Skip to content
3 role hubs · 7 tasksData privacy

AI for HR

Use ChatGPT, Claude or Copilot to draft HR words: job descriptions, policies, letters, objectives. Keep decisions about people human, and check UK GDPR and Equality Act rules before AI touches hiring.

Ranked jobs to hand over5Lowest risk first
Jobs to keep human6For now
Task guides34 more planned
Rules105 do's · 5 don'ts

What to hand to AI first

Ranked · 5
  1. Job description first draftsYou supply the duties and the skills; AI gives them structure. Mistakes are easy to see, and the inclusive-language check is quick.Full guideGuide: Job descriptions with ChatGPT (and Claude or Copilot)
  2. Policy structure and plain-English wordingAI is good at turning dense handbook text into readable sections. The legal minimums come from GOV.UK and Acas, and a named person approves.Full guideGuide: HR policies with ChatGPT: draft, check against UK law, approve
  3. Interview question banksQuestions drawn from the job description are quick to draft. Check each one is relevant to the job and fair to every applicant.
  4. Template lettersWork on the template, not on a letter to a named person, and you never need to paste anyone's details in.
  5. Performance review write-ups and objective wordingAI can shape a manager's anonymised notes into a balanced draft and tighten objectives. The rating stays with the manager.Full guideGuide: AI for performance reviews: write-ups, not judgements

Where AI fits in HR work

The line is simple: AI drafts words, people decide things about people. Everything else on this page works out what that means in practice.

ChatGPT, Claude and Copilot are good at first drafts. Job descriptions, policy wording, letters, objective wording, interview question banks. You give them the rough shape, they hand back something you can work with. A person checks and approves every one, every time, because the tool doesn’t know your organisation and will happily write something confident and slightly wrong.

The decisions are different. Who to hire, discipline, dismissal, pay, performance ratings. Those stay human. Not because the tools can’t produce an answer (they will), but because the answer carries weight for a real person, and the law has views about it.

So why start with the drafting? Because the risk is lowest and the check is easiest. If a job description comes back clunky, you spot it, fix it and move on. If a screening tool quietly rejects people for the wrong reasons, you might never know. Start where mistakes are visible.

And one habit worth getting into early: the facts come from your HR system, never from the AI. Pay, headcount, absence, dates. The AI drafts the words around them, and a person checks them against the system of record before anything goes out.

AI in recruitment and the law

Recruitment is where this gets serious, so here is the law in plain English.

Automated decisions: UK GDPR Articles 22A to 22D

The UK GDPR’s old Article 22 has been replaced. The Data (Use and Access) Act 2025 substituted Articles 22A to 22D, fully in force from 5 February 2026.

Two phrases matter. A decision is “based solely on automated processing” if there is no meaningful human involvement in taking it. A “significant decision” is one with a legal or similarly significant effect on the person.

Where a significant decision about someone is based solely on automated processing, the employer must have safeguards in place. Tell the person about the decision. Let them make representations. Let them obtain human intervention. Let them contest it. The ICO’s guidance on this was updated in draft on 31 March 2026 and is out for consultation, so check the current version before you rely on it.

Equality Act risk

The Equality Act 2010 lists nine protected characteristics: age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex and sexual orientation.

Acas is clear that employers must not discriminate when advertising, interviewing and deciding who to employ. Discrimination can be direct, or indirect: a rule that is the same for everyone but has a worse effect on someone because of a protected characteristic. That second kind is where AI tools tend to bite, because a tool can apply the same rule to everybody and still land badly on one group. You must also make reasonable adjustments for disabled applicants, which a tool alone may not be able to do.

What the ICO found

In November 2024 the ICO reported on its audits of several providers of AI recruitment tools, with almost 300 recommendations. Some tools let recruiters filter out candidates with certain protected characteristics. Others inferred gender and ethnicity from a candidate’s name instead of asking. Some collected far more personal information than necessary and kept it indefinitely. The ICO also published key questions for organisations buying these tools.

It raises the stakes that health data is special category data under UK GDPR, and so are some protected characteristics: race, religion or belief and sexual orientation, plus disability, pregnancy and gender reassignment where they reveal health information.

Checks before you buy a screening tool

The government’s Responsible AI in Recruitment guide (DSIT, March 2024) warns that AI in hiring can perpetuate existing biases, cause digital exclusion and lead to discriminatory job advertising and targeting. In short, it says to:

  • consider whether the tool falls within the UK GDPR automated decision-making rules, and whether you need a data protection impact assessment (DPIA)
  • ask the supplier for evidence of a bias audit, and for their own impact assessments
  • keep effective human oversight of the system and what it produces

Its worked example is a good one. An organisation routes applicants who declare a disability to a manual review instead of AI scoring, and clearly tells applicants that AI is used. If a supplier’s answers to these questions are vague, that tells you something.

Status rows

Do's and don'ts.

Green rows are habits worth keeping. Red rows are the ones that cost trust when they go wrong.

  • Treat every output as a draftA person checks and approves everything AI writes before it is used, sent or published.
  • Take facts from the system of recordPay, headcount, absence and dates come from your HR system or payroll, never from the AI.
  • Get the legal minimums from the sourceCopy requirements from GOV.UK, Acas and the ICO, and check them against the current version of each page.
  • Ask suppliers for evidenceBefore buying an AI recruitment tool, ask for bias audit results and their own impact assessments, as the DSIT guide suggests.
  • Tell applicants when AI is usedThe DSIT guide's worked example signposts AI use to applicants and offers a manual route.
  • Don't let a tool make a significant decision aloneA decision about a person based solely on automated processing brings legal safeguards under UK GDPR Articles 22A to 22D.
  • Don't filter or infer by protected characteristicThe ICO found tools that let recruiters filter out candidates with protected characteristics, or guessed gender and ethnicity from names.
  • Don't paste in what you don't needNames, health details and disciplinary history have no place in a drafting prompt. Use placeholders.
  • Don't take the AI's word on the lawIt can state a rule, a rate or a time limit confidently and wrongly. Check every one on GOV.UK or Acas.
  • Don't make AI the only route inDisabled applicants are entitled to reasonable adjustments, and some people cannot use, or do not have access to, the technology.

Task tiles

Tasks for HR.

Full guides carry the steps, the prompts, a checkpoint after each step and a sign-off checklist. Planned tasks are next, in this order.

Full guideJob descriptions with ChatGPT (and Claude or Copilot)Beginner · About 45 minutes to an hour for one roleChatGPTFull guideHR policies with ChatGPT: draft, check against UK law, approveIntermediate · About half a day for one policy, plus time for consultation and approvalChatGPTFull guideAI for performance reviews: write-ups, not judgementsBeginner · About an hour per review once your notes are in orderChatGPT
PlannedAI for recruitment screeningWhat a screening tool may and may not do, the UK GDPR rules on automated decisions, and how to check for bias.
PlannedInterview questions with AIBuilding a question bank from the job description, and checking it for relevance and fairness.
PlannedOnboarding plans with AITurning your handbook and the job description into a first-month plan for a new starter.
PlannedHR letters with AITemplate letters for offers, changes and invitations to meetings, drafted without anyone's personal details.

Confidentiality and UK GDPR

Before you paste anything: green, amber or red.

Before you paste anything, ask two questions: is there personal data in it, and is it confidential to my organisation or a client? If the answer to either is yes, use a tool your organisation has approved, under a business contract, and send only what the task needs.

Green · fine to share

Give it structure, not identities

Codes, headings, layouts, policy wording and your own notes with names taken out are usually enough. Customer names, staff names and bank details almost never are.

Ask for the formula, the template or the draft, not the answer. A formula you can test or a draft you can edit is checkable. A total typed back into a chat window is not.

Amber · approved tools only

Real data goes in an approved business tier

If it is your organisation's or a client's information, use the tool your organisation has approved, under its contract, not a personal account.

Under a business contract the provider usually acts as your processor. On a personal account you are agreeing to its consumer terms instead.

Red · never in a consumer tool

Never paste these into a personal AI account

  • Payroll reports, salaries by name, bank details or National Insurance numbers
  • Named employee records: health, absence, grievance or disciplinary details
  • Customer or supplier ledgers with names attached
  • Unpublished results, forecasts or board papers
  • Anything a client has given you
  • Passwords, API keys or bank logins (in any tool, ever)
UK GDPR, in four lines
  1. Send the minimum. UK GDPR's data minimisation principle says personal data must be adequate, relevant and limited to what is necessary for the purpose. For most tasks on this site, the personal data the AI needs is none. 1ICO: The data minimisation principleico.org.uk
  2. Know who is controller and who is processor. Under a business contract, the AI provider usually acts as your processor. On a personal consumer account, you are agreeing to the provider's own consumer terms instead. 2ICO: Controllers and processorsico.org.uk
  3. Check where the data goes. Many AI services process data outside the UK. Restricted transfers need safeguards, which a business agreement usually addresses and a personal sign-up does not. 3ICO: International transfersico.org.uk
  4. The ICO has AI-specific guidance. It covers accountability, transparency, accuracy and security when organisations use AI with personal data. 4ICO: Guidance on AI and data protectionico.org.uk
Confidentiality
  • Your employment contract almost certainly includes a duty of confidentiality, and your organisation may have an AI policy. Read both before you start.
  • Client information belongs to the client. If you work in practice, confidentiality is one of the fundamental principles in professional codes such as ICAEW's. 5ICAEW Code of Ethics (confidentiality is a fundamental principle)www.icaew.com
  • Commercially sensitive information (pricing, margins, unpublished results, deal work) counts even when it contains no personal data.
Consumer plans vs business tiersChecked 1 October 2026
AI tool tiers and whether your data trains models
ProviderPersonal plansBusiness and enterprise
OpenAI (ChatGPT)Check settingsPersonal plans: conversations can be used to train models unless you turn off "Improve the model for everyone" in Settings > Data controls.Not trained on by defaultChatGPT Business, Enterprise, Edu and the API: not used to improve models by default.6OpenAI Help Centre: How your data is used to improve model performancehelp.openai.com7OpenAI: Enterprise privacy at OpenAIopenai.com
Anthropic (Claude)Check settingsFree, Pro and Max: chats are used to train models only when the model-improvement setting is on. With it on, data is kept for up to five years; with it off, the standard is 30 days.Not trained on by defaultClaude for Work and the API: inputs and outputs are not used to train models by default.8Anthropic: Updates to Consumer Terms and Privacy Policywww.anthropic.com9Anthropic Privacy Center: Is my data used for model training? (consumer)privacy.claude.com10Anthropic Privacy Center: Is my data used for model training? (commercial)privacy.claude.com
Microsoft (Copilot)Check settingsPersonal Microsoft accounts are covered by Microsoft's consumer terms, not your organisation's.Processor under DPACopilot and Copilot Chat used through an organisation: covered by Microsoft's Data Protection Addendum with Microsoft as processor; your data is not used to train foundation models.11Microsoft Learn: Enterprise data protection in Microsoft Copilot and Copilot Chatlearn.microsoft.com12Microsoft Learn: Data, privacy and security for Microsoft Copilotlearn.microsoft.com

From the same studio · disclosed

Where one of ours fits

Forematter. In development, not open to customers yet. It answers staff questions from a company's own approved documents and shows where each answer came from: the onboarding end of HR.

Can You Use AI. The candidate's side of the same question: what applicants are told about using AI in interviews and tests, useful when you set your own rules.

Ours: made by the same studio that runs this site.

Forematter · pre-launch, no sign-up yetCan You Use AI: answer interview questions

Questions

Questions people ask. Every answer open.

Short answers, drawn from this page. The sources are listed above.

Something missing, or out of date? Tell the author.

Email hello@usingaias.com

HR 5

Can I use ChatGPT for HR work?
Yes, for drafting: job descriptions, policy wording, template letters, interview question banks and review write-ups. A person checks and approves every draft, and decisions about people stay human.
Is it legal to use AI to screen job applicants in the UK?
It can be, but if a significant decision such as rejecting someone is based solely on automated processing, UK GDPR Articles 22A to 22D require safeguards: telling the person, letting them make representations, get human intervention and contest the decision. Equality Act discrimination risk applies too.
What replaced Article 22 of the UK GDPR?
Articles 22A to 22D, substituted by the Data (Use and Access) Act 2025 and fully in force from 5 February 2026. The ICO is consulting on its updated guidance.
What did the ICO find when it audited AI recruitment tools?
In November 2024 it reported almost 300 recommendations. Some tools let recruiters filter out candidates with protected characteristics, some inferred gender and ethnicity from names, and some collected more data than necessary and kept it indefinitely.
Which HR jobs should never be handed to AI?
Decisions about people: who to hire, discipline, dismissal, pay and performance ratings.