About 43% of HR teams were using AI for HR tasks in 2025, up from 26% the year before. By the time SHRM's annual conference wrapped in Orlando this past month, the conversation had shifted from whether to use AI to how to do it without creating a legal or operational mess.
That shift matters for any organization that employs people, not just companies with a dedicated HR department.
Here is the core problem. When AI handles a routine process, and something goes wrong, the question of who is responsible does not disappear. It gets harder to answer. Employers remain legally responsible for employment decisions even when a software tool made the call.
The legal pressure on this point is now substantial and getting more specific. Illinois law, effective January 2026, prohibits employers from using AI in ways that discriminate against protected groups across the full employment process, from recruiting through termination. California's rules, which took effect in October 2025, require meaningful human oversight for any automated decision system used in employment, with someone trained and empowered to override the AI. Colorado requires risk assessments for high-risk AI systems. New York City already requires annual independent bias audits for automated hiring tools.
The EU goes further. From August 2026, AI used in hiring, promotion, performance evaluation, or dismissal is classified as high-risk under European rules. That means companies doing business in Europe face documentation, transparency, and oversight obligations that are not optional.
And there is a pending lawsuit against Workday, one of the largest HR software providers, over claims that its AI screening tools produced discriminatory outcomes. Workday disputes this, but the case illustrates the direction of travel: courts and regulators are increasingly willing to treat the employer, not the software vendor, as the accountable party.
The operational risk is just as real as the legal one. An automated payroll system does not know that an employee just relocated to a different state with different tax rules. An attendance-tracking tool can flag someone for poor performance without understanding the context behind the pattern. A résumé filter trained on historical hiring data can quietly disadvantage applicants who do not fit the profile of whoever was hired before.
One biased algorithm can affect thousands of people at once. That is categorically different from a single manager making a poor call. The scale of the error scales with the automation.
For business operators outside HR, the lesson is the same one that applies inside it. Automation is genuinely useful for handling volume, consistency, and speed. It is not a substitute for someone who understands the context and owns the outcome. The useful question to ask about any automated process in your business is simple: if this produces the wrong result, do you have a person who will catch it, and do they have the authority to fix it?
If the answer is no, the automation is not saving you risk. It is concentrating it.