Key takeaways
- GDPR Article 22 restricts decisions based solely on automated processing, and losing a job opportunity counts as a significant effect.
- The SCHUFA ruling (CJEU C-634/21) treats a probability score as the decision itself when a third party relies on it, so “we only recommend” is not a defence.
- The question a regulator asks is the override rate: out of the last hundred AI suggestions, how many did a human disagree with? Zero means there was no oversight.
- Auto-reject saves less time than expected because recruiters read the CV anyway; the hours go to coordination and feedback.
- 79% of candidates would apply again if they had received real feedback, which is impossible to write if a threshold made the call.
The request always arrives reasonably. “We get 400 applications a role. Just let the system drop anyone below 40%.” Sometimes it is softer: “make it a setting, we will keep it off.”
We do not build it, and there is no flag to enable it. That is a product decision with three separate justifications, and any one of them would be enough.
1. The law treats a score as a decision
GDPR Article 22 gives people the right not to be subject to a decision based solely on automated processing that significantly affects them. Losing a job opportunity qualifies. The usual escape hatch is “but a human reviews it”, and in 2023 the Court of Justice closed that hatch.
In the SCHUFA case (C-634/21), the court held that producing a probability score is itself an automated decision when a third party draws heavily on it. The company generating the score argued it only made a recommendation. That did not survive.
If the number decides in practice, it decides in law. “We only recommend” is not a defence.
Layer on the EU AI Act, which classifies recruitment as high-risk, and the calendar gets specific: transparency obligations under Article 50 apply from 2 August 2026, and the full high-risk regime lands on 2 December 2027. Colorado's ADMT rules and California's CCPA ADMT rules both start on 1 January 2027.
2. Rubber-stamping is the real failure mode
Even where automated rejection is legal, the compliance question is not “was there a human?” but “did the human do anything?” A regulator's version of that question is blunt:
Out of the last hundred AI suggestions, how many times did a person disagree?
If the answer is zero, you did not have oversight. You had a button. So we instrument the answer: every AI output records the model, the prompt version, an input digest, the output, and what the human did with it — agreed, edited, or overruled. Settings shows the override rate per user over the last thousand decisions. A healthy non-zero number is your evidence.
We also design against the reflex. Destructive confirmations arm 1.5 seconds after the dialog opens. Bulk actions are limited. A candidate's actual data is always on screen next to a score, never the score alone. And there is no single “fit percentage” anywhere in the product: ratings are per criterion, with the reason and the source quote attached.
What this means in the product: rejection is archiving with a reason, performed by a named person. There is no code path that rejects a candidate without a human actor, and lists are never silently truncated to a top-N.
3. The economics are worse than they look
The pitch for auto-reject is saved time. But the time is not where people think it is. Recruiters open the CV anyway; that is what the research on scoring tools keeps showing. The hours actually go to coordination and feedback, not to the decision itself.
Meanwhile the cost of a silent rejection is real and measurable. Thirty-four percent of candidates consider themselves ghosted after seven days of silence; 61% report being ghosted after an interview. And 79% say they would apply again if they had received real feedback. A rejection written from the actual reasons in a scorecard is the cheapest employer-brand win available, and it is impossible to write if a threshold made the call.
What we built instead
- Scores that sort, never decide. Points per requirement with a one-line reason each, a breakdown always one hover away, and an honest “not visible in the profile” instead of an inferred number.
- A queue of what needs a person. Candidates who have gone quiet surface after seven days with a specific rejection already drafted from the scorecard, ready to edit and send.
- A log you can replay. Prompts are versioned files, never edited in place, so a decision from six months ago can be reproduced exactly as it was made.
None of this is slower in practice. It is just honest about where the work is.
Frequently asked questions
Is automatic rejection of job candidates legal in the EU?
It is heavily restricted. GDPR Article 22 gives people the right not to be subject to decisions based solely on automated processing that significantly affect them, and rejecting a job application qualifies. Even where a lawful basis exists, you owe the candidate meaningful information about the logic involved and a route to human review.
Does a human reviewing the AI score make auto-reject compliant?
Only if the human genuinely can and does change outcomes. In CJEU case C-634/21 (SCHUFA), the court held that producing a probability score is itself an automated decision when a third party draws heavily on it. If the score decides in practice, adding a rubber-stamp step does not fix the legal position.
What is an AI override rate and why does it matter?
It is the share of AI suggestions a human disagreed with, edited or overruled. A non-zero rate is evidence that human oversight is real rather than decorative, which is exactly what regulators and auditors look for. ISTL Recruit records it per user from the last thousand logged decisions.
When do the EU AI Act obligations apply to recruiting tools?
Transparency duties under Article 50 apply from 2 August 2026, and the full high-risk regime lands on 2 December 2027 under Regulation (EU) 2026/1744. In the United States, Colorado's ADMT rules and California's CCPA ADMT rules both take effect on 1 January 2027.










CV (PDF)
LinkedIn
Email reply
Voice note
Interview