Industry Guides
AI in Hiring: How CV Screening Systems Work — and Where They Get It Wrong
A typical corporate job posting now draws around 250 applications; entry-level roles can top 400. Yet the share of applicants who actually make it to an interview has collapsed: from about 15% in 2016 to roughly 3% in 2024. HR teams can't manage a funnel narrowing that fast by hand, which is why ...

A typical corporate job posting now draws around 250 applications; entry-level roles can top 400. Yet the share of applicants who actually make it to an interview has collapsed: from about 15% in 2016 to roughly 3% in 2024. HR teams can't manage a funnel narrowing that fast by hand, which is why applicant tracking systems (ATS) and AI-powered ranking are now standard at almost every mid-size-or-larger company. But these systems aren't neutral. Real cases, from Amazon to Workday, show that an algorithm can inherit the bias of the past just as easily as it can remove human inconsistency.
This piece covers how CV screening systems actually work, where they go wrong, and what frameworks like GDPR and US employment law require of employers who use them. Our broader guide to AI by industry flagged HR as one of the sectors where AI risk intersects directly with discrimination law; this is that chapter in more depth.
How Does a CV Screening System (ATS) Actually Work?
When a candidate uploads a CV, the system matches keywords from the job post (years of experience, education, technical skills, industry background) against the CV's content, producing a fit score and ranking candidates by it. More advanced applicant tracking systems go further, using machine learning to learn from a company's past hiring data: essentially learning "people this company has historically hired tended to look like this," and scoring new candidates against that pattern.
Platforms like Workday, Greenhouse, and LinkedIn Recruiter dominate this space globally, offering large searchable candidate databases, one-click job posting across multiple boards, and no-code careers-page builders with built-in applicant tracking. What they have in common: they automate the manual first pass, but the decision still lands in front of HR as a scored, ranked list.
When Does the Algorithm Get It Wrong? Real Cases From Amazon to Workday
Amazon's AI-powered hiring tool, developed between 2014 and 2017, was trained on a decade of résumés from a male-dominated tech workforce, and began systematically down-ranking any CV that included the word "women's" (as in "women's chess club captain") along with graduates of women's colleges. When the bias couldn't be reliably corrected, Amazon scrapped the tool entirely in 2018.
A more recent case: iTutorGroup in the US agreed to a $365,000 settlement with the Equal Employment Opportunity Commission (EEOC) in 2023, after its hiring software was found to automatically reject female applicants over 55 and male applicants over 60, affecting more than 200 candidates. In the still-ongoing Mobley v. Workday case, applicants allege that Workday's AI-driven screening tools disproportionately rejected candidates over 40; the case won preliminary collective-action certification in May 2025, with Workday itself telling the court its platform processed roughly 1.1 billion job applications during the period covered by the claim.
On the video-interview side, HireVue removed its facial-expression, eye-contact, and tone-of-voice-based "emotional intelligence" scoring feature entirely in 2021, after its own data scientists found that visual data contributed only about 0.25% to the tool's actual predictive power. All four cases point to the same lesson: an algorithm learns from historical data, and if that data carries bias, the algorithm carries it too, usually quietly, in a way HR rarely notices on its own. Amazon caught its own problem through an internal audit; most small and mid-size businesses running an off-the-shelf ATS never ask which criteria are actually driving the score. That's exactly what makes the risk invisible.
Is Using AI in Hiring Legal? GDPR and the Right to a Human Decision
Under GDPR Article 22, individuals have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on them, unless a narrow exception applies, and even then specific safeguards, including a genuine right to human review, are mandatory. E-recruitment carried out without human intervention is explicitly cited as exactly this kind of significant effect.
The bar for "human review" here isn't cosmetic: a recruiter who approves or rejects a candidate based mainly on an AI-generated ranking, without actually looking at the underlying CV or interview notes, doesn't meet the standard. A candidate can request that a human review the decision, provide additional context the algorithm may have missed, and challenge the outcome.
The US Picture: NYC Local Law 144 and the EEOC
New York City's Local Law 144 requires any employer using an Automated Employment Decision Tool to commission an independent bias audit within one year of using it, publish a summary of that audit publicly, and give candidates at least 10 business days' notice before the tool evaluates them. Enforcement began in July 2023, with penalties running $500-1,500 per day of violation.
Critically, the law isn't limited by company size or headquarters location; it applies to any employer with candidates or employees residing in NYC, which in practice reaches far beyond companies actually based there. Outside New York, the EEOC has pursued AI-related hiring discrimination more broadly under existing federal law, as the iTutorGroup and Workday cases above show.
What Should Happen With 300 Applications for One Role? A Step-By-Step Scenario
Picture an e-commerce company's "Customer Experience Specialist" listing drawing 300 applications. An AI-powered ATS ranks candidates by keyword match ("Excel," "2 years' experience," "CRM") and hands HR a shortlist of the top 40. Two risk points show up here: first, the system rigidly enforcing "2 years' experience" and auto-rejecting an otherwise strong candidate at 1 year and 10 months; second, the system quietly having learned that candidates from a particular university or city were hired more often in the past, and silently favoring that same profile again.
A healthy version of this process looks like: AI compresses 300 applications into a shortlist of 40-50 that HR can realistically review (the real time savings happen here), but a human makes every final call, and borderline candidates (say, those ranked 39th through 45th) get sampled for a closer look. That clears both the "myth of the 6-second CV scan" (actual research finds recruiters spend closer to 17-46 seconds, and some surveys find 30 seconds to a minute, per CV) and the meaningful-human-review bar that GDPR Article 22 sets.
A second example shows up in skilled-trades hiring, where CVs are far less structured: candidates describe their experience in free text rather than a standard template. A system relying purely on keyword matching might down-rank an experienced candidate who wrote "lathe operator" instead of the posting's exact term, "CNC operator," simply because the terms don't match literally. Here, the ATS needs synonym and occupation-code matching, not just exact string matching. Otherwise your most qualified candidates fall out of the funnel for no real reason.
Which Hiring Tasks Should Go to AI, and Which Should Never Leave Human Hands?
Thinking task by task is more useful than asking "should we use AI or not." Drafting job posts, answering routine candidate questions (interview date, process steps), standardizing CV formats, and filtering a large volume of applications; these are low-risk tasks where AI genuinely saves time. Final rejection decisions, post-interview evaluations, and salary offers all shape a candidate's career directly, and should always go through a human.
Global surveys put AI use in HR and recruiting at roughly 43% of organizations in 2025, up sharply from about a quarter the year before. AI adoption in hiring is accelerating fast, and companies of every size are affected by discrimination-law exposure, not just large ones. A practical rule for a small HR team: use AI for volume management (getting through hundreds of CVs), keep decision-making authority with a person. Writing that split into a formal hiring policy makes it easier for new HR hires to ramp up, and gives you a clear answer when a candidate appeals: who made the call, and at what stage.
Frequently Asked Questions
Does using an AI-powered ATS violate the law?
It depends on how it's used, not on the tool itself. Risk rises sharply when candidates aren't told a decision is automated, aren't given a right to appeal, and the final call is made by the system alone with no human review; that risk drops considerably when genuine human oversight and transparency are built in.
Do small companies face bias risk too?
Yes, bias comes from the pattern in past hiring decisions, not from the size of the dataset. Even a ten-person company that has hired from the same university or the same profile for the last five years can have an AI system learn that pattern as the "ideal candidate" and keep repeating it.
How long can candidate CV data be kept?
Neither GDPR nor most national frameworks set one fixed retention period for hiring data. The data-minimization principle applies: delete CVs once the process concludes and the data is no longer current, or obtain explicit consent to keep it longer.
So, What Should You Do?
- Never leave automated rejection completely unchecked: sample-review a portion of the candidates the AI screened out, required both under GDPR Article 22 and to catch bias risk early.
- Know which criteria are actually driving your scores: ask your ATS vendor which variables (university, location, previous employer) feed the ranking, and turn off anything that acts as a proxy for a protected trait.
- Don't bundle candidate consent with the hiring process itself: spell out clearly what data is kept, for how long, and for what purpose.
- Make the appeal channel visible: give rejected candidates a way to confirm a decision wasn't made by an automated system alone.
- Run periodic bias checks: review the gender, age, and university distribution of your shortlists regularly: a sudden, unexplained pattern can be a sign the algorithm learned the wrong lesson from past data.
AI genuinely lightens the load of reading 300 applications one by one, but keeping a transparent, auditable process where a human has the final word is a responsibility that doesn't get automated away. Reach out if you're weighing how to add that kind of accountable AI layer to your own hiring process.

Written by
Faruk Talmaç
Co-Founder & Editor
Co-founder of YZ Uzman, with 20+ years of experience in web design and software development.
Comments
No comments yet. Be the first to comment!