Can AI Legally Reject Job Applicants Without a Human?
Sometimes—but legality depends on where you hire and how the decision is made. Using AI to organize applications is not the same as letting it reject candidates automatically. Some jurisdictions restrict the decision itself; others focus on discrimination, transparency, audits, and opportunities to challenge the outcome.
For your hiring workflow, the crucial question is not “Do we use AI?” It is “Who actually decides?”
The Boundary: Assistance Versus Automated Rejection
A solely automated decision is one made without meaningful human involvement. Rejecting a candidate can have a sufficiently significant effect to trigger special data-protection rules.
Examples make the distinction clearer:
- AI-assisted screening: A recruiter considers an AI ranking alongside the application and independently decides whether to proceed.
- Automated rejection: A score below a threshold automatically triggers a rejection email.
- Rubber-stamp approval: A recruiter clicks “approve” without substantively evaluating the recommendation. This may still count as solely automated.
Human involvement must change the decision-making process—not merely add a click.
How the Rules Differ
| Jurisdiction | Position on AI-only rejection | What you need to check |
|---|---|---|
| European Union | Generally restricted under GDPR Article 22 for decisions producing legal or similarly significant effects. GDPR Recital 71 expressly mentions recruitment without human intervention. | Whether a valid exception applies, such as contractual necessity, authorization by law, or explicit consent—and which safeguards are required. |
| United Kingdom | The Data (Use and Access) Act 2025 reforms permit significant automated decisions more broadly, subject to safeguards. Special-category data receives tighter protection. | Commencement and applicable provisions, candidate information, challenge mechanisms, and access to human intervention. |
| United States | No general federal requirement that a human personally reject every applicant. | Employment-discrimination law, disability accommodations, and additional state or local requirements. |
| Brazil | Not categorically prohibited. The LGPD provides rights to request review of solely automated decisions and information about decision criteria. | The statute does not expressly require every review to be performed by a human. |
| Australia | No general prohibition under the cited privacy framework. | Privacy and discrimination duties; additional automated-decision privacy-policy transparency obligations begin December 10, 2026. |
| Canada | Depends on province, sector, and whether the employer is public or private. | Applicable privacy and employment rules. Regulators’ human-oversight recommendations are not a universal statutory ban. |
Two Important Qualifications
EU requirements overlap. GDPR’s automated-decision restrictions already apply. Separately, recruitment AI is generally classified as high-risk under the EU AI Act, with human-oversight requirements as the relevant provisions become applicable. Check the operative implementation timetable rather than treating future AI Act obligations as a substitute for GDPR compliance.
US permission is not immunity. New York City requires qualifying automated employment decision tools to undergo a recent bias audit, publish audit information, and provide candidate notices. Those requirements are not a blanket ban on automated rejection—and passing an audit does not eliminate discrimination liability.
Build a Defensible Workflow
Before enabling automatic rejection:
- Map applicable jurisdictions: consider the job, candidate, employer, and processing arrangements.
- Identify the actual decision point: screening out applicants is consequential even if later hiring stages involve people.
- Validate the criteria: examine job relevance, discriminatory effects, and accessibility.
- Provide required notices and challenge routes.
- Make human review substantive: reviewers need relevant information, authority to override, and time to assess the case.
Bottom line: AI-only rejection is not universally illegal. But adding nominal human approval is not a reliable compliance strategy either.