AI Resume Screening

AI Hiring Compliance For Agencies

AI hiring compliance for agencies in 2026 means different things depending on where you're based and where your candidates are.

AI Hiring Compliance For Agencies

The short version for both markets:

UK: AI resume screening is legal under the Data (Use and Access) Act 2025 (in force 5 February 2026). You must tell candidates AI is used, ensure a human genuinely reviews shortlisting decisions, and give candidates a route to challenge outcomes. The ICO is actively auditing recruitment practices.

US: No federal AI hiring law. Requirements depend on where your candidates are. If you hire people based in New York City, NYC Local Law 144 requires an annual independent bias audit of any automated screening tool and advance notice to candidates at least 10 business days before the tool is used.

The Fuller Context

The compliance picture varies by location, tool type, and how the AI output is used.

  • UK. The ICO's recruitment-specific report, published March 2026, found many employers claiming human review was happening when in practice a human was rubber-stamping whatever the AI produced. That doesn't satisfy the requirement. The reviewer must have the authority and information to change the outcome before it's communicated to the candidate. A final guidance document following the May 2026 consultation is expected in summer 2026.

  • NYC. Local Law 144 has been in force since July 2023. If your agency hires candidates located in New York City and uses any automated employment decision tool, including AI CV screening, you need an annual bias audit from an independent third party, published results, and advance written notice to candidates at least 10 business days before the tool is used. Penalties run $500 to $1,500 per day of violation. The audit obligation falls on you as the employer, not on the tool vendor, though a vendor who has already completed an audit and can share the summary simplifies this significantly.

  • Illinois. The Artificial Intelligence Video Interview Act requires employers using AI to analyse video interviews to notify candidates before the interview, explain how the AI works, and obtain consent. Annual bias testing is also required. If you're conducting AI-assisted video screening for candidates in Illinois, this applies.

  • Colorado. A broader AI law affecting consequential automated decisions, including hiring, was delayed but is expected to take effect mid-2026. [VERIFY: confirm Colorado AI Act effective date before publishing.]

  • EU (relevant if you hire in the EU). The EU AI Act treats AI hiring tools as high-risk systems. Full compliance obligations phase in through 2026-2027. Most UK and US agencies hiring domestically won't be affected, but worth flagging if any hiring crosses into EU territory.

  • Baseline across all jurisdictions. Anti-discrimination law applies regardless of automation. If your AI screening tool produces outcomes that disadvantage candidates on the basis of a protected characteristic, race, age, sex, disability, you bear liability even if the bias came from the algorithm rather than a deliberate decision. This is not new law. It's existing law applied to a new context.

Related Questions

Q1. Do I need to tell candidates I'm using AI to screen their CVs?

In the UK, yes transparency is required under UK GDPR. In NYC, yes advance written notice at least 10 business days before the tool is used. In most other US states, there's currently no explicit disclosure law, but the trend is toward mandatory notice. Adding a brief disclosure to your application process is the lowest-effort way to cover yourself across all jurisdictions.

Q2. Does the NYC AI hiring law apply to small agencies?

Yes. NYC Local Law 144 applies to any employer using an automated employment decision tool for hiring or promotion decisions involving NYC-based candidates, with no carve-out for company size. If you use AI screening and hire people in New York City, the bias audit requirement applies to you.

Q3. What is a bias audit and do I actually need one?

A bias audit is an independent assessment of whether an AI tool produces systematically different outcomes for different demographic groups. Under NYC Local Law 144, it's required annually if you use AI screening for NYC hires. The audit is commissioned by you, conducted by a third party, and the results must be published. Some screening tool vendors have already completed audits and can share summaries, ask before assuming. For UK agencies, a formal bias audit isn't legally mandated yet, but documenting how your screening criteria were set and that a human reviewed the output is the practical equivalent.

Q4. What happens if my AI screening tool discriminates against a protected group?

Under existing employment law in both the UK and US, you remain liable for discriminatory outcomes even when they were produced by a vendor's algorithm rather than a deliberate human decision. The EEOC has been clear on this in the US. The Equality Act 2010 covers this in the UK. Liability doesn't transfer to the software company.

What This Means for Your Screening Process

Three practical steps that cover the compliance minimum for a small agency in both markets.

  • Add a disclosure line to your application form. One sentence stating that AI tools support initial CV screening and that a human reviews all decisions before candidates are progressed or rejected. Covers UK GDPR transparency and starts the notice trail for US requirements.

  • Use a tool with explainable scoring. If your screening tool only produces a score, your reviewer has nothing to engage with and the human review step is effectively theatre. A tool that shows per-candidate reasoning, what the AI found and why the candidate ranked where they did, is what makes genuine human oversight possible. That distinction matters for compliance and for shortlist quality. For a broader look at how agencies approach this, the guide to candidate screening tools built for agency workflows covers the practical setup.

  • Keep basic records. Note the criteria used, the tool used, and that a human reviewed the shortlist before outcomes were communicated. Simple documentation is what protects you if a candidate challenges a decision.

CVShelf returns a ranked list with a per-candidate explanation, which supports genuine human review rather than replacing it. Try it complimentary at cvshelf.com.

AI hiring compliance isn't complicated for a small agency. Tell candidates, review the reasoning, keep records. The requirements are manageable. Ignoring them isn't.


This post is not legal advice. For decisions affecting your business, speak to an employment lawyer or data protection adviser.