California's AI Hiring Rules Aren't Coming — They've Been Live Since October
California’s AI Hiring Rules Aren’t Coming — They’ve Been Live Since October
Most compliance content about AI hiring in the US still talks about California in the future tense — “regulations are coming,” “employers should prepare.” They’re not coming. California’s Civil Rights Council finalized its automated-decision-system regulations under FEHA, and they’ve applied to every employer using AI in hiring decisions since October 1, 2025. If your screening vendor still frames this as a future compliance project, that’s worth noticing.
This matters well beyond California-headquartered companies. Global Capability Centres in Bangalore, Hyderabad, and Pune routinely screen candidates for roles reporting into US parent companies, including California-based ones. If any candidate in your pipeline is being evaluated for a California-based role or team, the regulation likely already applies to that hiring decision — regardless of where your screening tool runs.
What Actually Changed on October 1
The regulations define an “automated decision system” broadly — any computational process used to aid or replace human judgment in an employment decision, including tools that score, rank, filter, or recommend candidates. That’s a direct description of what an AI screening tool does. Three obligations sit inside the regulation that most vendor compliance decks gloss over:
Bias testing, before and after adoption. Employers are expected to test for disparate impact both when a tool is first deployed and on an ongoing basis — courts evaluating a discrimination claim will look at the recency and scope of testing, not just whether testing happened at all.
Multi-year record retention. Employers are expected to preserve the input data, the scoring criteria applied, the output ranking, and any bias-testing results behind every automated hiring decision — current guidance points to a four-year retention window, well beyond a typical applicant-tracking data-retention default. That’s not a dashboard export you generate when asked — it’s a retention obligation that has to be designed into the system from day one, because you can’t retroactively reconstruct scoring criteria for a decision made two years ago if nobody logged it.
The regulation covers the whole employment lifecycle, not just the initial screen — promotion, compensation, discipline, and termination decisions assisted by automated tools are all in scope. Most vendor conversations only cover the hiring-funnel piece.
The Vendor Liability Trap
Here’s the uncomfortable part, and the one we’d rather say plainly than let a customer discover during a compliance review: using a third-party AI screening vendor does not shift liability to that vendor. Under FEHA, deploying an automated decision system is treated as the employer’s own business decision — the employer bears full responsibility for any discriminatory outcome the tool produces, regardless of who built it or where.
That reverses the assumption a lot of procurement conversations quietly rest on — “we bought a compliant tool, so we’re covered.” A vendor being careful about its own model doesn’t transfer that carefulness into your legal exposure. It just means your exposure is only as good as whatever you can independently verify and document about how that tool made its decisions on your candidates specifically.
What This Means If You’re Screening From India
If you’re an Indian AI screening vendor, or an Indian company running campus or lateral hiring for a US-facing team, the practical question isn’t “is my tool compliant” — no regulator has certified any tool as FEHA-compliant, because certification isn’t how this works. The real question is narrower and more useful: for the candidates your team rejected in the last hiring cycle who could plausibly fall under this regulation, could you reconstruct — today, not in theory — what input data, scoring criteria, and output ranking produced each rejection? If that reconstruction requires a support ticket and three days rather than an export button, that’s the gap this regulation is built to expose.
This is the same audit-trail question New York’s Local Law 144 enforcement gap already put in front of vendors — California’s version just adds a hard retention period and an explicit statement that the vendor doesn’t absorb the liability for you. Two state regulators asking the same question from different angles is a pattern, not a coincidence.
Where This Actually Bites
The gap shows up fastest for high-volume, high-rejection screening — exactly the shape of a 2,500-3,000 candidate campus drive with a 60%+ auto-rejection rate. Volume means more decisions to retain data on; a high rejection rate means more decisions a regulator or plaintiff’s attorney would want reconstructed first, because rejections are where discrimination claims originate, not offers. If your screening process can’t tell you why a candidate rejected six months ago was rejected, volume is the thing that turns a manageable compliance gap into an unmanageable one.
We built HireQwik’s decision layer around a transcript-and-scoring record that ties every reject to the specific criteria the AI applied at the time — not because we set out to build a FEHA-compliance product, but because “why was this candidate rejected” is a question honest recruiters ask us constantly, independent of any regulator. It turns out being able to answer that question on demand is most of what this regulation requires anyway.
If you’re not sure whether your current screening process could survive that reconstruction test, talk to us — it’s a shorter conversation than most compliance reviews.
See HireQwik in action
Book a 30-minute demo — bring a live JD and we'll screen your own candidates against it.