Most AI governance programmes start with the models an organisation builds. The 2026 case law is arriving somewhere else entirely: on the models organisations buy, licence, or embed — where the vendor made every design decision and the buyer holds the exposure.
Hiring: the claim is secrecy, not bias
In Kistler et al. v. Eightfold AI Inc., filed 20 January 2026 in Contra Costa County Superior Court, the plaintiffs allege the platform scraped personal data on more than one billion workers, generated ‘Match Scores’ on a zero-to-five scale, and filtered low-ranked candidates out before any human review — without the disclosures the Fair Credit Reporting Act requires when a consumer report is compiled for an employment decision.
The legal theory is the part worth internalising. The suit does not argue the algorithm was biased. It argues the algorithm existed in secret. Every fairness audit in the world does not address that claim — only disclosure and process do. And FCRA obligations attach to the employer using the score, not only to the vendor producing it.
‘The vendor runs the model’ has never been a defence. It is a description of where your evidence lives.
Pricing: an algorithm as a regulated device
A separate class action alleges UDR Inc. violated San Diego law through the use of algorithmic devices to set rental prices and occupancy levels. Note the framing: the algorithm is treated as a device whose use is regulated, independent of whether its outputs were accurate or its intent was benign. Sector-specific rules are beginning to name algorithmic decision-making directly rather than reaching it through general consumer-protection law.
Wearables: the sub-processor you never mapped
The Meta smart-glasses case is the most instructive, because the failure was entirely downstream. A Swedish investigation by SvD and GP found footage captured by Ray-Ban Meta glasses reaching human reviewers at a Nairobi-based subcontractor — including deeply private moments users did not know were being watched. A class action followed. Kenya’s Office of the Data Protection Commissioner opened formal investigations. Meta halted the AI training in question and ended the contract, after which the subcontractor, Sama, laid off more than 1,000 workers.
Every element of that chain — capture device, training pipeline, annotation vendor, reviewer jurisdiction — is a data-flow question that a standard vendor questionnaire does not ask. ‘Is our data used for training?’ and ‘who sees it, in which country, under what employment terms?’ are different questions, and only the second one produced this incident.
What this means for procurement
- Inventory purchased AI as your AI. If a vendor model scores, ranks, prices, or screens on your behalf, it belongs in the same register as anything you built.
- Negotiate audit rights, not assurances. A SOC 2 report says nothing about how a match score was computed or what data trained it.
- Map the sub-processors. Annotation vendors, reviewer jurisdictions, and training pipelines are where the Meta case actually happened.
- Document the human review that actually happens. Not the review the contract describes — the one a candidate or customer would see if it were reconstructed in discovery.