Most employers the regulator spoke to believed their hiring tools only supported a decision. The evidence it saw indicated the tools were making it.
AI in Recruitment and HR Decisions: The UK Rules in 2026, and What a People Team Must Do
By James Cotton · Last updated · 18 min read
Part of our topic guides on AI Governance & Data Strategy and AI Skills for Business.
By James Cotton, Founder, iO-Sphere
What Articles 22A to 22D require
Where software takes a significant decision about a person with no meaningful human involvement, the UK GDPR requires safeguards and sometimes forbids it. Articles 22A to 22D, which replaced Article 22 under section 80(1) of the Data (Use and Access) Act 2025 for decisions taken from 5 February 2026, set these rules. HR's own use of AI is covered in our guide to data and AI skills for HR.
Article 22A sets the tests. A decision is "based solely on automated processing if there is no meaningful human involvement in the taking of the decision", and significant if "it produces a legal effect for the data subject" or has "a similarly significant effect". In judging involvement, "a person must consider, among other things, the extent to which the decision is reached by means of profiling".
The draft guidance on automated decisions from the Information Commissioner's Office (ICO), whose functions passed to the Information Commission on 30 September 2026, applies the second test to hiring. It gives "e-recruiting practices without meaningful human involvement" as a similarly significant effect, and lists a decision's impact on "employment opportunities and circumstances (eg recruitment, promotion)" among the factors.
Article 22B is stricter where special category data (the categories in Article 9(1)) is involved. A significant decision based "entirely or partly" on it may not be solely automated unless it rests entirely on data the person explicitly consented to, or is necessary for a contract or required or authorised by law and point (g) of Article 9(2), a further condition in the same article, also applies.
Article 22B(4) also bars a solely automated significant decision where the processing behind it relies, even partly, on Article 6(1)(ea): recognised legitimate interests, one of the lawful bases on which personal data can be processed. A people team therefore needs to know what data its screening tool draws on, and on which lawful basis.
Where a solely automated significant decision is taken, Article 22C requires safeguards that give the person information about it and enable them "to make representations", "to obtain human intervention on the part of the controller" and "to contest such decisions". In a hiring process, each of those has to work for every candidate the tool turns away.
Under Article 22D the Secretary of State may set out by regulations when there is or is not meaningful human involvement, which decisions have a similarly significant effect, and further safeguards. As at 8 October 2026 no regulations had been made under Article 22D.
A breach of Article 22B or 22C sits in the higher fine tier of Article 83(5): up to £17,500,000, or for an undertaking 4% of total worldwide annual turnover if that is higher. Both figures are statutory maxima.
What the ICO's 2026 recruitment report found
On 31 March 2026 the ICO published Recruitment rewired, its report on employers' use of automated decision-making (ADM) in hiring. It draws on over 30 employers that talked to the ICO voluntarily between March 2025 and January 2026, and by its own account it was neither an audit nor an investigation.
Its key findings show employers using the tools for roles that traditionally draw many applicants and for graduate or early-career roles. Tasks included "scoring and ranking candidates' competencies and skills from written applications and CVs" and judging fit through "AI-powered behaviour games or psychometric assessments". The report's own worked scenario is an early careers drive with "around 10,000 applications for 100 roles".
The central finding is that "many employers engaging in automated recruitment are likely relying on solely automated decisions as part of this process", and so "a greater range of safeguards will need to apply than our evidence suggests are currently in place".
Most of the employers, according to the report's page on human involvement, thought their tools were "decision support rather than decision-making", because they believed a person was meaningfully involved. The evidence indicated that, in practice, the tools were making solely automated decisions.
On suitability or "fit" scores, which the report calls "a form of profiling", the ICO "frequently saw evidence suggesting hiring managers were unlikely to review the scores or responses of lower-scoring candidates". Its red, amber and green case shows how that happens.
In the case, a manager whose training says to review all the scores prioritises the green candidates, may review some ambers, and glances at the reds before rejecting them. The report's verdict: "The manager has 'rubber-stamped' the 'red' candidates' rejections. This constitutes solely ADM within the scope of article 22."
Hence the report's choice for employers: "Employers must either: apply the safeguards with the ADM provisions ... or adapt their organisational processes to ensure that there is meaningful human involvement in each decision about each candidate." That involvement "must be applied to every candidate, not just those who score highly". Which path each tool takes is a choice someone has to own, the ground AI governance covers.
The report's use cases place particular steps on each side of the line. Knockout questions on mandatory requirements, such as being eligible to work in the UK, are not ADM where "A human presets the questions and required responses", because the tool "is limited to taking an action predetermined by a human in response to a binary outcome".
A tool that "automatically rejects candidates with an overall score below a minimum pass mark via a pre-scripted email" is ADM. So is a rejection a hiring manager makes by hand without considering every application, because "there has been no meaningful human involvement". When the manager appoints or rejects after a face-to-face interview, that decision "is not solely automated".
The question to ask of each step in your own process, then, is whether a person weighs each candidate at a point where the outcome can still change. The report also says what that person needs: they have "the qualifications and training to disagree with the tool's recommendations or predictions and can overturn them", and "they don't attach disproportionate weight to the tool's recommendations".
On transparency, candidates must be told about ADM when their information is first collected, when they ask for their information (a subject access request), and when ADM is used on them. Employers should explain "how they use the tool to make decisions; how accurate the tool is; and what safeguards are in place", simply, and without anything that would let candidates "game the system".
The ICO saw little evidence of employers explaining their tools' logic or accuracy. The report gives the example of an employer that tells candidates they can ask for human intervention but has no method for handling the requests; that, it says, "isn't compliant with the ADM provisions, since candidates can't fully exercise their rights".
On fairness, the key findings record that "Many employers we spoke to hadn't fully assessed the fairness of their processing or considered whether the outcomes resulted in bias or discrimination." The good practice it saw included asking developers about their bias testing during procurement, trials, and "dashboards that provided ongoing bias monitoring and monthly bias reviews". Candidates "must be able to contest a decision in a timely manner".
ADM in recruitment is "likely to be an activity that requires a DPIA" (a data protection impact assessment), and the ICO would treat one as good practice in any case. Its page on DPIAs found several employers had not done one, several DPIAs "significantly outdated", and most with empty or incomplete risk assessments signed off with no advice recorded from the data protection officer.
The key findings add that "Many employers relied on consent and/or contract, which are unlikely to be an appropriate basis for processing personal information in most recruitment contexts." The lawful basis page explains that consent is unlikely to be "freely given" when candidates fear refusing will stop them progressing, and that contract is unlikely to fit processing "to shortlist, test or interview candidates".
A footnote to the key findings describes the effect of the 2025 Act: the old conditions for ADM (explicit consent, contract, or authorisation by law) now apply only where the decision rests partly or entirely on special category data, as Article 22B provides.
Sixteen employers have confirmed they will act on the report's recommendations, according to its next steps page.
The 2024 audit of tool providers
The 2026 report also expects developers to review their tools' "design and marketing regarding meaningful human involvement". The ICO had audited them already: from August 2023 to May 2024 it ran consensual audits of organisations that develop or provide AI recruitment tools, leaving out tools that process biometric data or use generative AI, and published its audit outcomes report in November 2024.
Of its 296 recommendations, 97% were accepted, 3% partially accepted and none rejected. Some tools let recruiters "filter out candidates with certain protected characteristics"; others inferred gender, ethnicity and other characteristics from an application or a name, information the ICO found "not accurate enough to monitor bias effectively".
Depending on the decision and human involvement, the audit said, "the accuracy being better than random is not enough to demonstrate that AI is processing personal information fairly". For recruiters, it recommended keeping fit or suitability scores out of automated decisions a tool was not designed for, giving candidates "a simple way" to object to or challenge them, and asking providers for evidence on fairness, accuracy and bias.
On 6 November 2024 the ICO published six questions for an employer considering an AI recruitment tool. They predate the 2025 Act's changes to the automated-decision rules, and the 2026 report returns to most of them:
- Have you completed a DPIA?
- What is your lawful basis for processing personal information?
- Have you documented responsibilities and set clear processing instructions?
- Have you checked the provider has mitigated bias?
- Is the AI tool being used transparently?
- How will you limit unnecessary processing?
Draft guidance, and when the final versions are due
Most of the guidance a people team would turn to was issued by the ICO before 30 September 2026, when SI 2026/1015 abolished the office of Information Commissioner and passed its functions to the Information Commission (the ICO). The guidance on automated decision-making and profiling was updated, still as a draft, on 31 March 2026 to reflect the 2025 Act.
That guidance will inform a statutory code of practice on AI and ADM, which SI 2026/425 requires and which now falls to the Information Commission. Final dates in the table come from the regulator's plans pages for technology and general data protection, read 8 October 2026; the code appears on neither, and as at that date no date had been given for it.
| Guidance | Where it stands | Final version due |
|---|---|---|
| Automated decision-making and profiling | Draft, updated 31 March 2026; consultation closed | Winter 2026 |
| Recruitment and selection | Draft from December 2023, written before the 2025 Act | Winter 2026 |
| Monitoring workers | Under review because of the 2025 Act | Winter 2026/2027 |
| Subject access requests generated by AI | Drafting | Winter 2026 |
| Statutory code of practice on AI and ADM | Required by SI 2026/425, in force 12 May 2026 | None given |
For involvement to count, the draft ADM guidance says a human should "assess and review the decision at an appropriate point to ensure actual impact on the outcome", be able to influence it, have "discretion and authority to alter the decision", be "suitably trained and qualified to understand the system's logic, outputs, limitations, and risks", and "take into account the relevant data and factors on which the decision was based".
The draft rules out ad hoc spot checks, "because some automated decisions won't receive a check". The involvement must come "before you apply the decision to a person and at a time you can still change any recommendation", and "A human merely designing or building an automated system does not count as meaningful human involvement." It should be recorded too, and keeping such records is data governance work.
Its HR examples reach beyond hiring. An automated clocking-in system flags late attendance and a warning follows: that has meaningful human involvement, because the decision is "taken by the employer's HR manager following a review of that data". A factory worker's pay set by an algorithm predicting their productivity, with nobody reviewing or adjusting the outcome, is solely automated and can have significant effects, which the draft calls ADM.
The monitoring workers guidance, now under review, names the people analytics uses that carry the same questions into performance and absence: "security purposes; managing workers' performance; and monitoring sickness and attendance".
Where a decision is solely automated, the draft's chapter on safeguards asks for "decision-specific information about the actual outcome", an explanation of how to challenge it given with the decision, and a record of how the human reviewed it: "Like human involvement, human intervention cannot be tokenistic." Involvement decides whether a decision is solely automated at all; intervention is a safeguard owed after one.
The Equality Act, section by section
Each section of the Equality Act 2010 below applies to what a hiring or HR tool does as it would to a manager making the same call.
Section 39 bars an employer from discriminating "in the arrangements A makes for deciding to whom to offer employment", in the terms offered, or by not offering the job; for employees it covers promotion, transfer, training, dismissal and "any other detriment". A screening tool is part of those arrangements.
Section 13 makes direct discrimination less favourable treatment "because of a protected characteristic". Under section 19, indirect discrimination is a "provision, criterion or practice" that puts people sharing a characteristic "at a particular disadvantage", unless the employer can show it is "a proportionate means of achieving a legitimate aim".
The ICO's 2023 draft recruitment guidance gave two examples of biased software: one that "excludes candidates who live a certain distance away from the place of work, even if they intend to move to the area", and one that "eliminates candidates with gaps in their CV even though this was because the candidate had a serious illness".
Section 15 covers unfavourable treatment of a disabled person "because of something arising in consequence of" their disability, with the same proportionality defence, unless the employer did not know and could not reasonably have been expected to know of the disability.
Section 20 requires reasonable adjustments where a provision, criterion or practice puts a disabled person at a substantial disadvantage, including giving information "in an accessible format", and the person cannot be made to pay for them. Schedule 8, paragraph 5 extends the duty to anyone who is, or has told the employer they may be, an applicant.
In the ICO's 2026 report, employers typically offered an adjustment, often a phone interview, to disabled candidates who could not use automated methods. The previous government's Responsible AI in Recruitment guide of 25 March 2024 worked through a CV-screening tool whose bias audit found disabled and neurodivergent applicants "may be disadvantaged": the buyer sent those declaring a disability to manual review, and the supplier committed to audits "every six months".
Section 60 bars asking about an applicant's health before offering work, with exceptions that include finding out whether adjustments are needed for an assessment and monitoring diversity. Only the Equality and Human Rights Commission can enforce it.
Under section 109, anything an agent does for a principal with its authority "must be treated as also done by the principal", whether or not the employer knew or approved. Whether a given vendor or recruitment agency acts as your agent is a question about that relationship.
Under section 136, where there are facts from which a court or employment tribunal could decide, without another explanation, that discrimination occurred, it must so hold unless the employer shows it did not discriminate. That is where an employer's own bias testing and monitoring records come in. The Act sets no upper limit on compensation (section 124).
Section 149 adds, for public authorities, the public sector equality duty: "due regard" to the need to eliminate discrimination, advance equality of opportunity and foster good relations.
Beyond the Equality Act, the Employment Rights Act 2025, which received Royal Assent on 18 December 2025, contains no provision on AI, automated decisions or workplace surveillance (text checked 8 October 2026). Acas published My boss the algorithm in March 2020 as a discussion paper; it gives its author's own views and says it "is not intended as guidance from Acas about how to apply algorithmic management".
Complaints received since 19 June 2026
Section 103 of the 2025 Act inserted section 164A into the Data Protection Act 2018, placing duties on controllers to handle complaints from data subjects; under SI 2026/82, those duties apply to complaints received on or after 19 June 2026. A candidate is a data subject, so a hiring process needs a way to take their complaints, alongside the route to contest that Article 22C requires.
Hiring tools under the EU AI Act
The EU AI Act applies, under Article 2(1), to "(b) deployers of AI systems that have their place of establishment or are located within the Union" and to "(c) providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union".
An employer that uses an AI system at work is what the Act calls a deployer, so for a UK employer the question turns on those two tests.
Employment is point 4 of Annex III, the Act's list of high-risk uses. It covers systems "intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates", and systems for decisions on promotion, termination and task allocation, or to "monitor and evaluate the performance and behaviour of persons in such relationships".
Under the amending Regulation (EU) 2026/1744, the high-risk duties for Annex III systems apply from 2 December 2027; the rest of the EU calendar is in the 2026 register of AI rules.
Article 6(3) lifts an Annex III system out of the high-risk class where it poses no significant risk of harm, such as one meant "to perform a narrow procedural task" or "a preparatory task to an assessment". Profiling closes that exit: the system "shall always be considered to be high-risk where the AI system performs profiling of natural persons", and a provider using the exit must document its assessment first.
Article 26 sets what deployers of a high-risk system must do. They must follow its instructions for use, assign human oversight to people "who have the necessary competence, training and authority, as well as the necessary support", keep input data they control "relevant and sufficiently representative", report risks and suspend use, and keep logs for at least six months. The Act's literacy duty is covered in our AI literacy guide.
Under Article 26(7), "deployers who are employers" must inform workers' representatives and the affected workers before putting a high-risk system into use at work. Like the rest of Article 26, that applies to Annex III systems from 2 December 2027.
Article 86 gives a person subject to a decision based on such a system's output, with legal or similarly significant effects they consider adverse to their health, safety or fundamental rights, the right to "clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken".
One EU prohibition already reaches the workplace: since 2 February 2025, Article 5(1)(f) has banned the use of AI to infer a person's emotions at work, except for medical or safety reasons. Among the employers it spoke to, the ICO's 2026 report saw no emotion detection in video interviews, and its 2024 audit left such tools out.
Breaching a prohibition can bring a fine of up to EUR 35 million or, for an undertaking, 7% of total worldwide annual turnover if that is higher (Article 99(3)). That ceiling is a statutory maximum and applies to prohibited practices only.
The amending regulation also allows deployers of high-risk systems, exceptionally and only to the extent "strictly necessary to ensure bias detection and correction", to process special category data under the safeguards it sets. That is EU law, and it gives a UK employer no permission under the UK GDPR.
How many employers use AI in hiring
The CIPD's Resourcing and talent planning 2026, a professional body's survey run online by YouGov from 2 April to 2 May 2026 with 1,014 UK HR and people professionals, weighted to UK employers, finds 56% of organisations using no AI in recruitment. The most common uses, at 16% each, are shortlisting candidates and writing job descriptions, the second a staff use that belongs in a staff AI policy.
That compares with 62% using none in 2024 and 84% in 2022. The CIPD calls the increases "marginal" and says adoption "remains low", and this year it narrowed the sample to senior people responsible for resourcing and talent planning, so "Comparability with 2024 or other years need to be viewed with this in mind."
Non-use is higher in the public sector (68%) than the private sector (52%), and 80% of SMEs use no AI in recruitment against 38% of larger organisations. The ICO's report also cites a survey by the background-checking firm Zinc, of 1,000 UK HR and talent professionals, which reported that 37% automated rejections entirely.
Across business generally, the AI adoption research published on gov.uk on 28 January 2026 (IFF Research, 3,500 business interviews, February to May 2025) finds that 26% of businesses using or planning to use AI name HR as an area using it now or in future, and 53% of large ones do.
In August 2023, nine in ten of the 167 senior HR professionals the Recruitment and Employment Confederation surveyed said their organisations did not use AI in recruitment.
What a people team needs to be able to do
Both halves of the regulator's either-or need trained people: a reviewer able to overturn a tool's recommendation, or a team able to explain each automated decision and handle the challenges. The AI Act's Article 26 asks for oversight with "competence, training and authority", the 2024 guide told buyers to ask staff what "education, training or skills" they needed, and the CIPD's 2026 advice is "Focus on capability before technology."
Our recommendation is to train the reviewers first, on the hiring and HR processes they run, which our team training in data and AI fluency does as part of our training for businesses, with our guide to data and AI skills for people teams covering the rest of what HR can do with AI.
Our Data & AI Governance apprenticeship (Level 4), on the ST0967 data protection and information governance practitioner standard, suits whoever will own these rules, and AI Transformation (Level 4) whoever redesigns hiring; our employer guide gives the government's share by the apprentice's age at the start of training and the employer's levy position (the levy falls on employers with a pay bill over £3 million).
Frequently asked questions
Does a CV-parsing tool count as an automated decision?
Only if its output decides who goes forward with nobody meaningfully reviewing each candidate. The ICO's 2023 draft recruitment guidance counts decisions about "whether to shortlist a candidate, recommend them for interview, reject them or promote them"; on our reading, a parser that only extracts details for a person to assess takes none. For the EU AI Act, the European Commission's own high-risk example is "CV-sorting software for recruitment".
Does the public sector equality duty apply to our tool?
It does if you are a public authority. If you are not, section 149(2) reaches you only where you exercise public functions, and only "in the exercise of those functions", so for a private employer the answer depends on whether the work its tool supports is a public function. Either way, section 39 and the other sections above bind every employer.
Who is accountable when our vendor says it is only a processor?
You are, for any tool you use, whatever the contract calls the vendor. The ICO says organisations "are responsible for the algorithms and tools they use to process personal information, even if they didn't build the software or create the algorithm". Check the label as well: its 2024 audit found "several instances where AI providers incorrectly defined themselves as processors rather than controllers".
What if our vendor is based outside the UK?
Your duties to candidates stay with you wherever the vendor is based, because "accountability lies with the employer using the tool", in the ICO's words. It expects you to give candidates information on "the accuracy and performance of the tools", so get that from the vendor, and ask where its data came from: the 2024 audit found personal information "scraped and combined with other information".
Not sure which path is right?
Book a 30-minute consultation to talk through your team's needs.