Where AI fits in HR work
The line is simple: AI drafts words, people decide things about people. Everything else on this page works out what that means in practice.
ChatGPT, Claude and Copilot are good at first drafts. Job descriptions, policy wording, letters, objective wording, interview question banks. You give them the rough shape, they hand back something you can work with. A person checks and approves every one, every time, because the tool doesn’t know your organisation and will happily write something confident and slightly wrong.
The decisions are different. Who to hire, discipline, dismissal, pay, performance ratings. Those stay human. Not because the tools can’t produce an answer (they will), but because the answer carries weight for a real person, and the law has views about it.
So why start with the drafting? Because the risk is lowest and the check is easiest. If a job description comes back clunky, you spot it, fix it and move on. If a screening tool quietly rejects people for the wrong reasons, you might never know. Start where mistakes are visible.
And one habit worth getting into early: the facts come from your HR system, never from the AI. Pay, headcount, absence, dates. The AI drafts the words around them, and a person checks them against the system of record before anything goes out.
AI in recruitment and the law
Recruitment is where this gets serious, so here is the law in plain English.
Automated decisions: UK GDPR Articles 22A to 22D
The UK GDPR’s old Article 22 has been replaced. The Data (Use and Access) Act 2025 substituted Articles 22A to 22D, fully in force from 5 February 2026.
Two phrases matter. A decision is “based solely on automated processing” if there is no meaningful human involvement in taking it. A “significant decision” is one with a legal or similarly significant effect on the person.
Where a significant decision about someone is based solely on automated processing, the employer must have safeguards in place. Tell the person about the decision. Let them make representations. Let them obtain human intervention. Let them contest it. The ICO’s guidance on this was updated in draft on 31 March 2026 and is out for consultation, so check the current version before you rely on it.
Equality Act risk
The Equality Act 2010 lists nine protected characteristics: age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex and sexual orientation.
Acas is clear that employers must not discriminate when advertising, interviewing and deciding who to employ. Discrimination can be direct, or indirect: a rule that is the same for everyone but has a worse effect on someone because of a protected characteristic. That second kind is where AI tools tend to bite, because a tool can apply the same rule to everybody and still land badly on one group. You must also make reasonable adjustments for disabled applicants, which a tool alone may not be able to do.
What the ICO found
In November 2024 the ICO reported on its audits of several providers of AI recruitment tools, with almost 300 recommendations. Some tools let recruiters filter out candidates with certain protected characteristics. Others inferred gender and ethnicity from a candidate’s name instead of asking. Some collected far more personal information than necessary and kept it indefinitely. The ICO also published key questions for organisations buying these tools.
It raises the stakes that health data is special category data under UK GDPR, and so are some protected characteristics: race, religion or belief and sexual orientation, plus disability, pregnancy and gender reassignment where they reveal health information.
The government’s Responsible AI in Recruitment guide (DSIT, March 2024) warns that AI in hiring can perpetuate existing biases, cause digital exclusion and lead to discriminatory job advertising and targeting. In short, it says to:
- consider whether the tool falls within the UK GDPR automated decision-making rules, and whether you need a data protection impact assessment (DPIA)
- ask the supplier for evidence of a bias audit, and for their own impact assessments
- keep effective human oversight of the system and what it produces
Its worked example is a good one. An organisation routes applicants who declare a disability to a manual review instead of AI scoring, and clearly tells applicants that AI is used. If a supplier’s answers to these questions are vague, that tells you something.