What legal regulations are already in place regarding AI and HR?

3. August 2026
AI opens up enormous opportunities in the HR sector—from efficient recruiting processes to optimized personnel management. But of course, this also brings with it legal issues and challenges, particularly when it comes to handling personal data. Its use is regulated primarily by the AI Regulation (AI-VO) and the General Data Protection Regulation (GDPR).
The higher the risk of an AI system, the stricter the requirements; for this reason, the AI Regulation also establishes risk classes for AI systems. Accordingly, AI systems used in recruiting are generally considered high-risk systems. Their use is permitted only if extensive requirements are met. This includes the obligation to inform all data subjects—and thus all applicants—that they are subject to the use of a high-risk AI system.
When AI is used to process personal data, companies must also assess this use in accordance with the provisions of the GDPR. In such cases, (former) employees and job applicants have certain rights to information and transparency regarding the processing of their personal data. In addition, (former) employees and job applicants have the right to file a complaint and may request the deletion of their data.
What can job applicants do if they are screened out by AI? What options are available to those affected? And how can one even determine whether the decision was made by AI?
Job applicants generally have the right not to be subject to a decision based solely on automated processing. A fully automated decision in the recruiting process typically violates the provisions of the GDPR as well as the “human-in-the-loop” principle, which requires human review of decisions.
If applicants have not been informed by the companies to which they applied about the use of AI but suspect that an automated decision was made, they may, for example, submit a request for information under Article 15 of the GDPR. As part of its response to the request for information, the company must inform them, among other things, about any automated decision and its implications. Alternatively, applicants are entitled to the “right to an explanation of the decision-making process in individual cases” under the AI Regulation.
This information can provide important clues as to whether and how the application process unfolded and whether discrimination occurred. If discrimination is suspected, it can be challenged in court, and those affected need only establish a prima facie case of discrimination.
Furthermore, the unlawful use of AI may also constitute a data protection violation, a violation of the AI Regulation, or a breach of obligations under labor law.
And how can we even tell if a decision was made by AI?
Indications of AI use may include, for example, automated rejection letters that arrive just a few minutes after an application is submitted. The rights to information under the GDPR and the AI Regulation also help gather the necessary information regarding the unlawful use of AI.
In which areas is the use of AI in HR particularly sensitive? What could go wrong?
The use of AI is particularly sensitive when it comes to candidate selection, performance evaluations, or decisions regarding promotions and terminations. This is especially true when AI is used in areas that could have significant negative consequences for those affected. There are several potential pitfalls: discrimination due to bias in the training data, for example, which goes undetected without human oversight, or a lack of transparency in decision-making (black box). Companies face sanctions, lawsuits, and reputational damage for these legal violations. On the positive side, many companies are aware of their responsibilities and are working hard to ensure that AI systems are used in a legally compliant and targeted manner. Job applicants, however, can also play a role by pointing out gaps and problem areas.

