12 September 2026

AI CV screening: the compliance line you cannot cross

Employers told the ICO their AI recruitment tools were decision support; the evidence said they were making solely automated decisions. Here is where the compliance line actually sits.

Most employers who opened their hiring processes to the UK's data protection regulator believed they had built decision support. The regulator read the evidence and disagreed. That single gap — between what a hiring team thinks it has deployed and what a regulator sees when it looks at the logs — is the whole of AI CV screening compliance. In Recruitment rewired, published on 31 March 2026 from voluntary engagement with over 30 employers between March 2025 and January 2026, the ICO's key finding was that "many employers engaging in automated recruitment are likely relying on solely automated decisions" — without meaningful human involvement, and with legal or similarly significant effects on the people affected.

CV screening is the most automated task in hiring and the most legally exposed one. The defensible pattern is not "no agents" — it is an agent that does the volume work while a human owns every reject and advance, with an audit trail that proves it.

What the ICO's evidence actually says about AI CV screening compliance

Employers told the regulator that hiring managers reviewed every score on a dashboard and selected candidates manually, so meaningful human involvement was present. The evidence said otherwise: employers "could not consistently demonstrate how they had mitigated the risk of their hiring managers relying disproportionately on the scores when faced with a high volume of applications", and the ICO "frequently saw evidence suggesting hiring managers were unlikely to review the scores or responses of lower-scoring candidates", according to the report's section on meaningful human involvement.

The worked example in that section is the one to show your talent team. A manager sees red, amber and green scores plus each candidate's answers. Training says review everything. In practice they work the greens, skim some ambers, and glance at reds before rejecting. The ICO's verdict: "The manager has 'rubber-stamped' the 'red' candidates' rejections. This constitutes solely ADM within the scope of article 22." The same requisition can therefore be compliant for the candidate who is hired and non-compliant for the candidate who is rejected.

The scale is not hypothetical. A survey of 1,000 UK HR and talent professionals by the background-checking platform Zinc, cited in the same ICO section, reported that 37% automated rejections entirely. The ICO has written to the employers likely to be carrying out automated decisions with specific recommendations and a set date to act; 16 employers have confirmed they will.

The 2024 audit set the bar for vendors, not just employers

This is the second pass the ICO has made at recruitment AI. On 6 November 2024 it published the outcomes of consensual audits of developers and providers of AI sourcing, screening and selection tools. The audit produced almost 300 recommendations, all of which the companies accepted or partially accepted.

The findings are a checklist for anyone procuring today. Some tools let recruiters filter out candidates with certain protected characteristics. Others inferred gender and ethnicity from a candidate's name rather than asking, which is neither accurate enough for bias monitoring nor lawful without a basis. Several collected far more personal information than necessary and retained it indefinitely to build candidate databases without people's knowledge.

Note who carries the liability. The ICO flags as poor practice employers that point candidates at the vendor's privacy information, because doing so "suggests that accountability for decisions lies with the provider. In reality, accountability lies with the employer using the tool." If you are buying, the same discipline applies as to any agent deployment — see our vendor security questions to ask before signing.

Article 22 and the UK's new Article 22A: where the line sits

Under long-standing UK GDPR guidance, Article 22 permits solely automated decisions with legal or similarly significant effects only where they are necessary for a contract, authorised by domestic law, or based on explicit consent — and requires information, a route to human intervention, and regular checks that the system works as intended.

The Data (Use and Access) Act 2025 renumbered these provisions and sharpened the test. As the ICO's report records, Article 22A of the UK GDPR now states that "a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision". The critical question, per the same section, is whether a human "can exercise real influence over [the] decision before it is applied and has the authority, discretion and competence to alter it". Two consequences follow that most Article 22 automated decision recruitment designs miss:

  • Consistency is the safeguard. "Meaningful human involvement can work as its own safeguard, but it must be applied to every candidate, not just those who score highly."
  • Design-time humans do not count. Specialists configuring the model does not constitute involvement in any individual outcome, "because the design phase happens long before any real-world decisions are made about people".

If you choose to run solely automated decisions instead, Article 22C safeguards apply: the candidate must be informed, able to make representations, able to obtain human intervention, and able to contest the decision.

EU AI Act Annex III employment rules apply from 2 December 2027, not August 2026

In the EU the exposure is product regulation rather than data protection. Annex III point 4(a) classifies as high-risk "AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates". Point 4(b) extends to promotion, termination, task allocation and performance monitoring.

Get the date right, because it moved. The European Commission's implementation timeline now lists 2 August 2026 for the majority of the Act's rules, but 2 December 2027 for high-risk Annex III systems and 2 August 2028 for high-risk AI embedded in regulated products. Teams still planning against August 2026 for EU AI Act Annex III employment obligations are planning against a superseded deadline.

The narrow exit is worth knowing. The Commission's employment guidance turns on whether a system materially influences the outcome of decision-making, and points to the Article 6(3) exemption for narrow procedural tasks — such as organising CV information without assessing candidates, or verifying credentials against official registries — provided the system does not materially shape candidate selection. Scoring and ranking do not qualify. Parsing, deduplicating and routing may. That distinction is the design brief.

The UK and EU are not the only jurisdictions watching

Employers hiring across markets should assume overlapping regimes rather than one. New York City has enforced a bias-audit rule since 5 July 2023: under Local Law 144, as set out by the NYC Department of Consumer and Worker Protection, an employer may not use an automated employment decision tool unless it has been subject to a bias audit within one year of use, the audit information is publicly available, and notice has been given to candidates and employees. That is a published-artefact obligation that lands on whoever operates the tool. For the wider regulatory map, we covered the UK regulators' positions on AI agents separately.

Where an agent genuinely earns its place in the hiring funnel

Split the funnel by whether the work changes a candidate's prospects. Work that does not rank or assess is where agents pay for themselves:

  • Parsing and normalising CVs into structured fields, with the source text retained so a human reads the application, not a summary of it.
  • Enrichment against stated criteria — right to work, certifications, notice period — recorded with provenance, never as an inferred characteristic. The ICO's audit found gender and ethnicity inferred from names; ask candidates directly instead.
  • Scheduling, reminders and candidate comms, including rejection messages a human has authorised.
  • Structured interview note-taking against a fixed scorecard, so human assessors produce comparable evidence.
  • Queue management: surfacing every application to a reviewer in a consistent order, with no colour-coded score inviting a rubber stamp.

What stays human: every reject and every advance. A red flag that makes rejection one click is exactly the pattern the ICO named. A good HR automation agent makes the reject path cost the same attention as the advance path.

What to log so you can prove human involvement

Regulators accept records, not policies. The ICO expects transparency at three distinct points — when information is collected, when a candidate exercises their right of access, and when an automated decision is taken — including "meaningful information about the logic involved and the likely consequences", and noted it did not see substantial evidence of employers providing this or of tool accuracy information, per the report's transparency and safeguards section. Translated into an event log, per candidate and per stage:

  • Which agent action ran, on which model and configuration version, and what it produced.
  • The named human reviewer, what was displayed to them, and how long the record was open.
  • The decision, and whether it departed from the agent's output — your override rate is the honest measure of whether involvement is meaningful.
  • Evidence that review coverage was consistent across the whole cohort, not concentrated on high scorers.
  • Notices served, and every representation, human-intervention request or contest, with its outcome and turnaround.
  • Bias monitoring runs on data candidates supplied themselves, with retention periods actually enforced.

If you cannot produce that per candidate on request, you do not have an audit trail — you have an assumption.

Getting the architecture right the first time

Braivex builds agents that deploy into the systems you already run, with the human decision point and the audit trail designed in rather than retrofitted after a regulator asks. If you are automating a hiring funnel and want the compliance line drawn before the build starts, talk to us.