AI in recruitment and automated decisions
Ask yourself one question about your hiring process: could the person reviewing the system’s output realistically have overturned it? If the honest answer is no, you have an automated decision with a signature on it.
What the UK rules now require
The Data (Use and Access) Act 2025 changed the position materially. The old near-prohibition on solely automated decisions with legal or similarly significant effects was replaced by a permissive regime with conditions.
Where a decision about an individual is made solely by automated means and has legal or similarly significant effects — which a hiring decision does — you must provide:
- Meaningful information about the logic involved
- A right to obtain human review
- A right to contest the outcome
The ICO is under a statutory duty to produce a Code of Practice on AI and automated decision-making. The enabling regulations came into force on 12 May 2026 and the Code is expected in 2027.
Meaningful human involvement — where it fails
“Meaningful” means active review before the decision takes effect, by someone with the competence to assess it and the authority to disagree.
The failure modes are consistent:
The EU layer, if you have EU candidates
The EU AI Act’s high-risk regime has been deferred to 2 December 2027, and recruitment and employment AI is classified high-risk — targeting job adverts, filtering applications, evaluating candidates, allocating work, monitoring performance, and decisions on promotion or termination.
It reaches you where the system’s outputs affect people located in the EU. A London business screening candidates for a role in Dublin is in scope.
Deployer obligations include human oversight with genuine authority to override, input data quality and logging, bias testing on your own candidate data, and informing workers and candidates that the system is being used.
The Equality Act layer
The exposure employers see last and should see first.
A tool that produces systematically worse outcomes for a protected group creates indirect discrimination risk — regardless of intention, and regardless of whether anyone can explain why the model behaves that way. The employer is liable, not the vendor. Compensation is uncapped, and a tool applied across thousands of applications does not produce one claim.
The full analysis is on our algorithmic discrimination page.
What to do
- Know what you are running, including AI features enabled inside platforms you already licence
- Document what each tool does and on what data it was trained — ask the vendor and keep the answer
- Make the human review real, and be able to evidence it
- Tell candidates the system is being used and how to contest the outcome
- Test outcomes across protected groups at each stage — taking advice first, as the analysis itself involves sensitive data
- Provide an adjustments route a candidate can use without disclosing a diagnosis to a machine
- Record the reasoning behind each decision about the system
What it costs
£400 per hour plus VAT. An AI hiring review — what you are running, what applies to it, and where the gaps are — is a fixed fee. Ongoing advisory work sits within our business counsel arrangement.
Questions
Questions businesses ask us
What counts as meaningful human involvement?
Active review before the decision takes effect, by someone competent to assess the output and authorised to disagree with it. A manager signing off a shortlist they had no realistic ability to interrogate has not provided it.
Do we have to tell candidates we use AI?
Yes, in substance. The rules require meaningful information about the logic, a right to human review and a right to contest — none of which works if the candidate does not know the system was used.
Does the EU AI Act apply to us?
If any of your candidates are located in the EU, quite possibly. The high-risk regime applies from 2 December 2027 and it reaches systems whose outputs affect people in the EU.
The vendor says the tool is bias-tested. Is that enough?
No. Ask for the results, ask what data it was tested on, and test outcomes on your own candidate data — a tool tested on one population can behave differently on yours. And the claim would be against you regardless.
Where do we start?
An inventory. Most organisations cannot list the AI systems they are running, and you cannot assess what you have not found.
Related
The hub
Also in this area
Also in this area
Start with a conversation
A free 20-minute call. Tell us what has happened and we will tell you whether we can help, what it would involve and roughly what it would cost.
No charge
A free 20-minute call
Tell us what has happened and we will tell you whether we can help, what it would involve and roughly what it would cost. No advice is given on this call and there is no charge for it.
£350 plus VAT
A paid strategy session
One hour with a partner, followed by a written summary of your position and options. For people who want proper advice without instructing a firm yet. Credited in full against your fees if you go on to instruct us.
Or reach us directly
We answer enquiries the same working day.