The technology is ahead of most organisations' ability to govern it. These are the questions that need answers first, and they are not primarily technical.

The distinction that determines almost every governance obligation. The third row is where most organisations place themselves incorrectly.
AI is now embedded across the hiring process, from sourcing and screening through to interview scheduling and assessment. In most organisations it arrived tool by tool rather than through a deliberate decision, which means the governance conversation is happening after deployment rather than before it.
That order is the problem. Hiring is one of the most consequential and most regulated decisions an organisation makes about an individual, and the questions below are considerably harder to answer retrospectively.
1. What decisions is the system actually making
There is a meaningful difference between a tool that ranks candidates for a human to review, one that filters candidates out before any human sees them, and one that produces a score a human is unlikely to overrule in practice.
The third is the one organisations tend to misclassify. A recommendation that is followed ninety-five per cent of the time is functionally a decision, and regulators increasingly treat it that way. The useful discipline is to measure the override rate rather than to assert the classification. If nobody in the organisation knows how often a recommendation is rejected, the classification is an assumption.
Map every point in the hiring process where a system influences an outcome, and be honest about which of those are effectively automated.
2. What is the system inferring, and from what
Ask what inputs the model uses. Historical hiring data encodes historical hiring patterns, including the ones an organisation is actively trying to change. A model trained to identify candidates resembling past successful hires will reproduce the composition of past successful hires, which is a problem precisely when the intent is to broaden a pipeline.
Ask particularly about proxies. A model may not use protected characteristics and still infer them reliably from other fields, which is why the absence of a protected field is not evidence of a fair process. Postcode, university, career gap length and even the phrasing of a personal statement can each carry a substantial amount of the information a protected field would have carried.
3. Can you explain a rejection
A candidate asks why they were screened out. Can the organisation answer?
In several jurisdictions this is a legal requirement rather than a courtesy, and it is also a reasonable internal standard: a process whose outcomes cannot be explained is one that cannot be defended or improved. The practical constraint is that explanation has to be designed in at the data layer. A system that did not preserve which inputs drove which outcome cannot produce an explanation later, whatever the vendor's interface suggests.
4. Who is accountable, and who tested it
Name the person accountable for the outcome. Vendor assurance is not accountability, and a vendor's fairness testing was conducted on their data and their candidate population, not yours.
Ask what testing has been done on your own pipeline since deployment, at what interval, and who reviewed the result. Systems drift, and a model validated at implementation is not validated permanently. This is the single most common gap we would expect to find in a well-intentioned organisation: a thorough pre-deployment assessment, and nothing since.
5. What are candidates told
Disclosure obligations differ by jurisdiction and are tightening. Beyond compliance, there is a practical dimension: candidates increasingly assume automation is present, and organisations that are straightforward about where it is used and how a human remains involved tend to fare better than those that are silent.
The regulatory direction, and one date worth having
The clearest signal available is the European Union's approach. Annex III of Regulation (EU) 2024/1689, the AI Act, classifies as high risk a set of AI systems used in employment and worker management, alongside those used for creditworthiness assessment and other consequential decisions about individuals.
Those obligations were originally to apply from 2 August 2026. They now apply from 2 December 2027, deferred by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026. Anyone planning against that date should confirm it against the operative article of the amending regulation rather than a summary page, and should check whether the Annex III numbering changed.
The sixteen-month deferral is worth using rather than banking. The obligations attached to high-risk classification are largely about evidence: risk management, data governance, technical documentation, logging, human oversight and post-market monitoring. Every one of those is easier to build before a system is embedded than after.
The extension is build time, not relief. An organisation that reaches December 2027 without the records will be in exactly the position it would have been in August 2026, having had sixteen extra months.
The organisational point
These questions are not obstacles to using the technology. They are the conditions under which it can be used defensibly.
The organisations that answer them before deployment gain something the others do not: the ability to keep using their tools when the questions eventually arrive from a regulator, a works council, a candidate or a journalist.
This is reporting, not legal advice. Employment and data protection obligations differ significantly by jurisdiction and change frequently. Take qualified legal advice on your specific circumstances.
References
Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.
European Union, Regulation (EU) 2024/1689, the AI Act, Annex III. https://artificialintelligenceact.eu/annex/3/
European Union, Regulation (EU) 2026/1744, the Digital Omnibus on AI, deferring Annex III high-risk obligations, 8 July 2026, in force 27 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
European Commission, AI Act policy page, application dates, updated 27 July 2026. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
How we work. This article was researched and written by the HR Hubs Media editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@hrhubsmedia.com and tell us what and why.
Filed under Employee Data & Privacy · Get The Weekly Brief

