Artificial intelligence is now part of mainstream hiring. Many organisations no longer rely only on recruiters reading every CV and scheduling every interview by hand. Instead, software helps find candidates, rank applications, assess skills, and move people through the hiring funnel. Used well, these tools can speed up recruitment and handle large volumes of applications. Used poorly, they can screen out qualified people and create legal and reputational risk.
This article explains how AI is typically used in recruitment, so the later articles on bias, candidate claims, liability and regulation rest on a clear operational picture.
Where AI sits in the hiring process
AI tools appear at several stages:
Sourcing
Systems search job boards, professional networks and internal databases to find possible candidates. They may rank profiles by predicted fit, suggest passive candidates, or target adverts at groups the model considers likely to apply or succeed.
Screening and shortlisting
This is the most common and most sensitive use. Algorithms score or rank applications based on CVs, application forms, questionnaires or other data. Some tools automatically reject candidates below a threshold before a human sees the file. Others present a ranked list and leave the decision to a recruiter.
Skills and suitability assessment
AI may power online tests, game-based assessments, video interview analysis, or written-response scoring. Some systems claim to measure communication, personality traits, or job-related competencies from speech, facial movement, or language patterns. These uses are particularly controversial because the link between the signal and job performance is often contested.
Interview support and scheduling
Chatbots answer candidate questions, collect information, and book interviews. Some tools summarise interviews or suggest follow-up questions. The final hiring decision is still usually human, but the information the human sees may already have been filtered or shaped by AI.
Internal mobility and workforce decisions
Similar techniques are sometimes used for promotions, internal job matching, or identifying employees for specific opportunities. The same fairness and accountability issues can arise.
Why organisations adopt these tools
The drivers are practical. Large employers receive more applications than recruiters can review in depth. AI promises consistency, speed and lower cost per hire. Vendors market tools as a way to reduce human bias, improve quality of hire, and give hiring managers a shorter, better list.
Those benefits are possible only if the system is designed, tested and overseen properly. If the model is trained on historical hiring data that reflects past bias, or if it optimises for narrow proxies of success, it can reproduce or amplify discrimination while appearing objective.
What "AI" usually means in this context
In recruitment, "AI" often means machine learning models that predict outcomes from patterns in data: who was hired before, who performed well, who looks similar to successful employees, or who matches a job description's language. It can also include rules-based automation, natural language processing for CV parsing, and ranking engines.
Candidates and regulators rarely see the model. They see a platform: an applicant tracking system, an assessment vendor, or a suite such as those offered by major HR technology providers. The important operational point is that decisions with real consequences - rejection, ranking, invitation to interview - may be influenced or made before any human exercises meaningful judgement.
Why this matters for risk and leadership
Recruitment AI is not a back-office efficiency feature only. It affects access to employment. When a system ranks or rejects people at scale, errors and biases scale too. That is why recruitment and selection tools have become a focus of discrimination claims in the United States and why, under the EU AI Act, many AI systems used in recruitment are treated as high-risk.
Personal data and the GDPR
Every recruitment AI system that uses CVs, application forms, test scores, video, voice or similar material is processing personal data. The GDPR applies to that processing when the organisation is established in the EU or targets candidates in the Union. The AI Act does not replace those duties. It sits beside them.
Typical GDPR issues in AI hiring include:
- Purpose and legal basis - screening for a stated vacancy is not the same as building a standing talent pool, sharing data with a vendor for model improvement, or reusing candidate data for later campaigns.
- Transparency - candidates should be told that automated tools play a role in sourcing, ranking or assessment, and who the vendor is, in line with Articles 13 and 14.
- Automated decisions - Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects. Automatic rejection below a score, with no meaningful human review, can fall in that category. The person then has a right to human intervention, to express their view, and to contest the outcome.
- Special category and biometric data - video analysis of faces, voice profiling, or inference of health, disability or similar characteristics can engage Article 9. Those uses need a specific lawful ground, not only a general recruitment privacy notice.
- Data protection impact assessment - Article 35 will often apply where the organisation systematically evaluates people at scale, uses new technology, or makes decisions that affect access to work. A DPIA is not optional window-dressing when those criteria are met.
- Vendors - the supplier that hosts the scoring engine is usually a processor, and sometimes more. The contract must say what the vendor may do with candidate data, including whether it may train or improve models.
- Data subject access requests - a candidate can ask for their personal data, including scores, rankings and, where Article 22 is in play, meaningful information about the logic involved. The employer is the controller and must answer. The vendor, as processor, must assist under Article 28. A contract that leaves the employer unable to retrieve a file, a score or an explanation is not an adequate processing arrangement.
A DPIA examines privacy risk. It does not, by itself, answer whether the ranking rule is discriminatory or whether the use is acceptable under the AI Act. Those are separate assessments that should use the same facts.
Fundamental rights and the EU AI Act
Annex III of the AI Act treats AI systems used in recruitment and selection, and systems used to take decisions affecting terms of work, promotion or termination, as high-risk in the cases the Annex describes. That classification exists because the use can affect access to work, equal treatment, and dignity - rights protected in the Charter of Fundamental Rights of the European Union, including non-discrimination, protection of personal data, and the right to engage in work.
High-risk classification brings provider duties (including a quality management system under Article 17) and deployer duties under Article 26: follow the instructions for use, assign competent human oversight, monitor operation, keep logs under the deployer's control, and report serious incidents. An employer that uses a third-party screening tool is usually the deployer. Rebranding the tool, substantially modifying it, or changing its intended purpose can change that role under Article 25.
Article 27 requires a fundamental rights impact assessment before first use of specified high-risk systems. That duty applies to deployers of Annex III systems who are bodies governed by public law, private entities providing public services, or deployers of the credit and insurance systems listed in Annex III, points 5(b) and 5(c). A private employer using recruitment AI is not automatically inside Article 27. Public employers, and private bodies delivering public services, often are. Where Article 27 applies, the FRIA must describe the real hiring process, who is affected, specific risks of harm, human oversight, and what happens if those risks materialise. A previous assessment, or the provider's documentation, is not enough if the process or the people affected are different.
Where Article 27 does not apply, fundamental-rights risk does not disappear. Equality law, the GDPR and Article 26 still require the organisation to know what the system does to people, to keep a human able to intervene, and to hold evidence of how screening was controlled. The later articles in this series look at bias in the model, candidate claims, vendor liability, and how the AI Act and the Product Liability Directive meet in this same hiring process.
Understanding how the tools are used is the first step. The next question is more uncomfortable: what do these systems actually optimise for, and how do experienced, highly qualified people end up overlooked?