AI recruitment tools do not "understand" a career the way an experienced hiring manager might. They look for patterns in data. Those patterns are often useful. They can also be crude. When the model optimises for the wrong signals, highly capable people are filtered out before a human ever reviews their application.
What systems typically optimise for
Most screening and ranking tools are built to predict something the organisation cares about: likelihood of being hired, likelihood of passing an interview, predicted performance, or similarity to people who succeeded in the role before. To do that, they rely on features extracted from CVs, application forms, assessments, and sometimes behavioural or online data.
Common signals include:
Keyword and skills matches
Language in the CV is compared with the job description or a skills taxonomy. Candidates who use different wording for the same experience, or whose expertise cuts across standard labels, can score poorly even when they are qualified.
Career shape and tenure
Models often favour tidy, linear progression, stable employment, and role titles that resemble past hires. Career breaks, career changes, freelance work, entrepreneurship, or time outside formal employment can reduce a score even when the person is strong.
Education and credentials
Certain institutions, degree types, or certification patterns may be weighted heavily if historical hires shared them. This can disadvantage capable candidates from different routes into the profession.
Similarity to previous successful employees
If the training data reflects who was hired and promoted in the past, the model learns to prefer people who look like that group. Where past hiring was narrow or biased, the model can reproduce those patterns at scale.
Engagement and process behaviour
Time spent on an application, completeness of forms, response speed, or performance in gamified tests may be used as proxies for motivation or ability. These proxies are imperfect and can favour some groups over others.
Assessment scores
Video, language, or psychometric tools may convert complex human behaviour into a small set of scores. If the link between those scores and actual job performance is weak, good candidates can be discarded for the wrong reasons.
Why experienced people are especially vulnerable
Experienced candidates often have non-standard profiles. They may have:
- broader, less keyword-dense CVs
- older role titles that do not match current jargon
- periods of consulting, leadership across functions, or industry changes
- fewer recent certifications but deeper practical expertise
- career gaps for family, health, study or economic reasons
A human recruiter can interpret that history. A ranking model trained on neater, more junior, or more homogeneous data may treat it as low fit. The result is a familiar complaint: people with strong track records cannot get to interview, while the system continues to advance candidates who match a narrow template.
Volume hiring makes this worse. When thousands of applications are reduced to a shortlist by automation, the cost of a false rejection is invisible to the employer but very real to the candidate. The organisation only sees the people the model kept.
The appearance of objectivity
Because the process is automated, it can appear neutral. In reality, every model embeds choices: what data was used, what outcome was defined as success, what features were included, and what threshold triggers rejection. If those choices are unexamined, the system can systematically overlook older workers, career-changers, people with disabilities whose CVs look different, or candidates from underrepresented backgrounds - not because a recruiter intended that result, but because the optimisation path led there.
This is the pattern seen in public controversies and legal actions involving automated hiring tools: the system was efficient at filtering, but the basis of the filter was discriminatory or unjustified.
What this means under the GDPR
The signals described above are not abstract model features. They are personal data: CVs, education history, employment gaps, test scores, video or voice assessments, and the ranking or rejection score the system assigns. Inferences the model draws about a person are also personal data. The GDPR applies when the employer is established in the EU or targets candidates in the Union. The AI Act does not replace that law.
Three GDPR issues sit directly on top of how algorithms look at candidates:
- Purpose and fairness of the features - using career gaps, age-correlated tenure, or similarity to past hires as predictors is still processing personal data. The employer needs a lawful basis and must be able to explain why those features are necessary for the stated hiring purpose. Features that proxy protected characteristics raise both GDPR and equality-law problems.
- Automated decisions - if a score auto-rejects a candidate, or if a human only rubber-stamps the ranked list, Article 22 can apply. The person then has a right to human intervention, to express their view, and to contest the outcome. A recruiter who never sees the rejected file is not meaningful review.
- Special category and biometric data - video analysis of faces, voice profiling, or inference of health or disability from a CV or assessment can engage Article 9. A general recruitment notice is not enough for that processing.
A data protection impact assessment under Article 35 will often be required where people are evaluated systematically at scale and access to work is at stake. The DPIA should describe the actual signals the model uses, not only the vendor's product name.
Access requests and the score itself
Under Article 15 a candidate can ask for their personal data. In this setting that includes the application file, the score or rank, and the categories of data used to produce it. Where Article 22 is engaged, they are also entitled to meaningful information about the logic involved.
"Meaningful" is not a copy of the source code. It is an explanation a person can use: what the system was predicting, which types of signal moved the score, and what a human can do about the result. "The model decided" is not an answer.
The employer is the controller and must meet the request. The vendor that hosts the scoring engine is usually a processor and must assist under Article 28. If the contract leaves the employer unable to retrieve a score, a feature list or an explanation, the processing arrangement is not adequate. Trade-secret claims can limit how much model detail is disclosed. They do not cancel the right of access to the candidate's own data and to a usable account of how they were assessed.
Fundamental rights and the EU AI Act
Annex III of the AI Act treats AI systems used in recruitment and selection, and systems used to take decisions affecting terms of work, promotion or termination, as high-risk in the cases the Annex describes. That classification exists because ranking and rejection affect access to work, equal treatment and dignity - rights in the Charter of Fundamental Rights, including non-discrimination, protection of personal data, and the right to engage in work.
High-risk use brings provider duties and deployer duties under Article 26: follow the instructions for use, assign competent human oversight, monitor operation, and keep logs under the deployer's control. An employer using a third-party screening tool is usually the deployer. Changing the intended purpose or substantially modifying the tool can change that role.
Article 27 requires a fundamental rights impact assessment before first use for specified deployers of Annex III systems: bodies governed by public law, private entities providing public services, and deployers of the credit and insurance systems in Annex III, points 5(b) and 5(c). A private employer is not automatically inside Article 27. Public employers, and private bodies delivering public services, often are. Where a FRIA is required, it must look at the real hiring process: who is filtered out by keywords, career shape, credentials or similarity-to-past-hires, and what residual risk remains after oversight and testing.
Where Article 27 does not apply, the fundamental-rights issue does not go away. Equality law, the GDPR and Article 26 still require the organisation to know what the model optimises for, who is disproportionately rejected, and whether a strong but atypical candidate can still reach a human. Those are the same questions leaders should already be asking of the ranking system.
What organisations should take from this
If AI is used to screen or rank, leaders should ask:
- What is the model actually predicting?
- What signals drive a high or low score?
- Who is disproportionately rejected at the automated stage?
- Can a strong but atypical candidate still reach a human review?
- Is there a meaningful way to challenge or override an automated rejection?
Without those answers, the organisation does not really control its hiring process. It has outsourced a critical gate to a system that may be optimising for convenience rather than fair access to opportunity.
The next article looks at what happens when unsuccessful candidates challenge those outcomes - including the first major US enforcement case to reach settlement.