AI in Recruitment: What Do UK Recruitment Agencies Need to Know About Compliance, GDPR and the EU AI Act?

UK recruitment agencies can use AI, but senior leaders need to understand where it is being used, what candidate or employee data it processes, whether it influences recruitment decisions and whether UK data protection rules or the EU AI Act apply.

AI is now appearing throughout recruitment: CV screening, candidate matching, job adverts, interview transcription, candidate communications, assessments and tools built directly into recruitment platforms.

For leadership teams, the issue isn’t simply whether employees are “using AI”. There are 3 areas of AI risk to understand: UK data protection and employment considerations, potential EU AI Act exposure, and internal AI governance.

For UK recruitment businesses working with EU clients or candidates, the question becomes particularly important because being based outside the EU does not automatically put an organisation outside the scope of the EU AI Act.

The practical starting point is therefore simple:

Find your AI usage→ understand how it is being used → establish your EU exposure → assess the risks → put proportionate controls around it.

Why Should Recruitment Leaders Be Looking at AI Governance Now?

AI in recruitment is no longer limited to specialist technology companies.

Recruiters can encounter AI when they:

  • write job descriptions;
  • search for candidates;
  • parse CVs;
  • rank or match candidates;
  • summarise candidate information;
  • transcribe interviews;
  • draft candidate communications;
  • assess applicants;
  • automate outreach;
  • analyse recruitment data.

Some of these uses are relatively low-impact. Others can influence opportunities and decisions affecting real people. That distinction matters.

The Information Commissioner’s Office (ICO) has already scrutinised AI recruitment technology. Following audits of AI recruitment providers, the regulator reported making almost 300 recommendations relating to areas including fairness, transparency, data minimisation and potential discrimination.

More recently, in March 2026, the ICO published further guidance following work with more than 30 employers, focusing specifically on automated recruitment decisions.

For CEOs, Managing Directors, Operations Directors and recruitment leaders, this creates a straightforward governance question:

Could you explain what AI your business is using, what it does with candidate data and where human decision-making begins and ends?

If the answer is unclear, that’s a sensible place to start.

What Are the 3 Main AI Risks for a UK Recruitment Agency?

We recommend looking at recruitment AI through a simple 3-part Recruitment AI Risk Framework.

1. UK Data Protection and Recruitment Risk

AI doesn’t remove your existing responsibilities around personal data simply because a third-party system performs the processing.

Recruitment can involve substantial amounts of personal information, including:

  • names and contact information;
  • employment histories;
  • CVs;
  • salary information;
  • interview notes;
  • assessment results;
  • right-to-work information;
  • inferred information about candidates;
  • potentially special category data.

If AI is introduced into these workflows, organisations need to understand what data is being processed, why it is being processed, where it goes and how the resulting information is used.

This becomes particularly important when automated processing influences decisions about candidates.

UK government guidance on responsible AI in recruitment highlights issues including data protection, bias and discrimination, transparency, human oversight, impact assessments and AI assurance.

The ICO has also specifically encouraged organisations to review safeguards around automated recruitment decisions.

So the question isn’t whether AI is legal in recruitment. A better question is: “How are we using AI, what decisions does it influence and do we have appropriate safeguards?”

2. EU AI Act Risk

The second area is particularly important for UK recruitment businesses with European activities.

A common misconception is: “We’re a UK business, so the EU AI Act doesn’t apply to us.”

That conclusion can be wrong. The territorial scope of the EU AI Act can extend beyond organisations established within the European Union.

For example, the Act covers providers placing AI systems on the EU market regardless of whether they are established in the EU. It also contains provisions applying to certain providers and deployers outside the EU where the output produced by their AI systems is used within the EU.

For a UK recruitment business, this creates several questions:

Do you recruit candidates in EU countries?

Do you work for clients based within the EU?

Are outputs from your AI systems used within the EU?

Do you sell or provide an AI-enabled recruitment system into the EU?

If there is an EU connection, the next step is to establish exactly what the business is doing and which AI systems are involved.

3. Internal AI Governance Risk

The third risk is one that can exist regardless of whether the EU AI Act applies:

Do you actually know how your employees are using AI?

A recruitment agency might officially have only one approved AI product while individual consultants are also using ChatGPT, Copilot, transcription applications, CV tools, browser extensions and other AI services.

That creates Shadow AI. Shadow AI doesn’t necessarily mean employees are behaving irresponsibly. Often, they’re trying to work faster. But leadership cannot manage risks it cannot see.

Questions worth asking include:

  • Which AI applications are approved?
  • Which applications contain candidate information?
  • Can employees paste CVs into public AI tools?
  • Which AI features are already built into the ATS or CRM?
  • Who assesses a new AI supplier before employees start using it?
  • Is human review required before AI-generated information is acted upon?
  • Who owns AI governance internally?
  • Are employees trained on acceptable AI use?

The objective shouldn’t be to stop useful AI adoption.

It should be to make safe AI easier than uncontrolled AI.

Is AI Recruitment Considered High-Risk Under the EU AI Act?

Certain AI systems used for recruitment and selection can be classified as high-risk under the EU AI Act.

Annex III of the Act specifically identifies certain AI systems intended for employment, worker management and access to self-employment.

This includes AI systems intended to be used for:

  1. placing targeted job advertisements;
  2. analysing and filtering job applications;
  3. evaluating candidates.

That makes recruitment a particularly important industry for AI governance. But it does not mean every use of AI within a recruitment agency automatically becomes a high-risk AI system.

Consider these two examples.

Example A: A consultant asks an AI assistant to suggest alternative wording for a job advertisement. The consultant reviews and rewrites the output before publication.

Example B: An AI system analyses 500 applications, evaluates candidate suitability and produces a ranked shortlist that influences who progresses.

Those are very different uses of AI.

The correct approach is therefore to assess the specific AI system, its intended purpose and how it is actually being used.

Does Using ChatGPT or Microsoft Copilot Make a Recruitment Agency High-Risk?

No. Simply using ChatGPT, Microsoft Copilot or another general-purpose AI application does not automatically mean your recruitment business is operating a high-risk AI system.

Context matters. There is a significant difference between using AI to summarise internal meetings and using it to evaluate whether an applicant should progress to the next stage of recruitment.

This is why an AI inventory should record both the technology and the use case.

A useful register might contain:

AI tool → supplier → owner → purpose → data processed → decision affected → EU connection → risk → required controls.

That gives senior management a much clearer picture than simply maintaining a list of software licences.

What Should Recruitment Directors Ask Their AI Suppliers?

This is frequently overlooked. Buying an AI-powered recruitment platform doesn’t transfer every responsibility to the software company.

Before implementing an AI recruitment product, consider asking the supplier:

  1. Exactly where does the product use AI?
  2. What candidate data does the AI process?
  3. Is our data used to train AI models?
  4. Where is information processed and stored?
  5. How does the system rank, score or evaluate candidates?
  6. What testing has been performed for bias and discrimination?
  7. What human oversight is expected from us?
  8. What Data Protection Impact Assessments or supporting documentation are available?
  9. How does the supplier approach EU AI Act classification and compliance?
  10. What happens to our candidate data when the contract ends?

The ICO itself recommends that recruiters procuring AI technologies consider matters such as DPIAs, lawful basis, controller/processor roles, bias mitigation and transparency.

A supplier saying “our product is AI compliant” should therefore not be the end of your due diligence.

Example: A 50-Person UK Recruitment Agency Using AI

Consider a fictional recruitment company employing 50 people. It operates primarily in the UK but has clients in Ireland, France and Germany.

The business uses:

  • an AI-enabled recruitment CRM;
  • automated CV parsing;
  • candidate matching;
  • ChatGPT;
  • Microsoft Copilot;
  • AI meeting transcription.

Senior management knows the company “uses AI”, but there is no AI register, formal acceptable-use policy or process for assessing AI suppliers. Some consultants occasionally paste candidate information into AI tools.

The company wants to introduce more automation over the next 12 months. What should leadership do?

It shouldn’t ban AI. Nor should it immediately assume every system breaches the EU AI Act. Instead, the agency could work through the 5-step framework:

Find → Map → Check EU Exposure → Assess → Govern.

The outcome might identify low-risk productivity uses that can continue with straightforward controls, higher-impact candidate applications requiring more detailed assessment, and specific EU-connected activities requiring an EU AI Act applicability review.

The business then has something much more valuable than a generic “AI policy”: a practical roadmap for adopting more AI with visibility and control.

This example is illustrative and is not an Impact IT Solutions client case study.

Does a UK Recruitment Agency Need an AI Policy?

If employees are already using AI for business activities, an AI acceptable-use policy is a sensible foundation for governance.

A useful AI policy should answer practical employee questions such as:

  • Which AI tools can I use?
  • Can I enter candidate information?
  • Can I upload CVs?
  • What information is prohibited?
  • Do I need to check AI-generated content?
  • Can AI evaluate candidates?
  • What do I do if I want a new AI application?
  • Who do I speak to if I’m unsure?

The policy needs to reflect what employees actually do.

A generic AI policy downloaded from the internet but disconnected from the organisation’s technology, data and processes is unlikely to solve the underlying problem.

Do Recruitment Agencies Need an AI Risk Assessment?

Higher-impact AI use cases should be assessed before organisations rely upon them for important recruitment activities.

Risk assessments can consider:

Purpose → People → Data → Decisions → Security → Suppliers → Regulation → Human Oversight.

An organisation using AI to draft internal meeting notes will usually face a very different risk profile from one introducing automated candidate evaluation.

Risk-based governance allows businesses to make that distinction.

What Should a UK Recruitment Agency Do About AI Now?

For most SMEs, start with 5 actions:

1. Identify the AI already being used.
Include AI embedded inside existing recruitment software and employee-led Shadow AI.

2. Identify candidate data entering AI systems.
Understand what is being uploaded, processed, stored and generated.

3. Identify AI influencing candidate decisions.
Pay particular attention to screening, filtering, matching, scoring and evaluation.

4. Check EU AI Act applicability.
If your recruitment activities connect with the EU, establish whether and how the Act applies rather than making assumptions.

5. Create an AI governance roadmap.
Prioritise the highest-risk gaps and enable employees to use approved AI safely.

How Can Impact IT Solutions Help Recruitment Agencies Manage AI?

Impact IT Solutions provides Managed AI Services for UK SMEs that want to adopt AI productively while maintaining appropriate security, governance and oversight.

Our AI Foundations Assessment includes:

  • AI & Copilot Readiness Assessment
  • EU AI Act Applicability Assessment
  • AI Governance Starter Pack
  • AI awareness and training
  • AI Readiness Report and Roadmap

For organisations progressing further with AI, our Managed AI services can also support ongoing AI risk assessments, AI supplier and vendor reviews, governance maintenance and ISO 42001 readiness.

This allows leadership to move from: “We’re pretty sure people are using AI.” to: “We know what we’re using, where the risks are and what we’re doing about them.”


Frequently Asked Questions About AI Compliance in Recruitment

Is AI recruitment legal in the UK?

Yes, AI can be used in recruitment in the UK. However, organisations still need to comply with applicable requirements including data protection and equality law. The level of governance required depends on how the AI is being used, the data involved and its influence over decisions.

Does the EU AI Act apply to UK recruitment agencies?

It can. Being headquartered in the UK does not automatically exclude a recruitment company from the EU AI Act. Its applicability depends on factors including the organisation’s role, AI systems, EU activities and where AI outputs are used.

Is AI CV screening high-risk under the EU AI Act?

It can be. Annex III identifies certain AI systems intended to analyse and filter job applications and evaluate candidates within its high-risk employment category. The individual system, intended purpose and circumstances still need to be assessed.

Can recruiters put CVs into ChatGPT?

Recruitment companies should not assume that uploading candidate information to an AI service is acceptable simply because employees have access to the tool. The organisation needs to consider personal-data processing, security, contractual settings, purpose, lawful basis and its own AI/data policies before allowing candidate information to be entered into AI systems.

Does our recruitment agency need an AI policy?

If employees use AI for business activities, an AI acceptable-use policy is a sensible governance control. It should clearly explain approved tools, prohibited data, human-review requirements and how employees obtain approval for new AI applications.

What is Shadow AI?

Shadow AI is the use of AI applications for work without appropriate organisational approval, visibility or governance. In recruitment this could include consultants independently using generative AI, transcription tools, browser extensions or other AI services with candidate or company information. Find out more here.

Do recruitment agencies need a DPIA for AI?

A Data Protection Impact Assessment may be required where processing is likely to result in a high risk to people’s rights and freedoms. Recruitment organisations should assess their specific processing rather than assume every AI application either does or does not require a DPIA.

Who is responsible for AI supplied by our ATS or recruitment software provider?

The supplier’s responsibilities do not necessarily remove the recruitment company’s own obligations. Organisations should understand their role, how the AI operates, what personal data is processed and what decisions or outputs they rely upon.

How do we check whether the EU AI Act applies?

Start by identifying your AI systems, intended uses, organisational role, EU connections and where outputs are used. Impact IT Solutions includes an EU AI Act Applicability Assessment within its AI Foundations Assessment to help UK SMEs establish where they stand.


This article provides general information about AI governance, data protection and the EU AI Act. It is not legal advice.

Find Out Where Your Business Stands

If your recruitment agency is already using AI or you’re planning greater AI adoption, the first step doesn’t need to be a large compliance project.

Start by answering three questions: what AI are we using, what are the risks, does the EU AI Act apply to us?

Share this article