Letting AI Screen CVs on Its Own? That's Not Just Risky, it's Against the Law

A recent conversation I had with a colleague has inspired this week’s blog about a specific use of AI. AI tools that scan, rank, and filter job applications are everywhere now. They save time, and nobody's arguing otherwise. The problem is what happens when a business lets that software make the actual decision, rejecting or advancing candidates with no real person checking the outcome. That's not a grey area. It's been against the law since 2018.

The rule: GDPR 

The GDPR gives job applicants specific protection, they can't be subjected to a decision based solely on automated processing if that decision has a legal or otherwise significant effect on them. Being screened out of a job application clearly counts. Unless a specific exception applies, fully automated rejection simply isn't allowed and even where an exception does apply, the person still has the right to human intervention, the right to say their piece, and the right to challenge the outcome.

This isn't new guidance dressed up as news. In July 2026, Europe's data protection regulators (the EDPB and EDPS) held a joint conference confirming exactly this: 

“…automated hiring decisions have been breaching Article 22 since the day GDPR took effect. It wasn't a new rule, it was a reminder that plenty of companies have been quietly getting this wrong for years.”

"A human clicked approve" isn't enough

Here's the part that catches people out:

Having a person nominally sign off on the AI's shortlist doesn't automatically fix the problem. The Court of Justice of the EU made this clear in a 2023 ruling on automated credit scoring, if the human reviewer is just rubber-stamping whatever the algorithm produced, without genuinely engaging with the decision, that's still treated as automated decision-making. Regulators are now applying the same logic to hiring. The review has to be real, that means a recruiter actually looking at the candidate's file, capable of overriding the system, not just clicking "confirm" on a ranked list.

The AI Act now adds its own layer

Separately, the EU AI Act classifies recruitment AI tools used to filter applications or evaluate candidates as "high-risk." That triggers its own obligation under Article 14: a human must be able to understand what the system is doing, spot when it's gone wrong, and override or stop it. Two different laws, both landing on the same conclusion, a person needs to be properly in the loop.

What this means in practice

If your business uses AI to help with recruitment, the tool itself isn't the problem. The risk sits in how it's used: AI can rank, sort, or flag candidates, that's fine. A person must genuinely review the outcome before anyone is rejected or advanced and be able to change it. Candidates should be told AI is involved, and a record should be kept showing human review actually happened, not just that a button was clicked.

Regulators across Europe are actively looking at this right now, so it's a good moment to check how your recruitment process actually works in practice, not just how it's described in a policy document.

The takeaway

AI can absolutely help with recruitment, sorting a stack of two hundred CVs is exactly the kind of task it's good at. What it can't do, legally, is make the decisions by itself. Keep a real person genuinely in charge of all the decision process, and you will be in a good place in the event of a complaint or investigation.

This is general information, not legal advice. If you'd like your recruitment process checked against these rules, get in touch and we'll take a look.

Next
Next

Shadow AI: why "we didn't approve that" isn't a GDPR defence