AI in Recruitment: Understanding Your Compliance Obligations

Parts 1 to 3 of this series both made the case for AI in recruitment and how impactful adoption requires responsible implementation. This article goes deeper into the binding legal obligations that underpin those best practices, and what agencies need to do to comply.

For recruitment agencies, compliance has shifted from a back-office concern to a commercial one. Getting it wrong carries the risk of fines, discrimination claims, and lasting reputational damage. Getting it right means being able to move fast, innovate with confidence, and position as an agency that candidates and clients can trust.

AI in Recruitment Series

Part 4 OF 4

This article is part of our AI in Recruitment series, where we break down how AI is changing hiring in practice, what impact it delivers, and how to implement it responsibly.

SERIES SO FAR:

PART 1

How AI is Transforming Every Stage of Recruitment

PART 2

PART 3

PART 4

GDPR sets the baseline. In Part 3 of this series, we outlined how it applies to AI: automated decision-making, transparency obligations, data minimisation, and vendor accountability. What’s changing is the layer of AI-specific regulation being built on top of it.

The emergence of AI as a fundamental element of recruitment has added complexity to compliance – and, in some cases, made it more urgent. Employment law, equality legislation, and data protection obligations set clear boundaries for how candidates should be treated and how recruitment information must be managed.

The use of AI in recruitment deepens existing obligations under data protection and anti-discrimination law, while simultaneously exposing agencies to nascent AI-specific regulation. Each carries its own requirements and together, they demand transparency, fairness, and human accountability.

Understanding where the obligations come from, and how they interact, is essential when attempting to navigate them effectively.

The UK Framework: Existing Law, Evolving Guidance

Rather than implementing a single prescriptive law, the UK government created the 2023 AI Regulation White Paper, which sets out a sector-led approach. This relies on existing regulators to enforce AI obligations within their respective domains. For recruitment agencies, three areas are most relevant.

Data protection: the ICO

The Information Commissioner’s Office (ICO) is the primary authority on how GDPR applies to AI in recruitment. As covered in Part 3, AI-assisted hiring decisions fall under Article 22, which gives candidates the right not to be subject to purely automated decisions that significantly affect them, such as being screened out of a role. In practice, this means human review is a legal requirement, not a best practice. Transparency obligations also apply: candidates must be informed when AI is being used to assess them. Agencies that fail to meet these standards face ICO enforcement action, including fines of up to 4% of global annual turnover.

Discrimination: The Equality Act and the Equality and Human Rights Commission (EHRC)

The Equality Act 2010 applies to all recruitment practices, including those involving AI. If an AI system produces outcomes that systematically disadvantage candidates based on protected characteristics – age, sex, race, disability, and others – the agency is liable, regardless of whether the discrimination was intentional.

The Equality Act does not distinguish between intentional and unintentional discrimination. For agencies operating across multiple clients, the risk is amplified: inherited biases from many different sources can be standardised at scale.

The Equality and Human Rights Commission (EHRC) oversees compliance and has enforcement powers. Regular bias audits, diverse training data, and human oversight are not optional best practices under the Equality Act – they are the foundation of a defensible process.

Responsible AI guidance

In late 2024, the UK government issued guidance on Responsible AI in Recruitment, encouraging voluntary best practices: human-in-the-loop decision-making, algorithmic transparency, and regular bias audits. While not yet law, they signal the direction of travel for AI regulation in the UK. Agencies that implement these practices now will be well-positioned when the regulatory screw tightens.

EU AI Act: What It Means for Recruiters

The EU AI Act is the world’s first comprehensive, binding legal framework for AI, and its implications for the recruitment agencies it touches are substantial. Enforcing a risk-based approach to AI governance, it bans unacceptable AI uses like social scoring and biometric categorisation to deduce protected traits. It also classifies AI systems used in recruitment and HR – including tools for CV screening, candidate ranking, and employee assessment – as high-risk.

UK recruitment agencies are not directly bound by the EU AI Act post-Brexit. Many will nonetheless be using AI tools built by vendors operating under EU regulation or placing candidates into EU-based roles – in either case, the Act is relevant.

The practical advice for UK agencies is straightforward: align with the Act’s requirements as a baseline. This will protect candidates, satisfy regulators on both sides, and avoid running different compliance standards in different markets.

Being classified as high-risk means more stringent obligations apply to both the vendors building these tools and the agencies deploying them. These include:

  • Conducting a risk assessment and putting mitigation measures in place
  • Maintaining detailed technical documentation and audit logs
  • Implementing a risk management system across the tool’s lifecycle
  • Ensuring the quality and representativeness of training data to minimise bias
  • Providing clear information to users about how the system works
  • Registering the system in an EU database of high-risk AI applications

For recruitment agencies, human oversight is not optional under the Act. They must be capable of monitoring, intervening, and overriding AI outputs where necessary. The Act also reinforces the transparency obligations established under GDPR and the Equality Act by requiring that candidates be notified when an AI system is involved in evaluating them.

Some provisions of the EU AI Act, notably those relating to general-purpose AI models, came into effect in August 2025.

Agencies must begin preparing for that deadline by auditing tools, engaging vendors, and building governance frameworks. This should include: asking vendors about algorithmic transparency, requesting evidence of bias testing, and checking whether training datasets reflect a diverse and representative candidate pool. Failure to do so could result in punitive punishment.

Agencies that fail to comply with the obligations set out in the Act will be hit with significant penalties that compound reputational damage. Non-compliance with high-risk AI system requirements carries fines of up to €15 million or 3% of global annual turnover, whichever is higher. For prohibited AI practices, these penalties escalate to €35 million or 7% of turnover – exceeding those imposed under GDPR.

Compliance Checklist

Part 3 of this series sets out the operational mitigations for bias, data privacy, candidate experience, and human oversight. The checklist below translates those principles into the specific legal and regulatory obligations recruitment agencies must satisfy across GDPR, the Equality Act, and the EU AI Act.

ActionRelevant framework
Document the legal basis for every use of AI in the candidate journey.GDPR
Notify candidates when AI is used in screening or decision-making – before it happens, not during.GDPR
Build a human review step into all AI-assisted shortlisting and rejection decisions, and document it.GDPR / EU AI Act
Ensure candidates can request human review of any AI-influenced decision.GDPR / UK guidance
Prepare a plain-language explanation of how AI screening tools work and what they consider.GDPR
Configure AI tools to collect only what is relevant to the role – no more.GDPR
Conduct due diligence on all AI vendors before deployment: GDPR compliance, data retention policies, security safeguards, and DPO involvement.GDPR
Appoint or consult a Data Protection Officer if processing candidate data at scale.GDPR
Run regular bias audits on AI tools, including a review of training data for skew across protected characteristics such as age, gender, and ethnicity.Equality Act 2010 / EU AI Act
Monitor shortlist and placement outcomes over time. If results are consistently skewed in one direction, investigate.Equality Act 2010
For recruitment agencies operating as MSPs: audit recruitment partners and candidate sources to ensure they comply with GDPR, Equality Act, and EU AI Act requirements. Document assurances and conduct periodic reviews.GDPR / Equality Act (vicarious liability)
Keep technical documentation and audit logs for all high-risk AI systems.EU AI Act
Register high-risk AI systems in the EU database as required.EU AI Act
Begin preparing for EU AI Act high-risk compliance now. The December 2027 deadline will not be extended again.EU AI Act (Dec 2027)
Audit the quality and structure of ATS and CRM data before deploying AI tools. Inconsistent or outdated candidate records will degrade AI outputs and may produce legally indefensible decisions.Data quality / Equality Act

Future-Proofing Recruitment Technology

Compliance today does not guarantee compliance tomorrow as the development of the regulatory environment around AI gathers pace.  Forward-thinking recruitment agencies build compliance into how they evaluate, deploy, and manage this technology, rather than reacting to external pressure. Five areas deserve particular attention:

Due diligence

Before any new AI tool enters the recruitment process, ask vendors to demonstrate how they have addressed bias in training data, what documentation they provide for regulatory purposes, and how they support clients in meeting regulatory obligations. Extend this due diligence to recruitment partners and candidate sources in your supply chain.

Data quality

If an AI tool is making recruitment decisions based on a database that contains demographic signals, outdated status fields, or inconsistent protected characteristics, those decisions may be legally indefensible. Auditing the quality and structure of ATS and CRM data before deploying AI is a regulatory prerequisite.

Governance

Human oversight should not be an afterthought during an AI-heavy process; it should be implemented from the start. That means documented human review checkpoints, clear escalation paths when AI outputs are queried, and regular internal audits that treat compliance as an ongoing commitment.

Regulatory horizon scanning

The EU AI Act’s December 2027 high-risk deadline is the most pressing landmark for agencies with EU exposure, but it will not be the last. Constantly monitoring regulatory developments will ensure regulatory compliance now and in the future.

Compliance as a competitive advantage

Don’t view compliance as a constraint on innovation. From being transparent with candidates to being compliant with data protection law, agencies that can demonstrate responsible AI use win and retain clients, attract top candidates, and differentiate in a saturated market.

From Obligation to Advantage

The regulatory framework governing AI in recruitment is not a static checklist to be ticked off and forgotten. This is a dynamic environment that will tighten as AI adoption continues to accelerate rapidly, and regulators gain confidence in enforcement.

To keep pace, agencies must foster a compliance culture that asks the right questions before deploying new tools, keeps humans meaningfully in the loop, and treats transparency with candidates as a standard of professional practice.

The legal obligations are real, the penalties are significant, and the reputational stakes are high. But the agencies that understand the strategic value of regulatory compliance will move beyond responsible AI use as an obligation and constraint to a competitive advantage.

Scroll to Top