The recent DOL polygraph guidelines matter because they do not create broad permission for workplace lie-detector testing. They clarify and reinforce a restrictive federal framework under the Employee Polygraph Protection Act, known as EPPA, while the Department of Labor continues to collect information tied to compliance duties, notices, records, and permitted exceptions.
For private employers, the practical effect is caution. A polygraph service may be lawful in limited settings, but the employer’s reason, notice process, examiner qualifications, records, and treatment of results all matter. For employees and applicants, the same rules preserve a strong baseline: most private-sector lie-detector requests are prohibited, and refusal cannot usually be used as a reason for adverse action. This article is analytical information, not legal advice.
What DOL Polygraph Guidelines Changed In 2026
DOL Polygraph Guidelines And Comment Process
On July 27, 2026, the Wage and Hour Division published a Federal Register notice seeking comment on extending EPPA-related information collection requirements. The notice listed 164,000 estimated respondents, 757,400 annual responses, 68,779 annual burden hours, and an estimated respondent cost of $3,614,475; the comment deadline was set for September 25, 2026, according to the Federal Register notice.
That notice did not make routine private-employer polygraph screening lawful. Its significance is more administrative and compliance-focused. It shows that EPPA’s notice, recordkeeping, and enforcement structure remained active as of September 17, 2026. Employers reading the DOL polygraph guidelines should therefore treat the 2026 activity as a reminder to review policies, not as a green light to expand testing.
What The Federal Baseline Still Says
EPPA prohibits most private employers from requiring, requesting, causing, or suggesting that an employee or job applicant take a lie-detector test. It also restricts employers from using, accepting, referring to, or asking about test results, and from taking adverse action based on a test result or a refusal, except under limited statutory exemptions described by the Department of Labor EPPA page.
This is the central point for workplace integrity programs: a polygraph is not a general-purpose hiring screen for most private employers. Even where a company has serious concerns about theft, embezzlement, inventory loss, or another incident, the question is not simply whether management wants more information. The question is whether a specific EPPA exemption applies and whether the employer can meet the required safeguards.
Employer Duties Under DOL Polygraph Guidelines
Narrow Exemptions Require Specific Facts
The most familiar private-employer exemption concerns an ongoing investigation into a workplace incident involving economic loss. The research record identifies examples such as theft or embezzlement and notes that the employee must have had access to the property involved. That is narrower than general suspicion, poor performance, workplace tension, or a desire to test credibility after a disagreement.
Other exemptions identified in the research include certain prospective employees of security service firms, such as armored car, alarm, and security guard companies, and current or prospective employees of firms authorized to manufacture, distribute, or dispense controlled substances. Those categories should not be stretched casually. A business that is merely concerned about internal honesty does not automatically become a covered security employer.
Employers reviewing DOL polygraph guidelines should separate three questions before contacting an examiner: whether EPPA applies to the employer, whether a statutory exemption fits the facts, and whether state law, local law, or a collective bargaining agreement gives workers stronger protection. The research notes that stricter protections are not displaced by EPPA, so a federal exemption may still be insufficient in a more protective jurisdiction or contract setting.
Procedural Safeguards Are Part Of The Right
Where testing is allowed, the process is not informal. The research describes safeguards across the pre-test, testing, and post-test phases. Those safeguards include written notice of rights and limitations, an opportunity to review questions, the ability to refuse or terminate the test, and requirements that examiners be licensed and bonded or carry professional liability insurance.
That structure has a practical purpose. A workplace polygraph can affect reputation, employment, and trust inside a team. Written notice forces the employer to define the basis for testing. Question review reduces surprise. The right to stop the examination recognizes that consent must have meaning. Examiner qualification requirements reduce, but do not remove, the risk that a poorly handled examination will produce unfair pressure or unreliable conclusions.
A useful internal control is to require a documented approval step before any test is requested. That approval should confirm the suspected incident, the economic loss, the employee’s access to the property, the proposed notice, the examiner’s qualifications, and the plan for handling results. For readers who need a worker-focused companion to this subject, our discussion of polygraph employee rights under DOL rules tracks many of the same safeguards from the employee side.
Employee Rights And Practical Risk Points
Refusal And Adverse Action
For employees and applicants, the core protection is straightforward: most private-sector lie-detector testing cannot be demanded as a condition of work or hiring. Under the research summary, adverse action based on refusal is also restricted unless a limited statutory exemption applies. That matters because pressure can be subtle. A request framed as voluntary may still raise concern if the surrounding message suggests that refusal will be viewed as guilt, disloyalty, or noncooperation.
Employees asked to take a test should receive written information, should understand the reason for the request, and should have a real chance to review the questions. They should also be alert to disclosure issues. Polygraph results are sensitive workplace information, and the research identifies protections on disclosure of results where permitted examinations occur.
AI And Similar Truth-Assessment Tools
A newer risk area involves tools that claim to assess truthfulness or deception through voice stress, facial micro-expression analysis, eye tracking, or similar signals. The research notes that recent DOL guidance treated AI or similar truth-assessment systems as lie-detector tests for EPPA purposes when they are used to assess deception. That means an employer cannot avoid EPPA simply by replacing a traditional polygraph instrument with a software product that serves a similar truth-testing function.
This point is especially relevant for vendors and human resources teams. Product language may describe screening, risk scoring, behavioral analytics, or credibility assessment without using the word polygraph. The legal risk turns on function, not branding. If a tool is used to assess whether an applicant or employee is truthful, the employer should pause and evaluate EPPA before use.
Using Polygraph Services Without Overclaiming Certainty

Integrity Programs Need More Than One Signal
A responsible workplace integrity program should not treat a polygraph result as a standalone verdict. The supported federal materials establish legal boundaries; they do not promise perfect truth detection. Employers still need ordinary evidence practices: inventory records, access logs, witness statements, financial controls, chain-of-custody records, and fair interview procedures. Polygraph services, where lawful, should be one limited input within a wider review.
That point protects both sides. Employers reduce the risk of acting on a weak or legally tainted process. Employees receive a better chance that accusations will be judged against verifiable facts rather than pressure or intuition. For related integrity and documentation themes across this publisher network, The Sketchbook Project offers another example of why recordkeeping and transparency matter in organized projects.
- Do not request testing unless an EPPA exemption has been identified and documented.
- Do not use refusal, test results, or questions about results outside permitted limits.
- Do review state law, local law, and collective bargaining agreements before relying on a federal exception.
- Do require written notices, qualified examiners, and secure records where testing is allowed.
- Do treat AI truth-assessment tools as a compliance concern, not as a workaround.
DOL Polygraph Guidelines For Workplace Rights
The rights impact of the DOL polygraph guidelines is best understood as a balance between limited investigative use and broad worker protection. Employers retain narrow options in defined situations, but those options carry strict conditions. Employees and applicants retain strong protection against routine testing, pressure to consent, and adverse action tied to refusal or results outside the statute’s limited exemptions.
The July 27, 2026 Federal Register notice also shows that EPPA compliance continues to involve real administrative burden, including notices, records, and respondent costs. That burden is not just paperwork. It is part of the structure that makes permitted testing reviewable and gives employees a record of their rights.
For corporate and legal settings, the practical lesson is conservative: define the business need, verify the exemption, document the basis, respect refusal rights, and avoid claims that a test can settle a workplace dispute by itself. Used carelessly, lie-detector testing can weaken trust and increase legal exposure. Used only within lawful limits, with transparent procedures and modest claims, it can support a narrower fact-finding process without replacing evidence-based judgment.