By Lee Flanagan
An AI screening tool can turn 800 applications into a shortlist of 12 within the hour. The trouble arrives months later, when a rejected candidate asks why they were filtered out and nobody in the business can answer. Samira Cakali, head of employment at Winston Solicitors, opens her People Management analysis with that scenario, and it names the real failure: an evidence-production problem, not a policy gap. No amount of legal reading fixes it until employers treat it as one.
What the ICO’s Recruitment Rewired Report Found
The Information Commissioner’s Office published its Recruitment rewired report in March 2026. It concluded that many employers using automated recruitment tools are making solely automated decisions under UK GDPR, without the safeguards the law requires for that kind of decision. Separately, the ICO expects employers to hold a proper data protection impact assessment for these tools, and it has found that many existing DPIAs lack the necessary detail. The algorithms are rarely the real problem. The gap is that nobody can show the human oversight employers claim exists is actually operating.
The Equality Act Question Is Also a Documentation Question
Cakali’s first legal test is discrimination: a screening tool trained on your historic hiring patterns learns those patterns, including the ones you would rather it did not carry forward. That is a classic indirect discrimination risk under the Equality Act 2010, and the respondent at tribunal is the employer, not the vendor. Employers also have to consider whether the tool disadvantages disabled applicants or employees, and whether reasonable adjustments are needed to the assessment method, the data inputs, or the route to human review.
None of those questions get settled by owning a fair tool. They get settled by proving, later, that you asked the question, tested the answer and adjusted the process when the answer was uncomfortable. A tool that performs well on average proves nothing if you cannot produce the testing behind it.
A Forwarded Shortlist Is Not a Decision
Cakali names the trap precisely: “A recruiter that forwards the top 10 of a ranked list has not exercised judgement, they have transmitted a decision.” Meaningful human review, in her framing, requires a reviewer with the authority, the context and the practical ability to reach a different answer. A rubber stamp will not usually be enough if the automated output determines the result in practice, regardless of what the sign-off process claims on paper.
Ask yourself when the named approver on your process last changed the tool’s ranking. If the honest answer is never, you don’t have review, you have a formality. This is the most common gap: a signed-off process map with nobody who has ever exercised the authority it assumes. A shortlist you cannot explain later was never a decision, whatever the log says it was.
The vendor carries none of that liability either. Assuming a vendor’s indemnity clause covers you here is a mistake; buying the tool from a third party distributes the work, not the risk. The Data (Use and Access) Act 2025 replaced what was close to a prohibition on automated decision-making with a framework of safeguards, in force since 5 February 2026. That framework gives candidates transparency about when the processing happens, a right to contest the outcome, and a right to request human review.
The ICO also expects employers to interrogate developers about bias testing during procurement, then to keep trialling and monitoring the tool once it is live. A supplier that cannot produce that evidence is telling you something.
Performance Scores Carry the Same Exposure, With Less Scrutiny
Cakali’s strongest point is the one easiest to miss: this exposure does not stop at the point of hire. Productivity scores and flight-risk indicators increasingly feed capability processes, promotions and redundancy selection, carrying unfair dismissal risk on top of the discrimination and data protection risk already in play. Our read is this is structural, not accidental: hiring decisions get audited because rejected candidates ask questions, while performance-tooling outputs sit inside the business, reviewed by nobody outside it.
The Record Has to Outlive the Vendor
A defensible file, on Cakali’s account, needs documented human review at each rejection point, the scoring criteria and the reasoning behind them, version control on the tool itself, and dated documentation of bias monitoring. The detail that should worry TA leaders most is timing: claims surface months after the decision, by which point a vendor may have rotated its logs or lost the contract entirely. That file cannot live only inside the vendor’s system, because it disappears exactly when you need it most. It has to belong to the employer, generated at the point of decision, not reconstructed from a supplier’s dashboard after a claim lands.
The ICO’s final guidance is due in winter 2026, but the obligations it will comment on are already in force. Employers who can produce a rejection’s reasoning on request are not the ones who read that guidance closely when it arrives. They are the ones who decided, before the tool was ever switched on, that somebody would own the record.
Original reporting: People Management.
Frequently asked questions
What does the ICO mean by a ‘solely automated decision’ in hiring?
The ICO’s Recruitment rewired report, published in March 2026, does not spell out a formal definition of the term. What it found is that many employers using automated recruitment tools are making these decisions under UK GDPR without the safeguards the law requires for them.
Did the Data (Use and Access) Act 2025 ban automated hiring decisions?
No. It replaced a near-prohibition with a framework of safeguards in force since 5 February 2026: transparency about when automated processing is used, a candidate’s right to contest a decision, and a right to request human review.
What separates meaningful human review from sign-off in name only?
According to Samira Cakali’s analysis, the reviewer needs the authority, the context and the practical ability to reach a different answer than the tool’s output. Forwarding a ranked shortlist without any of those three does not count as review, even if a human technically signs off.
Is a vendor liable if its AI hiring tool discriminates?
No. Liability sits with the employer at an employment tribunal, not the vendor, and no contractual indemnity shifts that risk back onto the supplier that built the tool.
Does this legal exposure apply outside recruitment?
Yes. Cakali’s analysis warns that productivity scores and flight-risk tools increasingly shape promotions, capability procedures and redundancy selection, carrying the same discrimination and data protection exposure as hiring, plus unfair dismissal risk on top.