Software companies
Selling an HR tech company after Mobley: AI liability in diligence
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Selling an HR tech company after Mobley v. Workday means buyers will test whether your AI features could expose them to discrimination claims as the vendor, not only through employers. Before diligence opens, assemble a model inventory, bias testing records, a summary of customer AI terms and indemnities, an account of training data and a complaint log.
Key takeaways
- Mobley v. Workday made vendor-side liability for AI screening a standard diligence topic for HR tech buyers.
- An inventory of every feature that ranks, scores, filters or rejects candidates is the first document buyers request.
- Testing records matter more than testing claims; buyers want dates, methods, results and what changed afterward.
- Customer contracts decide who carries compliance duties and who indemnifies whom, so summarize them before the data room opens.
- Rules on AI in employment keep changing, so show buyers how you track them rather than a single snapshot.
Why Mobley changed HR tech diligence#
Mobley v. Workday changed HR tech diligence because it put a direct question to every acquirer: can the software vendor, and not only the employers using its tools, face liability when automated screening is alleged to discriminate? The case's procedural status keeps moving, so get a current summary from counsel rather than relying on press coverage.
Whatever the final outcome, buyers now price the possibility. Diligence teams that once asked only about security and privacy now ask which features make or shape hiring decisions, what testing was done, and how customer contracts allocate responsibility. Sellers who answer with documents keep control of the timetable.
Insurance adds pressure. Buyers who rely on representations and warranties insurance may find underwriters asking about AI risk or proposing exclusions, which can push the buyer toward a special indemnity or escrow instead. Ask your banker and counsel early how they expect underwriters to treat your AI features.
Seller checklist: what to assemble before the data room opens#
The seller checklist covers the documents buyers request once AI liability is on the agenda. Assemble them before the data room opens, because reconstructing testing history under deadline pressure produces weaker answers and invites follow-up requests.
- Inventory of every feature that ranks, scores, filters, recommends or rejects candidates or employees.
- For each feature, the inputs used, the model or rules behind it, and who sets thresholds and defaults.
- Training data account: sources, dates, contract permissions and whether customer applicant data was used.
- Bias and adverse impact testing records with dates, methods, results and the changes that followed.
- Human review controls, including defaults customers can and cannot change.
- Customer contract summary covering AI clauses, compliance allocation, indemnities and liability caps.
- Complaints, regulator inquiries, demand letters and litigation involving AI features.
- AI governance policies and named owners for model changes and incident response.
- Insurance policies and any notices already given under them.
The model inventory buyers expect to see#
The model inventory buyers expect is a plain table that lets a non-specialist see where automation touches an employment decision. Keep it factual and current; an inventory that omits a feature later found in the product does more damage than the feature itself.
| Field | What to record | Why buyers care |
|---|---|---|
| Feature and decision point | Where in the hiring flow the feature acts | Shows whether it shapes outcomes or only organizes work |
| Inputs | Resume fields, assessments, interview data and inferred attributes | Reveals proxy risks for protected characteristics |
| Logic | Model type or rules, with version history | Supports reproducing past results |
| Configuration | Who sets thresholds, and the shipped defaults | Shows whether vendor or customer drove a decision |
| Testing | Most recent tests, methods and results | Evidence of reasonable care |
| Documentation | What customers were told about the feature | Tests marketing claims against reality |
Customer contracts and the indemnity question#
Customer contracts decide much of the exposure, because they allocate compliance duties, indemnities and liability caps between you and the employers using your product. Buyers will read your standard terms and every negotiated exception, so summarize them before they do.
Negotiated enterprise contracts are where surprises sit. A large customer may have won a broad indemnity years ago; list such exceptions in a schedule so the buyer hears about them from you first.
| Clause | What buyers look for | Common red flag |
|---|---|---|
| Compliance allocation | Customer responsible for its hiring decisions and legal compliance | Vendor promises the product complies with all employment laws |
| Indemnity | Indemnities limited and tied to defined vendor breaches | Uncapped indemnity for discrimination claims |
| Liability cap | Cap applies to AI-related claims | Carve-outs that lift the cap for data or discrimination issues |
| AI feature terms | Clear description of what features do and require | Claims of bias-free or objective scoring |
| Data use | Permission for any model training on customer data | Training on applicant data without contract support |
Training data and candidate data rights#
Training data and candidate data rights are the second strand of AI diligence: buyers want to know what data trained your features and whether you had the right to use it. Applicant data is personal data, and contracts with employers often limit its use to delivering the service.
California shows how the ground has shifted. The CCPA's temporary exemptions for employee and business-to-business personal information expired on January 1, 2023, and the California Privacy Protection Agency began preliminary rulemaking on April 20, 2026 on how the law applies to employees, job applicants and independent contractors. Expect buyers to ask how you handle applicant rights requests across customer accounts.
Keep a clear line between applicant data, which belongs to customers and their candidates, and your own engineering, support and product records. That line also decides what, if anything, could be licensed later without candidate risk.
Show buyers how you track changing rules#
Buyers want to see how you track changing rules on AI in employment, because a snapshot taken at signing may be stale by closing. Federal anti-discrimination laws apply to hiring whatever tools are used, and state and local rules, such as New York City's law on automated employment decision tools, add notice and audit duties for employers that often flow down to vendors.
Colorado shows how quickly the map moves. Its AI Act, signed in May 2024, was delayed once and then repealed and reenacted in a narrower form in May 2026, effective January 1, 2027. A short register listing each rule, its status, the features it touches and the responsible owner persuades buyers more than a long memo.
Illustrative example: a candidate scoring vendor prepares for sale#
Illustrative: a fictional vendor of interview scheduling and candidate scoring software for hourly-workforce employers hires a banker to run a sale. Its product ranks applicants with a model trained on historical hiring outcomes, and an auto-advance feature moves top-ranked applicants to interviews.
Before launch, the founder and outside counsel build the model inventory, gather adverse impact tests run across several releases, and find a small number of enterprise contracts with uncapped indemnities. They schedule those contracts, document that auto-advance was always customer-configurable, and summarize how training data permissions were obtained.
When the buyer's counsel raises Mobley on the first diligence call, the seller answers with the inventory, the test history and the contract schedule. The buyer still negotiates a specific indemnity for the scheduled contracts, but the process stays on its timetable.
How SourceX fits around an HR tech sale#
SourceX does not advise on M&A, but HR tech founders often ask whether licensing records before or after a sale creates new diligence questions. In the SourceX five-step transaction, candidate and employee personal data held for customers is generally excluded in the Rights step, and assessment focuses on the vendor's own engineering, support and product records.
Where a license exists, the SourceX Evidence Packet gives an acquirer a dated account of where the records came from, which licensing rights and permitted uses applied, how privacy was handled and who authorized the release, which is the kind of evidence AI diligence now expects.
Frequently asked questions
Should we raise Mobley-related risk ourselves?
Usually it is better for buyers to learn about AI exposure from your documents than from their own research. How and where to disclose, including what goes in disclosure schedules and what stays under privilege, is a decision for your M&A counsel. Preparing the inventory and testing history early gives counsel more options.
Does switching off an AI feature before the sale remove the risk?
No. Claims can relate to past use, so historical records still matter, and removing a feature shortly before a sale can raise more questions than it answers. If a feature should change, document why, what changed and when, and keep the earlier testing and configuration records.
What if we never formally tested for bias?
Start now, with counsel involved, and be accurate about the timeline. Some companies run testing under attorney direction to protect privilege over the analysis. A recent, well-documented test with clear follow-up actions is far better than a gap, and overstating past testing would be worse than either.
Can we license company records while a sale process is running?
It is possible but usually unwise without the buyer's knowledge, because a new license adds a contract the buyer must review and may restrict the business after closing. If licensing matters to your equity story, scope it before the process starts or agree the approach with the buyer.
Will buyers ask to see our model code?
Some will ask to review model documentation, testing code or samples of past decisions rather than full source code, often through a clean team or an independent reviewer. Agree the access method with counsel, protect trade secrets through the confidentiality agreement, and make sure no candidate personal data is exposed during the review.
Sources
- The Colorado AI Act (SB 24-205), signed May 17, 2024, was originally effective February 1, 2026. Colorado SB 25B-004, signed August 28, 2025, delayed its effective date to June 30, 2026, and on May 14, 2026 Governor Polis signed SB 26-189, which repealed and reenacted the law in a narrower form effective January 1, 2027. Source
- The California legislature ended its 2022 session on August 31, 2022 without extending the CCPA employee and business-to-business personal information exemptions, so the exemptions expired on January 1, 2023. Source
- The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 focused on how the CCPA applies to personal information of employees, job applicants and independent contractors, with preliminary comments accepted through May 20, 2026. Source
Related resources
- QuestionDo AI labs buy spreadsheets?
- QuestionCan licensed data be used to train competitors' models?
- InsightData and AI reps in purchase agreements: what buyers now ask sellers
- SolutionData monetization: earning revenue from data you already have
- SolutionHow AI developers source data
- IndustryBPO & contact centers data
See if your company qualifies
A short company assessment. No data uploads are needed.