The regulatory ground shifted in February 2026. Most employers haven’t caught up.
UK organisations using AI to screen or score job candidates are operating in materially different legal territory than they were 18 months ago. Two pieces of legislation — the Data (Use and Access) Act 2025, which came into force in February 2026, and the EU AI Act, whose core employment obligations apply from August 2026 — have created a compliance landscape that most technical recruiting teams haven’t fully mapped.
At the same time, the conversation happening in engineering and talent functions hasn’t slowed down. The pressure to modernise technical hiring, assess AI fluency, and reduce time-to-hire is real and growing. The organisations navigating this well are the ones that understand the regulatory framework clearly enough to move within it — not the ones waiting for perfect clarity that isn’t coming.
This piece covers what UK hiring teams need to understand: the current legal situation, where the UK diverges from EU requirements, what “meaningful human oversight” actually requires, and how to build an AI-assisted hiring process that is both compliant and actually useful.
The ICO just told most UK employers they’re non-compliant
In May 2026, the Information Commissioner’s Office closed a landmark consultation on automated decision-making in recruitment, releasing its Recruitment Rewired report alongside it. The findings were unambiguous.
The ICO reviewed more than 30 UK employers and found that most organisations using AI to screen and score candidates believed they were merely supporting human decisions when, in practice, the evidence showed those tools were making the decisions outright. The ICO wrote directly to 16 organisations identified as likely to be operating outside UK data protection law. All 16 committed to act on the regulator’s recommendations.
The gap between employer belief and regulatory reality is the crux of the problem. Organisations told the ICO their AI tools were used only as decision support, with a human making the final call. The regulator’s review found that in many cases the human review amounted to scanning an AI-generated shortlist and approving it — a process the ICO does not accept as meaningful human involvement.
This matters for any UK organisation using AI-assisted candidate screening, scoring, or ranking. The ICO’s position is explicit: a hiring manager who reviews an AI-generated shortlist and approves it without independent analysis has not provided meaningful human oversight. The candidate has, in regulatory terms, been subject to a solely automated decision.
What the law actually requires in the UK
The UK and EU have taken different approaches. The UK’s Data (Use and Access) Act 2025 amends UK GDPR and the Data Protection Act 2018 rather than introducing new standalone regulation, and it takes a lighter-touch approach to automated decision-making than the EU AI Act. The EU AI Act classifies AI systems used for recruitment, selection, or evaluation decisions as high risk — with full compliance obligations applying from 2 August 2026.
The DUAA reforms aim to simplify requirements for solely automated decision-making by limiting the strictest controls to processing of special category data only — which diverges from the EU’s approach. In plain terms: the UK has created more flexibility for organisations using AI in hiring, provided they can demonstrate genuine human involvement and meet the safeguards that remain in place.
But “more flexibility” is not the same as “no requirements.” The ICO’s Recruitment Rewired report establishes what genuine human involvement looks like in practice — and the bar is higher than most teams assume.
What “meaningful human oversight” requires in the UK:
A reviewer must have the authority, discretion, and competence to change the outcome of a candidate assessment before that assessment takes effect. Clicking “approve” on an AI-generated ranking without independent analysis does not qualify. In a multi-stage recruitment process where AI scores candidates at the screening stage, the human reviewer must be able to see sufficient information to form a judgment independent of the score — and must sometimes act against it.
Applying human review inconsistently — to some candidates but not others at the same hiring stage — is itself a compliance risk under UK GDPR.
How the UK and EU frameworks differ (and why it matters if you hire across both)
For organisations hiring across the UK and EU — which describes most large enterprises in the region — the divergence between these frameworks creates a real operational challenge.
The EU AI Act and GDPR’s Article 22 apply concurrently: AI Act compliance does not automatically satisfy GDPR obligations, and GDPR compliance does not meet AI Act requirements, although measures taken to comply with each regime will often overlap.
Key requirements for high-risk hiring AI under the EU AI Act include rigorous risk assessments and testing to ensure the system is accurate and free of unfair bias, detailed technical documentation explaining how the AI works, human oversight mechanisms to prevent automated decisions from going unchecked, and registration of the AI system in an EU database before it’s put into use.
From August 2026, high-risk hiring systems operating in the EU must provide clear explanations of the AI’s role and logic in decisions, available to affected persons.
In practice, the most defensible approach for UK-based teams with EU hiring activity is to build to the higher EU standard and treat UK compliance as a subset of it. The additional effort is modest; the risk of maintaining two divergent approaches is not.
The bias question is not optional
The ICO’s focus on bias monitoring is not precautionary. Research cited by the regulator found that 64 percent of people are concerned employers will rely too heavily on AI, and 61 percent are concerned it performs worse than human decision-makers when assessing individual circumstances. A November 2024 ICO audit of AI recruitment tool providers found candidate applications being filtered based on characteristics that amount to protected attributes.
This intersects directly with the Equality Act 2010. An Employment Tribunal does not accept “the algorithm produced the shortlist” as a defence to a claim of indirect sex, race, or disability discrimination. Bias testing is the employer’s legal obligation — not something that can be outsourced to the vendor.
For technical assessment specifically, this means any AI-powered screening tool should be able to demonstrate:
- How it was trained and what data it was trained on
- Whether scoring has been audited across demographic groups
- How it handles edge cases and unexpected candidate profiles
- What an assessor sees when reviewing a score, and whether that information is sufficient to form an independent view
If your vendor cannot answer these questions clearly, that is the answer.
What this means for technical assessment specifically
The concerns raised in these regulatory frameworks are especially acute for technical hiring, because the tools involved — AI-powered screening, automated code evaluation, voice-based interviewing — sit squarely within the high-risk category.
Here is what a compliant technical hiring process needs to look like in the UK in 2026:
Interpretable scoring. Every score produced by an AI tool should come with a clear rationale — not just a number, but citations from the session that explain why the score was reached. An assessor reviewing a candidate should be able to understand the scoring well enough to agree with it, question it, or override it.
No automatic rejection. No candidate should be rejected solely on the basis of an AI-generated score without a human independently reviewing the case. This is not just good practice — it is the line between compliant and non-compliant use under both UK GDPR and the EU AI Act.
Documented bias audits. Technical assessment tools should undergo regular bias audits and produce reports that employers can review. These audits should examine scoring patterns across gender, ethnicity, and other protected characteristics. The audit should be an ongoing process, not a one-time pre-launch exercise.
Candidate transparency. Under the EU AI Act, candidates must be informed when AI systems are used in their assessment. Recruiters and hiring managers must retain responsibility for final decisions. UK GDPR carries similar transparency obligations. Candidates should be told when AI is involved, what it is evaluating, and what their rights are.
Dynamic over static. A static take-home assessment — a fixed problem with a fixed answer — is harder to defend under a transparency framework, because it is harder to explain to a candidate how a score was reached. A dynamic assessment, where the evaluation includes conversation and probing into reasoning, produces interpretable output: here is what the candidate said, here is what we were evaluating, here is why the score reflects performance on those dimensions.
The question worth asking your vendor
UK organisations evaluating AI-powered technical assessment tools should ask vendors directly:
- Is your tool designed to produce recommendations or decisions? Is automatic rejection possible in default configurations?
- Can you provide your bias audit methodology and results?
- What does a reviewer see when they look at a candidate’s score — and is it sufficient for them to form an independent judgment?
- Are scores accompanied by citations from the session that explain how they were reached?
- Have you engaged with the ICO’s Recruitment Rewired findings and the EU AI Act’s August 2026 compliance deadlines?
The answers will tell you more than the sales materials.
The broader context
The regulatory framework is not the obstacle. It is the quality floor.
The organisations in the UK that are moving forward on AI-assisted technical hiring are not ignoring compliance — they are using the compliance requirements as a design brief. Interpretable scoring. Human oversight built into the workflow, not bolted on. Bias auditing as an ongoing process. Candidate transparency as a default.
Those requirements, taken seriously, produce a better hiring process than the one most organisations are running today. A static take-home assessment with opaque scoring that a recruiter reviews for 10 minutes is not compliant and not particularly useful. A dynamic AI screen with interpretable output, a human reviewer with genuine authority to override, and a documented audit trail is both compliant and a better signal.
The ICO’s consultation closing in May 2026 is, as the regulator put it, not the endpoint — it is the beginning of the accountability phase. UK employers who have been assuming that a hiring manager nodding at an AI-generated shortlist satisfies the law now have explicit guidance that it does not.
The question for talent and engineering leaders is not whether to adapt. It is how fast.
HackerRank builds technical assessment and interview tools designed for compliance in both UK and EU regulatory environments. Chakra, HackerRank’s AI-powered screening product, includes built-in bias auditing, interpretable scoring with session citations, and workflow design that keeps human reviewers in the decision loop. To learn more, visit hackerrank.com.