11 min readPriya Raman

Updated on

Explaining Automated Rejections Under EU and US Artificial Intelligence Laws

How talent operations teams must structure rejection explanations across different regulatory regimes

Explaining Automated Rejections Under EU and US Artificial Intelligence Laws

For years, applicant tracking systems processed millions of rejections in total silence. A candidate submitted a resume, an algorithm scored the document, and an automated trigger issued a generic rejection email three days later. That operational model is now illegal in several jurisdictions and faces tight restrictions across Europe and North America.

Regulators have shifted their focus from general data privacy to explicit governance of algorithmic hiring. When an automated system screens out a applicant, employers must explain why. This requirement appears in the European Union AI Act, New York City Local Law 144, and Illinois labor legislation. Each legal framework creates distinct requirements for talent acquisition operations, candidate relationship management systems, and legal counsel.

Talent acquisition teams must rewrite candidate communication workflows. Algorithmic transparency is no longer a candidate experience goal. It is an operational compliance requirement.

The Regulatory Patchwork for Rejection Transparency

Three distinct legal frameworks now dictate how organizations manage automated rejection notices. These laws establish different thresholds for what counts as an automated decision and what information employers must provide to rejected applicants.

The EU AI Act and GDPR Article 22

The European Union AI Act, formally Regulation 2024/1689, classifies AI systems used in recruitment, screening, and candidate evaluation as high-risk systems under Annex III. Under Article 86, affected candidates have a direct right to receive an explanation of the role played by the high-risk AI system in the decision-making process.

This right builds on Article 22 of the General Data Protection Regulation. GDPR Article 22 grants individuals the right not to be subject to a decision based solely on automated processing if it produces legal or similarly significant effects. Under EU law, a candidate rejected by an automated parser or scoring algorithm can demand meaningful information about the logic involved.

The territorial scope is broad. The EU AI Act applies to employers operating within the EU, including companies located in Germany, France, the Netherlands, and Spain. It also applies to employers based in the United States or the United Kingdom if their automated screening tools evaluate candidates located within the EU.

New York City Local Law 144

New York City Local Law 144 regulates Automated Employment Decision Tools, commonly known as AEDTs. The law defines an AEDT as any computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues a simplified output, such as a score, classification, or recommendation, used to substantially assist or replace discretionary decision-making.

Under Local Law 144, employers in New York City must comply with three core rules:

  • Perform an annual independent bias audit published on a public website.
  • Provide candidates ten business days of advance notice before using an AEDT.
  • Disclose the job qualifications and characteristics used by the tool to evaluate the applicant.

When a candidate requests an explanation of their score or rejection, the employer must provide details about the data fields and criteria processed by the AEDT within thirty days.

Illinois AI Video Interview Act and House Bill 3773

Illinois established early precedents with the Artificial Intelligence Video Interview Act. This law requires employers who analyze candidate video interviews using artificial intelligence to notify applicants, explain how the AI works, obtain consent, and delete video data upon request.

Illinois expanded these protections through House Bill 3773, which amends the Illinois Human Rights Act. Effective January 2026, the law prohibits employers from using artificial intelligence that has the effect of subjecting candidates to unlawful discrimination. It explicitly requires employers to notify job applicants whenever AI is used for recruitment, hiring, or candidate assessment.

JurisdictionPrimary RegulationRequired Notice TimingRight to Explanation Scope
European UnionEU AI Act (2024/1689) & GDPRAt or before initial data collectionDetailed logic and specific input weights
New York CityLocal Law 14410 business days prior to tool deploymentEvaluated job characteristics and criteria
IllinoisHB 3773 & Video Interview ActPrior to candidate evaluationGeneral explanation of AI function and criteria

The Mechanics of Rejection: Where Automated Systems Fail Candidates

Automated rejections occur in stages. Modern recruitment stacks use multiple layers of automated processing before a candidate reaches a human recruiter.

First, knockout questions filter applicants based on binary criteria, such as work authorization, location, or minimum education. Second, resume parsers extract structured fields and compute vector embeddings to compare resume text against job descriptions. Third, predictive scoring engines assign a percentile rank or suitability score based on historical hiring data.

An automated rejection is rarely the result of a single clear rule. It is usually the result of a weighted calculation across dozens of distinct resume signals.

This multi-layered approach creates significant explainability problems. Machine learning models use complex mathematical transformations. A gradient-boosted decision tree or a neural network evaluates interactions between hundreds of features. Extracting a simple, human-readable reason for candidate rejection requires post-hoc interpretability techniques.

Engineers use feature attribution methods like SHAP, which stands for SHapley Additive exPlanations, or LIME, which stands for Local Interpretable Model-agnostic Explanations. These mathematical techniques calculate how much each input signal shifted a candidate score above or below the qualification threshold.

Without these technical attribution tools, talent acquisition teams cannot generate valid rejection explanations. Standard ATS notification triggers rely on broad categories, such as failed screening or position filled. These generic responses fail to satisfy the explanatory standards established by European labor regulators and US municipal authorities.

Operationalizing Explanations: Architecture and Workflows

Translating technical attribution outputs into candidate-facing communications requires structural operational changes. Talent operations teams must map their entire recruitment stack to isolate where automated scoring happens.

[ Candidate Applies ] 
 │
 ▼
[ ATS Knockout Engine ] ──(Fails Binary Rule)──► [ Trigger Direct Binary Rejection ]
 │
 ▼
[ AI Parser & Scoring Engine ]
 │
 ├─► [ Computes SHAP Feature Weights ]
 │
 ▼
[ Recruiter Review Dashboard ]
 │
 ├─► (Human Overrides) ──► [ Update Model Log ]
 │
 ▼
[ Automated Rejection Trigger ] ──► [ Generate Specific Reason Code ]

A compliant explanation workflow must separate technical data from communication templates. It must convert raw algorithm weights into objective professional feedback without introducing legal risk.

Translating Model Weights into Compliant Feedback

When a candidate is rejected, the ATS or AI integration should not output raw code or raw numerical scores. The system must map feature attribution weights to standardized business rules.

If a model penalizes an application because the candidate possesses three years of experience with Python when the position requires five, the model output must trigger a specific experience code. If the model lowers a score due to missing certifications, the system must identify those specific missing credentials.

Talent acquisition leaders should establish a strict translation matrix:

  1. Identify the top three negative feature weights calculated by the scoring engine.
  2. Map each feature weight to an approved, job-related qualification statement.
  3. Verify that the qualification statement corresponds directly to the published job description.
  4. Draft the candidate email containing these specific, objective criteria.

This approach satisfies the EU AI Act mandate for explicit logic. It also complies with NYC Local Law 144 requirements regarding job characteristics.

Example Rejection Explanation Scenarios

Consider an enterprise hiring hundreds of software engineers across Germany, New York, and Illinois. The candidate submits an application for a Senior Systems Architect position.

A generic rejection email states: "Thank you for applying. We have reviewed your application and decided to pursue other candidates whose qualifications more closely match our current needs."

This response creates legal exposure in New York City and Europe. Under current regulatory expectations, a compliant response should provide objective reasons:

"Thank you for your application for the Senior Systems Architect position. Our automated application assessment evaluated your profile against the required job criteria. Your application was not advanced to the interview stage due to two specific factors: the screening model detected 3 years of Kubernetes administration experience, whereas the role threshold requires 5 years; and the system did not identify required certifications in enterprise cloud architecture. You may request a human review of this automated assessment within 14 days."

This structured notice provides clear reasoning grounded in the job post. It avoids subjective commentary while providing transparency.

Human-in-the-Loop Safeguards: Real Supervision vs Rubber-Stamping

Article 14 of the EU AI Act strictly requires high-risk AI systems to include effective human oversight. The law seeks to prevent fully autonomous decisions that negatively affect individuals. In recruitment, this rule means a human recruiter must oversee automated rejection decisions.

Many organizations rely on systemic rubber-stamping to maintain speed. A recruiter receives a daily batch of 300 candidates flagged for rejection by an AI tool. The recruiter selects all names and clicks approve in eight seconds. European regulators and courts do not accept this practice as meaningful human oversight.

For human supervision to be legally valid under EU AI Act expectations, the oversight process must fulfill four operational criteria:

  • The human reviewer must understand the capabilities and limitations of the AI tool.
  • The reviewer must have access to the underlying candidate data, not just the model output score.
  • The reviewer must possess the operational authority to override the system output without negative internal metrics.
  • The reviewer must spend sufficient time reviewing individual candidates.

According to research from the Josh Bersin Company and Gartner, a recruiter spends an average of 30 to 60 seconds reviewing a resume manually. When reviewing an automated rejection, spending less than 15 seconds per file suggests rubber-stamping.

Adding genuine human review changes operational financial models. If a team processes 10,000 applications per month and spends two minutes reviewing each automated rejection, that work requires over 330 staff hours per month. Talent operations leads must balance automated filtering efficiency against the labor costs of legally required human oversight.

Audit Trails, Logging, and Tech Stack Integration

Compliance requires comprehensive record-keeping. You cannot prove a rejection process was fair or compliant six months after the fact without audit logs.

Article 12 of the EU AI Act mandates automated recording of events throughout the system lifecycle. In candidate screening contexts, employers must capture and store specific data points for every application processed.

Required Data Fields for Compliance Logging

To construct an defensible audit trail, human resources information systems must log the following fields for every candidate transaction:

  • Candidate identification token and timestamp of application.
  • Version number of the job description and defined core criteria.
  • Specific model identifier, algorithm version, and training baseline ID.
  • Raw candidate feature vector inputs extracted from the resume.
  • Generated score, percentile rank, and feature attribution weights.
  • Specific candidate notification template ID and text sent.
  • Recruiter ID, timestamp of human review, and override indicator status.

Retaining these records requires alignment with local privacy laws. The GDPR sets principles for data minimization and storage limitation. NYC Local Law 144 requires employers to retain bias audit records and data log summaries for at least three years.

Employers operating across multiple jurisdictions must store algorithmic logging data in secure data repositories. Data retention schedules must account for conflicting regulatory timelines. For example, retaining data for three years to defend against US discrimination claims must be balanced against GDPR Article 17 erasure requests from European job applicants.

+-----------------------------------------------------------------------+
| AUDIT LOG DATA ARCHITECTURE |
+-----------------------------------------------------------------------+
| Candidate Token: CNT-2026-88391 |
| Job ID: ENG-SR-042 (Version 1.4) |
| Model Name: ScreeningEngine-v3.2 |
| Assessment Timestamp: 2026-03-29 T 14:22:10 UTC |
+-----------------------------------------------------------------------+
| RAW INPUT MATRIX: |
| - Total Years Experience: 4.2 |
| - Primary Skill Match (Python): 0.88 |
| - Cloud Certifications Present: FALSE |
+-----------------------------------------------------------------------+
| ATTRIBUTION OUTPUT (SHAP): |
| - Base Score: 0.75 |
| - Certification Penalty: -0.22 |
| - Experience Penalty: -0.15 |
| - Final Score: 0.38 (Threshold: 0.60) |
+-----------------------------------------------------------------------+
| HUMAN OVERRIDE LOG: |
| - Reviewed By: Recruiter ID 40291 |
| - Decision: Approved Automated Rejection |
| - Review Duration: 112 seconds |
+-----------------------------------------------------------------------+

Managing Tech Stack Disconnections

Most modern talent acquisition stacks rely on point solutions. An enterprise might run Workday or Greenhouse as its core ATS, use Eightfold or Phenom for candidate discovery, and deploy HireVue or Modern Hire for initial candidate assessments.

These systems exchange data through APIs. When a candidate is rejected, data fields can be lost between systems. If the candidate discovery engine computes an automated rejection score, but the core ATS simply logs a generic status change, the audit trail breaks.

Talent operations leads must audit API payload parameters between vendor applications. Automated vendor statements declaring full legal compliance are insufficient. The primary employer remains legally liable for unexplainable automated rejections under both US labor laws and European regulations.

The Next Three Years: Where Candidate Explanation Standards Are Heading

The legal obligations established in New York City, Illinois, and the European Union represent an initial baseline. Regulatory scrutiny of automated workplace decisions is expanding rapidly across other major economic markets.

In the United States, California is moving forward with automated decision-making technology regulations under the California Consumer Privacy Act. State legislation such as California Assembly Bill 2930 aims to regulate automated employment tools state-wide, introducing strict requirements for impact assessments and candidate notifications. State civil rights agencies in Massachusetts and New Jersey are drafting similar policy guidance.

In Canada, the proposed Artificial Intelligence and Data Act, part of Bill C-27, will establish federal oversight for high-impact AI systems, including talent selection tools. The Canadian law will mandate clear public disclosures and risk mitigation strategy reporting.

Labor unions and works councils across Europe are actively challenging black-box hiring software. In Germany, local works councils utilize rights under Section 87 of the Works Constitution Act to demand full access to algorithm parameters before automated talent selection tools can be deployed.

These legal shifts point toward a single market standard. The era of automated rejections without clear explanations is coming to an end. Organizations that continue to rely on generic candidate communications risk regulatory fines, legal challenges, and brand damage.

Talent acquisition leaders must audit their candidate screening tools today. Map where algorithms make decision recommendations, establish transparent attribution translation models, and ensure human recruiters conduct genuine reviews of every automated rejection.

Sources

  1. 01Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)EUR-Lex
  2. 02Automated Employment Decision Tools (Local Law 144)NYC Department of Consumer and Worker Protection
  3. 03Illinois Artificial Intelligence Video Interview Act (820 ILCS 40/)Illinois General Assembly
  4. 04General Data Protection Regulation (GDPR) Article 22EUR-Lex
ShareLinkedInXEmail

Read next in candidate experience

The newsletter

One edition roughly every two weeks: new articles, and what changed in hiring that is worth your time.

Back to all articles