Back to articles
Compliance & CQC

AI Hiring Compliance in 2026: What Healthcare Employers Need to Document Now

Tom Mundy 7 April 2026 10 min read
Compliance

The EU AI Act came into force on 1 August 2024. It classifies AI systems used in hiring decisions as "high-risk." Full enforcement was originally scheduled for August 2026, with a potential delay to 2027 linked to the Digital Omnibus Act. But the delay is not a green light to do nothing.

If you run recruitment in a regulated sector—particularly healthcare—the question is not whether to act. It is when, and how thoroughly.

The anxiety is understandable. Compliance feels like a burden, and AI hiring feels like a risk. But here is the shift in thinking that matters: compliance is not a reason to avoid AI in hiring. It is a reason to choose the right kind.

Healthcare employers already operate in one of the most regulated hiring environments in the UK. You already manage right-to-work verification, occupational health screening, DBS checks, and a diverse workforce spanning 36 different countries. Adding AI compliance to that landscape is not a new burden—it is an extension of what good practice already requires.

The organisations that will struggle are those using opaque, poorly documented AI tools without transparency or bias monitoring. The ones that will be fine are those using structured, auditable, human-centred systems. That distinction matters more now than ever.

This guide covers what you need to document, why healthcare is different, and what the next 90 days should look like.

What the EU AI Act Actually Requires from Hiring Teams

Strip away the legal language, and the EU AI Act's requirements for hiring are six practical obligations:

  1. Transparency: Candidates must be informed when AI is being used in hiring decisions. This is not optional and cannot be buried in a privacy notice. Candidates need to know, and know early.
  2. Bias audits: Employers must conduct and document regular audits of AI tools for discriminatory outcomes. Not one-time audits. Regular, ongoing monitoring of how the tool performs across different demographic groups.
  3. Human oversight: AI-assisted decisions must have a human review stage. AI cannot be the sole decision-maker. A human recruiter must see the AI output and make the final call.
  4. Documentation: Maintain records of how the AI tool works, what data it uses, and how decisions are made. This is your evidence that the system is working as intended and that you have investigated any bias concerns.
  5. Right to explanation: Candidates must be able to request an explanation of how AI influenced their outcome. This means you need to be able to explain the scoring, the reasoning, and the role of the human reviewer.
  6. Data retention: Record retention requirements are increasing. California's FEHA amendment extends this to four years for AI hiring records. UK employers should review their own policies and plan for similar timescales.

"Employers deploying AI systems must inform candidates of AI use and maintain documentation to demonstrate compliance. This includes regular bias audits, human review of decisions, and records of how the system operates."

These are not theoretical obligations. They are the baseline for operating legally in the EU and increasingly expected by regulators and candidates in the UK.

Why Healthcare Employers Face a Higher Bar

Healthcare hiring is already complex. You manage occupational health assessments, Disclosure and Barring Service (DBS) checks, immunisation requirements, and right-to-work verification. You are recruiting from one of the most diverse candidate pools in the UK: 21% of NHS staff are internationally trained, and 36% of doctors qualify outside the UK.

That diversity is a strength. It is also the reason healthcare employers need to be more careful about AI hiring tools than most.

AI systems that rely on speech recognition, language patterns, or communication style assessment can perform differently across candidates with accents, hearing impairments, regional dialects, or non-standard English patterns. In a healthcare setting where your recruits include nurses trained in Poland, doctors qualified in Nigeria, and allied health professionals from across the EU, that gap is not an edge case. It is mainstream.

The same applies to video screening tools that assess facial expressions, tone of voice, or body language. These tools can introduce bias—intentionally or not—against candidates from different cultural backgrounds, older candidates, candidates with neurodivergence, or candidates with disabilities affecting communication or appearance.

A 2025 NAVEX survey found that 96% of healthcare AI vendors now conduct routine algorithm audits for fairness. That is good news. But it raises a question: Is your vendor one of them? And have you seen the results?

If your AI hiring tool vendor cannot provide evidence of bias audits, performance data across demographic groups, or documentation of how they have investigated and corrected bias, that is a red flag. It is also a compliance risk.

Healthcare employers have a responsibility to their candidates and to the regulators who oversee their sector. That means asking harder questions about the tools you use and the evidence behind them.

The 90-Day Compliance Checklist

You do not need to build a compliance programme from scratch. You need to be systematic, document what you do, and make sure the gaps are addressed. Here is a practical 90-day plan:

Month 1: Audit Your Current Tools

  • Identify every point in your hiring process where AI or automation is used. This includes video screening, CV parsing, chatbots, automated interview scheduling, skills assessment tools, and any form of algorithmic ranking or scoring.
  • Request documentation from each vendor. Ask: What data does the tool use? How are decisions made? Has it been audited for bias? How does it perform across different demographic groups? Request a summary of any bias audits, fairness testing, or algorithm reviews.
  • Review your candidate communications. Do job postings, application confirmations, interview invitations, and rejection letters disclose that AI is being used? If not, they need to.
  • Audit your current data retention practices. How long do you currently keep recruitment records? You will need to extend this to at least two years, and review whether four-year retention is appropriate for your organisation.

Month 2: Establish Human Oversight

  • Assign a named person responsible for AI hiring compliance. This should be someone with authority over recruitment processes and access to vendor documentation. They do not need to be a lawyer or a technologist—they need to be organised and thorough.
  • Ensure every AI-assisted screening outcome is reviewed by a human before a candidate is advanced or rejected. Document the review process: Who reviewed it? When? What did they decide? Why did they agree or disagree with the AI recommendation?
  • Create a standard template for documenting human review decisions. This does not need to be lengthy, but it should capture the essence: candidate name, AI recommendation, human decision, and brief reasoning if there was disagreement.

Month 3: Prepare for Audit

  • Create a data retention and access policy covering AI hiring records. Include what data you keep, how long, who can access it, and how candidates can request their records or request an explanation.
  • Brief your recruitment team on candidate rights. Transparency: candidates know AI is being used. Opt-out: candidates know they can request a human review instead. Explanation: candidates know they can ask why they were rejected or screened in.
  • Review your privacy notices. Include specific detail about AI hiring use: which AI tools, what data they process, how long you keep records, and how to request an explanation or correction.
  • Document your bias monitoring process. How often will you audit your AI tools for fairness? Who will do it? How will you act if you find bias?

These three months are not just about ticking boxes. They are about building the infrastructure that makes your recruitment process both compliant and defensible.

What Compliant AI Hiring Actually Looks Like in Practice

There is a common misconception that compliance AI hiring sounds boring and rigid. In fact, it is more efficient, more fair, and more defensible than unstructured manual screening.

Here is what good looks like:

  • Every candidate receives the same questions in the same order. This creates consistency. It also eliminates the unconscious bias that comes from different recruiters asking different questions.
  • Scoring criteria are defined in advance and applied consistently. A candidate's response to "Tell us about your experience with team conflict" is scored against the same rubric, by the same system, every time. No surprises, no hidden algorithms.
  • Every conversation is recorded, transcribed, and summarised. This is not invasive. It is transparent. The candidate knows they are being recorded. The recruiter has a full record to review. There is no ambiguity about what was said.
  • Bias monitoring is built in, not bolted on. The system continuously tracks: Does this tool perform differently for men vs. women? For candidates with English as a first language vs. those without? For candidates from different age groups? If bias appears, you know it and can investigate.
  • The human recruiter reviews the AI output and makes the final call. The AI surfaces strong candidates, flags potential concerns, and suggests next steps. The recruiter sees all of that and decides. The recruiter is in control. The AI is a tool.

This is not just compliance. It is better hiring. It is faster, more transparent, more fair, and harder for a regulator to criticise because every step is documented and defensible.

The Window Before Full Enforcement

The potential delay in EU AI Act enforcement to 2027 gives you breathing room. But do not confuse breathing room with inaction.

The healthcare organisations that move first on compliant AI hiring will not just avoid penalties. They will also build recruitment processes that are more efficient, more auditable, and more defensible. That is a competitive advantage.

Regulators, candidates, and your own board expect healthcare employers to lead on responsible AI. Waiting until enforcement is imminent, then scrambling to comply, is a gamble. Building a compliant process now—while you have time to think clearly, involve your team, and choose the right tools—is the professional move.

Use the next 12 months to audit, document, and implement. By the time full enforcement comes into effect, your process will be solid.

Next Steps

Compliance is not a reason to avoid AI in hiring. It is a reason to choose the right tool—one that is transparent, auditable, and built with fairness as a core feature, not an afterthought.

If you are using AI in recruitment, start with the 90-day checklist above. Audit what you have. Document what you find. Close the gaps.

If you are considering AI hiring tools, ask your vendors the hard questions: How do you monitor for bias? Can you provide audit evidence? How do you ensure human oversight? How will candidates know AI is being used?

The healthcare employers that will thrive in this new regulatory landscape are those that see compliance not as a burden, but as an opportunity to hire better, more fairly, and with confidence.

Book a demo with Lily to see how structured AI screening with continuous bias monitoring, full transcripts, and built-in human oversight works in practice. We will show you how to turn compliance into a competitive advantage.


Further Reading

Stay in the loop

Get care sector hiring insights straight to your inbox

Join care providers across the UK who read our practical guides on recruitment, retention, and compliance, delivered straight to your inbox.

No spam. Unsubscribe anytime.

Want to see Lily in action?

See how Lily handles hiring for care providers like yours.

Book a demo