ICO states human oversight of AI hiring must be meaningful. Tired managers approving an AI shortlist doesn't count.
The ICO published its automated decision-making in recruitment report on 31 March 2026, alongside a consultation on draft guidance open until 29 May. For companies using AI to sift CVs, score assessments, or filter candidates at any stage, this is now a compliance issue, not just good practice.
The ICO engaged with more than 30 employers over the past year and wrote to 16 organisations already using automated decision-making in hiring. Based on the findings, all 16 have now committed to making changes after the regulator told them the current state of play wasn't good enough.
The ICO audited AI recruitment tool providers and made nearly 300 recommendations. These are tools employers are buying off the shelf, deploying at scale, and trusting to make consequential decisions about real candidates, often without those candidates knowing an algorithm was involved.
The Data (Use and Access) Act 2025 has widened the legal gateway for automated decisions. Employers can now use ADM without human involvement in certain circumstances. But the ICO is clear: wider legal permissions do not mean lower standards. The safeguards have to come first.
What the ICO now expects from any organisation using ADM in recruitment:
- Monitor for bias, monthly if possible. Don't wait for a complaint. Ask your vendor what bias testing they've done before you sign anything.
- Tell candidates AI is being used. Explain how it works in plain language, not buried in a privacy notice.
- Give candidates a route to challenge. If your AI rejects someone, they have a legal right to request human review. You have to tell them that.
We'd like your views:
- The ICO says human involvement must be "meaningful" — not just present. What does that actually look like in your organisation, and how would you prove it?
- If compananies are procuring AI hiring tools, what questions should they be asking vendors about bias testing before signing? Even if they do get answers, can they be verified?
- Candidates rejected by automated systems may not know automation was involved. At what point does that become a reputational risk, not just a compliance one?
- Is this better or worse than the old method of throwing CVs in the bin with a handwritten cover note in blue or black ink in the bin when a role was massively oversubscribed?


