AI in HR: improve recruitment, onboarding and employee support
A recruiter needs an interview outline, a new hire cannot find the equipment request form, and an employee wants to understand a leave policy. AI can help with all three. The consequences change sharply when the same tools start ranking applicants, assessing workers, or answering sensitive questions from incomplete information.

Start with the HR task and the person affected by it. Drafting an email, finding an approved policy, and deciding who gets an interview are different activities, even when the supplier presents them in one interface. Each needs its own purpose, inputs, review, and escalation path.
A useful implementation reduces repetitive work while keeping employment decisions explainable and contestable. It also makes routine information easier to find without exposing a personnel file to the wrong person. These outcomes require more than selecting a capable language model.
01Choose the task before choosing the AI tool
List the requests your HR team handles repeatedly. Identify where employees wait, where information is inconsistent, and where administrators copy data between systems. Separate those problems from decisions about suitability, pay, promotion, performance, or dismissal. Automating a slow process does not resolve unclear criteria or an outdated policy.
For a growing services company, an initial pilot might answer equipment and orientation questions from approved documents. Another might help recruiters draft structured interview questions against a defined role. Both can be useful without automatically scoring a person. The scope should say explicitly what the tool may produce and what it may never decide.
| HR workflow | Useful assistance | Control to define first |
|---|---|---|
| Recruitment preparation | Draft role descriptions and relevant interview questions | Recruiter checks job criteria, accuracy, accessibility and wording |
| Applicant information | Summarize evidence already supplied for the role | Reviewer checks original material; no hidden filtering or unsupported inference |
| Onboarding | Find approved steps, forms and role-specific orientation resources | Policy owner approves sources; managers confirm personal plans |
| Employee support | Answer routine questions with links to current policies | Permission checks, source dates, uncertainty and a human contact |
| Employment decisions | Support a clearly reviewed and authorized decision process | Legal classification, meaningful oversight, evidence and challenge route |
Give the pilot a named HR owner and a technical owner. The first maintains the process and source information. The second maintains access, integrations, testing, and failures. If either responsibility is missing, the tool is likely to become another place where employees receive conflicting answers.
02Use recruitment assistance without hiding the selection process
A recruiter can supply a role's actual responsibilities and ask for an interview outline. The reviewer should remove irrelevant questions, confirm that requirements are necessary, and check that the wording does not imply qualifications the job does not need. A polished draft is still a draft.
Summaries need closer attention. A model might omit a relevant project, mistake an employment gap for lack of experience, or turn uncertainty into a confident claim. Keep access to the original application and require the reviewer to verify evidence. Do not let an attractive summary become a separate, unchallengeable candidate record.
Ranking and screening introduce a different risk. Decide what the system measures, how the criteria relate to the job, whether candidates can use an accessible alternative, and how errors are corrected. A recruiter who accepts every recommendation without time or authority to disagree provides little practical oversight.
In the United States, the Department of Justice's guidance on AI and disability discrimination explains that hiring technology can exclude qualified people with disabilities and that accommodation obligations can apply. That is a US legal context, not a universal rulebook. It is also a useful reason to test the complete candidate experience instead of only the employer's interface.
03Make onboarding specific without inventing obligations
A new employee needs an accurate route through accounts, equipment, training, introductions, and the first assignment. AI can assemble a proposed checklist from a role, location, start date, and approved onboarding material. A manager then confirms the actual sequence and responsibilities.
Keep administrative actions separate from generated suggestions. A proposed training session should not become an invitation until its owner approves it. An account request should go through the normal identity process, with the appropriate role and approval. Do not grant permissions simply because a chatbot inferred that the employee might need them.
Local differences matter. A global company may have different benefits, holidays, working arrangements, or required training across offices. Attach each source to its relevant population and effective date. When the tool cannot identify the applicable policy, it should ask a necessary clarifying question or refer the employee to HR.
Keep the human welcome. A clear automated checklist cannot explain every team expectation or resolve a confusing first assignment. Use assistance to prepare information and surface missing steps, then let managers and colleagues provide context. Our guide to user onboarding covers similar questions about progression and points where people get stuck.

04Build employee support around approved sources and access
An internal assistant can help employees find a leave form or explain where to request a laptop. It should cite the relevant approved document, identify important qualifications, and provide a direct route to HR. Avoid turning it into an authority on employment entitlements that vary by contract or location.
Start with a small, maintained knowledge collection. Remove duplicate policies, assign owners, and distinguish draft material from current guidance. Search and generated answers will reflect the content supplied; adding AI to a disorganized shared drive often makes contradictions harder to notice.
Permissions must follow the person asking the question. Microsoft's SharePoint knowledge-source documentation describes authentication and user access requirements for that integration. This is a product-specific capability to configure and test, not evidence that every chatbot automatically respects your existing permissions.
Test with employees from different roles and locations. A person allowed to read the general handbook should not retrieve a manager's private case notes. Sensitive requests about illness, complaints, payroll disputes, or another employee should reach the appropriate protected channel. The assistant needs a useful refusal and escalation path, rather than an invented answer.
05Review employment and privacy rules in the relevant markets
Legal requirements follow the use, affected people, organization, and jurisdiction. Map where applicants and employees are located and which rules apply before rolling out across countries. Employment law, privacy law, accessibility obligations, and sector requirements may continue to apply whether the supplier calls the feature AI or automation.
Within the EU AI Act's scope, Annex III includes specified employment and recruitment uses. A generic writing assistant is not automatically equivalent to a candidate-ranking system. Classification needs the actual intended purpose, applicable conditions, and exceptions, rather than a label for the entire HR department.
As of 3 October 2026, the enacted 2026 amendment sets 2 December 2027 for Chapter III, Sections 1, 2 and 3, except Article 6(5), for high-risk systems classified under Article 6(2) and Annex III. It retains and simplifies support for staff AI literacy. Existing obligations and prohibitions need separate review; the later date is not permission to ignore today's employment or privacy rules.
Where the EU GDPR applies, the official regulation addresses purpose, lawful processing, data minimization, security, and relevant automated decisions. Article 22 concerns solely automated decisions with legal or similarly significant effects and contains conditions and exceptions. It is not a blanket ban on every AI-assisted HR task.
Ask qualified local advisers to review the concrete workflow where needed. Provide its inputs, outputs, decision authority, vendor arrangements, and affected groups. This makes the review more useful than asking whether AI in HR is generally allowed. The Commission's AI Act overview provides additional context, while the enacted legal text determines the precise provisions.
06Protect personnel data and test the actual result
Send only the information required for the defined task. A general onboarding assistant rarely needs medical records, disciplinary information, salary history, or complete applicant files. Establish retention for conversations and logs, access to them, and the process for correcting or deleting information when applicable.
Review what the supplier does with prompts, uploaded documents, model outputs, and diagnostic logs. Check contractual roles, subprocessors, locations, retention, and whether data is used for other purposes. A setting described as private does not answer every question about the service or your own integration.
Build tests from representative tasks: an outdated policy, a question outside scope, conflicting sources, a missing applicant detail, an inaccessible document, and a request for another person's information. Check the response, citation, permission boundary, and escalation. Record the version and configuration so changes can be evaluated.
For sensitive uses, review relevant differences across affected groups through a lawful and appropriate assessment. A single aggregate accuracy score can hide problems. Do not collect new sensitive attributes casually to make a dashboard look complete. Agree the method and evidence with the people responsible for HR, privacy, and the assessment.
07Run a pilot that measures help and catches harm
- Map one workflow. Define its purpose, users, sources, decision boundary and owner.
- Prepare the controls. Review access, vendor terms, relevant rules, human review and escalation.
- Test with real questions. Use approved examples and exceptions before limited employee access.
- Review and maintain. Compare useful outcomes, errors, effort and feedback before expanding.
Measure the work people actually need to complete. For an internal assistant, review whether employees reach the correct form or contact, whether sources are current, and how often HR must correct an answer. For recruitment preparation, review relevance and editing effort. Faster drafts alone do not demonstrate a better hiring process.
Include maintenance time and employee feedback in the decision. HR policies, roles, integrations, and model behavior change. Keep a way to disable an unreliable feature, route work to the normal process, and review changes before expanding access. A small, reliable service is easier to improve than a broad assistant with unclear authority.

08Questions about AI in HR
Where should a small HR team start?
Choose a repeated task with maintained sources and a clear reviewer, such as drafting onboarding checklists or finding approved forms. Define the task boundary and escalation before adding applicant evaluation or employment decisions.
Can AI shortlist candidates automatically?
That needs a separate review of the actual selection criteria, accessibility, oversight, relevant legal requirements, and challenge process. A capable ranking feature does not establish that its use is appropriate or lawful for your situation.
Does having a recruiter click approve solve the oversight issue?
The recruiter needs time, evidence, competence, and authority to question the output. Routine acceptance without checking the underlying information provides little practical protection against mistakes.
Can an employee assistant read our entire shared drive?
Limit sources to approved material and preserve user-specific access. Test different roles and sensitive requests. A product's permission features still need correct configuration, maintained documents, and verification.
Is every HR AI system high risk under the EU AI Act?
No. Review the intended purpose and applicable provisions within the Act's scope. Specified employment and recruitment uses appear in Annex III, but classification is more specific than calling an entire HR department high risk.
Do the later EU high-risk dates remove today's obligations?
No. The amended timeline applies to specified AI Act provisions. Existing prohibitions, relevant current AI duties, privacy requirements, employment law, and other applicable rules need their own assessment.
How do we know the pilot is worth continuing?
Review correct task completion, useful sources, review effort, access boundaries, failures, escalations, and employee feedback. Set acceptable conditions before the pilot and keep a practical route back to the normal HR process.