The Human in the Loop Is Standing Right Behind You
AI generated …….’he’s behind you’!
He's there. He's nodding. He's clicking approve. And the ICO has just asked, rather pointedly, whether he can actually do anything at all.
Every good pantomime needs a moment where the audience knows something the hero does not. He's behind you! we all shriek, delighted, while the poor soul on stage peers earnestly in precisely the wrong direction. It is a very old joke, and it works every time, because there is something irresistible about watching someone believe they are safe while the danger stands grinning just over their shoulder.
I mention this because a great many UK employers are currently starring in exactly this pantomime, and they do not yet know it is a comedy.
The setup is familiar. You have adopted AI somewhere in your hiring. Perhaps it screens CVs, perhaps it scores candidates, perhaps it runs the first-round assessment while everyone sleeps. And when your data protection people asked the nervous question, are we allowed to let a machine make these decisions?, you gave the answer that has soothed a thousand boardrooms. "It's fine. There's a human in the loop."
A human in the loop. What a wonderfully reassuring phrase it is. It conjures a wise, coffee-clutching professional, brow furrowed, weighing each candidate with the care of a judge at a village marrow competition. Surely, with that person in the process, no machine can lead you astray.
The Information Commissioner's Office has looked at your human in the loop. And in 2026, with the polite firmness of a regulator who has seen this trick before, it has asked the question the whole audience was already thinking. Can he actually change anything? Or is he just standing there, nodding, clicking approve?
"There's a human in the loop" has soothed a thousand boardrooms. The ICO has looked at that human and asked, politely, whether he can do anything at all.
The report that named names
This is not me theorising about what a regulator might think. In 2026 the ICO published a report on automated decision-making in recruitment, built on evidence from more than thirty employers, and it did something regulators do only when they mean it. It wrote to sixteen named organisations. Not a gentle newsletter. Letters. The kind that arrive with your name on them and ruin a Thursday.
And the central finding was quietly devastating. Employers told the ICO their AI tools were merely decision support, with a human making the final call. But when the ICO looked at what was actually happening, it found tools making the substantive decisions and human review that amounted to, and I use the technical term, rubber-stamping. The shortlist appears. The human glances. The human approves. The human could not realistically have done otherwise, because to overturn the machine would mean re-reading four hundred CVs by hand on a Friday afternoon, and nobody, but nobody, is doing that.
The ICO gave this pantomime a proper definition, and it is worth committing to memory because it is the whole game. Meaningful human involvement, they said, requires a reviewer with the authority, the competence, and the discretion to change the outcome before it takes effect. Scanning an AI-generated shortlist and clicking approve does not meet that bar. Your human is not in the loop. Your human is decorating it.
Why "the machine did it" has never once worked
Now, some readers will be thinking: fine, but if the tool gets it wrong, that's the vendor's problem, surely. I bought the thing. Let them answer for it.
I refer you, gently, to the growing pile of cases in which precisely this argument was tried and precisely this argument failed. When a company's AI does something unlawful, "the machine did it" enjoys roughly the same success rate as "the dog ate my homework," and for the same reason: everyone can see who was actually holding the leash. Under the Equality Act 2010, discrimination produced by an algorithm is discrimination. Indirect bias baked into a hiring model is unlawful in exactly the way it would be if a human had done the biasing by hand. The candidate does not sue the model. The candidate sues you.
"The machine did it" enjoys roughly the same legal success rate as "the dog ate my homework," and for exactly the same reason.
And the ground is only getting busier. The Data (Use and Access) Act 2025 updated the UK's rules on automated decisions and is precisely what the ICO's guidance interprets. If your business has any EU exposure, the EU AI Act classes AI recruitment tools as high-risk, adding an entire second layer of obligations that a tool passing the UK test may still fail. Multinational employers, marvellously, get to satisfy UK GDPR, EU GDPR and the EU AI Act as three separate assessments, each convinced it is the important one. It is a lot of nets, and, as regular readers will know from what I have written about AI vendor contracts, having many nets is not the same as having one that holds.
What the reformed employer actually does
Here is the good news, delivered before you swear off hiring software and go back to reading CVs by candlelight. The ICO is not trying to ban AI in recruitment. It is asking you to stop performing oversight and start doing it. The difference is entirely practical, and it comes down to a handful of things.
Requirement One
Meaningful involvement means the reviewer can genuinely change the outcome: they have the time, the information, the authority and the competence to overrule the machine, and sometimes do. If overturning the tool is practically impossible, you do not have a human in the loop, you have a mascot. Build a process where disagreement is realistic, not theoretical.
Requirement Two
Be transparent that AI is being used, how it works, and what it does in the process. The ICO also found that many employers did not even recognise they were doing automated decision-making, which is a difficult position from which to be transparent about it. Step one is admitting the machine is in the room.
Requirement Three
Monitor and test regularly for biased outputs, and apply your human review consistently across every candidate in a stage, not just the borderline ones. Good practice, per the ICO, includes asking your vendor about their own bias testing, which conveniently is also a contract and due-diligence question, not merely an HR one.
Requirement Four
Candidates must be able to challenge a decision and ask for genuine human review. And be warned: applicants increasingly exercise these rights using AI-generated requests of their own, which means the volume is rising and "we'll deal with it manually" is not a plan. It is a bottleneck waiting to become a complaint.
Notice that three of those four are really about vendor due diligence and process design, which is to say they begin long before a candidate ever applies. They begin when you choose the tool and sign the contract for it, and they live in the DPIA you did or, more often, the DPIA you meant to do.
The curtain line
Here is what I would want a fellow leader to walk away with, jokes aside, because beneath the pantomime this is a real and rising exposure. Nearly seventy per cent of UK employers expect to increase their use of AI in hiring. The ICO has made clear it regards most of them as not yet understanding the rules. And the single most common and most dangerous belief in the room, "it's fine, there's a human in the loop," is precisely the one the regulator has now taken apart.
So the question is not whether you have a human in the loop. Everyone says they have a human in the loop. The question, the one the ICO is now asking and the one a claimant's solicitor will ask after, is whether that human can actually do anything, or whether they are simply standing behind you, nodding along, while the decision that matters was made three steps earlier by a machine nobody quite audited.
He's behind you. The trick is making sure he can turn around.
Make sure your AI hiring stands up to the ICO, and to a claimant
RMOK Legal advises UK businesses on AI governance, automated decision-making and the contracts behind the tools, for a fixed fee confirmed before any work begins, handled personally by a senior solicitor and SCL AI Committee member. If you use AI anywhere in hiring, it is worth knowing whether your process would survive scrutiny.
Book a free discovery call →This article is general commentary on AI governance and UK employment and data protection law in 2026 and is not legal advice. It does not create a solicitor-client relationship, and outcomes depend on the specific facts. Regulatory positions referred to, including ICO guidance, the Data (Use and Access) Act 2025 and the EU AI Act, were accurate at the time of writing and continue to develop. For advice on your situation, speak to a qualified solicitor. RMOK Legal solicitors are authorised and regulated by the Solicitors Regulation Authority. For related reading, see our EU AI Act compliance guide and our AI governance service.

