HR automation software splits into two halves with different risk profiles. Automating leave, payroll data movement, document generation and onboarding tasks is a pure efficiency decision. Automating anything that screens, ranks, scores or filters a person triggers notice, bias-audit, human-review and retention duties that vary by jurisdiction. Buy the first half freely. Procure the second half with legal review.
Last reviewed 10 September 2026. This is not legal advice, and the status of several items below is genuinely unsettled, so we say so where it is.
The line that divides an HR automation purchase
Every comparison page written about HR automation software sorts the market by feature count, pricing tier and integration list. None of them draw the only line that changes what the purchase costs you, which is whether the software forms a view about a person.
Here is the line. A tool that moves data, applies a policy you wrote, or fires a task at a named human is an operational purchase. A tool that produces a score, a rank, a classification or a recommendation about a candidate or an employee is a regulated purchase, and in several jurisdictions it drags a published audit, a candidate notice, a human review route and a retention schedule along behind it.
The distinction is not ours. It is written into the statutes almost word for word. New York City's Local Law 144 of 2021 defines an automated employment decision tool as "any computational process, derived from machine learning, statistical modeling, data analytics, or artificial intelligence, that issues simplified output, including a score, classification, or recommendation, that is used to substantially assist or replace discretionary decision making for making employment decisions that impact natural persons." The same statute expressly carves out spreadsheets, databases, calculators and data sets, because those move numbers without forming a view.
Four terms travel with this and they are not synonyms, which is why procurement conversations go in circles.
An automated employment decision tool, or AEDT, is the New York City term and the Connecticut term, and it turns on whether output substantially assists a hiring or promotion decision. Automated decision-making technology, ADMT, is California's term under the Consumer Privacy Act regulations and Colorado's term under its 2026 statute, and it turns on whether the technology materially influences or substitutes for a significant decision. Automated decision-making in the UK and EU data protection sense, ADM, is the GDPR concept, and it turns on whether a decision with legal or similarly significant effects is made without meaningful human involvement. A high-risk AI system is the EU AI Act classification, and it turns on the use case listed in Annex III, point 4, regardless of how the vendor markets the product.
A single resume-ranking feature can be all four at once, in four jurisdictions, with four different remedies. A leave request approval workflow is none of them anywhere. That gap is the whole point of this piece, and it is the thing no vendor demo will show you, because the demo is built to make everything look like the second case.
Our standing reference on what actually changed, jurisdiction by jurisdiction, is the AI hiring law change log we refresh monthly. This page is the buying decision that sits on top of it.

Which HR processes carry a compliance cost, and which do not
This is the table we now build for clients before any HR automation tools are shortlisted. Read the third column first. If it says no, the purchase is an operations decision. If it says yes, it goes to legal before it goes to finance.
| HR process | What automating it actually does | Automated employment decision? | Obligation that attaches | Jurisdictions that care |
|---|---|---|---|---|
| Leave and absence management | Applies a policy rule to a date range | No | Retain the underlying records; nothing tool-specific | US, UK, EU record-keeping rules |
| Time and attendance capture | Records hours, sometimes location or activity | No, but it is monitoring | Works council agreement; DPIA; worker transparency | Germany, EU, UK |
| Payroll integration and data movement | Copies fields between HRIS and payroll | No | Payroll records three years under the FLSA | US, plus local payroll rules |
| Contract and letter generation | Merges stored data into a template | No | None specific to automation | Nothing triggered |
| Onboarding automation and task sequencing | Fires tasks at IT, facilities and the hiring manager | No | None specific to automation | Nothing triggered |
| Right to work and I-9 verification | Checks a document against a fixed rule | No | Retention: three years after hire or one after exit | US, UK |
| Background check ordering | Places an order and tracks its return | No | Consent and disclosure under the FCRA | US, UK |
| Background check auto-adjudication | Applies a pass or fail rule to a criminal record | Yes, in effect | Pre-adverse and adverse action notices; fair-chance timing | US federal and state, growing |
| Resume parsing with no score | Extracts fields into an applicant tracking system | No | Data minimisation and a retention schedule | EU, UK |
| Resume screening with a fit score or rank | Orders humans against each other | Yes | Bias audit, published summary, 10 business days notice | NYC, IL, CA, CO, CT, EU, UK |
| Interview scheduling by availability | Books a slot in two calendars | No | None specific to automation | Nothing triggered |
| Scheduling that deprioritises by predicted no-show | Allocates access to the process | Yes | Same duties as screening | NYC, IL, EU, UK |
| Video interview content analysis | Scores what a candidate said | Yes | Notice, consent, deletion on request; bias audit if it ranks | IL, NYC, EU |
| Emotion or affect inference from interviews | Infers an internal state | Yes, and prohibited at work in the EU | Article 5 prohibition, in force since 2 February 2025 | EU |
| Performance review scoring or forced ranking | Scores an employee | Yes | Notice, explanation, human review, risk assessment | CO from 2027, CA from 2027, IL, EU |
| Attrition and flight-risk prediction | Scores an employee for retention action | Yes, where it informs a consequential decision | Risk assessment and DPIA; explanation on request | CA, EU, UK |
| Promotion shortlisting | Orders existing employees | Yes | Local Law 144 covers promotion, not only hiring | NYC, CO, CA, EU |
| Discipline or termination recommendation | Proposes an adverse action against a named person | Yes | Human verification; explanation; contest route | CA if SB 947 is signed, CO, EU, UK |
| Offboarding and access revocation | Executes a decision already made | No | Retention schedule and deletion discipline | EU, UK |
| Compliance reporting and pay gap reporting | Aggregates records into a return | No | Accuracy of the return itself | US, UK |
Three things to take from it.
The administrative rows outnumber the regulated rows, and in most HR functions they also carry most of the manual hours. That is a convenient truth rather than an awkward one: the majority of what an HR team wants to stop doing by hand is not regulated as an employment decision anywhere.
The regulated rows cluster around one verb. Ranking. Every row marked yes involves software placing people in an order or a category, and every row marked no involves software executing an instruction. If you cannot decide which side a feature falls on, ask whether removing it would change who gets through, or only how fast they get through.
And the third column is not the vendor's to answer. Under Local Law 144 the duty to commission the bias audit and publish the summary sits with the employer or employment agency using the tool, not with the company that built it.
The administrative half: what you can buy on operational grounds alone
Leave management, absence tracking, document generation, benefits enrolment, expense approval, onboarding automation, offboarding task sequencing, payroll integration and internal helpdesk routing share a property. None of them form a view about a person. They apply rules a human wrote, to data a human entered, and produce an outcome a human could have produced more slowly.
Nothing in Local Law 144, the Illinois Human Rights Act amendments, the Colorado statute, the California Privacy Protection Agency's regulations or Annex III of the EU AI Act reaches a leave approval. Buy those on operational grounds: integration quality, support responsiveness, exit cost, and whether the vendor will give you your data back in a usable shape.
Does automating leave management or payroll create any regulatory obligation?
Not an automation-specific one, but it does not release you from record-keeping either, and automation changes where those records live.
Under the US Fair Labor Standards Act, the Department of Labor's recordkeeping fact sheet requires employers to preserve payroll records for at least three years, and the records on which wage computations are based, including time cards and work and time schedules, for two years. In the UK, regulation 9 of the Working Time Regulations 1998 requires employers to keep records adequate to show whether the working time limits are being complied with, and to retain those records for two years from the date on which they were made.
Neither rule cares whether a human or a system produced the record. Both care whether you can produce it. The failure mode we see most often in HR automation projects is not a compliance breach at all. It is a platform migration that silently drops three years of historical time and attendance data because nobody put record retention in the statement of work. Ask for the export format before you sign, not at renewal.
There is a second-order point worth making about employee records generally. Once leave, time, payroll and performance data sit in one platform, a data subject access request that used to touch four systems now touches one, which is good, and returns far more than it used to, which is a different problem. We come back to that below.
Where employee onboarding automation actually breaks
Employee onboarding is the largest administrative win available in an HR stack, and it is regulated as nothing in particular. A sequence that fires an equipment request at IT, a desk booking at facilities, a first-week plan at the hiring manager and a payroll record at the right cut-off is a policy you wrote, executed on a schedule. It forms no view about the person it is onboarding.
What breaks is the dependency order. Onboarding writes into more systems on day one than any other HR process: identity in the HRIS, access in the directory, bank details in payroll, a right to work check carrying its own retention clock. Most employee onboarding tools model that as a task list with owners and due dates, which captures who does what and not what has to be true before the next step can run. Move a start date by a week and the sequence reruns. Provisioning fires twice, the right to work record keeps the old date, and the payroll entry stays in the period it was first written to.
Two specifics belong in the statement of work. Any task that calls an external system needs an idempotency key, for the same reason the sync layer does. And the right to work step needs its retention period attached at record creation rather than inherited from a tenant-wide default, because the I-9 clock runs from the hire date or the exit date and nothing else in the sequence behaves that way.
Where the administrative half stops being administrative
The clean split has one genuine exception, and buyers walk into it constantly.
Time and attendance capture is not a decision about anybody. It is also, in Germany, a co-determination matter. Section 87(1) number 6 of the Works Constitution Act gives the works council a right to co-determine the "Einführung und Anwendung von technischen Einrichtungen, die dazu bestimmt sind, das Verhalten oder die Leistung der Arbeitnehmer zu überwachen", the introduction and use of technical equipment designed to monitor the conduct or performance of employees. German Federal Labour Court case law reads that broadly: the mere capability to monitor behaviour or performance is enough to trigger the right, whether or not anyone intends to use it that way, and the right is a veto rather than a consultation.
In practice that sweeps in time-recording systems, activity logs inside collaboration tools, ticketing systems that record handling times, and a good deal of standard HCM functionality that nobody thinks of as employee monitoring. If your European rollout plan has a German entity with a works council in it, negotiating a works agreement is a project dependency with a real duration, and it belongs in the timeline next to the integration work rather than in a footnote.
The equivalent in the UK is softer but not absent. Monitoring workers engages the UK GDPR: you need a lawful basis, you need to tell people, and where the monitoring is systematic or large scale you need a data protection impact assessment before you start rather than after go-live.
The EU is adding a third layer for one specific population. Directive (EU) 2024/2831 on improving working conditions in platform work entered into force on 1 December 2024 and must be transposed into national law by 2 December 2026. Its algorithmic management chapter requires platforms to disclose the automated monitoring and decision-making systems they use, prohibits processing aimed at automatically monitoring a worker's emotional or psychological state, requires that decisions to restrict, suspend or terminate an account be taken by a human being, and gives workers a right to human review with a substantiated response within two weeks. Transposition is running late across most member states, so the national detail is not yet knowable. If your workforce includes platform or gig populations in the EU, that is a 2027 budget line with an unknown number attached to it.
So the honest version of the split is this: the administrative half is unregulated as decision-making, and partially regulated as surveillance. Those are different obligations with different owners. Screening obligations land on your legal and talent teams. Monitoring obligations land on your works council, your data protection officer and your employment counsel.
The decisioning half: what changes the moment software ranks a person
The moment a feature produces a score, a rank or a shortlist, several sets of duties can attach at once. Here they are as a buyer needs them, with dates, and with the status flagged where it is unsettled. For the full change log and the litigation behind it, our monthly AI hiring law reference carries the detail and we will not restate it here.
New York City. If an automated employment decision tool substantially assists or replaces discretionary decision-making for a job located in New York City, the employer needs an annual bias audit by an independent auditor, a summary of that audit published on its site, and candidate notification at least 10 business days before the tool is used. The Department of Consumer and Worker Protection sets the requirements out on its own AEDT page and has been enforcing since 5 July 2023. The audit computes selection rates and impact ratios by race, ethnicity and sex, and an adverse impact ratio below 0.80, the four-fifths rule familiar from the Uniform Guidelines on Employee Selection Procedures at 29 CFR 1607.4(D), is the conventional signal of disparate impact. This rule follows the job, not your office.
Illinois. The Human Rights Act amendments under HB 3773 have been in force since 1 January 2026. Employers must notify applicants and employees when AI is used in covered employment decisions, must not use AI in a way that produces a discriminatory effect, and must not use ZIP code as a proxy for a protected class. The Department of Human Rights published proposed implementing rules on 15 May 2026 and then withdrew them, so the statutory duties are live while the rulemaking detail is not settled.
California, twice over. The Civil Rights Department's FEHA regulations on automated decision systems took effect on 1 October 2025 and carry a four-year record retention duty. Separately, the California Privacy Protection Agency announced on 23 September 2025 that the Office of Administrative Law had approved regulations covering automated decisionmaking technology, risk assessments and cybersecurity audits. Risk assessment obligations began on 1 January 2026; the ADMT obligations themselves apply from 1 January 2027, and significant decisions include hiring, compensation, allocation of work, promotion and demotion. Two California regimes, two regulators, one HR system.
Colorado. SB 26-189 replaced the repealed Colorado AI Act and applies from 1 January 2027 to decisions made on or after that date: notice before use, a plain-language explanation within 30 days of an adverse outcome, human review on request where commercially reasonable, and three years of compliance documentation.
Connecticut, which is new since our last write-up. Governor Lamont signed SB 5, the Artificial Intelligence Responsibility and Transparency Act, on 29 May 2026. It takes effect on a staggered basis from 1 October 2026, and the employment provisions apply to automated employment-related decision technology deployed on or after 1 October 2027. The employment duties are disclosure duties rather than audit duties. The deployer must tell employees and applicants that the technology was used, its purpose, the tool's trade name, the categories and sources of personal data used and how that data will be assessed, plus contact details. Trade secrets can be withheld with notice. Enforcement runs through the Attorney General as an unfair trade practice, with a cure period, and there is no private right of action.
California again, still pending. SB 947, the No Robo Bosses Act of 2026, would bar employers from relying solely on an automated decision system to discipline or terminate staff and would require independent human verification. The Senate concurred in Assembly amendments on 31 August 2026 by 28 votes to 10, and the bill was enrolled and presented to the Governor at 2pm on 9 September 2026. He has until 30 September 2026 to sign or veto it, and its predecessor SB 7 was vetoed in October 2025. As of 10 September 2026 it is not law and should not be treated as one. If you are buying performance management software with a discipline recommendation feature and you employ people in California, that is a contract clause you want now rather than a retrofit you want in 2027.
European Union. Annex III, point 4 of the AI Act covers employment and worker management systems, including systems that filter applications, evaluate candidates, and make or materially inform decisions on promotion, termination, task allocation and performance monitoring. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and moved the main standalone high-risk obligations from 2 August 2026 to 2 December 2027. What did not move: the Article 5 prohibitions, in force since 2 February 2025, which include emotion inference in the workplace; the Article 4 AI literacy duty; and the Article 50 transparency duties, which began applying on 2 August 2026. The deferral bought time for the conformity file. It bought nothing for the transparency and prohibition duties.
United Kingdom. There is no UK statute specific to AI in hiring, and the general rule is more demanding than a tool-specific one, because it applies to every automated decision. Section 80 of the Data (Use and Access) Act 2025 came into force on 5 February 2026, replacing GDPR Article 22 in the UK with Articles 22A to 22D. The new default permits significant automated decisions on non-special-category data provided the safeguards are implemented and documented, while keeping tighter restrictions where special category data is involved. Candidates must be informed, must be able to make representations, must be able to obtain human review, and must be able to contest the outcome. On 31 March 2026 the Information Commissioner's Office published a report and draft guidance on automated decision-making in recruitment, built on evidence from more than 30 employers gathered between March 2025 and January 2026. It found that employers who believed they were running decision support were in practice running solely automated decisions with no meaningful human involvement. The consultation closed on 29 May 2026 and the final guidance remains unpublished as at 10 September 2026, with the ICO indicating a winter 2026 date. Anyone telling you the UK position is settled is describing a draft.
The United States federally. The EEOC removed its AI employment guidance from its website in January 2025, and an April 2025 executive order directed federal agencies to de-prioritise disparate impact enforcement. Neither act repealed Title VII, the ADEA or the ADA. Federal guidance disappearing is not the same as federal liability disappearing, and the private plaintiff's bar has not been de-prioritised by anybody.

How do you tell whether a feature is an automated employment decision tool?
Not by the name on the tab. Vendor naming in this category is close to deliberately uninformative, so we run the same three questions against every feature in a demo, in this order.
Does it produce a simplified output about a person? A score, a rank, a percentage match, a traffic light, a tier, a "recommended" flag. If the screen shows candidates in an order the system chose, the answer is yes.
Does that output substantially assist the decision? New York City's rules resolve this with a usable test: a tool substantially assists when the employer relies exclusively on its output, weighs that output more heavily than any other criterion, or uses it to overrule a human judgement that had reached a different conclusion. A recruiter who sorts by fit score and works down the list is relying on it exclusively, whatever the process document says.
Does it affect access to the process, or only the speed of the process? This is the question that catches scheduling, sourcing and talent rediscovery features. If a candidate who would otherwise have been seen is now not seen, the tool allocated access.
Here is how that resolves against the feature names you will actually meet.
| What it is called in the demo | What it computes | Automated employment decision tool? |
|---|---|---|
| Candidate fit score, match percentage | A ranking of people against a role | Yes, unambiguously |
| Smart ranking, best-match ordering | The same thing with the number hidden | Yes; hiding the score changes nothing |
| Knockout questions, hard filters | A deterministic rule you wrote and can read | Usually no, because there is no model, but it can still create disparate impact |
| Auto-advance to interview | A decision, executed | Yes |
| Talent pool rediscovery, silver medallists | Who gets resurfaced from your own database | Yes; it allocates access to the process |
| Interview scorecard suggestions | A prompt to a human who then scores | Borderline; depends whether reviewers follow it |
| Sentiment or engagement scoring | A classification of an employee | Yes where it informs a consequential decision |
| Attrition or flight risk | A prediction attached to a named employee | Yes where anyone acts on it |
| Headcount and workforce forecasting | A number about roles, not people | No |
| Job description optimisation | Text about a role | No, though ad targeting is separately in Annex III |
Two rows deserve a word.
Knockout questions are a genuine grey area, and the grey runs in your favour on the AEDT question and against you on the discrimination question. A rules-based filter with no model is probably outside the New York City definition, which requires a computational process derived from machine learning, statistical modelling, data analytics or artificial intelligence. It is squarely inside Title VII if the rule screens out a protected group at a disproportionate rate. A "must have five years of continuous employment" filter is not an automated employment decision tool and is still a lawsuit.
Interview scorecard suggestions are the row that will move. The ICO's March 2026 finding was precisely that employers classify these as decision support while using them as decisions. The practical test is empirical rather than definitional: pull 200 reviews and measure how often the human score diverges from the suggestion. If divergence sits at a few percent, you are running automated decision-making with extra steps, and you are better off recording that yourself than having a regulator record it for you.
Does a human approving the output take you out of scope?
It changes which rules apply, not whether rules apply. Human sign-off can move you outside the UK's solely-automated category and outside Colorado's materially-influences trigger where the reviewer genuinely reconsiders. It does nothing for Local Law 144, which turns on substantial assistance rather than on who clicks approve, and nothing at all for disparate impact, where liability attaches to the outcome. The ICO's formulation is the one everybody is converging on: human involvement must be meaningful and active, exercised by someone with the authority, discretion and competence to alter the decision, and not a token gesture or a rubber stamp. We covered the design consequences of that in the hiring law reference and in our guide to candidate screening and where humans still decide.
If you want a second pair of eyes on which of your existing HR automation tools fall on which side of that line, our AI automation practice runs that inventory as a free session. Bring your ATS configuration and your HRIS module list.
Procurement: the vendor's compliance claims become your liability
This is the position we take with clients, and it is commercially inconvenient for us to say it as plainly as we do, because we sell into this market. When you buy HR automation software that ranks people, you are not buying a compliance outcome. You are buying an input to a compliance obligation that remains yours.
The reason is structural rather than adversarial. A vendor bias audit is computed on the vendor's aggregate population, across every customer, every role family and every geography. Your adverse impact ratio depends on your applicant pool, your role mix and your funnel. Those are different numbers computed from different data, and only one of them is the number a regulator or a plaintiff will ask you for. Under Local Law 144 the obligation to have a current audit and to publish the summary sits with the employer using the tool.
So the decisioning half is a procurement exercise with a legal reviewer attached, and the questions are not the ones on a standard security questionnaire.
The due diligence questionnaire, mapped to the obligation behind each question
This is the sheet we hand clients to drop into an RFP. It is organised by obligation rather than by product area, because a question you cannot trace to a named duty is the question you trade away in the second round of negotiation. Every row names the instrument, the jurisdiction and the date it bites, so the same sheet works as the scoping note for your legal reviewer. The fourth column is the one buyers skip: it holds the answer that sounds cooperative, closes the item in the tracker, and leaves the whole exposure with you.
| Obligation, jurisdiction and date | Question to put to the vendor | Answer that satisfies it | Answer that means the liability stays with you |
|---|---|---|---|
| An inventory of every feature that forms a view about a person. Implied by every regime below | List each feature that issues a score, rank, classification or recommendation about a person, with the output type for each | A named feature list, by output type, attached to the contract as a schedule and updated on each release | "The product does not make decisions, it assists the recruiter." That is a marketing position, not an inventory |
| Annual bias audit by an independent auditor. NYC Local Law 144, enforced since 5 July 2023 | Will you give us the underlying audit data for our own tenant, with selection rates and impact ratios by race, ethnicity and sex, in a form we can recompute? | A per-customer applicant flow export, field level, on demand, carrying the categories the rule requires | A platform-wide audit PDF. It describes a population that is not yours, and the duty to hold a current audit is still yours |
| Candidate notice at least 10 business days before use. NYC Local Law 144 | Can the tool generate that notice from the job posting workflow and record the date it was served to each candidate? | Configurable notice text wired to the posting, with a per-candidate served date that cannot be edited afterwards | "You can put that on your careers page." Manual notice is unprovable notice, and the ten days is a date you have to evidence |
| Notice that AI was used, no discriminatory effect, and no ZIP code as a proxy for a protected class. Illinois Human Rights Act as amended by HB 3773, in force 1 January 2026 | Which model inputs are geography, or derived from geography: postcode, commute distance, location radius, catchment area? | The full input feature list including derived features, plus the ability to switch geography-derived features off | "We do not use ZIP code," with no derived-feature list. Distance to office is a postcode wearing a different name |
| Disclosure of the trade name, purpose, and the categories and sources of personal data. Connecticut SB 5, employment provisions applying to technology deployed on or after 1 October 2027 | Give us the trade name, the purpose statement, and the data categories and sources, in text we are free to publish | A maintained disclosure pack, versioned, with any trade-secret redactions identified as redactions | "That is commercially confidential." The statute lets trade secrets be withheld with notice, so a blanket refusal does not match the rule either |
| Plain-language explanation within 30 days of an adverse outcome, and human review on request. Colorado SB 26-189, decisions made on or after 1 January 2027 | At decision time, which contributing factors are retrievable for one named candidate, through what interface, and for how long? | Per-decision factor attribution available through an API for at least as long as the applicable limitation period | "The explanation is in the dashboard for 90 days." The claim arrives long after 90 days |
| Risk assessments and automated decisionmaking duties. California CPPA regulations, risk assessments from 1 January 2026 and ADMT from 1 January 2027, plus the Civil Rights Department's FEHA regulations effective 1 October 2025 with four-year retention | What is retained per decision, for how long, and can we set the retention period ourselves for each data category? | Retention configurable by category to four years and beyond, with an export that survives termination | A fixed global retention policy, usually shorter than the statute, usually presented as a security feature |
| Information to workers and their representatives before a high-risk system is used at work. EU AI Act Article 26(7), applying with the high-risk obligations now dated 2 December 2027 by Regulation (EU) 2026/1744 | Will you supply instructions for use and a model card naming inputs, training data provenance, known limitations and the human oversight measures, in the languages of our EU entities? | A versioned document we can hand to a works council without rewriting it first | A datasheet of performance claims with no limitations section. You cannot consult a workforce on a brochure |
| Human review by a person with the authority to change the outcome. UK Data (Use and Access) Act 2025 section 80, Articles 22A to 22D in force 5 February 2026 | Can the reviewer interface refuse to commit a decision without a stated reason, and does it show the reviewer the contributing factors rather than only the score? | A mandatory reason field, factors rendered on the review screen, and the override recorded against the named reviewer | An approve button. A reviewer shown a score and given a button is the rubber stamp the ICO described in March 2026 |
| Prohibition on inferring emotion in the workplace. EU AI Act Article 5, in force since 2 February 2025 | Does any feature infer emotional or psychological state from face, voice or text, including anything labelled engagement, enthusiasm, confidence or culture fit? | A written no, extended to subprocessors, given as a contractual warranty rather than a sales assurance | "Those features are off by default." A default is a setting, and a setting is not a prohibition |
| Evidence for a claim filed years after the decision. No statute cited here requires it; it is the record that decides cases | What is written to the decision log, is it append-only, and does every entry carry the model version that produced the output? | Model version, input features, output, timestamp, reviewer identity and reviewer reason, immutable and exportable | "Full audit logging," on a platform that updates model configuration in place. The log then describes a model that no longer exists |
| Keeping the audit description true to the model actually running. NYC Local Law 144 and the EU deployer file | How will you notify us of material model changes before deployment, and can we stay on the prior version while we re-audit? | Contractual advance notice, with version pinning for a defined window | "We ship continuous improvements." Your published audit then describes last quarter's model |
| Allocation of discrimination liability between the two of us | Who indemnifies discrimination claims arising from model output, does the indemnity survive termination, and does it sit outside the general liability cap? | A named indemnity, carved out of the cap, surviving termination | Silence, or an indemnity capped at twelve months of fees |
| Storage limitation and erasure. UK and EU GDPR Article 5(1)(e) and Article 17 | Define deletion. Does it reach backups, derived features such as embeddings, and training corpora, and on what timetable for each? | A per-category schedule, a stated backup horizon, and written confirmation of what happens to derived data | "We delete on request." The retention section below sets out why that sentence is incomplete |
| Control over what your applicant data trains. Contractual, in every jurisdiction | Is our applicant or employee data used to train models served to other customers, now or under any future product? | A contractual no, or an opt-in with a tenant-scoped model you can have retrained from your own corpus | "Your data is only used to improve the service." That sentence is how training permission is usually granted |
How to score the answers
Sort every answer into one of three states before the second vendor call, because the states have different owners. Satisfied as shipped means you watched it happen in a tenant carrying your own field names, not in a slide. Fixable in the contract covers the indemnity, the model change notice, the retention periods, the training permission and the exit export: no engineering work, just a redline, cheap before signature and close to unobtainable after it. Structurally unavailable should change the shortlist rather than the contract, because if a platform cannot produce per-tenant applicant flow data, or overwrites model configuration in place on every release, no clause repairs it.
Four shapes of non-answer recur often enough to name: the deflection, which restates that a human is in the loop without saying what the human is shown; the roadmap, which converts a present obligation into a release date; the confidentiality claim, applied to questions the statute expressly makes disclosable; and the appeal to silence, that no other customer has asked. Record the answer verbatim in all four cases.
Which of these belong in the RFP and which belong in the contract?
The inventory, the audit data, the decision logging, the notice mechanics and the emotion-inference question are capability questions, so they go in the RFP and their answers decide the shortlist. Raising them during contracting is late in a literal sense: the vendor already knows they have won, and your only remaining lever is a delay you have spent. The indemnity, the model change notice, the retention periods, the training permission and the exit export allocate risk rather than describe a feature, so they belong in the contract, where they cost a vendor nothing to build and a great deal to concede. The Connecticut disclosure pack and the EU instructions for use sit in both, because they are a capability at RFP stage and a maintenance obligation afterwards, and a vendor who will produce the document once but not keep it current has answered the half that expires. Most HR technology contracts answer none of this, not out of villainy but because until recently nobody asked and the templates never grew the clauses. Vendor due diligence here is a legal exercise wearing an IT jacket.
One practical note from our own engagements. The bias-audit data question is the one that separates vendors fastest. The answer you want is a number you can recompute. The answer you usually get is a PDF.
Employee consultation is a gate before deployment, not an announcement after it
In several European jurisdictions the obligation that derails an HR automation rollout has nothing to do with discrimination law. It is the duty to involve employee representatives before the technology is introduced. Miss it and the remedy is not a fine at year end, it is an order to stop using the system you have already bought and migrated onto.
Germany sets the hardest version. The co-determination right under section 87(1) number 6 of the Works Constitution Act, covering technical equipment capable of monitoring employee conduct or performance, is exercised through a works agreement signed before go-live. Where the two sides cannot agree, either can convene a conciliation committee under section 76 of the same Act, chaired by a neutral, whose award takes the place of agreement. Two provisions added by the Works Council Modernisation Act, in force since 18 June 2021, bear on AI directly. Section 80(3) treats an outside expert as necessary where the works council has to assess the introduction of artificial intelligence, so the employer pays for the council's technical adviser instead of arguing about whether one is warranted. Section 95 was amended so that the rules on selection guidelines apply where the guidelines are produced with AI.
The Netherlands runs a consent model. Article 27 of the Works Councils Act requires the council's prior consent for arrangements covering staff appraisal and for facilities intended to monitor or check attendance, conduct or performance. A decision taken without consent can be declared void at the council's request, and the route around it is a court application for substitute authorisation, which is a proceeding rather than a formality.
France runs a consultation model with a clock. Under Article L.2312-8 of the Code du travail the social and economic committee must be informed and consulted on the introduction of new technologies and on significant changes to working conditions, with a defined window to give its opinion, one month by default and longer where it appoints an expert. Proceeding before the opinion is given is treated as obstruction of the committee, which in France is a criminal offence rather than a civil one.
Two EU layers sit above that. Article 26(7) of the AI Act requires employers deploying a high-risk system to inform workers' representatives and the affected workers before it is put into service at the workplace, and that duty travels with the high-risk obligations, moved to 2 December 2027 by Regulation (EU) 2026/1744. Directive (EU) 2024/2831 on platform work, in force since 1 December 2024 and due for transposition by 2 December 2026, adds information and consultation of workers' representatives on decisions likely to introduce or substantially change automated monitoring and decision-making systems.
The UK has no equivalent general right. It has two weaker hooks: under the Information and Consultation of Employees Regulations 2004 employees can request a formal information and consultation agreement, on a request threshold that dropped from 10% of the workforce to 2%, subject to a minimum of 15 employees, on 6 April 2020; and Article 35(9) of the UK GDPR requires you to seek the views of data subjects or their representatives where appropriate when running a data protection impact assessment, which for workplace monitoring means the workforce or a recognised union.
The effect on a plan is specific. Consultation is a gating milestone rather than a parallel workstream, because the thing being consulted on is the introduction of the system, and a pilot running on real employee data is already the introduction. There is no statutory deadline for concluding a German works agreement, so its duration is a negotiation rather than a date you can commit to. Consult against a document you had to produce anyway: the instructions for use and the model card you should already be demanding from the vendor, translated, are what a council needs to form a view. Asking for those during the RFP rather than the month before go-live is the cheapest schedule risk to take out of a European AI automation rollout.
Integration reality: HRIS, HCM, ATS and payroll
None of the above is enforceable inside your own organisation unless the plumbing supports it, and the plumbing is where most HR automation programmes actually fail.
A typical mid-market stack has an HRIS or HCM as the system of record, an applicant tracking system for hiring, a payroll platform, a time and attendance tool, a learning system, and between two and six point solutions bought by individual teams. Automation sits across all of them. The compliance artefacts you need, meaning the decision log, the applicant flow data, the reviewer reason and the model version, are produced by whichever system happened to make the call, and they are almost never joined up.
Two design requirements follow, and they hold whether you build or buy.
An immutable decision log keyed to model version. Most platforms overwrite model configuration in place on update. If a claim lands in 2030 about a 2026 rejection, the question will be which model version scored that candidate and what the reviewer did about it, and a system that upgraded in place cannot answer. No statute we have cited requires this record. It is the record that decides cases.
Applicant flow data that exports without a data science project. If producing an adverse impact ratio takes a quarter of analyst time, you will produce it once a year under duress rather than quarterly as a control. We build that as a standing export in our AI HR Agent for exactly that reason, and the time-to-hire case study describes what the pipeline looks like when the audit trail is designed in rather than retrofitted. The wider architectural pattern, and where an agent should replace a rules engine rather than sit beside one, is in our piece on enterprise workflow automation with agents.

What the HRIS owns, and what the automation layer is allowed to own
The system of record holds identity, employment status, contract terms, compensation and working time, and it holds them as effective-dated records with a validity period rather than as current values. The automation layer holds events and decisions: the score, the reviewer's reason, the notice served date, the task fired at IT on a Tuesday.
Confusion starts when the automation layer accumulates fields nobody else has. A fit score exists nowhere but the screening tool, and neither does the rejection reason code or the evidence that a candidate was notified ten business days before the tool ran. Those are records in their own right, with an owner and a retention period, and they are precisely what a regulator or a claimant asks for. Treating them as transient workflow state is how an organisation ends up able to produce the outcome and unable to produce the reasoning.
The rule we apply is narrow enough to enforce. The automation layer may own decisions and the evidence supporting them. It may not own identity, employment status, compensation or working time, because those are the fields a statutory record request is aimed at, and a request answered out of a workflow tool is answered late.
Why bidirectional sync creates a conflict nobody scopes
Integration requirements are written as two-way sync between the HRIS and everything else, and the conflict rule is left unstated, which means it defaults to last write wins. That is not a policy. It resolves to whichever system's scheduler ran most recently, an operational accident dressed as a rule.
Two structural problems sit underneath. The first is effective dating: HRIS records carry a validity period, so a promotion entered today effective the first of next month is a future record, and an automation layer storing current state only will round-trip it back as a change effective now. Someone gets paid at the new rate a month early. The second is retroactive correction, where a start date corrected backwards regenerates downstream records that have already produced statutory outputs, and most automation layers have no concept of a period that has closed.
What to specify instead is cheap and unglamorous. Field-level ownership, one writer per field, the reverse direction read-only. A reconciliation job that reports divergence rather than resolving it silently, so a human sees both values and their timestamps. A queue for genuine conflicts instead of an automatic winner. And an idempotency key on every event, so a webhook replayed after a timeout does not apply the same change twice. The same ownership problem appears wherever an agent sits in front of an existing rules engine, and the resolution is the same: decide who owns the field before deciding who writes to it.
Payroll cut-off is the hard edge of every HR automation project
Payroll runs on a calendar. There is a cut-off date, and between cut-off and pay date the file is locked while it is validated, approved and submitted. Anything automated that touches pay has to land before cut-off or it lands in the next period: a new starter's bank details, leave that affects pay, a contractual change, a termination.
Automation that writes continuously into a system with a periodic lock produces a failure that is easy to miss, because the record is right and the payment is wrong. Nothing looks broken in the HRIS. The reversal is constrained too: in the UK a Full Payment Submission must reach HMRC on or before the date of payment under real time information rules, so a correction is a further submission rather than a rewind, and in the US state wage payment law sets when wages are due, so correcting an underpayment after cut-off usually means a chargeable off-cycle run.
So model the cut-off inside the workflow, apply effective-dated changes to the period they belong to rather than the period they were entered in, and give the automation a pre-cut-off freeze window where it stops writing and produces a variance report instead. Termination is the case worth building properly, because two clocks run at once and they are not the same clock. Access revocation is an IT event for the last working day. Final pay is a statutory deadline that varies by jurisdiction: in California, Labor Code section 201 requires wages immediately on involuntary termination, and section 202 allows 72 hours where an employee resigns without notice. An offboarding workflow that treats final pay as one more task in a sequence will eventually miss one of those, and the penalty attaches to the employer rather than to the tool.
What happens when a candidate files a data subject access request?
It gets considerably more interesting once your stack is automated, and this is the scenario most buyers have not rehearsed.
A rejected candidate in the UK or EU can request the personal data you hold about them, and where a decision was automated they can also seek meaningful information about the logic involved and a human review of the outcome. Under the UK's Article 22A to 22D regime, in force since 5 February 2026, the safeguards must be implemented and documented, which means the documentation is itself disclosable evidence of whether you did the work.
Now count what an integrated HR platform holds about one applicant: the application, the parsed fields, the fit score and its inputs, the recruiter's notes, the scheduling history, interview transcripts if you record them, the rejection reason code, and any enrichment data pulled from third-party sources. A data subject access request reaches all of it. Systems that store a score without storing what produced it put you in the worst position available. You must disclose the score, and you cannot explain it.
Two things make this survivable. A retention schedule per data category that actually deletes on time, so the request has a bounded surface. And a decision record structured for disclosure from the start, meaning the score, the top contributing factors, the model version and the human reviewer's stated reason held together as one object rather than scattered across four tables.
Which jurisdiction's rules apply when your HR team sits somewhere else?
Follow the role and the candidate, not the org chart. Local Law 144 applies to a job located in New York City regardless of where the employer sits, so a company in Lahore, Manchester or Austin screening for a New York City role is covered. Colorado's statute follows decisions about Colorado residents. The EU AI Act reaches providers and deployers placing systems on the EU market or whose output is used in the EU. UK data protection follows the candidate's data.
The practical consequence for a multinational is that per-jurisdiction configuration of a hiring workflow is more expensive than it looks and less reliable than it sounds, because someone will eventually post a US role from the UK template. Most organisations hiring across more than three or four jurisdictions end up building to the strictest applicable standard and applying it everywhere. That is usually New York City for audit and notice, the EU for documentation, and the UK for human review.
Retention schedules, and what deletion means once a model has learned
Retention gets set once, globally, by whoever configured the tenant, and then quietly determines whether you can defend a decision four years later. The periods below are minimums drawn from the instrument named in the third column. They disagree with each other, which is the point.
| Record type | Minimum retention | Instrument, jurisdiction and date |
|---|---|---|
| Payroll records | 3 years | Fair Labor Standards Act recordkeeping, 29 CFR 516.5, US |
| Records on which wage computations are based, including time cards and work schedules | 2 years | Fair Labor Standards Act recordkeeping, 29 CFR 516.6, US |
| Form I-9 | 3 years after the date of hire, or 1 year after employment ends, whichever is later | Immigration Reform and Control Act, US |
| Applications and personnel or employment records | 1 year from making the record or from the personnel action, whichever is later, and through final disposition where a charge has been filed | EEOC recordkeeping under Title VII, 29 CFR 1602.14, US |
| Applications and personnel records, California | 4 years | Government Code section 12946, extended from two years to four with effect from 1 January 2022 |
| Data relating to automated decision systems, California | 4 years | Civil Rights Department FEHA regulations, effective 1 October 2025 |
| Compliance documentation for covered decisions, Colorado | 3 years | SB 26-189, applying to decisions made on or after 1 January 2027 |
| Bias audit and published summary, New York City | An audit no more than one year old, with the summary and the distribution date publicly available while the tool is in use | Local Law 144 and the DCWP rules, enforced since 5 July 2023 |
| Working time records | 2 years from the date the record was made | Regulation 9, Working Time Regulations 1998, UK |
| PAYE records | 3 years after the end of the tax year they relate to | HMRC employer requirements, UK |
| Everything else holding personal data | No fixed period. You set one and you justify it | Storage limitation, Article 5(1)(e), UK GDPR and GDPR |
A single global retention setting is wrong in both directions at once. Set it short and you destroy the California and Colorado records you are required to hold. Set it long and you breach storage limitation on everything the statutes do not reach, while widening the surface of every subject access request you will ever answer. The operative period is the longest applicable one for that record type in that jurisdiction, applied per category, which is why retention configurability belongs in the vendor questionnaire rather than in the implementation backlog.
Limitation periods drive these numbers more than the recordkeeping rules do. In Great Britain a discrimination claim must normally reach the employment tribunal within three months less one day of the act complained of, under section 123 of the Equality Act 2010, subject to ACAS early conciliation and the tribunal's discretion to extend where it is just and equitable. In the US a charge must be filed with the EEOC within 180 days, extended to 300 days where a state or local agency enforces a comparable law. Filing is only the start, and what follows runs for years.
What "we delete on request" leaves out
A deletion request lands on four different things, and most vendors have answered for one.
The live row is the easy case: a record with a primary key, and deleting it is a supported operation. Derived data is the first gap, because an embedding of a CV, an aggregate feature computed from an applicant's history and a cached score in a reporting table are each a copy of the personal data in a different shape, and a routine written against the source table will not touch any of them. Our walkthrough of how a screening pipeline turns a CV into a vector sets out where those copies get made. Backups are the third: they roll on their own schedule, so honest deletion means removed from live immediately and gone from backups within the backup horizon, and that horizon is a number which belongs in the contract.
The training corpus is the fourth, and deleting things does not solve it. If a candidate's data sat in a set used to train a model, removing the row does not remove that record's contribution to the weights. Retraining from a corrected corpus does. Techniques for approximately removing the influence of specific records from a trained model are an active research area, not something to accept as a contractual assurance. The European Data Protection Board's Opinion 28/2024 on personal data in AI models, adopted on 17 December 2024, takes the position that a model trained on personal data cannot be assumed to be anonymous and that anonymity must be demonstrated case by case. That puts the burden of proof on the opposite side from where most vendor answers quietly place it.
A complete answer therefore has four parts: the live deletion timescale, the treatment of derived data, the backup horizon, and whether customer data ever enters a training corpus. If it does, deletion has to mean exclusion from the next training run plus a stated retraining cadence, and if the vendor will not state a cadence, deletion means the row and nothing else. The clean contractual position avoids the question: customer data is not used to train models served to other customers, and any tenant-scoped model is retrained from a corpus you can re-derive from your own records.
Which deletion requests must you refuse?
The ones aimed at a record you are legally required to keep. Article 17(3)(b) of the GDPR disapplies the right to erasure where processing is necessary for compliance with a legal obligation, and the same reasoning applies to a US employer holding an I-9, a payroll record, or a personnel record still inside the EEOC retention window. Refusing is not discretionary there, and the refusal has to name the obligation it rests on.
Automation raises the stakes. An erasure job that honours every request on receipt, without checking for a retention or litigation hold, will eventually destroy the record that would have defended the claim. Evaluate the hold before the job runs and log the evaluation. That log is the only evidence that a gap in your records was policy rather than convenience.
Background checks, right to work and I-9
Worth separating, because it is the process buyers most often misfile.
Ordering a background check, chasing it and tracking its return is administrative. Verifying a right to work document against a fixed rule set is administrative. Storing the result with the correct retention period is administrative. In the US, Form I-9 must be retained for three years after the date of hire or one year after employment ends, whichever is later, and electronic storage is permitted where the system meets the security, indexing, accessibility and audit trail requirements.
Automatically adjudicating the result is not administrative. The moment software applies a pass or fail rule to a criminal record and closes an application without a human looking, you have an adverse action with a statutory notice sequence attached under the Fair Credit Reporting Act, and fair-chance ordinances in a growing list of US jurisdictions govern when in the process you are even allowed to ask. Washington State's Fair Chance Act amendments under EHB 1747, effective 1 July 2026 for employers with 15 or more employees and 1 January 2027 for smaller ones, are the most recent example of that direction of travel.
So automate the chasing. Do not automate the judgement. This is the cheapest place in the whole stack to get the split right, because the manual work is almost entirely in the chasing and almost none of it is in the judgement.
Employee engagement strategies, and the part automation cannot do
Most HR automation platforms sell an engagement module: pulse surveys on a schedule, sentiment scoring on free-text answers, a dashboard with a score per team, an alert when a score drops. What that automates is measurement. Employee engagement strategies succeed or fail on the conditions people are responding to, which are workload, manager quality, pay, progression and whether anything happened the last time they were asked. A survey tool changes none of those. It changes how fast you hear about them.
Getting that distinction wrong has a cost. A fortnightly pulse survey that produces no visible action is worse than no survey, because the next one is answered by people who watched the last one produce nothing. Automation makes the cadence cheap, which is what makes it easy to run past the point where the organisation can act on the answers. If the binding constraint is a manager's capacity to respond, a faster survey loop is a faster way to collect complaints nobody will answer.
Two parts of an engagement stack sit on the regulated side of the line drawn at the top of this piece, and buyers rarely file them there.
Sentiment scoring of free-text answers classifies an employee. Where that classification informs anything consequential, and that includes performance ratings, promotion shortlists, allocation of work and retention action, it is the same category of processing as a screening score and carries the same duties. California's automated decisionmaking technology regulations name hiring, compensation, allocation of work, promotion and demotion as significant decisions from 1 January 2027. Colorado's SB 26-189 attaches notice, a plain-language explanation and human review to consequential employment decisions made on or after that date.
Anything that infers an emotional or psychological state is a harder stop. Article 5 of the EU AI Act prohibits emotion inference in the workplace and has done since 2 February 2025, and no deferral is available, because Regulation (EU) 2026/1744 moved the high-risk obligations to 2 December 2027 and left the prohibitions where they were. Directive (EU) 2024/2831 separately prohibits platforms from processing aimed at automatically monitoring a worker's emotional or psychological state. Feature naming in this corner of the market is unhelpfully cheerful: enthusiasm, confidence, wellbeing signal, culture fit, burnout risk. Ask in writing what is being inferred, and from what input, rather than accepting what the tab is called.
One more check sits outside the decision question entirely. A survey described as anonymous that lets a manager filter down to a team of four is not anonymous, and under UK and EU data protection that is personal data being processed for a purpose respondents were told it was not. Set a minimum reporting threshold in the tool, confirm that free-text answers are not surfaced verbatim to line managers where the writing identifies the writer, and record the decision in the data protection impact assessment you need anyway for workplace monitoring.
What automation genuinely does well here is narrow. It removes the scheduling and the chasing, holds the question set stable so a change in a score means a change in the thing rather than a change in the wording, and gets results to a manager while the period they describe is still recent. Those are worth having, on one condition: someone owns the response. The employee engagement strategies that survive automation are the ones where the loop closes in public, covering what was asked, what came back, what changed, and what will not change and why.
Workforce planning is a separate automation target with a worse data problem
Workforce planning sits apart from everything else in this piece. The transactional processes automate a task someone is already doing by hand. This one automates an analysis most organisations are not doing at all: headcount forecasting against a financial plan, skills gap analysis against a role architecture, internal mobility and succession coverage, scenario modelling for a reorganisation or a site closure.
On the compliance question it starts on the safe side. A forecast about roles, budget and capacity is a statement about positions rather than a view about a named person, so it is not an automated employment decision tool in any of the regimes above. It crosses the line at one identifiable moment, when the output stops being a headcount and becomes a list of people. Selection for redundancy, succession shortlists and flight-risk scores attached to named employees are decisions about individuals, and they pick up the notice, explanation and human review duties wherever the decision is consequential. In Germany the crossing is written into statute: section 95 of the Works Constitution Act, as amended by the Works Council Modernisation Act in force since 18 June 2021, applies the co-determination rules on selection guidelines where those guidelines are produced with artificial intelligence.
The consultation clocks are separate again, and they are long. In Great Britain, section 188 of the Trade Union and Labour Relations (Consolidation) Act 1992 requires collective consultation to begin at least 30 days before the first dismissal where 20 to 99 redundancies are proposed at one establishment within 90 days, and at least 45 days where 100 or more are proposed. In the US, the Worker Adjustment and Retraining Notification Act requires 60 calendar days' written notice of a plant closing or mass layoff from employers with 100 or more employees, and several states run their own versions with lower thresholds. A scenario model that produces a plan with a start date inside those windows has produced a plan you cannot execute.
Why workforce planning output is less reliable than the dashboard suggests
The quality of the answer is bounded by position data, and position data is the worst-maintained data in the HR stack.
Four problems recur. Position records and person records drift apart, because a vacancy nobody closed in the HRIS keeps reporting as an open position long after the budget moved. Job architecture is inconsistent across entities after any acquisition, so a skills gap computed across the group compares job titles rather than roles. Contingent workers, contractors and agency staff usually sit in a procurement or vendor management system rather than the HRIS, which means capacity forecasts run on a partial population. And effective dating gets flattened on export, so a promotion effective next month is counted either now or not at all, depending on how the extract was written.
None of that is fixable inside the planning tool, which is the part the category is quiet about. A model fitted to inconsistent historical position data still produces a confident forecast, and the confidence is a property of the model rather than of the data underneath it. The order that works is unglamorous: fix position data ownership, agree one job architecture, bring contingent labour into the same view, then model. Reverse it and the first year of the programme goes on arguing about whose headcount number is correct.
Where automation earns its place is the refresh. A scenario that takes an analyst three weeks to rebuild is a scenario nobody re-runs when the assumptions move, and the plan ages into a document. The argument we make for standing exports in our HR automation agent applies to planning too: the number worth having is the one you can recompute on demand, because a forecast that can be rebuilt in an afternoon gets challenged, and being challenged is what makes it useful.
What we build, and what we will not wire up
We build HR automation for clients on one rule we do not negotiate: every score must be reconstructable. In practice that means an immutable decision log keyed to model version, applicant flow data that exports to impact ratios without a project, candidate notification generated from the job posting workflow so it cannot be skipped, and a reviewer interface that will not let a decision commit without a stated reason attached to it. The reviewer screen in our AI HR Agent enforces the last of those, and our sourcing product AI Talent Scout is built on the same separation: it may find, summarise and schedule, and it may not reject.
Three things we tell clients not to automate, and only one of them is because of a rule.
Do not automate the final rejection after a candidate has sat a live interview. No statute forbids it. It converts a routine adverse outcome into a grievance, and grievances become complaints.
Do not automate accommodation and adjustment requests under the ADA or the Equality Act 2010. The obligation is an individualised interactive process, and a model cannot conduct one.
Do not automate emotion or affect inference anywhere, at any stage. It is prohibited in EU workplaces under Article 5 of the AI Act and has been since 2 February 2025, the platform work directive bans it for platform workers from transposition, and the scientific basis for inferring an internal state from a face or a voice is contested enough that we would decline the build in a jurisdiction that permitted it.
The wider design question, which agent state transitions you allow and which you do not, is the same one we work through in any agentic AI development engagement. In hiring the answer is unusually simple. An agent may gather, summarise, schedule and rank, and it may not issue a rejection.
One last note on market context, dated because it matters. SHRM's state of AI in HR research, published 3 April 2026 and drawn from more than 1,900 HR professionals, put AI adoption in HR functions at 39%, concentrated in recruiting at 27%, HR technology at 21% and learning and development at 17%, and found that 56% of HR functions do not formally measure the success of their AI investments, with only 16% using ROI as a metric. Read those two findings together. The function is adopting fastest in precisely the area that carries the regulatory obligations, while more than half of it measures nothing. The measurement gap and the compliance gap are the same gap, because the evidence that proves a tool works is the evidence that proves it did not discriminate.
If you are evaluating HR automation software now and you want the inventory before the shortlist, our AI automation team will map which of your existing features are automated employment decision tools, which are Annex III systems, and which are neither. That inventory is the first artefact of any HR compliance programme that survives contact with a regulator, and in three years of doing this we have been handed a complete one exactly once. Book a session and bring your vendor list.


