Somewhere in your organisation, an algorithm is already deciding who gets seen. It ranks the CVs, filters the applicants, perhaps scores the video interview and flags who is “a flight risk.” Most boards could not tell you which tools, trained on what data, are making which calls. That should worry us — because the law has stopped accepting “we didn’t know” as an answer.
AI in hiring is not coming; it is here, sitting at every gate from the first application to the exit interview. Used well, it can widen a search and strip out some human caprice. Used carelessly, it does something more dangerous: it takes our existing biases and runs them at scale, behind a screen, with the false authority of a number.
And the regulators have arrived. The era of the unaudited hiring algorithm is over.
An algorithm can inherit your bias and run it at scale. The law now holds you — not the vendor — to account.
What follows: where AI sits in the hiring lifecycle, how it scales bias, the law that has arrived, why accountability is yours, and what to actually do about it.
The algorithm at every gate
Start by mapping where AI already sits. It sources candidates and writes the adverts. It screens and ranks CVs. It scores video interviews for “competencies” and tone. Once people are hired, it monitors productivity, flags performance, predicts who will quit, and increasingly shapes who gets promoted. There is now an algorithm at almost every gate of a working life.
None of this is inherently wrong. A well-built tool can surface candidates a tired recruiter would miss and apply a consistent standard where humans drift. The danger is not automation; it is unexamined automation — a decision that looks neutral, scales instantly, and answers to no one.
The danger is not automation. It is automation no one is examining.
Bias, at the speed of software
Here is the failure mode that should keep a board awake. A model learns from the past — from the people you have hired, promoted and kept before. If that history carries bias, the model does not correct it; it encodes it, polishes it, and applies it to every future candidate at once — faster and more consistently than any prejudiced human ever could.
It is not hypothetical. Amazon famously built, then scrapped, an internal recruiting tool after discovering it had taught itself to downgrade CVs that mentioned “women’s” — because it had learned from a decade of mostly male hires. The model was not malfunctioning. It was working perfectly, on a biased world. And opacity makes it worse: a candidate cannot appeal a reason no one can see.

The rules have arrived
For a while, the law lagged the tools. No longer. Since July 2023, New York City has enforced Local Law 144: any automated hiring or promotion tool must pass an independent bias audit within the prior year, publish a summary, and give candidates at least ten business days’ notice and the option of an alternative. The EU AI Act goes further, classing employment AI as high-risk and attaching strict obligations to it.
And beneath the new statutes sits an older, blunter truth: existing anti-discrimination law — Title VII in the US, the Equality Act here — already applies to an automated decision exactly as it does to a human one. The tool is not a shield. “The algorithm did it” has never been a defence.

You deployed it; you answer for it
This is the part leaders most want to avoid, so let me be plain. When you license a hiring tool, the accountability does not transfer with the contract. In law and in practice, the organisation that deploys a system answers for the decisions it makes — not the vendor who built it. Responsibility cannot be outsourced; it can only be neglected.
Which means the governance is yours to do. Audit the tool for disparate impact before it touches a candidate, and again each year. Keep a human in the loop on every adverse decision — a rejection, a flag, a non-promotion. Tell people when a machine is assessing them, and give them a route to a person. None of this is exotic. It is simply ownership.
The accountability never transfers with the contract. You deployed it; you answer for it.

Five moves before the next hire
If AI touches your hiring — and it almost certainly does — these five are not optional.
Inventory the tools
Know every automated system touching recruitment, monitoring and promotion — including the ones inside your ATS you never consciously chose.
Audit before you deploy
Test for disparate impact across protected groups before a tool sees a candidate — then re-audit annually, and demand the vendor’s audit too.
Notify, and offer an alternative
Tell candidates a machine is assessing them, and give them a human route. It is the law in New York; it should be your default everywhere.
Keep a human on adverse calls
No rejection, flag or non-promotion goes out on the machine’s word alone. A person owns every decision that changes a livelihood.
Document the chain
Record what the tool did, who reviewed it, and why. When the regulator or the tribunal asks, “we didn’t know” is the one answer that fails.
Do this and AI becomes what it should be in hiring: a wider, fairer net — not a faster way to repeat yesterday’s mistakes.
If a machine decides who you hire, you still answer for who you didn’t. Audit it like you mean it.
- NYC Local Law 144 of 2021 (Automated Employment Decision Tools); NYC DCWP — effective Jan 2023, enforced from 5 July 2023.
- EU Artificial Intelligence Act — Annex III (employment classed as high-risk).
- US EEOC / Title VII; UK Equality Act 2010 — anti-discrimination law applies to automated decisions.
- Dastin, J. Reuters, 2018 — “Amazon scraps secret AI recruiting tool that showed bias against women.”
