Everything below is in force today except the AI legislation, which does not exist. The instrument that changed most recently — the automated decision-making regime — is the one most UK vendor pages still describe incorrectly.
UK GDPR Articles 22A-22D — automated decision-making (as substituted by the Data (Use and Access) Act 2025, section 80 and Schedule 6)
In force · new regime governs decisions taken on or after 5 February 2026 · SI 2026/82 saves the old rules for earlier decisions · ICO confirmed on 19 June 2026 that all DUAA data protection provisions are in force
Article 22A defines a significant decision as one that produces a legal effect for the data subject or has a similarly significant effect, and frames the test in terms of whether there was meaningful human involvement, having regard in particular to the extent to which the decision was based on profiling. Article 22B sets the general rule: a significant decision based entirely or partly on personal data may be taken solely by automated means, on any lawful basis, where the controller puts safeguards in place. The required safeguards are that the controller provide the data subject with information about decisions taken, enable the data subject to make representations about such decisions, enable them to obtain human intervention, and enable them to contest such decisions. Article 22C is the restriction: a significant decision involving special category data may not be taken solely by automated means unless the data subject has given explicit consent, or the decision is necessary for a contract or required by law and an Article 9(2)(g) substantial public interest condition applies. A decision relying on Article 6(1)(ea) recognised legitimate interests may not be taken solely by automated means at all. Article 22D gives the Secretary of State power to define meaningful human involvement and supplement the safeguards by affirmative-resolution regulations.
What it means for a hiring assessment
Read Article 22C first, then Article 22B, because the order most compliance pages use is backwards for an assessment buyer. The relaxation is real and it does apply to a straightforward score-based sift on ordinary personal data: you no longer have to construct a contract-necessity or explicit-consent argument to auto-reject below a cut, and legitimate interests will now carry it if you can evidence the four safeguards. What you have to establish first is whether special category data is anywhere in the pipeline, because if it is, nothing relaxed and you are still under the old restriction. Three routes put it there and none of them is obvious from a product demo. A fairness dashboard built on inferred ethnicity or gender is the first. A personality or wellbeing instrument that yields health inferences is the second. An accommodations field carried forward into the scoring record rather than held separately is the third. Then build the safeguards as configuration rather than as policy prose: the rejection notice has to say a decision was made by automated means, the candidate needs a route to a named human who can actually change the outcome, and that human needs the score, the item-level evidence and the authority to overturn — a reviewer who can only confirm is not human intervention, and the ICO's Recruitment rewired work is squarely aimed at that gap.
Source: Data (Use and Access) Act 2025, section 80 (legislation.gov.uk)
The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82)
In force · made 2026 · commencement and saving instrument
Regulation 5 provides that the amendments made by section 80 of, and Schedule 6 to, the 2025 Act do not apply in relation to any decision taken before 5 February 2026. The ICO's own summary records that the data protection changes were phased in between June 2025 and June 2026, and that as of 19 June 2026 all of the Act's data protection provisions are in force.
What it means for a hiring assessment
This is the entry that decides which rulebook a live dispute is judged under, and it is the reason a date belongs in your audit trail. A candidate rejected in January 2026 was rejected under the old Article 22; the same rejection in March 2026 was not. If your applicant tracking system does not record the date a rejection decision was taken, distinct from the date the assessment was sat and the date the email went out, you cannot answer that question about your own funnel. Record the decision date, and keep the version of the cut score and the scoring configuration that produced it — a screen whose bar moved in February cannot be reconstructed later without it.
Source: SI 2026/82, regulation 5 (legislation.gov.uk)
ICO, AI tools in recruitment — audit outcomes report (November 2024)
In force as regulatory expectation · audits conducted August 2023 to May 2024 · published November 2024 · not a statute
The ICO audited developers and providers of AI recruitment tools and issued 296 recommendations and 42 advisory notes; 97% were fully accepted, 3% partially accepted and none rejected. Its findings include that providers frequently inferred protected characteristics such as gender and ethnicity rather than collecting them, often estimating them from names without a lawful basis or transparency, and that information intentionally inferred in this way is still special category data and will not be adequate and accurate enough for reliable bias monitoring. Several providers incorrectly defined themselves as processors rather than controllers and had consequently not complied with the data protection principles, with the ICO taking the position that a provider exercising control over central model development is a controller regardless of the contract's label. Candidates were often unaware their data was being reused to train models or that characteristics were being inferred about them. The recommended alternative is to collect demographic information directly from candidates through an optional survey after the assessment, or to stop the processing where no lawful basis can be established.
What it means for a hiring assessment
Turn this into three questions for any vendor, and ask them before the pilot rather than after. First: do you infer or estimate any protected characteristic, from a name, a photograph, a voice sample or anything else, and if so under what lawful basis and where is it disclosed to the candidate? An answer of yes changes your legal analysis, not just theirs. Second: are you a controller or a processor for this processing, and for which parts — a vendor that develops or tunes a central model on candidate data is a controller for that, whatever the data processing agreement says, and a contract that assigns you all the responsibility is one of the exact patterns the audit criticised. Third: is candidate data used to train or improve your models, and can a candidate be told so in a sentence they would understand? The audit's constructive finding is the one to design to: demographic data for fairness monitoring should be self-declared, optional, collected after the assessment rather than before it, and kept off the selection path entirely.
Source: ICO — AI tools in recruitment, audit outcomes report (PDF)
ICO, Recruitment rewired — automated decision-making in recruitment (31 March 2026)
In force as regulatory expectation · published 31 March 2026 · drawn from voluntary engagement with over 30 employers between March 2025 and January 2026
The ICO's update on its work on the fair and responsible use of automation in recruitment, published alongside its AI and biometrics strategy. It reports that many employers engaging in automated recruitment are likely relying on solely automated decisions without adequate safeguards currently in place, and that the human involvement an employer does apply has to be applied consistently to every candidate within a hiring stage. Its accompanying public perceptions research found people accepted that automated decision-making can help remove bias while also being concerned it could have the opposite effect. Employer-facing expectations run to establishing a lawful basis, meaningful transparency, safeguards, fairness and bias testing, and a data protection impact assessment.
What it means for a hiring assessment
The consistency point is the operational one and it is cheap to get wrong. A screen where the recruiter reviews borderline candidates but lets clear failures through untouched is not a human-reviewed process with a shortcut; it is a solely automated process for everyone below the borderline band, and that is the population the safeguards exist to protect. Either the human sees every candidate at that stage, or accept that the stage is automated and build Article 22B's four safeguards around it — those are the two defensible designs and the middle is the one the ICO has flagged. The second half of the work is the DPIA, and it is yours: no vendor can conduct it for you and none should offer to. What a vendor owes you is the inputs — what is captured during an attempt, where it is stored, who inside your organisation can see it, which sub-processors receive it, and the retention period.
Source: ICO — Recruitment rewired
Equality Act 2010, section 19 — indirect discrimination
In force · Royal Assent 8 April 2010 · enforced through the employment tribunal; EHRC has strategic enforcement powers
A person discriminates against another if they apply a provision, criterion or practice which is discriminatory in relation to a relevant protected characteristic. It is discriminatory if it is applied to persons who do not share the characteristic, it puts persons sharing it at a particular disadvantage when compared with persons who do not, it puts that person at that disadvantage, and it cannot be shown to be a proportionate means of achieving a legitimate aim. Section 19(3) lists the relevant protected characteristics: age, disability, gender reassignment, marriage and civil partnership, race, religion or belief, sex, and sexual orientation. The section states no ratio, percentage or numerical threshold of any kind.
What it means for a hiring assessment
A selection test is a provision, criterion or practice, and every cut score is one too, which means the tribunal question is never "did it pass a statistical rule" but "was this a proportionate means of achieving a legitimate aim". Proportionality is answered with documents you either wrote before the drive or did not: the job analysis that says which capabilities the role requires, the reason each instrument was chosen to measure one of them, the basis on which the bar was set at the number it was set at, and evidence that you considered a less discriminatory way of getting the same information. Two habits fail this test regularly and neither looks like discrimination at the time — a timed element on a test where the job has no speed requirement, and a cut score inherited from a previous drive that nobody has re-justified against the current role. Do the arithmetic anyway, because a group difference is the thing that prompts you to look; just do not treat a passing ratio as a defence, because in this jurisdiction it is not one.
Source: Equality Act 2010, section 19 (legislation.gov.uk)
Equality Act 2010, section 60 — enquiries about disability and health
In force · direct enforcement reserved to the Equality and Human Rights Commission under section 120(8)
An employer must not ask about the health or disability of an applicant before offering work, whether conditionally or unconditionally, or before including the applicant in a pool of people to be offered work in the future. The exceptions permit questions necessary for establishing whether the applicant will be able to comply with a requirement to undergo an assessment, or whether a duty to make reasonable adjustments is or will be imposed in relation to such an assessment; establishing whether the applicant will be able to carry out a function intrinsic to the work, with reasonable adjustments in place; monitoring diversity in applications; supporting positive action for disabled people; and establishing that an applicant has a disability where having one is an occupational requirement. Only the EHRC can enforce a breach directly. Where an employer asks a prohibited question and then rejects the applicant, the burden of proof shifts to the employer in a subsequent disability discrimination claim.
What it means for a hiring assessment
This section changes the form, not the policy, which is why it belongs on a page like this rather than in a handbook. Audit every screen your candidates actually see and delete health questions from the pre-offer path: general medical declarations, sickness-absence history, and wellbeing or resilience items whose answers are health information dressed as a personality inventory. Then add the one question the exceptions specifically permit and most screens omit — whether the candidate needs an adjustment in order to take the assessment — and route the answer to whoever configures the sitting rather than into the scoring record, since an adjustment need is data about disability and does not belong beside a score. Common adjustments are extra time, a screen-reader-compatible format, a paused or untimed section, and an alternative to a webcam-proctored sitting. Decide in advance what happens to a score produced under an adjustment, because "we gave extra time and then compared against the standard bar" is a decision, and one you should have made deliberately.
Source: Equality Act 2010, section 60 — explanatory notes (legislation.gov.uk)
The four-fifths rule — 29 CFR 1607.4(D), United States
NOT UK LAW · a United States EEOC Uniform Guidelines convention · included because it is routinely sold into the UK as a compliance standard
A selection rate for any race, sex, or ethnic group which is less than four-fifths, or eighty percent, of the rate for the group with the highest rate will generally be regarded by the Federal enforcement agencies as evidence of adverse impact. The same paragraph qualifies itself in both directions: smaller differences in selection rate may nevertheless constitute adverse impact where they are significant in both statistical and practical terms, or where a user's actions have discouraged applicants disproportionately; and greater differences may not constitute adverse impact where the differences are based on small numbers and are not statistically significant, or where special recruiting programmes make the candidate pool atypical.
What it means for a hiring assessment
Included because it is the honest limit of a feature AssessAll ships. The platform's adverse-impact monitor computes selection rates per group and flags a group falling below 80% of the highest-rate group — the American convention — over self-declared gender and a four-way age band, with groups smaller than five shown but excluded from flagging. That is a useful investigative prompt and it is what the code calls it. It is not a UK compliance test, for three separate reasons worth stating plainly: the rule has no standing under the Equality Act; the monitor carries no ethnicity, religion or disability dimension, so the characteristics most often at issue in a UK indirect discrimination claim are not measured at all; and a passing ratio is evidence of nothing under a statute that contains no ratio. The right way to use it in the UK is as a trigger to open the proportionality file, never as a badge to close it — and if a vendor offers you an ethnicity dimension for this, ask whether the data is self-declared or inferred before you accept it.
Source: 29 CFR 1607.4 — Information on impact (Cornell LII)
Cross-sector AI legislation
DOES NOT EXIST · no AI bill in the King's Speech of 13 May 2026 · the Regulating for Growth Bill carries an AI Growth Lab sandbox · the 2023 pro-innovation white paper principles are non-statutory
The UK has no AI-specific statute and no dedicated AI regulator. AI is governed through existing law applied in context, plus the non-statutory principles of the 2023 pro-innovation white paper, with existing regulators acting within their remits. The King's Speech of 13 May 2026 contained no cross-sector AI bill; the Regulating for Growth Bill includes provisions for an AI Growth Lab allowing AI products and regulatory reforms to be tested under real-world conditions. In December 2025 the Secretary of State told Parliament she was thinking more in terms of specific areas where action may be needed than a single all-encompassing bill. The AI Security Institute, renamed from the AI Safety Institute in February 2025, tests AI systems and develops risk-mitigation methods but is not a regulator of employment AI.
What it means for a hiring assessment
Two errors in opposite directions, and UK buyers make both. Do not accept a vendor claim of "UK AI Act compliant" — there is nothing to comply with, and the claim tells you the page was written by someone who did not check. And do not read the absence as permission: the ICO is the regulator that already reached this ground, twice, and the Equality Act reached it decades earlier. Note also what does not exist here that does exist elsewhere, because global vendor collateral blurs it — the UK has no equivalent of New York City's Local Law 144 annual independent bias audit and no equivalent of Illinois's video-interview consent statute, so an American vendor's bias-audit certificate is a fact about another jurisdiction. If you operate in the EU as well, the EU AI Act's employment provisions are a separate analysis on a separate timetable and nothing on this page speaks to them.
Source: House of Lords Library — AI regulation in the UK: the need for cross-sector legislation