top of page

The Emerging Regulatory Challenges of AI Recruitment

Anika Prakash
Sep 3
5 min read

AI recruitment raises several concerns. Existing employment laws globally already place limits on discrimination, but automated hiring tools raise newer questions around bias, audits, transparency and accountability. For regulators, the challenge is building frameworks that preserve longstanding protections while remaining proportionate to risk, adaptable to technological change and supportive of beneficial innovation.


By Anika Prakash



Customising CVs for roles has become easier than ever – a few prompts, a base draft and viola, you now look like the perfect candidate for the open role! But, while AI is able to draft, fine-tune and customize CVs, it is equally able to screen CVs, rank applicants and influence who reaches an interview. Recruiters are not the first layer of screening that job applications go through anymore, AI tools are. So, recruitment is becoming less a process for matching people to jobs and more of bots optimising for bots, raising a few policy concerns.


Theoretically, the efficiency gains on both the applicant and recruiter sides are obvious. But fundamentally, recruitment is supposed to distinguish between people. Hiring necessarily involves separating eligible candidates from ineligible ones. If an engineering role requires an engineering qualification, excluding an applicant who does not hold that qualification is a relevant distinction.


But it gets complicated when every AI-polished application looks equally strong. Then, screening tools rank on whatever is left - employment gaps, university names, postcodes. An employment gap could be a maternity leave or a period of illness. A university name could be a proxy for family income. A postcode could be indicative of ethnicity. The line between legitimate selection and bias is drawn by a model's fallback ranking behaviour, not a recruiter's judgement.


// Legal and Policy Landscape


From a regulatory lens, employment and anti-discrimination laws across different nations already prescribe which forms of differential treatment are prohibited. For example, in the UAE Article 4 of Federal Decree-Law No. 33 of 2021 prohibits discrimination on the basis of race, color, sex, religion, national or social origin or disability where it impairs equality of opportunity or equal treatment in employment. In India, Article 16 of the Constitution guarantees equality of opportunity in public employment and prohibits discrimination in State employment on grounds including religion, race, caste and sex.


With the advancements in AI enabled recruitment, what is developing is an additional regulatory layer focused on how automated systems that influence recruitment should be tested, monitored and explained to ensure that the spirit of anti-discrimination laws holds. For example, Article 6 of the EU AI Act, read with Annex III treats AI systems used in employment, including recruitment and candidate selection, as potentially “high-risk” where they materially influence decision-making. High-risk AI systems are brought within a wider framework dealing with how the technology itself is managed, including risk management, data governance, documentation, traceability and human oversight.


Similarly, § 20-871 of the New York City Administrative Code, introduced by Local Law 144, requires covered Automated Employment Decision Tools to undergo a bias audit no more than one year before they are used. Employers must also make a summary of the audit results publicly available and provide prescribed notices to affected candidates or employees.


In May 2026, Singapore’s Ministry of Manpower confirmed that employers deploying AI must continue to comply with existing fair and merit-based employment practices and the developing Workplace Fairness framework. At the same time, the government stated that it is still studying the effectiveness and business impact of stronger safeguards adopted elsewhere before deciding what additional approach is appropriate for Singapore. The Workplace Fairness Act 2025, which has been enacted but is not yet in force, specifically covers hiring decisions and protects against discrimination based on characteristics including age, nationality, sex, pregnancy, race, religion, disability and mental health condition.


In the UAE, Article 18 of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data gives individuals the right to object to decisions resulting from automated processing, including profiling, particularly where those decisions have a legal impact or adversely affect them. While this is not specific to recruitment, it could become relevant where an automated hiring makes or materially influences a decision about a candidate. Article 22 of the EU GDPR restricts solely automated decisions, including profiling, that produce legal or similarly significant effects, while Article 24 of China’s Personal Information Protection Law requires automated decision-making to be transparent, fair and impartial and gives individuals affected by significant decisions a right to seek an explanation and refuse decisions made solely through automated means.

 

// Enforcement Reality


While frameworks exist or are coming into existence to tackle specific concerns with the use of AI in recruitment, passing a law is not the same as making it work.


In July 2026, Regulation (EU) 2026/1744 amended the AI Act and moved key requirements for Annex III high-risk AI systems, including recruitment and candidate-selection systems, to 2 December 2027. The delay partly reflected the fact that harmonised standards being developed by the European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC) for areas such as risk management, data governance, human oversight and cybersecurity were still under development. Meanwhile, the EU has also clarified which systems should be considered high-risk in the first place. The European Commission’s 2026 high-risk AI consultation asked whether its guidance and examples were clear enough for businesses and regulators to apply consistently.


Bias audits appear to provide one answer, but their enforcement illustrates another problem. In New York, the State Comptroller in assessing whether the New York City Department of Consumer and Worker Protection had designed and implemented an effective system to enforce compliance with Local Law 144 found that systems had weaknesses. The regulator had received only two complaints during the period examined, and officials acknowledged that identifying non-compliance was particularly difficult where employers simply failed to disclose that they were using an automated tool or failed to publish a bias audit. The Comptroller reviewed the same group of companies as the regulator and identified at least 17 instances of potential non-compliance, compared with one identified by the city's review. This demonstrates the gap between creating an audit requirement and being able to enforce it.


There is also the question of what an audit should test. A system may show similar outcomes across gender and race while still disadvantaging older or disabled candidates. Uneven applicant pools and proxy factors can also make bias harder to identify, meaning that looking only at final outcomes may not show where the problem entered the process.


Third-party recruitment tools create a further challenge. Employers may remain responsible for hiring decisions while having limited access to the model, training data or reasoning behind an external system. This can make it difficult to determine why a candidate was filtered out or where responsibility should lie.


So, while bias audits can identify unequal outcomes, their usefulness depends on what is being measured and which groups are included. Candidate disclosure can improve transparency, but telling someone that AI was involved does not itself establish that the process was fair. Human oversight can provide accountability, but only where the person reviewing the decision understands the system sufficiently and has the authority to challenge its recommendation.


Responsibility between employers and technology providers is equally important. If employers remain responsible for complying with anti-discrimination law, they require sufficient information about the tools they are using to understand how those tools reach important decisions. Otherwise, accountability risks falling into the space between the company that developed the system and the company that relied on it.


Existing employment law can tell us which forms of discrimination are prohibited, but AI regulatory instruments must translate that principle into rules that are measurable, technically workable and practically enforceable.

 

bottom of page