ARTICLE

You Still Own the AI Risk, Even If You Didn’t Build the Tool

By Nahteava
July 23, 2026

A federal judge in California allowed a discrimination lawsuit against Workday to proceed as a collective class action this year. The case goes back to 2023, when a job applicant claimed Workday’s screening software rejected him and others based on age, race, and disability rather than qualifications. What makes the case worth paying attention to isn’t just the discrimination claim itself. It’s who’s on the hook. Workday didn’t do any hiring. It built the software that companies use to screen applicants. The court is treating that as enough to share liability with the employers who used it, and by the company’s own disclosures, we’re talking about a tool that processed billions of job applications.

Workday isn’t an isolated example. Cigna is facing a lawsuit over an algorithm called PXDX, which reviewed insurance claims and denied ones that didn’t match preset criteria, with no doctor required to actually look at the case. Court filings show the system rejected over 300,000 claims in two months, averaging about 1.2 seconds of review per claim. Peloton got pulled into a lawsuit over chat data that a third-party vendor, Drift, allegedly mishandled during customer conversations. Drift built the tool and ran the processing. Peloton is the one being sued.

None of these companies wrote the AI themselves. All of them are the ones answering for it in court.

The Pattern Nobody Can Afford to Ignore

There’s a theory a lot of companies have been operating under, whether they’d say it out loud or not: if we license the AI tool instead of building it, the liability mostly sits with whoever made it. That theory isn’t holding up. Courts and regulators keep landing on the same conclusion. The company closest to the customer, the applicant, the patient, whoever actually got affected, is the one that answers for what the tool did. Not the vendor sitting one or two steps removed.

That makes sense once you think about it from the regulator’s side. A patient whose claim got denied in 1.2 seconds doesn’t have a relationship with the software company. They have a relationship with Cigna. A job applicant rejected by an algorithm applied for a job at a specific employer, not at Workday. The legal system tends to go after the party the harmed person actually dealt with, and increasingly, that’s enough to establish liability even when the underlying tool came from somewhere else entirely.

Why “We Outsourced It” Isn’t a Defense Anymore

This shows up as a real gap in a lot of governance programs. Companies will spend real effort vetting AI they build in-house, then treat a purchased or licensed tool almost like off-the-shelf software, something you install and trust because a vendor sold it to you. That gap is exactly where these lawsuits are landing.

If your company is buying or licensing AI tools for hiring, claims processing, customer service, or anything that touches a real person’s outcome, the questions worth asking aren’t really about the vendor’s marketing claims. They’re about your own exposure. Do you know how the tool actually makes decisions, or just that it works most of the time? Did anyone check it for the kind of bias that shows up in the Workday case? Is there a person accountable for reviewing edge cases, or does the algorithm run unsupervised the way Cigna’s did? If a regulator or a plaintiff’s attorney showed up tomorrow asking these questions, could you answer them, or would you be finding out the answers for the first time alongside them?

Most companies can’t answer those questions right now. That’s not a knock on any particular organization. It’s just where the industry is. Governance programs were largely built around AI you develop yourself. The legal exposure has moved faster than that, and it’s landed squarely on the buyer.

Where We Can Help

Our AI policy, governance, and risk assessment questionnaires were built to close exactly this gap, including the part that’s easy to overlook: the risk that walks in the door through a vendor contract instead of your own engineering team. We can help you figure out where your exposure actually sits, whether that’s your vendor vetting process, how decisions made by purchased AI tools get reviewed, or your broader governance structure. Reach out, and we’ll help you find the right starting point.

Sources: You Outsourced the AI, But You Still Own the Risk — Harvard Business Review; Workday Loses Bid to Toss AI Discrimination Suit in California — Bloomberg Law; A Federal Judge, A 1967 Law And A Billion Rejected Job Applications — Forbes; Cigna Hit With AI Lawsuit Over Controversial AI Technology Use; Court Allows Lawsuit Over AI Use in Benefit Denials to Proceed — NFP; Peloton Takes a Spin Through Court, Thanks to AI Privacy Lawsuit — Dark Reading

Let’s Build What’s Next – Together