Compliance path for employers using AI in recruitment: legal risks, DPIA, equality impact assessment, GOV.UK guidance, bias testing, candidate transparency, record-keeping.
Running a BusinessUpdated 15 September 2026
references 4 guides
AI in recruitment: a high-risk use of automated decision-making
AI tools are increasingly used to screen CVs, rank candidates, conduct video interviews, and automate shortlisting. These tools can process hundreds of applications in minutes, but they carry significant legal risk.
Recruitment AI makes decisions about people's livelihoods. Under UK data protection law and the Equality Act 2010, employers bear full legal responsibility for the outcomes of these tools, even when a third-party vendor supplies the software. If an AI system discriminates, it is the employer who faces enforcement action.
Understanding the equality risk
AI recruitment tools can embed and amplify bias in ways that are difficult to detect. A system trained on historical hiring data may learn to favour candidates who match the profile of previously successful applicants, indirectly discriminating against protected groups. This applies to all nine protected characteristics under the Equality Act 2010.
Detailed guidance on how AI tools can breach the Equality Act 2010, common sources of algorithmic bias, and how to assess equality impact.
Data protection: DPIA is mandatory
Using AI to process candidate data is high-risk processing under UK GDPR. A Data Protection Impact Assessment is not optional for recruitment AI. The ICO's guidance on AI and data protection makes clear that automated profiling and decision-making about individuals requires a DPIA before you begin processing.
Complete employer guide to using AI in hiring: lawful basis, DPIA process, ICO expectations, and practical compliance steps.
Transparency: telling candidates about AI
Candidates have a right to know when AI is involved in decisions about their application. Under UK GDPR Article 22, individuals have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Recruitment decisions clearly meet this threshold.
Human oversight: the right to contest
AI tools should support human decision-making, not replace it entirely. The Data Use and Access Act 2025 strengthens the right to contest automated decisions, requiring organisations to demonstrate meaningful human involvement in consequential decisions.
Testing for bias before and during use
Before deploying any AI recruitment tool, conduct an Algorithmic Impact Assessment to evaluate whether the system produces discriminatory outcomes. This is not a one-off exercise. You should test regularly using representative data and monitor outcomes by protected characteristic once the tool is in use.
Ask your vendor for documentation on how the model was trained, what fairness metrics were applied, and what testing was conducted. If they cannot provide this, reconsider whether the tool is fit for purpose.
Verify your compliance
Use the AI compliance checklist to audit your recruitment AI against all current legal requirements. This covers data protection, equality, transparency, human oversight, and record-keeping in a single structured assessment.