The UK data regulator says most employers using AI hiring tools are failing to provide genuine human review — and warns enforcement action may follow.

---

The gap between what employers believe about their AI hiring tools and what those tools actually do has never been wider — and Britain's data regulator just put that gap on the record.

On March 31, the UK Information Commissioner's Office published "Recruitment Rewired," a landmark report drawing on evidence from more than 30 employers gathered between March 2025 and January 2026. The central finding is stark: most companies using automated systems to screen, score, and shortlist job candidates are making solely automated decisions about people's livelihoods — even when they insist a human is in the loop.

The ICO's consultation on its accompanying draft guidance closed yesterday, May 29, marking the end of the comment period and the beginning of what privacy lawyers across the UK are calling the accountability phase.

The Rubber-Stamp Problem

The report zeroes in on a practice the ICO considers widespread and legally inadequate. Organisations told investigators their AI recruitment tools served only as decision support, with a human making the final call. But when the regulator looked at how those processes actually worked, the picture was different. In case after case, human review amounted to a hiring manager scanning an AI-generated shortlist and clicking approve — a process the ICO explicitly rejects as meaningful human involvement.

The ICO's own report states that "many employers engaging in automated recruitment are likely relying on solely automated decisions as part of this process," meaning systems "without meaningful human involvement" are making choices that carry "legal or similarly significant effects on people."

Under the regulator's standard, a reviewer must possess the authority, information, and capacity to override or alter an AI-generated outcome before it takes effect. The person must be trained to understand the system's logic, limitations, and risks. Token approval does not count. And critically, a human designing or building the automated system in the first place does not, in the ICO's view, constitute meaningful involvement in the decisions that system later produces.

New Legal Terrain

The timing is not accidental. The Data (Use and Access) Act 2025, which came into force on February 5, 2026, overhauled the UK's approach to automated decision-making. The old framework under Article 22 of the UK GDPR treated such decisions as a general prohibition with narrow exceptions. The new law reframes this as what the ICO describes as "a right of challenge with safeguards" — giving employers more latitude to use automation, provided they meet specific protective conditions.

James Tumbridge, a data protection partner at Keystone Law, noted that the shift creates a two-path choice for employers: "Employers can accept that the process lacks meaningful human involvement" and apply required safeguards, or they can "redesign their processes so that a human plays a genuine role in each decision for each candidate." For companies processing thousands of applications, the first path is often the only practical one — but it triggers a cascade of compliance obligations.

Those obligations include establishing a lawful basis for processing, providing candidates with clear explanations of how automated tools work and what effects they may have, conducting thorough data protection impact assessments, and — perhaps most consequentially — giving every candidate a functioning mechanism to contest automated outcomes and request human review.

Bias, Transparency, and the 16 Letters

The ICO is not limiting its focus to procedural compliance. The report calls for robust, ongoing fairness monitoring that goes well beyond checking a box at deployment. The regulator recommends monthly bias reviews as good practice and expects employers to interrogate their vendors directly about bias-testing methodology and frequency — at the procurement stage and embedded in the contract.

Public trust is a motivating factor. ICO research found that 64 percent of people are concerned employers will rely too heavily on AI, while 61 percent worry it performs worse than human decision-makers when evaluating individual circumstances. The regulator also flagged findings from its own November 2024 audit of AI recruitment tool providers, which uncovered cases where candidate applications were being filtered based on characteristics amounting to protected attributes — a direct pathway to indirect discrimination claims under the Equality Act 2010.

The ICO has already moved beyond advisory mode. It wrote directly to 16 organisations it identified as likely operating outside UK data protection law. All 16 have committed to acting on the regulator's recommendations. The message from the ICO is unambiguous: employers should treat the guidance "as a strong signal that enforcement action may follow where organisations fall short."

A Wider Regulatory Squeeze

The ICO's intervention does not exist in isolation. The House of Commons Business and Trade Committee has launched a parallel inquiry examining how AI is reshaping recruitment, performance management, and workplace decision-making. The Competition and Markets Authority has flagged concerns that shared AI hiring platforms could facilitate the exchange of competitively sensitive information between rival employers. And Parliament has laid regulations requiring the ICO to prepare a dedicated code of practice on AI and automated decision-making.

For employers with European operations, an additional layer arrives in August 2026 when the EU AI Act's high-risk system requirements take effect. The Act classifies recruitment and candidate evaluation tools as high-risk, triggering conformity assessments and human oversight obligations that exceed UK requirements. A tool that satisfies UK GDPR standards may not satisfy the EU framework — the two must be assessed independently.

DLA Piper attorneys Alexa Smith and Rachel de Souza underscored the cross-border complexity, noting that "in the EU, not only the GDPR but also the AI Act will need to be considered, and the interaction between these two frameworks adds a further layer of complexity."

What Comes Next

Nearly 70 percent of UK employers anticipate increasing their use of AI in recruitment over the next five years, according to the Institute of Student Employers. That expansion is now colliding with a regulatory framework that the ICO's own evidence suggests most employers do not yet understand.

The consultation is closed. The 16 letters have been sent. The question is no longer whether the regulator is paying attention — it is whether employers will act before enforcement compels them to.

“Employers can accept the process lacks meaningful human involvement and apply safeguards, or redesign their processes.”
— James Tumbridge, Partner, Keystone Law
30+
Employers reviewed
16
Warning letters sent
64%
Public concerned
~70%
UK employers planning AI expansion