AI is becoming part of everyday recruiting, from writing job descriptions and finding candidates to screening applications and scheduling interviews.
But using AI in hiring is different from using it for a routine administrative task.
When an AI system influences who gets shortlisted, interviewed, or rejected, HR teams need to consider fairness, privacy, transparency, human oversight, and applicable regulations.
The challenge is knowing which controls are needed for each use case without slowing down the entire recruiting process.
This guide covers the key AI compliance requirements for HR and hiring teams, with practical examples, regulatory considerations, and a checklist you can use before and after deployment.
Why AI Compliance Matters More as AI Enters Hiring Decisions
AI adoption in recruiting is already substantial. SHRM reported that 51% of organizations use AI to support recruiting, with job-description writing, resume screening, candidate search, job-post customization, and applicant communication among the most common uses.
Among organizations using AI for recruiting, 89% reported that it saves time or increases efficiency, while 36% said it helps reduce recruitment, interviewing, or hiring costs.
The compliance question changes depending on what the AI actually does.
For example, using AI to rewrite a job description is generally a different compliance situation from allowing an algorithm to automatically reject candidates based on a score.
The closer AI gets to an employment decision, the more important it becomes to document how the system works, test its outcomes, define human review, and understand which laws apply.
The UK's Responsible AI in Recruitment guidance similarly identifies sourcing, screening, interviewing, and selection as areas where organizations should consider risks such as bias, discrimination, digital exclusion, transparency, accountability, and redress.
7 AI Compliance Requirements HR Teams Should Put in Place
There is no single checklist that makes every AI recruiting system compliant everywhere. Requirements depend on the tool, the decision it influences, the data involved, and the jurisdictions where the organization operates.
However, these seven controls provide a practical starting point.
1. Create an AI Inventory for Your HR Processes
Before assessing compliance, HR needs to know where AI is actually being used.
This sounds simple, but organizations can easily lose track of AI tools when recruiters use multiple platforms, browser extensions, generative AI tools, ATS features, assessment platforms, and sourcing products.
Your inventory should record:
- AI tool and vendor
- Recruiting activity it supports
- Purpose of the AI system
- Candidate data it processes
- Users with access
- Employment decision it influences
- Human reviewer responsible
- Applicable jurisdictions
- Date of the latest review
Example
A company officially approves an AI recruiting platform for candidate sourcing.
Six months later, recruiters also started using a generative AI tool to summarize resumes and create candidate assessments.
The first tool may be recorded in the company's AI inventory while the second isn't.
That creates a governance gap.
A useful rule is:
If AI touches candidate information or influences a recruiting decision, put it on the inventory.
2. Test AI Systems for Bias and Discrimination
Bias is one of the biggest compliance concerns in AI-assisted hiring because a system can produce discriminatory outcomes even when discrimination wasn't intentionally programmed into it.
HR teams should understand:
- What information the system evaluates
- Which criteria affect candidate scores
- What data was used to develop the system
- Whether certain groups experience different outcomes
- Whether the criteria are relevant to the job
- How often the system is tested
- What happens when testing identifies a problem
The EU AI Act specifically classifies certain AI systems used for recruitment and selection as high-risk, including systems used to place targeted job advertisements, analyze or filter applications, and evaluate candidates.
Example
Imagine an AI screening system gives additional points to candidates with uninterrupted employment histories.
At first glance, that may look like a neutral criterion.
But if the requirement isn't actually necessary for the job, it could exclude qualified candidates who have taken career breaks.
The HR team should therefore ask:
Is this criterion genuinely related to successful job performance, and what happens to the candidate pool when it is applied?
Compliance isn't just about checking whether the algorithm has a label such as "bias-free." It requires looking at the criteria, data, outputs, and real-world impact.
3. Make AI Use Transparent to Candidates
Candidates increasingly interact with AI without always knowing where it appears in the hiring process.
Transparency requirements vary by jurisdiction, but HR teams should establish a clear policy covering:
- When candidates are informed about AI use
- What the AI is being used for
- What candidate information is evaluated
- Whether human review is involved
- How candidates can request accommodations where applicable
- How candidates can raise concerns or seek clarification
New York City's Local Law 144 provides a concrete example. Covered employers and employment agencies using an automated employment decision tool must meet requirements including a bias audit, public availability of audit information, and candidate/employee notices.
The law also requires notice to affected candidates at least 10 business days before the tool is used and provides for requests for an alternative selection process or accommodation.
Example
Instead of treating an AI assessment as invisible infrastructure, an organization should determine what candidates need to be told under the applicable law.
The exact notice will depend on the jurisdiction and use case, so HR should not copy a generic disclosure and assume it satisfies every requirement.

4. Define Human Oversight Before Deployment
"Human in the loop" sounds straightforward, but it needs to mean more than having a recruiter click an approval button.
HR teams should define:
- Which decisions AI can support
- Which decisions require human review
- Who reviews AI recommendations
- When a recruiter can override the system
- How overrides are documented
- Who is accountable for the final decision
A safer workflow for a high-impact decision might look like:
AI recommendation → Recruiter review → Candidate assessment → Human decision
Rather than:
AI score → Automatic rejection
The EU AI Act's requirements for high-risk AI include appropriate human oversight, along with risk management, data quality, logging, documentation, accuracy, robustness, and cybersecurity. The employment-related high-risk rules are currently scheduled to apply from December 2, 2027 under the current EU implementation timeline.
Example
An AI system ranks 500 applicants and recommends 80 for recruiter review.
The recruiter should be able to question why a candidate was excluded, review the underlying information, and apply appropriate judgment rather than treating the AI ranking as an unquestionable hiring decision.
5. Protect Candidate Data Used by AI
AI recruiting systems can process large volumes of personal information, making data governance an important part of AI compliance.
HR should know:
- What candidate data enters the system
- Where the data is stored
- Who can access it
- How long it is retained
- Whether the vendor uses customer data to train models
- Whether data is transferred across borders
- How information can be deleted
- What privacy rights apply
Example
A recruiter uploads 1,000 resumes into an AI tool to generate candidate summaries.
Before doing so, the organization should understand:
Is the tool simply processing those resumes, or can the vendor retain or reuse the information?
That question should be answered during vendor review, not after sensitive candidate information has already been uploaded.
HR should also avoid sending unnecessary information into an AI system. If a tool only needs job title, skills, and experience to perform a task, there may be little reason to provide unrelated personal information.
6. Keep Documentation and Audit Trails
Compliance becomes difficult when an organization cannot explain how AI was used.
Maintain records such as:
Example
A candidate challenges a hiring decision six months after applying.
The company should ideally be able to determine:
Which AI tool was used → what it evaluated → what output it produced → who reviewed it → what final decision was made.
Without documentation, even a well-designed process can become difficult to investigate.
7. Conduct AI Vendor Due Diligence
An AI vendor saying that its platform is "compliant" does not automatically mean the employer's use of the platform satisfies every applicable requirement.
Before deployment, HR, legal, IT, procurement, or compliance teams should ask:
- What candidate data does the system process?
- What is the data retention period?
- Is customer data used for model training?
- What bias testing has been performed?
- What documentation can the vendor provide?
- How are model changes communicated?
- Can recruiters override recommendations?
- How does the vendor handle security incidents?
- Can relevant logs or records be exported?
- What happens when the contract ends?
The UK's responsible AI guidance specifically highlights justified trust in suppliers and the importance of evidence supporting supplier claims about their systems.
A useful principle is:
Don't evaluate an AI recruiting vendor only on features. Evaluate the evidence behind its claims.
What AI Hiring Regulations Should HR Teams Know?
AI compliance doesn't come from one universal HR regulation. The requirements can depend on the country, state, city, industry, candidate location, and the type of AI system being used.
Here are some important examples.
The EU AI Act specifically lists AI systems used for recruitment or selection—including targeted job advertising, application filtering, and candidate evaluation—within the employment category of high-risk systems.
For NYC, Local Law 144 requires covered employers and employment agencies to have a qualifying bias audit conducted no more than one year before using an AEDT, publish a summary of the most recent audit, and provide required notices.
The important point for HR teams is that location matters. A recruiting workflow used in New York City may have requirements that don't apply in exactly the same way to a similar workflow elsewhere.
How to Assess the Compliance Risk of an AI Recruiting Tool
One of the easiest mistakes is treating every AI feature as equally risky.
A better approach is to assess what the AI actually does.
Ask these five questions before deployment:
1. Does the system process candidate data?
If yes, review privacy, security, retention, and data-access controls.
2. Does it evaluate or rank candidates?
If yes, investigate the criteria, testing, fairness, and explain ability.
3. Can its output influence who progresses?
If yes, define human-review requirements.
4. Can it automatically reject candidates?
If yes, conduct a deeper legal and compliance assessment before deployment.
5. Does the workflow operate across multiple jurisdictions?
If yes, map the requirements for each relevant location rather than applying one country's rules everywhere.
Example: Two AI Tools, Two Risk Profiles
Tool A: Generates interview questions based on a job description.
Tool B: Scores 5,000 applicants and automatically removes anyone below a predetermined threshold.
Both use AI.
But Tool B directly influences access to employment and therefore deserves significantly more scrutiny.
This is why HR teams should classify AI by use case, not simply by the name or marketing description of the software.
AI Compliance Checklist for HR Teams
Instead of treating compliance as a document HR completes once, use it as a three-stage process: before buying, before using, and after deployment.
Before You Buy
Ask the vendor:
- What exactly does the AI do?
- Does it rank, score, recommend, or reject candidates?
- What candidate data does it process?
- Can you provide bias-testing information?
- Is customer data used to train models?
- Can humans override AI recommendations?
- How are model changes communicated?
- What audit records are available?
Red flag
If a vendor cannot clearly explain what data its system uses, what its output means, or how customers can monitor changes, pause before deploying it in a high-impact workflow.
Before You Deploy
Make sure you have:
☐ An inventory entry for the AI system
☐ A defined business purpose
☐ Applicable jurisdictions identified
☐ Privacy review completed
☐ Vendor due diligence completed
☐ Bias-testing evidence reviewed
☐ Human-review points defined
☐ Candidate notice requirements identified
☐ Accommodation process established
☐ Recruiters trained on acceptable use
After You Deploy
Monitor:
- Candidate progression rates
- AI recommendations
- Human overrides
- Candidate complaints
- Accommodation requests
- Unexpected screening patterns
- Vendor/model updates
- Data access
- Retention practices
Don't assume that passing a review on launch day means the system stays compliant forever.
A model can change. A vendor can update a feature. A company can start using an existing tool for a different purpose.
Each of those changes can require another review.
If You Find a Problem
Use a simple:
Detect → Investigate → Correct → Document
Example
An HR team notices that a screening tool is unexpectedly excluding a large share of applicants from one demographic group.
Detect: Flag the unusual result.
Investigate: Review the criteria, data, configuration, and candidate outcomes.
Correct: Adjust the workflow or pause the affected feature where appropriate.
Document: Record the issue, investigation, action taken, and follow-up monitoring.
This turns compliance from a static policy into an operating process.
5 Common AI Compliance Mistakes HR Teams Make
1. Using AI Without Knowing Where It Is
Recruiters may use AI features across multiple platforms without HR having a complete inventory.
Fix: Maintain an AI inventory and update it when tools or use cases change.
2. Treating the Vendor's Compliance Claim as Proof
A vendor may have strong security and governance practices, but that doesn't automatically address every requirement in your specific jurisdiction.
Fix: Request evidence and conduct your own use-case review.
3. Letting AI Make Unexplained Rejection Decisions
A candidate shouldn't disappear from a hiring pipeline simply because an algorithm produced a low score that nobody understands.
Fix: Define human review for consequential decisions.
4. Using Vague Screening Criteria
Terms such as "culture fit," "executive presence," or "professional personality" can be difficult to define consistently.
Fix: Use clear, job-related criteria that can be explained and reviewed.
5. Reviewing AI Only Once
Compliance shouldn't end when the vendor passes procurement.
Fix: Reassess after major model changes, workflow changes, regulatory developments, or unexpected outcomes.
Suggested Reading:
11 Job Boards Recruiters Can Use to Build a Stronger Candidate PipelineAI Compliance in Practice: A 2,000-Candidate Hiring Example
Consider a company hiring for 20 software engineering positions.
It receives 2,000 applications.
Instead of asking AI to make the hiring decision, the company builds this workflow:
2,000 applications
↓
AI-assisted skills matching
↓
500 potential matches
↓
Recruiter review
↓
100 shortlisted candidates
↓
Structured interviews
↓
20 hires
The AI system can help reduce the amount of manual screening work, but the organization establishes controls around how it is used.
The compliance controls could include:
Before screening
The company defines job-related skills and requirements.
During screening
The AI uses those criteria to assist candidate matching.
Human review
Recruiters review candidates before significant decisions are made.
Transparency
The organization provides any notices required by applicable law.
Data governance
Candidate information is handled according to the organization's privacy and retention requirements.
Monitoring
The company reviews outcomes and investigates unexpected patterns.
Documentation
The organization records the AI tool, purpose, relevant configuration, reviews, and changes.
The point isn't to eliminate automation.
It's to make sure automation has defined boundaries and accountability.
AI Compliance Requirements: Quick Reference
A strong AI compliance program connects these requirements rather than treating them as separate tasks.
For example, a bias test is more useful when HR knows which AI version was tested, what data was used, which workflow it supported, and whether the system changed afterward.
Conclusion
AI can make recruiting faster and easier, but compliance needs to be part of the workflow rather than an afterthought.
HR teams should know where AI is being used, what data it processes, which decisions it influences, and what requirements apply in each jurisdiction.
Bias testing, transparency, privacy controls, human oversight, documentation, vendor due diligence, and ongoing monitoring provide the foundation for responsible use.
The goal isn't to remove AI from recruiting; it is to establish clear boundaries around how it is used.
Platforms such as Leelu can help connect and automate recruiting activities, while HR teams remain responsible for defining the controls that govern that automation.
Frequently Asked Questions
Is AI screening legal for job applicants?
AI screening can be used for recruitment, but the requirements depend on the jurisdiction, the tool's function, and how its output affects employment decisions. Certain employment-related AI systems are classified as high-risk under the EU AI Act, while jurisdictions such as New York City impose specific requirements on covered automated employment decision tools.
Do employers have to disclose AI use during recruitment?
Disclosure requirements vary by jurisdiction and use case. For example, NYC Local Law 144 requires covered employers and employment agencies to provide specific notices when using covered automated employment decision tools.
What should an HR AI compliance policy include?
A practical policy should cover approved AI uses, prohibited uses, candidate-data handling, human oversight, vendor review, documentation, monitoring, candidate transparency, and an escalation process for problems.
How often should AI hiring tools be audited?
There is no single audit frequency that applies to every AI recruiting tool. Some laws impose specific timelines. For example, NYC Local Law 144 requires a qualifying bias audit no more than one year before use of a covered AEDT. Organizations may also need additional reviews after significant system, data, or workflow changes.
Who is responsible for AI compliance in HR?
Responsibility should be clearly assigned rather than left entirely to HR, IT, or the vendor. Depending on the organization, HR, legal, privacy, IT, procurement, and compliance teams may all have roles. The key is having a named owner and defined escalation process.
What should HR ask an AI recruiting vendor before buying?
Ask what the system does, what candidate data it processes, how it is tested for bias, whether customer data is used for model training, how changes are communicated, what audit documentation is available, and how humans can review or override its outputs.



