AI Assurance Institute Logo AI Assurance Institute

When Unsuccessful Candidates Can Bring Claims

AI in Recruitment


AI Risk Management

Being rejected for a job is common. Not every rejection is unlawful. Claims arise when a candidate can show that the selection process discriminated against them because of a protected characteristic - such as age, race, sex or disability - or that an automated system produced a discriminatory effect that the employer cannot justify.

AI does not change that basic legal idea. It changes how discrimination can occur and how hard it may be for a candidate to see what happened.

How discrimination claims work in hiring

In broad terms, a candidate may argue:

Direct discrimination

They were treated less favourably because of a protected characteristic. An example is software explicitly programmed to reject applicants over a certain age.

Indirect discrimination / disparate impact

A neutral-looking process disadvantages a protected group, and the employer cannot show the practice is job-related and necessary. An AI ranking model trained on historical hires can fall into this category if it systematically filters out, for example, older applicants or candidates from a particular racial group.

Disability-related claims

Tools that screen people out because of gaps in employment, assistive-technology use, or other disability-related patterns may raise separate issues, depending on the jurisdiction.

The candidate usually needs a path to evidence: what system was used, how it operated, and what effect it had. With AI, that evidence is often inside a vendor platform, which is why documentation, audit rights and transparency matter so much for employers.

The iTutorGroup case - the first major US AI hiring settlement

In 2023, the US Equal Employment Opportunity Commission (EEOC) settled its first AI-related hiring discrimination case with iTutorGroup.

The EEOC alleged that the company's recruitment software was programmed to automatically reject older applicants - women aged 55 and over and men aged 60 and over - and that more than 200 qualified candidates were screened out because of age.

The case was brought under age discrimination law. It did not require a debate about complex machine-learning theory. The allegation was straightforward: the system applied an age filter. That made it a clean example of automated hiring discrimination.

The settlement included payment of $365,000 to affected applicants and obligations to prevent the same practice recurring. iTutorGroup did not admit liability, which is common in settlements, but the case remains the leading resolved federal enforcement action on AI or software-driven hiring bias in the US.

For employers, the lesson is simple. If an automated tool uses a protected characteristic as a hard filter, or is configured in a way that amounts to the same thing, exposure is immediate and easy to explain to a court or regulator.

Age discrimination and fundamental rights

In EU law, age is not only an employment-law category. Article 21 of the Charter of Fundamental Rights of the European Union prohibits discrimination on listed grounds. Age is named in that list, alongside sex, race, disability and the others. Treating a candidate less favourably because of age can therefore be a breach of the Charter right to non-discrimination.

Not every age distinction is automatically unlawful. Under the Employment Equality Directive (2000/78/EC), differences of treatment on grounds of age can be justified if they pursue a legitimate aim and the means are appropriate and necessary. Some retirement or seniority rules fall in that space. A hiring tool that screens people out by age is a different matter. A hard filter of the iTutorGroup type - reject women aged 55 and over, or men aged 60 and over - is direct discrimination on a Charter ground. It is the kind of harm a fundamental rights impact assessment is meant to catch where Article 27 applies.

A private employer is not automatically inside Article 27. That duty applies to bodies governed by public law, private entities providing public services, and the credit and insurance deployers named in Annex III. Public employers, and private bodies delivering public services, often are. Where Article 27 does not apply, age discrimination remains actionable under equality law and relevant under the GDPR. Age can be inferred from a CV, from career length, or from a date of birth field. A ranking model that systematically filters out older applicants can produce the same effect as an explicit age rule even when the word "age" never appears in the configuration.

What candidates need in practice

An unsuccessful candidate who suspects AI was involved typically needs to establish:

In the US, charges are often filed first with the EEOC or a state agency. In other jurisdictions, candidates may go to employment tribunals or equality bodies. The practical barrier is information. Candidates may not know which vendor was used, whether a model ranked them, or why they scored below a threshold. That information asymmetry is one reason regulators and courts have begun scrutinising both employers and, in some cases, the vendors that operate the tools.

GDPR claims sit beside discrimination claims

In the EU, an unsuccessful candidate is not limited to equality law. Screening, ranking and rejection scores are personal data. A candidate can complain to a supervisory authority under Article 77 GDPR, or seek a judicial remedy and compensation under Articles 79 and 82, without first proving discrimination.

Typical GDPR grounds in this setting include:

These routes can run in parallel with an equality claim. A data-protection complaint does not replace a discrimination case. It is another way a candidate can force the organisation to explain the process.

Access requests as the first practical step

Article 15 is often the candidate's first tool. They can ask for their personal data, including the application file, the score or rank, and the categories of data used to produce it. Where Article 22 is engaged, they are also entitled to meaningful information about the logic involved - not source code, but an explanation they can use: what the system was predicting, which types of signal moved the score, and what a human can do about the result.

The employer is the controller and must answer. The vendor is usually a processor and must assist under Article 28. If the employer cannot retrieve a score or an explanation because the vendor will not release it, that is the employer's problem, not the candidate's. Trade-secret arguments can limit model detail. They do not cancel the right of access to the candidate's own data.

In practice, many claims start here. Once the candidate has the score, the vendor name and a description of the filter, the information asymmetry that currently protects the process begins to close.

Fundamental rights and the EU AI Act

Annex III of the AI Act treats many recruitment and selection systems as high-risk because they affect access to work, equal treatment and dignity - rights in the Charter of Fundamental Rights, including non-discrimination, protection of personal data, and the right to engage in work. High-risk use brings deployer duties under Article 26: follow the instructions for use, assign competent human oversight, monitor operation, and keep logs under the deployer's control.

Article 27 requires a fundamental rights impact assessment before first use for specified deployers of Annex III systems: bodies governed by public law, private entities providing public services, and deployers of the credit and insurance systems in Annex III, points 5(b) and 5(c). A private employer is not automatically inside Article 27. Public employers, and private bodies delivering public services, often are.

Where a FRIA is required, it should identify the people who may be filtered out and the residual risk after oversight. Where it is not required, equality law, the GDPR and Article 26 still apply. A candidate who cannot see how they were scored is exactly the information problem the later articles in this series address.

Why this matters beyond the US

Even for organisations outside the United States, iTutorGroup is a warning signal. It shows that regulators are prepared to treat software-enabled screening as a hiring practice subject to discrimination law, and that "the system did it" is not a defence when the system was configured or chosen by the organisation.

It also shows that the clearest cases are not always about opaque deep learning. Sometimes the risk is a simple rule embedded in a workflow. The harder cases - statistical bias in complex ranking models, vendor platforms used by many employers, and questions of who is legally responsible - are the territory of ongoing litigation such as Mobley v. Workday.