Est.

Proxy Discrimination in Credential-Based AI Filtering

Senior Writer · · 13 min read
Cover illustration for “Proxy Discrimination in Credential-Based AI Filtering”
Bias & Fairness · September 30, 2026 · 13 min read · 2,827 words

Proxy discrimination happens when an AI system uses a data point that looks neutral, like a zip code or a school name, but actually stands in for race, gender, age, or another protected trait. The result is a filtering process that quietly encodes bias while claiming to be blind to it, and that makes it both a fairness problem and a talent problem at once. Understanding exactly how this happens mechanically is the first real step toward fixing it.

Credential-based AI filtering and proxy discrimination

Start with the definition, because it matters more than it sounds like it should. Proxy discrimination is what happens when an AI system relies on a facially neutral data point that's statistically tied to a protected characteristic. The protected trait itself never enters the model. Its shadow does.

This is different from the kind of discrimination employment law was built to catch. No one has to intend anything for the harm to occur. That absence of intent is exactly what makes proxy discrimination so slippery, both legally and operationally, because the usual tools for proving bias assume someone meant to discriminate.

So how does it actually happen? Walk through it step by step. An employer or a vendor strips out the obvious fields, race, gender, age, believing that removing them makes the system neutral. Then the model gets trained on historical hiring data, and it starts looking for whatever predicted "success" in the past, meaning who got hired, who got promoted, who stuck around. But what if the things that predicted past success were never about merit to begin with?

That's step three, and it's the crux of the whole mechanism. The neutral signals the model learns to rely on are themselves proxies. ZIP code correlates with race. University name correlates with socioeconomic background and, again, with race. Graduation year correlates with age. First name correlates with gender and ethnicity. Employment gaps correlate with disability and with caregiving responsibilities. None of these facts are secret. They're just usually invisible in the moment a resume gets scored.

Step four is where it all lands: the model re-encodes the protected characteristic through the proxy, and nobody programmed it to do that on purpose. It emerges from the correlation, not from a rule someone wrote.

This isn't unique to hiring. The Stanford Law Review, in a piece published in September 2026, points to a widely used health care algorithm that assigned Black patients lower risk scores by treating prior health care spending as a stand-in for medical need. Spending patterns reflected access to care, not health status, so the proxy was broken from the start. HHS extended nondiscrimination principles to AI decision-support tools in 2024 in direct response to that failure. Same structural mistake, different door.

Hiring has its own version, and it has a name attached to it now. Derek Mobley applied to over one hundred jobs through employers using Workday's AI screening platform and got rejected every single time, some of those rejections landing by email at 2:00 AM, when no human being was anywhere near the decision. Mobley is Black, over forty, and lives with a disability. His allegation is that Workday's algorithm filtered out applicants like him by weighting interruptions in employment history and medical-related leave, both neutral-looking data points that correlate tightly with protected traits.

None of this is meant to sound alarmist. It's meant to be precise, because precision is what lets a hiring team actually audit for the problem instead of just feeling uneasy about it.

The scale at which proxy discrimination now operates

The numbers start to matter now. In 2024 alone, AI-powered hiring tools processed over 30 million applications, and that volume came paired with hundreds of discrimination complaints Akerman LLP. This is the mainstream use case. It's the mainstream one.

Adoption tells the same story from a different angle. That concentration is its own risk: when a handful of vendors serve nearly everyone, a single bias baked into one model doesn't stay contained to one company. It replicates across millions of decisions at once Stanford research. Add to that the fact that 84% of talent leaders plan to use AI in recruiting in 2026, based on Korn Ferry's 12th Annual Talent Acquisition Trends survey of over 1,670 global talent leaders, and the direction of travel is obvious.

Stanford Law Review has a term for what this produces: algorithmic monocultures in hiring. When most of the market runs on the same few vendor models, one biased training corpus doesn't cause isolated errors here and there. It causes correlated errors across thousands of employers, all at the same time, in the same direction.

Volume is accelerating the whole thing. Companies are now seeing nearly three times as many applications for entry-level roles as they did in 2022. At that scale, AI screening stops being optional, which means whatever bias exists in the model runs deeper into the funnel than it would if a human were reading every resume.

So the problem was never that AI entered hiring decisions. It's that biased signal selection is now operating at a velocity and a reach no human reviewers could ever match, which means errors compound rather than average out. Bricker's findings show that 99% of Fortune 500 companies now use AI to filter job applicants.

Empirical evidence on which candidates get filtered out

Diagram: The Racial Screening Gap: Names, Identical Qualifications, Different Outcomes. Visualizes: Visualize the stark disparity in AI screener preference rates by race, from a Brookings and Stanford-MIT study.

The clearest finding on race comes from a Brookings and Stanford-MIT study, which found AI screeners showed racial bias in 93.7% of tests run Brookings/Stanford-MIT study. White-associated names were preferred at an 85.1% rate Brookings/Stanford-MIT study. Black-associated names, despite identical qualifications, were preferred just 8.6% of the time Brookings/Stanford-MIT study. That gap represents a substantial, systemic disparity. It's close to a tenfold difference.

Exposure to that bias isn't evenly spread either.

Age and gender appear as separate, documented patterns rather than footnotes. In October 2025, Stanford-affiliated researchers found that AI resume-screening tools portrayed female candidates as younger and less experienced than male candidates, with older men rated more favorably, even when every resume was generated from identical underlying data. That's bias against older women specifically, not just women in general. And research published through VoxDev found that AI hiring tools systematically favored female applicants over Black male applicants who had identical qualifications. Bias doesn't run along one axis. It runs along several at once, and it can favor one group over another group that's also marginalized, which complicates any simple story about who the system helps and who it hurts.

There's a named example that ties this back to credentials directly. iCIMS faces allegations that its AI and ML tools screen, rank, or filter applicants using race-correlated data points, specifically educational institutions, employment history, and ZIP codes, in a way that disproportionately excludes African American applicants, in alleged violation of Title VII and 42 U.S.C. § 1981.

The legal system is registering all of this, even if slowly. The EEOC logged 88,531 discrimination charges in fiscal year 2024, a 9.2% jump over the year before. Not every charge traces back to an algorithm. But the trend line is moving the wrong way just as AI adoption in hiring keeps climbing, meaning discrimination charges are likely to keep rising as more employers deploy these tools. These are measured risks documented in real deployments, not hypothetical ones sketched out in a whitepaper. They're measured outcomes, from real tools, screening real applications. Stanford HAI research shows that 26% of Black applicants and 15% of Asian applicants applied to positions where the AI system discriminated against their racial group Stanford research.

Why "skills-based hiring" declarations don't automatically fix proxy discrimination

Diagram: Skills-Based Hiring in Name Only: The Degree Reset Paradox. Visualizes: Visualize the gap between stated policy and actual hiring outcomes in skills-based hiring.

That sounds like real progress until the actual hiring numbers appear. Joint research from Harvard Business School and the Burning Glass Institute found that only about 0.14% of actual hires went to people without a college degree, roughly 97,000 hires out of 77 million annual U.S. hires, fewer than one in every 700. Only 37% of companies that dropped their degree requirements actually went on to hire more non-degree candidates.

Why the gap? Call it the degree reset paradox. A company deletes "bachelor's degree required" from a job posting and still, somehow, keeps hiring from the same familiar universities, the same recognizable employers, the same conventional career tracks. The label changed. The scoring underneath it didn't.

That's the actual mechanism at fault. For skills-based hiring to mean anything, the assessment process has to change alongside the job description, not instead of it. The bias was never really sitting in the text field. The scoring model contains it, one layer removed from what the job posting says, and produces the mismatch between stated criteria and actual outcomes.

Trace it back to root cause and it lines up with the mechanical explanation from earlier: AI trained on historical "successful hire" data learns whatever proxies predicted past hires, not whatever proxies would actually predict future performance. And those past hires, by definition, reflect the exact credential preferences the company now says it wants to move away from.

That creates a strange kind of invisibility. A company can sincerely believe it has shifted to skills-based hiring while its AI vendor's model keeps doing credential pattern-matching one layer down, unnoticed. That gap between stated policy and actual scoring behavior is the core operational risk here, and it's one most hiring teams don't even know to look for. TestGorilla's State of Skills-Based Hiring 2025 survey found that 85% of employers reported using skills-based hiring.

Mobley v. Workday is the case to watch. The court dismissed the intentional discrimination claims, finding Workday failed to plausibly allege that Workday intended its tools to discriminate. But the ADEA age discrimination claims were certified as a collective action in May 2025 and were still pending as of the Stanford Law Review's September 2026 publication. At the start of 2026, a federal court let the federal claims move forward, granting Workday's motion to dismiss in part and denying it in part. What the case has established, regardless of how it ultimately resolves, is that facially neutral inputs like employment history, geographic data, and education can produce discriminatory disparate impact even with zero intent behind them.

A second case adds a different angle. The claims allege violations of the FCRA and California's Investigative Consumer Reporting Agencies Act. This is a transparency and consumer-protection complaint more than a discrimination one, but it points at the same underlying opacity problem: candidates don't know what's scoring them or how.

State law is filling in around these cases, unevenly. New York City Local Law 144, effective since January 2023 with enforcement starting July 5, 2023, requires annual independent bias audits for any automated employment decision tool and at least 10 business days' notice to candidates before one is used, with fines up to $500 per violation for a first violation (and same-day violations), and $500–$1,500 per violation for each subsequent violation, with every day of noncompliant use counted separately. It applies specifically when the AI output is the sole factor, weighted more heavily than anything else, or used to override human judgment, not when a human makes the final call with the AI ranking as one equal input among others.

California's Civil Rights Council Regulations, effective October 1, 2025, bar any automated-decision system used in employment from discriminating on FEHA-protected grounds, whether through direct discrimination or disparate impact, and require anti-bias testing and at least four years of record retention, with vendors potentially liable under agency principles when they act on an employer's behalf. Illinois House Bill 3773, effective January 1, 2026, bans AI use that results in bias against protected classes regardless of intent, and specifically bans ZIP codes as a proxy. Colorado's Artificial Intelligence Act, effective June 30, 2026, treats hiring AI as a "high-risk" system requiring annual impact assessments and an appeal process for adverse decisions Akerman LLP. Texas takes the opposite path: TRAIGA, effective January 1, 2026, bans intentional discrimination but explicitly rejects disparate impact as a standalone basis for liability, a real departure from California's approach.

These statutes share a deeper gap, and it produces the same failure across each one. American civil rights law is built around named protected classes, but machine learning models generate their own classifications out of hundreds or thousands of features that have no obvious tie to race, sex, or any other prohibited ground. That protected-class framework has anchored enforcement for over sixty years, and it simply wasn't built for a pattern like this. Courts are applying existing doctrine anyway, even where AI-specific statutes don't exist yet, and the operating conclusion is that existing law is more than sufficient to regulate AI-driven decisions. In other words, the absence of a state AI law isn't a safe harbor.

Proxy discrimination as a talent quality failure

This gets missed most often. When AI screens on credential proxies, it isn't selecting for ability. It's selecting for the demographic and socioeconomic groups that historically had access to those credentials in the first place. The people getting filtered out are differently credentialed candidates, not weaker ones. They're differently credentialed ones, and that distinction changes everything about how a company should think about its funnel.

The errors run in both directions at once. A weak candidate with a recognizable university and a familiar employer's name on the resume sails through the screen. A strong builder with an unconventional path, a military veteran, a career-changer, a technical specialist who came up through a non-elite school, gets filtered out before a single human ever looks at their work.

The data backs this up. Semantic search, the kind that evaluates context and clusters of skills instead of matching keywords, finds 60% more relevant profiles and cuts false-positive rates by 62%. That's a substantial improvement. That's a fundamentally different funnel.

What makes this stranger is the mismatch between what employers say they want and what their AI actually rewards. Yet credential-based AI scoring keeps rewarding the exact signal employers claim they don't want. The stated priority and the actual scoring model are pointing in two different directions, and most companies haven't noticed the split.

The cost of getting this wrong isn't abstract. The U.S. Department of Labor estimates a bad hire can cost up to 30% of that employee's first-year wages Akerman LLP. Proxy discrimination doesn't just create legal exposure. It systematically installs the wrong people into roles while rejecting the right ones, and that's a cost that compounds quietly, long after the rejection email went out Akerman LLP. CTO Magazine's report finds that 59% of employers want to see skills demonstrated with concrete examples on a résumé rather than merely listed. Korn Ferry finds that 73% of talent leaders rank critical thinking as their top skill priority for human hires, as cited in HeroHunt's report.

Filtering requirements based on evidence of actual work

The shift that actually fixes this moves attention away from inputs that happen to correlate with protected traits and toward outputs that demonstrate the work itself, what someone has built, shipped, solved, or led, assessed directly instead of inferred from where they went to school.

That shift doesn't happen by accident. It takes deliberate calibration. A hiring team has to define what "exceptional" actually looks like for a specific role, not a generic job description copied from a template, but a working standard built around the capabilities that actually predict success in that context. And that calibration works best across functions. An HR manager might spot that a certain credential functions as a proxy for socioeconomic status in a way a developer-turned-engineer on the same panel would never think to question. Cross-functional review, spanning HR, data science, legal, and the hiring managers themselves, is how those blind spots actually become visible.

Blind screening is one structural control that directly prevents resume-screening bias. Stripping names, photos, graduation years, and addresses out of a resume before anyone reviews it removes the exact signals that drive most resume-screening bias. Properly implemented, blind screening that removes those demographic cues has been shown to cut gender bias by 54% and improve underrepresented minority hiring by 35%.

Structured assessment matters just as much once candidates get past that first screen. Structured interviews predict job success with a validity coefficient of 0.51, against 0.38 for unstructured ones, nearly twice as effective at forecasting actual performance. Work samples, coding challenges, and situational judgment tests give candidates from nontraditional backgrounds a real way to show what they can do, rather than asking a resume to speak for them. AI still has a role here. It can score those work samples consistently, at scale, giving hiring teams objective data instead of a gut read on a credential.

None of this is a one-time fix. A calibration standard set once and never revisited will drift right back toward the same proxies it was built to avoid, because the underlying data keeps reflecting who got hired before, not who deserves to get hired next.

Sources

  1. HRDef: AI in Hiring: Emerging Legal Developments and Compliance Guidance for 2026 - Akerman LLP
  2. AI-Based Hiring: 2026 Developments Employers Can’t Ignore
  3. Classifying and Countering AI Proxy Discrimination | Stanford Law Review
  4. AI Hiring Tools Can Yield Racial Bias and Systemic Rejection
  5. Unlawful Proxy Discrimination: A Framework for Challenging Inherently Discriminatory Algorithms
Filed underBias & Fairness

More in Bias & Fairness