Short answer
Use AI in hiring for bounded administrative support, not hidden judgement. Let it draft, organise, schedule and summarise under a human-owned process. Keep a person accountable for shortlisting, rejection, offers, accommodations and exceptions; tell candidates where AI is used; and test the workflow for bias, accessibility, accuracy and unequal outcomes before and after launch.
A recruiter receives a ranked list of applicants. The ranking looks precise, so it becomes the shortlist. Nobody can explain which past decisions shaped the score, which writing style the tool prefers, or what happens to a candidate who needs an accommodation. That is how a time-saving tool becomes an unapproved employment policy.
AI is now easy to add to a recruitment workflow. It can draft a vacancy, extract experience from CVs, schedule interviews, answer routine questions and summarise notes. Those are useful capabilities. The mistake is to let the tool quietly decide who deserves attention, then call the result objective because it came from software.
This guide is for HR directors, founders and people leaders. It is governance guidance, not legal advice. The EU, UK and US sources below are useful benchmarks, but an organisation must check the employment, privacy, equality and accessibility rules that apply in its own country and obtain local advice where the decision is high-risk.
Start with one distinction: assist or decide?
“AI used in HR” is too broad to govern. Write down the exact task and its consequence.
| AI role | Example | Governance level |
|---|---|---|
| Assist | Draft an advert from an approved role profile or suggest interview questions. | Human checks the output before use. |
| Organise | Schedule interviews or group applications by a stated, job-related field. | Document the rule; monitor errors and access. |
| Recommend | Rank candidates or flag a person as likely to succeed. | High control: evidence, human review and challenge route. |
| Decide | Reject, hire, determine pay, or deny an accommodation. | Do not delegate the decision to an opaque tool. |
The closer the output is to an employment decision, the stronger the controls must be. The EU AI Act is a useful signal even for organisations outside the EU: its Annex III identifies recruitment and selection systems, targeted job advertising, application filtering and candidate evaluation as high-risk use cases within its framework. That does not make the regulation local law, but it shows why “it is only a ranking tool” is not an adequate risk assessment.
Where AI can genuinely help
The best early uses reduce repetitive work while leaving the meaning of the decision visible.
Drafting and administration
Ask an approved tool to turn a signed-off role profile into a first draft of a vacancy, create a plain-language version, remove unexplained jargon, or prepare a checklist for interviewers. A person must check that the advert describes the real job and does not introduce unnecessary requirements or language that discourages qualified applicants.
Scheduling and candidate questions
Scheduling, reminders, location details and answers to routine process questions are usually more bounded than candidate scoring. Give the assistant a narrow knowledge base, a route to a human, and a rule that it must not invent a status, promise an outcome or request information that the process does not need.
Structured summaries
AI can turn structured interview notes into a consistent summary. It should not fill gaps with assumptions, infer personality from a face or voice, or convert a vague impression such as “not a good fit” into a polished paragraph. The interviewer remains responsible for the evidence and should be able to correct the summary.

Where bias enters the workflow
Bias is not only a malicious rule. It can enter through data, proxies, language, design choices, missing context or the way people respond to a score.
Historical decisions become a hidden target
If a tool learns from previous hiring decisions, it may learn the organisation’s old preferences rather than the capabilities the job actually needs. A history of hiring from a narrow network can make that network look like a definition of merit. A history of rejecting career breaks can make a gap appear to be a defect when it may have no bearing on performance.
Proxies look neutral
Names, schools, postcodes, employment gaps, language patterns, device signals and online behaviour can stand in for protected or sensitive characteristics. Removing a field does not remove its proxies. A model can also reward the format and vocabulary of applicants who have had better access to coaching, polished CV templates or the dominant business language.
Personality and emotion scores are especially fragile
Claims that a camera, voice recording or facial expression can reveal honesty, leadership or “culture fit” should trigger a stop-and-review decision. The signal may be weak, culturally narrow or inaccessible to a person with a disability. It can also encourage interviewers to trust a confidence score instead of asking job-related questions.
The US EEOC and Department of Justice warn that AI tools may screen out disabled applicants who could do the job with a reasonable accommodation. The practical lesson is wider than US law: accessibility cannot be an afterthought in an automated workflow. Ask how a candidate can request an accommodation, how the tool avoids penalising it, and who can override a bad result.

The human must stay in charge of five moments
“Human in the loop” is too vague if nobody can say what the human does. Name the moments where a person must review, question and own the result:
- Before the advert is published: confirm the criteria describe the work, not an accidental profile of previous hires.
- Before a candidate is screened out: check the reason against the stated criteria and look for missing context or an accommodation.
- Before a shortlist is approved: review a representative sample, including people the tool ranked low.
- Before an offer or rejection: make the decision from job-related evidence, not an unexplained score.
- When a candidate challenges the process: provide a real route to human review and record what was reconsidered.
The ICO’s Recruitment Rewired work emphasises that human involvement should be consistent for candidates within the same hiring stage. A reviewer who checks only the borderline cases, or only the people who look promising, is not providing a reliable control.

What a fair-use policy should require
Use the following as the core of a two-page policy. Expand the controls when the tool influences selection, pay, promotion or dismissal.
Approved use
Name the tool, task, data used, owner, human check and acceptable output. Do not approve “AI for recruitment” as one undifferentiated category.
Prohibited use
Ban hidden candidate scoring, emotion inference, unreviewed rejection, unauthorised personal data and any use that circumvents an accommodation.
Candidate notice
Explain where AI appears, what it does, what it does not decide, how long relevant data is kept, and how to request human review or an accommodation.
Testing and records
Keep the version, prompt or rule, criteria, test set, review sample, incidents, overrides, vendor terms and decision log. Re-test after a model or workflow change.
Use the NIST AI Risk Management Framework as a useful vocabulary for validity, reliability, safety, security, transparency, explainability, privacy and fairness. It is voluntary and not a substitute for local law, but it helps an HR team ask better questions of a supplier and its own process.
Questions to ask an AI hiring vendor
- What exactly does the system do, and which employment decisions can it influence?
- What data trained or configured it? Is our candidate data used for general model training?
- Which languages, CV formats, assistive technologies and accessibility paths were tested?
- Can we see the factors or evidence behind a recommendation without exposing another candidate’s data?
- What happens when the model is updated? Will we receive a change notice and a new evaluation record?
- Where are candidate data, logs and backups stored, who can access them, and when are they deleted?
- Can the tool export a complete decision record and support a human override?
If the vendor cannot answer these questions, do not compensate with confidence. Narrow the use case to a lower-risk administrative task or pause the purchase.

A sensible 30-day starting plan
- Week 1: inventory every AI feature already used in recruitment, including browser tools and informal staff use. Map each to assist, organise, recommend or decide.
- Week 2: pause unapproved high-impact uses. Write the approved-use rules, name owners, define candidate notice and agree the accommodation route.
- Week 3: test one bounded workflow against representative cases. Review errors, language, accessibility, unequal patterns and the quality of human overrides.
- Week 4: publish the policy, train recruiters, create an incident and challenge log, and set a review date for the tool and the results.
A small organisation does not need a complicated committee to act fairly. It needs a visible decision rule, a human owner, a way for candidates to ask questions, and enough evidence to notice when the tool is treating people differently. Efficiency is worth having. Quietly automating an old bias is not.
For the wider operating model, combine this guide with the two-page AI policy template and the guide to responsible AI governance. If you need help reviewing an AI use case before it reaches candidates, contact Peter.
Frequently asked questions
Can AI make the final hiring decision?
It should not make the final decision in a responsible hiring process. AI can organise information or support a defined, job-related review, but a named human decision-maker must own the shortlist, rejection, offer, accommodation and exception decisions.
What are safe uses of AI in recruitment?
Lower-risk uses include drafting a job advert from an approved role profile, scheduling interviews, answering routine candidate questions, checking that an application is complete, and summarising structured interview notes. Each use still needs an owner, access controls and a quality check.
How can an employer check an AI hiring tool for bias?
Test the tool against representative historical and synthetic cases before launch, compare outcomes across relevant groups where lawful and appropriate, check disability and language accessibility, monitor live results, and investigate unexplained differences. Do not treat a vendor fairness statement as a substitute for your own review.
Should candidates be told when AI is used in hiring?
Yes. Tell candidates where AI is used, what role it plays, what information it considers, who reviews the result, and how they can ask a question or request human review. The notice should be understandable before a person submits sensitive information.
Do small organisations need a formal AI hiring policy?
They need clear rules even if the document is short. A one- or two-page policy can name approved uses, prohibited uses, human accountability, candidate notice, accessibility, testing, records, vendor checks and an escalation route. A small team can use a lighter process, not an undefined one.
Sources & the researchers worth crediting
External figures and recommendations are credited here so you can check the reasoning. The practical frameworks are Peter Bamuhigire’s analysis, not statistics presented as facts.
- European Union, Regulation (EU) 2024/1689 (EU AI Act), Annex III and Article 6: employment and recruitment systems classified as high-risk in the EU framework
- UK Information Commissioner’s Office, What jobseekers need to know about automated recruitment decisions (31 March 2026)
- UK Information Commissioner’s Office, Recruitment Rewired: transparency, human involvement and fairness monitoring
- US Equal Employment Opportunity Commission and Department of Justice, warning on disability discrimination and AI tools
- NIST AI Risk Management Framework FAQs: trustworthy AI characteristics and voluntary risk-management practice
Read next
Write Your Company's AI Policy in Two Pages
A plain-language starting point for approved uses, prohibited data, human review, ownership and incidents.
Responsible AI Without Digital Dependence
Put accountability, contracts, data and local capability around AI before a useful tool becomes a dependency.
The Skills Gap Is Killing Your AI Strategy
A practical build, hire, partner or diaspora sourcing playbook for AI capability.
About the author
Peter Bamuhigire
Technology & Business Consultant
Peter Bamuhigire helps African organisations turn technology into controlled operating capability. He writes for leaders who need practical rules around AI, not a promise that a vendor’s score can replace judgement, context or accountability.

