AI Resume Screening Bias Risk: The SMB Compliance Guide (2026)

Published: 08 April 2026 · Last updated: 17 July 2026

Author: Ben Lovis, HF Editor

A practical 2026 guide to AI resume-screening bias: test job-related criteria, audit outcomes, challenge vendor claims and meet UK, US and EU duties.

AI Resume Screening Bias Risk: The SMB Compliance Guide (2026)

AI resume-screening bias occurs when a tool or the process around it disadvantages candidates for reasons that are not necessary to the job. Risk can enter through training data, proxy variables, poorly chosen criteria, inaccessible assessments or reviewers who accept a ranking without examining the evidence.

An SMB does not need to avoid every AI tool. It does need to define job-related criteria, test representative cases, inspect selection outcomes, preserve meaningful human review and give candidates an appropriate route to challenge errors. The employer or agency remains responsible for the hiring process even when a vendor supplies the software.

One 2025 University of Washington study, summarised by Brookings, found strong name-associated racial and gender preferences in the language-model retrieval systems it tested. Those results are important evidence of a risk, not proof that 85% of every commercial screening product is biased. This guide shows how to evaluate the actual tool and workflow you intend to use.

TL;DR: Test the criteria and the output, not the vendor's adjective. Ask for evidence, examine intersectional selection rates, sample false negatives, train reviewers to challenge recommendations and document every material change.


What Is AI Hiring Bias — and Why Does It Keep Landing Employers in Court?

In April 2025, researchers at the University of Washington tested 554 resumes and 571 job descriptions across nine occupations, analysing how AI models selected candidates by name alone (Brookings Institution, 2025). White-associated names were favoured in 85.1% of cases. Black-associated names led in just 8.6%. Resumes with Black men's names were selected 0% of the time in head-to-head comparisons with white men's names. The AI wasn't told anyone's race. It inferred it from names, and it discriminated anyway.

Diverse team of professionals meeting at a conference table to review hiring decisions

Bias enters AI models during training. If the historical hiring data reflects decades of biased decisions (fewer women promoted, fewer candidates from certain postcodes hired), the model learns those patterns as proxies for "good candidate." It isn't deliberately discriminating. It's pattern-matching against data that was already skewed. For a broader look at why AI CV sifting works — and where it doesn't, the training data question is the first thing to interrogate.

The legal risk for employers isn't hypothetical. In 2023, the EEOC announced a $365,000 settlement with iTutorGroup after the company programmed application software to reject female applicants aged 55 or older and male applicants aged 60 or older, affecting more than 200 qualified US applicants (EEOC, 2023).

A second finding from the University of Washington study deserves more attention than it's received. When hiring managers were shown AI recommendations, they mirrored the AI's biases in their own selections, even though the same participants showed little bias when working without AI input (University of Washington, November 2025). Human oversight, by itself, is not a reliable safeguard. You can't assume a reviewer will catch what the model gets wrong.

In that specific experiment, the tested systems favoured white-associated names in 85.1% of the race comparisons and showed a preference by gender in 63% of comparisons (Brookings Institution, 2025). The study covered nine occupations and a defined set of models; do not generalise its percentages to a product that has not been tested.


What Does the Law Now Require from UK and US Employers?

The regulatory picture changed significantly in 2023–2025. Compliance is no longer optional, and the question of which regulations apply depends on where you hire.

United States

The EEOC has made AI hiring bias a priority enforcement area. Its existing guidance makes clear that employers are liable for discriminatory outcomes from AI tools they deploy, even if the vendor built the tool. The FY 2024 annual report recorded 88,531 new discrimination charges and nearly $700 million in monetary relief, its highest recovery in recent history (EEOC, 2024).

New York City's Local Law 144 applies to covered automated employment decision tools used in the city. The official DCWP guidance requires a bias audit within one year of use, public information about the audit and prescribed candidate or employee notices; its materials clarify a 10-business-day advance-notice requirement (NYC DCWP). Confirm that the tool and use fall within the law's definitions rather than assuming every recruitment automation feature is covered.

United Kingdom

The UK Equality Act 2010 already prohibits indirect discrimination. An AI tool that disproportionately screens out candidates of a protected characteristic can breach the Act regardless of intent. The Equality and Human Rights Commission named AI a "significant new threat" to equality in its 2025–2028 Strategic Plan (Fieldfisher, 2025) and committed to targeted enforcement. The ICO has separately flagged AI recruitment tools for lacking transparency about how decisions are made, which also creates exposure under UK GDPR.

European Union

The EU AI Act identifies certain employment systems, including CV-sorting software, as high-risk depending on their intended use. Following the May 2026 political agreement on the AI Omnibus, the European Commission says the high-risk rules for stand-alone systems in areas including employment are scheduled to apply from 2 December 2027. Other AI Act and GDPR obligations have separate timelines. Check the final law and current guidance for your role as provider, deployer, importer or distributor (European Commission, 2026).

For UK/EU employers specifically, see our guide to GDPR and AI recruitment compliance for the data protection layer that sits alongside these new AI-specific rules.

AI Screening Bias: Which Groups Get Selected? (Brookings 2025)% of tests where that group's resumes were favouredWhite names (race)Men's names (gender)Equal outcome (gender)Women's names (gender)Equal outcome (race)Black names (race)85.1%51.9%37.0%11.1%6.3%8.6%
Source: Brookings Institution / University of Washington, April 2025 (n=554 resumes, 571 job descriptions, 9 occupations)

How Do You Spot a Biased AI Screening Tool Before You Sign?

Asking a vendor whether their tool is "fair" will get you a reassuring answer every time. The useful questions are more specific.

HR professionals from varied backgrounds reviewing compliance documents together in an office

Before committing to any AI screening tool, ask these seven questions and request documented answers:

  1. Has your tool undergone an independent bias audit in the last 12 months? Not an internal review: independent, third-party, with published results.
  2. Which protected characteristics does the audit cover? At minimum: race, gender, age. Ask also for disability and nationality.
  3. What data was the model trained on? If it was historical hiring data from a single industry or geography, the bias risk is higher.
  4. Can I configure scoring criteria myself? Tools that let you define what "good" looks like for your role reduce the risk of the model importing assumptions from unrelated industries.
  5. What does the shortlist output show? You want to see the criteria, the supporting application evidence and the basis for any score. A selection tool should not infer or expose protected characteristics merely to make its ranking look explainable.
  6. Who bears liability if a candidate makes a discrimination complaint? Vendors often write their contracts to push this entirely onto the employer. Read the indemnity clause.
  7. How are you preparing for the EU AI Act? Ask the vendor to identify its intended-use classification, role in the supply chain, evidence plan, logging, human-oversight design and current implementation timeline. A generic “AI Act compliant” badge is not a substitute for documentation.

What Does a Bias Audit Actually Look Like for an SMB?

If your organisation uses a covered AEDT in New York City, Local Law 144 requires the prescribed independent bias audit within one year before use and publication of a summary. Requirements elsewhere differ. Even where a particular audit is not mandated, outcome testing is a sensible governance control; obtain advice on the law that applies to each hiring location.

A bias audit for a screening tool typically covers:

  • Selection rate analysis by demographic group: does the tool shortlist different proportions of candidates by race, gender, or age?
  • Adverse impact ratio: calculated as the selection rate for a protected group divided by the rate for the most-selected group. The EEOC's four-fifths rule flags ratios below 0.8 as potentially discriminatory.
  • Intersectional analysis: the Brookings study found that Black women's resumes were selected at especially low rates even when Black men's and white women's rates looked acceptable in isolation. A complete audit checks intersections, not just each characteristic separately.
  • Criteria sensitivity testing: does changing the scoring weights alter the demographic distribution of results?

For an SMB, start with data the organisation is lawfully permitted to use, a documented purpose and sufficient sample sizes. Do not guess protected characteristics from names or photographs. Small samples can be misleading, so involve a qualified analyst or adviser where the result will drive a consequential change.

Our complete guide to AI resume screening for SMBs covers how to build a compliant screening workflow from scratch, including what to include in your vendor evaluation checklist.


What Should You Do If Your Tool Is Flagged—or You Receive a Complaint?

The EEOC received 88,531 new discrimination charges in FY 2024 (a 9% increase over the previous year) and recovered nearly $700 million for workers (EEOC, 2024). If a candidate believes your AI screening tool contributed to discrimination, here's how to respond.

Immediately:

  • Preserve relevant documentation: configuration, outputs, criteria, notices, reviewer actions and audit results.
  • Pause or limit the affected use where continuing could create further harm.
  • Escalate to the organisation's legal, data-protection and employment owners.

In parallel:

  • Notify the vendor through the contractual incident or support route.
  • Establish which version, criteria and data were used.
  • Review the original applications and whether human involvement was genuine.
  • Assess whether other candidates or vacancies may be affected.

Next:

  • Follow the applicable regulator, tribunal, complaint and candidate-rights process.
  • Commission appropriately independent analysis where needed.
  • Correct inaccurate data and remedy affected decisions where required.
  • Change or retire criteria only through a documented process; never rewrite the historic record.

If you're comparing tools or your current vendor can't answer the audit questions above, read our comparison of ATS platforms vs dedicated AI screeners for a breakdown of what built-in bias protections actually look like in practice. And if you're weighing the full cost of getting this wrong, our guide to the hidden costs of manual CV screening puts the time and compliance exposure in context.

Run your first shortlist free

Upload the role and CVs. Hire Forge ranks the strongest candidates with clear reasoning, ready for your review.

Start free

100 CV screenings. No credit card required.


Buying a vendor tool does not remove the employer's duties under applicable employment and data-protection law. Liability and contractual allocation depend on the facts and jurisdiction. Review the tool, your use of it and the contract with qualified counsel rather than relying on a vendor warranty.

Yes. The UK Equality Act 2010 prohibits indirect discrimination, which includes AI tools that disproportionately screen out candidates of a protected characteristic, regardless of intent. The Equality and Human Rights Commission named AI a "significant new threat" to equality in its 2025–2028 Strategic Plan. UK employers using AI in hiring face the same legal exposure as US employers, through a different statutory framework.

Following the May 2026 political agreement on the AI Omnibus, the European Commission says high-risk rules for stand-alone systems in areas including employment are scheduled to apply from 2 December 2027. Classification depends on intended use, and other AI Act and GDPR duties have separate dates. Check the final text and current Commission guidance.

NYC Local Law 144 requires an independent audit at least annually for any automated employment decision tool used with NYC candidates. Outside NYC, there's currently no fixed legal frequency in US or UK law, but annual audits reflect best practice, particularly because model behaviour can drift as vendors update their algorithms without notifying customers.


What This Means for Your Hiring Process

The research demonstrates a credible failure mode in the tested models. It does not establish the behaviour of every commercial tool. Your responsibility is to obtain evidence for the system, role and candidate population you actually use, then keep monitoring after launch.

AI screening can support a more consistent first review when criteria are job-related, outputs are inspectable and reviewers can challenge them. None of those controls should be assumed from a sales claim.

Key actions to take now:

  • Ask your current or prospective vendor for their independent bias audit results before signing anything
  • Review selection outcomes using lawfully collected data and appropriate statistical support
  • Prepare for the EU AI Act's current 2 December 2027 high-risk employment-system timeline while continuing to meet existing GDPR duties
  • Read your vendor contract's indemnity clause before your next renewal
BL

About the author

Ben Lovis·Founder, Hire Forge AI

A professional recruiter who built and deployed AI-powered screening systems internally before founding Hire Forge AI. He now designs AI recruitment systems for hiring teams worldwide.

Ready to try Hire Forge AI?

Upload a job description and your CVs to see a ranked shortlist built around the evidence that matters.

Start free

100 CV screenings. No credit card required.