Recruitment algorithms rarely need a date of birth field to act on age. Thirty years of programming, audit, risk or operations experience on a CV is enough. The model treats a long career as a signal, infers that the candidate is older, and drops the score. The person never reaches a human recruiter. The organisation thinks it has optimised hiring. What it has often done is filter out the people who know how to keep AI systems under control.
This is not only a fairness problem. It is a capability problem for the AI community. Safe systems need people who have designed controls, investigated failures, written code that had to run in production, and sat in front of auditors. Those skills accumulate over decades. A screening engine that treats that history as a defect removes the teachers the next generation of AI practitioners needs.
How the proxy works
Most hiring models do not "understand" a career. They look for patterns that predicted hire or interview in past data. Common features include years of experience, number of roles, graduation year, first job date, career breaks, and how closely the CV language matches a junior or mid-level job description.
Years of experience is a close proxy for age. A candidate with three decades in software, quality management, information security or internal audit is statistically older than a candidate with five years. If the training data favoured shorter, linear careers, or if the role was specified as "high energy" or "early career" without a genuine job-related reason, the model learns to penalise the long CV. The word age never appears. The effect is the same as an age filter.
That pattern was set out earlier in this series: tidy tenure and familiar titles score well; long or atypical careers score poorly, even when the person is qualified. Age-specific hard filters, as in the iTutorGroup case, make the same decision in the open. Proxy scoring makes it quietly.
Why this is a fundamental-rights issue as well as a hiring issue
Article 21 of the Charter of Fundamental Rights of the European Union lists age as a prohibited ground of discrimination. Treating someone less favourably because they are older can therefore be a breach of that right. Under the Employment Equality Directive (2000/78/EC), some age-related differences can be justified if they pursue a legitimate aim and the means are appropriate and necessary. Screening people out because a model has inferred age from career length is not that kind of rule. It is a selection practice that needs a job-related justification the organisation can evidence.
Where the tool is a high-risk recruitment system under Annex III of the AI Act, deployer duties under Article 26 still apply: competent human oversight, monitoring, and logs under the deployer's control. Article 27 requires a fundamental rights impact assessment only for the deployers the Act names - bodies governed by public law, private entities providing public services, and the credit and insurance uses in Annex III, points 5(b) and 5(c). A private employer is not automatically inside Article 27. Equality law and the GDPR still apply. Age inferred from a CV is personal data. An automatic rejection based on that inference can engage Article 22 if no human exercises real judgement.
What the AI field actually needs from long careers
Building and operating AI systems is not only model training. It is also the work that sits around the model: specifying intended purpose, setting risk appetite, writing and testing controls, governing data, handling change, investigating incidents, and showing an auditor or a regulator what happened. That work has names in the standards and in the AI Act. It includes:
- programming and systems engineering that has been through production failures, not only notebooks and prototypes
- risk management - identifying reasonably foreseeable harm, residual risk, and treatment that can be operated, not only described
- internal control and quality management, including the disciplines in EN 18286 and ISO/IEC 42001: document control, competence, change control, monitoring and CAPA
- information security, cybersecurity and resilience, including the ability to recognise poisoning, drift and access failures
- data governance and privacy operations, including lawful basis, DPIA practice and answering access requests
- audit, evidence and accountability - the ability to reconstruct why a system was approved and what oversight was exercised
People who have done this work for twenty or thirty years are not interchangeable with people who have only built models. The younger cohort in AI is large and technically strong. It is thinner on the operational and assurance side. That is the shortage organisations already feel when they look for AI quality management, conformity assessment, and people who can sit between engineering and the board.
If those experienced practitioners are filtered out at the first automated gate, two things happen at once. The individual is denied a fair chance of being considered. The organisation, and the wider AI community, lose the people who can teach how controls are designed, how incidents are handled, and how a system is kept inside its intended purpose once it is live.
The cost of treating experience as a defect
A model that penalises thirty years of relevant work is not selecting for safety. It is selecting for a career shape that looks like recent hires. That shape is often shorter, more specialised in current tools, and lighter on regulated-environment experience. For roles in AI assurance, QMS, risk, security and governance, that is the opposite of what the work requires.
The loss is practical:
- fewer people who can review a risk file and say whether the residual risk is actually acceptable
- fewer people who can design human oversight that works under time pressure, not only on a process map
- fewer people who can train junior staff in change control, logging and evidence instead of leaving them to learn from incidents
- a thinner pipeline of mentors for the engineers who will operate high-risk systems under the AI Act and, from December 2026, under the revised Product Liability Directive
Ageing of the specialist workforce makes this sharper. Competence in quality, audit and risk is already concentrated in people closer to retirement. Automated screening that treats their CVs as too long accelerates the gap. The organisation then tries to close it with generic AI-literacy modules. Literacy is necessary. It is not a substitute for people who have run controls in anger.
What organisations should do
If AI is used to screen or rank, treat years of experience as a feature that needs a human rule, not an unsupervised penalty.
- Do not use hard age filters, and do not use career length as a silent substitute for one.
- For assurance, risk, security, QMS and similar roles, treat long relevant tenure as a positive signal unless there is a documented, job-related reason not to.
- Route CVs with substantial relevant experience to a qualified human before any automated rejection.
- Test whether older applicants, or applicants with long careers, are rejected at a higher rate at the automated stage. If they are, the model is not neutral.
- Be able to explain, for an access request or a claim, what the system predicted and whether years of experience moved the score.
That is the same discipline as the rest of this series: know what the tool optimises for, keep a human able to intervene, and hold evidence. Applied to age, it is also how the organisation stops throwing away the people who can make AI systems safer to run.