Since October 1, 2025, California employers with five or more employees have been covered by new rules on how they can use AI tools to hire, promote, or discipline people. The rules come from the Civil Rights Council, the body that writes regulations under the Fair Employment and Housing Act (FEHA), and they don’t require a new department or a compliance officer. They do require knowing whether a tool the business already uses, an AI resume screener, a screening chatbot, a video-interview scoring service, counts as an “automated-decision system” under the rule, and what to do if it does.
What changed on October 1, 2025
The Civil Rights Council finalized amendments to Title 2 of the California Code of Regulations, the section that governs FEHA discrimination claims, effective that date. FEHA already banned discrimination in hiring, promotion, and discipline before this. What changed is that the regulations now spell out how that ban applies when a computer program, not a person, makes or shapes the decision.
Four pieces of the rulemaking reach an ordinary small business:
- A formal definition of “automated-decision system” (ADS), broad enough to cover most AI-assisted hiring and screening tools on the market.
- A rule making it unlawful to use an ADS, a qualification standard, an employment test, or a “proxy” that discriminates on a FEHA-protected basis, unless the employer can show a permissible defense.
- A longer recordkeeping requirement: four years instead of two, now explicitly covering “automated-decision system data,” not just paper personnel files.
- A formal definition of “agent” that makes clear a vendor administering an ADS on an employer’s behalf can itself be treated as an employer under FEHA, on top of the employer’s own liability for what its vendors do.
None of this requires a business to stop using AI tools. It requires knowing which tools count, and keeping a short paper trail that shows the business took the risk seriously.
What counts as an automated-decision system
The regulation’s own definition, at 2 CCR § 11008.1(a), is: “a computational process that makes a decision or facilitates human decision making regarding an employment benefit,” which “may be derived from and/or use artificial intelligence, machine-learning, algorithms, statistics, and/or other data processing techniques.”
That’s deliberately broad. The regulation lists five specific things an ADS does that trigger the rule:
- Runs computer-based assessments, tests, questions, puzzles, or games to predict how an applicant will perform, measure their skill or reaction time, gauge personality or “cultural fit,” or screen and rank candidates.
- Directs job ads or recruiting material to specific, targeted groups of people.
- Screens resumes for particular terms or patterns.
- Analyzes facial expression, word choice, or voice during an online interview.
- Analyzes employee or applicant data acquired from a third party.
If a tool does any one of these five things and the output feeds into a hiring, promotion, discipline, or pay decision, the regulation treats it as an ADS, whether or not the vendor calls it “AI.”
What’s explicitly excluded
The regulation also lists what it doesn’t cover, ruling out a lot of ordinary office software: word processors, spreadsheets, map navigation tools, web hosting, domain registration, networking, data storage, firewalls, antivirus software, spam filters, spellcheckers, calculators, and databases. The condition on this list matters as much as the list: these tools are excluded “provided that these technologies do not make a decision regarding an employment benefit.”
That last clause is the whole test. A spreadsheet that a manager uses to manually rank candidates isn’t an ADS. A spreadsheet formula that auto-scores and auto-eliminates candidates below a threshold, with no human touching the ranking before rejection letters go out, starts to look like one.
The small-business HR tools this catches
Translated into what a 10-to-40-person business is likely to be running, the tools most exposed to this rule are:
- AI resume screeners built into an applicant tracking system. Most modern ATS platforms, including several free or low-cost ones aimed at small businesses, now include a scoring or keyword-ranking feature. That’s a textbook example of “screening resumes for particular terms or patterns.”
- Chatbot-assisted application intake. A chat widget that asks screening questions and passes a recommendation to the hiring manager falls under “computer-based assessments” if it scores or ranks answers rather than simply collecting them.
- Video-interview tools that score tone, word choice, or facial expression. These map directly onto the regulation’s own example language, and carry the added disability, race, and national-origin discrimination risk the rule names explicitly.
- Skills or “personality fit” assessment games, the short online quizzes some hiring platforms bundle in front of an application. A game that screens out anyone who can’t complete it at a set speed can create the same disability-discrimination risk the regulation calls out for selection devices.
- Targeted recruiting ads. Directing a job ad only to a platform’s algorithmically defined “young professionals” or a similarly age- or gender-skewed audience segment is now named directly as an ADS use.
Using ChatGPT, Claude, or Gemini to draft a job description, summarize a resume for a human reader, or write interview questions doesn’t, by itself, trigger this regulation. The line the rule draws is between AI that helps a person decide and AI that decides, ranks, or screens on its own.
The three provisions that matter most with no HR department
Recordkeeping jumped from two years to four. Under the amended 2 CCR § 11013, employers must keep applications, personnel records, selection criteria, and “automated-decision-system data” for four years from whichever is later: when the record was made, or when the related personnel action happened. A business running an ATS with built-in scoring needs that platform’s scoring data to stay retrievable for four years, not purged at the end of a hiring cycle.
Anti-bias testing is a defense, not a mandate, but its absence gets used against the employer. The regulations don’t force a bias audit before using an AI hiring tool. What they do, under the amended 2 CCR § 11009(f), is make evidence of anti-bias testing, or the lack of it, relevant to any discrimination claim or defense. A business that can point to a vendor’s bias-testing documentation sits in a materially better position than one that never asked whether the tool had been tested at all.
The vendor doesn’t shield the employer, and can itself be liable. The regulation’s definition of “agent” (2 CCR § 11008(b)) covers anyone acting on an employer’s behalf to exercise a hiring, screening, or pay function “through the use of an automated decision system.” An agent of the employer is also an “employer” under the Act. In practice: buying a resume-screening tool from a well-known vendor doesn’t move legal risk away from the business that uses it, and the vendor doesn’t get to hide behind “we just sell software.”
What a small business should do
Law-firm client alerts on this rule tend to recommend a three-part program: audit every AI tool touching HR, write a governance policy, and run vendor risk assessments. That’s the right shape of work, scaled for a company with a legal and compliance team. Here’s the same three steps sized for a business with none of that:
- List every tool that touches hiring, promotion, or discipline, and mark which ones score or rank people automatically. For most businesses this is a five-minute exercise: the ATS or job board the business posts to, any chatbot on the careers page, any video-interview or skills-assessment product, and any spreadsheet formula that auto-eliminates candidates.
- Write one paragraph, not a policy binder. State plainly that a specific person, not the software, makes the final call on every hiring, promotion, and discipline decision, and that AI tools support that person’s judgment. This costs nothing to write and gives the business a defensible answer if a rejected applicant asks how the decision was made.
- Ask each vendor three questions before renewing or buying: has this tool been tested for bias, what were the results, and who is responsible if it discriminates? Keep the answers in writing. A vendor that can’t answer any of the three is worth weighing against price and features at renewal.
None of this requires outside counsel for a business with a straightforward hiring process and no discrimination complaints on file. It just requires someone at the business, usually the owner at this size, to ask the three questions instead of assuming a household-name platform already handled it.
How this differs from the CPPA’s 2027 rules
A separate set of rules, the California Privacy Protection Agency’s automated decisionmaking technology (ADMT) regulations, gets frequently confused with the Civil Rights Council rules covered here. They aren’t the same rule, and a small business shouldn’t treat them as one project.
| Civil Rights Council ADS rules (this article) | CPPA ADMT rules | |
|---|---|---|
| Effective date | October 1, 2025 | Compliance duties begin January 1, 2027 |
| Legal basis | FEHA (employment discrimination) | CCPA (consumer/employee privacy) |
| Who’s covered | Employers with 5+ California employees | For-profit businesses with more than $25 million in annual gross revenue that do business in California, or that otherwise meet CCPA’s coverage thresholds |
| What it requires | Anti-discrimination liability, 4-year recordkeeping, anti-bias testing as a defense | Pre-use notice, opt-out rights, and a documented risk assessment for “significant decisions” |
The practical read for most 5-to-50-person businesses: the Civil Rights Council rules already apply today if the business has five or more employees and uses any of the tools described above. The CPPA’s rules mostly reach larger businesses over the $25 million revenue threshold, so most small employers can treat 2027 as a “watch this” item rather than an active deadline.
Frequently asked questions
What does “automated-decision system” mean under California’s new rule?
Any computer process that makes or helps make a decision about an employment benefit, hiring, promotion, discipline, pay, or training selection, using AI, machine learning, algorithms, or similar data processing. The regulation gives five examples: scored assessments and games, targeted job ads, resume-term screening, facial or voice analysis in interviews, and analysis of third-party applicant data. Office software that doesn’t make an employment decision, word processors, spam filters, reference spreadsheets, is explicitly excluded.
Does this rule apply to a business with fewer than five employees?
No. The regulation’s definition of “employer” carries over FEHA’s existing five-employee threshold: a business must regularly employ five or more people to be covered. Part-time staff count the same as full-time staff, and employees outside California count toward that headcount too, even though those out-of-state employees aren’t themselves protected unless the unlawful conduct reached California. A business right at that line should count carefully rather than assume it’s exempt.
Is using ChatGPT to write a job description covered by this regulation?
No, not on its own. The rule targets tools that make or shape a decision about a specific applicant or employee: screening, scoring, ranking, or recommending them. Using a general-purpose AI tool to draft a posting, summarize a resume for a human reader, or prepare interview questions doesn’t fit that, because a person still does the deciding. The line moves the moment a tool starts scoring or eliminating candidates without a person reviewing the result.
What records does a small business need to keep now that recordkeeping doubled to four years?
Applications, personnel records, selection criteria, and any “automated-decision system data,” meaning data an ADS used or produced about a specific applicant or employee, now need four years of retention from whichever is later: when the record was created or when the related personnel action happened. For a business using an ATS with built-in scoring, keep that platform’s scoring history retrievable for four years rather than letting it purge at the end of a hiring cycle.
Is a business required to run a bias audit on its AI hiring tools?
Not required, but worth doing as protection. The regulation makes evidence of anti-bias testing, or its absence, relevant to any discrimination claim involving an ADS. A business doesn’t have to commission a formal audit, but asking the vendor whether one has been done, and getting the answer in writing, is a low-cost way to have something to point to if a claim comes up.
Can a vendor be held responsible instead of the business that bought the tool?
Both can be. The regulation defines an “agent,” someone acting on an employer’s behalf to exercise a hiring, screening, or pay function through an automated-decision system, as itself an “employer” under the Act. A vendor administering a screening tool can face its own liability. That doesn’t remove the buying business’s own liability for using the tool.
Does an AI video-interview tool that analyzes tone of voice or facial expression violate this rule automatically?
No, but it carries specific, named risk. The rule states that analyzing tone of voice, facial expressions, or other physical characteristics during an interview may discriminate against applicants based on race, national origin, gender, disability, or other protected traits, and that an employer may need to provide a reasonable accommodation to avoid that outcome. Using the tool isn’t unlawful by itself; using it with no way to accommodate someone who can’t be fairly assessed that way is the risk.
How is this different from the “No Robo Bosses Act” that was in the news?
They’re unrelated. SB 7, the “No Robo Bosses Act,” would have added separate notice and human-review requirements around automated discipline and termination decisions, but Governor Newsom vetoed it on October 13, 2025. The rule covered here is a different, already-in-effect regulation issued through the normal FEHA rulemaking process, not through that vetoed bill.
Where can I read the actual regulation text instead of a summary?
The Civil Rights Council’s final regulation text is published on calcivilrights.ca.gov as part of the rulemaking package behind the October 1, 2025 effective date. The relevant sections sit in Title 2 of the California Code of Regulations, Division 4.1, Chapter 5, Subchapter 2: § 11008 (definitions, including “agent” and “proxy”), § 11008.1 (the ADS definition), § 11009(f) (discrimination and anti-bias testing), § 11013 (recordkeeping), and §§ 11015 through 11017.1 (recruitment, applications, interviews, and selection devices).
Key takeaways
- The Civil Rights Council’s automated-decision rules took effect October 1, 2025, and apply to any California business with five or more employees.
- An “automated-decision system” is any tool that scores, ranks, screens, or recommends applicants or employees, not general-purpose AI used only to help a person draft or think through a decision.
- Recordkeeping for applications, selection criteria, and automated-decision-system data runs four years now, up from two.
- Anti-bias testing isn’t mandatory, but the lack of it counts against an employer if a discrimination claim comes up, and vendors can be independently liable as an employer’s “agent.”
- This is a different rule from the CPPA’s 2027 ADMT regulations, which mostly reach larger businesses over the CCPA’s revenue threshold.
A short AI-use policy and a five-minute tool inventory cover most of what this regulation asks of a business this size. For the fuller picture of rolling AI out to a team, including what to put in writing before anyone touches a chatbot, see the California AI training playbook or the Los Angeles buyer’s guide. Businesses ready to talk through their specific hiring stack can book a free AI-readiness call.
Dirk Jan van Veen, PhD