In December 2027, a rule takes effect across the European Union that changes the posture of any company using AI to decide things about people: hiring, promoting, evaluating performance, or setting the terms of a job through AI now counts as high-risk, with a requirement that a human being can understand, monitor, and, if needed, stop the decision before it takes effect. That is what Article 14 and Annex III of the European AI law spell out, and they name exactly the cases that show up most often inside companies today: filtering applications, evaluating candidates, deciding on a promotion or a termination, assigning tasks based on behavior.
Across the Atlantic, New York City already treats this as more than a promise: since 2023, any company using an automated tool to screen or evaluate candidates there has to publish an independent bias audit every year and notify each candidate at least ten business days in advance. Companies that fail to comply pay a fine per violation — and skipping the audit and skipping the notice count as two separate violations.
In Brazil, the path is different, but the destination looks similar: the country's data protection law already gives a person affected by a decision made solely through automated processing the right to request a review, and that covers decisions about someone's professional, consumer, or credit profile — not only decisions made by big tech companies. For anyone shaping internal AI policy at a Latin American company, these three fronts aren't distant news: they describe the design any tool that decides about people will eventually have to follow.
The Problem Isn't the Algorithm, It's the Silence Around It
The most visible case didn't come out of Europe or New York — it came from a lawsuit in California. Derek Mobley, a Black man over forty with a disability, applied to more than one hundred positions through Workday's recruiting platform starting in 2017. The replies came back almost instantly, many overnight, always negative, without a single interview. In 2023 he sued the company, alleging that its automated screening system discriminated on the basis of age, race, and disability.
The case took years just to settle a prior question: who is responsible when a screening tool makes the call instead of a recruiter? In 2024 a court found that Workday could be treated as an agent of the employers using its tool — not as a neutral software vendor. In May 2025 part of the case became a nationwide collective action, open to applicants over forty screened by the system since 2020. In June 2026 a judge denied Workday's motion to dismiss, keeping the age- and disability-discrimination claims alive.
Mobley isn't an outlier, it's a symptom. Researchers from Stanford, Chapman, and Northeastern universities analyzed more than 4 million applications from 3 million people, all screened by algorithms from a single vendor across 156 employers. By examining each job posting separately — instead of averaging across all of them, which had hidden the problem — they found that nearly 26% of applications from Black candidates and about 15% of applications from Asian candidates went to postings where the algorithm produced an outcome the U.S. legal standard treats as discriminatory. In some cases, the same person was rejected across multiple employers' openings at a higher rate than would be expected if each company decided independently — a pattern the researchers called systemic rejection.
Nearly 26% of all applications submitted by Black applicants — close to 40,000 submissions — were for positions where the algorithm produced what federal guidelines define as discriminatory outcomes.
The pattern behind both cases isn't technical. It's that, at the moment the decision happened, no one inside the company could say what information it was based on, or who — or what — confirmed it.
Why Reviewing After the Fact Doesn't Work

The most common response, after reading numbers like these, is to publish a policy or run a one-time audit when the tool launches. Both help, but neither solves the core problem, for two reasons.
The first is timing. An annual audit, like the one New York requires, happens after the fact: even with good practices, a biased pattern can run for months before anyone audits again and notices it. In that window, the decision has already happened to hundreds or thousands of people.
The second is that reviewing "after the fact" usually means reviewing the outcome, not the process. No one recorded, at the moment of the decision, who requested the screening, with what instruction, or based on what company information. Without that record, a later audit only sees the aggregate result — the same problem the Stanford-led study found when it noticed that averaging across all job postings had hidden the bias that showed up posting by posting.
What's missing isn't more rules. It's a mechanism that acts at the moment of the decision, not after it.
What Has to Be in Place
An AI environment that decides, suggests, or influences decisions about people — hiring, promotion, credit, disciplinary action — needs verifiable mechanisms before any decision leaves the conversation.
Identity of who asked. Every request for screening, evaluation, or a recommendation carries the name of the person who made it, coming from the same identity directory the company already uses — never a personal account outside IT's control.
Human approval before the action, not after the outcome. A sensitive action about a person — rejecting a candidate, flagging credit risk, proposing disciplinary action — pauses and asks for confirmation from someone with authority before it goes through, inside the conversation itself, not in an audit that chases what already happened.
Segregation between who proposes and who approves. The person, or the agent, that suggests the decision and the person who confirms it can't be the same, so an automatic recommendation never becomes a final decision on its own.
Access according to each person's role. Only people with authority over HR, credit, or conduct can confirm this kind of decision; every other profile in the company doesn't even see the option.
An audit trail that can be reconstructed. When someone disputes a decision — as happened in the Mobley case — it takes minutes, not guesswork, to reconstruct what information the decision was based on, who requested it, and who confirmed it.
This is how Skyller was designed: human approval before a sensitive action, access according to each person's role, and a detailed audit trail across the system.
What Changes for the People Deciding

The most visible gain is legal. Much of the Mobley case turned on a question an audit trail would answer in seconds: who controlled the tool at the moment of the decision, and whose agent was it acting as? Companies that record who requested and who confirmed each decision about a person enter that kind of dispute with evidence, not with a reconstruction of memory months later.
There's a gain that comes before the dispute: fewer disputes to begin with. When human approval happens before the action — not afterward, in an audit — some of the errors that trigger complaints never reach the person at all. And when a candidate or an employee knows a human confirmation step exists, the decision carries less distrust, even when the outcome is negative.
For HR, credit, or compliance teams, the practical gain is being able to separate, inside the system itself, what was an AI suggestion from what was a decision confirmed by a person — the exact distinction that judges, regulators, and candidates have been demanding more often every year.
Questions to Bring to Your Next Meeting
Before expanding AI use in any decision that affects people, it's worth bringing these questions to the next meeting with HR, legal, and IT:
- Does any decision about hiring, promotion, credit, or discipline leave a conversation with AI today without a recorded human confirmation? If the answer is yes, that's the first thing to fix, before any other adjustment.
- Do the requester and the approver show up as different people in the record, or is it always the same person in both roles? If it's always the same person, there's no real segregation — just her name twice.
- If a candidate or employee disputes a decision six months from now, can you reconstruct what information it was based on? Without that trail, the company's defense depends on memory, not on record.
- Can the company point, for any decision about a person in the last 90 days, to who confirmed it? If the answer requires searching across several different tools, the record doesn't really exist — it's scattered.






