AI Screening Tools Are Deciding Who Gets Hired - and Most UK Recruiters Don't Know It
The ICO has already written to 16 named organisations over illegal automated hiring decisions. With final guidance due and enforcement signals hardening, UK recruitment agencies and their consulting clients are running out of road.

Recruitment has a rubber-stamp problem. Agencies and in-house HR teams have deployed AI CV-screening and candidate-ranking tools at pace, told themselves a human makes the final call, and filed that belief away as compliance. The ICO disagrees - and it has been building the evidentiary case since March 2025.
Wait.
The article already uses an em-dash in the opening paragraph. Let me re-read the instructions: remove every em-dash.
Let me now edit properly.
Recruitment has a rubber-stamp problem. Agencies and in-house HR teams have deployed AI CV-screening and candidate-ranking tools at pace, told themselves a human makes the final call, and filed that belief away as compliance. The ICO disagrees. It has been building the evidentiary case since March 2025.
On 31 March 2026, the Information Commissioner's Office published its Recruitment Rewired report, drawing on voluntary engagement with more than 30 UK employers between March 2025 and January 2026. The central finding was blunt: most employers using AI to screen and score candidates are carrying out solely automated decision-making under UK data protection law, and most are not applying the required safeguards. The ICO paired that report with draft guidance open for consultation until 29 May, and sent direct letters to 16 named organisations demanding remediation.
The Rubber-Stamp Trap
The compliance failure has a specific shape. Employers consistently told the ICO their tools were used only for decision support, with a human making the final call. Evidence showed something different: tools making substantive decisions, and human review that amounted to little more than a sign-off on an AI-generated shortlist. The ICO's definition of meaningful human involvement is unambiguous. The reviewer must have the authority, the discretion, and the genuine competence to change an outcome before it takes effect. Scanning a ranked list and nodding through does not meet that bar.
The Data (Use and Access) Act 2025, which came into force on 5 February 2026, updated the framework, replacing the near-total prohibition on significant automated decisions with a permissive but safeguard-heavy regime. The loosening was conditional: legitimate interests can now be used as the legal basis for AI screening, but only where transparency, meaningful human review, bias monitoring, and the right to contest decisions are all baked in. The ICO's expectations tightened alongside the Act, not relaxed.
For agencies with EU operations, a second layer of obligation adds complexity. The EU AI Act classifies recruitment, candidate selection, and evaluation tools as high-risk systems, triggering conformity assessments and technical documentation requirements that go beyond what the Data (Use and Access) Act demands. A tool that satisfies UK requirements may still fail EU AI Act obligations. The two frameworks must be assessed separately.
The ROI Blind Spot
The compliance picture sits inside a wider management failure. AI use across professional services nearly doubled in a year, from 22% in 2025 to 40% in 2026, according to the Thomson Reuters Institute's 2026 AI in Professional Services Report, which surveyed more than 1,500 professionals across 27 countries. Yet only 18% of those professionals said their organisation actually tracks return on investment from AI tools. A further 40% said they did not know whether ROI was measured at all.
Read those numbers next to each other. The sector has scaled AI adoption while flying almost completely blind on what it is getting back. That is not a technology failure. It is a management failure, and in recruitment it carries a compliance tail risk that most practice leads have not priced into their engagements.
The billable-hour tension compounds the problem. AI that makes hiring faster threatens margin when agencies charge per-placement fees tied to volume throughput. The firms adapting well are moving screening-heavy work to fixed or capped fees, retaining value-based arrangements for judgment-intensive roles. Those that are not will face a pricing conversation they are not prepared to have, possibly alongside an ICO enforcement notice.
What Agencies and Consultants Must Do
The ICO has set out specific expectations. Any tool that filters, ranks, scores, or shortlists candidates needs a Data Protection Impact Assessment with enough granularity to satisfy the regulator's requirements. Many existing DPIAs, the ICO found, lack that detail. Monthly bias reviews and regular fairness testing are described as good practice. When procuring tools, agencies should question vendors directly about their own bias-testing methodology, because once a non-compliant tool is embedded in a workflow, the liability sits with the employer, not the developer.
The ICO has also flagged that candidates are increasingly exercising their data rights, sometimes using AI-generated requests. Agencies that cannot produce a meaningful audit trail of how a candidate was screened, and by whom, are exposed on multiple fronts at once.
Final guidance on automated decision-making and profiling was expected in summer 2026, following the consultation that closed in May. Parliament has also laid regulations requiring the ICO to produce a dedicated code of practice on AI and automated decision-making. The regulatory infrastructure is assembling in plain sight.
A Signal Worth Reading
The ICO's October 2025 penalty against Capita (£14 million for cybersecurity failures) is the relevant precedent for anyone who thinks the regulator lacks appetite for enforcement. Recruitment ADM is now named as a priority. The consultation is closed. The letters have gone out.
For UK professional services cohorts, SIC 70.22 management consultancies, SIC 78.20 recruitment agencies, training providers under 85.59, the compliance window is not closing. It has already closed. What remains is the enforcement queue.
Establishing a governance framework is increasingly a commercial move, not just a legal one. AIBD analysis of IPO trademark data shows 1,615 UK filings in Nice Class 45 (legal and security services) during Q3 2026, up 1.4% on the prior period. Service businesses are moving to protect compliance-adjacent propositions as a competitive differentiator, not a cost of entry.
The uncomfortable truth is this: if your recruiting tool scores a candidate, and a person glances at the output and clicks confirm, you are running an automated decision-making process under UK data protection law. The ICO knows it. Most agencies do not.
