AI Compliance · Recruitment 24 August 2026

Is AI CV Screening
Legal in the UK?

Yes. There is no law in the United Kingdom that prohibits using software to read, rank or filter job applications, and there is no licence to obtain before you start. That is the honest answer, and it is also why it is the wrong question. The question that decides whether your firm has a problem is narrower and far more awkward: when your tool puts a candidate on the "no" pile, is a human being genuinely making that decision?

Three separate bodies of law bear on AI recruitment screening in the UK, and they do not ask the same thing. Data protection law asks whether a person is meaningfully involved in the decision. Discrimination law asks whether the outcome disadvantages a protected group, and does not care in the slightest how the software works. The EU AI Act asks whether the system is high-risk — and it applies to a UK firm the moment it recruits for a role in the EU.

What follows is what those instruments actually say, quoted from the statutes rather than summarised from someone else's summary of them.

1. The UK rule: it is about human involvement, not about the software

Section 80 of the Data (Use and Access) Act 2025 rewrote the UK's automated decision-making rules, and the new provisions — Articles 22A to 22D of the UK GDPR — have been in force since 5 February 2026.

Two definitions in Article 22A do most of the work. A decision is "based solely on automated processing if there is no meaningful human involvement in the taking of the decision". And a decision is significant if it produces a legal effect for the individual or has a similarly significant effect on them. Rejecting someone's job application clears that second bar comfortably.

So the pivot is "meaningful human involvement", and Article 22A(2) tells you how to test it: you must consider, among other things, the extent to which the decision is reached by means of profiling. That sentence is aimed squarely at the arrangement most firms actually have — a tool scores every applicant, sorts them, and a recruiter works down the list from the top. If the ranking decides who is ever read, the human at the end of it is confirming an outcome rather than taking a decision.

What most commentary gets backwards

You will read a great deal about this change tightening the law. It did the opposite. Under the old rule, significant solely-automated decisions were prohibited by default and permitted only in listed cases. Under Article 22B, that outright restriction now bites only where the decision is based entirely or partly on special category data — health, ethnicity, religion, sexual orientation, trade union membership and the rest of the Article 9(1) list — in which case you need explicit consent, or contractual necessity coupled with a qualifying Article 9(2)(g) basis.

Ordinary solely-automated screening is therefore permitted. It is simply conditional, and Article 22C sets the conditions. Where a significant decision is taken solely by automated means, you must have safeguards that:

  • provide the individual with information about the decision taken about them;
  • enable them to make representations about it;
  • enable them to obtain human intervention from you; and
  • enable them to contest the decision.

Read that list against your careers page. For most firms running an automated sift, the rejected candidate is told nothing, has nowhere to make representations, and has no route to a human. That is the gap — and it is a gap in your process and your privacy notice, not in your software licence.

One thing worth knowing before you build a policy around a fine distinction: Article 22D gives the Secretary of State power to make regulations specifying when there is, or is not, meaningful human involvement. The line is expressly moveable. A screening process that only just qualifies as human-led today is sitting on a definition that can be redrawn by statutory instrument.

2. The Equality Act does not care how the tool works

Data protection compliance is not a defence to a discrimination claim, and this is where firms are most exposed, because the exposure is invisible until someone litigates it.

Section 19 of the Equality Act 2010 makes it indirect discrimination to apply a "provision, criterion or practice" that puts people sharing a protected characteristic at a particular disadvantage, unless you can show it to be a proportionate means of achieving a legitimate aim. The protected characteristics it lists are age, disability, gender reassignment, marriage and civil partnership, race, religion or belief, sex, and sexual orientation.

An automated screening rule is a provision, criterion or practice. If it was tuned on your own historical hiring — the standard way these tools are built — it has learned the pattern of who your firm has hired before, including any skew in that pattern. A model that quietly penalises CV gaps disadvantages people who have taken maternity leave or been ill. A model that rewards a particular phrasing of experience can track first language, and therefore national origin.

Two consequences follow, and both catch people out. There is no "the software did it" defence — you applied the criterion, and the burden of showing it was proportionate is yours. And satisfying every Article 22C safeguard does not help you here: a discriminatory outcome that the candidate was properly told about, and could contest, is still a discriminatory outcome.

The practical implication is unglamorous. If you cannot say what your tool weights and you have never tested its outcomes across protected groups, you cannot mount the proportionality defence the statute requires — because you do not know what you would be defending.

3. The EU AI Act, if you hire into the EU at all

A UK firm advertising a role based in Dublin, Madrid or Berlin is inside this regime. It is not a question of where your office is.

Recruitment screening is not merely implied to be high-risk — it is named. Annex III, point 4(a) covers AI systems intended to be used for the recruitment or selection of natural persons, "in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates". That is a description of CV screening written into the instrument itself. High-risk obligations for Annex III systems apply from 2 December 2027.

There is an escape hatch in Article 6(3): an Annex III system is not high-risk where it does not pose a significant risk of harm — because it performs a narrow procedural task, improves the result of completed human work, detects deviations from prior decision-making without replacing the human assessment, or performs a preparatory task. Vendors know this provision well and you will hear it quoted at you.

Read the sentence that closes it. "Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons." Scoring, ranking or evaluating individual candidates is profiling. For the overwhelming majority of CV screening tools, the derogation is shut — and a provider claiming otherwise must document that assessment before the system goes on the market and register it under Article 49(2).

You are almost certainly a deployer, not a provider

This distinction is worth getting right, because most published advice blurs it and then hands you the wrong list of obligations. If you bought the tool, you are a deployer. The conformity assessments, technical documentation and CE marking sit with the provider who built it. Article 26 sets out what falls to you, and four items in it are the ones that reach an ordinary recruitment operation:

  • Human oversight by a named, competent person. Article 26(2) requires oversight to be assigned to natural persons who have the necessary competence, training and authority. Someone with no power to overturn the tool's output does not satisfy this.
  • Input data that is relevant and representative. Where you control the input data, Article 26(4) makes that your responsibility — which, for screening, means the job criteria and any historical data you supply.
  • Logs kept for at least six months. Article 26(6), to the extent the logs are under your control.
  • Tell the workforce first. Article 26(7) requires employers to inform workers' representatives and affected workers before putting a high-risk AI system into service at the workplace.

And the candidate has a right of their own. Under Article 86, a person affected by a decision the deployer took on the basis of a high-risk system's output, where it produces legal or similarly significant effects they consider adverse, may require clear and meaningful explanations of the role the AI system played in the decision and the main elements of the decision taken. "The system scored you below the threshold" is not that explanation.

On penalties, be careful with the figures you have probably seen quoted. A serious breach of UK data protection law carries £17.5 million or 4% of global annual turnover, whichever is higher. Breaching the EU AI Act's high-risk obligations carries €15 million or 3% of global annual turnover, whichever is LOWER for a small or medium business — in practice 3% of turnover.

The two regimes size a fine in opposite directions, which is the detail most coverage gets wrong. UK data protection law takes the higher of the cash ceiling and the percentage; the EU AI Act does the same for large undertakings but inverts it for small and medium businesses, so an SME is capped at the lower figure. That is not a technicality for readers of this article — almost every firm running a recruitment sift is an SME, and the headline number quoted at them is the one that does not apply.

The questions to ask before your next hiring round

None of this requires a programme of work to begin. Ask these five questions of your own process and count the confident answers:

  • If your screening tool ranks candidates, does anyone ever read the applications it placed at the bottom — or is the ranking the decision?
  • Can the person exercising oversight actually overturn the tool's output, and do they know they are permitted to?
  • Does a rejected candidate get told an automated process was involved, and given a route to a human who will look again?
  • Do you know what your tool weights, and has anyone tested its outcomes across age, sex, race and disability?
  • Do you recruit for any role based in the EU?

Two or more uncertain answers and the tool is deciding more than your firm intends. That is a governance problem rather than a technology problem, and the fix is a written position on where the human decision sits, safeguards a candidate can actually use, and evidence you tested the outcome — all of which is dramatically cheaper to put in place before a candidate asks than after.

This article explains what the legislation says. It is not legal advice, and how these rules apply to a particular hiring process depends on facts specific to that firm.

Find out where your hiring process stands

Our free AI compliance guide for HR teams and consultancies walks through automated decision-making, the safeguards that have to be in place, and the recruitment tools that most often trigger them — with no charge and no call required.

Get the free HR compliance guide →
Call Now Claim Your Free Audit