AI in hiring: what is legal in the EU and UK
AI systems used to recruit and select employees are classified as high-risk under the EU AI Act. Here is what that means in practice for an employer, and what it does not mean.
Under the EU AI Act, AI systems used for recruitment, candidate selection and employment decisions are classified as high-risk, bringing obligations around risk management, data governance, transparency, human oversight and record-keeping. Crucially, obligations fall on the employer deploying the system, not only on the vendor supplying it. GDPR applies in parallel to all candidate data.
This is general orientation, not legal advice. Obligations phase in over time, the detail continues to develop, and specifics vary by jurisdiction and by exactly how you use a system. Take advice from a qualified adviser for your own circumstances before relying on any of this.
Why hiring is singled out
The EU AI Act uses a risk-based structure, and employment is treated as one of the higher-risk domains. The reasoning is straightforward: decisions about who gets work materially affect people's lives, the people affected have little power in the process, and automated systems can apply a flawed criterion consistently and at enormous scale in a way an individual biased interviewer cannot.
This is not a hypothetical concern. Systems trained on historical hiring data learn historical hiring patterns, including the discriminatory ones.
The obligation employers most often miss
High-risk classification places duties on both the provider (the vendor building the system) and the deployer (you, the employer using it). Many buyers assume the vendor has handled compliance on their behalf. That is not a safe assumption, and it is the most common misunderstanding we encounter.
Deployer-side duties broadly include using the system in line with its instructions, ensuring meaningful human oversight, monitoring how it operates in practice, keeping records, and informing affected people where required. What exactly applies to you depends on your use.
GDPR applies regardless
Separately from the AI Act, candidate data is personal data. Interview recordings, transcripts, CVs and AI-generated assessments are all personal data about an identifiable person. That means:
- A lawful basis for processing, identified and recorded before you start.
- Purpose limitation — data collected to assess one application should not silently become a permanent talent database.
- Defined retention. "We keep everything forever" is not a policy. Set a period, document the reasoning, and actually delete.
- Data subject rights — access, rectification, erasure. You need a process that works, not just a mailbox.
- Transparency — candidates should know what you collect, why, and whether AI is involved in assessing them.
Where automated processing significantly affects someone, GDPR provisions on automated decision-making and profiling may also apply. See GDPR in hiring.
Recording interviews
Recording an interview means processing personal data, and in some jurisdictions consent rules for recording conversations apply on top of data protection law. Practically:
- Tell candidates before the interview, not as it starts — being asked to consent with the camera already on is not a free choice.
- Explain what the recording is for, who will see it, and how long it is kept.
- Offer a genuine alternative if they decline, and do not disadvantage them for declining.
- Apply the same retention rules you apply to everything else.
Human oversight is not a checkbox
Meaningful human oversight means a person who can actually understand, question and override the system's output — not someone who clicks approve on a ranked list. If your process would produce the same outcome with the human removed, the oversight is nominal.
The practical implication: AI-assisted assessment that surfaces evidence for a human to weigh is a materially different proposition from automated ranking or automated rejection. It is worth being clear which one you are operating.
What to ask any AI hiring vendor
- Is our candidate data used to train your models, or anyone else's?
- Which sub-processors touch candidate data, and in which jurisdictions?
- Can you delete an individual candidate on request, and within what timeframe?
- What is the retention default, and can we configure it?
- Does the system make or automate any rejection decision without a human?
- What documentation can you provide to support our own high-risk assessment?
- How do you test for and monitor discriminatory outcomes?
A vendor unable to answer these clearly is a risk you are taking on, because the deployer obligations land on you regardless of what they told you.
Beyond the EU
The UK has not adopted the AI Act, but UK GDPR and the Equality Act both apply to AI-assisted hiring, and the direction of regulatory attention is similar. In the US, New York City's Local Law 144 requires bias audits and candidate notification for automated employment decision tools, and other jurisdictions are moving. If you hire across borders, the practical approach is usually to work to the strictest standard that applies to you.
A reasonable position to take
None of this makes AI in hiring unusable — it makes unexamined AI in hiring risky. A defensible setup generally looks like: AI surfaces evidence and structure, humans make every decision, candidates are told AI is involved, retention is defined and enforced, and you can explain to a candidate how their assessment was reached. That is achievable, and it is also just better hiring.
Common questions
Is it legal to use AI to screen candidates in the EU?
Using AI in recruitment is not prohibited, but such systems are classified as high-risk under the EU AI Act, which brings specific obligations on both the vendor and the employer using it. GDPR applies in parallel. Take advice on your particular use.
Do I have to tell candidates I am using AI?
Transparency obligations under GDPR and the AI Act point strongly toward telling them, and it is good practice regardless. The exact requirement depends on how the AI is used and where you operate.
Is it legal to record job interviews in the UK?
Recording is possible, but you are processing personal data and should inform candidates in advance, explain the purpose, and set a retention period. Consent and notification requirements vary — take local advice.
Who is responsible if an AI hiring tool discriminates — us or the vendor?
Both may carry obligations. Employment discrimination liability generally sits with the employer, and AI Act duties fall on deployers as well as providers. Assuming your vendor has absorbed the risk is not a safe position.