Two authoritative UK sources set the regulatory baseline for AI in hiring: GOV.UK's "Responsible AI in Recruitment" guidance (published 25 March 2024) and the ICO's "Guidance on AI and data protection" (last updated 15 March 2023). A 2026 ICO blog post reinforces the central principle: automated decision making in recruitment can streamline the process, but only with the right safeguards in place.
This document turns that regulatory backbone into a working decision matrix for UK HR teams.
"Automation" means a system handles a task that a person would otherwise do manually, such as scheduling, sending a reminder, or transcribing an interview. "Automated decision making" (ADM) under UK GDPR is narrower and more serious: a system produces an outcome that directly determines whether a candidate advances or is rejected, with no meaningful human review before that outcome takes effect.
To classify a step, answer three questions:
If the answer to question 2 is "nobody" and question 3 is "adverse effect," the step is likely ADM and carries the highest compliance obligations. Re-run this classification any time a vendor changes their model or scoring methodology, or when you move the tool to a different job family.
| Funnel step | Example automation | ADM or decision support? | Risk level |
|---|---|---|---|
| Job ad distribution / targeting | Programmatic ad placement, audience targeting | Decision support | Low |
| CV / keyword filtering | Keyword match, formatting parse | Decision support if a human reviews all outputs; ADM if auto-rejected | Low to medium |
| Candidate intake chat | AI-driven conversational screening (e.g. Selection Lab SmartChat, which responds within 10 seconds via webchat or WhatsApp) | Decision support; results surface in the ATS for recruiter review | Low to medium |
| Automated scoring / ranking | Psychometric or skills score, ranked shortlist | Decision support if the recruiter reviews; ADM if the ranking auto-removes candidates | Medium |
| Pass/fail triage | Threshold-based auto-reject or auto-advance | ADM | High |
| Assessment proctoring | Flagging unusual behaviour during an online test | Decision support; a human must review the flags | Medium |
| Interview transcription / summarisation | AI note-taking, summary generation | Decision support | Low |
| Match recommendations | "Best fit" candidate suggestions to the hiring manager | Decision support | Medium |
| Shortlist selection | System-generated final shortlist without human review | ADM | High |
| Offer decision | Any automation that determines the final hire/reject | ADM | High |
The two high-risk rows (pass/fail triage and shortlist/offer decisions) require explicit legal basis under UK GDPR, a Data Protection Impact Assessment (DPIA), candidate transparency notices, and a documented route to human review and challenge before any outcome is applied.
High-risk indicators (any one of these should escalate your classification):
Controls by risk level:
Under the ICO's AI and data protection guidance, lawfulness, fairness, transparency, and statistical accuracy are non-negotiable regardless of risk level. The GOV.UK responsible AI in recruitment guide extends this to procurement assurance: governance obligations begin before a vendor contract is signed.
Where privacy-by-design is built into the tooling, the control burden on HR teams is lower. Selection Lab, for example, stores personal data in Frankfurt, applies GDPR-aligned consent and retention configurations, and uses local LLMs to strip personal identifiers from conversation data before processing. Results are shown to candidates first. These architectural choices reduce the remediation surface area but do not replace the human oversight requirement.
Ask these before signing any AI recruitment contract:
Any vendor unable to answer the first two questions with specifics should be treated as high-risk regardless of their marketing materials.
1. Stop. Disable the automation step or switch it to read-only/support mode immediately. Do not let additional candidates pass through an unreviewed ADM flow.
2. Triage. Identify the affected candidate cohort and time window. Assess which decisions may have produced adverse effects without adequate human review. Flag those decisions for manual reprocessing.
3. Rectify. Issue updated transparency information to affected candidates and provide a clear route to request human review of their outcome. Rerun flagged decisions with proper oversight documented.
4. Remediate the vendor relationship. Require written confirmation of updated technical controls, a revised DPIA, and evidence of bias/accuracy testing. Attach these as contractual deliverables with a deadline.
5. Document internally. Update your risk register, relevant SOPs, and any training materials. If the non-compliance involves a large cohort or a systemic failure, schedule advice from employment law or data protection counsel before engaging with the ICO.
Consistent application of this matrix across vendors and job families is what converts the GOV.UK and ICO guidance from policy reading into operational HR practice.
Automation means a system handles a task a person would otherwise do manually, such as scheduling or transcribing an interview. Automated decision making (ADM) under UK GDPR is narrower. A system produces an outcome that directly determines whether a candidate advances or is rejected, with no meaningful human review before that outcome takes effect.
It depends on what happens with the output. If a recruiter reviews every result before a candidate is affected, keyword filtering is decision support. If the system rejects candidates automatically without a human checkpoint, it is ADM and carries the highest compliance obligations.
Threshold-based pass/fail triage, system-generated shortlists without human review, and any automation that determines the final hire or reject decision. These require an explicit legal basis, a Data Protection Impact Assessment, candidate transparency notices and a documented route to human review and challenge.
Start with two questions. Which steps in their workflow directly determine candidate advancement or rejection, and what human checkpoint exists before that output is applied? And how is meaningful human oversight implemented technically, and how can they evidence it to a regulator? A vendor who cannot answer these with specifics should be treated as high-risk.
Stop the automation or switch it to support mode, identify the affected candidates and time window, issue updated transparency information with a route to human review, require the vendor to confirm updated controls and a revised DPIA, and update your risk register and procedures. For large cohorts, take legal advice before engaging with the ICO.

Two authoritative UK sources set the regulatory baseline for AI in hiring: GOV.UK's "Responsible AI in Recruitment" guidance (published 25 March 2024) and the ICO's "Guidance on AI and data protection" (last updated 15 March 2023). A 2026 ICO blog post reinforces the central principle: automated decision making in recruitment can streamline the process, but only with the right safeguards in place.
This document turns that regulatory backbone into a working decision matrix for UK HR teams.
"Automation" means a system handles a task that a person would otherwise do manually, such as scheduling, sending a reminder, or transcribing an interview. "Automated decision making" (ADM) under UK GDPR is narrower and more serious: a system produces an outcome that directly determines whether a candidate advances or is rejected, with no meaningful human review before that outcome takes effect.
To classify a step, answer three questions:
If the answer to question 2 is "nobody" and question 3 is "adverse effect," the step is likely ADM and carries the highest compliance obligations. Re-run this classification any time a vendor changes their model or scoring methodology, or when you move the tool to a different job family.
| Funnel step | Example automation | ADM or decision support? | Risk level |
|---|---|---|---|
| Job ad distribution / targeting | Programmatic ad placement, audience targeting | Decision support | Low |
| CV / keyword filtering | Keyword match, formatting parse | Decision support if a human reviews all outputs; ADM if auto-rejected | Low to medium |
| Candidate intake chat | AI-driven conversational screening (e.g. Selection Lab SmartChat, which responds within 10 seconds via webchat or WhatsApp) | Decision support; results surface in the ATS for recruiter review | Low to medium |
| Automated scoring / ranking | Psychometric or skills score, ranked shortlist | Decision support if the recruiter reviews; ADM if the ranking auto-removes candidates | Medium |
| Pass/fail triage | Threshold-based auto-reject or auto-advance | ADM | High |
| Assessment proctoring | Flagging unusual behaviour during an online test | Decision support; a human must review the flags | Medium |
| Interview transcription / summarisation | AI note-taking, summary generation | Decision support | Low |
| Match recommendations | "Best fit" candidate suggestions to the hiring manager | Decision support | Medium |
| Shortlist selection | System-generated final shortlist without human review | ADM | High |
| Offer decision | Any automation that determines the final hire/reject | ADM | High |
The two high-risk rows (pass/fail triage and shortlist/offer decisions) require explicit legal basis under UK GDPR, a Data Protection Impact Assessment (DPIA), candidate transparency notices, and a documented route to human review and challenge before any outcome is applied.
High-risk indicators (any one of these should escalate your classification):
Controls by risk level:
Under the ICO's AI and data protection guidance, lawfulness, fairness, transparency, and statistical accuracy are non-negotiable regardless of risk level. The GOV.UK responsible AI in recruitment guide extends this to procurement assurance: governance obligations begin before a vendor contract is signed.
Where privacy-by-design is built into the tooling, the control burden on HR teams is lower. Selection Lab, for example, stores personal data in Frankfurt, applies GDPR-aligned consent and retention configurations, and uses local LLMs to strip personal identifiers from conversation data before processing. Results are shown to candidates first. These architectural choices reduce the remediation surface area but do not replace the human oversight requirement.
Ask these before signing any AI recruitment contract:
Any vendor unable to answer the first two questions with specifics should be treated as high-risk regardless of their marketing materials.
1. Stop. Disable the automation step or switch it to read-only/support mode immediately. Do not let additional candidates pass through an unreviewed ADM flow.
2. Triage. Identify the affected candidate cohort and time window. Assess which decisions may have produced adverse effects without adequate human review. Flag those decisions for manual reprocessing.
3. Rectify. Issue updated transparency information to affected candidates and provide a clear route to request human review of their outcome. Rerun flagged decisions with proper oversight documented.
4. Remediate the vendor relationship. Require written confirmation of updated technical controls, a revised DPIA, and evidence of bias/accuracy testing. Attach these as contractual deliverables with a deadline.
5. Document internally. Update your risk register, relevant SOPs, and any training materials. If the non-compliance involves a large cohort or a systemic failure, schedule advice from employment law or data protection counsel before engaging with the ICO.
Consistent application of this matrix across vendors and job families is what converts the GOV.UK and ICO guidance from policy reading into operational HR practice.
Automation means a system handles a task a person would otherwise do manually, such as scheduling or transcribing an interview. Automated decision making (ADM) under UK GDPR is narrower. A system produces an outcome that directly determines whether a candidate advances or is rejected, with no meaningful human review before that outcome takes effect.
It depends on what happens with the output. If a recruiter reviews every result before a candidate is affected, keyword filtering is decision support. If the system rejects candidates automatically without a human checkpoint, it is ADM and carries the highest compliance obligations.
Threshold-based pass/fail triage, system-generated shortlists without human review, and any automation that determines the final hire or reject decision. These require an explicit legal basis, a Data Protection Impact Assessment, candidate transparency notices and a documented route to human review and challenge.
Start with two questions. Which steps in their workflow directly determine candidate advancement or rejection, and what human checkpoint exists before that output is applied? And how is meaningful human oversight implemented technically, and how can they evidence it to a regulator? A vendor who cannot answer these with specifics should be treated as high-risk.
Stop the automation or switch it to support mode, identify the affected candidates and time window, issue updated transparency information with a route to human review, require the vendor to confirm updated controls and a revised DPIA, and update your risk register and procedures. For large cohorts, take legal advice before engaging with the ICO.