If you screen CVs with AI, or you are about to start, there is a question worth getting ahead of: can you prove the process is compliant? In 2026 this has moved from a nice-to-have to something UK recruiters are being asked about directly, by candidates, by clients, and by their own compliance teams.

The Information Commissioner's Office has made automated decision-making in hiring a clear area of focus, and the reforms in the Data (Use and Access) Act 2025 changed how these rules are framed. None of this is a reason to avoid AI screening. It is a reason to choose and use it carefully. Below is a practical checklist you can run against any tool, including the one you already use.

A quick note before we start: this is general guidance to help you ask the right questions, not legal advice. For a formal view on your specific setup, speak to a data protection professional.

Why compliance suddenly matters for CV screening

Under UK GDPR, people have specific protections around decisions that are made solely by automated means and that have a legal or similarly significant effect on them. Being screened out of a job you applied for can count as that kind of significant effect. That is the heart of it: the law is not concerned with AI reading a CV, it is concerned with AI being the only thing that decides your future with no human in the picture.

Two things have raised the stakes this year. First, candidates are far more aware of their rights, including the right to an explanation and the right to ask for a human to review a decision. Second, regulatory attention on AI in recruitment has grown, so "we did not realise the tool worked that way" is no longer a comfortable position to be in. The good news is that staying compliant is mostly about process and transparency, not about avoiding the technology.

The one question that decides your risk: is a human really in the loop?

Almost everything comes back to a single distinction. Is a candidate being rejected by a solely automated decision, or is AI ranking and explaining while a recruiter makes the call? A tool that automatically bins candidates below a cut-off, with nobody looking, sits squarely in the risk zone. A tool that produces a ranked, explained shortlist for a recruiter to review does not make the final decision, so the human stays responsible and in control.

The word regulators use is meaningful human involvement. That means a person with the authority and the information to change the outcome actually reviews it, rather than rubber-stamping whatever the machine produced. If your reviewer cannot see why a candidate scored low, they cannot meaningfully review anything, which is exactly why explainability is not a nice extra. It is what makes the human review real.

Your 2026 AI CV screening compliance checklist

Run any screening tool, and your own workflow, against these seven checks:

How to defend your process if a candidate asks

Imagine a candidate emails to ask why they did not make the shortlist. If your tool only ever produced a number, you are stuck. If it produced a written reason for each score, you can explain the decision, show that a human reviewed it, and offer a human re-review if they want one. That single capability, explainability, turns an awkward compliance moment into a straightforward answer. It is worth choosing tools with that in mind before you ever get the email.

Practically, keep a light record of who reviewed each shortlist and the criteria used. You are not building a legal file for every role, you are making sure that if you are ever asked, you can show the decision was human, reasoned, and fair.

Where Lucuma fits

Lucuma was built around exactly this line. It never auto-rejects a candidate. It ranks and scores every CV against the criteria you set, and it gives a plain-English reason for each score, so your human review is genuine and your answers to candidates are ready-made. If a CV lacks the data to score fairly, it flags it for manual review rather than inventing a result, so no strong candidate is silently dropped.

On the data side, processing happens in the EU, CV data is not kept after the session and is never used to train AI models, and a full Data Processing Agreement is available on Agency and Enterprise plans. You can see a real anonymised shortlist to understand what "explainable" actually looks like on the page, or read what to look for in AI CV screening software before you buy.

Frequently asked questions

Is AI CV screening legal in the UK?

Yes. It is legal when used in line with UK GDPR and ICO guidance. The main condition is that a candidate is not rejected by a solely automated decision with no meaningful human involvement. A tool that ranks and explains candidates, leaving the final decision to a recruiter, is on the right side of this.

Does GDPR ban automated CV screening?

No. UK GDPR does not ban AI CV screening. It places conditions on decisions made solely by automated means that have a legal or similarly significant effect on a person, which can include screening someone out of a job. Keeping a human meaningfully involved and being transparent with candidates keeps you within the rules.

What counts as meaningful human involvement?

A person with the authority and information to change the outcome actually reviews the result, rather than rubber-stamping it. In practice the recruiter can see why each candidate scored as they did, can override the ranking, and makes the final shortlist decision themselves.

Can a candidate ask why an AI rejected their CV?

Yes. Candidates can ask for an explanation of how a decision affecting them was reached and can request human review. If your screening tool gives a plain-English reason for every score, you can answer that. If it only outputs a number, you cannot.