AI in Recruitment: What Sheffield Employers Need to Get Right
AI in recruitment is legal in the UK. That's the easy bit. The harder bit, and the bit that actually matters if a decision gets challenged, is whether the business can explain, justify and evidence how it used the tool. Increasingly, "the software decided" is not a defence. It's an admission that nobody was watching.
The legal framework, briefly
Three things sit underneath any AI recruitment tool: UK GDPR and the Data Protection Act, the Equality Act 2010, and, as of February this year, new automated decision-making safeguards under the Data (Use and Access) Act. Where a significant decision is made solely by automation, an AI auto-rejecting a candidate with no human review, the candidate has the right to be told, to make representations, to get meaningful human intervention, and to contest the outcome. The practical takeaway is straightforward even if the law isn't: keep a genuine human making the actual call.
Bias doesn't need to be intentional to be a problem
An AI system trained on historic hiring data can learn and repeat whatever patterns were baked into that data, including patterns nobody would have signed off on if they'd been written down explicitly. The Equality Act doesn't care that the discrimination was unintentional or delivered by software rather than a person. The employer remains liable for the outcome of the tool it chose to deploy.
What the regulator is actually looking at
The ICO has been auditing AI recruitment vendors and, separately, has been directly engaging with employers using automated decision-making on jobseekers, some of whom have already committed to changing practice off the back of it. Its concerns have centred on inferred demographic data being used to test for bias without being accurate enough to do so reliably, and vendors relying on generic, multi-purpose privacy policies rather than anything specific to what the tool actually does. None of that is abstract regulatory theatre. It's the checklist a business would be measured against if a candidate complained.
What good practice actually looks like
Tell candidates clearly when and how AI is being used to assess them, in plain language, not buried in a privacy policy nobody reads. Keep a human genuinely reviewing outputs, with the authority to override them, not just nodding them through. Run bias audits and keep the records, across more than just gender and ethnicity where possible. And get vendor contracts right, so it's clear who's the data controller, and so the vendor isn't quietly using your candidates' data to train its own model.
The Sheffield SME reality check
Most businesses this size aren't running sophisticated in-house AI hiring systems. They're using AI features bundled into an ATS or job board, often without having thought through any of the above. That's not a reason to panic, it's a reason to ask the vendor a few direct questions before renewal: what bias testing has been done, who's the data controller, and can a hiring decision made with this tool actually be explained to a candidate who asks. If those questions don't have clean answers, that's worth knowing now rather than after a complaint lands.

