Tag: automated decision-making

  • The Human Review Illusion

    The Human Review Illusion


    In brief: Putting a person at the end of an automated process does not, on its own, meet the legal requirement for human involvement. The ICO has said the review must be meaningful: it happens before the decision takes effect, it is done by someone trained on that specific system, and that person has the time and authority to overrule it. The ICO has already written to 16 employers whose recruitment tools fell short. The same standard applies wherever automated systems make significant decisions about people, and a human review clause in a policy is no evidence that the review happens.

    Picture a routine hiring process. A candidate applies for a role. An automated system scores, ranks and filters their CV. A hiring manager opens the shortlist, scans the names and scores, and moves on. The process has been followed, and a human was involved.

    But the human’s involvement was not meaningful, and that distinction now matters in law.

    This is the human review illusion: the belief that a person at the end of an automated process satisfies the requirement for human oversight. The UK’s data protection regulator has now said explicitly that it does not.


    What the ICO found

    On 31 March 2026, the Information Commissioner’s Office published a report and draft guidance on the use of automated decision-making in recruitment, drawing on evidence from more than 30 employers across sectors.

    Many employers did not recognise that they were carrying out automated decision-making at all. Tools that screen CVs, score candidates, run behavioural assessments and rank applicants were in use without the organisations deploying them realising that these processes carried specific legal obligations under UK data protection law.

    The problem was one of visibility as much as knowledge of the rules. Tools were deployed and significant decisions about people were made, in many cases, it seems likely, without boards or senior leaders knowing what they had authorised or that it needed specific safeguards to be lawful.

    Where human review processes did exist, the ICO found they often lacked the detail the law requires. Data protection impact assessments were inadequate, candidates were not told enough, and human involvement was often inconsistent and tokenistic.


    What meaningful human involvement requires

    The ICO’s draft guidance is specific on this point, which matters because the gap between common practice and the legal requirement is wide.

    Meaningful human involvement has to happen before a decision is applied to someone. A retrospective check, or a sign-off on an outcome the system has already settled, does not qualify.

    The reviewer must be trained and qualified to understand the system’s logic, outputs, limitations and risks. That means training on the specific system in use, over and above general competence. Someone with excellent judgement about candidates who does not know how the scoring algorithm weights particular variables, what data it was trained on, or where it is known to fail, does not meet the standard, however senior or experienced they are.

    Ad hoc spot checks, monthly dip-sampling, and a reviewer who approves outputs without the knowledge to question them all fall short.

    The ICO also wrote to 16 organisations it believed were using automated decision-making in ways that did not meet these standards. Those organisations have since committed to acting on its recommendations. The regulator is already intervening.


    Why a policy document cannot fix this

    Most organisations that use AI tools in recruitment also have a policy governing their use. Many include a human review clause, and believe this meets the requirement.

    It does not, and the reason explains what governance assurance is for.

    A policy describes what should happen. A structural control determines what does happen. Accountability failures occur in the distance between the two.

    Complying with the ICO’s human review requirement needs five things. The reviewer has had training on that specific system. The training is documented, current and proportionate to the system’s risk. The review happens before the decision takes effect. The reviewer has the time, information and authority to override the output. And all of this can be shown with evidence if the organisation is asked to account for its decisions.

    A policy saying that “all automated decisions will be reviewed by a qualified human before being applied” makes none of that happen. It states an intention, and the gap between that intention and what actually happens is where the ICO will look and where liability sits.


    Where the rules stand now

    The ICO’s consultation on its draft guidance closed on 29 May 2026. Final guidance has not yet been published. Waiting for it before acting would still be a mistake, for three reasons.

    First, the legal obligations exist independently of the guidance. The Data (Use and Access) Act 2025 reformed the automated decision-making framework, and the ICO confirms that all of its data protection provisions were in force by June 2026. The guidance explains expectations that the law already sets.

    Second, the standard is about to harden. Regulations made in April 2026 require the Information Commissioner to prepare a statutory code of practice on AI and automated decision-making. Courts must take a statutory code into account, and the ICO must have regard to it when deciding on enforcement. Legal commentators expect the code to take effect in 2027.

    Third, adoption is growing. According to the ISE Student Recruitment Survey 2025, 70% of employers expect to increase their use of automation in recruitment over the next five years. Organisations that wait will be building governance under regulatory scrutiny, which costs more and leaves them more exposed.

    The question for boards is whether they can show that the organisation’s human review policy matches what actually happens, and that what happens meets the standard the ICO has set out.

    Answering it takes assurance: an independent check that the controls work as intended, as well as existing on paper.

    Questions for the board

    • Do we know every point in the organisation where an automated system makes, or materially shapes, a significant decision about a person?
    • For each one, who reviews the decision before it takes effect, and what training have they had on that specific system?
    • Do reviewers have the time and the authority to overrule the system, and how often do they?
    • Could we show the ICO evidence of all this next week, rather than a policy that says it should happen?

    Beyond recruitment

    The ICO’s guidance focuses on recruitment, but the human review illusion reaches well beyond it.

    Automated systems make or materially influence decisions about credit, insurance premiums, benefits eligibility and access to services across regulated industries every day. The same gap between a documented review process and meaningful human oversight exists in each of those settings, and the same legal obligations apply wherever automated means are used to make decisions with significant effects on people.

    Recruitment is where the regulator has acted first and most visibly. It is unlikely to be the last area it examines.


    Read alongside AI Is Not Exempt, which looks at how public procurement could make evidence of AI governance a condition of winning contracts.

    This article was researched and drafted with the assistance of AI tools. All claims have been verified, all sources checked, and editorial judgement exercised throughout by the author.

    Updated 23 September 2026: the ICO consultation has closed (29 May 2026); the article now reflects that all Data (Use and Access) Act data protection provisions are in force and that regulations made in April 2026 require a statutory ICO code on AI and automated decision-making. Questions for the board added.