RSS Amplifier

Noesis Hiring · May 13, 2026

The procurement function bought the algorithm. The HR function inherited the liability.

0
Sign in to vote or save

Antonio Specchia · Noesis Hiring

In the Mobley v. Workday class certification filings, Workday represented that 1.1 billion applications had been rejected through its tools during the relevant period. The ADEA collective — applicants over forty rejected since September 2020 — was conditionally certified in May 2025. The case is not settled and it is not a merits ruling. It is, however, the largest hiring-discrimination collective ever certified, and the legal theory that survived motion practice — that the vendor can be directly liable as an agent of the employer — is being read by every plaintiffs’ firm in the country.

These are the systems HR has to certify, document, and defend.

Wherever an integrated HCM platform is procured at scale, the buyer and the user are not the same function. The CFO and the CIO sponsor the deal. Procurement runs the negotiation. A steering committee approves the migration. Someone from HR sits in the room. The head of people may sign one of the schedules. But the function whose budget moves is not the function whose work changes.

The pattern is not limited to the Fortune 500. Maine’s $54m HR rollout was terminated in 2021. UBC’s HCM implementation escalated to roughly $300m. McGill teaching assistants went unpaid through the 2022 winter cutover. Same architectural fault line. Anywhere an HCM platform is procured by committee.

Most procurement teams get the contract right. The data model is unified. The licence economics hold up. The audit trail behind the deal is impeccable. The function that signed the contract did everything right.

The trouble is that the function that signed the contract is not the function the regulator addresses.

Then a letter from a regulator arrives, addressed to the function that uses the system — which, under Article 3 of Regulation 2024/1689, is the function that bears the deployer obligation.

On top of that risk, time-to-hire moves in the wrong direction.

That is the part the procurement business case did not price in.

Annex III(4) of the EU AI Act classifies AI used to recruit, screen, or evaluate candidates as high-risk.

  • The Recruiter Agent sits there.

  • The HiredScore matching layer sits there.

  • The Illuminate agents for talent mobility and succession sit there.

  • The classification is not negotiable.

The November Digital Omnibus has slipped the Annex III deadline without changing the substance.

Under Article 3, the provider is Workday, the deployer is the employer.

Under Article 26, the deployer must inform workers and worker representatives before deploying a high-risk system; assign competent humans to substantive oversight under Article 14; ensure relevant input data and retain logs for at least six months; and inform individual candidates when they are subject to a high-risk decision under Article 26.

GDPR Article 22 already prohibits decisions based solely on automated processing with significant effects, and the EDPB is clear that the human review must be substantive, not rubber-stamping.

Article 99 sets the deployer-violation ceiling at the higher of fifteen million euros or three per cent of worldwide turnover. For an eighty-billion-revenue group, three per cent is two and a half billion euros per violation. The penalty does not need to actually land for the procurement modelling to change.

The deployer obligations are non-delegable. They live with the function that uses the tool, not the function that bought it.

The Act does not redistribute it. The penalty schedule does not redistribute it. The procurement memo from three years ago does not redistribute it either.

This is not an argument that anyone should rip out Workday. Most readers of this newsletter could not even if they wanted to. The integration is too deep, the data migration too expensive, the political capital too rare.

It is an argument that the assessment layer is a separate question from the system of record.

The system of record can stay where it is. The decisions that carry deployer liability — who gets shortlisted, on what basis, with what audit trail, with what worker-representative consultation — can sit somewhere else. Procured separately, by the function that will defend it.

That somewhere else is what NoesisHiring is building. Not another ATS. A relationship-grade assessment layer with the documentation, the human-oversight design, and the candidate-facing transparency the deployer obligations actually require.

So that when the question from the works council arrives, or the question from the candidate, or the question from the DPA, the answer will not be: “ask the vendor.”

The answer is yours.

That’s what NoesisHiring is building.

Share

Antonio Specchia is a researcher, Routledge author, and the creator of the Applicant Relationship Management (ARM) framework.

He is the founder of NoesisHiring, an AI-powered recruitment platform. His first book, Customer Relationship Management (CRM) for Medium and Small Enterprises (Routledge, 2022), laid the foundation.

A forthcoming book, Applicant Relationship Management (ARM): Human–AI Collaboration in the Agentic Economy, is in preparation for Routledge. His research on Applicant Relationship Management has been presented widely accepted among academics and HR professionals.

No posts

Read the original on noesishiring.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.