AI in HR under regulatory scrutiny

Violetta Matusiak | Data Protection Inspector | Crowe Poland
8/17/2026
AI in HR under regulatory scrutiny

Is AI used in recruitment a high-risk system?

Yes. In many cases, AI systems used for candidate selection, employee assessment, promotion or HR decisions are classified as high-risk systems under the AI Act. This means they must comply with the requirements of the AI Act, GDPR and employment law.


Artificial intelligence used for candidate selection, employee assessment or promotion decisions is no longer merely a tool for increasing the efficiency of HR departments. As of 2 August 2026, the AI Act generally applies, and a significant proportion of AI systems used in employment have been classified by the EU legislator as high-risk systems.

The President of the Personal Data Protection Office (UODO) has also identified the issue. On 16 July 2026, Mirosław Wróblewski called on the Minister of Family, Labour and Social Policy to undertake work on additional regulations protecting candidates and employees against the discriminatory effects of AI.

AI in HR and the AI Act - key information:

  • AI used in recruitment often constitutes a high-risk system.
  • Human involvement does not always eliminate the risk of automated decision-making.
  • The AI Act does not replace obligations arising from the GDPR.
  • In many cases, a DPIA may be required.
  • Employers should audit all HR tools currently in use.

How often is AI already being used in recruitment?


The use of artificial intelligence is growing rapidly. According to Eurostat, in 2025, 20% of EU enterprises with at least 10 employees used AI technologies, compared with 13.5% the previous year. In Poland, the figure was lower, at 8.4%, but it is also steadily increasing.

The data concerning HR itself is even more interesting. According to an SHRM survey, 51% of organisations using AI in HR apply it to recruitment. Applications include:

creating job descriptions - 66%, 

CV screening - 44%, 

automated candidate sourcing - 32%, 

personalised job advertisements - 31%,

candidate communication - 29%. 

As many as 89% of HR professionals using AI in recruitment report time savings or increased efficiency, while 36% report reduced recruitment, interviewing and hiring costs, and 24% report an improved ability to identify the best candidates.

The business benefits are therefore tangible. So are the legal risks.

Why is AI in HR considered high-risk?


The EU AI Act explicitly identifies employment as one of the areas in which the use of AI may significantly affect fundamental rights.

Annex III of the AI Act covers, among other things, systems intended for:

  • recruitment or selection of individuals,
  • analysing and filtering applications,
  • assessing candidates,
  • making decisions concerning the terms of employment,
  • making decisions on promotion or termination of employment,
  • allocating tasks based on employees’ behaviour or personal characteristics,
  • monitoring and evaluating employees’ performance and behaviour.

This is therefore not limited to situations where “an algorithm hires a person”. A system that generates a ranking of candidates or a score identifying the five best CVs for a recruiter may also fall within the high-risk category.

AI Governance

What particularly concerns the UODO?


AI in HR under regulatory scrutiny

The President of the UODO points out that the Office is receiving an increasing number of reports concerning the use of AI tools in recruitment processes. These systems may process personal data on a large scale and, in some cases, special categories of personal data.

One of the key risks is the perpetuation of existing biases.

An algorithm trained on historical recruitment decisions may reproduce previous inequalities. If a particular group of candidates was historically less likely to be hired or promoted, the model may treat this pattern as a predictive signal.

As a result, technology intended to make a process more objective may automate existing biases on a much larger scale.

This is precisely why the President of the UODO is calling for additional regulations to protect candidates and employees against discrimination resulting from the use of AI.

Does having a human approve an AI decision solve the problem?


Not always.

This is one of the more common mistakes when implementing AI systems in HR. An organisation assumes that since the final decision is made by a recruiter or manager, there is no significant risk of automated decision-making.

However, what matters is the actual, rather than declared, human influence on the decision.

If a system evaluates 1,000 CVs, rejects 900 candidates, and the recruiter reviews only the 100 applications identified by the algorithm as the most suitable, the actual role of the system in the entire decision-making process should be examined.

“Human in the loop cannot mean a person who merely approves an algorithm’s recommendation. If an organisation cannot demonstrate that the person making the decision understands the system’s output, can challenge it and actually exercises that possibility, human oversight may prove to be merely formal,” says Violetta Matusiak.

This is also relevant from the perspective of Article 22 of the GDPR, which establishes specific rules concerning decisions based solely on automated processing where such decisions produce legal effects concerning an individual or similarly significantly affect them.

The problem may start with the CV itself


The risk does not begin only when a hiring decision is made.

An AI system analysing a CV may process significantly more information than the employer originally intended to use.

A model may infer characteristics of a candidate based on their employment history, language, manner of expression, photograph, voice recording or video footage. The risk is even greater when the system analyses a job interview and attempts to draw conclusions about personality, behaviour or other human characteristics.

In such a case, asking “do we have a legal basis for storing the CV?” is clearly insufficient.

It is necessary to determine what data the system actually uses, what information it derives from that data, and whether the employer would be legally entitled to obtain that information without the use of AI.

Will the AI Act replace the GDPR?


No, although this is one of the most important practical conclusions for employers.

Meeting the requirements of the AI Act does not automatically mean that a process is GDPR-compliant. The two regulatory regimes will operate in parallel.

Employers should therefore determine:

- first - the legal basis;

the legal basis for processing data at each stage of the system’s operation must be established. In the employment context, particular caution is required when relying on consent due to the imbalance between the employee and the employer;

- second - the scope of data;

it is necessary to examine not only the data provided directly to the system, but also information generated or inferred by the model;

- third - the system provider;

the organisation must know whether the provider acts as a processor, an independent controller or, in certain processes, may fulfil different roles. It is also crucial to determine whether the data is used to further train the models;

- fourth - data transfers; 

the use of global AI platforms may involve the transfer of data outside the European Economic Area;

- fifth - DPIA;

the use of AI for systematic assessment of candidates or employees may result in the need to conduct a Data Protection Impact Assessment pursuant to Article 35 of the GDPR.

What changed on 2 August 2026?


The AI Act was adopted in 2024, but its provisions are being applied in stages. As of 2 August 2026, the regulation generally applies, subject to the exceptions provided for in Article 113.

For employers using high-risk systems, requirements concerning, among other things, risk management, data quality, documentation, record-keeping, transparency, human oversight, accuracy and cybersecurity are particularly important.

The AI Act also provides for a specific obligation concerning the workplace. Before using a high-risk AI system, an employer acting as a deployer should, subject to the conditions set out in the regulation, inform employee representatives and the employees affected by the system that it is being used.

AI regulation in HR is only just beginning


On 16 July 2026, the President of the UODO called on the Ministry of Labour to undertake legislative work concerning the use of AI in employment.

This is an important signal for the market.

The GDPR allows Member States to introduce more detailed regulations concerning data processing in the employment context. Poland may therefore introduce additional safeguards in the future that go beyond the AI Act.

The issue has also attracted the attention of European regulators. On 9 July 2026, the EDPS and EDPB organised a conference at the European Parliament entitled “Hired by an algorithm: Data protection and AI regulation in modern HR practices.” Topics discussed included CV screening, video interview analysis, employee performance prediction, the possibility of providing genuinely valid consent, and the transparency of automated decisions.

Where should employers start?


AI in HR under regulatory scrutiny

The first step should not be purchasing another system or preparing an AI policy.

First, it is necessary to determine where AI is already being used.

In practice, AI systems may appear in an organisation before the legal department or DPO becomes aware of them. They may be a feature of an ATS, an HR platform, an online interview tool, an employee assessment system or a solution purchased directly by HR.

“In AI compliance projects, one of the first challenges is establishing the actual tool landscape. An organisation may believe it does not use AI to make employment decisions, while scoring, ranking or recommendation functions are already part of the HR system it uses. That is why an audit should start with functionalities rather than with the question of whether the product has ‘AI’ in its name,” says Violetta Matusiak.

Only after such a map has been prepared can an organisation determine which solutions fall under the AI Act, which process personal data, where a DPIA is required and where the process itself needs to be changed.

Summary


AI in HR is no longer merely a technology project. It is becoming a regulatory project.

An employer using an algorithm to filter CVs, assess candidates, monitor employees or recommend promotions must now take into account the GDPR, the AI Act and employment law simultaneously.

The benefits are measurable - according to SHRM, 89% of HR professionals using AI in recruitment report time savings or increased efficiency. At the same time, the European legislator has classified certain uses of AI in employment as high-risk.

These two figures clearly illustrate the market situation: AI will increasingly be used in HR, but the “implement first, check compliance later” approach is no longer viable.

Frequently asked questions (FAQ)


Does every use of AI by an HR department mean that it is a high-risk system?

No. The intended purpose and the way a particular system is used are key. AI that helps prepare the content of a job advertisement will be assessed differently from a system that analyses CVs and creates a ranking of candidates.

Can AI automatically reject candidates?

Such a solution requires particularly careful analysis. In addition to the AI Act, Article 22 of the GDPR concerning automated decision-making may also apply.

Is it enough for a recruiter to approve the final decision?

Not always. It must be examined whether human involvement is genuine and meaningful to the outcome of the process, rather than being limited to formally approving the system’s recommendation.

Does a DPIA have to be carried out before implementing AI in recruitment?

Not automatically in every case, but the criteria under Article 35 of the GDPR should be assessed. In the case of systematic assessment of individuals, profiling and decisions having a significant impact on candidates, the likelihood that a DPIA will be required is high.

Should a candidate know that their CV is being analysed by AI?

The organisation must ensure transparency of processing in accordance with the GDPR, and depending on how the system operates, additional obligations under the AI Act may also apply.

Sources

  • President of the Personal Data Protection Office (UODO), “President of the UODO calls for regulation of the use of AI systems in employment”, 16 July 2026.
  • European Data Protection Supervisor, “Hired by an algorithm: Data protection and AI regulation in modern HR practices”, 9 July 2026.
  • Regulation (EU) 2024/1689 of the European Parliament and of the Council - AI Act, in particular Annex III, point 4.
  • Eurostat, “20% of EU enterprises use AI technologies”, data for 2025.
  • SHRM, “2025 Talent Trends: AI in HR”.
Violetta Matusiak
Violetta Matusiak
Data Protection Inspector