The employer liability point applies in the US as well: technology does not transfer employer liability. If an AI tool produces discriminatory screening outcomes, the employer who deployed it is liable under existing employment discrimination law.
The 6-Question Vendor Evaluation Checklist
This is the section most directly matching what searchers landing on this article are actually looking for. For each vendor you evaluate, get written answers to these six questions:
Question 1: Can you provide local explainability for individual decisions?
The vendor must be able to explain why a specific candidate received a specific score or outcome — not just how the model works in general. Ask for a live demonstration using a test candidate profile. Red flag: they can only show feature importance rankings or global model explanations.
Question 2: Do you provide documentation compatible with EU AI Act Article 11 technical requirements?
This is a specific document, not a general data sheet. It should cover training data sources, model architecture, validation methodology, accuracy metrics disaggregated by demographic group, and known limitations. Red flag: they offer a "compliance summary" rather than technical documentation at the level of detail Article 11 requires.
Question 3: Have you completed an independent bias audit? For which jurisdictions?
NYC Local Law 144 requires an independent bias audit — not self-assessed. Ask for the audit report, the auditor's name and methodology, and the date of the most recent audit. Red flag: bias testing is described as internal, or the last audit was more than 12 months ago.
Question 4: What is your data handling architecture — does candidate data reach your model before pseudonymization?
If your vendor's model processes raw candidate data including names, addresses, and demographic indicators, that creates GDPR exposure at the point of processing — regardless of the vendor's own compliance status. Red flag: the vendor cannot confirm where in the pipeline pseudonymization or anonymization occurs.
Question 5: What human oversight mechanism do you provide, and how is it implemented?
EU AI Act Article 14 requires a physical halt/override mechanism assigned to a named person with defined authority. "HR reviews all AI recommendations" is a process statement, not an oversight mechanism. Red flag: human oversight is described as a policy or process, not a built-in system control.
Question 6: Who is liable when a candidate challenges an AI-influenced decision — and what evidence can you produce?
Ask the vendor to walk you through the evidence chain they can provide if a candidate files a discrimination complaint or GDPR Article 22 challenge against a specific hiring decision. Red flag: the vendor refers you to their legal team rather than demonstrating an audit trail.
The Data Privacy Layer — What Most HR Teams Miss
Most explainability discussions focus on the model's output transparency. The compliance exposure most HR teams haven't mapped is at the input level: what data is the model seeing, in what form, and where is it processed?
The specific risk: an HR AI that processes candidate CVs, cover letters, and application data is processing personal data — and in many cases special category data (age, national origin, disability status inferable from employment gaps). Under GDPR, this processing requires a lawful basis and data minimization. Under the EU AI Act, Article 10 requires that training and validation data be relevant, representative, and free of errors.
The practical architecture that addresses both: A pseudonymization layer between your applicant tracking system and the AI vendor's model strips personal identifiers before the data reaches the model. The AI sees: employment history, skills, experience duration, and role-relevant qualifications — not name, address, age, or national origin. This:
- Reduces GDPR processing risk (model processes pseudonymized data)
- Reduces AI Act Art. 10 bias risk (demographic identifiers not available to the model)
- Strengthens your position in any candidate challenge (the model demonstrably could not have used protected characteristics)
- Enables you to satisfy Art. 9 GDPR if special category data was inferable from the CV
Frequently Asked Questions