Fair Work and AI: Hiring, Rosters and Surveillance

Workforce AI Is the Highest-Discrimination-Risk Class of AI a Midsize Business Runs
AI now reads resumes, scores candidates, predicts attrition, allocates shifts, monitors keystrokes, summarises meeting transcripts, and feeds the data points that performance reviews and redundancy decisions are built on. In a 50 to 500 person business those features arrive bundled inside platforms the People team already uses: applicant tracking systems, HRIS modules, workforce management suites, the AI copilot inside Microsoft 365 or Google Workspace.
Each touches a discrete provision of Australian workplace law. Most midsize employers have not mapped which provision is triggered by which feature, who signs off, and what evidence will satisfy a Fair Work Commission member or Australian Human Rights Commission inquiry if something goes wrong.
In our why-not-DIY analysis and production reality piece we covered why workforce AI carries operational risk that consumer chatbots do not, and in the staffing gap article we covered who owns these decisions. This piece is the legal-exposure layer underneath. The thesis is simple: of all the AI a midsize business runs, the workforce stack carries the highest aggregate discrimination, procedural fairness, and surveillance risk, and the controls required to defend it look nothing like the controls for customer-facing AI. If you have read the AI change management piece, this is its legal twin. That article was about getting employees to use AI. This one is about using AI on employees.
Part 1: Five HR and Payroll Decisions Where AI Is Actively in the Loop
The first step is mapping where AI is already making, or materially influencing, decisions in your workforce systems. In a 50 to 500 person business, the five high-risk decision classes are almost always these, and each one triggers a different provision of Australian law.
Five Workforce AI Decisions and the Law They Touch
| Metric | AI Use Case | Australian Provision Triggered |
|---|---|---|
| Hiring and candidate screening | Resume parsing, candidate scoring, video-interview sentiment analysis, knock-out questions | Sex Discrimination Act 1984 (Cth), Disability Discrimination Act 1992 (Cth), Racial Discrimination Act 1975 (Cth), Age Discrimination Act 2004 (Cth), state Equal Opportunity / Anti-Discrimination Acts |
| Rostering and shift allocation | Algorithmic shift offers, predictive demand staffing, automated swap approvals | Modern award consultation clauses, FW Act 2009 s65 (flexible work requests), Closing Loopholes No.2 right to disconnect (s333M) |
| Performance, promotion, and pay review | Productivity scoring, AI-generated review summaries, attrition risk flags fed into talent calibration | FW Act s340 (general protections / adverse action), Workplace Gender Equality Act 2012 reporting obligations, AHRC guidance on algorithmic bias |
| Monitoring and productivity scoring | Keystroke and screen monitoring, location tracking, email and chat sentiment analysis | NSW Workplace Surveillance Act 2005, ACT Workplace Privacy Act 2011, VIC Surveillance Devices Act 1999, Privacy Act 1988 APP 5 and APP 11 |
| Termination and redundancy selection | AI-assisted ranking for redundancy pools, performance flags as PIP trigger, automated misconduct detection | FW Act s387 (procedural fairness in unfair dismissal), FW Act s389 (genuine redundancy), s340 adverse action, anti-discrimination acts |
Almost every midsize employer we speak to runs AI in at least three of these five rows. Few have mapped which provision is triggered, fewer still have the documented sign-off and audit trail an FWC member would expect to see.
Part 2: The Discrimination-by-Algorithm Trap
The defining feature of workforce AI risk is that it produces discrimination at scale without anyone deciding to discriminate. The model learns from historical hiring, promotion, and termination data. That data reflects past human choices. The model reproduces them, often with new proxy variables the business never thought to police.
The international precedents are now well-documented. In iTutorGroup (2023) the US Equal Employment Opportunity Commission settled for USD 365,000 after the company's recruitment software was configured to reject female applicants aged 55 and over and male applicants aged 60 and over. It was the EEOC's first AI-hiring discrimination settlement. Amazon's internal resume-screening tool, abandoned in 2018, famously penalised resumes that included the word "women's" because the model had learned that historic Amazon hires were overwhelmingly male.
Australian law does not treat the "but the model just learned from the data" defence kindly. The indirect discrimination tests in the Sex Discrimination Act 1984 (s5(2)), Disability Discrimination Act 1992 (s6), Racial Discrimination Act 1975, and Age Discrimination Act 2004 do not require intent. They require a condition, requirement, or practice that has a disparate impact on a protected group and that is not reasonable in the circumstances. An algorithm is a condition, requirement, or practice. "We did not know the model was biased" is not a defence. It is, at best, mitigation.
The Australian Human Rights Commission has published technical guidance on AI in decision-making, most notably its 2021 Human Rights and Technology Final Report and follow-up Guidance Resources on AI-informed decision-making. The AHRC position is consistent: where AI is used to make or materially influence decisions about a person, the entity using the AI carries the same human rights and anti-discrimination obligations it would carry if a human had made the decision unaided.
The practical implication for midsize employers is that the vendor's claim of "bias-free AI" or "fairness-audited model" does not transfer the legal risk. The risk sits with the employer. Vendor warranties on this point are usually narrow, and we have unpacked the questions to ask in our AI vendor selection article.
Part 3: The Fair Work Act Layer
Even where no protected attribute is involved, the Fair Work Act 2009 imposes a separate set of obligations whenever AI feeds into a workforce decision. There are four provisions a midsize People and Legal team should know cold.
Consultation Obligations Under Modern Awards
Almost every modern award contains a consultation clause, generally clause 8 in the standard award template, requiring the employer to consult with affected employees and their representatives before implementing a "major change" to production, programme, organisation, structure, or technology likely to have significant effects. Deploying AI that materially changes how shifts are allocated, how performance is measured, or how termination decisions are reached almost always meets that threshold.
The Fair Work Commission has heard a steady stream of disputes since 2020 about technology rollouts implemented without proper consultation. The remedy is not usually to overturn the technology, it is an order to consult, and in some cases an order that decisions made in the unconsulted window be reconsidered. The reputational and operational cost of having to undo three months of AI-influenced decisions is the part that bites.
s387: Procedural Fairness in Termination
FW Act s387 lists the factors the Commission must take into account in unfair dismissal. They include whether the person was notified of the reason for dismissal, whether they had an opportunity to respond, and whether the dismissal was harsh, unjust, or unreasonable. Where AI flagged the performance concern, scored the productivity, or summarised the misconduct evidence, the employer needs to be able to explain what the AI did, why its output was relied on, and what human verification occurred before the dismissal decision.
"The system flagged them as bottom decile" is not a sufficient answer. The employee, and the Commission, are entitled to know what the model measured, what data it used, and whether the employee had a meaningful opportunity to challenge the AI output before the dismissal was finalised.
s340: Adverse Action and General Protections
s340 prohibits an employer from taking adverse action against an employee because the employee has a workplace right. The reverse onus in s361 means that once the employee alleges the reason, the employer must prove the reason was something else. Where AI scored, ranked, or flagged the employee, the question of "what was the actual reason for the action" becomes harder to evidence, not easier, because the model's reasoning may be opaque.
Right to Disconnect: s333M
The Closing Loopholes No.2 Act 2024 inserted s333M into the Fair Work Act, giving most employees a right to refuse to monitor, read, or respond to contact from the employer outside working hours, unless the refusal is unreasonable. AI-monitored after-hours work, "always on" status tracking, and chat-sentiment analysis that flags response delays now operate in tension with this right. Employers need to be careful that their AI monitoring does not, in practice, defeat the protection the statute creates.
Part 4: Workplace Surveillance, the State-by-State Patchwork
Workforce monitoring AI sits on top of an Australian surveillance law landscape that is genuinely fragmented. There is no national workplace surveillance statute. The rules change by state and territory, and the consequences of getting them wrong include both penalty exposure and the inadmissibility of monitoring evidence in subsequent dismissal proceedings.
Workplace Surveillance Laws by Jurisdiction
| Metric | Jurisdiction and Statute | Core Obligation |
|---|---|---|
| NSW: Workplace Surveillance Act 2005 | Covers camera, computer, and tracking surveillance of employees at work | Written notice at least 14 days before surveillance starts (or by start of employment); covert surveillance only with magistrate authorisation; specific signage and policy requirements |
| ACT: Workplace Privacy Act 2011 | Covers data, camera, optical, tracking, and listening surveillance | Notice and consultation requirements broadly similar to NSW, with a stronger consultation overlay and explicit prohibitions on certain monitoring locations |
| VIC: Surveillance Devices Act 1999 | Regulates listening, optical, tracking, and data surveillance devices generally | No dedicated workplace statute; private conversations cannot be recorded without consent; employer monitoring relies on policy, contract, and Privacy Act compliance |
| QLD, WA, SA, TAS, NT | No dedicated workplace surveillance Acts (as at 2026) | Common law privacy, state surveillance devices Acts on recording of conversations, Australian Privacy Principles, and contractual notice; monitoring permissible with informed notice and reasonable purpose |
| Commonwealth: Privacy Act 1988 | Applies across all jurisdictions to APP entities | APP 5 (notification of collection), APP 6 (use and disclosure), APP 11 (security); 2024 amendments narrowed circumstances in which automated decision-making can be relied on without disclosure |
Midsize employers running AI-based monitoring across multiple states cannot apply a single national policy and assume compliance. NSW and ACT impose specific written notice obligations with prescribed content and timing. Victoria is governed by a more general surveillance devices regime. Other states sit largely on common law and federal privacy law. A national rollout needs a notice and policy framework calibrated to the highest-bar state.
The 2024 Privacy Act amendments are also material here: where a decision is "substantially automated" and affects an individual's rights or interests, APP entities are increasingly expected to disclose that automation in their privacy policy and to provide a mechanism for human review.
Part 5: The Employee Records Exemption, What It Does and Does Not Cover
Most employers we speak to assume the Privacy Act employee records exemption (s7B(3)) gives them broad freedom to use workforce data for AI purposes. It does not.
The exemption applies only to an "employee record" of a "current or former employee" where the act or practice is "directly related to" the employment relationship. The High Court and the OAIC have read this narrowly. Importantly, the exemption does not cover:
- Prospective employees: candidate data, including resumes, video interviews, assessment outputs, and AI-derived scores, sit outside the exemption. The Privacy Act and the Australian Privacy Principles apply in full to recruitment AI.
- Contractors and labour-hire workers: not employees. Their data is outside the exemption.
- Third parties incidentally collected: the colleague mentioned in a 360 review, the customer whose voice appears in a monitored call, the family member referenced in a leave application.
- Biometric and genetic information in many practical contexts, because the exemption sits inside a wider statutory framework that treats sensitive information separately.
- Use of records for purposes not "directly related" to the employment relationship: feeding employee records into an AI training corpus or a vendor model is rarely "directly related" without explicit consent.
The 2024 Privacy and Other Legislation Amendment Act, and the broader privacy reform programme initiated by the Attorney-General's Department's 2022-2023 Privacy Act Review, have signalled progressive narrowing of the exemption. Forward-leaning midsize employers are already operating on the assumption that the exemption will not be a defence to AI-related complaints in three to five years' time. Our GDPR-vs-Privacy-Act analysis walks through the direction of travel in more detail.
Part 6: How a Workforce AI Decision Becomes Litigation
The pathway from an algorithmic output to a legal proceeding is shorter and better-defined than most People teams realise. The same flow applies whether the underlying decision was hiring, performance, or termination.
From AI Output to Legal Forum
The point of mapping this flow is not to frighten the People team. It is to identify, before deployment, what evidence the employer will need to produce at each stage and to make sure it exists. The most common failure we see is the absence of any documented human sign-off on the AI output that led to the adverse action. Without it, s340 reverse onus and s387 procedural fairness arguments become very hard to defend.
Part 7: The Control Stack, Pre-Deployment Through Incident Response
The control stack for workforce AI is not the same as the control stack for customer-facing AI. The audit trail has to satisfy an FWC member, an AHRC officer, or a civil litigant, not just an internal risk function.
Workforce AI Control Stack: 16 Weeks From Decision to Steady-State
Several of these controls have direct analogues in the AI agent governance framework we have used for customer-facing AI. The difference is the evidentiary standard. Workforce AI logs need to survive cross-examination, not just an internal audit.
Part 8: Where Is Your Workforce AI Exposure?
Use this as a triage tool. Run each AI feature you operate through it. If the answer is "no" at any branch where a "yes" is required, you have an open exposure to remediate.
Workforce AI Exposure Triage
The triage is deliberately blunt. In our experience working with businesses building managed AI capability, the controls catch about 80% of the exposure for about 20% of the effort, and the remaining 20% is what the legal team and the AHRC-aligned advisor should be focused on.
Part 9: The CHRO and General Counsel Pre-Deployment Checklist
Twelve questions every CHRO and General Counsel should be able to answer "yes" to before a workforce AI feature goes live, or be able to articulate why a documented exception is acceptable.
- Have we identified, in writing, which workforce decision class this AI feature influences (hire, roster, performance, monitoring, termination)?
- Have we mapped the specific FW Act, anti-discrimination, surveillance, and Privacy Act provisions triggered by this feature?
- Have we completed a combined Privacy Impact Assessment and equality impact assessment?
- Where the rollout is a major change under an applicable modern award or EBA, have we completed the consultation clause obligations and documented them?
- Does the feature use, or can it derive, any protected attribute (sex, race, age, disability, religion, sexual orientation, family responsibilities) directly or via proxy?
- Have we run a disparate impact audit against the relevant protected groups in the last 12 months and since the last model retrain?
- Is there a documented human reviewer between the AI output and the workforce decision, with a standard for the review and a record of the reviewer's reasoning?
- Does our decision log retain model version, inputs, output, reviewer identity, reviewer reasoning, and final decision for at least seven years?
- For monitoring features, have we issued the written notice required in each state where employees are located, calibrated to the highest-bar state's content and timing?
- Have we confirmed that any candidate, contractor, or third-party data in the pipeline is treated under full APP compliance, not the employee records exemption?
- Have we secured vendor warranties and indemnities specifically covering anti-discrimination and Fair Work claims, not just generic IP and confidentiality indemnities?
- Do employees and candidates have a documented, internally-published channel to request human review of an AI-influenced decision affecting them?
If you cannot answer "yes" to all twelve for any workforce AI feature you operate, that is the prioritisation list. None of the twelve are particularly expensive in isolation. The expensive failure is having none of them in place when the first complaint arrives.
This checklist sits alongside the broader compliance frameworks in our 50-point AI security checklist and the ACCC consumer guarantees article. Together they form the regulated-environment baseline. For employers in regulated sectors there is an additional layer: financial services overlays in our APRA and ASIC piece, and Commonwealth procurement obligations in our government contracts piece.
What This Looks Like in Practice
A 200 employee professional services firm rolling out AI recruitment screening, an AI productivity overlay on Microsoft 365, and an AI-assisted performance review summariser should expect, at a minimum, a PIA and equality impact assessment per feature, formal consultation under any covering modern award for the productivity overlay (which is most clearly a major change), workplace surveillance notices calibrated to NSW form for NSW staff with parallel ACT, VIC, and other-state coverage, quarterly disparate impact audits on the recruitment and performance tools, human reviewer protocols ensuring no candidate is rejected and no employee is PIP'd or rated "below expectations" purely on AI output, and a published internal pathway for review requests.
None of this is hypothetical effort. It is the effort the FWC, AHRC, or OAIC will expect to see documented if a complaint is filed. The cost of building it before deployment is materially lower than the cost of building it mid-inquiry.
Most midsize employers find they cannot run workforce AI well without dedicated capability inside the People and Legal functions. Whether the answer is internal hires, team augmentation, or managed AI services, the gap between "we deployed an AI tool" and "we can defend the AI tool in front of the Commission" is exactly the gap our staffing gap article covers. Our own product work on Carbonly and RootCauseAI reinforced the lesson: the audit trail has to be designed in at the start, not bolted on after the first incident.
Where to Start
The practical next step is not another policy document. It is to inventory every AI feature already touching workforce decisions in your business, run each through the Part 8 triage, and score the gaps against the Part 9 checklist. In most 50 to 500 person businesses that exercise takes about a week and surfaces between four and nine in-scope AI features, of which two or three carry material exposure.
If you would like a working session to map your workforce AI exposure and design the control stack against your specific award coverage, state footprint, and HRIS estate, book a consultation. We will run the inventory and triage with your People and Legal leads and leave you with a prioritised remediation plan. You can also read more about how we approach AI strategy for midsize Australian employers.
Related Reading:
- AI Agents for Australian Businesses: Why Not DIY Without Understanding - Series opener on the underlying capability gap
- Operating AI Agents: Production Reality for Australian Businesses - Operational risks that sit alongside the legal exposure
- The AI Agent Staffing Gap in Australian Midsize Business - Why workforce AI control stacks need dedicated owners
- AI Vendor Selection: Questions Every Australian Business Should Ask - Vendor warranty and indemnity framework underpinning Part 7
- AI Change Management: Driving Employee Adoption - The adoption-side companion to this legal-side piece
- AI Agent Governance: Data Access, Privacy, and Human Override - The broader governance framework workforce AI sits inside
- GDPR vs Privacy Act for Australian Business - Direction of travel on the employee records exemption
Sources:
Fair Work Act 2009 (Cth), particularly sections 65, 340, 361, 387, 389, 333M; Fair Work Legislation Amendment (Closing Loopholes) Act 2023 and (Closing Loopholes No.2) Act 2024; Sex Discrimination Act 1984 (Cth); Disability Discrimination Act 1992 (Cth); Racial Discrimination Act 1975 (Cth); Age Discrimination Act 2004 (Cth); Workplace Gender Equality Act 2012 (Cth); Privacy Act 1988 (Cth) and Australian Privacy Principles; NSW Workplace Surveillance Act 2005; ACT Workplace Privacy Act 2011; VIC Surveillance Devices Act 1999. Australian Human Rights Commission, Human Rights and Technology Final Report (2021) and subsequent Guidance Resources on AI-informed decision-making. Department of Industry, Science and Resources, Voluntary AI Safety Standard (2024). US EEOC v iTutorGroup Inc et al, Settlement (E.D.N.Y., 2023) as international precedent on AI hiring age discrimination. Reuters reporting on Amazon's discontinued AI recruitment tool (2018). Attorney-General's Department, Privacy Act Review Report (2023) and subsequent Privacy and Other Legislation Amendment Act 2024.