Responsible AI governance for HR and recruitment, mapped to the EU AI Act, NYC Local Law 144 and UK employment law

HR & RECRUITMENT

Responsible AI Governance for Hiring

HR teams are deploying AI to screen, rank and assess candidates faster than they can govern it. We engineer the governance that keeps your hiring AI lawful and fair under the EU AI Act, NYC Local Law 144 and UK employment and data protection law, so the people committee can sign it off with confidence.

For CHROs, Heads of Talent Acquisition, HR Directors and their employment lawyers. AEO and employer-brand content handled downstream, engineered to the same compliance standard rather than gamed.

THE EXPOSURE

Why AI Hiring Is Now a Board-Level Risk

Hiring sits under regimes that all reach AI: the EU AI Act, GDPR, the Equality Act and a growing US state patchwork led by NYC. Deploy AI to screen people without governing it and the exposure is regulatory and personal, not just reputational.

EUR 35M / 7%

Maximum EU AI Act fine for prohibited AI practices

Article 99 sets fines up to EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher, for prohibited practices. High-risk breaches reach EUR 15 million or 3 percent. Recruitment AI sits in the high-risk tier, and the exposure sits at board level.

EU AI Act, Article 99 (artificialintelligenceact.eu)

Annex III.4

Recruitment AI is high-risk under the EU AI Act

Annex III point 4(a) names AI used to place targeted job adverts, analyse and filter applications, and evaluate candidates. Point 4(b) covers AI that decides on promotion, termination, task allocation and performance monitoring. The full high-risk obligations apply.

EU AI Act, Annex III point 4 (artificialintelligenceact.eu)

10 days

NYC LL144 candidate notice before an AI hiring tool runs

An automated employment decision tool needs an independent bias audit, a published summary of the results, and notice to candidates at least 10 business days before use. In effect since 1 January 2023, enforced from 5 July 2023.

NYC Local Law 144 (nyc.gov, DCWP rules)

Nov 2024

ICO published its AI-in-recruitment outcomes report

The ICO audited recruitment AI providers and issued close to 300 recommendations, with a DPIA expected before any screening tool goes live. Under UK GDPR Article 22, solely automated rejections need meaningful human review, and the Equality Act 2010 covers indirect discrimination.

ICO AI tools for recruitment outcomes report (ico.org.uk)

THE POSITION

Govern AI Hiring Well and It Becomes an Advantage

Regulation isn't the enemy of AI in hiring. Govern it properly and you screen at scale while rivals are still arguing about who owns the risk.

Governed hiring AI ships faster

Teams with a clear governance model approve new hiring tools in days, not quarters. The bottleneck is rarely the model. It is the absence of an agreed way to assess and sign off the risk.

Bias audits are a hiring asset, not a tax

A documented bias audit doesn't just satisfy NYC LL144. It tells candidates and regulators you tested the tool, which is exactly the trust signal a fair hiring process needs.

Fairness expertise is your trust asset

Your people team understands fairness and the Equality Act better than any vendor. Turned into governed AI and into clear, accurate published guidance, that expertise is what regulators and AI search engines both reward.

AEO without dark patterns protects the brand

The wider AEO industry is being penalised for manipulative tactics. Done to a Responsible AI standard, employer-brand visibility is engineered cleanly, so an accurate careers page is also the one AI engines cite.

OUR APPROACH

Systems. Strategy. Execution.

The same three-level framework, recast for the AI governance, fairness and compliance realities of modern hiring.

1

SYSTEMS

AI Hiring Governance Operating Model

We architect the governance your CHRO, Head of Talent Acquisition and employment counsel can stand behind. Every hiring tool that screens, ranks or assesses people mapped to its obligations under the EU AI Act, UK GDPR, the Equality Act and the US state patchwork, with clear ownership and escalation.

  • -Hiring-tool inventory and Annex III high-risk classification
  • -Governance operating model: roles, controls, escalation
  • -EU AI Act, UK GDPR, Equality Act and NYC LL144 obligation mapping
  • -Board and people-committee reporting on AI hiring risk
2

STRATEGY

AI Hiring Risk and Compliance Roadmap

We build a prioritised AI risk register and remediation roadmap for your hiring stack, sequenced to real deadlines. Where AI search and employer-brand content sit in scope, we set the guardrails before the work runs.

  • -AI risk register scored by likelihood and regulatory exposure
  • -Bias-audit readiness assessment for in-scope hiring tools
  • -Vendor and model assessment against the EU AI Act timeline
  • -AEO guardrails for accurate, fair employer-brand content
3

EXECUTION

Audits, Artefacts and Compliant AEO

When execution is needed, we engineer the evidence. Bias and fairness audits, DPIAs, vendor assessments, governance artefacts, and answer engine optimisation built to compliance standard so your employer brand holds up under scrutiny.

  • -Bias, fairness and adverse-impact audits for hiring tools
  • -DPIAs and Article 22 human-review process design
  • -Governance artefacts: technical documentation, logging, oversight
  • -AEO and content engineering without dark patterns

WHERE WE CREATE VALUE

Typical HR and Recruitment Engagements

Illustrative scenarios reflecting the types of team we work with. Specific scope depends on your hiring stack, regulatory footprint and risk appetite.

CANDIDATE SCREENING

Employer Filtering Applications with AI

AI ranks and filters job applications at volume. Annex III point 4(a) makes the tool high-risk, yet the bias testing, human oversight and technical documentation are not in place, and candidates are not told.

Systems-level engagement: classify the in-scope tools, build the risk management and logging required, and design the human-review and candidate-notice processes the EU AI Act and UK GDPR expect.

BIAS AUDIT

Talent Team Hiring in New York City

An automated employment decision tool screens candidates for NYC-based roles. NYC Local Law 144 needs an independent bias audit, a published summary and 10 business days of candidate notice, none of which is live.

Bias-audit readiness programme: scope which tools are in scope, stand up the independent audit, publish the summary, and put the candidate-notice process in place before the tool runs.

VENDOR ASSESSMENT

HR Buying an AI Assessment Platform

The team is procuring a video-interview or assessment tool from a vendor. Under the EU AI Act the deployer carries obligations too, and the Illinois AI Video Interview Act adds notice, consent and deletion rules in that state.

Vendor and model assessment: due diligence on the tool, deployer-obligation mapping, and a register that records bias testing, lawful basis and jurisdiction-specific notice rules.

EMPLOYER BRAND

Staffing Firm Engineering AI Visibility Safely

Marketing uses AI to generate employer-brand and careers content and wants visibility in AI search. Claims about how candidates are assessed must be accurate, and the wider AEO industry is being penalised for dark patterns.

Governance-led AEO: guardrails for AI-generated employer-brand content, claim substantiation, and answer engine optimisation engineered to compliance standard rather than gamed.

WHY US

We Understand Regulated Markets

Sotiris has 27 years across regulated markets where mistakes cost licences, not just rankings, and is the author of Ethical AI, AI Moats and TRANSFORM. VerityAI is a Responsible AI advisory, not a software platform. We govern your hiring AI and your employer-brand visibility from the same principle: build it so it holds up under scrutiny.

Governance the people committee can defend

We architect AI hiring governance mapped to the EU AI Act, UK GDPR, the Equality Act and NYC LL144, with ownership and evidence a regulator or tribunal can follow. Not a policy PDF. A working operating model.

Responsible AI applied to AI search

AI engines reward authoritative, well-structured, expert-attributed content. We engineer that employer-brand visibility without the dark patterns the AEO industry is being penalised for, so it stays accurate and fair.

Board language, not jargon

We speak to CHROs, HR directors and employment counsel. Reporting connects AI to regulatory exposure, discrimination risk and candidate outcomes, not vanity metrics.

FROM THE PUBLIC RECORD

What Ungoverned Hiring AI Actually Costs

Named cases are public record with sources cited. Composites are flagged and identify no client.

PUBLIC RECORD

Workday: the deployer defence didn't hold

In Mobley v. Workday (N.D. Cal.), a federal court let an age-discrimination claim over AI applicant screening proceed as a nationwide collective action under the ADEA, certified on 16 May 2025. The court found the vendor could be liable as an agent of the employers using its tool.

Takeaway: "the vendor built it" is not a shield. The employer and the tool both carry the risk.

Mobley v. Workday, N.D. Cal. (Fisher Phillips case analysis, fisherphillips.com)

PUBLIC RECORD

iTutorGroup: an age filter, in the code

The EEOC alleged iTutorGroup's recruiting software automatically rejected women aged 55 and over and men aged 60 and over, screening out more than 200 US applicants. It settled in 2023 for $365,000, the EEOC's first AI-related hiring case.

Takeaway: an untested rule inside a screening tool is a documented liability the moment a regulator looks.

EEOC v. iTutorGroup, settlement announced 2023 (eeoc.gov newsroom)

COMPOSITE

The tool nobody had classified

Composite, built from several engagements. A UK employer had bought an AI CV-screening tool and switched it on before anyone had classified it as high-risk or run a fairness check. No bias audit, no DPIA, no human-review step for rejections. The exposure sat with them, not the vendor.

Takeaway: most hiring AI risk we see isn't a rogue algorithm. It's a tool deployed with no governance around it.

Composite of VerityAI engagements. No client identified.

START HERE

Wherever You Are in the Decision

Three routes in, depending on where you've got to. Learn the rules, compare the approaches, or move to a decision.

LEARN THE RULES

Getting oriented

New to how AI regulation lands on hiring? Start with what the rules actually require, then with how bias creeps into a screening tool and how to detect it before it reaches a candidate.

COMPARE YOUR OPTIONS

Weighing approaches

Already scoping the problem? Look at how to build a compliant hiring system, and what changes when you hire into a regulated industry where the compliance picture is sharper.

READY TO ACT

Moving to a decision

Ready to govern it properly? Start with the NYC LL144 requirements and the risk register template, then book a conversation about your hiring stack and where governance reduces the most risk.

BY JURISDICTION

UK, US and EU: The Rules Are Not the Same

The same hiring tool sits under different rulebooks depending on where it operates. We advise UK-first, and serve US and EU clients in English.

UK

Lead market. We advise UK-first.

  • -Equality Act 2010: an AI screening tool that disadvantages a protected group can be indirect discrimination
  • -ICO guidance on AI in recruitment: a DPIA expected before a tool goes live, close to 300 recommendations issued
  • -UK GDPR Article 22: solely automated rejections need meaningful human review

US

Served in English.

  • -NYC Local Law 144: independent bias audit, published summary, 10-business-day candidate notice
  • -Illinois AI Video Interview Act: notice, consent and deletion rules for AI-analysed video interviews
  • -EEOC Title VII and ADA still apply to AI hiring; federal guidance was withdrawn in 2025, so state law is now the sharper edge
  • -Colorado: the original AI Act was repealed and replaced by SB 26-189, in effect from 1 January 2027

EU

Served in English.

  • -EU AI Act: recruitment and candidate selection are high-risk under Annex III point 4
  • -GDPR Article 22: restrictions on solely automated decisions with a significant effect
  • -Full high-risk obligations: risk management, bias-tested data, logging, human oversight

FAQ

AI Hiring Compliance: Questions HR and Legal Ask

Straight answers on the rulebooks that reach AI in hiring: the EU AI Act, NYC Local Law 144, the UK Equality Act 2010, UK GDPR Article 22 and ICO recruitment guidance.

Is AI used for recruitment high-risk under the EU AI Act?

Yes. Annex III point 4(a) classes AI systems intended to recruit or select people as high-risk, naming the placing of targeted job adverts, the analysis and filtering of applications, and the evaluation of candidates. Point 4(b) extends this to AI that decides on promotion, termination, task allocation and performance monitoring. High-risk systems carry the full obligations: a risk management system, bias-tested data, technical documentation, logging, human oversight and transparency. Breaching high-risk obligations can draw fines up to EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher (Article 99). Prohibited practices reach EUR 35 million or 7 percent. We map which of your hiring tools fall in scope and engineer the governance to meet it.

What does NYC Local Law 144 require for AI hiring tools?

NYC Local Law 144 governs automated employment decision tools used to screen candidates for jobs in New York City. Before using one, an employer must commission an independent bias audit, publish a summary of the audit results on its careers site, and notify candidates at least 10 business days before the tool is used. The audit checks for adverse impact across sex, race and ethnicity. The law has been in effect since 1 January 2023, with enforcement from 5 July 2023. We help HR and talent teams scope which tools are in scope, stand up the audit and notice process, and keep the published summary current.

How does UK law apply to AI in recruitment?

Two regimes apply. The Equality Act 2010 makes it unlawful to discriminate on a protected characteristic, and an AI screening tool that disadvantages a protected group can give rise to an indirect discrimination claim even though the Act never mentions AI. UK GDPR governs the candidate data: Article 22 restricts solely automated decisions with a legal or similarly significant effect, so a tool that screens people out needs meaningful human review. The ICO audited recruitment AI providers and published its outcomes report in November 2024 with close to 300 recommendations, and a Data Protection Impact Assessment is expected before any AI screening tool goes live. We build the governance that keeps your hiring lawful, fair and documented.

Do UK employers need a bias audit for hiring AI?

UK law doesn't mandate a NYC-style bias audit by name, but in practice you need to test for bias anyway. The Equality Act 2010 makes indirect discrimination unlawful, so if an AI screening tool disadvantages a protected group you carry the liability whether or not you tested it. The ICO expects a Data Protection Impact Assessment before an AI screening tool goes live, and its November 2024 recruitment outcomes report pressed providers and employers to check tools for fairness and accuracy. So the safe answer is yes: document a fairness and adverse-impact assessment to evidence the tool doesn't discriminate. We run that audit and produce the records a tribunal or the ICO would expect to see.

Does the EU AI Act apply to a UK or US employer hiring in Europe?

It can. The EU AI Act reaches deployers and providers whose AI output is used in the EU, so a UK or US employer screening candidates for EU-based roles can fall in scope regardless of where the company sits. Recruitment and candidate selection are high-risk under Annex III point 4, which brings the full obligations: risk management, bias-tested data, logging, human oversight and transparency. The deployer carries duties too, not just the vendor that built the tool. We map your cross-border hiring against the Act and tell you which tools and which roles are caught.

Can we be sued if an AI tool rejects qualified candidates unfairly?

Yes. Under the UK Equality Act 2010 a screening tool that systematically disadvantages a protected group can support an indirect discrimination claim, and "the vendor built it" isn't a defence, since the employer makes the hiring decision. UK GDPR Article 22 gives a rejected candidate the right to contest a solely automated decision and obtain human review, so a tool that screens people out with no human in the loop is exposed. In the US, NYC Local Law 144 and EEOC guidance under Title VII and the ADA point the same way. A documented bias audit and a real human-review step are the controls that reduce the risk, and that's the governance we build.

START HERE

Let's Discuss Responsible AI for Hiring

A conversation about your hiring stack, your regulatory footprint, and where governance will reduce the most risk. No pitch decks. No proposals on the first call.

Request a Consultation