Copy article

ICO states human oversight of AI hiring must be meaningful. Tired managers approving an AI shortlist doesn't count.

ended 02. April 2026

The ICO published its automated decision-making in recruitment report on 31 March 2026, alongside a consultation on draft guidance open until 29 May. For companies using AI to sift CVs, score assessments, or filter candidates at any stage, this is now a compliance issue, not just good practice.

The ICO engaged with more than 30 employers over the past year and wrote to 16 organisations already using automated decision-making in hiring. Based on the findings, all 16 have now committed to making changes after the regulator told them the current state of play wasn't good enough.

The ICO audited AI recruitment tool providers and made nearly 300 recommendations. These are tools employers are buying off the shelf, deploying at scale, and trusting to make consequential decisions about real candidates, often without those candidates knowing an algorithm was involved.

The Data (Use and Access) Act 2025 has widened the legal gateway for automated decisions. Employers can now use ADM without human involvement in certain circumstances. But the ICO is clear: wider legal permissions do not mean lower standards. The safeguards have to come first.

What the ICO now expects from any organisation using ADM in recruitment:

  • Monitor for bias, monthly if possible. Don't wait for a complaint. Ask your vendor what bias testing they've done before you sign anything.
  • Tell candidates AI is being used. Explain how it works in plain language, not buried in a privacy notice.
  • Give candidates a route to challenge. If your AI rejects someone, they have a legal right to request human review. You have to tell them that.

We'd like your views:

  • The ICO says human involvement must be "meaningful" — not just present. What does that actually look like in your organisation, and how would you prove it?
  • If compananies are procuring AI hiring tools, what questions should they be asking vendors about bias testing before signing? Even if they do get answers, can they be verified?
  • Candidates rejected by automated systems may not know automation was involved. At what point does that become a reputational risk, not just a compliance one?
  • Is this better or worse than the old method of throwing CVs in the bin with a handwritten cover note in blue or black ink in the bin when a role was massively oversubscribed?

2 responses from the Newspage community

Copy all

Star Quote
Copy

Meaningful oversight means the human can say no to the algorithm. There must be enough time, context, and authority to actually do it. In most hiring workflows right now, they don't. They're reviewing an AI-ranked shortlist under deadline pressure, with no visibility into why candidates below the cut were excluded.

Firms must ask vendors for the training data demographics, the false negative rate by protected characteristic, and the last independent audit date. If the vendor can't answer all three, you don't have enough information to deploy the tool lawfully, let alone confidently. Verification is harder, but a vendor unwilling to share audit results is telling you something important before you've signed anything.

As for the blue-ink-cover-note bin protocol? At least that system was honest about its limitations. Everyone knew it was arbitrary. The risk with AI screening is that it looks rigorous when it is anything but.
Copy

Meaningful like any legal term open to interpretation without exact definition, typical regulators.

Automated AI rejections for candidates may be preferable for the candidates the current common situation of no reply.

The recruitment business seems to be an escalating arms race on both sides ie candidates applying by the click of the button means the volume application increases for employers to handle.

I know of at least one recruitment agency offering AI systems for employers, basically outsourcing the compliance headaches.