IT Owns the Technology, HR Owns the Liability: Convincing HR to Embrace AI Governance
10 Critical Facts to Move HR From AI Adoption to AI Governance and Why IT Needs to Care about Getting This Right.
What will it take to convince HR that they own AI governance in talent systems when they believe they own AI adoption and training?
That question came out of a response to a recent article on IT-led governance. An HR reader offered a different view, he said: “HR owns the people side of AI adoption, IT owns governance, data security, privacy, and guardrails, and the two functions do their best work as partners. That’s how they built it. That’s what I encourage other leaders to do.”
It’s a fair position, and for a long time it was the right one. Adoption and governance used to live in separate rooms, with IT handling technical risk and HR handling the rollout. That line has shifted.
Adoption measures whether a tool gets used. Governance measures whether a decision holds up, and that question belongs to whoever is running people, not just software, through the system. A recruiter adopting a screening tool wants to know if it saves time. A regulator wants to know if it screened out a protected class. HR sits closer to that second question than any other function in the enterprise.
The law has drawn a harder line between the two. Here are ten facts every HR leader needs to consider before the next class action names their organization rather than their vendor.
10 Critical Facts to Move From AI Adoption to AI Governance in HR.
1. Active law already assigns governance duty to the employer, not the vendor who built the tool.
a. California’s Fair Employment and Housing Act (FEHA) Automated-Decision System regulations, effective October 1, 2025, apply to any system that makes or facilitates an employment decision. The duty falls on the employer running the system, not the company that sold it.
b. Illinois’s amendment to the Illinois Human Rights Act (IHRA) (HB 3773), effective January 1, 2026, does the same across the entire employment lifecycle.
c. Texas’s Responsible Artificial Intelligence Governance Act (TRAIGA), also effective January 1, 2026, prohibits developing or deploying AI with intent to discriminate, a prohibition that can reach the employer as deployer, not only the vendor as developer. All three laws are already in force.
2. The EU AI Act names the deployer, not the developer, as the party with ongoing obligations. Article 26 requires deployers of high-risk AI systems, and employment AI is explicitly high-risk under Annex III, to monitor operation and maintain human oversight. If you hire or evaluate anyone connected to the EU, that obligation sits with whoever runs the system in production. That’s HR.
3. Mobley v. Workday established that using a vendor’s tool does not transfer your liability to the vendor. Judge Rita Lin allowed the case to proceed on the theory that an AI vendor acts as an agent of the employer when the tool participates in the decision, not just applies criteria the employer set. The employer named in that suit wasn’t IT. It was HR.
4. Data security and algorithmic bias are two different legal questions, and only one of them is IT’s. IT is responsible for who can access the data and whether it’s protected. But whether an AI-driven hiring decision is job-related, consistent with business necessity, and free of disparate impact is a standard set by federal law, Title VII, the Americans with Disabilities Act (ADA), and the Age Discrimination in Employment Act (ADEA), and enforced through federal claims and state statutes like the Fair Employment and Housing Act (FEHA) in California and the Illinois Human Rights Act (IHRA) in Illinois. That’s not a systems question. It belongs to HR.
5. Insurance carriers are already underwriting around this distinction. Most Employment Practices Liability Insurance (EPLI) policies exclude or cap coverage for algorithmic discrimination claims. Carriers are asking for documented governance processes before they’ll price coverage, and they’re not asking IT for it. They’re asking HR.
6. Two more state governance regimes are already on the calendar, and neither one names IT. Colorado’s AI Act, delayed by SB 26-189 to January 1, 2027, will require deployers, employers, not software vendors, to run a documented risk-management program and complete annual impact assessments on high-risk AI used in hiring, pay, and termination decisions. Connecticut’s CART Act (SB 5), effective October 1, 2026, will make it an unlawful practice under the state’s Fair Employment Practices Act when an automated employment decision causes a discriminatory outcome. Both are still ahead of us, and neither waits for IT.
7. NYC Local Law 144 has required bias audits and candidate notice since 2023, and the obligation sits with the employer using the tool. The audit has to happen before the tool is used, and candidates get at least ten business days’ notice that AI is involved. Any HR function using an automated tool to screen or promote in New York City is already inside its obligations, whether or not IT flagged it.
8. The exposure is already universal, whether or not governance was ever planned. Ninety-nine percent of Fortune 500 companies use AI hiring tools. Seventy percent of companies use AI-based employment tools in some form. The absence of a governance plan isn’t a future risk. It’s a current gap across nearly every HR function reading this.
9. IT-driven guardrails don’t answer the question a plaintiff’s attorney will ask. Illinois’s ban on using ZIP codes as a proxy for race or socioeconomic status is a clear example. Access controls and encryption don’t catch it. Catching it requires asking whether the AI’s scoring logic produced a disparate outcome and whether a person reviewed it first. That’s a decision question, not an infrastructure question.
10. Penalties are assessed to the deployer, not the vendor, when the law names a deployer at all. iTutorGroup settled an AI hiring discrimination case for $365,000. Texas’s TRAIGA, active now, carries civil penalties up to $200,000 per violation for developing or deploying with discriminatory intent, enforced by the state Attorney General. Colorado’s 2027 law adds penalties up to $20,000 per violation against the deployer specifically. None of these numbers are the ceiling; discrimination class actions can run into the hundreds of millions. Whoever signs that check is the person who made the decision the AI informed. In a talent system, that’s most often HR.
None of this erases the partnership between HR and IT. IT still owns the infrastructure, the guardrails, the security posture that makes governance technically possible. But infrastructure isn’t accountability.
IT can build every guardrail correctly and still hand HR a system that produces a discriminatory outcome, because the guardrail was never built to answer the question the law is now asking: was this decision fair and defensible?
Most Organizations Try to Boil the Ocean to Implement AI Governance in HR.
The typical governance scenario. HR and IT agree on an implementation plan; they build a framework, draft the policy, set draconian guardrails, schedule stakeholder training, and try to deploy governance everywhere at once.
Five Questions to Close the AI Governance Knowledge Gap for HR Leaders
Do you know which of your talent systems currently use AI to screen, score, or rank candidates and employees? Is the AI an add-on to legacy infrastructure or a true AI implementation?
Can you identify who owns each of those systems, and could that person explain the model’s logic to a regulator without calling IT first?
Have you completed a written impact assessment or bias audit for any high-risk AI tool in your stack? Could you produce it on demand?
Do you know whether your AI vendor’s tool has been independently tested for disparate impact, or are you relying on a marketing claim of fairness rather than evidence?
If a candidate or employee challenged an AI-informed decision tomorrow, do you have a documented human review process in place to address their concerns?
These are HR questions about HR systems, with HR’s name in the answer.
IT still owns the infrastructure, guardrails, and security posture that enable governance. That work matters, and none of it goes away.
The question we should be asking from both the IT and HR desks: Does HR know what it’s being held accountable for, and is anyone in the organization documenting the answer before the plaintiff’s attorney requests it?
We need to get this right before someone gets thrown under the bus and the blame game rears its ugly head.
This is the thinking behind When AI Breaks the Law: AI Governance for Talent Leaders, my fourth book and the first AI governance guide built specifically for HR and talent leaders. It’s for the people who sit between the engineers building these systems and the candidates, employees, and executives those systems will judge. The book launches August 19th. If you’re the person who will get the call from General Counsel the morning after an algorithm makes a decision no one can explain, this book ensures you’re not standing there unprepared.
Order your copy now on Amazon (Link Here)





