Is It Safe to Use AI for Recruiting?
Yes, if you handle two risks: GDPR (candidates are data subjects) and bias. Pasting raw CVs into a consumer AI tool exposes your company on both fronts.
Yes, you can recruit with AI, but not in any way you like. Two risks fall on the employer. First GDPR: a candidate is a data subject, and their CV is full of personal data. Second bias: automated candidate filtering can reproduce discrimination. The EU AI Act even classes this filtering as high-risk. Pasting raw applications into a consumer AI tool exposes you on both fronts. The fix comes down to one rule: anonymize candidate data before any AI screening.
Two distinct risks for the employer
Using AI to screen CVs isn't unsafe by itself. But two risks stack up, and they are different.
The first is GDPR. A CV holds a name, an email, an address, a career history. That's personal data. The candidate is a data subject. So you owe a lawful basis, transparency and a limited retention period. Pasting an application into a consumer tool sends that data out of your control.
The second is discrimination. A screening tool learns from past data. If that data is biased, the tool reproduces the bias. That's why candidate filtering is closely regulated.
The EU AI Act classes recruiting as high-risk
The EU AI Act places recruitment and selection AI in the high-risk category. It's spelled out in Annex III, point 4(a). The text covers systems used to place targeted job ads, to analyse and filter job applications, and to evaluate candidates. Managing workers is covered too: promotion, termination, task allocation, performance monitoring.
This high-risk status triggers obligations. Risk assessment, technical documentation, human oversight, transparency, and record-keeping through logs. These employment-related obligations become applicable on 2 August 2026 under the EU AI Act's timeline.
Human oversight is required. A recruitment AI must not decide a rejection or an evaluation on its own, without a qualified human in the loop. But be careful: a recruiter reviewing the AI's output does not remove the high-risk status. If the AI materially influences access to the job, the classification stands. GDPR adds a guardrail: Article 22 restricts decisions based solely on automated processing, and an automated job rejection typically falls under it.
This isn't a theoretical fear
The best-known case comes from Amazon. The company built an experimental CV-screening tool, with development starting around 2014. The tool learned to penalise female candidates. Why? It was trained on a decade of resumes, largely dominated by men.
The concrete result: the tool downgraded resumes containing the word “women's” and favoured male-coded language. Amazon could not guarantee the system would be neutral. The company scrapped the project. It's a real, documented example of a recruitment AI copying bias from past data.
Regulators took up the issue. In November 2024, the UK ICO published the outcomes of audits of AI recruitment tools, run between August 2023 and May 2024. The regulator made almost 300 recommendations. It found tools that collected far more data than needed and kept it indefinitely. Some inferred gender or ethnicity from a candidate's name. Others let recruiters filter out applicants with protected characteristics.
The fix: anonymize before you screen
The rule is simple. Remove identifiers before pasting an application into an AI to summarise it or build a shortlist. Name, contact details, address, and other identifiers: strip them from the text first.
This step works twice. On one side, it reduces the personal data leaving your control. On the other, it removes name-based signals. And those are exactly the signals some tools use to guess gender or ethnicity, as the ICO showed.
Under GDPR, the employer owes a clear lawful basis, such as legitimate interests or consent. It must be transparent about the AI's role. It must apply data minimisation and defined retention periods. Anonymizing doesn't replace these duties, but it strongly cuts exposure.
- Remove name, email, address and identifiers before sending anything to a screening AI.
- Keep a qualified human who truly decides on rejection or shortlisting.
- Set a lawful basis, a retention period, and clear notice to the candidate.
Here's a simple running order to frame AI screening:
- 1Confirm your use case is high-risk (filtering, screening or evaluating applications).
- 2Run a Data Protection Impact Assessment (DPIA) before you start processing.
- 3Anonymize applications before sending them to the AI.
- 4Have a recruiter review every major decision, and keep the logs.
| You assume | The reality |
|---|---|
| “Screening CVs with AI is just a time-saver” | The EU AI Act classes it high-risk and imposes obligations |
| “A recruiter reviews it, so it's covered” | Review doesn't remove high-risk status if the AI influences access to the job |
| “The tool is neutral, it's a machine” | Amazon's AI penalised women; the ICO found name-based inferences |
| “The vendor handles compliance” | The employer stays the data controller for candidate data |
That's exactly what ONYRI Sanitize is for: the engine replaces candidate data with reversible tokens before sending. Detection and the mapping stay in your browser, and only anonymized text reaches the model. The AI sees a profile with no name and no contact details — not your candidates' real information.
Frequently asked questions
- Is it safe to use AI for recruiting?
- Yes, as long as you handle two risks. GDPR first: candidates are data subjects, so you need a lawful basis, transparency and a retention period. Bias second: automated screening is classed high-risk by the EU AI Act. The fix is to anonymize candidate data before any AI screening.
- Is AI CV screening really high-risk?
- Yes. The EU AI Act classes recruitment and selection AI as high-risk in Annex III, point 4(a): placing targeted job ads, analysing and filtering applications, evaluating candidates. This triggers obligations (risk assessment, human oversight, transparency, logs) applicable on 2 August 2026.
- Is anonymizing CVs enough to be compliant?
- No, but it strongly cuts exposure. Anonymizing removes the personal data leaving your control and strips name-based signals used to infer gender or ethnicity. You still owe a lawful basis, human oversight, notice to candidates, and a DPIA before high-risk processing.
Sources & references
- EU AI Act Annex III — AI used for recruitment, filtering job applications and evaluating candidates is high-risk (point 4(a)) — EU Artificial Intelligence Act (Future of Life Institute)
- ICO: intervention into AI recruitment tools leads to better data protection for job seekers — audit findings and ~300 recommendations — Information Commissioner's Office (ICO, UK)
- Amazon ditched AI recruitment software because it was biased against women — MIT Technology Review
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.