When AI Gets It Wrong: Who Actually Owns the Liability?
Picture applying to more than 100 jobs through the same screening platform and never landing a single interview. The vendor calls it an algorithmic anomaly. A federal judge in California saw a viable discrimination claim.
On June 26, 2026, Judge Rita Lin denied Workday’s motion to dismiss in Mobley v. Workday Inc.. Fair Employment and Housing Act (FEHA) and Americans with Disabilities Act (ADA) claims survived against the vendor itself, not just the employer.
Our September 17, 2026 webinar brought together attorneys Maria McReddie, Maria Lobato, and former Chief Information Security Officer (CISO) Larry Whiteside Jr. to unpack what’s next.
The themes worth your attention.
- Vendor liability decouples from employer exposure when tools originate in California
- Contract indemnities promise who pays after the disaster, not who prevents it
- And boards that document oversight survive while boards that stay silent do not
“If you can’t reconstruct consequential decisions a year later, you don’t have governance, you’ve just got compliance theater.” – Kayne McGladrey
The Workday Case
What Happened
Mobley applied to over 100 jobs using the same screening platform. He received zero interviews. Discovery revealed the tool filtered candidates using proxy indicators for race, age, and medical-related leave patterns. The court advanced a direct liability framework rather than routing claims solely through employers.
Workday’s headquarters in Pleasanton created the jurisdictional hook. Think about how many Software as a Service (SaaS) platforms operate out of California. The legal theory treats the tool as an active participant in those rejections, not a neutral instrument. This means the “customers make final decisions” defense just lost its shield.
What It Means for You
The case remains in pleadings phase, and appeals are inevitable. Nothing is settled law. The trajectory, however, is unmistakable:
- Vendors can be sued directly, even if your company has no FEHA exposure
- Screens deployed from California can reach your doorstep through a jurisdictional nexus
- “The algorithm did it” fails as a defense once your system actively screens, scores, or rejects
Contracts Break When Risk Outpaces Bargaining Power
The Risk Template Approach
Small or mid-size companies cannot renegotiate Workday or Microsoft terms. Maria Lobato’s advice was blunt. Build a risk template instead, documenting three things for every vendor relationship:
- What contractual protections you requested but could not secure
- What compensating controls or mitigations you implemented internally
- Which named executive approved the residual exposure
Legal teams highlight risk. They aren’t decision makers. The template forces someone accountable to sign their name.
The Indemnity Checklist
Forward-looking contracts should carve out AI-specific language. Cover design, training data, operation, and deployment. Request audit rights for disparate impact testing. Demand decision reconstruction capability, because if a model drifts after three months, can you prove what it did at rejection time?
The Copyright Trap Nobody Reads
Enterprise agreements carry a hidden problem in intellectual property (IP) language. Outputs belong to you, they say, followed by the qualifier “if any.” Under U.S. domestic law, purely machine-created works cannot be copyrighted. Your company may own nothing.
Personal accounts fare worse. Retention runs 30 days to five years. Human reviewers may read your prompts. Indemnity caps sit around $100 or fees paid, whichever is lower.
| Risk Factor | Personal Account | Enterprise Account |
|---|---|---|
| Model training on your data | Yes | Off by default (opt-in) |
| Human review of prompts | Possible | Not guaranteed |
| IP rights in outputs | None | “if any” caveat |
| Data retention | 30 days–5 years | Negotiated |
| Indemnity ceiling | ~$100 | Negotiated |
Shadow AI Won the War
Gartner reports 68 percent of knowledge workers use AI tools. Only 23 percent of enterprises maintain formal usage policies. That gap isn’t technical. It’s operational, and it compounds daily.
“Employees don’t get fired for security violations. They get fired for not getting the job done.” – Kayne McGladrey
The Identity Gap
Organizations wire organizational charts for humans. Software agents now act like coworkers without badges or non-disclosure agreements. Identity and access management systems routinely clone an accountant’s credentials onto an AI agent because nobody distinguished human from machine entitlements. Ask “who did what” after an incident, and half the “who” turns out not to be human.
Why Blocking Backfires
Companies that block AI websites push usage to personal laptops and phones. Employees face pressure to deliver. Screen captures bypass restrictions. Punishing experimentation guarantees zero visibility into what’s actually happening with your data.
A Colorado magistrate made a related point in Dunn v. LexisNexis Risk Solutions, rejecting approval processes so heavy that every new tool triggered full relitigation. Friction with no point just drives usage underground. I covered the implications at length in a separate post.
The practical alternative treats people as intelligent adults:
- Inventory AI tools separately from other software assets
- Log decisions, not just outputs, so consequential choices can be reconstructed
- Teach staff a handful of evaluation questions (does the vendor hold a SOC 2? does the tool train on your data? would this prompt embarrass you in a press release?)
- Keep low-risk uses frictionless; a cat picture generator doesn’t need committee review
The underlying discipline predates AI entirely. Know what you have, know where it lives, know where it goes, know who can touch it. Larry Whiteside Jr. has spent 34 years in security leadership and argues we’ve never gotten those four right. New technology merely monetizes the same old gaps.
Insurance Exclusions Already Exist
A named policy form took effect at the start of 2026 carrying absolute generative AI exclusions. Coverage language now reaches into fiduciary liability and management liability lines. Insurers are quietly rewriting vague AI wordings into explicit denials.
Larry runs tabletop exercises across the country with 40 to 80 CISOs per session. Each AI scenario ends the same way. The exclusion clause activates, coverage evaporates, and executives discover the gap for the first time on their worst day. He’s watched it happen in live incidents he can’t name.
Real losses already illustrate the exposure. A Canadian tribunal held an airline to its chatbot’s fabricated refund policy. A community bank disclosed customer data exposure through unauthorized employee AI use in an 8-K filing this year.
Maria McReddie’s prescription was straightforward:
- Audit every existing policy for AI exclusion language now, not at renewal
- Negotiate the named form at renewal cycles, treating AI coverage as a new insurance type
- Close the gap between what policies cover and what your customer contracts promise
My backup plan echoes the ransomware era playbook. If you’re banking cost savings from AI, set aside cash reserves against the day an uncovered loss arrives. Early products like Armilla AI, incubated through Lloyd’s Lab, show genuine innovation, but they remain niche for now.
“Coverage gaps extend beyond your policies. They include mismatches between what you promise customers and what you actually insure.”
Governance Requires Ownership, Not Committees
What Boards Actually Need
Delaware Chancery Court set the standard in the Boeing and Marriott derivative cases. Imperfect oversight beats no oversight, provided it’s documented. Boards want one throat to choke, and the owner can be the CISO, CEO, Chief Information Officer (CIO), or general counsel. A separate AI committee adds bureaucracy without adding accountability. Use the audit committee you already have.
Tiered Acceptable Use
Maria Lobato structures client policies around a traffic-light model aligned with the EU AI Act and consistent with the General Data Protection Regulation (GDPR), and it travels well across jurisdictions:
| Tier | Conditions | Requirements |
|---|---|---|
| Green | No personal data, no system access | No approval needed |
| Amber | Some personal or business data, human in loop | Lightweight review |
| Red | Sensitive data, no human oversight | Committee approval plus team training |
Since 2018, GDPR has required meaningful human review for automated decisions on significant outcomes like employment. Europe arrived at this conclusion years before American courts did. Notably, a consent-based approach founders internally, since employee consent within an employment relationship isn’t freely given under European doctrine. Lean on legitimate interest instead.
One attendee proposed in the webinar chat an opt-in model where employees must actively agree to the AI policy rather than inheriting it automatically, with quarterly recertification to keep it serious. Most corporate policies function as checkbox exercises. Anything that makes people pause and read has value.
Know Where to Stop
Not every task needs AI. An architectural firm asked me whether structural engineers could be replaced by machine models. Buildings occasionally fall down, and when they do, liability lands on the firm that signed off, not the vendor who sold the model. Meanwhile, operational technology environments like beverage bottling already run at peak efficiency. The marginal gain doesn’t justify the added exposure.
Edge Cases Worth Watching
Philips v. Parlade surfaced in Nevada federal court in August 2026, holding that judicial immunity covers mistakes made using AI. Compare that with India’s proposed 2026 Guidelines on AI, which would mandate indemnity clauses protecting courts from defects in vendor-supplied systems. Damien Charlotin’s tracker documents at least 32 matters globally where judges relied on hallucinated citations in their rulings.
Reality Check on the Doom Narrative
One final correction on the story making the rounds, the one where AI ends humanity within a decade. That theory traces, in significant part, to the fact that Claude can control your lights. If you opt in. And configure it. That’s the factual foundation, and it’s a stretch by any measure. Larry’s sober counterpoint from his years securing an energy utility carries more weight. The genuine danger is threat actors using cheap, accessible AI against infrastructure that’s aging and fragile.
What to Do Before Litigation Finds You
- Audit vendor contracts for AI indemnity gaps and decision reconstruction rights
- Run documented disparate impact testing on employment screening tools, on real applicant flow
- Inventory AI tools and their credentials, distinguishing machine entitlements from human ones
- Review every insurance policy for the generative AI exclusions introduced in 2026
- Document board-level oversight activities, even imperfect ones, and keep the paper trail
- Train red-tier teams like HR on the specific risks their tools create
- Allocate reserve capital against uncovered AI losses until the insurance market matures
Want to discuss how these issues apply to your organization? Book time with Maria Lobato and me.