← All posts

AI Hiring Tools: The Discrimination Gap Bias Audits Miss

AI Hiring Tools: The Discrimination Gap Bias Audits Miss
TL;DR

The DOJ's $3.2 million settlement with OpenAI over citizenship-status discrimination exposed a gap in AI hiring tool compliance: standard bias audits test race, ethnicity, and sex, but not citizenship status or national origin. Vendors and buyers need to verify the full candidate funnel, not just the model card.

The $3.2 Million Hiring Case Nobody Connected to AI Tools

On August 4, 2026, the U.S. Department of Justice's Civil Rights Division announced a combined $3.2 million settlement with OpenAI OpCo LLC and its subsidiary Statsig Inc. The allegation was citizenship-status discrimination in PERM recruitment, in violation of the Immigration and Nationality Act (INA).

The details are worth reading closely, because almost none of the coverage connected them to the product category that should be paying attention: AI hiring tools.

According to the DOJ's press release, OpenAI did not advertise PERM positions on its external job site, even though that was standard practice for other roles. It required paper applications for those positions while allowing electronic applications elsewhere. It advertised some roles on the radio late at night. Fewer than ten positions were involved, but the resolution still came to $1.2 million in civil penalties plus a $2 million back-pay fund.

Here is the thing. None of that required an AI model. It was process discrimination, plain and simple. And that is exactly the point for anyone building, selling, or buying AI hiring software.

The Category Under Pressure: AI Hiring Tools

AI hiring tools sit at a strange intersection. They promise to remove human bias from screening, ranking, and interviewing. Their documentation, from model cards to marketing pages, leads with fairness. Reduce bias. Objective screening. Compliant by design.

Most of those claims are anchored to a narrow definition of what discrimination means. And that narrow definition is where the exposure lives.

New York City's Local Law 144 is the best-known AI hiring regulation in the United States. It requires an independent bias audit before an automated employment decision tool is used, with a public summary of results and a 10 business day notice to candidates. Enforcement began July 5, 2023, per the DCWP's AEDT page.

The EU AI Act, fully enforceable for high-risk systems since August 2, 2026, classifies employment AI, including recruitment and promotion, as high-risk under Annex III. That triggers risk management, data governance, human oversight, and technical documentation obligations, with fines up to EUR 15 million or 3% of global turnover for the high-risk tier. We broke down the five obligations due now in a separate framework post.

So the compliance conversation is already active. The gap is what those frameworks actually test for.

The Discrimination Gap Bias Audits Miss

Here is the information gain in one sentence. NYC Local Law 144 bias audits evaluate selection rates across race, ethnicity, and sex. The INA's anti-discrimination provision, 8 U.S.C. § 1324b, covers citizenship status and national origin. Those are not the same thing.

A hiring tool can pass a clean Local Law 144 bias audit, with published results showing no adverse impact across race, ethnicity, and sex, and still be configured to filter on citizenship status or visa sponsorship in a way that runs straight into the exact violation OpenAI just paid $3.2 million to settle.

Citizenship-status discrimination is a distinct legal axis. It is not a subset of the categories a standard bias audit reports. A vendor can be bias-audit compliant and still ship a tool, or a workflow, that excludes U.S. workers in favor of visa holders. That is precisely the conduct the DOJ's Protecting U.S. Workers Initiative is now pursuing against technology companies.

The OpenAI settlement is the thirteenth under that initiative since it relaunched in 2025. The DOJ was explicit about the pattern it is targeting: companies that structure hiring to prefer temporary visa holders over U.S. workers. When that structuring happens inside software rather than through paper applications and late-night radio ads, the same statute applies.

What Regulatory Requirements Actually Demand

For AI hiring tools, three frameworks now overlap, and they do not align cleanly.

The INA, 8 U.S.C. § 1324b, prohibits citizenship-status and national-origin discrimination in hiring, firing, and recruitment. It is enforced by the Immigrant and Employee Rights section of the DOJ Civil Rights Division. There is no AI exception. If a tool's logic or a workflow's configuration excludes on citizenship status, it is in scope.

NYC Local Law 144 requires a bias audit, a public results summary, and advance notice. The audit looks at selection rates for protected categories, but the categories it operationalizes are race, ethnicity, and sex. Citizenship status is absent from the standard audit methodology.

The EU AI Act, codified at Regulation (EU) 2024/1689, classifies employment AI as high-risk under Annex III. That is a far broader obligation set, but its focus is risk management and fundamental rights, not the specific U.S. citizenship-status axis. A vendor compliant with all three can still carry a gap on the INA axis, because that axis is the one the U.S. federal government is now actively enforcing against the AI sector.

Gaps and Risks for Vendors and Buyers

The practical risk breaks into two directions.

For vendors, the risk is shipping a feature that enables citizenship-status filtering, or a workflow that does it by default, without recognizing that this is a federal civil rights issue, not a feature request. The DOJ settlement makes clear the government is naming technology companies specifically.

For buyers, the risk is inheriting a tool that passed a bias audit and assuming that covers everything. It does not. A clean Local Law 144 report says nothing about whether the tool or the surrounding workflow excludes on citizenship status or national origin. Our internal audit checklist walks through what to check before signing.

There is also a documentation risk. Most AI hiring vendors publish model cards and bias audit summaries, but very few document the full candidate-funnel configuration, including which fields are filterable, which statuses are excluded, and who controls those settings. That is exactly the layer where INA exposure hides.

What Buyers and Vendors Should Verify

  • Ask whether the tool can filter or rank on citizenship status, visa type, or work authorization. If it can, ask why, and whether that filter is a default.
  • Request the full bias audit, not just the summary, and confirm which categories it actually tested. Citizenship status and national origin are usually absent.
  • Map the candidate funnel from job posting to offer. Discrimination can live in the workflow around the tool, not in the model.
  • Confirm how the vendor handles the EU AI Act Annex III employment classification if the tool touches EU candidates.
  • Get the INA compliance question in writing. If the vendor has never heard of 8 U.S.C. § 1324b, that is a finding.

The BizThriveAI Take

The OpenAI settlement is not an AI story in the way most coverage framed it. It is a hiring-process story with an AI company's name on it. But the lesson transfers directly to the AI hiring-tool category, and it transfers now.

The compliance conversation has been trained on a specific definition of bias, the selection-rate definition that Local Law 144 and the EU AI Act's high-risk regime operationalize. The DOJ is enforcing a different axis, citizenship status, and it is doing so against the technology sector on purpose.

The vendors and buyers who treat a passed bias audit as the end of the question are carrying an exposure they have not measured. The ones who map the full funnel, including the citizenship-status axis, are the ones enterprise procurement trusts in 2026. If you want to see how independent verification reads against your funnel, book a call, review a sample report, or check pricing.

If you are building or buying AI hiring software and want to know whether your funnel has the gap this settlement exposed, start with the configuration, not the model card. That is where the $3.2 million is.

Written by David Swan, reviewed and fact-checked against primary regulatory sources. AI-assisted but human-directed.

Frequently asked questions

What was the DOJ's OpenAI settlement about?

On August 4, 2026, the DOJ announced a $3.2 million settlement with OpenAI OpCo LLC and Statsig Inc. over citizenship-status discrimination in PERM recruitment, in violation of the Immigration and Nationality Act. It included $1.2 million in civil penalties and a $2 million back-pay fund.

Why does the OpenAI settlement matter for AI hiring tools?

The conduct involved process discrimination, like paper-only applications and late-night radio ads, rather than an AI model. The same legal exposure transfers to software: an AI hiring tool or workflow that excludes on citizenship status or visa type violates the same statute, even if no algorithm is involved.

What do NYC Local Law 144 bias audits actually test?

Local Law 144 requires an independent bias audit of automated employment decision tools, with a public results summary and a 10 business day candidate notice. The audits evaluate selection rates across race, ethnicity, and sex, but do not cover citizenship status or national origin.

Is citizenship-status discrimination covered by the EU AI Act?

The EU AI Act classifies employment AI as high-risk under Annex III, which triggers broad risk management and documentation obligations. But the specific U.S. citizenship-status axis is enforced under 8 U.S.C. 1324b by the DOJ, not by the EU AI Act.

What should buyers verify in an AI hiring tool?

Confirm whether the tool can filter or rank on citizenship status, visa type, or work authorization. Request the full bias audit and check which categories it tested. Map the full candidate funnel from posting to offer, and get the vendor's INA compliance position in writing.

Does passing a bias audit mean a hiring tool is compliant?

No. A bias audit covers a narrow set of categories. A tool can pass a clean Local Law 144 audit and still be configured to discriminate on citizenship status or national origin, which is a separate federal civil rights violation.