Nobody Approved a Decision-Maker
What a regulator found inside 30 UK employers, and the four questions a board can ask about its own hiring without understanding a single line of the model.
Somewhere in your organisation there is a procurement form.
On it, someone wrote the words "decision support".
That phrase is why nobody stopped.
It implies a person decides and a tool assists. It sounds like a spreadsheet. It went to a board, or more likely it did not, because nothing about it seemed to warrant the trip.
The system it describes now decides who gets seen.
What the regulator actually found
On 31 March 2026 the Information Commissioner's Office published the findings of its work with more than thirty UK employers on automated decision-making in recruitment. It issued draft guidance alongside it, and wrote to sixteen named organisations, all of whom have since committed to act.
Four findings. The first three are the ones you would expect.
Employers rely on these tools without effective human oversight.
Safeguards are applied inconsistently, and candidates often cannot challenge a decision made about them.
Transparency is poor, so candidates cannot understand how their data is being used.
Then the fourth.
Many employers do not acknowledge that they are carrying out automated decision-making at all.
Read that again as a trustee rather than as a technologist.
It does not say those organisations were doing it badly. It says they did not know they were doing it. You cannot govern a thing you have not admitted exists. Every safeguard downstream, every fairness check, every appeal route, depends on somebody first writing it down as a decision.
Nobody wrote it down.
The same finding, from a completely different direction
In August the BBC reported on women in their forties, fifties and sixties who cannot get past the first stage of a job application. It spoke to more than sixty of them, most with decades of senior experience.
One had applied for 442 roles in nine months. Another has been out of work for nearly four years after a thirty-year career in advertising, and is now on jobseeker's allowance. A third described stripping her age and years of experience out of her CV, and called it "Botoxing" it.
Buried in that reporting is a sentence from Laura Holden, an AI lawyer, about the products themselves.
Companies describe them as decision-support tools. In her assessment, they often function as automated decision-making systems.
That is the ICO's fourth finding, almost word for word, reached by a completely different route. The regulator got there by auditing employers. The lawyer got there by reading vendor products. Neither is citing the other.
When two independent parties produce the same sentence, it stops being a point of view.
Why this is a governance failure and not a scandal
Look at the mechanism rather than the villain, because there is no villain.
Holden describes one tool that grades CVs from A to D and encourages recruiters to prioritise the higher grades. Another flags something like a seven-year career gap as a "thing to note".
Both are sold as support. Both have already decided.
By the time a human sees the pile, the pile has been ordered, and the ordering is the decision. The person at the end of that process is not exercising judgement. They are ratifying an outcome that was determined before they arrived, using information they cannot see, against criteria nobody has written down.
Nobody in that chain lied.
The vendor said decision support and meant it. The recruiter said a human reviews every shortlist and meant it. The board, if it was ever asked, approved a tool for managing application volume and meant that too.
Every individual statement was true. The system as a whole does something none of them described.
That is what a governance gap looks like from the inside. It never announces itself. It sits in the space between what each party honestly believes and what the assembled thing actually does.
The four questions
You do not need to understand the model. You need to ask questions the model cannot dodge.
One. Does anything in our hiring produce a score, a grade, a rank or an order that a person then acts on?
Not "do we use AI". That question gets answered wrongly, and in good faith, because the people answering are thinking about chatbots. Ask about scores and ordering, and the answer changes.
Two. At what point does a candidate stop being considered, and what causes it?
Every process has a point at which a person ceases to be a possibility. Somebody should be able to say where it is. If the answer arrives vaguely, that is the finding.
Three. For one named applicant we rejected last month, can we say why?
Not the policy. The reason, for that person. If the organisation cannot produce it, it cannot defend the decision to a tribunal, to a regulator, or to the applicant, and it has been making decisions it cannot account for.
Four. Who decided this was decision support, and what were they shown when they decided it?
This is the trustee question, and it is almost never asked. Somewhere a categorisation was made that determined the level of scrutiny everything after it received. It was probably made by one person, quickly, using the vendor's language, and it has been load-bearing ever since.
None of these four require technical knowledge. All four are answerable. The pattern of the answers tells you more than any assurance report will.
Turn the instrument around
Dr Eleanor Drage of the University of Cambridge makes a point that deserves lifting out of the article it appeared in.
Organisations should use these tools to evaluate their own hiring practices, rather than to assess the people applying to them.
That is the whole argument in one move. The same technology currently pointed outward at applicants could be pointed inward at the process, where the organisation owns the data, holds the consent, and would learn something it can actually act on.
It is also the harder direction, because it produces findings about you.
The part that gets left out
The BBC reported that some London companies have stopped using these tools over concerns about bias.
That deserves more attention than it received, because it settles the argument that usually ends these conversations. Stopping was available. It was on the table the whole time. Some boards looked at what they were running, did not like the answer, and withdrew.
That is not a technology decision. Nobody in those rooms out-engineered the problem. They asked what the thing did, got an answer they could not defend, and acted on it.
Which is, more or less, the job.
What this is really about
A trustee is accountable for an estate they must rely on and cannot personally inspect. What is in it. What it costs. What it exposes. And what it is permitted to decide.
That last one is the one everybody forgets, and it is the one that matters here.
Nobody sat in a boardroom and approved a system that would decide, unsupervised, which people would be considered for work. That decision was never taken. It arrived by accretion, through a procurement form, a plausible phrase, and an assumption that a human at the end of the process constituted oversight.
The first duty is not a better tool. It is an honest inventory.
Ask the four questions. Write down what you find, including the parts that are unflattering and the parts you cannot yet answer.
You cannot govern what you have not admitted you are doing.
Sources
Information Commissioner's Office, findings and draft guidance on automated decision-making in recruitment, 31 March 2026, drawn from engagement with more than 30 UK employers, with letters issued to 16 named organisations.
BBC News, "'I've had to Botox my CV': Are AI recruitment tools affecting women's careers?", 6 August 2026, reporting by Meghan Owen, including comments from Laura Holden and Dr Eleanor Drage.