When HR Is Not in the Room, Legal Liability Walks In
There is a pattern playing out inside enterprises right now that should alarm every C-suite executive who thinks AI governance is primarily a technology problem. Companies are deploying AI tools that touch their most legally sensitive asset — their workforce — and they are doing it without the one function that understands both the human and the compliance dimensions of that decision. They are deploying without HR. And according to Deepa Menon, a partner at global law firm Eversheds Sutherland who advises organizations on exactly these questions, that omission is not a minor process gap. It is an active liability generator.
- When HR Is Not in the Room, Legal Liability Walks In
- The Litigation Risk Is Not Hypothetical
- The Data Leakage Problem Is Worse Than Most CFOs Realize
- The Organizational Design Imperative
- The Regulatory Patchwork Is a Feature, Not a Bug, for Litigants
- The Strategic Position: Build the Framework Now, Before the Litigation Finds You
- What Executives Should Do This Quarter
The article, drawn from an interview with Menon at the 2026 SHRM annual meeting, reads at first glance like a checklist of familiar AI governance concerns — bias in hiring, data privacy, regulatory patchwork. But the sharper argument embedded in it deserves more attention than it typically receives: the legal exposure from AI in the workforce is not primarily a technology problem or even a legal problem. It is an organizational design problem. And the organizations getting it wrong are the ones that have not yet restructured who sits at the table when an AI deployment decision is made.
The Litigation Risk Is Not Hypothetical
Menon’s framing of litigation risk is worth sitting with. Her argument is not simply that AI can introduce bias — that point has been made repeatedly. Her argument is structural: the moment you remove the human component from a consequential decision, the legal burden of proof shifts dramatically against you. Defending an automated system in court is materially harder than defending a human decision-maker, because an automated system cannot demonstrate intent, context, or situational judgment. It can only demonstrate its outputs. And if those outputs correlate with protected characteristics — even incidentally — the plaintiff’s case becomes significantly easier to construct.
This is not a hypothetical litigation theory. It is the logical extension of how existing employment law works. Title VII, the Americans with Disabilities Act, the Age Discrimination in Employment Act — none of these were written with AI in mind, but all of them apply with full force to AI-driven decisions. The EEOC has been clear on this point even as the current federal administration takes a lighter regulatory touch. Menon’s prediction that we will see more federal hands-off behavior is credible, but her follow-on observation is the one that matters for enterprise planning: state litigation and state privacy statutes are accelerating to fill the vacuum. Companies that breathe a sigh of relief at reduced federal enforcement pressure and stand down their compliance programs are making a strategic error.
The Data Leakage Problem Is Worse Than Most CFOs Realize
Beyond the discrimination exposure, Menon surfaces a risk that tends to get underweighted in boardroom conversations: the IP and trade secret exposure created when employees use public AI tools in the absence of enterprise policy. The scenario is straightforward. An enterprise has not deployed its own AI tools, or has deployed them only partially. Employees, being resourceful humans who want to do their jobs efficiently, reach for ChatGPT, Claude, Gemini, or whichever consumer-grade tool is accessible. Proprietary information — customer data, product roadmaps, internal financial projections, personnel records — gets pasted into prompts. That data may be used to train third-party models. The enterprise has now potentially lost control of its most sensitive information with no contractual recourse and no audit trail.
The contractor dimension compounds this further. When organizations bring external contractors into AI development projects, the IP ownership questions around training data become genuinely murky. If a contractor’s proprietary data or methodologies are incorporated into a model, does the contractor have a claim on the model itself? This is not a settled area of law. It is precisely the kind of question that generates expensive litigation, and it is exactly the kind of question that a well-structured AI governance framework — built before deployment, not after — is designed to prevent.
The Organizational Design Imperative
The most actionable insight in Menon’s interview is the one that should be most uncomfortable for technology and legal teams to hear: HR cannot be a downstream recipient of AI deployment decisions. The model where IT or an AI Center of Excellence selects and deploys a workforce tool, then hands it to HR to communicate and manage, is operationally broken. It produces legal exposure, it produces employee relations failures, and it produces the exact kind of trust deficit that Menon identifies as the root cause of most AI-related workforce conflict.
The trust point deserves elaboration because it is more analytically interesting than it might initially appear. Menon’s observation — that employee resistance to AI is often a signal of pre-existing trust deficits rather than a reaction to the technology itself — reframes the entire AI change management problem. Organizations that have been opaque about compensation decisions, inconsistent in their performance management, or unclear about career development pathways are not facing an AI communication problem when they deploy workforce tools. They are facing a credibility crisis that AI deployment is revealing. The solution is not better messaging about the AI tool. The solution is repairing the underlying trust architecture, which is HR’s domain and nobody else’s.
This has direct implications for CHROs who may feel that AI governance is something happening to them rather than something they should be shaping. Menon’s argument — and it is the right argument — is that HR’s seat at the AI governance table is not a courtesy or a checkbox. It is a legal and operational necessity. No AI tool that touches hiring, performance management, compensation, promotion, or workforce reduction should reach deployment without HR having evaluated its workforce implications, its disclosure requirements, and its jurisdictional compliance posture.
The Regulatory Patchwork Is a Feature, Not a Bug, for Litigants
Menon’s description of the regulatory environment as a patchwork is accurate and understates the complexity. In the United States alone, organizations operating across multiple states face different AI-specific statutes, different data privacy regimes, different disclosure requirements for automated decision-making, and different standards for what constitutes a background check subject to the Fair Credit Reporting Act. The FCRA question she raises — whether AI tools that scrape social media and public records constitute background checks — is not an edge case. It is an active litigation theory that plaintiffs’ attorneys are already advancing, regardless of whether the federal government chooses to pursue it administratively.
Internationally, the complexity multiplies. The EU AI Act creates an entirely different compliance architecture for high-risk AI systems in employment contexts. GDPR imposes data subject rights that conflict in interesting ways with how many AI vendors structure their data retention and processing. A global enterprise that tries to build a single AI governance policy and apply it uniformly across jurisdictions will find it does not work. A global enterprise that builds jurisdiction-specific carve-outs without a coherent governing framework will find it cannot manage them consistently.
Menon’s point that 100% compliance is impossible is not a counsel of despair. It is a risk management prescription. The question for every enterprise is not how to achieve perfect compliance — it is how to make defensible, documented, prioritized decisions about where to invest compliance resources. That requires legal counsel and HR working together, not sequentially but simultaneously, from the moment an AI tool is under consideration.
The Strategic Position: Build the Framework Now, Before the Litigation Finds You
The wait-and-see approach has a certain rationality to it in periods of regulatory uncertainty. Why invest heavily in compliance infrastructure for rules that may change? But Menon’s analysis reveals why the wait-and-see logic breaks down specifically in workforce AI contexts. The litigation risk does not wait for regulatory clarity. Employees who believe they were passed over, terminated, or disadvantaged by an AI system do not need a new statute to file a claim. They have Title VII. They have state discrimination statutes. They have the CCPA if they are in California. The legal exposure exists right now, under existing law, and it is activated the moment an automated system produces an outcome that disadvantages someone in a protected category.
The RIF and WARN Act dimension Menon raises crystallizes this point sharply. If an organization uses AI to identify employees for a reduction in force, and that reduction disproportionately affects women, or workers over forty, or employees in a particular demographic group, the AI involvement transforms what might have been a defensible business decision into a class action candidate. The question of whether the AI was selecting people in a protected category is not difficult for a plaintiff’s attorney to raise. It is very difficult for a defendant to answer if the documentation, the human oversight, and the governance process were not built in advance.
The enterprises that will navigate the next five years of workforce AI without catastrophic legal exposure are the ones building their governance frameworks now — with HR, legal, and technology functions working in genuine collaboration, not in the sequential handoff model that has characterized technology adoption for the past three decades. The ones that treat HR as the function that gets notified after the procurement decision will discover, expensively, what Menon already knows: the human component is not a compliance checkbox. It is the primary defense.
What Executives Should Do This Quarter
Three concrete priorities emerge from Menon’s analysis. First, audit every AI tool currently in use across the organization that touches a workforce decision — hiring, scheduling, performance review, promotion, compensation, or reduction in force. For each one, document the human oversight mechanism. If there is no human in the loop, that tool represents the highest litigation exposure and should be the first governance priority. Second, establish a standing AI governance committee that includes HR leadership with genuine decision-making authority, not advisory status. The pattern Menon describes — where HR is notified after the tool is selected — is an organizational design failure that needs structural correction. Third, conduct a jurisdictional inventory. Every location where the organization employs people is a potential compliance obligation. The states and cities with AI-specific employment regulations are multiplying. Knowing where exposure exists is the prerequisite for managing it.
The argument Menon is making is not that AI in HR is too risky to pursue. It is that AI in HR deployed without the right governance architecture is unnecessarily risky. The technology creates genuine value — in recruiting efficiency, in performance analytics, in workforce planning. That value is recoverable. A class action judgment, or a pattern of regulatory enforcement actions, or a reputational event around discriminatory AI deployment, is substantially harder to recover from. The investment in governance is asymmetrically cheap compared to the downside it prevents. That is the calculation every C-suite reading this article should be running right now.
Based on reporting from HR must have a say in AI policy to forestall legal risks, originally published 2026-06-18 03:00:00.

