No items found.

AI interviews with candidates: what EU employers can do

By Jürgen Ulbrich

AI interviews with candidates are not banned in the EU. What is not acceptable is treating an AI score as the final hiring decision without a lawful basis, clear notice and meaningful human review. The legal answer depends on what the system actually does with candidate data, not on whether the product calls itself an interview assistant, a voice agent or a screening tool.

This article reflects the EU position as of 20 August 2026. It is a practical framework, not legal advice for a specific hiring workflow. National employment rules still matter, and an employer recruiting across borders should assess the countries, data transfers and local worker-representation rules involved.

What counts as an AI interview?

An AI interview is a candidate interaction in which software asks questions, captures answers or evaluates them. The system may transcribe a call, summarise answers, match evidence against role criteria, produce a recommendation or generate a ranking for the recruiting team.

The legal risk changes with that design. A tool that turns a conversation into notes is different from a tool that scores motivation, filters people out or sends a recruiter only the highest-ranked profiles. The more directly the output controls access to the next stage, the more carefully the employer must assess GDPR, discrimination and AI Act obligations.

For a broader view of the use cases, see the AI interviews and voice recruiting hub. The crucial distinction is simple: AI can support an interview process, but the employer remains accountable for how candidates are treated and selected.

Start with GDPR: purpose, necessity and a legal basis

A lawful AI interview needs a purpose-specific legal basis before data are collected. For ordinary application data, Article 6(1)(b) GDPR may be relevant where processing is necessary to take steps at the candidate’s request before entering into an employment contract. That does not automatically make every optional or expansive analysis necessary.

Article 6(1)(f), legitimate interests, is not a blanket permission either. The employer must identify a legitimate interest, show that the processing is necessary for it and balance that interest against the candidate’s rights and freedoms. Recording speech, inferring personal characteristics, building a profile or creating a rejection score all make that assessment more demanding. The legal test and the right to object are set out in the official GDPR text on EUR-Lex.

Consent is not automatically the safer route. In a hiring process, consent must be freely given, specific, informed and as easy to withdraw as to give. If an employer relies on consent for an AI interview, the practical safeguard is a genuinely equivalent non-AI route with no negative consequence for declining. A required checkbox attached to the application is unlikely to demonstrate real choice on its own.

Interview design should also avoid collecting special-category data, such as health information, religion or trade-union membership. An open-ended conversational system can draw in information that a fixed application form would never request. If special-category data are processed, Article 9 GDPR adds a separate and narrow condition; ordinary Article 6 reasoning is not enough.

What candidates need to know before the interview starts

Transparency is not satisfied by a label saying AI-powered. Under Article 13 GDPR, information given when data are collected must cover, among other things, the controller, purpose, legal basis, recipients, retention period or criteria, candidate rights and, where relevant, international transfers and safeguards.

In a candidate-facing notice, explain the process in the order a person needs it: that AI is involved; whether audio is recorded; whether answers are transcribed, summarised, ranked or scored; which people receive the output; how long the data are retained; whether a human makes the final assessment; and how to exercise access, correction, objection or complaint rights. Put the notice before the interview, in plain language, not behind a generic privacy-page link.

If the workflow includes solely automated decision-making covered by Article 22 GDPR, the notice must also provide meaningful information about the logic involved, the significance of the processing and its expected consequences. The aim is not to disclose a trade secret or source code. It is to allow a candidate to understand how an automated process affects them and to challenge it where necessary.

Article 22: when an AI score becomes an automated decision

Article 22 GDPR protects people from a decision based solely on automated processing, including profiling, where it produces legal effects or similarly significant effects. The GDPR’s recitals expressly identify an online recruitment process without human intervention as an example. A decision to reject a candidate or stop considering them can therefore be highly significant.

An AI recommendation is not automatically an Article 22 decision. A recruiter may use a transcript or structured summary as one input in a broader assessment. But a person who merely clicks approve on an AI shortlist does not necessarily make the decision genuinely human. The reviewer should have the authority, time and relevant underlying information to disagree with the system.

Where Article 22 applies, the available exceptions are limited: necessity for a contract, an authorising EU or Member State law, or the candidate’s explicit consent. For the contract and consent exceptions, Article 22 requires safeguards including human intervention, the ability to express a viewpoint and the ability to contest the decision. These rights are in the official Article 22 GDPR text.

A useful operating rule is therefore to prohibit automated rejection based on an interview score alone. Require recruiters to record their own assessment against job-related criteria and to document when they overturn or rely on an AI suggestion. That is not merely paperwork: it exposes weak criteria, gives candidates a route to correction and creates evidence that human oversight is real.

Why candidate-evaluation AI is high risk under the EU AI Act

The EU AI Act treats AI intended for recruitment or selection of natural persons as a high-risk use case. Annex III specifically includes analysing and filtering applications and evaluating candidates. A voice or chat interview system that evaluates candidate suitability should therefore be assessed as high risk from its intended purpose, even if it is presented as an efficiency tool.

There is a narrow exception for some Annex III systems that do not pose a significant risk, but it is not a marketing label and systems that perform profiling cannot rely on it. Classification should be assessed and documented before launch. The relevant categories are in Article 6 and Annex III of the EU AI Act on EUR-Lex.

For stand-alone Annex III high-risk systems, the high-risk obligations apply from 2 December 2027. That date follows the amendment that entered into force on 27 July 2026, Regulation (EU) 2026/1744. The later date does not pause GDPR, employment law or non-discrimination law: those requirements apply now.

The AI Act separates provider and deployer responsibilities. Providers must establish measures such as risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity, then carry out the applicable conformity work. An employer that develops an in-house system or makes a substantial change under its own name may take on provider responsibilities.

Employers deploying the system must use it in accordance with instructions, allocate meaningful human oversight, ensure input data under their control are relevant, monitor the system and handle available logs. A data protection impact assessment is especially likely to be needed where a system systematically evaluates personal aspects and drives significant employment decisions. Selection criteria must also be scrutinised under applicable equality law, regardless of the AI Act timetable.

Bring worker representation in before procurement, not after launch

Works council requirements are national rather than EU-wide, but they are a material part of a German implementation. Under section 95 of the German Works Constitution Act, selection guidelines for hiring require works-council agreement; section 95(2a) expressly confirms that this applies where AI is used in setting up those guidelines. The official German text of section 95 BetrVG is a useful starting point.

Section 87(1) no. 6 BetrVG is particularly relevant where a technical system can monitor the conduct or performance of employees, for example if the platform also assesses recruiters, interviewers or existing staff. The exact participation right for a candidate-only flow depends on the configuration, existing agreements and the workplace context. That is a reason to involve the works council early, not to assume the issue disappears because applicants are not yet employees.

Share more than a vendor demo. Give representatives the purpose, question framework, scoring criteria, user roles, access rights, retention and deletion rules, data-transfer information, change-management process and the proposed human-override procedure. The official text of section 87 BetrVG covers technical facilities capable of monitoring employee conduct or performance.

A pre-launch checklist for AI candidate interviews

The best practical test is whether the process owner can explain, in ordinary language, why this AI step is necessary, what a human decides independently and how a candidate can correct an error. If any of those answers is missing, the workflow is not ready to go live.

  1. Limit the purpose: define the precise interview task and the decision that remains with a human recruiter.
  2. Map the data: identify questions, audio, transcripts, scores, recipients, processors, storage locations, retention periods and third-country transfers.
  3. Document the legal basis: test necessity and legitimate interests; use consent only where there is a real, equal alternative.
  4. Assess impact: complete a DPIA where the processing is likely to create high risk, and test whether criteria are job-related and could disadvantage protected groups.
  5. Design human review: name the reviewer, specify what evidence they see, allow them to override the output and retain a reasoned record.
  6. Write the candidate notice: make AI involvement, recording, scoring, retention and rights clear before the interview begins.
  7. Involve the works council: identify the relevant German participation rights and agree the operating safeguards before rollout.
  8. Challenge the supplier: request documentation, a data processing agreement, security information, oversight instructions and a process for model or feature changes.

A voice interview workflow can help structure early candidate conversations, but it does not transfer the employer’s legal responsibility to the software provider. Organisations should also consider how a candidate portal can make notices, data access and corrections easier to manage across the application journey.

An important limit: there is no universal answer based only on the product category. Adding call recording, a personality signal, a new score or an automated rejection rule can change the GDPR assessment, Article 22 analysis, AI Act classification and works-council position. The AI interview and voice tools category can support market research, but it cannot validate a specific deployment.

FAQ: AI interviews with candidates

Do employers always need consent for an AI interview?

No. The first question is whether the processing is necessary for the application process and which legal basis actually fits it. Consent should be used only where it is freely given and candidates can choose an equivalent alternative without losing an opportunity.

Can an AI system automatically reject a candidate?

That is a high-risk design. A rejection based solely on automated processing may fall within Article 22 GDPR because it can significantly affect a person. Build a meaningful human decision stage with access to the underlying information and authority to change the outcome.

Do candidates need to be told that their voice is recorded?

Yes. Recording, transcription and evaluation are separate processing steps that should be explained before the interview. The notice should identify the purpose, legal basis, recipients, retention period and way to exercise data-protection rights.

Must a German works council be involved?

AI used in hiring selection guidelines is expressly addressed by section 95(2a) BetrVG. Further participation rights may arise where the system can monitor employees or their performance. The exact answer depends on the workflow and existing agreements, so involve the works council during design.

When do the EU AI Act high-risk rules apply to recruitment AI?

For stand-alone Annex III high-risk systems, including relevant recruitment and candidate-evaluation systems, the amended date is 2 December 2027. Employers should prepare earlier because GDPR and equality obligations already apply, and meaningful oversight cannot be added convincingly at the last minute.

Jürgen Ulbrich

CEO & Co-Founder of Sprad

Jürgen Ulbrich has more than a decade of experience in developing and leading high-performing teams and companies. As an expert in employee referral programs as well as feedback and performance processes, Jürgen has helped over 100 organizations optimize their talent acquisition and development strategies.

Free Templates &Downloads

Become part of the community in just 26 seconds and get free access to over 100 resources, templates, and guides.

No items found.

The People Powered HR Community is for HR professionals who put people at the center of their HR and recruiting work. Together, let’s turn our shared conviction into a movement that transforms the world of HR.

Similar Posts