Svennis AI
10 min read

Using Claude in hiring: what UK law allows, and where a person must decide

Claude can draft job adverts, summarise applications and prepare interview questions. Under UK GDPR and the Equality Act, a person must still make every hiring decision.

Abstract cover with a branching line of steps that each pass through a single upright checkpoint before moving on

Using Claude in hiring: what UK law allows in short

Using Claude in hiring is workable under UK law when Claude supports people and a person makes every decision. Claude can draft job adverts, summarise applications for a reviewer who reads every one, prepare interview questions and write scheduling emails after someone has chosen whom to invite. It should not reject, rank out or score candidates on its own.

The dividing line is the solely automated decision. A solely automated decision is a decision with no meaningful human involvement in the taking of it. That is the wording of UK GDPR Article 22A. In the ICO's recruitment use cases, a tool that automatically rejects candidates below a pass mark makes this kind of decision. So does a hiring manager who rejects candidates without considering every application.

This guide covers the two bodies of law that apply most directly to a UK employer's hiring process: data protection law and equality law. It also covers Anthropic's own Usage Policy, which is a contract term rather than law. It is not legal advice. Where your process sits close to a line, a lawyer or the ICO's published guidance is the next step.

UK GDPR Articles 22A to 22D and the Equality Act 2010 are the rules that apply

Two sets of rules decide what a UK employer may do with Claude in recruitment. The first is data protection law, in particular the automated decision-making articles of the UK GDPR. The second is the Equality Act 2010, which governs how an employer decides whom to offer a job.

UK GDPR on automated decisions

Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D on automated individual decision-making. Parts came into force on 19 June 2025 for specified purposes. The rest came into force on 5 February 2026, by S.I. 2026/82. If you want the articles laid out with notes, see the key UK GDPR articles for AI, annotated.

The Equality Act 2010 on recruitment

Section 39 of the Equality Act 2010 says an employer must not discriminate against a person in the arrangements it makes for deciding to whom to offer employment. The same section bars discrimination by not offering a person employment. Section 19 defines indirect discrimination, which is the risk most relevant to an AI tool applying the same criterion to everyone. Both sections extend to England, Wales and Scotland.

A screening process that uses Claude is part of those "arrangements". The law applies to the process as a whole, whichever tool carries out a step.

Solely automated decisions under Article 22A and the safeguards they require

Article 22A of the UK GDPR defines a solely automated decision. A decision is based solely on automated processing if there is no meaningful human involvement in taking it. A significant decision is one that produces a legal effect for the person, or a similarly significant effect. The ICO treats recruitment decisions made this way as falling within these provisions.

Article 22A also tells you how to judge the human role. A person judging the human role must consider, among other things, how far the decision is reached by means of profiling. A person who glances at a score produced by profiling is weaker involvement than a person who reads the application.

If an employer does take significant decisions based solely on automated processing, Article 22C of the UK GDPR requires safeguards. The controller, meaning the organisation deciding how personal data is used, must put in place measures that:

  • give the candidate information about such decisions;
  • let the candidate make representations about them;
  • let the candidate obtain human intervention from the employer;
  • let the candidate contest the decisions.

There are stricter limits too. Special category data includes health and ethnic origin. A significant decision based entirely or partly on such data may not be taken solely by automated processing. The exceptions include the person's explicit consent. The Secretary of State may also make regulations stating when there is, or is not, meaningful human involvement. For a small employer, the practical reading is simple: keeping a person in every decision avoids building this machinery for a hiring round.

The ICO use cases show where meaningful human involvement starts and stops

The ICO's use cases on meaningful human involvement are the clearest guide to where a hiring tool crosses the line. The ICO sets a test for decision support. A tool counts as decision support, not automated decision-making, only if employers build meaningful human involvement into each stage. That means a human must make every decision about whether to progress a candidate to the next stage.

The ICO describes what the human needs. The person should have the discretion and authority to alter the recruitment decision. They should have the qualifications and training to disagree with the tool and overturn it. They should not attach disproportionate weight to the tool's recommendations. Where several candidates have similar qualifications and experience, a human decides whom to interview, though they can consider the software's recommendations.

The use cases then name the failures. One tool rejects candidates with an overall score below a minimum pass mark, through a pre-scripted email. The ICO says that decision constitutes automated decision-making. A hiring manager who rejects candidates manually without considering every application also makes one, because there has been no meaningful human involvement.

The ICO also names tools that profile candidates. They include personality tests, gamified tests, AI chatbot interviews and AI assessment of written applications used to produce fit scores. A face-to-face interview followed by a manager's decision to appoint or reject is not solely automated. You can read the full set of ICO use cases on meaningful human involvement in about ten minutes.

A hiring tool stays decision support only while a person decides every candidate's progression. Decision support / Solely automated decision. Progression to next stage: A person decides for every candidate / Tool output settles it without meaningful

ICO findings from 2024 and 2026 on AI tools in recruitment

The ICO has looked at AI recruitment tools twice, and both times it found more automation than employers assumed. Its approach has been to engage with the market rather than to begin by enforcing.

The 2024 audit of recruitment tool providers

On 6 November 2024 the ICO published an overview report on AI tools used in recruitment. It carried out consensual audit engagements with developers and providers of AI-powered sourcing, screening and selection tools. The aim was to understand how those tools comply with UK data protection law. The ICO recognised that the tools can offer benefits to employers, and said their use can also lead to risks for people and their information rights.

Recruitment rewired, 2026

The ICO made automated decision-making in recruitment a key regulatory focus in its AI and biometrics strategy of June 2025. Its later report, Recruitment rewired, draws on evidence from over 30 employers that talked to the ICO voluntarily between March 2025 and January 2026. The findings come from voluntary engagement, not an audit or investigation.

The key finding is that many employers using automated recruitment are likely relying on solely automated decisions. The ICO says more safeguards will need to apply than its evidence suggests are in place. It says employers must improve how they inform candidates about the use of automated decision-making. Where employers include meaningful human involvement, it must be applied consistently to all candidates within a hiring stage. Employers should also adopt good practice in monitoring for fairness and bias.

Equality Act sections 39 and 19 applied to AI screening

The Equality Act 2010 matters for AI screening because a tool applies the same criterion to every candidate, and a uniform criterion is exactly what indirect discrimination law examines. Section 39(1) covers the arrangements an employer makes for deciding to whom to offer employment, the terms of an offer and a refusal to offer. Section 39(5) adds that a duty to make reasonable adjustments applies to an employer.

Section 19 defines indirect discrimination. An employer discriminates if it applies a provision, criterion or practice that is discriminatory in relation to a protected characteristic of the candidate. A criterion is discriminatory when all of these conditions hold:

  • the employer applies it, or would apply it, to people who do not share the characteristic;
  • it puts people who share the characteristic at a particular disadvantage compared with those who do not;
  • it puts the candidate at that disadvantage;
  • the employer cannot show it to be a proportionate means of achieving a legitimate aim.

The relevant protected characteristics in section 19 are eight: age, disability, gender reassignment, marriage and civil partnership, race, religion or belief, sex and sexual orientation.

For Claude, this has a direct consequence. An instruction such as "prefer candidates with continuous employment" is a criterion. The criterion may disadvantage disabled people, or women who took time out for caring. If it does, you need to be able to justify it. Write your criteria yourself, from the job, and never ask Claude to infer anything about a candidate's protected characteristics.

Anthropic's Usage Policy: contract terms for employment use cases

Anthropic's Usage Policy adds contract obligations on top of the law when Claude's output in an employment use case is consumer-facing. An example is output that reaches candidates. The policy is a contract term, not law. It applies to anyone who can submit inputs to Anthropic's products and services, including through authorised resellers or passthrough access.

The policy lists "High-Risk Use Cases", and employment and housing is one of them. For those use cases it sets a human-in-the-loop requirement. When products are used to provide advice, recommendations or subjective decisions directly affecting individuals, Anthropic's Usage Policy requires that "a qualified professional in that field must review the content or decision prior to dissemination or finalization."

The policy also sets a disclosure rule for high-risk use cases where outputs reach people directly. You must disclose the use of AI, and "this disclosure must be provided at a minimum at the beginning of each session." Separately, all consumer-facing chatbots, including any external-facing or interactive AI agent, must tell users they are talking to AI rather than a human. A candidate-facing assistant on your careers page falls in that group.

Two further points apply. Agentic use cases, where Claude takes actions rather than only writing text, must still comply with the policy. And if Anthropic learns a user has broken the policy, it may throttle, suspend or terminate access. The policy and the law point the same way: a qualified person reviews before anything is final.

Anthropic's contract adds a qualified professional review on top of the human role UK law requires. UK law / Anthropic Usage Policy. Source: UK GDPR Articles 22A to 22D, Equality Act 2010 / Contract term for Claude users; Who it binds: Employers deci

Which hiring tasks Claude can do, and which stay with a person

The table below sorts common hiring tasks by what Claude does and what a person must do. The rule behind it comes from the ICO use cases: a human makes every decision about whether a candidate moves to the next stage.

TaskClaude's rolePerson's roleWhy
Job advertDraft wording from the role's dutiesSet the criteria, check each one is justifiedCriteria are a "provision, criterion or practice" under section 19
Application summariesSummarise each application against stated criteria, no score or verdictRead every application and decide who progressesICO: a human decides every progression
Fit scores and pass marksNoneNot usedICO: automatic rejection below a pass mark is ADM; fit scores profile candidates
Ranking a shortlistNone as a gateDecide whom to interviewICO: rejecting without considering every application is ADM
Interview questionsDraft questions tied to the criteriaEdit, ask them, decideA face-to-face interview decision is not solely automated
Scheduling and emailsDraft invitations and replies after a decisionMake the decision, approve messagesUsage Policy: review before dissemination
Inferring emotion or protected characteristicsNoneNot doneSection 19 and special category data limits

If a task is not in the table, ask one question: does Claude's output decide whether a candidate moves on? If it does, a person must make that decision after considering the application.

Worked example: summarising applications for a reviewer who reads every one

A worked example shows where the line falls in a normal small-business hiring round. Say you are hiring an office administrator. Applications arrive in your applicant tracking system, for example Zoho Recruit, and the hiring manager will decide who to interview.

First, the manager writes the criteria from the job: the tasks, the software used, the working pattern. Claude then produces one summary per application, using an instruction such as this:

Summarise this application against the criteria listed. For each criterion, quote the evidence from the CV or say "not mentioned". Do not score, rank or recommend. Do not comment on age, gaps in employment, name, nationality or any personal characteristic.

The manager reads every CV alongside its summary and records the decision. The summary saves reading time on structure. It does not replace reading the application.

Compare the ICO's use case. There, a tool gives each application a fit score and rejects everyone below a pass mark by pre-scripted email. The ICO says that decision constitutes automated decision-making. The difference is not the model. It is whether a person with authority considered each application before it was rejected.

At Svennis we set these up so Claude writes its summary into the candidate record while the progression field stays empty until the reviewer fills it in. Where we see it go wrong is a summary that drifts into a verdict line, which reviewers then copy instead of deciding.

Once the manager has chosen whom to invite, Claude can draft the invitations and a booking link from Zoho Bookings can handle times. The manager approves each message before it goes.

What this means for a UK company hiring this year

For a UK employer, two sets of rules shape Claude in recruitment. The first is the UK GDPR as amended by the Data (Use and Access) Act 2025, whose automated decision-making articles have applied since 5 February 2026. The second is the Equality Act 2010. The ICO has made automated recruitment a regulatory focus and has said candidates need better information about automation.

Three practical consequences follow for a small or mid-sized company:

  • Your privacy notice for candidates should say how Claude is used, because the ICO expects clear information about automation in recruitment.
  • Your hiring managers need the authority and the training to disagree with anything Claude produces.
  • Your process must treat every candidate in a stage the same way, since the ICO says human involvement must be applied consistently.

If you recruit in the EU as well, EU rules apply to those roles alongside UK law, and this post does not cover them. For the wider picture of what applies to a UK business using AI, see AI law in the UK and what applies to your business. For the data protection checks before you deploy Claude at all, the GDPR checklist for European firms using Claude is the companion to this guide.

None of this is legal advice. If your process uses scores, filters or anything candidate-facing, have a lawyer review it against the ICO's guidance before your next hiring round.

A checklist to adopt this week

The checklist below turns this guide into steps a hiring manager can take before the next vacancy opens. Each item maps to a rule covered above.

  1. List every step in your hiring process and mark where a candidate can be dropped.
  2. Confirm that a named person makes each of those decisions after considering every application.
  3. Remove any score, pass mark or automatic rejection that Claude or another tool applies on its own.
  4. Write your selection criteria yourself, and note why each one is needed for the job.
  5. Instruct Claude to summarise against those criteria only, with no score, rank or recommendation.
  6. Forbid prompts that ask Claude to infer emotion, personality or any protected characteristic.
  7. Update the candidate privacy notice to say how Claude is used in the process.
  8. Add an AI disclosure at the start of any candidate-facing chat, as the Usage Policy requires.
  9. Have a person approve every message before it reaches a candidate.
  10. Book a review of the process with a lawyer if anything in steps 2 to 8 is unclear.

When the process is settled, the next step on this site is the annotated UK GDPR articles for AI. Read Articles 22A to 22D there before you put Claude into your recruitment workflow.

Sources

  1. 1. Anthropic Usage Policy
  2. 2. Equality Act 2010, section 19
  3. 3. Equality Act 2010, section 39
  4. 4. ICO: Understanding how meaningful human involvement applies, use cases
  5. 5. ICO: Recruitment rewired
  6. 6. ICO: AI tools used in recruitment (2024)
  7. 7. UK GDPR Article 22A
  8. 8. Data (Use and Access) Act 2025, section 80

Related articles