analysis) 4. Primary class-action theories in play (e.g., Title VII disparate impact, ADEA, ADA reasonable accommodation, state AI audit laws like NYC Local Law 144, Illinois AIVIA, BIPA for biometrics, FCRA if the tool aggregates consumer-report-like data) 5. Analogous pending or settled cases to cite (Mobley v. Workday, Eightfold FCRA action, CVS/HireVue-style BIPA suits, iTutorGroup ADEA settlement — only cite ones you are confident exist) 6. Preliminary risk rating (High / Medium / Low) with a one-sentence reason After the table, write a short "Assumptions & information gaps" list: what you'd need HR or procurement to confirm before the rating firms up. Do not invent caselaw. If a cell is unknown from the input, write "Confirm with HR." Begin the memo with the header: "PRIVILEGED & CONFIDENTIAL — ATTORNEY WORK PRODUCT — Prepared at the request of the General Counsel." Here is the vendor inventory:
Company: Meridian Foodservice Holdings (approx. 42,000 US employees, ops in CA, IL, NY, TX, FL) AI hiring tool inventory as of Q2: 1. TalentPilot AI (vendor: TalentPilot Inc.) — resume ranking / applicant scoring. Used for all hourly and salaried reqs. Ingests resume text, self-reported EEO data is walled off per vendor. Rolled out April 2024, no bias audit on file. 2. VidScreen Async (vendor: VidScreen Labs) — one-way video interviews for shift-lead and above. Uses facial-expression and vocal-tone scoring. Used in all 50 states including IL and TX. 3. SourceForge Reach (vendor: SourceForge HR) — programmatic job-ad targeting on social platforms. Age and gender inferred from platform audience segments. 4. FitCheck Assessment (vendor: Cognify) — gamified cognitive assessment for corporate roles. No documented ADA accommodation pathway; candidate requests routed informally to recruiter. 5. OfferOptimizer (vendor: PayLens) — recommends starting salary based on candidate profile and market comp data. Live in CA and NY. Known incidents: Two internal complaints in the last 9 months from candidates over age 55 alleging they were auto-rejected by TalentPilot without human review. No litigation yet. NYC Local Law 144 bias audit was completed for TalentPilot only.
Step 2 — Draft the narrative memo sections around that table.
Now expand the table into the memo body: theories of liability, vendor-contract gaps, and recommended mitigations. This is the section where hallucinated cites are most dangerous, so the prompt constrains what the model can assert.
Using the risk table and assumptions you just produced, draft the remainder of the privileged risk memo. Use these exact section headings, in this order:
I. Executive Summary (5-8 bullets, plain English, for the GC and CHRO)
II. Legal Framework
A. Federal — Title VII disparate impact, ADEA, ADA, FCRA where applicable
B. State — call out any jurisdiction in the input (e.g., Illinois BIPA and AIVIA, New York City Local Law 144, California FEHA/ADS regs, Colorado AI Act if in scope)
C. EEOC guidance treating algorithmic selection procedures as "selection procedures" under the Uniform Guidelines
III. Tool-by-Tool Risk Analysis (reference the table; add one paragraph per tool covering the theory most likely to be pled first)
IV. Vendor Contract Gaps (indemnity scope, audit rights, data-retention, cooperation in litigation, IP/model-training carve-outs, source-of-training-data reps, notice of regulatory inquiry)
V. Privileged Recommendations (30/60/90 day) — bias audits, human-in-the-loop review, ADA accommodation pathway, candidate notice/consent language, document-retention hold considerations, insurance review (EPLI + tech E&O from vendor)
VI. Open Questions for HR, Procurement, and IT Security
Rules:
- Do not cite any case, statute, or regulation you are not certain exists. If you are unsure, describe the theory generically ("courts have allowed disparate-impact theories to proceed against vendors of algorithmic screening tools") rather than inventing a citation.
- Every recommendation must be concrete enough that HR could action it — no "consider evaluating."
- Preserve the PRIVILEGED & CONFIDENTIAL header at the top.
- Keep total length under roughly 1,500 words.Step 3 — Stress-test the draft against plaintiff-side theories.
Before it goes to the GC, run a red-team pass. This surfaces the arguments a plaintiff's firm would lead with — which is what determines whether your mitigations are actually pointed at the right risk.
Switch roles. You are now a plaintiffs' class-action employment lawyer reading the company's internal risk memo above. In no more than 500 words: 1. Identify the three strongest class or collective theories you would file first, and against which of the listed tools. 2. Point out any factual admissions or gaps in the memo that would help a plaintiff at the motion-to-dismiss stage (e.g., missing bias audit, informal accommodation pathway, biometric use in Illinois). 3. Identify which vendor is the most attractive co-defendant or third-party defendant and why. 4. Flag any argument the memo currently *understates* — meaning the defense-side draft is too comfortable. Return this as an appendix titled "Appendix A — Red-Team Review (privileged)." Do not rewrite the memo; just flag issues by section reference so counsel can revise.
Step 4 — Hand-review, then attach to your privileged file.
Read every citation, every statute name, every jurisdiction claim. Delete anything the model asserted that you can't personally verify in Westlaw or Lexis in under two minutes. What survives is your working draft.
Gotchas
- Fabricated cites are the #1 failure mode. Even with the "do not invent" instruction, models occasionally produce plausible-looking case names and docket numbers. Check every citation before circulating. The safer play is to let the model describe theories generically and add the citations yourself.
- Privilege hygiene. The "PRIVILEGED & CONFIDENTIAL — ATTORNEY WORK PRODUCT" header is necessary but not sufficient. If you're using a public LLM, confirm your firm or company has an enterprise agreement with no-training and confidentiality terms; otherwise use only synthetic or heavily-redacted vendor data as input.
- Jurisdictional drift. State AI-in-employment law is moving fast (Colorado AI Act, California ADS regs, NYC Local Law 144). The model's snapshot of what's in force may be stale by a quarter. Verify against a current tracker before finalizing Section II.B.
- Vendor contract gaps are the leverage point. The memo is only useful if it gives procurement specific redline asks — indemnity for algorithmic discrimination claims, audit rights, cooperation clauses. If Section IV comes back generic, re-prompt with your actual MSA language pasted in.
- Don't skip the red-team step. Skipping Step 3 produces a memo that reads well and misses the theory plaintiffs will actually plead.
Time saved
A typical first-draft AI-hiring risk memo runs 4-6 hours of attorney time — mostly structural drafting, not legal judgment. This workflow moves the drafting to roughly 30-45 minutes of prompting plus 45-60 minutes of citation verification and substantive redline, saving on the order of 3-4 hours per memo. Estimate, not a measurement; your mileage varies with how clean the vendor inventory is and how much of the caselaw you already carry in your head.
What we got when we ran it
We executed every prompt above, in order, against the sample input (model: claude-sonnet-4-6). Outputs below are real and unedited apart from length truncation.
Step 1 output
# PRIVILEGED & CONFIDENTIAL — ATTORNEY WORK PRODUCT — Prepared at the request of the General Counsel Meridian Foodservice Holdings — AI Hiring Tool Risk Assessment Prepared by: Employment Litigation Counsel Date: Q2 2024 Classification: Attorney-Client Privilege / Attorney Work Product Doctrine Distribution: Restricted to General Counsel and designated in-house legal team only --- > Preliminary note on scope: This memorandum constitutes a privileged litigation risk assessment prepared in anticipation of potential employment litigation. It is not a compliance certification, an HR policy directive, or an admission of any violation. All ratings are counsel's preliminary judgment based on publicly available law, disclosed facts, and known litigation trends. Ratings are subject to revision upon receipt of additional information identified in the Assumptions & Information Gaps section below. --- ## AI Hiring Tool Risk Matrix | # | Tool & Vendor | Hiring-Funnel Stage | Protected-Class Inputs or Proxies | Primary Legal Theories in Play | Analogous Pending / Settled Cases | Preliminary Risk Rating | |---|---|---|---|---|---|---| | 1 | TalentPilot AI / TalentPilot Inc. | Screening | Resume text may encode proxies for race (HBCU/minority-serving institution names, neighborhood/ZIP codes, names with ethnic markers), age (graduation year, length of work history, employment gaps), and gender (gendered language patterns, sorority/fraternity affiliations). EEO data reportedly walled off, but proxy ingestion is the primary concern. | Title VII disparate impact (42 U.S.C. § 2000e-2(k)); ADEA disparate impact (29 U.S.C. § 623 + Smith v. City of Jackson); NYC Local Law 144 (bias audit partially completed
…output truncated at 250 words.
Step 2 output
# PRIVILEGED & CONFIDENTIAL — ATTORNEY WORK PRODUCT — Prepared at the request of the General Counsel Meridian Foodservice Holdings — AI Hiring Tool Risk Memo (Continued) Prepared by: Employment Litigation Counsel Distribution: General Counsel, CHRO only --- ## I. Executive Summary - Meridian is operating five AI hiring tools simultaneously, at least three of which present litigation-ready exposure today — meaning a plaintiff's attorney could file a facially viable class or collective action based on publicly available facts without additional discovery. - TalentPilot AI has already generated two internal complaints from 55+ candidates alleging auto-rejection without human review. Those complaints are potential EEOC charge predicates; a litigation hold should be evaluated this week. - VidScreen Async is collecting facial geometry and voiceprint data from candidates in Illinois without confirmed BIPA-compliant written consent. Each unconsented collection is a separate statutory violation carrying liquidated damages of $1,000–$5,000 per person per occurrence under BIPA. - SourceForge Reach is using age and gender as direct audience-segment inputs for job-ad delivery — not proxies, but the protected characteristics themselves. This is among the highest-risk configurations in the inventory because it may support an intentional discrimination theory, not merely disparate impact, eliminating the business-necessity defense. - FitCheck Assessment has no documented ADA accommodation pathway. Routing accommodation requests informally through recruiters is legally insufficient and creates individual-claim exposure on every corporate hire where a candidate with a disability was assessed without accommodation. - OfferOptimizer may be perpetuating historical pay disparities through proxy inputs (prior salary, employer
…output truncated at 250 words.
Step 3 output
# PRIVILEGED & CONFIDENTIAL — ATTORNEY WORK PRODUCT — Prepared at the request of the General Counsel Appendix A — Red-Team Review (Privileged) Prepared by: Employment Litigation Counsel (Adversarial Perspective Review) Purpose: To pressure-test the foregoing risk memo from a plaintiff's-counsel standpoint and identify where the current defense posture is thin, overconfident, or incomplete. Distribution: General Counsel only --- ## 1. Three Strongest First-Filed Theories First: BIPA Class Action Against VidScreen Async (Illinois) This is the most attractive filing from a plaintiff's standpoint. The memo itself concedes — in Sections II.B and III — that biometric data is being collected in Illinois without confirmed written consent and without a publicly available retention and destruction schedule. BIPA provides a private right of action with no actual-harm requirement, liquidated statutory damages of $1,000–$5,000 per violation per person, fee-shifting, and a five-year limitations period. The class is self-defining: every Illinois candidate who completed a VidScreen Async interview. Plaintiff's counsel would not need a single expert at the pleading stage — the memo's own language ("without confirmed BIPA-compliant consent framework") is the complaint. This case files in Cook County state court tomorrow. Second: ADEA Collective Action Against TalentPilot AI (Nationwide) The memo identifies two named complainants over age 55 alleging auto-rejection without human review — that is a collective action with pre-identified opt-in plaintiffs already in hand. Under 29 U.S.C. § 216(b), conditional certification requires only a modest showing that putative collective members are similarly situated. Plaintiff's counsel would argue that every 40+ applicant
…output truncated at 250 words.
---
This content is for informational purposes only and is not legal advice. Confirm confidentiality, privilege, and jurisdictional rules before using any AI tool with client matters.
Source: hrexecutive.com
More for Legal professionals →
Get the next one in your inbox