id: PIR-2026-0002title: iTutorGroup pays $365K after recruitment software auto-rejected female applicants 55+ and male applicants 60+date_occurred: 2020 (automated rejections)date_detected: 2020 (a rejected applicant resubmitted an identical application with a more recent birth date and was offered an interview)date_disclosed: 2022-05-05 (EEOC suit filed, E.D.N.Y., 1:22-cv-02565); settlement filed 2023-08-09status: corroborated (EEOC filings, court record, five-year consent decree)agent_description: iTutorGroup's tutor-recruitment application software, which screened and rejected US-based applicants for online English-tutoring roles with no human review of individual decisions.operator_type: enterpriseautonomy_level: autonomous-within-policy (fully automated rejection authority; the policy itself was the defect)model_stack: unknown (rule-configured screening software; internals never disclosed)harness: proprietary applicant-tracking/screening systemfailure_locus: operator-config (the discriminatory rule was deliberately encoded by the operator)authority_scope: data access (applicant PII incl. birth dates), decision authority over hiring outcomes (no funds, no code execution)funds_at_risk_usd: unknown (lost wages to excluded applicants never aggregated)blast_radius: customers/third parties (200+ external job applicants)root_cause: operator-error - primary: deliberate discriminatory configuration. Contributing: policy-violation (automated execution of an ADEA-illegal rule at scale)mechanism: The software was configured to automatically reject female applicants aged 55+ and male applicants aged 60+. In 2020 it screened out more than 200 qualified US applicants on age alone, at machine speed and with no human review. Exposed when one rejected applicant reapplied with an identical application bearing a more recent birth date and received an interview - a manual A/B test of the system.adversary_present: noexploitation_status: in-wild-malfunction (real applicants harmed in production; no attacker - reclassified from in-wild-exploited, which implies an adversary; the system faithfully executed a misconfigured policy)severity: lossdirect_loss_usd: 365,000 (paid to the rejected applicants under the consent decree)indirect_loss_usd: unknown (compliance program, training, five-year decree obligations)downtime: nonedata_exposure: nonedetected_by: third-party (victim's own resubmission experiment, then EEOC)time_to_detect: months (rejections in 2020; suit May 2022)time_to_recover: settlement filed 2023-08-09, ~3 years after the rejectionsremediation: $365K to ~200 applicants; affected applicants invited to reapply; anti-discrimination policy, training, and injunctions against age/sex screening and birth-date collectionstructural_fix: five-year consent decree with EEOC monitoringcontrols_that_worked: none internal - detection required a victim manually probing the system from outsideliability_holder: iTutorGroup, Inc. (operator; consent decree, no admission)precedent_set: first US EEOC settlement over discrimination by an automated/AI hiring toolsealed_material: notelemetry_grade: operator-logs (application-system records, surfaced through litigation into public court record)sources:confidence: high (settlement figures and mechanism from EEOC and court record). Weakest link: none material.All dates and the $365K figure verified against EEOC releases and the court record; suit-filed date sharpened from "May 2022" to 2022-05-05. Boundary case as flagged at intake: the rule was deliberately encoded, so root_cause primary moved from policy-violation to operator-error (deliberate configuration, not emergent agent behavior); the automated execution at scale is the agentic dimension. Recorded under the v0.1 legal block.