RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 10, 2026

The Model Rescored Everyone Overnight. Your Records Didn't.

Adverse impact claims are won and lost on records. AI screening tools generate more decision data than any manual process ever did — and then quietly overwrite it, version past it, and delete it on a schedule set by a vendor's storage budget. The gap between what the law expects you to preserve and what your stack actually keeps is where these cases get decided.

Impact data
Records showing effect on identifiable race, sex, and ethnic groups are required
Until disposition
Once a charge is filed, preservation runs to final disposition — no fixed end
Vendor default
Short retention and deletion on termination, unless you negotiate otherwise

The Obligation Predates the Technology

Nothing about the recordkeeping duty is new or AI-specific. Employers covered by federal anti-discrimination law must preserve applications and records relating to hiring, promotion, demotion, transfer, and termination. Separately, the uniform guidelines on employee selection procedures require employers to maintain records sufficient to show the impact of their selection procedures on identifiable race, sex, and ethnic groups, and to have validity evidence available where a procedure has adverse impact.

An algorithmic screen is a selection procedure. That is the entire analytical move — once you accept it, every existing recordkeeping obligation attaches to the model's outputs the way it attaches to a test score or an interview rating. What changes is only the practical difficulty of complying, and that difficulty is severe.

Four Ways an AI Stack Destroys Its Own Evidence

Scores are overwritten, not versioned
Many ATS integrations store a single current score per candidate. Re-run the screen after a configuration change and the prior score is gone. The record you needed was the one that existed at the moment of the rejection.
The model changes without a release note
Vendors retrain on their own cadence and rarely notify per-customer. Two candidates rejected six weeks apart may have faced materially different procedures, which is both a defensibility problem and a fairness problem you cannot see from inside the ATS.
Retention is set by the vendor's cost model
Ninety-day or twelve-month deletion defaults are common and are chosen for storage economics and privacy posture. They are not aligned to the period during which a charge can be filed, let alone to the life of the resulting litigation.
Termination triggers deletion
Switching vendors is the highest-risk moment in this whole system. Standard terms delete customer data on termination, and the employer's obligation to preserve does not terminate with the contract. Migrations get planned by procurement, who are not thinking about a charge that has not been filed yet.

What To Preserve, Concretely

A defensible record of an algorithmic selection decision has six components. Most organisations have two of them.

1
The decision record
Candidate identifier, requisition, timestamp, score or rank produced, the cutoff or rule applied, the resulting disposition, and whether a human reviewed or overrode it.
2
The system identity at decision time
Model or configuration version identifier, feature set, weighting or threshold settings. Enough to answer 'what exactly was applied to this person' a year later.
3
The applicant pool composition
Aggregate demographic data for the pool at each stage, collected through a lawful self-identification mechanism kept separate from selection decisions.
4
Stage-by-stage flow statistics
Pass rates by group at every gate the algorithm touches, computed and stored contemporaneously. Reconstructing these from raw data years later is expensive and disputable.
5
Validity and audit evidence
Whatever validation work supports the procedure's job-relatedness, plus any bias audit performed, including the underlying data and the methodology — not just the summary.
6
The human oversight trail
Records of accommodation requests, alternative process offers, and overrides. Where a human departed from the model, why. This is often the strongest evidence available and it is almost never captured.

Note what is not on this list: the model weights themselves. You generally do not need the vendor's intellectual property. You need to be able to describe and reproduce the decision, which the six items above accomplish without anyone handing over a proprietary artefact. Framing the ask that way is what makes it negotiable.

The Contract Terms That Make This Possible

You cannot retain what the vendor will not give you. Five clauses do the work, and they are far easier to obtain at renewal than after a charge arrives:

  • A retention floor stated in years, not the vendor's default, explicitly overriding the standard deletion schedule.
  • Model change notice — advance written notice of retraining, reweighting, or version changes affecting your tenant, with the version identifier recorded in exportable data.
  • Export rights to decision-level data in a machine-readable format, available on demand rather than only at termination.
  • Litigation-hold cooperation obligating the vendor to suspend deletion on your written notice and to preserve tenant data for the duration.
  • Post-termination preservation for a defined tail period, with an export delivered before any deletion runs.

This is the same non-delegable-duty problem that runs through every AI vendor relationship: the obligation stays with you while the facts sit with them. The clause list overlaps substantially with the one in our AI vendor contract terms guide, which is a reason to negotiate them once, together, rather than issue by issue.

Bias Audits Are Not a Retention Strategy

Jurisdictions with bias-audit mandates — New York City's rule for automated employment decision tools being the most familiar — require an audit and a published summary on a recurring basis. Teams frequently treat the audit as the compliance artefact and stop there. It is not sufficient. An audit summarises a period; a defense requires the underlying decisions. Keep the audit's input data and methodology alongside the published summary, and keep the per-decision records regardless of whether any audit mandate applies to you.

Frequently Asked Questions

What records must we keep when an AI tool screens applicants?

Applications and hiring-related records as required by federal recordkeeping regulations, plus records showing the impact of the selection procedure on identifiable race, sex, and ethnic groups. Where the algorithm is the selection procedure, that means scores, inputs, cutoffs, dispositions, and stage-by-stage flow statistics — not merely a list of who was hired.

How long must AI hiring records be retained?

Longer than typical vendor defaults. The baseline federal period runs from the making of the record or the personnel action, whichever is later, with longer periods for some employers including federal contractors, and state law may extend it. Once a charge or action is filed, preservation runs until final disposition with no fixed end date.

Our vendor retrains the model. Do we need to keep the old version?

You need to be able to describe and reproduce the decision as applied to a specific candidate: version identifier, feature set, threshold, and score distribution at that time. That is usually achievable without possessing proprietary weights, and framing the request that way is what makes vendors willing to agree.

Can we rely on the vendor to hold the records for us?

Only under a contract that obligates them to, and even then the legal duty generally remains yours. Default SaaS terms specify short retention and deletion on termination. Negotiate a retention floor, litigation-hold cooperation, on-demand export, and post-termination preservation.

What is the risk if records are missing?

Unfavorable inferences and, where a preservation duty had attached, potential spoliation sanctions. The practical harm is that a dispute you could have addressed with data becomes a dispute about your recordkeeping, which is a substantially worse position with both a fact-finder and a regulator.

Does a completed bias audit cover our recordkeeping obligation?

No. An audit is a periodic summary produced for a disclosure requirement; recordkeeping is about preserving the individual decisions that a claim will be litigated over. Keep both, and keep the audit's underlying data rather than only the published summary.

Fix the Migration Clause First

Of everything above, the highest-value change is the smallest: before your next screening-vendor switch, export decision-level data and suspend deletion. Vendor transitions destroy more relevant evidence than any other single event, they are scheduled months in advance, and nobody currently owns that step.

Then work backward — retention floors and version identifiers at the next renewal, flow statistics computed contemporaneously rather than on demand.

Related Reading