Journey

Using AI in recruitment safely

Compliance path for employers using AI in recruitment: legal risks, DPIA, equality impact assessment, GOV.UK guidance, bias testing, candidate transparency, record-keeping.

Running a Business Updated 15 September 2026
references 4 guides

AI in recruitment: a high-risk use of automated decision-making

AI tools are increasingly used to screen CVs, rank candidates, conduct video interviews, and automate shortlisting. These tools can process hundreds of applications in minutes, but they carry significant legal risk.

Recruitment AI makes decisions about people's livelihoods. Under UK data protection law and the Equality Act 2010, employers bear full legal responsibility for the outcomes of these tools, even when a third-party vendor supplies the software. If an AI system discriminates, it is the employer who faces enforcement action.

Understanding the equality risk

AI recruitment tools can embed and amplify bias in ways that are difficult to detect. A system trained on historical hiring data may learn to favour candidates who match the profile of previously successful applicants, indirectly discriminating against protected groups. This applies to all nine protected characteristics under the Equality Act 2010.

AI and equality: understanding bias risks

Detailed guidance on how AI tools can breach the Equality Act 2010, common sources of algorithmic bias, and how to assess equality impact.

Data protection: DPIA is mandatory

Using AI to process candidate data is high-risk processing under UK GDPR. A Data Protection Impact Assessment is not optional for recruitment AI. The ICO's guidance on AI and data protection makes clear that automated profiling and decision-making about individuals requires a DPIA before you begin processing.

AI in recruitment and HR

Complete employer guide to using AI in hiring: lawful basis, DPIA process, ICO expectations, and practical compliance steps.

Transparency: telling candidates about AI

Candidates have a right to know when AI is involved in decisions about their application. Under UK GDPR Article 22, individuals have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Recruitment decisions clearly meet this threshold.

Human oversight: the right to contest

AI tools should support human decision-making, not replace it entirely. The Data Use and Access Act 2025 strengthens the right to contest automated decisions, requiring organisations to demonstrate meaningful human involvement in consequential decisions.

Testing for bias before and during use

Before deploying any AI recruitment tool, conduct an Algorithmic Impact Assessment to evaluate whether the system produces discriminatory outcomes. This is not a one-off exercise. You should test regularly using representative data and monitor outcomes by protected characteristic once the tool is in use.

Ask your vendor for documentation on how the model was trained, what fairness metrics were applied, and what testing was conducted. If they cannot provide this, reconsider whether the tool is fit for purpose.

Verify your compliance

Use the AI compliance checklist to audit your recruitment AI against all current legal requirements. This covers data protection, equality, transparency, human oversight, and record-keeping in a single structured assessment.

AI compliance checklist

Structured checklist covering all legal requirements for AI systems, including recruitment-specific obligations.

AI governance framework

Broader governance guidance for organisations deploying AI across multiple business functions.