LinkedInInstagramXTikTok

AI in Recruitment: The Legal Risks Every Employer Should Know

Why AI in recruitment is more legally loaded than it looks

Few areas have adopted artificial intelligence as quickly as recruitment. Tools now sift CVs, rank candidates, screen video interviews, score personality assessments and even draft the first round of rejections. For a stretched HR team the appeal is obvious: less manual work, faster shortlists and a sense of objectivity. What is far less obvious to most employers is that recruitment is one of the most legally sensitive places to deploy AI, because it sits at the intersection of three demanding bodies of law at once.

An AI tool used to decide who gets a job touches employment and discrimination law, data protection law and now the EU AI Act, which singles out recruitment as a high-risk use of AI. The convenience is real, but so is the exposure, and the gap between the two is where companies get into trouble. This article explains how these rules apply, where the risks concentrate and how to use AI in hiring without walking into a legal problem.

Three bodies of law, applying at the same time

The first thing to understand is that no single rulebook governs AI in recruitment. Three regimes apply simultaneously, and a tool can comply with one while breaching another.

The AI Act and high-risk classification

The EU AI Act treats AI used for the recruitment and selection of candidates, and for decisions affecting workers, as a high-risk application. That classification is not symbolic. It brings obligations around human oversight, transparency to the people affected, data quality, technical documentation and accuracy. An employer that deploys such a tool is a deployer under the Act and carries duties of its own, even though it did not build the system. These obligations are being phased in, and although the exact deadlines for high-risk systems have been subject to proposed changes during 2026, the direction is clear: recruitment AI is squarely in the regulated category.

The GDPR and automated decisions

Recruitment is intensive processing of personal data, often including sensitive information, and the GDPR applies in full. Candidates must be informed about how their data is used, the processing needs a lawful basis, and data should not be kept longer than necessary. A particular point of friction is the GDPR’s rule on decisions based solely on automated processing that produce significant effects on a person. A hiring decision can be exactly such a decision, which means a purely automated rejection, with no meaningful human involvement, can be unlawful unless specific conditions are met.

Discrimination law

Finally, recruitment is governed by the prohibition on discrimination. The danger with AI here is subtle: a model trained on historical hiring data can learn and reproduce the biases embedded in that data, disadvantaging candidates on grounds such as sex, age, ethnicity or disability without anyone intending it. The fact that a machine produced the outcome is no defence; the employer remains responsible for a discriminatory result.

Where the risks concentrate

The most serious risk is hidden bias. Because an AI model reflects the data it was trained on, it can quietly entrench patterns that an employer would never adopt deliberately, and it can do so at scale and invisibly. A model that learned from years of hiring in which one group was favoured may keep favouring that group, dressed up as a neutral score.

A second concentration of risk is the absence of genuine human oversight. Many tools are marketed as decision support, but in practice the human simply approves the machine’s ranking without independent judgement. When that happens, the decision is effectively automated even if a person clicks the button, raising both GDPR and AI Act concerns. A third risk lies in transparency: candidates are frequently never told that AI was involved in assessing them, which sits uneasily with both data-protection information duties and the AI Act’s transparency expectations. Finally, there is the supply-chain problem familiar from data protection. The employer rarely built the tool and may not fully understand how it works, yet remains legally responsible for how it is used.

Practical example: the screening tool that learned the wrong lesson

Imagine a company that introduces an AI tool to rank applicants for technical roles. The tool is trained on the profiles of people the company has hired and promoted successfully over the past decade. It performs impressively in testing, surfacing candidates who resemble the firm’s existing high performers, and the HR team comes to rely on its rankings.

The problem is that the company’s historical hires were not demographically balanced, and the model has quietly learned to treat the characteristics correlated with that imbalance as markers of suitability. Strong candidates from underrepresented groups are systematically ranked lower, not because of their ability but because they do not match the historical pattern. No one designed this outcome, and for a long time no one notices it, because the tool looks objective. When a pattern of rejections eventually draws scrutiny, the company faces potential discrimination liability, GDPR questions about automated decision-making and AI Act obligations it never assessed, all from a tool adopted to save time. A bias review before deployment, meaningful human oversight and proper documentation would have made the same tool defensible.

Common mistakes companies make

The first mistake is assuming the vendor has handled compliance. The supplier may have built a capable tool, but the legal responsibility for how it is used in hiring rests with the employer, who must satisfy the deployer obligations, the GDPR and discrimination law in its own context.

The second mistake is treating the human in the loop as a formality. Oversight that consists of rubber-stamping the machine’s output is not meaningful human involvement, and it leaves the decision exposed as effectively automated.

The third mistake is never testing for bias. Because discriminatory outcomes from AI are typically invisible without deliberate examination, an employer that does not test its tool for disparate impact will usually not discover the problem until a candidate, a regulator or a court raises it.

Legal risks

The exposure here is cumulative because three regimes overlap. Discrimination in recruitment can lead to compensation claims and reputational damage, and the use of AI does not reduce the employer’s responsibility for the result. GDPR infringements, whether around unlawful automated decisions, inadequate information or excessive retention, carry the data-protection sanction regime with its substantial maximum fines. The AI Act adds its own obligations and penalties for high-risk uses that are not properly governed.

Beyond formal sanctions, there is a growing commercial and ethical dimension. Candidates increasingly care how they are assessed, and a company seen to reject people through an opaque algorithm risks its reputation as an employer. For organisations that take diversity and fairness seriously, an unexamined AI tool can quietly undermine the very goals they are trying to advance.

Recommended actions

Start by mapping where AI already touches your hiring process, including features built into the applicant-tracking or assessment systems you already use. For each one, treat it as a high-risk use and ask the three core questions: how candidates are informed, whether a human exercises genuine judgement over the outcome, and whether the tool has been tested for biased impact.

Build real human oversight into the process rather than a final click of approval, and make sure candidates are told that AI is part of the assessment. Ask vendors hard questions about how their models were trained, what data they use and what they have done to detect and mitigate bias, and document the answers. Keep personal data only as long as you need it and on a clear lawful basis. Above all, test for disparate impact before and during use, since this is the single most effective way to catch the risk that hurts both candidates and the company. Treat the whole arrangement as something to review regularly, because the tools, your hiring patterns and the law will all keep changing.

Frequently asked questions about AI in recruitment

Is using AI to screen candidates even allowed?

Yes, but as a regulated, high-risk activity rather than a free one. You can use AI in recruitment provided you meet the obligations that come with it: informing candidates, ensuring meaningful human oversight, maintaining a lawful basis under the GDPR and making sure the tool does not produce discriminatory outcomes.

Can we let the AI make the rejection decision automatically?

That is the riskiest design. The GDPR restricts decisions based solely on automated processing that significantly affect a person, and a hiring rejection can fall within that. Unless specific conditions are met, you need genuine human involvement in the decision, not a person mechanically confirming the machine’s output.

We bought the tool from a reputable vendor. Aren’t they responsible?

The vendor has its own duties, but as the employer using the tool you are the deployer and you carry responsibility for how it is applied in your hiring, including under discrimination law and the GDPR. Vendor assurances are useful but do not transfer your legal responsibility away.

How would bias even show up if the tool looks neutral?

That is exactly the danger: biased outcomes are usually invisible unless you look for them. A model trained on unbalanced historical data can disadvantage certain groups while appearing objective. The only reliable way to find this is to test the tool for disparate impact rather than trusting its appearance of neutrality.

Does the AI Act apply to us if we only use a hiring tool?

Yes. Recruitment is classified as a high-risk use, and an employer using such a tool is a deployer with obligations of its own, even without having built the system. The obligations are being phased in, so it is wise to prepare now and confirm the applicable deadlines as they are finalised.

Conclusion

AI can genuinely improve recruitment, but it does so in one of the most legally sensitive corners of a business, where employment, data protection and AI-specific rules all apply at once. The companies that get into difficulty are rarely acting in bad faith; they simply adopt a convenient tool without asking how candidates are informed, whether a human is really deciding and whether the model is quietly discriminating. Those who ask these questions, test their tools and document their reasoning can capture the benefits of AI in hiring while staying on the right side of the law and treating candidates fairly.

Lawgent helps employers assess the AI tools they use in recruitment, meet their obligations under the AI Act, the GDPR and discrimination law, and build a hiring process that is both efficient and defensible. We combine experienced business-law advice with AI-driven efficiency, so that you get clear, practical guidance faster and more cost-effectively than at a traditional firm. Using or considering AI in your hiring? Contact Lawgent for a review of your recruitment tools and processes.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop