FPF and Leading Companies Release Risk Assessment Framework and Updated Best Practices for AI in Hiring & Employment
Expert working group updates 2023 report to account for the rise of generative AI; will host a webinar on September 28 to present an overview of best practices and risk framework
WASHINGTON, D.C. – The Future of Privacy Forum (FPF), with Dayforce, LinkedIn, UKG, Workday, and Beamery – leading HR, payroll, and employment software developers – today released Updated Best Practices for AI and Workplace Assessment Technologies. The Updated Best Practices build on Best Practices published in 2023 and address today’s widespread deployment of generative AI and agentic systems that can perform multi-step workflows with varying degrees of autonomy and oversight.
The 2023 Best Practice Framework laid the foundation of responsible AI governance, focusing on non-discrimination, transparency, data security and privacy, and human oversight as the industry was looking into the future. Today, as agents and generative AI work side-by-side with humans in consequential workflows, policymakers and practitioners need to know the full AI value chain and understand a novel risk assessment framework.
Instead of treating employment use cases as categorically either low or high risk, the Best Practices recommend a range of heightened safeguards that can be scaled with respect to an AI system’s overall functionality and intended use. In practice, risk is often dependent on context and configuration. Factors that increase risk include:
- Sensitivity of Data and Inferences – Systems that ingest sensitive data or make (or are capable of making) sensitive or unexpected inferences about people should be limited or subject to heightened guardrails.
- Degree of Autonomy, Discretion, and Action – Systems that operate more autonomously or independently may require greater protections to ensure transparency, auditability, and meaningful human oversight.
- Proximity to Decisions – Systems that directly make decisions or exist in close proximity to human decision-making should be subject to greater protections.
- Nature and Significance of Impact – Systems should be evaluated in relationship to the nature or significance of the decision being made, with the most consequential decisions (e.g. termination) requiring the greatest oversight.
FPF and the working group caution that no single risk factor is determinative, and urge organizations to assess where their AI system falls along a spectrum, considering how factors combine to elevate or reduce overall risk, as well as how each dimension may carry associated legal standards and compliance considerations.
“So much has changed around the use of AI in employment and hiring in the last few years,” said Stacey Gray, Senior Director of the FPF Center for Artificial Intelligence. “The unique risks posed by agentic and generative AI systems — such as fabricated content, reduced transparency and auditability, and the capacity to act with much less human oversight — have altered the responsibilities for developers and deployers. Safeguards like red teaming, auditing, and post-deployment monitoring are no longer optional, making this an important moment to update our previous recommendations.”
The working group’s updated best practices assign responsibilities to Developers and Deployers across the risk spectrum, including:
- Responsible AI governance programs that govern, map, measure, and manage risk across the system lifecycle and account separately for predictive, generative, and agentic behavior
- Non-discrimination practices that direct organizations to comply with applicable anti-discrimination law and to test proactively for unintended bias
- Transparency practices that divide disclosure duties between Developers and Deployers
- Data security and privacy practices that safeguard personal data alongside newer exposures such as prompt injection and agentic access to connected systems.
- Human oversight practices that describe a graduated set of authority levels and require humans to remain accountable for outcomes
FPF and the expert working group will host a webinar in the coming weeks to present their updated best practices and an overview of the risk assessment framework to policymakers, staff, developers, deployers, and other interested parties. The webinar, set for September 28 at 12 pm ET, is free to attend, but registration is required. For more information and to register, click here.
“The increasing use of generative AI in the workforce presents real benefits to job seekers, employees, and employers, but can also introduce new and compounding risks,” said Sheila Jambekar, SVP, Chief Privacy Officer, Associate General Counsel at Dayforce. “Implementing AI governance can be complex, but with this new risk assessment framework from FPF, policymakers and organizations should have a better way to understand and evaluate AI governance requirements and scale their application of these updated best practices accordingly.”
“As AI becomes a more integral part of how we work, organizations need clear, practical guidance for adopting these technologies responsibly,” said Sara Harrington, VP, Legal at LinkedIn. “These updated best practices help organizations deploy AI responsibly while upholding the principles of transparency, privacy, security, and human oversight.”
“Responsible AI creates trusted AI, and trust will be the catalyst for AI adoption,” said Aditya Bharadwaj, Assistant General Counsel, AI & Data Governance, UKG. “UKG has helped organizations around the world run complex workforces in highly regulated environments for nearly 50 years, and AI is the next evolution of that responsibility. When frontline workers trust AI, organizations can move faster and with more confidence to transform how works gets done – unlocking better experiences for employees, stronger outcomes for employers, and a foundation for the next generation of frontline workforce operations.”
“Workday believes responsible AI can expand opportunity for job seekers, employees, and employers, but only when people trust it,” said Barbara Cosgrove, Chief Privacy and Digital Trust Officer at Workday. “Grounded in leading frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001, these updated best practices offer employers a practical, risk-based approach to managing generative and agentic AI, while building a foundation to collaborate with policymakers on a responsible future of work.”
The Updated Best Practices are intended to serve as a holistic practitioner framework, and draw throughout on the NIST AI Risk Management Framework and related NIST guidance, ISO/IEC 42001 and 42005, relevant provisions of the EU AI Act, and emerging U.S. state frameworks, including those in California, Colorado, and Connecticut. It is designed to help Developers and Deployers meet current obligations under civil rights, employment, and privacy law while preparing for a governance environment that continues to evolve.
For more information about the Future of Privacy Forum, visit www.fpf.org.
# # #
About Future of Privacy Forum (FPF)
FPF is a global non-profit organization that advances principled and pragmatic data protection, AI and digital governance practices. We convene leaders across industry, academia, and the public sector to provide expert analysis, benchmarking, and best practices that support responsible innovation and regulatory compliance. FPF has offices in Washington D.C., Brussels, and Singapore. Follow FPF on X and LinkedIn.
The Center for Artificial Intelligence at the Future of Privacy Forum is dedicated to navigating the complex landscape of AI governance and its intersection with privacy and data protection law. Drawing on expertise from a global Leadership Council comprising industry leaders, academics, civil society, and policymakers, the Center provides sophisticated, practical policy analysis to help organizations align innovation with responsible implementation while meeting evolving regulatory requirements. Learn more about the FPF Center for AI at https://fpf.org/ai.