AI screening and UK law: what employers need to know
Using AI in recruitment is lawful in the UK, but the same rules apply as to any other hiring process - plus a few specific to data and automation. Here is a plain-English overview, and the questions to ask any AI screening vendor, including us.
In this guide
1. The Equality Act 2010
The Equality Act protects job applicants, not just employees, from discrimination on nine protected characteristics: age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex and sexual orientation. Using AI doesn't change your responsibility - if a tool discriminates, the employer is still liable.
Indirect discrimination
The biggest AI risk is indirect discrimination: a criterion that applies to everyone but puts one group at a particular disadvantage - for example, an unnecessary fluency requirement, or penalising career gaps, which affects more women and disabled people. It is unlawful unless you can show it is a proportionate way to achieve a legitimate aim. Keep criteria tied to what the job genuinely needs.
Reasonable adjustments
Employers must make reasonable adjustments for disabled applicants, including in the application and screening process. Offer an alternative route for anyone who can't use an automated screen, and make it easy to ask for.
Health questions before an offer
Section 60 of the Act restricts asking about health or disability before a job offer, apart from narrow exceptions such as asking about adjustments needed for the recruitment process itself. Keep these questions out of your screening criteria.
2. UK GDPR and automated decisions
Screening candidates means processing personal data, so UK GDPR applies in full. In practice that means:
- Transparency: tell candidates you use AI in screening, what it does and how to ask for a person instead.
- Lawful basis and minimisation: only collect what you need for the role, and only use it for recruitment.
- Retention: decide how long you keep applications and transcripts, and delete them after.
- Rights: candidates can access their data, correct it and object.
UK law has special rules on decisions made solely by automated means that have a significant effect on someone - which a rejection can be. The Data (Use and Access) Act 2025 reformed these rules, with the changes taking effect on 5 February 2026, but safeguards remain: people must be told, must be able to contest the decision and must be able to get human intervention. The human involvement must be meaningful - a person rubber-stamping an automated output can still count as a solely automated decision - so reviewers need to genuinely weigh the evidence. The simplest way to stay on the right side is to make sure a person makes the hiring decision. With BeCareers the AI gathers information and summarises it and your team decides; if you use automatic knock-out rules, tell applicants and give them a way to ask for a person to review the outcome.
The ICO has looked closely at AI recruitment tools. Its 2024 audit of AI recruitment providers recommended fairness monitoring, data minimisation, clear information for candidates and impact assessments. Its guidance is worth reading before you buy.
3. Data protection impact assessments
Using AI to evaluate job applicants is the kind of processing the ICO expects to be covered by a Data Protection Impact Assessment (DPIA). The DPIA should describe what the tool does, the risks to candidates - including bias and inaccuracy - and how you reduce them. Ask your vendor for their DPIA and compliance documentation to build on. BeCareers provides ours on request.
4. The EU AI Act
The EU AI Act treats AI used for recruitment and selection - including screening and evaluating candidates - as high-risk. It is an EU law, but it can reach UK organisations that offer AI systems in the EU, or whose AI outputs are used in the EU, for example when hiring for EU-based roles. High-risk obligations include risk management, data governance, human oversight, transparency to candidates and record-keeping.
In 2026 EU lawmakers agreed to postpone the high-risk obligations, with those covering recruitment now expected to apply from December 2027. Separate transparency duties - such as telling people when they are interacting with an AI system - are due to apply earlier. Check the current timetable if you hire into the EU. Even where it doesn't apply, its requirements are a useful checklist for good practice.
5. Questions to ask any AI screening vendor
- Does the tool make or recommend rejections automatically, or does a person decide?
- What data does it use? Only what the candidate submits, or also social media and other public profiles?
- Can we see a full record of each screening - not just a score?
- How do you test for bias across protected characteristics, and can we see the results?
- Where is candidate data hosted, and is it transferred outside the UK?
- Can candidates withdraw, and can they ask for a human alternative?
- Will you share your DPIA and compliance documentation?
- Is pricing published, and what does it cost at your volume?
How BeCareers answers
The AI never makes the decision - your team does, and any knock-out rules are yours to set. We screen what the candidate shares with us. Every screening has a full transcript. Data is hosted in the UK. Candidates can withdraw at any time. Our DPIA is available on request, and our prices are published.
Frequently Asked Questions
AI screening built for UK compliance
Your rules, full transcripts, UK data residency and a DPIA on request.