For HR teams the most attractive candidate for automation is the first-round screening interview. Hundreds of applications arrive, the same five questions get asked, and most answers are clear within a few minutes. Automating it is not technically hard.
What is hard is establishing precisely which decision the automation makes and who owns that decision. Candidate assessment is one of the areas regulators watch most closely, and that attention is increasing.
Where the regulation stands
The EU AI Act classifies systems used in employment as high risk under Annex III. The scope is broad: targeting job advertisements, analysing and filtering applications, and evaluating candidates all fall in this category.
An important detail: the system does not have to make the final rejection decision. A tool that ranks, scores or filters applications is in scope even when a human makes the call. The classification follows the use case, not the degree of automation.
The timetable changed during 2026, and that change affects planning directly. The Digital Omnibus regulation entered into force on 27 July 2026, deferring high-risk obligations for standalone Annex III systems to 2 December 2027 (Gibson Dunn analysis, European Commission).
That deferral looks like relief and is not, for two reasons. First, the Commission can pull the date forward once it determines the necessary standards and guidance are in place; December 2027 is an outer limit, not a guarantee. Second, the substance of the obligations is what you should be building today anyway: risk management, data governance, human oversight, record-keeping and technical documentation. An organisation that starts in 2027 will not be ready in 2027.
The position in Turkey
Turkish data protection law has no direct equivalent of GDPR Article 22. It does, however, grant data subjects under Article 11 the right "to object to the occurrence of a result against the person by analysing the processed data exclusively through automated systems" (kvkk.gov.tr).
The implication for HR automation is direct: if a system rejected a candidate entirely automatically, the candidate can object, and the organisation needs a process capable of handling that objection. Without a mechanism to answer it, the obligation is not being met.
On discrimination, the equal treatment principle in Article 5 of the Turkish Labour Law applies. A system producing discriminatory outcomes is not excused by the absence of intent.
If you assess candidates in the United States
New York City's Local Law 144 imposes three concrete obligations on automated employment decision tools: an independent bias audit conducted annually, public posting of a summary of that audit, and notice to candidates at least ten business days before the tool is used (NYC DCWP).
The point worth noting in practice is that the obligation sits with the employer using the tool, not with the vendor supplying it.
Where bias comes from
"We do not give the model gender" does not eliminate discrimination risk. The problem usually operates through proxies rather than directly:
- Graduation year carries age
- Neighbourhood of residence carries socioeconomic information
- Career gaps correlate with parental leave and health conditions
- Military service status and certain certifications correlate strongly with gender
- School and club names carry information about social background
Even when these fields are withheld from the model, they enter indirectly if they appear in free-text CVs.
Voice screening adds a layer of risk
This differs from written application screening and is not discussed enough. In a voice-assisted first-round interview, the candidate is assessed through a speech recognition layer.
Speech recognition performance is not equal across speakers. Regional accent, non-native speakers, speech differences such as stuttering, and speech characteristics associated with hearing loss all raise error rates. When the error rate rises, answers are captured incompletely or incorrectly, and the candidate scores lower not because of what they said but because your system could not understand them.
This is fixable but hard to notice, because aggregate metrics look fine. Transcript quality can be high across the whole cohort and markedly lower within one subgroup.
Organisations using voice screening therefore need to do two things: measure transcript quality by subgroup, and offer every candidate at least one alternative to the voice interview. That alternative is also an accessibility requirement.
Design determines the risk profile
You can build the same technology two ways, and the two carry very different risk.
The risky build. The assistant interviews the candidate, produces a suitability score, and candidates below a threshold are automatically eliminated. The system makes the decision; the human only sees a list.
The defensible build. The assistant interviews the candidate, turns verifiable facts into structured data, and presents it to the HR team. A human makes the elimination decision.
In the second build, what the assistant collects are facts rather than judgements: work authorisation status, whether a required certification is held, total years of experience, location suitability, availability for the working hours, salary expectation range, earliest start date.
These rest on the candidate's own statements, are reproducible, and can be shown to the candidate. An output like "this candidate's communication skill is 6.4" is neither reproducible nor defensible.
In our experience the time saved by the second build is not meaningfully lower than the first, because most of the time goes on collecting basic information through repeated calls, not on scoring.
The candidate experience side
The most common complaint about screening automation is candidates losing track of where they stand. A few practical rules help:
- Say at the start that this is an automated first-round interview
- State up front how long it will take and how many questions there are
- Let the candidate switch to a human at any point
- At the end, say what the next step is and within what timeframe
- Respond to unsuccessful candidates too
The last one is not a technical matter, but it is the most visible output of automation for your employer brand. An automated process that goes silent is received worse than a manual one that does.
What to settle on the data side
Candidate data should be governed differently from employee data:
- How long is candidate data retained, and what happens at the end
- Is separate consent obtained for inclusion in a talent pool
- Are voice recordings kept, and if so for how long
- Are transcripts and assessment notes managed as a separate category
- Who can access the data of candidates who were not hired
- Is the information notice presented at the start of the interview
If a voiceprint is extracted from the recording, the data processed becomes biometric and falls under the special-category regime in Article 6 of the Turkish data protection law. It is difficult to find a strong justification for that in a recruitment process.
Measurement: not accuracy, but pass rates by group
Measuring a screening system by "accuracy" is misleading, because there is no ground truth about who should have passed. The more meaningful measurement is the system's relationship to later stages and its behaviour across groups.
Track:
- Progression rate of screened-in candidates through later stages
- Share of screened-out candidates who progressed after an objection was reviewed
- Differences in pass rates between candidate groups
- Interview completion rate and where candidates drop off
- Distribution of transcript quality by subgroup
For the third, US employment enforcement has long used a threshold: if a group's selection rate falls below four-fifths of the rate of the highest-scoring group, that is treated as an indicator of adverse impact (Uniform Guidelines on Employee Selection Procedures, 29 CFR 1607).
That threshold is not part of Turkish law, but it is a practical and defensible starting point for monitoring whether your system produces discriminatory outcomes. Doing the measurement requires collecting group data, which is itself a legal question and is generally handled in aggregated and anonymised form.
Where to start
Candidate screening is the highest-risk area in HR automation. The same technology has much lower-risk uses that deliver results faster: leave balance queries, payroll questions, benefits information, policy and procedure questions, and onboarding guidance.
Those flows make it easier for employees to reach their own data, decide nothing about anyone, and noticeably reduce the repetitive question load on HR teams. For most organisations the right sequence is to start there and move to candidate processes once the governance structure exists.
Checklist
- Does the system make elimination decisions, or collect information
- Can you evidence that the rejection decision was made by a human
- Is an objection mechanism defined and working
- Have proxy variables been assessed
- Is an alternative to the voice interview offered
- Is transcript quality measured by subgroup
- Are pass rates by group monitored regularly
- Are candidate data retention periods and access rights defined
- Are technical documentation and decision records maintained
To see voice assistant flows in HR processes, look at HR Assistants, and for the internal knowledge assistant architecture see the enterprise chatbot article.
This article is general information and is not legal advice. Review your own case with your legal and HR teams before implementation.
References
- EU AI Act, Annex III: High-Risk AI Systems. artificialintelligenceact.eu
- Gibson Dunn, EU AI Act Omnibus Agreement, Postponed High-Risk Deadlines. gibsondunn.com
- European Commission, AI Act regulatory framework. digital-strategy.ec.europa.eu
- Law No. 6698 on the Protection of Personal Data, Article 11. kvkk.gov.tr
- NYC Department of Consumer and Worker Protection, Automated Employment Decision Tools. nyc.gov
- Uniform Guidelines on Employee Selection Procedures, 29 CFR Part 1607. ecfr.gov
