AI Academy · Book
Executives & Directors · Module 05 · Chapter 004

AI in Human Resources

AI can answer employees' questions, draft and summarize at a speed no HR team can match. The same tools, pointed at hiring, pay, shifts or exit, start deciding things about people's working lives. Use AI freely for service work; for people decisions, insist that a named person decides, that outcomes are tested and that the people affected are told.

≈ 16 min read

After this chapter you can

  • Distinguish HR service work from consequential people decisions, using one test question.
  • Design a safe first HR use case around an approved source, access controls and a handover to a person.
  • Explain why a model trained on past HR decisions repeats them, and why agreement with past selectors is not proof of quality.
  • Place an HR AI proposal on a risk tier, including what the EU prohibits outright.
  • Name the EU and US rules that reach HR AI as of October 2026, and which duties apply before launch.

In December 2022 the Pew Research Center asked more than 11,000 American adults how they felt about AI in hiring. The answers split along a line that every HR leader should notice. Using AI to review job applications drew opposition from 41 percent. Using AI to make the final hiring decision drew opposition from 71 percent, with only 7 percent in favor. Two in three said they would not want to apply to an employer that used AI to help make hiring decisions1.

Employers are moving faster than that public mood. In SHRM’s surveys of US HR professionals, the share of organizations using AI for HR tasks rose from 26 percent in 2024 to 43 percent in 20252. Much of that use is sensible: drafting job descriptions, answering employee questions, summarizing applications. Some of it drifts, often without anyone choosing it, from reviewing toward deciding.

The public drew the line in the right place. The distance between helping a person decide and deciding for them is where HR AI succeeds or fails, and it is a distance the executive, not the vendor, has to set.

Service work and people decisions

HR runs a wide range of work: employee questions, service requests, recruiting, onboarding, learning, talent reviews, workforce planning, pay and performance. AI can help in all of it. But the work comes in two kinds, and they need different designs.

HR service work aims for speed with access controls; people decisions need a named person who owns the decision.HR SERVICE WORKAnswer, route and draftfor employees.Speed with access controlsPEOPLE DECISIONSHire, promote, pay, assignor dismiss.A named person decidesvs
Figure 5.4.1 Both kinds save time. Only one decides something about a person’s livelihood.

Service work answers, routes and drafts. An employee asks how parental leave works; a manager needs a job ad; a request needs to reach the right team. The goal is speed and consistency, and the main risk is showing the wrong person the wrong data. People decisions are different in kind. Who is hired, who is promoted, who is paid more, who gets which shifts, who is asked to leave. The goal there is a decision that is fair, that someone owns and that the person affected can have explained to them.

The test that separates the two is one question: does the output shape someone’s job, pay or opportunity? Leaders who skip it make two opposite mistakes. They under-design the consequential cases, treating a candidate ranking as just another assistant. And they over-fear the safe ones, holding back a policy assistant that could save many hours because “AI in HR” sounds dangerous.

Start with the questions employees already ask

The highest volume and the lowest risk sit in the same place: the questions employees ask every day. Picture an illustrative case. Today, an employee who wants the parental leave rules searches the intranet, opens three documents that disagree, and then emails HR anyway. Someone in HR reads the email, finds the policy for that country and contract type, and writes the same answer for the fortieth time that month.

An HR knowledge assistant recognizes the question, retrieves the approved policy, answers with the source and hands over to a person, all inside access rules.RecognizeLeave, benefits,travelRetrieveRight policyversionAnswerShow the sourceHand overWhen sensitiveAccess rules decide what it sees.
Figure 5.4.2 An HR knowledge assistant is only as safe as the source it answers from and the data it is allowed to see.

With a knowledge assistant, the flow changes. The assistant recognizes the kind of question. It retrieves the approved policy, and the right version of it, because policies differ by country, contract type, business unit and effective date. It answers and shows the source, so the employee can check it. And it hands over to a person when the case is unusual, sensitive or unclear: a bereavement, a grievance, a health question.

Two design choices decide whether this works. The first is the source. The answer must come from your policy, not from what a general model happens to know about leave law in general. The second is access. An assistant connected to HR systems can surface salaries, health notes or performance records to the wrong person if its permissions are loose; Privacy and Confidential Data covers how permission-aware retrieval prevents that. Design what the assistant may see before you design what it says. Then measure what matters to the employee: whether the answer matched the policy, whether sensitive cases reached a person, and whether HR still receives the email. Take that baseline yourself: independent evidence of what HR assistants deliver in real deployments is still thin, and most published figures come from vendors, so the time saved is a capability to prove, not a result to assume.

In recruiting, AI assists and a person decides

Recruiting is where many HR AI proposals arrive, because volume is the recruiter’s daily problem. It is also where the line between helping and deciding matters most.

In recruiting AI may organize applications, draft job ads and suggest internal matches, but must not alone reject, promote, dismiss or set pay.AI may assistOrganize applicationsDraft job adsSuggest internal matchesNot decide aloneReject candidatesPromote or dismissSet pay'Best candidate' is a judgment, not a field.
Figure 5.4.3 AI earns its place in recruiting by helping people read faster, not by deciding who is read at all.

AI does useful work on the left. It can extract and organize what is in an application, so a recruiter reads a clean summary instead of a messy file. It can draft job ads and interview guides. It can suggest internal candidates whose skills fit an open role, for a manager and the employee to review together. These are capabilities; there is little independent evidence yet that they improve who is hired, as opposed to how fast recruiters read. What it should not do alone is reject a candidate, promote or dismiss someone, or set pay. “Best candidate” is not a field in a database. It is a judgment about what the organization needs now, and it changes with strategy. A model trained on past choices knows only what you used to want.

A person at the end of the process is not, by itself, enough. In its first ruling on the GDPR’s rule on automated decisions, the EU Court of Justice held that an automated score that plays a determining role in someone else’s decision counts as a decision in its own right3. The case was about credit scoring, but the logic travels: if recruiters only ever see the candidates a ranking puts on top, the ranking has decided for everyone below the line.

The risk is not only subtle. In 2023 iTutorGroup, an online tutoring business, paid 365,000 dollars to settle the US Equal Employment Opportunity Commission’s first lawsuit over automated hiring, which alleged that its application software automatically rejected women aged 55 or older and men aged 60 or older4. No machine learning was needed; a filter nobody questioned was enough.

The same caution applies to attrition prediction. A model can find patterns linked to people who left before. That is a signal for a conversation at team level, not a verdict about an individual.

Yesterday’s decisions become tomorrow’s rules

HR data needs more care than most business data, because it is made of past decisions about people.

Past hiring decisions become training data, the model learns the pattern and its proxies, and its recommendations repeat yesterday - so outcomes must be tested by group.Past decisionsWho wehired beforeTraining dataBecomes thedefinition of goodModelLearns the patternand proxiesOutputsRepeat yesterdayat scaleThe bias loopTest by group
Figure 5.4.4 A hiring model trained on past hires makes the organization more efficient at repeating yesterday.

The loop starts with who was hired, promoted and rated highly over many years. Those decisions become the training data and, quietly, the definition of a good candidate. The model learns the pattern, including the parts that were habit rather than strategy. Its recommendations then shape the next round of decisions, and the loop closes.

Two shortcuts do not break it. Removing gender or age fields is not enough, because other fields carry the same signal; Bias and Fairness shows how these proxies work. Nor do newer models escape the problem. When researchers ran more than 3 million résumé-to-job comparisons through three language models, résumés with white-associated names were preferred in 85.1 percent of cases5. And a recruiter glancing over a ranked list does not remove a systematic pattern, because people tend to accept a ranking they are shown, as Operational and Workforce Risk explains.

What works is measurement. Compare outcomes by group, such as selection rates for women and men or by age band, before launch and at fixed intervals afterward, and assign someone to act on what the comparison shows. Fairness in HR has to be measured; it cannot be assumed.

Risk rises with what the system decides about a person

Put the two kinds of work and the bias loop together and you get a risk map. At each tier the question is the same: how much could this change someone’s working life?

HR AI risk rises from policy answers to talent matching to high-risk people decisions, and emotion recognition at work is prohibited in the EU.Prohibited(EU)Emotion recognition at workStopHigh riskHiring, promotion, exit, tasks, monitoringPerson decidesMediumMatching, workforce analyticsExplainLowerPolicy answers, draftingAccess controlsSTAKES
Figure 5.4.5 HR AI risk rises with the consequence for the person. At the top, the EU does not regulate the use; it bans it.

At the bottom sit policy answers, drafting and routing; the main control is access. Next come talent matching and workforce analytics, which shape opportunities indirectly, so people need to be able to see a suggestion and why it was made. Then the high-risk tier. The EU AI Act lists as high-risk any AI used to recruit or select people, “to analyse and filter job applications”, and AI used to decide promotion or termination, to allocate tasks based on behavior or personal traits, or to monitor and evaluate performance6. An Annex III system that profiles people is always treated as high-risk7.

At the top is a tier many leaders do not expect. Since 2 February 2025, the EU has prohibited AI systems that infer the emotions of people at work, with narrow medical and safety exceptions. The Commission’s guidelines make the line concrete: a call center using webcams and voice analysis to track its employees’ emotions is prohibited, while analyzing customers’ emotions is outside this ban, and detecting physical states such as a driver’s fatigue is not emotion recognition at all8. Engagement scores read from faces on video calls fall on the wrong side of that line. The public is not far behind the law: 70 percent of Americans in Pew’s survey opposed using face recognition to analyze employees’ facial expressions1.

The rules that already apply

HR AI is one of the most regulated uses of AI, and the rules sit in several places at once.

As of October 2026, HR AI meets the EU AI Act ban and high-risk duties, GDPR Article 22, works-council consultation, New York City bias audits, and Colorado and California notice duties.RuleWhat it requiresAppliesEU AI ActEmotion AI at work banned; HR AI high-riskFeb 2025; Dec 2027GDPR Art. 22No solely automated significant decisionsSince 2018Works councilsInform or consult before monitoring toolsNowNYC LL144Yearly bias audit, results, noticeSince 2023ColoradoNarrower, notice-based frameworkJan 2027California ADMTNotice, opt-out, accessJan 2027
Figure 5.4.6 Six rules that reach HR AI in Europe and the United States, as of October 2026.

Two patterns run through the list. The first is timing. Several of these duties apply before the system is switched on: the consultation, the candidate notice, the bias audit, the impact assessment. A team that discovers them after a pilot has already broken some of them. The second is that a rule on paper is a floor, not proof of safety. Bias and Fairness shows how weakly New York’s audit law has been enforced14; a tool can pass a narrow legal test and still screen out the people you most wanted to hire.

Before approving, ask who owns the decision

When an HR AI proposal reaches your desk, one question sorts it.

If an HR AI proposal shapes someone's job, pay or opportunity, a named person decides and the organization tests, notifies and consults; otherwise approve it with access controls.Does it shapesomeone's job, payor opportunity?NoNo - service workApprove with access controlsYesYes - people decisionA named person decidesTest, notify, consult
Figure 5.4.7 The approval question is not whether the tool works. It is who decides, and what has been done before launch.

If the answer is no, it is service work. Approve it with an approved source, access controls and a clear handover to a person, and measure accuracy and speed. If the answer is yes, the bar rises, and the proposal should answer five questions before it reaches you. Who makes the final decision, by name, and do they see every case or only the ones the system passes through? What personal data does the system use, and is any of it more than the task requires? How will outcomes be compared across groups, before launch and after? Who is told, and when: candidates, employees, their representatives? And what is the value once the cost of oversight, testing and consultation is counted? Sometimes the assistance is worth it and the automation is not.

Story: the program that agreed with its selectors

One of the clearest post-mortems of an automated applicant screen is almost forty years old, and it happened at a university.

In the 1970s, a doctor on the staff of a London medical school, part of the University of London, began writing a program to take over the first sift of applications. The school received about 2,000 a year, and reading them all was a heavy load for the selection panel. He built the program to do what the panel did. By 1979 it agreed with the panel’s gradings 90 to 95 percent of the time, and from 1982 every initial application passed through it before any person decided who would be interviewed15.

A medical school's screening program, built to mimic its selection panel, agreed with it 90 to 95 percent of the time, screened every application from 1982, and was found to discriminate in 1988.1970sProgramwrittenBuilt to mimic theselection panel197990-95%agreementMatches the panel'spast gradings1982Screens everyapplicationBefore any personsees them1986Two lecturersraise the alarmReport to theequality regulator1988Found todiscriminateOn grounds of raceand sex
Figure 5.4.8 The program did exactly what it was built to do. That was the problem.

In December 1986 two senior lecturers at the school told the UK’s Commission for Racial Equality that the program discriminated. The commission’s investigation found that it deducted points from applicants with non-European names, about 15, and from women, about 315. In 1988 the commission found the school guilty of racial and sexual discrimination. As many as 60 applicants a year may have been refused an interview because of their sex or racial origin16.

The program agreed with the selection panel 90 to 95 percent of the time, and up to 60 applicants a year may have been refused interview because of sex or race.90-95%Agreement with the panelThe test the program passedUp to 60Applicants a yearPossibly refused interview by sex or raceSource: BMJ, 1988; IEEE Spectrum, 2019 · 1979-1988
Figure 5.4.9 High agreement with past decisions was the evidence of quality. It was also the evidence of bias.

The post-mortem holds four lessons, and none of them is about software. First, the program was validated against the wrong standard. Agreement with past selectors was treated as proof of quality, but as the British Medical Journal noted, the program had not introduced new bias; it had faithfully reproduced the bias already in the panel’s decisions16. Second, nobody compared outcomes by group for years. The problem was found by two colleagues who looked, not by a control that was designed to look. Third, taking people out of the first sift removed the one place where someone might have noticed a strong application being turned away. Fourth, the school remained responsible. The program was its own, and so was the finding; three applicants who had been rejected were later offered places15.

Replace the medical school with any employer and the panel with ten years of hiring decisions, and the story describes a modern résumé screen almost exactly. The EU AI Act’s description of high-risk recruiting AI, filtering applications and evaluating candidates, would fit it word for word.

What this means for leaders

The lessons for an executive are practical. Start with service work, where volume is high and the consequence for any one person is low, and invest in the source and the access rules. In hiring, promotion, pay, task allocation and exit, let AI assist people and keep a named person accountable for every decision, including every rejection. Treat agreement with past decisions as a warning sign as much as a quality mark, and require outcome tests by group before launch and on a schedule. Find out which duties apply before the pilot, not after: consultation, notice, audits and the EU ban on emotion recognition at work. And judge success by the people outcome, not only by recruiter hours saved.

Check yourself

  1. Removing gender and age fields makes a hiring model fair.
  2. In the EU, using AI to infer employees’ emotions at work is prohibited, not just high-risk.
  3. If a recruiter signs off at the end, a ranking tool cannot count as an automated decision.
  4. High agreement with past hiring decisions proves a screening model is good.
  5. In New York City, an automated tool that substantially assists hiring needs a yearly independent bias audit and candidate notice.
  6. An employee policy assistant carries no real risk.

Reflection: where does your line sit?

What comes next

In HR, the cost of a confident mistake falls on a candidate or an employee. The next chapter, AI in Sales and Marketing, turns to the functions closest to revenue, where AI shapes what customers see, are offered and buy, and where personalization raises its own questions of trust.

Laws referenced

EU AI Act · EU

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.

  • 2024-08-01 — Entered into force
  • 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
  • 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
  • 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
  • 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
  • 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
  • 2028-08-02 — High-risk obligations for AI in products regulated under Annex I

Last verified 2026-10-06 · official text

General Data Protection Regulation · EU

Regulation (EU) 2016/679

Personal data is any information relating to an identified or identifiable person, directly or indirectly, including by an identifier such as an online ID (Art. 4(1)). Lawful basis and purpose limitation (Arts. 5-6); processing special-category data, including biometric data used to identify a person, health data and data revealing ethnicity, is prohibited unless a specific exception applies (Art. 9); data protection by design and by default (Art. 25); processors such as AI vendors may act only under a written contract with required terms and sufficient guarantees (Art. 28); transparency to data subjects (Arts. 13-14); right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (Art. 22); breach notification to the supervisory authority within 72 hours (Art. 33) and to individuals without undue delay when the risk is high (Art. 34); data protection impact assessment for high-risk processing (Art. 35). Fines up to EUR 20 million or 4% of global turnover.

  • 2018-05-25 — Applies

Last verified 2026-10-08 · official text

Worker consultation on workplace technology · EU member states

AI Act Art. 26(7); national co-determination law, e.g. Germany BetrVG s.87(1) no. 6, Netherlands WOR art. 27

Introducing systems that can monitor or assess employees usually requires informing or obtaining the consent of works councils or employee representatives, depending on the country. Plan this before a pilot, not after.

Last verified 2026-10-06

NYC Local Law 144 (automated employment decision tools) · US - New York City

NYC Local Law 144 of 2021; DCWP rules

An automated tool that substantially assists hiring or promotion decisions needs an independent bias audit within the past year, a published summary of results, and notice to candidates at least ten business days before use. Penalties USD 500 to 1,500 per violation.

  • 2023-07-05 — Enforcement began

Last verified 2026-10-06 · official text

Colorado AI law · US - Colorado

SB 24-205, repealed and re-enacted by SB 26-189 (signed 14 May 2026)

The first US state law aimed at algorithmic discrimination in consequential decisions. It was delayed and then replaced by a narrower, notice-based framework before it ever took effect. Expect further change.

  • 2027-01-01 — Operative requirements of SB 26-189 take effect

Last verified 2026-10-06

California privacy rules on automated decisions (CCPA regulations) · US - California

California Consumer Privacy Act; CPPA regulations on ADMT, risk assessments and cybersecurity audits (approved by OAL Sept 2025)

The most concrete US privacy rule on AI. Businesses that use automated decision-making technology to make a significant decision about a California resident (finance or lending, housing, education, employment or pay, healthcare) must give notice before use, offer an opt-out unless an exception applies, and answer access requests. Processing that poses significant privacy risk needs a documented risk assessment. There is no comprehensive federal privacy statute; about 20 states have their own laws, and California's is the reference point.

  • 2026-01-01 — Updated CCPA regulations take effect; risk-assessment duty applies to new high-risk processing
  • 2027-01-01 — ADMT duties for significant decisions: pre-use notice, opt-out (with exceptions) and access (some firm alerts cite enforcement from 1 Apr 2027)
  • 2028-04-01 — Attestation of 2026-2027 risk assessments due to the CPPA; cybersecurity audits phase in 2028-2030 by revenue

Last verified 2026-10-06

References

  1. Pew Research Center. AI in Hiring and Evaluating Workers: What Americans Think. Pew Research Center. 2023.
  2. Society for Human Resource Management (SHRM). 2025 Talent Trends. SHRM. 2025.
  3. Court of Justice of the European Union. Judgment of 7 December 2023, OQ v Land Hessen (SCHUFA Holding - Scoring), Case C-634/21. Court of Justice of the European Union (CURIA). 2023.
  4. US Equal Employment Opportunity Commission. iTutorGroup to Pay $365,000 to Settle EEOC Discriminatory Hiring Suit. EEOC Newsroom. 2023.
  5. Kyra Wilson and Aylin Caliskan. Gender, Race, and Intersectional Bias in Resume Screening via Language Model Retrieval. Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society (AIES) 7. 2024.
  6. European Commission, AI Act Service Desk. AI Act, Annex III: High-risk AI systems referred to in Article 6(2). European Commission. 2024.
  7. European Parliament and Council of the European Union. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. 2024.
  8. European Commission. Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act). European Commission. 2025.
  9. European Union. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689. Official Journal of the European Union. 2026.
  10. European Parliament and Council of the European Union. Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union. 2016.
  11. NYC Department of Consumer and Worker Protection. Automated Employment Decision Tools (Local Law 144 of 2021) - revised proposed rules. City of New York. 2022.
  12. McDermott Will & Schulte. Colorado AI law in flux: Comprehensive replacement bill signed after federal court blocks predecessor's enforcement. McDermott Will & Schulte. 2026.
  13. White & Case. CPPA finalizes rules on ADMT, risk assessments, and cybersecurity audits requirements under the CCPA. White & Case LLP. 2025.
  14. Office of the New York State Comptroller. Enforcement of Local Law 144 - Automated Employment Decision Tools (audit of the NYC Department of Consumer and Worker Protection). Office of the New York State Comptroller. 2025.
  15. Oscar Schwartz. Untold History of AI: Algorithmic Bias Was Born in the 1980s. IEEE Spectrum. 2019.
  16. Stella Lowry and Gordon Macpherson. A blot on the profession. British Medical Journal 296(6623), 657-658. 1988.

Further reading

Sources last verified 2026-10-08.