Governing risk and ethics
As AI’s influence grows, so do the stakes. Without ethical guardrails, AI systems can amplify bias and erode trust. The Amazon case is perhaps the most cited example: a CV screening tool built between 2014 and 2017 was found to systematically downgrade resumes containing the word “women’s” and to penalize graduates of women’s colleges, because the model had been trained on a decade of hiring data that reflected existing male dominance in technical roles. Amazon scrapped the project when it could not guarantee the system would not learn other discriminatory patterns (MIT Technology Review, 2018). The lesson is not that AI cannot be used in recruitment, but that training data encodes history, and history in hiring has rarely been neutral. Excessive automation risks robbing HR of its human-centered edge. The example of Moderna also warns of the perils of merging HR and tech mindsets, with distinct mandates and values, risking skewed outcomes if not carefully balanced. At the same time, boards and CEOs expect disciplined AI deployment and oversight. In 2024, surveys of directors show boards elevating AI governance, asking management (often via the CHRO and CIO) to evidence controls for ethics, workforce impacts, and culture (Harvard Law School Forum on Corporate Governance, 2024). CHROs must actively safeguard the human in human resources.
Equally important, CHROs are becoming policy makers in enterprise AI governance, operating in a rapidly shifting and increasingly complex regulatory landscape.
Navigating the EU AI Act
The Act entered into force on 1 August, 2024, establishing a risk-based framework for AI use across the EU. For HR, the most immediate impact has already arrived: since 2 February 2025, certain AI practices in the workplace have been outright banned, including emotion recognition during hiring interviews and biometric categorization of candidates. The pivotal compliance deadline for HR is 2 August 2026, when the full suite of high-risk system obligations becomes enforceable for all employment-related AI, covering recruitment, screening, candidate evaluation, performance monitoring, and promotion decisions. Requirements include mandatory risk assessments, bias testing, technical documentation, human oversight mechanisms, transparency disclosures to candidates, and continuous monitoring. Non-compliance can carry fines of up to €35m ($40.98m) or 7% of global annual turnover for the most serious violations (European Commission, 2024; Ogletree, 2025). The Act carries extraterritorial reach: US employers using AI tools to recruit EU-based candidates or manage EU-based workers are subject to these obligations even without a physical EU presence.
Understanding shifting US regulations
The US federal regulatory picture has shifted significantly. In January 2025, the Trump administration revoked Biden-era executive orders on AI governance, and the EEOC subsequently removed its 2023 guidance on responsible AI use in employment selection from its website. However, employers remain fully liable under Title VII and other existing federal laws if their AI tools produce a disparate impact on protected groups, regardless of whether the tool was purchased from a third-party vendor. At the state level, the regulatory patchwork is tightening: Colorado’s Senate Bill 24-205, effective February 2026, mandates bias audits for high-risk AI used in employment decisions; California’s Civil Rights Council has extended anti-discrimination rules to AI tools, requiring employers to retain automated decision data for four years; and New York City, Illinois, and other jurisdictions have layered additional notice, audit, and human-review requirements onto HR AI use (Holland & Knight, 2025; Lexology, 2026).
Taken together, these developments place CHROs squarely at the center of algorithmic risk management, owning adverse-impact testing, accommodation processes, transparency obligations, and vendor due diligence in an environment where regulatory requirements are simultaneously tightening globally and fragmenting domestically. As Kalin Anev Janse, CFO of the European Stability Mechanism, underscored, “Every leader, including CFOs, must champion AI and understand the systemic risks of generative AI in finance”, a principle that applies with equal force to HR (World Economic Forum, 2025).