The ICO has warned that AI tools are stripping humans of a genuine role in the hiring decision, and it’s a major compliance risk. Here’s how talent leaders can respond.
On 31 March 2026, the UK’s Information Commissioner’s Office (ICO) sent a clear message to the recruitment industry: if you use AI to hire, you need to prove that a human—not an algorithm—is actually in charge.
This warning didn’t come out of nowhere.
Over the last two years, the rush to adopt AI has been relentless. In early 2024, nearly 40% of HR leaders were piloting generative AI, with recruiting among the top use cases. Just two years later, the ICO puts that figure closer to 70%—nearly 7 in 10 UK employers plan to increase AI hiring use within five years, under rules most don’t yet understand. The ICO is worried that using artificial intelligence to screen and rank applications or evaluate video interviews without a human weighing in and making the final call might be breaking data protection rules.
The regulator just closed a public consultation on the topic. It was paired with a report, “Recruitment Rewired,” which lays out the results of a year spent watching how over 30 UK companies actually use AI to hire.
Their core finding is a massive disconnect: most employers believe they are using AI as a helpful “assistant” when legally they’re running “automated decision-making” systems—and as a result, they’re risking a candidate’s privacy and information rights.
Human on Paper, Artificial in Practice
Talent acquisition (TA) was an early and prolific adopter of AI. Algorithmic screening was marketed as a blessing—a way for recruiters to move through applications faster and finally get a handle on the sheer volume of candidates. AI is fast, it’s cheap, it’s scalable.
Now, the ICO is saying the vast majority of UK employers are performing “automated decision-making” (ADM) without meaningful human involvement. Most of these employers don’t even realise they’re doing it, and that ignorance bypasses the legal safeguards required under UK GDPR Article 22A.
ADM happens whenever an AI system is used to screen, rank or score candidates in a way that affects their chances of getting a job. Running these systems on autopilot is a compliance issue. You’re on the hook to be transparent, give applicants the right to a human review, and make sure they have a way to challenge any decision the AI makes about them.
Human-in-the-loop or human-on-the-side?
The problem, the regulator says, is that many recruiters using AI to filter CVs or score candidates believe these tools are just “supporting” a human decision, not making one. The phrase “human in the loop” is everywhere in recruiting technology. We’ve taken it to mean that if a human is involved at any point—even just to sign off on an AI-generated shortlist—the system is inherently safe.
But the ICO says that phrase is being used far too loosely. The test is not whether a person looks at a shortlist; it’s whether that person has the information, the authority, and the genuine capacity to overrule the AI’s decision. If they don’t, the AI is the one making the call, not the human.
Think about it: if a hiring manager gets a ranked list of 10 people out of 400 applications, but has no idea who was filtered out or why, no real time to dig into the methodology, and no easy way to pull an excluded candidate back into the mix—that isn’t human review. It’s just formalising an automated decision.
The illusion of oversight
This creates a serious practical problem for employers. You might have a policy that claims there’s a “human in the loop,” but if the workflow strips away the ability for that human to actually intervene, then you only have the language of compliance, but not the substance.
That, says the ICO, is the crux of the problem. The regulator is concerned that “rubber stamping” has become the new normal without enough scrutiny, documentation or challenge. It sends a message that your hiring process is human-led when, in reality, it isn’t.
Operating this way while using third-party algorithms that haven’t undergone documented, independent bias testing is a failure of due diligence that leaves your entire organisation wide open to litigation.
Is AI Making Bad Decisions?
The British government certainly thinks so. The Data (Use and Access) Act 2025, key parts of which came into force on February 5, 2026, updated the UK GDPR’s rules on automated decision-making. It creates a clearer compliance framework for organisations that want to use automation lawfully, and the ICO’s current report and consultation is the first detailed look at how those rules apply to your hiring funnel.
But concerns about ADM are not just a UK regulatory exercise. The tension between regulators and recruiters is global, largely because the “black box” nature of these algorithms makes it incredibly difficult to see why a candidate was ranked up or filtered out. The industry has spent years training these tools on historical hiring data, and as it turns out, that’s a recipe for repeating the bias of the past:
- In 2017, one of the largest employers in the US scrapped an internal CV screening tool after discovering it was penalising female candidates. The system had learned to mirror the patterns of a decade of hiring data that heavily favoured men.
- Researchers at the University of Washington looked at three state-of-the-art large language models and found that when ranking candidates across nine different occupations, that AI favoured white-associated names 85% of the time.
- In the US, there are lawsuits against HR tech giants currently in discovery, with the court signalling that AI vendors, not just employers, can be held directly liable for discriminatory outcomes.
All of these concerns are pushing regulators to move fast. From the UK GDPR to the EU AI Act to New York City’s Local Law 144, jurisdictions everywhere are beginning to mandate everything from bias audits to explicit candidate disclosures regarding the use of AI.
For employers who recruit in multiple jurisdictions, these laws layer on top of each other and essentially demand compliance with the “toughest” rule. An AI workflow that passes the UK’s ADM test may not satisfy EU requirements, for example. Multinational employers must satisfy each law independently.
Why This Lands Hard: The Volume Problem
Data laws aside, what we are actually talking about here is the volume problem. Recruitment is a high-volume environment, so it is understandable that teams look for tools that promise to speed up the process of dispositioning candidates.
But if a recruitment function requires an algorithm to triage hundreds or thousands of applications, then surely the bottleneck is not the screening technology, it’s the front-end attraction process. Which begs the question—should we be casting the widest possible net and then relying on automation to manage the fallout? Or should we be finding better ways to attract the right people with the proper skill set and genuine intent, then reward them with a low-friction application experience while filtering out everyone else?
This is the uncomfortable question the ICO’s report poses. It forces TA leaders to ask whether the business is using AI to compensate for a broken front end. If the answer is yes, the legal risk is only a small part of the story.
The TA functions that handle this well solve for volume much earlier in the process, long before the point of screening:
- They’re clear about how jobs are distributed and to whom they are targeted.
- They build application journeys that surface the right information at the right time, rather than asking too much, too early, in an application that only the most tenacious (often desperate) candidates complete.
- They re-engage the talent that is almost right for the role, instead of discarding those silver medallists.
- They use real data to identify where the high-quality applications come from and stop spending money on sources that generate unqualified applicants.
When the front end does its job, you don’t need to rely so heavily on AI to make the screening workload manageable. And the human review process can perform exactly as the ICO expects.
What To Do Next: A Five-Step Compliance Process
It’s easy to think of the ICO’s intervention as yet another compliance headache in an industry that’s plagued by them. But it actually represents a strategic opportunity to reset the value proposition of the talent function—away from one that prioritises speed and towards one that captures the quality of hire.
Use these five steps to align your current operations with the regulator’s expectations.
- Audit the pipeline
Map every stage of your hiring process from the initial job posting to the final offer. Identify every point where an automated tool scores, ranks, filters or flags a candidate. “We use an ATS” is not a sufficient description—you need to identify which specific features are active and what automated decisions flow from them. This audit is your baseline. You cannot defend a process you have not fully mapped.
- Interrogate your “human-in-the-loop”
Document what human review looks like in practice, not just in policy. If an ICO auditor were to walk into your office tomorrow, you must be able to demonstrate that human reviewers have the information, capacity and authority to challenge AI-driven outcomes. Specifically, verify:
- What information is visible to the reviewer at the exact moment of decision?
- Does the reviewer have access to the candidates the AI filtered out?
- Do they have the realistic capacity to pull a candidate back into the process?
- Have they ever actually overridden an AI recommendation?
- Assess your vendors
Your AI partners must be accountable for any bias in their models and the clarity of their methodology. Talk to your vendors directly. Ask them when they last tested for bias, what methodology they used and what specific documentation they can provide. If a vendor cannot provide evidence of independent, regular bias testing, that tool is a liability that requires immediate re-evaluation.
- Update your Data Protection Impact Assessments (DPIAs)
Many organisations are operating with outdated DPIAs that do not specifically account for the AI tools now in use. If your current DPIAs don’t detail the mechanics of your automated decision-making and your human review process, they need an urgent update. Build a thorough audit trail now. If you had to prove to an auditor that a human remains in control at every stage, your DPIA should be the first document you present.
- Rebuild your attraction strategy around quality
Push your attention back to the quality of applications arriving in the ATS, which is where many of the real gains can be made. Do whatever you can to reduce poor-quality volume and keep qualified candidate volume at a level that human reviewers can thoroughly and lawfully handle.
The Strategic Reset
To be clear, the ICO hasn’t removed your ability to hire at scale. It has simply forced a question you should have been asking all along—is your screening process genuinely helping you find better people, or just helping you move more people through a flawed system?
The organisations that come through this well won’t be the ones removing AI from hiring—at this point, that would be closing the stable door after the horse has bolted. Instead, they’ll be the ones creating a function that is legally defensible. They’ll have data that shows the quality of hire, not just the speed of process. They will be able to show their business leaders how they navigated the pressure to build a better, more honest hiring process.
The compliance problem, handled well, becomes the business case. It gives you the clarity to see exactly where your best candidates come from, moving you away from the reliance on opaque tools and into a position of total process control. That is a better standard for compliance, and a better standard for hiring.

