Business Strategy

Fair Work and AI: Hiring, Rosters and Surveillance

Fair Work and AI: Hiring, Rosters and Surveillance

AI workforce governance and compliance map for Australian midsize employers

Workforce AI Is the Highest-Discrimination-Risk Class of AI a Midsize Business Runs

AI now reads resumes, scores candidates, predicts attrition, allocates shifts, monitors keystrokes, summarises meeting transcripts, and feeds the data points that performance reviews and redundancy decisions are built on. In a 50 to 500 person business those features arrive bundled inside platforms the People team already uses: applicant tracking systems, HRIS modules, workforce management suites, the AI copilot inside Microsoft 365 or Google Workspace.

Each touches a discrete provision of Australian workplace law. Most midsize employers have not mapped which provision is triggered by which feature, who signs off, and what evidence will satisfy a Fair Work Commission member or Australian Human Rights Commission inquiry if something goes wrong.

In our why-not-DIY analysis and production reality piece we covered why workforce AI carries operational risk that consumer chatbots do not, and in the staffing gap article we covered who owns these decisions. This piece is the legal-exposure layer underneath. The thesis is simple: of all the AI a midsize business runs, the workforce stack carries the highest aggregate discrimination, procedural fairness, and surveillance risk, and the controls required to defend it look nothing like the controls for customer-facing AI. If you have read the AI change management piece, this is its legal twin. That article was about getting employees to use AI. This one is about using AI on employees.


Part 1: Five HR and Payroll Decisions Where AI Is Actively in the Loop

The first step is mapping where AI is already making, or materially influencing, decisions in your workforce systems. In a 50 to 500 person business, the five high-risk decision classes are almost always these, and each one triggers a different provision of Australian law.

Five Workforce AI Decisions and the Law They Touch

Metric
AI Use Case
Australian Provision Triggered
Hiring and candidate screeningResume parsing, candidate scoring, video-interview sentiment analysis, knock-out questionsSex Discrimination Act 1984 (Cth), Disability Discrimination Act 1992 (Cth), Racial Discrimination Act 1975 (Cth), Age Discrimination Act 2004 (Cth), state Equal Opportunity / Anti-Discrimination Acts
Rostering and shift allocationAlgorithmic shift offers, predictive demand staffing, automated swap approvalsModern award consultation clauses, FW Act 2009 s65 (flexible work requests), Closing Loopholes No.2 right to disconnect (s333M)
Performance, promotion, and pay reviewProductivity scoring, AI-generated review summaries, attrition risk flags fed into talent calibrationFW Act s340 (general protections / adverse action), Workplace Gender Equality Act 2012 reporting obligations, AHRC guidance on algorithmic bias
Monitoring and productivity scoringKeystroke and screen monitoring, location tracking, email and chat sentiment analysisNSW Workplace Surveillance Act 2005, ACT Workplace Privacy Act 2011, VIC Surveillance Devices Act 1999, Privacy Act 1988 APP 5 and APP 11
Termination and redundancy selectionAI-assisted ranking for redundancy pools, performance flags as PIP trigger, automated misconduct detectionFW Act s387 (procedural fairness in unfair dismissal), FW Act s389 (genuine redundancy), s340 adverse action, anti-discrimination acts

Almost every midsize employer we speak to runs AI in at least three of these five rows. Few have mapped which provision is triggered, fewer still have the documented sign-off and audit trail an FWC member would expect to see.


Part 2: The Discrimination-by-Algorithm Trap

The defining feature of workforce AI risk is that it produces discrimination at scale without anyone deciding to discriminate. The model learns from historical hiring, promotion, and termination data. That data reflects past human choices. The model reproduces them, often with new proxy variables the business never thought to police.

The international precedents are now well-documented. In iTutorGroup (2023) the US Equal Employment Opportunity Commission settled for USD 365,000 after the company's recruitment software was configured to reject female applicants aged 55 and over and male applicants aged 60 and over. It was the EEOC's first AI-hiring discrimination settlement. Amazon's internal resume-screening tool, abandoned in 2018, famously penalised resumes that included the word "women's" because the model had learned that historic Amazon hires were overwhelmingly male.

Australian law does not treat the "but the model just learned from the data" defence kindly. The indirect discrimination tests in the Sex Discrimination Act 1984 (s5(2)), Disability Discrimination Act 1992 (s6), Racial Discrimination Act 1975, and Age Discrimination Act 2004 do not require intent. They require a condition, requirement, or practice that has a disparate impact on a protected group and that is not reasonable in the circumstances. An algorithm is a condition, requirement, or practice. "We did not know the model was biased" is not a defence. It is, at best, mitigation.

The Australian Human Rights Commission has published technical guidance on AI in decision-making, most notably its 2021 Human Rights and Technology Final Report and follow-up Guidance Resources on AI-informed decision-making. The AHRC position is consistent: where AI is used to make or materially influence decisions about a person, the entity using the AI carries the same human rights and anti-discrimination obligations it would carry if a human had made the decision unaided.

The practical implication for midsize employers is that the vendor's claim of "bias-free AI" or "fairness-audited model" does not transfer the legal risk. The risk sits with the employer. Vendor warranties on this point are usually narrow, and we have unpacked the questions to ask in our AI vendor selection article.


Part 3: The Fair Work Act Layer

Even where no protected attribute is involved, the Fair Work Act 2009 imposes a separate set of obligations whenever AI feeds into a workforce decision. There are four provisions a midsize People and Legal team should know cold.

Consultation Obligations Under Modern Awards

Almost every modern award contains a consultation clause, generally clause 8 in the standard award template, requiring the employer to consult with affected employees and their representatives before implementing a "major change" to production, programme, organisation, structure, or technology likely to have significant effects. Deploying AI that materially changes how shifts are allocated, how performance is measured, or how termination decisions are reached almost always meets that threshold.

The Fair Work Commission has heard a steady stream of disputes since 2020 about technology rollouts implemented without proper consultation. The remedy is not usually to overturn the technology, it is an order to consult, and in some cases an order that decisions made in the unconsulted window be reconsidered. The reputational and operational cost of having to undo three months of AI-influenced decisions is the part that bites.

s387: Procedural Fairness in Termination

FW Act s387 lists the factors the Commission must take into account in unfair dismissal. They include whether the person was notified of the reason for dismissal, whether they had an opportunity to respond, and whether the dismissal was harsh, unjust, or unreasonable. Where AI flagged the performance concern, scored the productivity, or summarised the misconduct evidence, the employer needs to be able to explain what the AI did, why its output was relied on, and what human verification occurred before the dismissal decision.

"The system flagged them as bottom decile" is not a sufficient answer. The employee, and the Commission, are entitled to know what the model measured, what data it used, and whether the employee had a meaningful opportunity to challenge the AI output before the dismissal was finalised.

s340: Adverse Action and General Protections

s340 prohibits an employer from taking adverse action against an employee because the employee has a workplace right. The reverse onus in s361 means that once the employee alleges the reason, the employer must prove the reason was something else. Where AI scored, ranked, or flagged the employee, the question of "what was the actual reason for the action" becomes harder to evidence, not easier, because the model's reasoning may be opaque.

Right to Disconnect: s333M

The Closing Loopholes No.2 Act 2024 inserted s333M into the Fair Work Act, giving most employees a right to refuse to monitor, read, or respond to contact from the employer outside working hours, unless the refusal is unreasonable. AI-monitored after-hours work, "always on" status tracking, and chat-sentiment analysis that flags response delays now operate in tension with this right. Employers need to be careful that their AI monitoring does not, in practice, defeat the protection the statute creates.


Part 4: Workplace Surveillance, the State-by-State Patchwork

Workforce monitoring AI sits on top of an Australian surveillance law landscape that is genuinely fragmented. There is no national workplace surveillance statute. The rules change by state and territory, and the consequences of getting them wrong include both penalty exposure and the inadmissibility of monitoring evidence in subsequent dismissal proceedings.

Workplace Surveillance Laws by Jurisdiction

Metric
Jurisdiction and Statute
Core Obligation
NSW: Workplace Surveillance Act 2005Covers camera, computer, and tracking surveillance of employees at workWritten notice at least 14 days before surveillance starts (or by start of employment); covert surveillance only with magistrate authorisation; specific signage and policy requirements
ACT: Workplace Privacy Act 2011Covers data, camera, optical, tracking, and listening surveillanceNotice and consultation requirements broadly similar to NSW, with a stronger consultation overlay and explicit prohibitions on certain monitoring locations
VIC: Surveillance Devices Act 1999Regulates listening, optical, tracking, and data surveillance devices generallyNo dedicated workplace statute; private conversations cannot be recorded without consent; employer monitoring relies on policy, contract, and Privacy Act compliance
QLD, WA, SA, TAS, NTNo dedicated workplace surveillance Acts (as at 2026)Common law privacy, state surveillance devices Acts on recording of conversations, Australian Privacy Principles, and contractual notice; monitoring permissible with informed notice and reasonable purpose
Commonwealth: Privacy Act 1988Applies across all jurisdictions to APP entitiesAPP 5 (notification of collection), APP 6 (use and disclosure), APP 11 (security); 2024 amendments narrowed circumstances in which automated decision-making can be relied on without disclosure

Midsize employers running AI-based monitoring across multiple states cannot apply a single national policy and assume compliance. NSW and ACT impose specific written notice obligations with prescribed content and timing. Victoria is governed by a more general surveillance devices regime. Other states sit largely on common law and federal privacy law. A national rollout needs a notice and policy framework calibrated to the highest-bar state.

The 2024 Privacy Act amendments are also material here: where a decision is "substantially automated" and affects an individual's rights or interests, APP entities are increasingly expected to disclose that automation in their privacy policy and to provide a mechanism for human review.


Part 5: The Employee Records Exemption, What It Does and Does Not Cover

Most employers we speak to assume the Privacy Act employee records exemption (s7B(3)) gives them broad freedom to use workforce data for AI purposes. It does not.

The exemption applies only to an "employee record" of a "current or former employee" where the act or practice is "directly related to" the employment relationship. The High Court and the OAIC have read this narrowly. Importantly, the exemption does not cover:

  • Prospective employees: candidate data, including resumes, video interviews, assessment outputs, and AI-derived scores, sit outside the exemption. The Privacy Act and the Australian Privacy Principles apply in full to recruitment AI.
  • Contractors and labour-hire workers: not employees. Their data is outside the exemption.
  • Third parties incidentally collected: the colleague mentioned in a 360 review, the customer whose voice appears in a monitored call, the family member referenced in a leave application.
  • Biometric and genetic information in many practical contexts, because the exemption sits inside a wider statutory framework that treats sensitive information separately.
  • Use of records for purposes not "directly related" to the employment relationship: feeding employee records into an AI training corpus or a vendor model is rarely "directly related" without explicit consent.

The 2024 Privacy and Other Legislation Amendment Act, and the broader privacy reform programme initiated by the Attorney-General's Department's 2022-2023 Privacy Act Review, have signalled progressive narrowing of the exemption. Forward-leaning midsize employers are already operating on the assumption that the exemption will not be a defence to AI-related complaints in three to five years' time. Our GDPR-vs-Privacy-Act analysis walks through the direction of travel in more detail.


Part 6: How a Workforce AI Decision Becomes Litigation

The pathway from an algorithmic output to a legal proceeding is shorter and better-defined than most People teams realise. The same flow applies whether the underlying decision was hiring, performance, or termination.

From AI Output to Legal Forum

AI Output
Model scores, ranks, or flags a worker or candidate
Adverse Action
Non-hire, no promotion, PIP, pay decision, redundancy, dismissal
Complaint
Employee or candidate raises internal grievance or external complaint
Forum Triage
Fair Work Commission, Australian Human Rights Commission, state tribunal, OAIC, or civil court
Evidence Phase
Employer must produce model documentation, training data lineage, decision logs, consultation records
Remedy
Reinstatement, compensation, civil penalty, injunction, public undertaking, or referral for prosecution

The point of mapping this flow is not to frighten the People team. It is to identify, before deployment, what evidence the employer will need to produce at each stage and to make sure it exists. The most common failure we see is the absence of any documented human sign-off on the AI output that led to the adverse action. Without it, s340 reverse onus and s387 procedural fairness arguments become very hard to defend.


Part 7: The Control Stack, Pre-Deployment Through Incident Response

The control stack for workforce AI is not the same as the control stack for customer-facing AI. The audit trail has to satisfy an FWC member, an AHRC officer, or a civil litigant, not just an internal risk function.

Workforce AI Control Stack: 16 Weeks From Decision to Steady-State

1
Weeks 1-2
Privacy and Equality Impact Assessment
Combined PIA and AHRC-aligned equality impact assessment. Identify protected attributes, proxy variables, and population segments most exposed to disparate impact.
2
Weeks 3-4
Modern Award and EBA Consultation
Where deployment is a 'major change' under clause 8 of applicable modern awards or EBAs, run the formal consultation process. Document representative engagement and feedback responses.
3
Weeks 5-6
Vendor Due Diligence
Use the vendor question set from our vendor selection article. Get warranties on training data lineage, bias testing, and indemnity for discrimination claims, not just generic IP indemnity.
4
Weeks 7-9
Human-in-the-Loop Design
Document where and how a human reviewer sits between the model output and any material workforce decision. Capture the standard the reviewer is to apply.
5
Weeks 10-12
Logging and Retention
Build decision logs that retain model version, inputs, output, reviewer identity, reviewer reasoning, and final decision for the FW Act 7-year record retention horizon at minimum.
6
Weeks 13-14
Disparate Impact Audit
Run a statistical audit comparing model outputs across protected attribute groups. Document methodology and findings. Schedule the audit to recur quarterly or after any model retraining.
7
Weeks 15-16
Complaints Channel and Review Pathway
Establish a documented internal channel for employees and candidates to request human review of an AI-influenced decision. Train the People team and the legal first-responder on intake.

Several of these controls have direct analogues in the AI agent governance framework we have used for customer-facing AI. The difference is the evidentiary standard. Workforce AI logs need to survive cross-examination, not just an internal audit.


Part 8: Where Is Your Workforce AI Exposure?

Use this as a triage tool. Run each AI feature you operate through it. If the answer is "no" at any branch where a "yes" is required, you have an open exposure to remediate.

Workforce AI Exposure Triage

Does the AI feature make or materially influence a decision affecting hiring, pay, promotion, monitoring, or termination?
No, the AI is purely informational and a human makes the decision independently
→ Lower risk: confirm informational status in writing, monitor for scope creep, light-touch logging is sufficient
Yes, and the AI uses protected attributes directly or proxies (postcode, name, education origin, gap years, voice tone)
→ HIGH RISK: full PIA + equality impact assessment, disparate impact audit before go-live, legal sign-off, human-in-the-loop mandatory
Yes, and the rollout has not been consulted under the applicable modern award or EBA clause 8
→ Consultation gap: pause deployment, run formal consultation, document outcomes before proceeding
Yes, and there is no documented human sign-off between model output and the workforce decision
→ Procedural fairness gap: insert human reviewer with documented standard, retain reviewer reasoning in the decision log
Yes, and no disparate impact audit has been run in the last 12 months or since the last model retrain
→ Audit gap: commission a statistical audit, document methodology and remediation, set quarterly recurrence
Yes, and the data flow includes candidate, contractor, or third-party data
→ Employee records exemption does NOT cover this: confirm full APP compliance, candidate notice, and retention policy

The triage is deliberately blunt. In our experience working with businesses building managed AI capability, the controls catch about 80% of the exposure for about 20% of the effort, and the remaining 20% is what the legal team and the AHRC-aligned advisor should be focused on.


Part 9: The CHRO and General Counsel Pre-Deployment Checklist

Twelve questions every CHRO and General Counsel should be able to answer "yes" to before a workforce AI feature goes live, or be able to articulate why a documented exception is acceptable.

  1. Have we identified, in writing, which workforce decision class this AI feature influences (hire, roster, performance, monitoring, termination)?
  2. Have we mapped the specific FW Act, anti-discrimination, surveillance, and Privacy Act provisions triggered by this feature?
  3. Have we completed a combined Privacy Impact Assessment and equality impact assessment?
  4. Where the rollout is a major change under an applicable modern award or EBA, have we completed the consultation clause obligations and documented them?
  5. Does the feature use, or can it derive, any protected attribute (sex, race, age, disability, religion, sexual orientation, family responsibilities) directly or via proxy?
  6. Have we run a disparate impact audit against the relevant protected groups in the last 12 months and since the last model retrain?
  7. Is there a documented human reviewer between the AI output and the workforce decision, with a standard for the review and a record of the reviewer's reasoning?
  8. Does our decision log retain model version, inputs, output, reviewer identity, reviewer reasoning, and final decision for at least seven years?
  9. For monitoring features, have we issued the written notice required in each state where employees are located, calibrated to the highest-bar state's content and timing?
  10. Have we confirmed that any candidate, contractor, or third-party data in the pipeline is treated under full APP compliance, not the employee records exemption?
  11. Have we secured vendor warranties and indemnities specifically covering anti-discrimination and Fair Work claims, not just generic IP and confidentiality indemnities?
  12. Do employees and candidates have a documented, internally-published channel to request human review of an AI-influenced decision affecting them?

If you cannot answer "yes" to all twelve for any workforce AI feature you operate, that is the prioritisation list. None of the twelve are particularly expensive in isolation. The expensive failure is having none of them in place when the first complaint arrives.

This checklist sits alongside the broader compliance frameworks in our 50-point AI security checklist and the ACCC consumer guarantees article. Together they form the regulated-environment baseline. For employers in regulated sectors there is an additional layer: financial services overlays in our APRA and ASIC piece, and Commonwealth procurement obligations in our government contracts piece.


What This Looks Like in Practice

A 200 employee professional services firm rolling out AI recruitment screening, an AI productivity overlay on Microsoft 365, and an AI-assisted performance review summariser should expect, at a minimum, a PIA and equality impact assessment per feature, formal consultation under any covering modern award for the productivity overlay (which is most clearly a major change), workplace surveillance notices calibrated to NSW form for NSW staff with parallel ACT, VIC, and other-state coverage, quarterly disparate impact audits on the recruitment and performance tools, human reviewer protocols ensuring no candidate is rejected and no employee is PIP'd or rated "below expectations" purely on AI output, and a published internal pathway for review requests.

None of this is hypothetical effort. It is the effort the FWC, AHRC, or OAIC will expect to see documented if a complaint is filed. The cost of building it before deployment is materially lower than the cost of building it mid-inquiry.

Most midsize employers find they cannot run workforce AI well without dedicated capability inside the People and Legal functions. Whether the answer is internal hires, team augmentation, or managed AI services, the gap between "we deployed an AI tool" and "we can defend the AI tool in front of the Commission" is exactly the gap our staffing gap article covers. Our own product work on Carbonly and RootCauseAI reinforced the lesson: the audit trail has to be designed in at the start, not bolted on after the first incident.


Where to Start

The practical next step is not another policy document. It is to inventory every AI feature already touching workforce decisions in your business, run each through the Part 8 triage, and score the gaps against the Part 9 checklist. In most 50 to 500 person businesses that exercise takes about a week and surfaces between four and nine in-scope AI features, of which two or three carry material exposure.

If you would like a working session to map your workforce AI exposure and design the control stack against your specific award coverage, state footprint, and HRIS estate, book a consultation. We will run the inventory and triage with your People and Legal leads and leave you with a prioritised remediation plan. You can also read more about how we approach AI strategy for midsize Australian employers.


Related Reading:


Sources:

Fair Work Act 2009 (Cth), particularly sections 65, 340, 361, 387, 389, 333M; Fair Work Legislation Amendment (Closing Loopholes) Act 2023 and (Closing Loopholes No.2) Act 2024; Sex Discrimination Act 1984 (Cth); Disability Discrimination Act 1992 (Cth); Racial Discrimination Act 1975 (Cth); Age Discrimination Act 2004 (Cth); Workplace Gender Equality Act 2012 (Cth); Privacy Act 1988 (Cth) and Australian Privacy Principles; NSW Workplace Surveillance Act 2005; ACT Workplace Privacy Act 2011; VIC Surveillance Devices Act 1999. Australian Human Rights Commission, Human Rights and Technology Final Report (2021) and subsequent Guidance Resources on AI-informed decision-making. Department of Industry, Science and Resources, Voluntary AI Safety Standard (2024). US EEOC v iTutorGroup Inc et al, Settlement (E.D.N.Y., 2023) as international precedent on AI hiring age discrimination. Reuters reporting on Amazon's discontinued AI recruitment tool (2018). Attorney-General's Department, Privacy Act Review Report (2023) and subsequent Privacy and Other Legislation Amendment Act 2024.