Workday AI Features Vendor Transparency and Security Disclosure Audit

Workday publishes AI governance docs, but independent verification remains incomplete.

Editor at Large · · 8 min read
Cover illustration for “Workday AI Features Vendor Transparency and Security Disclosure Audit”
Product Security · September 24, 2026 · 8 min read · 1,888 words

Workday calls itself "the enterprise AI platform for managing people, money, and agents." Over 11,500 organizations use it, including more than 65% of the Fortune 500. That's a lot of payroll runs, benefits elections, and ledger entries now sitting next to AI agents that can read, write, and act on that data, which puts this in a different risk bucket than a customer-service chatbot. When AI touches HR and finance records, the questions an enterprise buyer needs answered aren't about accuracy alone. They're about who audited the claims, what the audits actually covered, and what's still resting on Workday's word.

This piece works through Workday's AI security and transparency documentation piece by piece, covering the agent governance system, the certifications, the fact sheets, the government transparency reports, and the EU AI Act posture. The goal is to show what the paper trail actually proves, and where a buyer still has to ask harder questions. It's to show what the paper trail actually proves, and where a buyer still has to ask harder questions.

What Workday's Agent System of Record governs and assumes

Workday's Agent System of Record (ASOR) is now generally available. Think of it as mission control for AI agents: one place to discover, register, configure, monitor, and manage every agent running in the environment, whether Workday built it or a third party did.

The pitch is that agents don't get a separate rulebook. They inherit the same security model, delegation rules, business process controls, and audit trail that already govern human users inside Workday. Agents even show up in the org chart alongside employees, each with defined skills and access, rather than floating around as some external plug-in bolted onto the side of the system.

Workday's design philosophy holds that guardrails belong close to the inference engine itself, not wrapped around the model as an afterthought, and that's a real architectural choice. It's a defensible position. But it's also, at this point, an architectural claim rather than an independently verified one. Nothing in the public record shows a third party testing whether agents actually inherit those controls consistently across every module, every integration, every edge case where a business process gets customized. So does the org-chart framing change outcomes, or just optics? Does the org-chart framing change outcomes, or just optics, before treating ASOR as a finished answer rather than a promising design?

Agent Passport: how Workday is trying to solve the self-attestation problem

Announced June 2, 2026 at Workday DevCon in Las Vegas, Agent Passport tackles a specific problem: how do you know an AI agent is safe before it goes live, and how do you know it stays safe after?

The design tests and verifies every agent, Workday-built or third-party, before it enters production. Then it keeps monitoring afterward. What does it test for? Prompt injection, jailbreak attempts, goal hijacking, system prompt extraction, leaks of employee data, and unsafe outputs. That's a fairly complete list of the failure modes security researchers worry about most with agentic systems right now.

Each attestation ties back to named, public standards. OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS. None of these are Workday inventions. That means, in principle, an agent's Passport results could be compared against results from agents built by other vendors, tested against the same yardstick. Whether Workday publishes those results in a way that supports real comparison is a separate question to ask directly in any vendor review.

The certifications Workday holds, what they cover, and where the audit data shows the field struggles

As of June 2025, Workday holds ISO 42001 accreditation, the AI-specific governance standard covering bias, transparency, explainability, and human oversight. It also holds an independent attestation of alignment with the NIST AI Risk Management Framework.

Neither of these came from Workday grading its own homework. Schellman independently verified the ISO 42001 accreditation. Coalfire independently attested the NIST AI RMF alignment. Coalfire's stated finding: "Workday demonstrated a strong AI governance program along with the internal expertise to manage the risks induced by using AI within their SaaS products." That's a specific claim from a named assessor, which counts for more than marketing copy, even if it's still commissioned work.

These certifications add something on top of something like ISO 27001, which most enterprise software vendors already hold. ISO 27001 covers information security controls: encryption, access management, incident response. It says nothing about whether an AI model treats certain demographic groups unfairly, or whether a human reviews an automated hiring decision before it becomes final. ISO 42001 and NIST AI RMF alignment are aimed squarely at those AI-specific risks.

But certification isn't a permanent state. ISO 42001 certifications are not permanent and require ongoing surveillance audits to remain valid. That's standard practice across the industry, not a knock on Workday specifically. Workday rolled out seven new AI agents between late 2025 and early 2026. An annual audit cycle means there's a real window where new capability ships faster than the certification cycle can re-examine it. The certification is a snapshot, not a live feed. The certification is a snapshot.

What Workday's AI Fact Sheets and transparency notices disclose, and the gap a third-party index found

Workday publishes AI Fact Sheets for its features. They document model inputs, design limits, and intended use cases, and they exist so customers can configure features correctly and explain them accurately to employees affected by them.

The responsibility model splits into two layers. Workday, as the developer, documents system characteristics and limits. The customer, as the deployer, has to give affected employees clear, timely notice before an AI evaluation begins, say, before an automated screening tool reviews a job application. That's a sensible division of labor on paper. Whether every customer actually follows through on the notice requirement is outside what any vendor disclosure can guarantee.

On data use, Workday states: "We never share customer data to train third-party public models."" That's a clear, quotable commitment to take at face value as a policy statement.

The record gets thinner. The Verifywise AI Trust Index gave Workday a B, 60 out of 100, crediting the company for disclosing most of its data practices while flagging specific gaps. No named data retention period exists; the policy language is "for as long as we have a legitimate business need to do so," which is a sentence that could mean thirty days or ten years. There's no disclosure of whether user inputs train Workday's own models, or what the default opt-in or opt-out setting is. No synthetic output marking. And the index found the training data governance disclosures short on specifics. None of these gaps contradict the "never share with third parties" commitment. They just sit next to it, unaddressed.

Workday's security posture, per its government data transparency report and SEC filings

Workday publishes a Government Request Transparency Report twice a year, and that biannual habit is itself a meaningful commitment, since plenty of vendors say nothing at all on this front. The most recent one, Report No. 11, covers November 1, 2025 through April 30, 2026. The number of government requests received in that window: zero. No subpoenas, no search warrants, no court orders, no disclosures of customer content.

Also zero: national security requests. No requests under any national security legal process, and none under any secret surveillance court order. Workday's stated policy is that any government request for customer data should go to the customer that owns it, not to Workday directly. Fair enough, and consistent with how most enterprise SaaS vendors handle this.

Then there's the other side of the ledger. Workday's SEC filings acknowledge, as legally required, that the company faces ongoing cybersecurity threats and risks tied to third-party technology vulnerabilities. That kind of candid disclosure is arguably more useful to an auditor than a vendor who claims a spotless record. Every enterprise software company of Workday's size gets probed constantly. The vendors who say so are the ones worth trusting.

Workday's EU AI Act posture and its published AI governance framework

The EU AI Act rolled out in phases: the ban on prohibited AI systems took effect February 2, 2025, general-purpose AI obligations started August 2, 2025, and high-risk AI system requirements become fully applicable August 2, 2026. That last deadline matters most for a platform like Workday, since hiring and workforce management tools sit close to what the Act classifies as high-risk.

Workday says it's operating to an EU AI Act-ready standard, backed by a risk-based governance program, and joined the EU AI Pact back in 2024. It's also putting money behind the claim: a new AI Centre of Excellence in Dublin, backed by a three-year €175 million investment and 200 specialized AI roles.

The published framework, called Workday's "Vision for AI Governance," centers on what it calls "high-impact AI": systems making consequential decisions affecting people. It is consistent with the NIST AI RMF and ISO/IEC 42001 frameworks that Workday holds certifications against, and addresses AI risk across the system lifecycle. Notably, Workday's governance approach distinguishes among different types of AI systems rather than lumping them under one umbrella policy. It also addresses responsibility across different stages of the AI system lifecycle, which maps onto the developer/deployer split described in the fact sheets.

The disclosure gaps that remain and the questions a rigorous vendor audit should still ask

Add it up, and Workday's public record establishes a fair amount. ISO 42001 and NIST AI RMF alignment, independently verified by Schellman and Coalfire respectively. An agent governance system, ASOR, that's generally available and built with auditability in mind. A third-party attestation mechanism, Agent Passport, tied to named public standards like OWASP and MITRE ATLAS rather than a proprietary scoring system nobody outside the company can check. A clear policy against training third-party public models on customer data. Biannual transparency reporting with zero government disclosures in the latest window. And a candid SEC filing that admits to ongoing attack attempts rather than pretending the target on Workday's back doesn't exist.

That's a genuinely stronger disclosure posture than a lot of enterprise software vendors offer. But strong disclosure isn't the same as complete disclosure, and a rigorous buyer should still be asking pointed questions before signing anything.

Start with retention: what's the actual number of days or months behind "legitimate business need," and does it differ by data type, payroll records versus recruiting chat logs versus performance review notes? Ask next whether user inputs train Workday's own models, not just third-party ones, and what the default setting is for that, opt-in or opt-out, because the fact sheet quote only rules out sharing with outside vendors. Push on the gap between agent releases and audit cycles: with new agents shipping regularly, what happens to Agent Passport testing when a Workday-built agent gets a significant capability update mid-cycle, does it get re-tested before that update ships, or does it ride on the original attestation? And finally, ask for the actual Agent Passport results, not just confirmation that testing happened. A named standard is only useful for comparison if the scores against it are visible.

None of these questions accuse Workday of hiding something. They're the same questions to ask any vendor whose AI touches payroll, benefits, and workforce records, because that's not a category where "trust the vendor" is ever going to be a complete answer on its own.

Filed underProduct Security

More in Product Security