The intricate terrain of employment background checks is undergoing a profound transformation, driven by a confluence of rapid technological advancements and shifting legal interpretations. As employers increasingly leverage sophisticated tools, from artificial intelligence in resume screening to biometric identity verification, they face an escalating array of legal challenges under foundational statutes like the Fair Credit Reporting Act (FCRA), Title VII of the Civil Rights Act of 1964, and emerging biometric privacy laws. Robert T. Quackenboss, a partner, and Evangeline C. Paschal, counsel with the law firm Hunton, highlight critical questions employers must address to mitigate burgeoning risks and ensure compliance in this dynamic environment. This period marks a pivotal moment, demanding heightened vigilance and proactive adaptation from organizations striving to maintain fair and lawful hiring practices.
The Rise of AI and FCRA Scrutiny: Are Candidate Profiles "Consumer Reports"?
The integration of artificial intelligence into the hiring process has heralded unprecedented efficiencies, yet it simultaneously introduces novel legal ambiguities, particularly concerning the Fair Credit Reporting Act (FCRA). Enacted in 1970, the FCRA primarily aims to protect consumer privacy by regulating the collection, dissemination, and use of consumer information, initially focused on credit reports. Over time, its scope expanded significantly to cover employment background checks, mandating specific disclosure and authorization procedures, and requiring a pre-adverse action notice if a report leads to a negative employment decision. However, the application of FCRA to AI-driven candidate assessment tools represents a relatively new frontier of legal interpretation.
One of the most significant recent developments challenging the conventional understanding of the FCRA is the assertion that AI hiring tools, such as sophisticated resume sorters and talent profile generators, produce "consumer reports." This theory posits that the vendors designing and deploying these tools could be classified as "consumer reporting agencies" (CRAs), thereby subjecting them and their employer clients to the stringent requirements of the FCRA. This argument gained prominence with the lawsuit Kistler v. Eightfold AI Inc., a case that has sent ripples through the HR technology industry and legal community.
In Kistler, the plaintiff alleged that Eightfold AI’s widely used software system went beyond mere resume parsing. It reportedly assembled and evaluated a vast spectrum of information about job candidates, not solely from applications, but also by gleaning data from various third-party sources like public social media profiles (e.g., LinkedIn), professional networking sites, and specialized job boards. This aggregated data was then purportedly used to generate a "talent profile" that assigned a specific score to candidates and ranked them, influencing hiring decisions. The plaintiff contended that because of these features – the gathering of information from third-party sources and its use to assess eligibility for employment – Eightfold’s profiles should qualify as "consumer reports" under the FCRA.
Eightfold AI has moved to dismiss these allegations, arguing that its role is fundamentally different from a CRA. The company asserts it merely sells sophisticated software to employers, akin to how analytics companies like FICO license their credit scoring algorithms to traditional credit bureaus. Under this interpretation, FICO itself is not considered a CRA, but rather the entities that use its scores to generate reports are. This distinction is crucial: if Eightfold’s argument prevails, AI vendors might largely avoid direct FCRA obligations, shifting the onus onto employers to understand the nature of the data being processed. Conversely, if the plaintiff’s characterization holds, then any AI software that aggregates and analyzes applicant data from external, third-party sources could trigger the FCRA’s comprehensive disclosure and notification requirements.
The implications of such a ruling would be far-reaching. Employers currently utilizing AI-powered talent acquisition platforms might suddenly find themselves needing to issue FCRA disclosures and obtain explicit authorizations from candidates before their data is processed by these tools. Furthermore, if an AI-generated score or ranking contributes to an adverse employment decision, the employer would be obligated to follow the FCRA’s pre-adverse action and adverse action notification procedures, providing the candidate with a copy of the "report" (the AI-generated profile) and a summary of their rights. This potential expansion of FCRA coverage underscores the urgent need for employers to audit their AI hiring tools, understand their data sources, and consult legal counsel to assess potential compliance gaps. The legal debate surrounding Kistler is poised to redefine the regulatory boundaries of AI in HR, compelling both technology providers and employers to reconsider their operational frameworks.
The Nuance of Notification: When Must Applicants Learn of Adverse Actions?
Beyond the classification of AI tools, the Fair Credit Reporting Act (FCRA) continues to be a fertile ground for novel legal arguments, particularly concerning the timing of pre-adverse action notifications. The FCRA explicitly mandates that an employer must issue a pre-adverse action notice "before taking any adverse action based in whole or in part" on a background report. This requirement is designed to provide job applicants with an opportunity to review their background report, dispute any inaccuracies, and provide explanatory context before a final adverse employment decision is made. Historically, the FCRA has not specified a precise timeframe for this notice, implying a reasonable period. However, recent plaintiffs’ arguments have introduced a new layer of complexity, contending that applicants have a right to be notified immediately once an employer receives a background report that raises concerns.
This novel argument posits that delaying notification, even for a short period, constitutes a "concrete injury" to the applicant. Plaintiffs argue that this delay prevents them from acting promptly to correct any potential inaccuracies in the report, or to explore alternative employment opportunities before the position in question is filled. For instance, if a report contains an error that would disqualify a candidate, an immediate notice would allow them to initiate a dispute process, potentially clearing their record while the job remains open. Without immediate notification, the argument goes, the applicant is deprived of a crucial window to mitigate the damage to their job prospects.
From an employer’s perspective, there are often practical and legitimate reasons for not issuing an immediate pre-adverse action notice upon receipt of a concerning background report. Many employers, for example, choose to conduct an "individualized assessment" as recommended by the Equal Employment Opportunity Commission (EEOC) guidance, particularly when dealing with criminal history information. This assessment involves evaluating factors such as the nature and gravity of the offense, the time elapsed since the conviction or completion of the sentence, and the nature of the job held or sought. Such an assessment requires time for internal review, consultation, and careful consideration before an employer can definitively conclude that an adverse action is warranted. Employers typically believe that this practice, which aims for a more equitable and holistic review, complies with the letter and spirit of the FCRA, as the notice is still issued before the adverse action is finalized.
However, this practice has recently attracted unconventional claims, suggesting that the FCRA implicitly includes a right to immediate pre-adverse action notification. This theory draws strength from a line of cases where unsuccessful applicants successfully pursued FCRA claims against companies that allegedly failed to provide timely pre-adverse notices, even when the background report itself was accurate. The underlying principle in these cases was that the procedural right to notice was violated, irrespective of the report’s accuracy, thus constituting a concrete injury. The new argument extends this by focusing not just on the presence of notice, but its immediacy, asserting that the delay itself harms the applicant’s ability to respond effectively.
In light of this evolving legal theory, employers face a dilemma: balance the need for thorough internal review with the risk of litigation over delayed notification. To mitigate the risk of attracting such claims, legal experts now increasingly advise employers to consider sending the pre-adverse action notice promptly upon receiving a background check report that might lead to an adverse decision, even if further internal review and investigation are still ongoing. While this might alter established internal processes, it proactively addresses the "immediate knowledge" concern and minimizes the window during which a plaintiff could claim a concrete injury due to delayed awareness. Navigating this fine line requires careful policy adjustments and a clear understanding of the potential legal ramifications of timing in the FCRA compliance framework.
The Shifting Sands of Disparate Impact Theory: A Cornerstone Under Threat?
For decades, the "disparate impact" theory has been a formidable legal tool, frequently employed in challenges to employer criminal background check programs under Title VII of the Civil Rights Act of 1964. Title VII prohibits employment discrimination based on race, color, religion, sex, or national origin. Disparate impact occurs when a seemingly neutral employment policy or practice, such as a blanket ban on hiring individuals with certain criminal convictions, disproportionately affects individuals from protected classes (e.g., racial or ethnic minorities) even if there is no explicit intent to discriminate. This theory has been a cornerstone of civil rights enforcement, robustly supported by the U.S. Equal Employment Opportunity Commission (EEOC) and leveraged by plaintiffs’ class-action counsel to secure multi-million-dollar judgments against employers whose policies inadvertently created systemic barriers.
However, the legal landscape surrounding disparate impact theory has recently experienced significant tremors, signaling a potential paradigm shift. In April 2025, President Donald Trump issued Executive Order 14281, titled "Restoring Equality of Opportunity and and Meritocracy." This executive order controversially declared that the theory of disparate-impact liability violates the U.S. Constitution. The order’s rationale, articulated in accompanying fact sheets, asserted that disparate impact "undermines civil-rights laws by mandating discrimination to achieve predetermined, race-oriented outcomes." Essentially, the administration argued that focusing on statistical disparities rather than intentional discrimination forces employers to engage in reverse discrimination to meet quotas, thereby contradicting the very essence of equal opportunity. The order specifically directed federal agencies, including the EEOC, to de-prioritize legal challenges that relied solely on disparate-impact theory.
Building on this directive, the U.S. Department of Justice (DOJ) further intensified the challenge to disparate impact. On June 9, the DOJ issued a Memorandum Opinion, formally concluding that the EEOC’s long-standing guidance for analyzing disparate impact claims was "similarly unconstitutional." This memorandum provided a detailed legal justification for the administration’s stance, arguing that disparate impact effectively creates a quota system and is incompatible with the Equal Protection Clause of the Fourteenth Amendment and the colorblind principles inherent in federal civil rights law.
These governmental actions represent a coordinated strategy to diminish, if not dismantle, disparate impact as a viable legal theory. While these developments do not immediately eliminate disparate impact as a cause of action in private litigation – as executive orders and DOJ opinions do not directly overturn Supreme Court precedent – they certainly "augur a growing coordinated strategy to do so." The clear articulation of these constitutional arguments by both the executive branch and the nation’s chief law enforcement agency provides a powerful new legal framework for defendants to challenge disparate impact claims in federal courts. This could potentially pave the way for a federal case to eventually reach the U.S. Supreme Court, which could then issue a definitive ruling on the constitutionality of disparate impact theory itself.
The implications for plaintiffs’ class-action attorneys are substantial. Disparate impact has long been a powerful tool, often easier to prove than intentional discrimination (disparate treatment) because it doesn’t require evidence of discriminatory intent. Now, attorneys with pending or soon-to-be-filed disparate impact cases face the daunting prospect that a cornerstone of their class-action practice could be significantly diminished or even eliminated before their cases run their course. Furthermore, they can no longer reliably depend on the EEOC to investigate their clients’ charges of disparate impact. Historically, an EEOC investigation provided a no-cost means of testing the viability of a case, often leading to conciliation or a right-to-sue letter that bolstered subsequent federal court litigation. Without this investigative support, plaintiffs’ attorneys may face higher initial costs and greater risks in pursuing such claims.
In response to this evolving threat, the plaintiffs’ bar has already begun to adapt its litigation strategies. In new pleadings concerning background checks, disparate impact claims are now more frequently "backed up by claims of intentional discrimination – disparate treatment – under Title VII." This strategic shift aims to hedge their bets, ensuring that if disparate impact theory is indeed diminished or dissolved while their case is pending, they still have an alternative, albeit often more challenging, cause of action to pursue. This adaptation presents defendants with additional opportunities to challenge both the pleadings and the underlying evidence supporting claims of both disparate impact and disparate treatment, potentially leading to more complex and protracted litigation. The battle over disparate impact theory is far from over, but the current administration’s actions have undeniably initiated a critical phase that could fundamentally reshape civil rights litigation in employment.
Identity Screening and Biometric Laws: Navigating the Privacy Minefield
In an era of increasingly sophisticated digital threats and a remote workforce, the integrity of a job applicant’s identity has become paramount. Employers nationwide have reported a significant rise in cases of identity fraud and misrepresentation among job applicants, driven by advancements in deepfake technology and readily available fraudulent documents. To combat this, organizations are increasingly turning to a growing community of identity screening vendors, many of whom leverage advanced biometric tools to confirm applicant identities. While these tools offer crucial security benefits, their rapid deployment has created a new legal frontier fraught with privacy concerns, particularly under emerging biometric information privacy laws.
The use of biometric data – unique biological characteristics like fingerprints, facial scans, and voiceprints – for identity verification is highly sensitive. Biometric information, unlike other forms of personal data, is immutable; if compromised, it can lead to permanent identity theft. Recognizing this profound privacy risk, several states, most notably Illinois with its Biometric Information Privacy Act (BIPA), have enacted stringent laws regulating the collection, use, and storage of biometric data. BIPA, passed in 2008, is considered the most comprehensive biometric privacy law in the United States and has served as a model for other states and municipalities. It mandates that private entities obtain informed written consent before collecting or storing biometric identifiers or information, disclose the purpose and duration of storage, and prohibits the sale or profiting from such data. Crucially, BIPA also includes a private right of action, allowing individuals to sue for statutory damages (up to $1,000 for negligent violations and $5,000 for intentional/reckless violations per violation), which has led to a surge in class-action lawsuits.
The rush to bring identity screening tools to market has, in some instances, led vendors and employers to overlook these critical privacy and biometric information laws. A prominent example is the allegations raised against identity screening tools under Illinois’ BIPA in McGowan, et al. v. Veriff Inc., et al. In this case, Veriff, a widely used identity verification service, faced a class-action lawsuit alleging that it collected and stored users’ biometric data without obtaining the explicit, informed consent required by BIPA. The case highlights the significant financial risks involved, as Veriff ultimately settled the BIPA claim for $4 million.
Another significant case, already discussed in the context of FCRA, is Kistler et al. v. Eightfold AI Inc. While primarily focused on FCRA compliance, the lawsuit also includes allegations related to biometric data. If Eightfold AI’s systems, in their process of creating "talent profiles," involve the collection or analysis of biometric identifiers (e.g., through facial recognition in video interviews or analysis of voice patterns), then it could also face challenges under BIPA and similar state laws. This multi-faceted legal challenge against a single vendor underscores the complex web of regulations that HR technology providers and their clients must navigate.
Employers utilizing these identity screening tools face mounting challenges. The need to confirm an applicant’s identity and screen for criminal background information is undeniable for security and compliance purposes. However, the methods employed to achieve these goals must strictly adhere to privacy laws. Failure to do so can expose employers to significant legal exposure, including costly class-action lawsuits, substantial statutory damages, and reputational harm.
To mitigate these risks, employers must adopt a proactive and comprehensive approach. This includes thoroughly vetting identity screening vendors to ensure their compliance with all applicable biometric privacy laws, not just BIPA but also emerging regulations in states like Texas, Washington, California, and others. Employers should also review their own internal policies and processes for collecting, using, and storing any biometric data, ensuring clear, informed consent is obtained from applicants, transparent disclosures are provided, and strict data retention and destruction policies are in place. Consulting with legal counsel regarding current tools, vendors, and processes used for identity confirmation and background checks is no longer merely advisable but a critical necessity to identify and manage all potential legal exposures and compliance obligations in this rapidly evolving and high-stakes area.
Conclusion: Navigating a New Era of Employment Compliance
The landscape of employment background checks is undeniably at an inflection point. From the burgeoning debate over AI tools as "consumer reporting agencies" under the FCRA to the nuanced interpretation of pre-adverse action notice timing, and from the governmental challenge to disparate impact theory under Title VII to the critical implications of biometric privacy laws, employers face an increasingly intricate web of regulations and litigation risks. The insights shared by legal experts like Robert T. Quackenboss and Evangeline C. Paschal underscore a fundamental truth: historical compliance models are no longer sufficient.
The sheer volume of technological innovation in HR, coupled with dynamic legal interpretations and a proactive plaintiffs’ bar, demands a continuous reassessment of hiring practices. Employers must move beyond mere reactive compliance, adopting a strategic, forward-looking approach. This involves conducting regular audits of all screening tools and processes, from initial application to final hiring decisions. It necessitates a deep dive into vendor contracts to understand liability allocations and data handling practices. Moreover, fostering an internal culture of compliance, informed by ongoing legal counsel and employee training, is paramount.
The current environment signals a pivotal shift where legal and technological diligence must converge. Organizations that proactively engage with these challenges, adapt their policies, and prioritize transparent and lawful practices will be best positioned to navigate this new era of employment compliance, safeguarding their operations while upholding principles of fairness and equity in the hiring process. The imperative for employers is clear: stay informed, stay compliant, and stay agile in the face of relentless change.
