TL;DR: On August 4, 2026, the DOJ's Civil Rights Division announced a $3.2 million settlement with OpenAI and its subsidiary Statsig Inc. over PERM hiring violations dating to at least 2023. OpenAI allegedly buried PERM job postings off its public careers site, required paper applications for those roles, and ran late-night radio ads -- tactics the DOJ says were designed to discourage U.S. workers from applying so the company could favor temporary visa holders. The penalty: $1.2 million in civil fines plus a $2 million backpay fund for affected workers, plus three years of DOJ monitoring. What this means for HR compliance: the DOJ is now scrutinizing how AI companies -- not just AI tools -- hire.
The enforcement actions against AI companies have mostly been about what the AI does -- discriminatory hiring outputs, deceptive outputs, biased credit decisions. The August 4, 2026 DOJ settlement with OpenAI flips that frame. This one is about how an AI company hires its own people.
The Civil Rights Division announced a $3.2 million settlement with OpenAI OpCo LLC and its subsidiary Statsig Inc., a Bellevue, Washington-based software development company. The settlement resolves findings that both companies violated the Immigration and Nationality Act by discriminating against U.S. workers during the Permanent Labor Certification process -- the formal federal process companies use to sponsor foreign workers for green cards.
"It is illegal to discriminate against U.S. workers by preferring temporary visa holders," said Assistant Attorney General Harmeet K. Dhillon. The DOJ found violations dating to at least 2023.
What PERM is and why it matters
PERM stands for Program Electronic Review Management. Before an employer can sponsor a foreign worker for lawful permanent residence, federal regulations require a good-faith effort to recruit qualified U.S. workers first. The idea is straightforward: you can sponsor foreign workers for green cards, but only after demonstrating that you could not fill the position domestically.
The rules are specific about what "good-faith recruitment" looks like. Job postings must reach U.S. workers through standard professional channels. Electronic application submission must be accepted where it is the normal method. The design of the recruitment process must not systematically discourage U.S. applicants from learning about or applying to the positions being sponsored.
When employers game those requirements -- advertising only in places U.S. workers are unlikely to see, creating friction in the application process for sponsored roles, or otherwise structuring recruitment to minimize U.S. worker engagement -- they violate the Immigration and Nationality Act. That is what the DOJ says OpenAI did.
The three violations
The DOJ's investigation, launched in August 2025 and concluded with the settlement a year later, identified three specific recruitment practices across PERM-related positions at OpenAI and Statsig.
Postings kept off the public career site. For some PERM-related positions, OpenAI failed to advertise the openings on its public careers website. A U.S. worker who regularly checked OpenAI's listed positions would have had no way to discover those roles existed.
Paper applications required while electronic was the norm. OpenAI accepted electronic applications for most positions. For the PERM-related roles subject to this settlement, applicants were required to submit paper applications. Creating a friction differential between sponsored and non-sponsored roles -- one pathway smooth, one deliberately cumbersome -- is exactly the kind of design the PERM good-faith requirement prohibits.
Late-night radio advertising. In some instances, OpenAI advertised PERM openings through radio spots that ran late at night, when listenership is lowest. The DOJ's position is that this constitutes a facially inadequate recruitment effort, not a genuine attempt to attract U.S. applicants.
Taken together, the pattern suggests the PERM recruitment was designed to clear a procedural hurdle rather than to actually compete for U.S. workers. OpenAI denied wrongdoing as part of the settlement, but agreed to resolve the matter.
What OpenAI must do now
The three-year consent period that comes with this settlement is not ceremonial. OpenAI is required to:
- List all future PERM openings on its public career site
- Accept electronic applications for PERM-related positions
- Provide anti-discrimination training to relevant employees
- Update hiring policies to comply with INA recruitment requirements
- Submit to DOJ monitoring and periodic reporting for three years
The monitoring obligation is the part that matters most for vendor risk purposes. OpenAI is not just paying a fine and moving on. The company is now under active federal oversight of its hiring practices through at least 2029.
Why this settlement is different from the usual AI enforcement pattern
Most enforcement actions against AI companies over the past two years have focused on AI outputs: Workday's lawsuit over discriminatory hiring screening, EEOC guidance on AI-assisted hiring decisions, FTC actions over deceptive product claims. The underlying theory in those cases is that AI tools produce outcomes that harm people.
The OpenAI DOJ settlement is about the company's internal HR function, not its products. The AI technology that OpenAI builds was not the mechanism of discrimination here -- the PERM process was. But the target of enforcement is the same company whose models millions of organizations use as infrastructure.
This matters for how compliance teams frame vendor risk. An AI vendor does not only carry liability exposure from what its products do. It carries liability exposure from everything a regulated company carries: employment law, immigration law, environmental compliance, financial reporting. The $3.2 million DOJ settlement lands in the same vendor risk category as the FTC enforcement actions tracker, even though the underlying statute has nothing to do with AI.
Critics from the group Jobs Now argued the penalties are too small to deter widespread PERM abuse across industries. That critique is almost certainly correct -- $1.2 million in civil penalties is a rounding error for a company at OpenAI's scale. The deterrence mechanism here is not the fine. It is three years of DOJ oversight with ongoing reporting obligations, plus the reputational signal that DOJ is now actively investigating AI company hiring practices.
The compliance angle no one has written about yet
Here is the question this settlement raises that most coverage has not addressed: if your organization uses AI vendors as a component of your own hiring workflow, what is your exposure when your vendor settles a DOJ discrimination case?
The direct answer is: probably nothing, because the OpenAI settlement is about OpenAI's own internal PERM practices, not its products. A company that uses ChatGPT or Claude in its HR workflow is not inheriting OpenAI's PERM liability.
The indirect answer is more complicated. Three practical considerations for compliance teams.
DOJ-monitored vendor status belongs on your vendor risk register. Most enterprise vendor risk frameworks track regulatory sanctions, consent orders, and active government monitoring as risk indicators. OpenAI now has all three. Whether that changes your risk tier for OpenAI depends on your framework, but the field needs to exist before you can assess it. Add "active government consent agreement or monitoring obligation" to your AI vendor assessment questionnaire if it is not already there.
The question to ask: "Is your company currently subject to any consent decree, settlement agreement, or active monitoring obligation with any federal or state regulatory agency?" The answer for OpenAI, as of August 2026, is yes.
Vendor legal distractions have operational consequences. Three years of DOJ monitoring means OpenAI's legal and HR teams are occupied with compliance obligations unrelated to product development. That is a minor operational drag at a company of OpenAI's size, but it is worth noting for organizations with deeply integrated OpenAI dependencies. The Anthropic export ban is the worked example of what AI vendor legal distraction looks like when it becomes severe: 17 days of model unavailability because the company's leadership was consumed by government negotiation.
Immigration scrutiny of AI companies is increasing. The DOJ investigation that produced this settlement was launched in August 2025, less than a year ago. DOJ announced similar settlements with other tech companies in the same period. This is not a one-off; it reflects sustained DOJ attention to tech-sector PERM practices under the current administration. AI companies that have grown rapidly through visa-worker hiring are disproportionately exposed.
For HR teams that recruit alongside AI companies -- for joint programs, secondments, or vendor embedded arrangements -- understanding your vendor's immigration compliance posture is now a reasonable due diligence question.
A five-item vendor PERM and regulatory compliance checklist
Add these questions to your AI vendor assessment process:
-
Active government oversight: Is your company currently subject to any consent decree, settlement agreement, or monitoring obligation with any federal or state regulatory agency? If yes, describe the agency, the subject matter, and the duration.
-
PERM and immigration compliance: Has your company sponsored foreign workers for permanent residence (green card) through the PERM process? If yes, have you received any DOJ Civil Rights Division inquiry, demand, or complaint related to PERM recruitment practices?
-
Employment discrimination exposure: In the past three years, has your company settled, been subject to judgment in, or received a formal EEOC complaint regarding employment discrimination? (This is separate from AI output discrimination claims.)
-
Monitoring obligations and reporting: If your company is under any active government monitoring or consent agreement, what are the reporting obligations, and how do those obligations affect your product roadmap or staffing?
-
Indemnification scope: Does your standard enterprise contract's indemnification clause cover regulatory enforcement actions against the vendor related to the vendor's own employment or immigration practices? (Almost none do -- but knowing the answer changes your risk calculus.)
Context for what comes next
The AI enforcement landscape through August 2026 has been dominated by product-liability actions: what models produce, what vendors disclose about their training data, what AI tools do to the humans who interact with them. The OpenAI PERM settlement adds an employment-law dimension that most compliance frameworks have not anticipated.
AI companies are large, fast-growing employers with unusual staffing profiles -- heavy in temporary visa holders, internationally distributed, and expanding rapidly into regulated markets. The DOJ Civil Rights Division has flagged that it is actively auditing that profile. More settlements are likely.
For enterprise compliance teams, the immediate action is simple: audit your vendor risk framework for government monitoring status as a tracked field, and add the five questions above to your next AI vendor renewal or procurement cycle. The AI vendor due diligence checklist covers the broader framework; the PERM and regulatory oversight questions above slot into the "vendor legal exposure" section.
The larger point is that AI vendor risk is not only AI risk. A company whose models power your customer service, your HR workflows, and your compliance monitoring is also a company that carries the full regulatory exposure of any large enterprise. The DOJ settlement with OpenAI is a reminder to check that category.
Related Reading
- Workday AI Lawsuit: HR Screening Checklist for Small Teams
- EEOC AI Hiring Guidance 2026: Employer Checklist
- FCRA AI Hiring Disclosure Requirements 2026
- FTC AI Enforcement Actions 2026: Real Cases, Real Risks
- AI Vendor Due Diligence: 30-Minute Checklist for Small Teams
Sources: DOJ Office of Public Affairs: Civil Rights Division Secures Settlement with OpenAI (Aug 4, 2026), Axios: OpenAI reaches $3.2 million DOJ settlement over U.S. worker claims (Aug 4, 2026), Newsweek: OpenAI Settles DOJ Lawsuit for $3.2M (Aug 5, 2026), Fox Business: OpenAI to pay $3.2 million to settle DOJ allegations (Aug 4, 2026)
