Governed AI

When “Approval” Isn’t Oversight: What the ICO’s Recruitment Work Means for AI Governance

The ICO’s recent recruitment findings draw a clear line between a person being present in a process and genuine human oversight. For any business using AI to shape a decision about a person, that distinction matters.

Phil LlewellynHuman Heartbeat AIUpdated 6 min read
Governed AIrecruitment automationhuman oversightHuman Decision Gate
Original HHAI editorial image showing a manager pausing above a laptop approval control while a colleague reviews a candidate assessment and makes notes, representing informed human judgement rather than automatic acceptance.
A click is not a decision. Original HHAI editorial image; no regulator branding or endorsement implied.

The hiring manager clicks approve.

It is Tuesday morning. An AI-assisted recruitment system has identified five candidates for a customer-service role. A manager looks at the output and accepts it. The process now has a human in it.

But did the person make a decision?

That is the question underneath the ICO’s recent work on automated decision-making in recruitment. A human click does not automatically turn an automated outcome into accountable human judgement. The review has to be real: informed, capable of challenge and able to make a difference.

The token gesture problem

In March 2026, the ICO published findings from voluntary engagement with more than 30 employers between March 2025 and January 2026. This was not an audit or investigation. It was a focused look at how automation is being used in recruitment, from CV filtering to assessments and other hiring decisions.[1]

The important finding was not that employers use automation. Many do, and it can help handle large volumes of applications consistently and quickly. The issue was whether meaningful human involvement was genuinely present when an automated process affected someone.

The ICO said that many employers using recruitment automation were likely to be relying on solely automated decisions without meaningful human involvement. It also said that, where meaningful human involvement is used at a hiring stage, it must be applied consistently to all candidates.[1]

That exposes the difference between approval and oversight.

Approval confirms what is already in front of someone. Oversight asks whether the outcome is sound, fair and appropriate in the circumstances — and gives the reviewer the authority to challenge it.

HHAI editorial interpretation

Oversight spectrum

  1. Token confirmationA person confirms an output without a real opportunity to question it.
  2. Inconsistent human involvementReview is present for some people or stages, but not applied as a dependable safeguard.
  3. Meaningful human involvementA reviewer has enough knowledge, time and authority to challenge the outcome.
  4. Documented accountable reviewChallenge, override and escalation are evidenced so the safeguard can be examined.
Oversight spectrum: An HHAI editorial interpretation of the difference between a person appearing in a process and a meaningful, accountable human control. It is not an ICO framework.

Why this moment matters

The ICO’s work is not a distant policy discussion. It is a practical signal to organisations already using, buying or designing automated decision-making systems.

On 31 March 2026, the ICO also opened a consultation on draft guidance about automated decision-making and profiling following the Data (Use and Access) Act 2025. The consultation closed on 29 May 2026.[3]

The relevant standard is not whether a business can point to a person somewhere in the workflow. It is whether its process protects people’s rights and whether the business can explain how the control works.

The ICO has already set out practical expectations for organisations using automated decision-making in recruitment. These include transparent communication with candidates, consistent human involvement, proactive monitoring for bias, and clear routes for people to challenge decisions or request human review.[4]

That does not mean every AI-assisted process is the same. The legal position depends on what the system does, the effect it has on people and the wider processing context. But it does mean that a business cannot treat “a human looked at it” as the end of the governance conversation.

HHAI editorial interpretation

What the ICO’s 2026 work did — and did not — establish

  1. Voluntary engagementMore than 30 employers contributed evidence to the ICO’s recruitment work.
  2. Recruitment RewiredThe ICO published its recruitment findings and opened consultation on draft ADM guidance.
  3. Consultation closesThe consultation period on the draft guidance closed.
  4. Final guidance / Code timingThis diagram does not state a final publication or Code timetable.
What the ICO’s 2026 work did — and did not — establish: This bounded timeline identifies the published recruitment work and consultation dates only. It does not state a final guidance or Code timetable.

What genuine oversight looks like

A better question is not, “Do we have a human in the loop?”

It is, “What can that person actually do — and what evidence do we have that the control works?”

For a business using AI in a decision process, five practical questions follow.

1. Can the reviewer genuinely challenge the outcome?

A reviewer needs sufficient knowledge, authority and independence to question an AI-supported result. The ICO’s human-review toolkit recommends that organisations maintain a record of overrides and the reasons for them.[2]

2. Is human involvement applied consistently?

If human involvement is meant to safeguard a stage of a process, it cannot be available to some people and absent for others without a defensible reason. The ICO’s recruitment findings make consistency a central issue.[1]

3. Can the affected person ask for help or challenge the decision?

For solely automated decisions with legal or similarly significant effects, the ICO’s current guidance says people must have simple ways to request human intervention or challenge a decision. Organisations should identify staff who are authorised to carry out reviews and change decisions.[5]

4. Is the process monitored for bias, errors and drift?

The ICO expects organisations using recruitment automation to monitor for bias proactively. Its human-review toolkit also calls for documented testing methodology, manageable reviewer caseloads, training and escalation where a system’s reliability is in question.[2] [4]

5. Is there durable evidence of how the safeguard operated?

A control is difficult to trust if nobody can show how it was used. The ICO guidance points to documented review processes, override logs, testing records and reporting. For high-risk solely automated decisions, its individual-rights guidance also identifies a Data Protection Impact Assessment as a required safeguard.[2] [5]

HHAI editorial interpretation

Five practical questions for genuine oversight

  1. 01Can a reviewer challenge the outcome?
  2. 02Is human involvement applied consistently?
  3. 03Can people seek recourse?
  4. 04Is bias monitored?
  5. 05Is there durable evidence?
Five practical questions for genuine oversight: Questions for examining an AI-supported process, not legal requirements or a compliance checklist.

The governance question

The old question was often: What can we get away with?

The better question is: What must be true for this decision to remain fair, understandable and accountable to the person affected by it?

That is the move from compliance theatre to governance.

For one organisation, the answer may involve redesigning a recruitment workflow. For another, it may mean clarifying review authority, making a recourse route visible, creating a proper record of overrides and checking whether the human control is applied consistently. The point is not to add paperwork after the fact. It is to build a decision process that can be understood and challenged before harm is normalised.

AI can advise. A person still has to decide.

What to examine in your own process

If AI helps your organisation rank, recommend, filter, route, assess or decide something about a real person, examine the point where that output becomes action.

Can the responsible person see enough to exercise judgement? Can they disagree? Is the process consistent? Can the affected person seek review? Can you evidence what happened?

Those are not abstract governance questions. They are the operating questions that determine whether an AI-assisted process remains accountable when it matters.

HHAI editorial interpretation

From output to answerable decision

  1. SeeCan the responsible person see enough to exercise judgement?
  2. DisagreeCan they disagree?
  3. Apply consistentlyIs the process consistent?
  4. Seek reviewCan the affected person seek review?
  5. EvidenceCan you evidence what happened?
From output to answerable decision: An HHAI editorial interpretation of the operating questions a business can examine where an AI output becomes action.

This article is HHAI editorial commentary based on the sources below. It is not legal advice. The applicable legal position depends on the system, context and use of personal data.

Sources and further reading

  1. ICO — Recruitment rewired: fair and responsible use of automation in recruitment
  2. ICO — Human review toolkit
  3. ICO — Consultation on draft automated decision-making guidance
  4. ICO — Automated decisions can streamline the hiring process, with the right safeguards in place
  5. ICO — Rights related to automated decision-making, including profiling

Share this article

← Back to Articles

Choose your next useful place

Take the idea somewhere useful.

Continue through established public resources. These links do not add you to a list or start an automated journey.

Read Founder NotesHear the Founder’s perspective in full.
Go there
See today’s AI evidenceExplore the approved Breaking Stories archive.
Go there
Explore the ecosystemReturn to the wider map of routes.
Go there