AI in Recruitment: Bias, Fake Candidates, and the Law
A recruiter runs 400 applications for a remote developer role through an AI shortlister, then books three video interviews. The top candidate interviews well, clears the background check, and asks for the laptop to go to a new address.
Two of those steps involved AI, and both can fail in ways the recruiter never sees. The shortlister may have dropped qualified people for reasons nobody chose, and the person on camera may not be the person on the documents.
What is AI in recruitment?
Section titled “What is AI in recruitment?”AI in recruitment is the use of machine-learning tools to source, screen, rank, interview, or verify job candidates. It speeds up hiring, but it adds risks that traditional hiring never had: biased scoring nobody can inspect, candidates who fake their identity on video, and legal duties that now attach to the tool itself.
Many hiring stacks already include it without calling it AI. Resume parsers rank applicants, chatbots schedule screens, and video platforms transcribe and score interviews.
How does AI hiring bias happen?
Section titled “How does AI hiring bias happen?”AI hiring bias happens when a model learns patterns from past decisions and repeats them. If the people hired over the last decade skew one way, a model trained on those hires will score new applicants the same way, whether or not anyone intended it.
The best-known case is Amazon’s experimental resume-scoring tool. Reuters reported in 2018 that the tool, trained on ten years of resumes that mostly came from men, penalized resumes containing the word “women’s” and downgraded graduates of two all-women’s colleges. Amazon stopped using it because it could not rule out other ways the model might discriminate.
The mechanism is usually a proxy variable. The model never sees gender or ethnicity, but it does see a postcode, a club, a university, or a career gap, and any of those can stand in for a protected trait.
Proxies are hard to spot from the outside, which is why fairness checks have to look at outcomes by group. The bias and discrimination in AI exercise puts learners in front of a fairness dashboard for a resume screening tool, where they trace the proxy behind a skewed result and escalate it the right way.
How do fake job candidates use deepfakes?
Section titled “How do fake job candidates use deepfakes?”Fake candidates apply under a stolen or invented identity, often for remote technical roles that come with system access. Deepfakes make the video interview, once the strongest identity check in remote hiring, much easier to fool.
The FBI’s Internet Crime Complaint Center warned about this in June 2022. Its public service announcement described applicants using deepfakes and stolen personal information to apply for remote IT, programming, and database roles, some with access to customer data and financial systems. Interviewers noticed that lip movements did not fully match the audio.
The problem has grown since. In July 2025 Gartner predicted that one in four candidate profiles worldwide will be fake by 2028, and in a Gartner survey of 3,000 job candidates, 6% admitted to interview fraud, either posing as someone else or having someone pose as them.
Warning signs hiring teams can check for:
- Video that glitches exactly when the candidate is asked to turn their head or move a hand across their face
- Lip movement that drifts out of sync with the audio
- A background check that returns details belonging to someone else
- A request to ship equipment to an address that does not match the application
- Pressure to skip identity steps because the role is fully remote
Process catches fake candidates more reliably than gut feel. The deepfake hiring fraud exercise has hiring managers run a liveness check mid-interview, verify the person against their documents rather than trusting the paperwork, and hold the offer when the story starts to bend. Our guide to deepfake social engineering covers the same technology used against finance and executive teams.
Is AI recruitment high-risk under the EU AI Act?
Section titled “Is AI recruitment high-risk under the EU AI Act?”Yes. Annex III of the EU AI Act lists AI systems used for recruitment or selection as high-risk, including tools that place targeted job ads, filter applications, and evaluate candidates. The same annex covers AI used for promotion, termination, task allocation, and performance monitoring.
The timing changed in 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the high-risk obligations for Annex III systems to 2 December 2027. That buys employers time, and the obligations still arrive.
One rule already applies. Since 2 February 2025, Article 5 has banned AI that infers people’s emotions in the workplace, and the Commission’s guidelines on prohibited practices apply that ban to candidates during recruitment. A video interview tool that scores a candidate’s enthusiasm from their face or voice falls inside it.
Classifying each tool correctly is the skill that makes the rest possible. The AI risk classification exercise trains it by sorting real deployments into banned, high-risk, transparency-only, and minimal-risk uses, and our guide to EU AI Act risk categories explains each tier.
What does AI hiring compliance require?
Section titled “What does AI hiring compliance require?”The duties depend on where you hire and whether you built the tool or bought it. For an employer using a vendor’s screening tool, the main obligations look like this:
| Obligation | Source | What it means in practice |
|---|---|---|
| Human oversight | EU AI Act, Art. 26 | A trained person reviews the tool’s ranking and can override it before it decides anything |
| Tell workers first | EU AI Act, Art. 26(7) | Workers’ representatives and affected staff hear about a workplace high-risk system before it goes live |
| Tell candidates | EU AI Act, Art. 26 | People assessed with a high-risk system are informed that it is being used on them |
| No emotion recognition | EU AI Act, Art. 5 | Features that read emotion from video or voice stay switched off, in force since February 2025 |
| Human review of automated decisions | GDPR, Art. 22 | Candidates can contest a decision made solely by automated processing and ask for a human to look again |
| Annual bias audit | NYC Local Law 144 | An independent bias audit, a published summary, and candidate notice at least 10 business days before use |
Compliance also has a people side. When a recruiter pastes a candidate list into an unapproved AI tool to save a few minutes, the organization carries any fine and the recruiter answers to their employer.
The when AI use goes wrong exercise walks through exactly that: a four-minute hiring shortcut that turns into a case. Learners map each breach to its penalty tier, see what moves the amount, and file the report that improves the outcome.
How should HR and security share AI hiring risk?
Section titled “How should HR and security share AI hiring risk?”Hiring sits between two teams that rarely train together. HR owns the process and the tools, while security owns identity verification, device shipping, and access, which is where a fake candidate cashes in.
A shared checklist closes the gap:
- Inventory every AI feature in the hiring stack, including the ones a vendor switched on by default.
- Ask vendors for their intended purpose and bias testing results, and check both against Annex III.
- Switch off any feature that infers emotion or personality from video or voice.
- Add a liveness step and a document match to remote interviews for roles with system access.
- Match equipment shipping addresses to the verified identity before day one.
- Train recruiters and hiring managers on the scenarios, not only on the policy.
RansomLeak covers both sides of AI hiring risk. The AI and LLM security catalogue includes the deepfake interview scenario for hiring managers, and the privacy and compliance catalogue covers bias, risk classification, and what AI misuse costs. Each exercise is a 5 to 10 minute interactive scenario.
Frequently asked questions
Section titled “Frequently asked questions”Is AI in recruitment legal?
Section titled “Is AI in recruitment legal?”Yes, in most places, but it is regulated. In the EU, AI used to screen or evaluate candidates is high-risk under the AI Act, with those obligations applying from 2 December 2027, and emotion recognition of candidates is already banned.
What is the biggest risk of using AI in hiring?
Section titled “What is the biggest risk of using AI in hiring?”Hidden bias is the hardest to see, because a model can discriminate through proxy variables without anyone choosing to. Identity fraud is the most direct, because a fake candidate who gets hired also gets system access.
How do you spot a deepfake job candidate?
Section titled “How do you spot a deepfake job candidate?”Ask for a live action that face-swap software handles badly, such as turning the head or passing a hand across the face, and watch for lip movement that drifts from the audio. Then verify the person against their identity documents and check that the equipment shipping address matches.
Can candidates refuse AI screening?
Section titled “Can candidates refuse AI screening?”In the EU, the GDPR gives people the right not to be subject to a decision based solely on automated processing that significantly affects them, with limited exceptions. Where an exception applies, they can still ask for human review and contest the decision.
Who is liable when an AI hiring tool discriminates?
Section titled “Who is liable when an AI hiring tool discriminates?”The employer stays responsible for its hiring decisions, even when a vendor built the model. Under the EU AI Act the vendor carries provider duties and the employer carries deployer duties, and anti-discrimination law applies to the outcome either way.
Bottom line
Section titled “Bottom line”Nobody is taking AI out of hiring pipelines, and there is no reason to. The risks are specific: bias hides in proxies, identities get faked on camera, and the law now follows the tool.
Map every AI feature in your hiring stack, verify the people you hire as carefully as their paperwork, and train the people who run the process. If you want scenario-based training for recruiters and hiring managers, talk to our team.
Sources
Section titled “Sources”- Reuters (2018): Amazon scraps secret AI recruiting tool that showed bias against women
- FBI IC3 (2022): Deepfakes and stolen PII utilized to apply for remote work positions
- HR Dive (2025): By 2028, 1 in 4 candidate profiles will be fake, Gartner predicts
- Regulation (EU) 2024/1689 (AI Act), Official Journal
- European Commission: AI Omnibus enters into force
- European Commission: Guidelines on prohibited AI practices
- NYC DCWP: Automated Employment Decision Tools