
Last updated: August 15, 2026
Important: This article provides general information, not legal advice. Automated-hiring rules depend on the employer, the tool, the role, the candidate’s location, and where the work will be performed. Candidates facing a deadline or possible discrimination should contact the relevant regulator, union, or qualified lawyer promptly.
Artificial intelligence can now help decide which job ad you see, how your résumé is parsed, whether you advance to an interview, and how an assessment is scored. But “AI recruiting” is not one technology, and an applicant tracking system is not automatically an autonomous rejection machine. Some systems primarily store applications and manage workflow; others match skills, rank candidates, score tests, summarize interviews, or recommend a next step. Employers also configure knockout questions and thresholds themselves.
That distinction matters. A scheduling chatbot presents very different risks from a model that assigns every applicant a “fit” score. It also matters legally: a vendor’s software does not relieve the employer of its anti-discrimination, accessibility, privacy, or recordkeeping duties.
The short version
- AI can make hiring faster and more consistent, but consistency is not the same as fairness or job relevance.
- Bias can enter through historical data, the target being predicted, proxy variables, inaccessible tests, recruiter settings, or the way human reviewers rely on a score.
- In the United States, existing federal civil-rights laws already apply to automated selection tools. Several states and cities add notice, audit, or recordkeeping requirements.
- In the EU, the GDPR applies now. The AI Act already prohibits most workplace emotion recognition, while the main high-risk obligations for recruitment systems are scheduled for December 2, 2027.
- Applicants should ask what is being assessed, request accommodations early, preserve records, and seek genuine human review where the law or employer process allows it.
- HR teams should validate the tool for the actual job and local workflow, monitor outcomes by stage and group, and never treat a vendor badge or generic audit as a substitute for their own controls.
Where automation enters the hiring process
| Stage | What the system may do | Examples of tools or product categories | Main questions to ask |
|---|---|---|---|
| Advertising and sourcing | Choose an audience, search profiles, recommend prospects, or predict who may respond. | Recruiting ad platforms, talent CRMs, sourcing and recommendation products. | Who never sees the opportunity? Which profile data or inferred traits shape delivery? |
| Application management | Collect and parse résumés, track stages, apply recruiter-configured rules, and store notes. | Greenhouse, iCIMS, Workday Recruiting, and other ATS products. | Is the tool only organizing records, or is it also filtering, ranking, or recommending? |
| Matching and ranking | Compare skills and experience with a job profile, grade candidates, or prioritize a recruiter’s queue. | Workday Talent Acquisition and products such as Workday HiredScore; AI capabilities also appear in many ATS suites. | What outcome was the model trained to predict? Can a recruiter see the basis for a score and override it? |
| Pre-employment assessment | Score cognitive, behavioral, situational-judgment, personality, language, or job-simulation exercises. | SHL assessments, Harver, Criteria, and similar platforms. | Does the test measure an essential job capability? Is it validated and accessible for this role? |
| Recorded interview | Capture answers, transcribe them, score selected competencies, or help a human reviewer compare responses. | HireVue and other asynchronous interview platforms. | Are words, voice, video, gaze, facial movements, or metadata analyzed? Is an alternative available? |
| Technical testing and proctoring | Run coding tasks, score tests, detect similarities, and flag behavior for integrity review. | HackerRank, Codility, and other skills platforms. | What is automatically scored or merely flagged? What accessibility and appeal process exists? |
| Generative assistance | Draft job descriptions, summarize résumés, generate interview questions, or write recruiter notes. | Built-in copilots and general-purpose language models. | Are factual claims checked? Are protected or sensitive data sent to a model? Are prompts and versions logged? |
An ATS is not automatically AI
An applicant tracking system is fundamentally a database and workflow platform. It may collect applications, keep status records, schedule interviews, and centralize feedback. Some ATS products also offer matching, ranking, chatbots, or generative features. A fast rejection can come from an AI score, but it can also come from a recruiter-configured knockout question, such as lack of work authorization, a required license, location, or willingness to work a stated schedule.
This is why “beat the ATS” advice is often too simplistic. There is no universal résumé score or secret keyword formula shared by all employers. A better strategy is to use truthful, recognizable language from the job description, spell out important acronyms at least once, use conventional headings, and make the document easy to parse without hiding keywords or misrepresenting experience.
Video assessment claims must be checked product by product
Older descriptions of AI interviews often say every platform reads facial expressions, eye contact, or “micro-expressions.” That is no longer an accurate blanket statement. HireVue says its current video assessments analyze the transcript of a response rather than facial analysis, video, or audio, and the company stopped using visual analysis in new assessments in 2020. Other tools may use different inputs. Candidates and employers should verify the exact product, configuration, data fields, and model version instead of relying on a category label.
How bias can enter an automated hiring system
- The target is wrong. A model trained to imitate past hiring decisions may reproduce the organization’s old preferences. A model trained to predict retention may penalize people whose past employment patterns reflect disability, caregiving, layoffs, or unequal opportunity.
- The data are incomplete or unrepresentative. Performance data may cover only people previously hired, excluding qualified applicants who never had a chance to demonstrate performance.
- Proxy variables stand in for protected traits. Names, schools, postal codes, career gaps, language patterns, and online behavior can correlate with race, sex, age, disability, socioeconomic status, or national origin even when the model never receives a field labeled with that trait.
- The assessment is not job-related. A reliable score can still measure the wrong construct. A game, personality inventory, or speech measure needs evidence connecting it to important work behaviors for the specific role.
- The interface creates unequal barriers. Timed tests, mouse-only controls, uncaptioned video, speech analysis, and remote proctoring can screen out people with disabilities or people using assistive technology.
- Employer settings change the risk. Thresholds, knockout questions, job profiles, and weighting choices may be configured locally. A vendor’s general validation report does not validate every customer’s implementation.
- Humans over-trust the output. A nominal “human in the loop” adds little protection if reviewers lack time, training, authority, or information to question the score.
- The system changes after testing. New training data, prompts, model versions, integrations, or job requirements can invalidate earlier results.
The U.S. National Institute of Standards and Technology treats bias as a socio-technical problem, not merely a defective data point. Its Special Publication 1270 on identifying and managing AI bias emphasizes that organizational processes, human decisions, and social context matter alongside model design.
What the research actually shows
| Source | What it found | How to interpret it |
|---|---|---|
| Stanford HAI, 2026 | Researchers studied about 4 million applications from 3.4 million people across 1,700 postings, 150 employers, and one third-party screening vendor. Twenty-six percent of Black applicants and 15% of Asian applicants applied to positions where recommendation rates triggered the four-fifths adverse-impact flag. The authors estimated 40,000 additional applications would have advanced if those groups had been recommended at the most-favored group’s rate. | This is rare large-scale evidence from a real system, but it concerns one vendor and observational data. A four-fifths flag is a screening indicator, not by itself a final court finding of unlawful discrimination. |
| An et al., ACL 2024 | In controlled prompting experiments, several language-model settings favored applicants with White-associated names over applicants with Hispanic-associated names. Results varied with prompt templates. | The experiment shows that model output can be sensitive to names and prompt design. It does not measure a named employer’s live hiring process. |
| Raghavan et al., FAccT 2020 | The researchers examined vendor claims and practices around algorithmic employment assessments, highlighting difficult choices about training data, prediction targets, validation, and the meaning of “bias mitigation.” | Fairness cannot be established by a marketing claim or a single metric. Employers need evidence tied to the specific tool, job, population, and workflow. |
| UK ICO recruitment audits, 2024 | The regulator made 296 recommendations and 42 advisory notes. It found examples of insufficient accuracy testing, filters that could exclude protected groups, inaccurate inference of gender or ethnicity from names, excessive data collection, and unclear controller/processor roles. | The audits were consensual snapshots across several providers, not a claim that every tool had every defect. They are strong practical evidence of recurring privacy and governance failures. |
Research also shows why a single pooled fairness number can mislead. A vendor may appear balanced across all jobs while producing large disparities within particular roles. HR teams should therefore monitor at the decision level: by requisition, stage, location, and relevant group, using statistically appropriate methods and sufficient sample sizes.
Three cases that changed the conversation
| Case | What happened | Legal status and lesson |
|---|---|---|
| Amazon experimental recruiting model Internal experiment | Reuters reported in 2018 that an experimental model trained on ten years of résumés penalized terms such as “women’s” and downgraded graduates of two women’s colleges. Amazon disbanded the project team. Sources told Reuters that recruiters viewed recommendations but did not rely solely on them; Amazon said the tool was never used to evaluate candidates. | This was not a court judgment. It remains a useful example of how historical patterns and proxy terms can survive attempts to remove an obvious protected signal. |
| EEOC v. iTutorGroup Settled | The EEOC alleged that application software automatically rejected women aged 55 or older and men aged 60 or older. The company agreed to pay $365,000 to more than 200 affected applicants, plus non-monetary relief. | This is a resolved federal enforcement case. It also involved U.S.-based tutors working remotely, showing that online hiring and cross-border business operations do not erase U.S. anti-discrimination obligations. |
| Mobley v. Workday Pending litigation | Applicants allege that Workday’s algorithmic screening tools discriminated based on race, age, and disability. A federal court held that the plaintiffs plausibly alleged that a vendor could be liable as an employer’s agent when delegated traditional hiring functions. The EEOC supported that agency theory in an amicus brief. The litigation continued in 2026. | These remain allegations, not a final finding that Workday’s products discriminated. Workday denies the claims and says its AI does not make hiring decisions. The procedural rulings nevertheless warn employers and vendors that outsourcing a selection function may not outsource liability. |
The law: what applies in 2026
No single global “AI hiring law” controls every application. Anti-discrimination, disability, privacy, biometric, consumer-protection, and employment rules can overlap. The table below is a practical starting point, not an exhaustive jurisdictional survey.
| Jurisdiction | Status | Core rule relevant to hiring | Official source |
|---|---|---|---|
| United States — federal | In force | Title VII, the ADA, and the ADEA apply to covered employers and selection procedures whether a human or software makes or informs the decision. The ADA may require reasonable accommodation and an alternative assessment method. The four-fifths rule is a rule of thumb for identifying possible adverse impact, not a safe harbor or automatic finding of liability. | EEOC: AI and the ADA; employment tests and selection procedures |
| New York City | Enforced since July 5, 2023 | Local Law 144 restricts use of a covered automated employment decision tool unless an independent bias audit was completed within the prior year, a summary is public, and required notices are given. Scope depends on the tool’s role and the connection to hiring or promotion in New York City; not every automated feature is an AEDT. | NYC Department of Consumer and Worker Protection |
| California | Effective October 1, 2025 | FEHA regulations clarify that automated-decision systems can create unlawful discrimination and that third-party agents may be covered. They also address disability-related inquiries and require covered employment records, including automated-decision data, to be retained for at least four years. | California Civil Rights Department; final regulatory text |
| Illinois | Effective January 1, 2026 | The Illinois Human Rights Act prohibits using AI in recruitment and other employment decisions in a way that subjects people to protected-class discrimination, prohibits using zip codes as a proxy for protected classes, and requires notice of covered AI use. The statute directs the Department of Human Rights to set notice details; employers should check the latest rulemaking rather than rely on an old proposed format. | 775 ILCS 5/2-102(L) |
| Maryland | In force | An employer may not use facial-recognition service technology to create a facial template during an applicant interview without the applicant’s signed consent waiver. | Md. Labor & Employment § 3-717 |
| Colorado | Effective January 1, 2027 | SB 26-189 replaced the earlier framework. For covered automated decision-making technology used in consequential decisions such as employment, it creates developer documentation, deployer notice, recordkeeping, data-correction, and meaningful human-review requirements. The attorney general was still conducting rulemaking in August 2026. | Colorado General Assembly; Colorado Attorney General rulemaking |
| Ontario, Canada | Effective January 1, 2026 | Covered employers with 25 or more employees must disclose in a publicly advertised job posting if they use AI to screen, assess, or select applicants for the position, subject to the Act and regulation’s definitions and exemptions. | Ontario official guide; Employment Standards Act |
| European Union — GDPR | In force | Employers and recruiters need a lawful basis, transparency, data minimization, accuracy, security, retention controls, and processes for data-subject rights. Article 22 restricts solely automated decisions that produce legal or similarly significant effects, subject to limited exceptions and safeguards. Rights and duties depend on the actual processing, not whether a vendor calls it “AI.” | GDPR consolidated text; EDPB automated-decision guidelines |
| European Union — AI Act | Partly in force Main hiring duties: December 2, 2027 | Most AI used to target job ads, analyze or filter applications, or evaluate candidates is listed as high-risk. The main high-risk requirements for Annex III systems are now scheduled for December 2, 2027. Separately, the prohibition on using biometric AI to infer emotions in workplaces generally has applied since February 2, 2025, subject to medical or safety exceptions. | AI Act consolidated through July 27, 2026 |
| United Kingdom | In force; guidance evolving | UK data-protection law changed under the Data (Use and Access) Act 2025. The ICO’s March 2026 guidance says jobseekers subject to automated recruitment decisions should receive notice, fair treatment, an explanation, an opportunity to contest, and human review. Special-category data receives additional protection. | ICO guidance for jobseekers; recruitment and selection guidance |
Remote applications create a location-mapping problem
A remote posting can connect several legal systems: the employer’s headquarters, the hiring entity, the candidate’s residence, the intended work location, and the location where a vendor processes data. HR teams should map all five before choosing notices and controls. Candidates should not assume that “remote” means no local protection. The iTutorGroup settlement involved U.S.-based applicants for fully remote tutoring work, while the EU AI Act can reach some providers or deployers outside the EU when their system’s output is used in the EU.
What job seekers can do
Before applying
- Save the evidence. Keep the job ad, application questions, privacy notice, AI notice, assessment invitation, and the date and time you saw each item. Web pages change.
- Use a readable résumé. Prefer conventional section headings, selectable text, clear dates, and a simple reading order. Test the file by copying its text into a plain-text document. A PDF is often acceptable, but follow the employer’s requested format.
- Use accurate role language. If you genuinely have a required skill, use the recognizable term from the posting and add context and results. Include both the full term and acronym where helpful. Do not paste invisible keywords, copy the entire job description, or claim experience you do not have.
- Review knockout questions carefully. A mistaken answer about authorization, location, schedule, license, or minimum qualification may trigger an immediate rule-based rejection that is unrelated to AI.
- Read the privacy and assessment notice. Look for the vendor, data collected, purpose, retention period, sharing, automated-decision information, accommodation contact, and appeal or human-review process.
- Ask for an accommodation early. Do not wait until a timed test has expired. In the U.S., the EEOC warns that algorithmic tools can unlawfully screen out a person with a disability and says employers should have a reasonable-accommodation process.
Accommodation request template
Subject: Accommodation request for [role / assessment]
Hello [recruiting or accessibility contact],
I am applying for [role]. Because of a disability or medical condition, I am requesting a reasonable accommodation for [assessment or interview]. The current format creates a barrier because [brief functional explanation; a diagnosis is not always necessary]. An effective option would be [extra time, captions, screen-reader-compatible format, keyboard access, breaks, alternative communication method, or human-administered assessment].
Please confirm the confidential process and whether the deadline will be paused while this request is reviewed.
Thank you,
[Name]
During an AI-assisted test or interview
- Confirm which inputs are analyzed. “Video interview” does not tell you whether the system scores only a transcript or also uses audio, video, gaze, or biometric information.
- Ask whether automated scoring determines the result or only supports a human reviewer.
- Use the official technical check, supported browser, and practice environment. Record technical failures and contact support immediately.
- For coding or work-sample tasks, follow the stated policy on external resources and generative AI. Employers use different integrity rules.
- If a proctoring system requests ID, camera access, screen recording, room scans, or biometric data, read the collection and retention notice before proceeding and ask for an alternative if the process is inaccessible or appears inconsistent with the notice.
- Do not try to perform a supposedly “ideal” personality. Answer consistently and truthfully. A process that rewards a hidden stereotype is an employer governance problem, not a puzzle a candidate should have to reverse-engineer.
After an unexplained rejection
- Preserve the rejection, application ID, timestamps, screenshots, test results, platform name, and any accommodation request.
- Ask whether an automated tool made or materially influenced the decision, what data it used, and whether a qualified person can conduct a fresh review.
- Request correction of inaccurate data. Where GDPR, UK law, Colorado’s future law, or another applicable rule provides additional rights, ask for access, explanation, contestation, or human reconsideration in the language of that rule.
- Escalate through the employer’s recruiting, accessibility, privacy, or data-protection contact. A vendor support desk may not control the employment decision.
- If discrimination may be involved, act quickly. The EEOC says a U.S. charge generally must be filed within 180 days, sometimes extended to 300 days; federal applicants generally have a different 45-day counselor process. State, local, union, contractual, and international deadlines differ.
Human-review and data question template
Subject: Request for information and review — application [ID]
Hello [recruiter / privacy contact],
I am requesting information about the processing of my application for [role]:
- Did an automated system score, rank, filter, recommend, or reject my application?
- What system and vendor were used, and what role did the output play?
- What categories of data and job criteria were evaluated?
- Was the decision solely automated, or did a person meaningfully review my application?
- How can I correct inaccurate data or contest the result?
- Can a qualified reviewer reconsider the application without relying solely on the original automated output?
- What is the retention period for my application, assessment, recording, score, and related inferences?
Please treat this as an exercise of any applicable access, correction, contestation, and human-review rights. I would appreciate a response through the process and timeframe required in my jurisdiction.
Thank you,
[Name]
A rejection alone does not prove discrimination, and not every jurisdiction requires an employer to disclose a score or trade-secret information. The purpose of the request is to identify the process, correct errors, and preserve available rights.
An implementation checklist for HR and recruiting teams
1. Inventory every automated decision point
List the product, owner, vendor, model or ruleset, data inputs, output, affected roles, candidate locations, user group, and downstream decision. Include embedded ATS features, spreadsheet scoring, assessment integrations, ad delivery, proctoring, and general-purpose AI used to summarize or rank. A system cannot be governed if procurement does not know it exists.
2. Define the job-related purpose before choosing the tool
Write down the essential work behavior or skill being measured and why the output is necessary. Do not begin with “we have a personality model” and search for a use. For each scored feature, ask whether a less intrusive, more accessible, and less discriminatory method could meet the same need.
3. Demand validation evidence for the actual use
Obtain the technical manual, intended-use limits, validation design, criterion measures, sample characteristics, reliability, subgroup results, accessibility testing, and known limitations. Then validate the local implementation. Evidence for call-center hiring in one country does not automatically validate a modified threshold for managers in another.
4. Test outcomes at the correct level
Monitor selection rates and errors by requisition, stage, location, and legally relevant group, including intersectional groups where lawful and statistically supportable. Review false negatives, not only average accuracy. Treat the four-fifths rule as one diagnostic flag; combine it with sample-size-aware statistical analysis, practical significance, job-relatedness review, and a search for less discriminatory alternatives.
5. Build accessibility and accommodation into the default workflow
Publish an easy-to-find contact, pause deadlines while requests are considered, keep disability information separate from selection data, and offer an alternative that measures the same job requirement. Test with keyboard navigation, screen readers, captions, magnification, color-contrast needs, speech differences, neurodivergence, and intermittent conditions. An alternative that is materially harder or slower is not equivalent merely because it exists.
6. Make human review real
The reviewer should understand the tool’s limits, see relevant source material, have enough time, document reasons, and possess authority to override or disregard the output. Do not ask a recruiter to “confirm” a rejection while showing only the model’s score. Measure override patterns and investigate reviewers who never disagree with the system.
7. Give candidates usable notice and a contest route
Plain-language notice should identify the tool’s role, key data categories, what the output affects, important retention and sharing information, and contacts for accommodations, privacy requests, and review. Meet the most specific local timing and content rules. A generic privacy policy linked at the bottom of a careers page may not satisfy a law requiring advance notice about a particular tool.
8. Control data collection and retention
Collect only what is necessary for the stated purpose. Do not repurpose candidate recordings, scraped profiles, or assessment data for training without a valid legal basis, transparency, and governance. Map controllers, processors, sub-processors, transfers, deletion, security, and litigation holds. In its audit report, the ICO found cases where personal data from millions of profiles were scraped and repurposed without recruiters or candidates understanding the practice.
9. Govern changes like a safety-critical release
Require notice before a vendor changes models, features, training data, prompts, thresholds, or sub-processors. Re-test material changes. Version prompts and evaluation datasets for generative AI. Maintain a rollback plan and suspend use when monitoring, complaints, or incidents indicate unacceptable risk.
10. Keep accountability with the employer
A contract should allocate tasks, but it should not declare the employer free of responsibility. The employer chooses whether and how to use the tool. The Workday litigation illustrates that vendors may also face exposure when they are plausibly delegated traditional hiring functions; it does not remove the employer’s duties.
EU warning: Do not deploy biometric emotion-inference systems in workplace recruiting in the EU unless qualified counsel confirms a narrow medical or safety exception. This prohibition is separate from the delayed December 2027 high-risk-system requirements.
Questions HR should ask every recruiting-technology vendor
| Area | Questions | Evidence to request |
|---|---|---|
| Function | Does the tool store, summarize, score, rank, filter, recommend, or automatically reject? Which features can the customer switch on? | Data-flow map, user guide, configuration list, sample output. |
| Data | What raw, derived, inferred, biometric, device, and third-party data are used? Is customer or candidate data used to train models? | Data dictionary, privacy notice, retention schedule, training-data policy. |
| Job relevance | What construct or outcome is predicted, and how does it connect to essential job performance? | Technical manual, validation studies, job-analysis method, known limitations. |
| Fairness | Which groups, intersectional groups, jobs, languages, and locations were tested? What happens when a disparity appears? | Full audit results, sample sizes, error rates, remediation and re-test records. |
| Accessibility | Which standards and assistive technologies were tested? Can the employer offer an equivalent non-automated or alternative format? | Accessibility conformance report, user testing, accommodation workflow. |
| Human control | Can users understand, challenge, override, and document disagreement with an output? | Explanation interface, audit log, override controls, reviewer training. |
| Change management | How are model, prompt, data, and threshold changes versioned? How much advance notice does the customer receive? | Release policy, model cards, change log, regression-test plan, rollback process. |
| Legal and security | Who is controller or processor? Where is data stored? Which sub-processors and transfers are involved? Who handles access, deletion, complaints, incidents, and regulator requests? | Data-processing agreement, transfer mechanism, security reports, breach terms, records of processing. |
A practical standard: assistance, not abdication
AI does not make recruiting ethical or unethical by itself. A well-designed system can help recruiters apply a structured rubric, find overlooked skills, reduce administrative delay, and document decisions. A badly designed or badly governed system can scale an invalid criterion, obscure accountability, and repeatedly exclude the same people across employers.
The right question is not “Do we use AI?” It is: What decision is being influenced, what evidence supports that influence, who may be harmed, what rights and alternatives exist, and who is accountable when the result is wrong?
For candidates, the most useful response is not to guess a machine’s personality. Make your evidence of job fit readable, ask what the tool does, request accommodations, correct inaccurate data, and seek human reconsideration when appropriate. For employers, the standard should be equally concrete: measure job relevance, test real outcomes, protect candidate data, preserve meaningful human judgment, and stop a system when the evidence does not support continued use.
Official resources and research
United States
- EEOC: Artificial Intelligence and the ADA
- EEOC: Employment Tests and Selection Procedures
- EEOC: Time Limits for Filing a Charge
- NYC DCWP: Automated Employment Decision Tools
- California Civil Rights Council: Rulemaking Actions
- Illinois Human Rights Act § 2-102
- Colorado SB 26-189, as enacted
- Maryland Labor & Employment § 3-717
Europe and national regulators
- EU General Data Protection Regulation
- EU AI Act, consolidated July 27, 2026
- European Data Protection Board: Automated Decision-Making and Profiling Guidelines
- European Data Protection Board: National Supervisory Authorities
- UK ICO: AI in Recruitment Outcomes Report
- France’s CNIL: Recruitment and Data Protection Guide
Canada and research
- Ontario: Requirements for Publicly Advertised Job Postings
- Stanford HAI: AI Hiring Tools Can Yield Racial Bias and Systemic Rejection
- ACL 2024: Do Large Language Models Discriminate in Hiring Decisions?
- FAccT 2020: Mitigating Bias in Algorithmic Hiring
- NIST SP 1270: Identifying and Managing Bias in Artificial Intelligence
Final legal note: This guide cannot determine whether a particular system or decision is lawful. Rights, coverage thresholds, filing periods, remedies, and required notices vary. Obtain advice from a qualified professional for a specific hiring process, complaint, or deployment.
Career coach focused on helping women navigate the tech industry. I’ve worked in product and engineering roles before shifting to coaching full-time. Now I write about imposter syndrome, salary negotiation, and how to grow without burning out.