AI Services for Human Resources
Hiring is the most regulated AI application in any company, and several of the rules are already live rather than approaching.
Everywhere else in AI the compliance conversation is about 2027. In hiring several obligations are already live, they differ by jurisdiction, and they attach to the tool as much as to the employer.
AI services for human resources cover candidate sourcing and application operations, interview scheduling, attrition and retention modelling, workforce analytics, employee enquiry handling, and the bias auditing, notice and record keeping obligations attaching to automated employment decision tools.
What already applies, jurisdiction by jurisdiction
These obligations are in force or dated, they differ materially, and they apply according to where your candidates and employees are rather than where your HR team sits.
- New York City. Automated employment decision tools require an annual independent bias audit, publication of results, and notice to candidates before use.
- Illinois. Since 1 January 2026, notice is required where AI is used in employment decisions, discriminatory use is prohibited, and zip codes may not be used as proxies for protected classes.
- California. Regulations effective 1 October 2025 make evidence of anti bias testing relevant to claims and defences, and extend retention of automated decision system data to four years including training data.
- Colorado. The state AI Act was postponed to 30 June 2026, requiring impact assessments and disclosures for high risk systems, which includes employment.
- European Union. Recruitment, selection, promotion, termination, task allocation and worker monitoring are high risk under Annex III, with obligations from 2 December 2027.
The four year retention rule quietly changes your architecture
California's requirement to retain automated decision system data for four years, expressly including training datasets, is easy to read past and effectively impossible to satisfy retrospectively. It means the data that trained a screening model, the inputs it saw for each candidate and the outputs it produced must be retained and retrievable for far longer than machine learning systems are usually designed to keep anything. Building it in at the start costs very little. Discovering it in year three costs a great deal. See AI governance frameworks.
If you screen, build it so it survives an audit
Test outcomes, not inputs
Removing protected characteristics from the feature set proves nothing. Education, employment gaps, postcodes, names and language patterns all correlate with protected groups, and the only way to know the effect is to measure selection rates across groups at each stage.
Rank rather than reject
A system that orders candidates for a recruiter to review is materially different from one that filters candidates out unseen. The second concentrates the exposure and removes the human involvement several of these regimes assume.
Build the audit trail as a product feature
Which candidates were assessed, what the model saw, what it output and what the human decided, retained and queryable. Where an annual independent audit is required, that is precisely what the auditor asks for.
Job description analysis is the lower risk starting point
Analysing postings for language that correlates with narrower applicant pools improves outcomes without making any selection decision about anyone.
Where the safe value is while screening is settled
| Application | Regulatory weight | Note |
|---|---|---|
| Attrition and retention modelling | Low | Informs a conversation, not a selection decision |
| Interview scheduling and coordination | Low | Pure operations; large saving in high volume hiring |
| Application data extraction | Low | Parsing into structured fields; do not let parsing become scoring |
| Job description analysis | Low | Improves the pool without deciding on anyone |
| Employee enquiry handling | Low | Policy and process questions; escalate anything about a case |
| Sourcing and candidate search | Lower | Finding is different from selecting; document the distinction |
| Screening and ranking | High | Bias audit, notice and record keeping obligations attach |
| Emotion inference in interviews | Prohibited in the EU | Do not build it |
Attrition modelling is the HR application nobody argues about
Predicting which employees are at risk of leaving, and why, uses data you already hold, informs a retention conversation rather than a selection decision, and sits outside the automated employment decision tool regimes on most readings. It is also worth more commercially in most organisations than faster screening, because replacing a skilled employee costs far more than a slow hiring process does. It is our usual recommendation when a client arrives asking for screening.
How an engagement runs
The jurisdictional position first, because it determines what may be built at all.
Compliance position
Where your candidates and employees are, which regimes apply, and what each requires.
Data assessment
Hiring history, outcome data, and whether group level analysis is possible with what you hold.
Build
Sourcing and operations, attrition modelling, or screening with audit trail and outcome testing built in.
Testing
Selection rates across groups at every stage, documented as an artefact rather than a slide.
Operation
Scheduled outcome testing, retention to the longest applicable period, annual audit support.
What you receive
Operational time recovered, and anything regulated built to survive inspection.
Jurisdictional compliance position
Which regimes apply to your hiring footprint and what each obliges you to do.
Attrition and retention modelling
Risk with reasons, informing conversations rather than decisions.
Application operations
Parsing, scheduling and candidate communication, with decisions kept with people.
Outcome testing harness
Selection rates by group at every stage, run on a schedule and retained.
Audit trail
What the model saw, what it output and what the human decided, retained and queryable.
Job description analysis
Language that narrows the applicant pool, surfaced before posting.
Is this the right starting point?
Worth being direct. There are situations in human resources where custom AI work is the wrong spend, and those are listed rather than buried.
Worth doing if
- You hire across multiple jurisdictions with no map of which AI rules apply.
- Interview scheduling and application processing consume recruiter time at volume.
- A screening tool is in use and you cannot produce the bias audit evidence required.
- Attrition is expensive and has never been modelled.
- Job postings are written without analysis of who they attract.
Do something else if
- You want automated rejection without a human reviewing the decision.
- You want emotion or affect inference from interviews.
- Hiring outcome data cannot support group level analysis and there is no route to collecting it.
- There is no appetite for the record retention several of these regimes require.
Frequently asked questions
Marked up with FAQPage schema so these answers can surface directly in search results and inside AI assistant responses.
Which rules apply to us?
It depends on where your candidates and employees are rather than where your HR team sits, and the answer is usually several at once. New York City requires an annual independent bias audit with published results and candidate notice. Illinois requires notice and prohibits zip codes as proxies from 1 January 2026. California regulations from 1 October 2025 make anti bias testing evidence relevant and extend automated decision data retention to four years. Colorado arrives 30 June 2026. In the EU, hiring AI is high risk from 2 December 2027. Mapping your footprint takes days rather than weeks.
Our model does not use protected characteristics. Is that enough?
No, and it is the most persistent misunderstanding in HR technology. Education history, employment gaps, postcodes, names, language patterns and hobbies all correlate with protected groups, so a model with an entirely clean input list can still produce materially different selection rates. Both the regulatory regimes and the litigation risk look at outcomes. Measuring selection rates across groups at each stage is the only way to know, and it requires demographic data you may not currently collect, which is a project in itself.
Can we automate rejections?
You can build it and we would advise against it in most configurations. Automated rejection concentrates your exposure in exactly the decision these regimes scrutinise and removes the human involvement several of them assume is present. Ranking candidates for a recruiter to review achieves most of the throughput benefit at a fraction of the risk and keeps a person accountable. If volume genuinely requires filtering, the threshold, its justification and its measured effect across groups all need documenting before it runs.
What should we build instead of screening?
Attrition modelling, usually. It uses data you already hold, informs a retention conversation rather than a selection decision, sits outside the automated employment decision tool regimes on most readings, and replacing a skilled employee costs far more than a slow hiring process does. Beyond that, scheduling, application parsing and candidate communication are operational savings with no meaningful regulatory weight. We suggest these routinely to clients who arrive asking for screening, and a fair number find the alternative worth more.
What does the four year retention rule actually require?
California requires retention of automated decision system data for four years, expressly including the datasets used to train the system. In practice the training data, the inputs the model saw for each candidate, its outputs and the resulting decision must all be retained and retrievable for far longer than machine learning systems are usually designed to keep anything. It is easy to read past and effectively impossible to satisfy retrospectively, because the data will not have been kept. Designing for it upfront costs very little.
Other business functions
Teams working on human resources usually share systems, data and stakeholders with these. All twelve are listed on the Solutions page.
AI Services for Legal and Compliance
Contract extraction, precedent retrieval and policy checking, built around a verification step that actually happens.
Read more →AI Services for Operations
Backlog analytics, scheduling with real constraints and exception handling, built to be used rather than admired.
Read more →AI Services for Executive and Strategy Teams
Portfolio assessment, board reporting and governance, including which projects should stop.
Read more →Tell us what the problem looks like.
Thirty minutes, no charge, no deck. We will tell you whether this is an AI problem, a data problem, or a process problem, and we will say when the honest answer is to buy something rather than build it.