Start free trial of Lex HR →

AI in recruitment: UK discrimination law and bias audits

How the Equality Act 2010 applies to CV screening, video interviews and candidate scoring, what a defensible bias audit looks like, and the vendor questions that protect employers from tribunal claims.

Last updated 3 September 2026

AI screening is now standard in high-volume recruitment. The legal exposure sits almost entirely with the employer, not the vendor: it is the employer that makes the hiring decision, and it is the employer that will be the respondent at tribunal.

This guide covers how UK discrimination law applies and how to run a bias audit that would survive scrutiny.

Which laws apply

  • Equality Act 2010 — direct discrimination, indirect discrimination, discrimination arising from disability, and the duty to make reasonable adjustments all apply to job applicants, not just employees.
  • UK GDPR — screening is processing; automated rejection engages Article 22; candidates have access rights over the data and, in many cases, the logic involved.
  • Employment agency legislation and sector rules may add further duties where a third party runs the process.

Note there is no cap on compensation for discrimination claims, and a single flawed screening model can generate a large group of comparable claimants.

The three ways AI screening goes wrong

1. Proxy variables. A model that never sees ethnicity can still learn postcode, school, or name-derived signals that track it. The same applies to career-gap features, which correlate with parental leave and disability.

2. Historic bias in training data. A model trained on who was hired before reproduces who was hired before. If past hiring skewed, the model treats that skew as the definition of a good candidate.

3. Interface and interaction design. Timed assessments, video interviews and gamified tests can disadvantage disabled candidates. Facial analysis performs worse for people with facial differences, visual impairments, or non-standard speech. The reasonable-adjustments duty is anticipatory: you cannot wait for a candidate to complain.

Indirect discrimination in one paragraph

A provision, criterion or practice applied to everyone that puts people sharing a protected characteristic at a particular disadvantage is unlawful unless it is a proportionate means of achieving a legitimate aim. An AI screening threshold is a textbook PCP. The employer must be able to show both the legitimate aim (efficient, consistent selection) and proportionality — which means evidence that the model actually predicts job performance and that no less discriminatory alternative was available. "The vendor says it works" is not evidence.

What a defensible bias audit contains

Run this before launch, then at least annually and after any model retraining.

  • Adverse impact analysis at each funnel stage. Compare selection rates by sex, ethnicity, age band and disability status where you hold the data. The four-fifths rule imported from US practice is a useful screen, not a legal standard in the UK — investigate any material gap.
  • Validity evidence. Does the score correlate with later performance for people you did hire? If nobody can produce this, the tool is being used on faith.
  • Feature review. List the inputs. Flag anything that is a plausible proxy for a protected characteristic, and test the model with and without it.
  • Accessibility testing. Run the process with assistive technology, and offer an alternative route by default rather than on request.
  • Sample review. Have a human recruiter blind-review a sample of rejected candidates against the criteria and compare with the model.
  • Documentation. Record the date, method, results, decisions taken and who signed them off. The audit's evidential value depends on it existing before the claim.

Human review that counts

Article 22 UK GDPR restricts decisions based solely on automated processing that produce legal or similarly significant effects — rejecting a job application qualifies. Human involvement must be meaningful: a reviewer with the competence and authority to reach a different conclusion, who actually considers the underlying application. Rubber-stamping a ranked list is not human involvement, and neither is a reviewer who only ever sees the candidates the model passed.

Candidate transparency

Tell candidates, at the point of application:

  • that AI is used, and at which stage
  • what it assesses
  • that they can request human review of an automated rejection
  • how to request an adjustment

This is both a GDPR transparency requirement and the single cheapest way to reduce complaints.

Vendor due diligence questions

  1. What exactly does the model predict, and what was the outcome variable in training?
  2. What data was it trained on, and how representative is it of the UK labour market?
  3. What adverse-impact testing has been done, on what population, and can we see the results?
  4. Which features are used? Are any derived from free text, video or audio?
  5. How is the tool accessible to disabled candidates, and what alternatives exist?
  6. What retraining happens, and are we notified before the model changes?
  7. What contractual liability and indemnity is offered for discriminatory output?
  8. Can we export our own decision data to run an independent audit?

Get the answers in writing and attach them to the contract. An employer that asked the questions and kept the answers is in a very different position from one that did not.

The practical takeaway

AI screening is defensible when it is validated, audited, disclosed and reviewable by a human who can say no. It is indefensible when the employer cannot explain what the model measures. Most tribunal risk comes from that second state, not from the technology itself.

This guide is general information for HR professionals, not legal advice. Take advice on your own facts before acting.

Related guides

The Weekly Briefing

Get AI & HR insights every week

One email a week with the latest cases, regulations and practical guidance on AI in the workplace.

Protected by reCAPTCHA. Privacy & Terms.