AI hiring is already a legal risk: What Australian employers can learn from overseas
SHARE THIS ARTICLE
Australian employers should not wait for AI-specific hiring regulation before putting safeguards around recruitment technology, one expert has said, noting that existing employment and anti-discrimination laws already create obligations for businesses using AI to screen and assess candidates.
As AI tools increasingly move into CV screening, candidate assessment and recruitment recommendations, Deel global head of policy Nick Catino (pictured) told HR Leader that employers risk treating regulation as a future problem when the legal framework to address discriminatory outcomes already exists.
“Employers can’t afford to wait for AI hiring regulations to catch up,” he said. “In Australia, job applicants are legally protected from discrimination, so reckless use of AI tools can potentially put employers at risk of breaking the law.”
Catino said the risk is not limited to AI systems that have been deliberately designed to discriminate: “AI doesn't have to be designed to discriminate to cause real harm. Even if your criteria seem fair on the surface, if they unfairly exclude certain groups, they're still illegal.”
The existing Fair Work Act 2009, and federal discrimination laws covering race, sex, age and disability, provide an important baseline for employers, meaning HR teams can begin strengthening governance without waiting for a dedicated AI hiring regime.
From policy to practice
For organisations already using AI in recruitment, Catino said the first step should be establishing clear boundaries around what the technology cannot do.
That includes prohibiting automated ranking, numerical candidate scoring, personality inference from CVs or interviews, and AI-generated hire or no-hire recommendations. Catino also warns against using “culture fit” comparisons based on historical employees, which can reproduce existing patterns in a workforce.
“AI should never make or recommend a hiring decision,” Catino said.
Instead, employers should maintain a short list of approved AI tools and use cases, with human oversight built into the recruitment process.
Recruiters should review every sourced profile before contacting a candidate and every application before advancing or rejecting it. Similarly, verification technologies such as deepfake detection should not automatically trigger adverse action without human review.
Candidates should also be told when AI is being used and given access to a manual review process, Catino said.
The approach is designed to make AI a support tool rather than the decision-maker. Candidate assessments should be based on defined competencies such as problem-solving, adaptability, customer focus and ownership, alongside role-specific communication and technical capabilities.
“Observations must be written by people, with AI only structuring what they have already documented,” Catino said.
“Hiring managers can override any AI output and must document why. Rejection reasons are authored by humans, never pulled from algorithm flags or scores.”
Overseas lessons are already emerging
International jurisdictions offer Australian HR leaders a glimpse of what more prescriptive regulation can look like.
In New York City, employers and employment agencies using covered automated employment decision tools must meet requirements including a bias audit, public disclosure of audit information, and candidate notification. The European Union is taking a broader risk-based approach. Under the EU AI Act, certain AI systems used in employment are classified as high-risk, with obligations covering areas including risk management, data quality, logging, documentation, human oversight and accuracy. The employment-related high-risk rules are scheduled to apply from December 2027, under the current implementation timeline.
For Australian employers, Catino said the lesson is not simply to copy overseas regulation, but to build governance that can adapt as requirements evolve.
“The answer is both: one global standard with market-specific adaptation,” he said.
That global baseline should include prohibitions on automated ranking, sentiment analysis, numerical scoring, AI-generated hiring recommendations and direct or indirect discrimination. Local requirements can then be layered on top, including notification, bias auditing, data retention or disclosure obligations where required.
Accountability is the missing piece
Catino said one of the biggest differences between effective AI policies and policies that merely look good on paper is accountability.
“Policies that fail in practice lack accountability mechanisms and clear implementation pathways,” Catino said. “They use aspirational language without specifying who enforces the policy, how violations are caught, or what consequences exist for breaches.”
Effective governance, he said, should require hiring managers to document their reasoning when accepting or overriding AI outputs, regular training on competency frameworks, audits for demographic drift and policy breaches, and progressive enforcement for non-compliance.
For Australian employers, the opportunity is to establish those systems before regulation makes them mandatory.
“By moving now and contributing to the conversation, organisations can ensure that regulation becomes reinforcement rather than disruption,” Catino said.
RELATED TERMS
Compliance often refers to a company's and its workers' adherence to corporate rules, laws, and codes of conduct.
The practice of actively seeking, locating, and employing people for a certain position or career in a corporation is known as recruitment.
Want to see more stories from trusted news sources?Make HR Leader a preferred news source on Google.