Why AI Risk Management Must Treat Ethical Conduct as a Business Imperative, Not Just a Compliance Box

A federal judge in California ruled this month that Workday can be held liable for AI-driven hiring discrimination under state civil rights law — even for employers who never touch the algorithm themselves.

The case, Mobley v. Workday, covers more than a billion rejected applications and rests on a simple but uncomfortable idea: an AI vendor acting as an employer’s “agent” can’t hide behind the black box when the outcomes are discriminatory.

For boards, executives and risk teams, this is the moment ethics stops being a values statement and becomes a line item on the risk register.

The 30-second take

Ethical conduct in AI use is a tangible risk management priority, not an aspirational add-on.

Boards and executives must move beyond principles and policy statements toward AI strategy, governance, risk assessment, and genuine human oversight.

Mobley v. Workday shows what happens when that oversight is missing: liability flows to whoever deployed the system, vendor included. Organisations that can’t produce evidence of how ethical risk is assessed and controlled are exposed — legally, reputationally, and commercially.

What’s actually happening — three real scenarios

Mobley v. Workday (United States, 2026). Derek Mobley applied to more than 100 roles through employers using Workday’s AI screening tools and was rejected every time. In June 2026 a federal judge allowed his age discrimination claims to proceed under an “agent” theory of liability, and roughly 14,000 people have since joined the collective action. The ruling puts every algorithmic hiring platform — and every business that relies on one without validating it — on notice.

Eightfold AI consumer-report claims (United States, 2026). A separate class action filed against Eightfold AI alleges its AI-generated applicant scores, built from external signals like social media activity and “career trajectory,” function as consumer reports under the Fair Credit Reporting Act. The theory matters beyond hiring: any AI system scoring people from third-party data may carry obligations the business never designed for.

The board oversight gap (NACD / Fortune 100, 2026). Despite 88% of large organisations using AI in at least one business function, only 39% of Fortune 100 companies disclosed any form of board-level oversight of AI. The AICD’s own guidance to Australian directors makes the same point: AI governance frameworks need a defined accountable owner and continuous evaluation, not a one-off sign-off.

Questions to ask your organisation

  • Can we produce documented evidence of an ethical risk assessment for every AI system that makes or influences decisions about customers, employees, or applicants?
  • If we use a vendor’s AI model, have we validated it ourselves, or are we relying entirely on the vendor’s assurances?
  • Where AI scores or ranks people, do we know exactly what data feeds that score, and would it hold up as a “consumer report” or equivalent under relevant law?
  • Is human review of AI-influenced decisions meaningful — can staff actually challenge or override an outcome — or is it a token sign-off?
  • Who is the named, accountable owner for the ethical performance of each material AI system, and what do they report to the board?
  • What is our process for capturing and escalating an ethical incident before it becomes a legal or reputational one?

Human Oversight, Ethics and Responsible Decisioning

This Innovation of Risk theme helps leaders focus on real-world ethical risk management.

Our tools help ask:

  • what decisions does AI influence or make?
  • What human review is required, and is it meaningful?
  • Can staff override or escalate outcomes?
  • How are fairness, ethics, and customer impact managed in practice — not just documented in a policy?

Innovation of Risk provides AI maturity and risk assessment tools to help organisations have better internal risk, governance and assurance discussions. This post is general information only and is not legal, regulatory, audit or professional advice.

Want to see how your organisation’s AI ethics and oversight practices measure up? Take a readiness snapshot in the Innovation of Risk Reading Room.


Free 3–5 minute AI diagnostic

Know where your AI governance stands in five minutes.

Use a short diagnostic to test practical AI governance, oversight and risk controls. Get an immediate visual result and suggested next focus areas.

Practical tools for boards, executives, auditors and risk professionals.

10 questions Visual result Local browser storage
Learn more Visit reading room
Privacy note: your individual results are not stored by Innovation of Risk. Results stay in your browser; we only track aggregate usage such as page views and average score once you leave our page.

More from the Reading Room

Why AI Risk Management Must Integrate Privacy, Security and Ethical Oversight from the Start

AI risk management is more than compliance—it requires integrated oversight of privacy, security, and ethics to protect customers and uphold trust. Business leaders must embed these considerations early to avoid harm and accelerate responsible AI adoption.

Why AI Operational Resilience Must Be a Boardroom Priority Now

AI failures can disrupt critical operations and damage customer trust. Boards and executives must treat AI operational resilience as a core governance responsibility—not just a technical issue—to safeguard business continuity and reputation.

How to Master AI Risk Control Testing for Real-World Assurance

NIST’s August 2026 TEVV-Athlon draft makes real-world AI evaluation a current governance issue. Businesses should connect every test to pre-agreed acceptance thresholds, a named decision owner and clear retest triggers.

Why Clear Third-Party AI Evidence Requirements Are Non-Negotiable for Risk Management Success

ASD’s Australian Cyber Security Centre and the UK National Cyber Security Centre show why AI supplier assurance must cover the full lifecycle and extended supply chain. Moffatt v Air Canada demonstrates that business accountability remains with the organisation using the automated service.