29 August 2026
The Human Review Step Is Not a Review
The "human review" step in most UK hiring processes is not a review. It's a signature on a score the manager didn't produce and usually can't interrogate.
By the end of 2027, a UK employment tribunal will find a candidate's rejection unlawful. Not because the score was wrong. Because the signature had no judgment behind it. That ruling is coming. The ICO has already found the breach.
Bloomberg Opinion noted this week1 that AI is fixing UK productivity, with a cost. The cost the piece gestures at shows up in wages and investment data. The cost this post is about doesn't appear in any index. It sits in a rejected application that a human technically signed off, inside a process the Information Commissioner found was operating outside data protection law.
The ICO's "Recruitment Rewired" report2, published March 2026 after reviewing more than 30 UK employers, found most organisations running AI screening tools believed they were supporting human decisions. The ICO found the tools were making the decisions outright. It wrote to 16 employers it considered likely to be operating outside the law. All 16 committed to changes.
Everyone in hiring already knows this. The manager opening a scored shortlist isn't deciding. They're confirming. The machine ranked; the human clicked. The gap between those two things is the entire legal question, and it sat in plain sight for years before any statute gave a courtroom reason to care about it.
The Data (Use and Access) Act 20253, in force from 5 February 2026, is what makes it a courtroom question. It requires genuine human involvement in consequential AI decisions. The ICO's test4: does the reviewer have authority, discretion, and competence to change the outcome before it takes effect? Approving a shortlist the reviewer can't override doesn't clear that bar.
Picture this concretely. A firm routes 300 AI-scored candidates to a hiring manager with four hours free. 300 divided by 240 minutes: 48 seconds per candidate. Every name gets touched. The ICO found something worse4: human involvement was often inconsistent, some candidates genuinely looked at, others rejected on an automated score with no file ever opened. Forty-eight seconds is the generous reading. Some candidates got zero.
The counterargument matters. Without AI screening, the same manager reads 20 CVs and ignores the rest. The machine at least sees everyone. The problem isn't that a score gets produced. It's that the law wrote a role for someone with real information and real authority, then placed that person downstream of a queue they can't meaningfully work through.
Lloyds Bank found5 that 61% of UK firms now use AI. TechMarketView found6 68% of tech leaders expect net headcount to fall even where AI augments rather than replaces roles. The gap between those two figures runs to 14 percentage points: the distance between "AI created some jobs" and "net headcount fell." Created is not net. The headline travels without the denominator.
The ICO found the breach in March, sent letters, and waited. The firms signed commitments. The question the tribunal will answer is simpler: when the manager opened the file and clicked, did they decide anything? Forty-eight seconds is not an answer. It's an exhibit.