Dark teal cover showing a short handwritten note beside a screen of system log entries, for an article on recording AI-assisted decisions about people.
Record keepingAI governanceData protectionHiringAccountability

AI helped you choose who to hire. You still have to prove it was fair.

Hiring, pay, promotion and redundancy selection now run through software that scores people. This is what to write down when it does, where to put it, and how long to keep it.

Good Transformer17 min read

If a candidate you turned down brings a discrimination claim, and shows enough for a tribunal to take it seriously, proving there was no discrimination becomes your job. And if the tribunal finds your explanation inadequate, it must decide against you.

Six months on, you go looking for that explanation. The tool that ranked the applications kept a record of who used it and when, and nothing about the decision.

So write two lines on the candidate's record at the time. Write what the tool recommended, and why you agreed with it or overruled it.

This is not only about hiring. It covers pay, promotion, selection for redundancy, and the price you quote one customer and not another. Separately from the burden of proof, the data protection rules on automated decisions changed on 5 February 2026, and most firms have not looked at them.

Why this is a 2026 question

Two years ago these tools wrote first drafts and a person made the decision. That separation has gone. Software now scores and ranks applications and moves them to the next stage, and the newer agent-style tools act on their own output without a person triggering each step.

The February change was substantial. The Data (Use and Access) Act 2025 replaced the old automated-decision provisions in the UK GDPR with a new set, Articles 22A to 22D. They came into force this February, and most firms have not yet looked at them.

The Information Commissioner's Office has moved from gathering evidence to setting deadlines. It spent ten months from March 2025 talking to more than thirty employers about automated recruitment. Its report says its key finding is that many of them "are likely relying on solely automated decisions as part of this process".

In the ICO's words, many employers "didn't consider that ADM was taking place", meaning automated decision-making. They had no safeguards, because as far as they knew there was nothing to safeguard. The ICO has since written to them with recommendations and "a set date to take the necessary steps", and sixteen have confirmed they will act.

The Department for Science, Innovation and Technology is now asking businesses whether the test for meaningful human involvement works in practice. Its call for evidence opened on 15 July 2026 and closes at 11.59pm on 9 September. If you have a view on what this costs a twenty-person firm, that is where to say so.

Which decisions count

"Decisions about people" is too vague to work from. Draw the line at decisions that change what happens to someone.

In scope:

  • Who gets shortlisted, and who gets rejected
  • Who gets an offer, and at what salary
  • Pay reviews, bonuses and promotions
  • Performance ratings that feed into any of those
  • Selection for redundancy
  • What you quote a particular customer, and which prospective client you turn away

Out of scope are tools used to draft an interview question, tidy a job advert, or summarise a document you then read yourself. The test is whether the tool's output decided the outcome. If you read the source and formed your own view, the tool helped you work. If you acted on what it produced, it helped you decide.

It helps to separate three things. Some decisions are made by software alone with no meaningful human involvement, and those carry the specific legal safeguards set out below. Some are made by a person with an AI score or ranking pushing hard on the outcome, and those sit outside those safeguards but still carry fairness, evidence and data-protection risk. And some are just AI helping you work, where no decision record is needed.

This article is mostly about the middle one, because that is where most small firms actually are.

Which makes the ranking case awkward. A tool that ranks fifty applications and puts eight at the top has shaped what happens to the other forty-two, even if a person formally approves the shortlist. Whether that counts as a solely automated decision in law depends on what the reviewer did. Someone who read the applications, knew the tool's limits and could have changed the result was meaningfully involved. Someone who waved the ranking through was not. Either way, record how the ranking was reviewed, because that is the fact anyone will later want.

One thing sits outside all of this. Staff using their own personal chatbot accounts leave no organisational record at all, and we have written separately about what shadow AI use is telling you.

What your tools actually record

Most firms assume that because everything is logged, everything is recoverable. It is not, and three of the four vendors below document that themselves.

Microsoft 365 Copilot. The audit record carries who, when, where, and a list of the files and messages Copilot accessed. It does not carry the text of the prompt or the reply. Microsoft's own worked example shows the message attribute holding an identifier where the words would be.

The prompts and responses are stored separately, in the user's mailbox, and can only be retrieved through a legal discovery process. Audit retention for Copilot is 180 days by default.

Claude for Work. Anthropic's activity feed is kept for six years, which sounds generous until you read what is in it. In Anthropic's words, it "does not capture the prompt text or model responses inside chats or messages". The exportable audit log is narrower still: "Title and content of chats and projects are not available to be exported in audit logs (only their unique identifiers will be exported)."

Google Workspace with Gemini. The documented log attributes are actor, action, event, application, date, address and device. There is no content field at all, and retention is six months.

Google Vault can preserve prompts and responses for the standalone Gemini app, but Google lists Gemini for Google Workspace among the services Vault does not support. So Gemini working inside Docs, Gmail and Meet has no content preservation of its own.

OpenAI. What its compliance interface records, and for how long, is not publicly documented: the public page points to a document only a signed-in administrator can open. That is not a criticism, and it does not mean the capability is missing. It does mean you cannot check what is recorded before you sign a contract.

Then there are the traps that catch small firms specifically, and none of them involve AI at all:

  • Revision history expires. Airtable's free plan keeps two weeks of revision history. A Google Drive version "might be permanently deleted after 30 days or if there are 100 newer versions".
  • Assessments can be quietly rewritten. Workable is explicit that an author can change an evaluation after the fact. Greenhouse handles this properly: an edited scorecard carries an "Edited" label, and hovering over it prompts the team to ask the interviewer why it changed. In our experience most products behave like Workable.
  • Some tools do not log at all. Breathe, a British small-business HR product, addresses this in its own help centre. It asks whether the product has an activity log of recent user actions, and answers no.

The pattern is consistent. Your software records that someone used it, not what they concluded. Some of that record can be edited afterwards without trace, and much of it is gone inside six months.

Is this the law, or is it good practice?

It is both. It is worth knowing which is which before you write a policy.

This is law, and it applies to you now. Article 5(2) of the UK GDPR says a controller "shall be responsible for, and be able to demonstrate compliance with" the data-protection principles. The duty is to be fair and to be able to show you were fair. You cannot show that from memory a year later.

One related point catches people out. Employers with fewer than 250 staff are generally excused from documenting their processing activities. The exemption falls away where the processing is regular, or is likely to risk people's rights and freedoms, or involves special category data. Repeated AI screening or scoring of candidates and staff is unlikely to be occasional, and it can create a risk to people's rights and freedoms, so the exemption often will not cover it.

This is also law, and it is the part that decides whether you can defend a claim. Section 136 of the Equality Act 2010 says that where a claimant proves facts from which a tribunal could decide there was a contravention, the tribunal must find that it occurred, unless the employer shows it did not. The burden of proof moves to the employer.

There is a limit, and it matters. The burden only moves once the claimant has proved those facts, so a missing record does not by itself create a claim. It is what leaves you unable to defend a claim once one is brought. The statutory Code of Practice puts the consequence plainly: if the employer's explanation is inadequate or unsatisfactory, the tribunal must find the act unlawful.

A different regulator has made the same point about what oversight has to look like. A review published by the Financial Conduct Authority in July 2026 put it this way:

"Human oversight and accountability will remain critical and many respondents underscore its importance. But it will not be enough to say that a person remains 'in the loop.' Firms will need to be clear about what the person is expected to do, what information they receive, when they can intervene, how challenge is recorded and how escalation works."

That is a review rather than a rule, and it was written about retail financial services. We think the same expectation is reasonable well beyond it.

This is law, but it is probably not about you. Article 22C applies only to decisions "based solely on automated processing", which Article 22A(1)(a) defines as decisions taken with "no meaningful human involvement".

If a real person genuinely made your call, you are outside it, and a rejected candidate generally cannot require you to explain an AI-assisted decision. We have written separately about why an explanation is not the same thing as an audit trail.

This is not law yet. The ICO's test for meaningful human involvement is draft guidance, published on 31 March 2026 and consulted on until 29 May. Its own page still describes it as draft. It has five parts. For involvement to be meaningful, a human should:

  1. "assess and review the decision at an appropriate point to ensure actual impact on the outcome"
  2. "have the ability to influence the outcome"
  3. "have discretion and authority to alter the decision"
  4. "be suitably trained and qualified to understand the system's logic, outputs, limitations, and risks"
  5. "take into account the relevant data and factors on which the decision was based"

Two further sentences are worth having in front of you, because a final version is coming. On the record itself: "You should keep a record of how the human was involved in the decision." And on the shortcut most firms rely on: "Using ad hoc spot-checking isn't sufficient because some automated decisions won't receive a check and therefore don't have meaningful human involvement."

A code of practice has been ordered but not written. Regulations made on 16 April 2026, in force since 12 May, require the Commissioner to prepare a statutory code of practice on artificial intelligence and automated decision-making. There is no draft and no published date.

So you are being asked to meet a standard that has only ever been written down in a consultation draft. Write something down now rather than wait for it.

For the wider picture, we have covered the rules on automated decisions and when you need a data protection impact assessment.

The decision log

The whole thing is two lines, written where you already record the decision:

What the tool produced: ranked all 34 applications, top 8 by score. What we did with it, and why: took 5 of the top 8, dropped 3 with no operations experience, added 1 from rank 14. J. Okonjo, 3 August 2026.

The part that does the work is what the reviewer actually checked. "Reviewed and approved by the hiring manager" is a record of nothing. "Read all 34 against the essential criteria, checked the five just below the cut-off, moved one up" is evidence.

Write it most carefully on the days you agree with the tool. Agreeing does not feel like deciding, so that note is the one nobody thinks to make. It also fits what the ICO found, which is that employers did not realise a decision was being made at all.

A row that reads "went with the tool's ranking, checked all 34 against the job description first" is a record of a real check. A row that reads "went with the tool" is a record of no check. It is better to know that now than to discover it in a tribunal.

Two lines is the minimum, not the answer to everything. For recruitment screening, redundancy selection, pay and pricing, keep the fuller version below. Copy the table and fill one row per decision. The last two columns are the only ones that take any thought.

Date Decision Tool and version What it was given What it produced What the reviewer checked Final decision, and who made it
2026-08-03 Shortlist for the operations role, 34 applications down to 6 Recruiter Pro, CV screening, ranked list The 34 CVs and the job description Ranked all 34; top 8 by score Read all 34 against the essential criteria, not just the top 8. Checked the five immediately below the cut-off. Noted that the score did not weight operations experience. Took 5 of the tool's top 8, dropped 3 with no operations experience, added 1 from rank 14. J. Okonjo.

Where it goes, who writes it, and how long you keep it

Put the note in the record you already keep for that decision: the candidate's file, the pay-review form, the quote. A separate log is a second system, and second systems stop getting updated. If your firm makes these decisions in three different places, pick the record that is already kept reliably and put all the notes there.

The reason has to come from whoever was responsible for the decision, which is often not the person who ran the tool. If a coordinator runs the screening and a partner picks the shortlist, the partner writes the last column.

Do not set the retention period from the claim deadline alone. A discrimination claim in an employment tribunal generally has to be brought within three months of the act complained of, though a tribunal can allow longer where it thinks that just and equitable, and the case itself can then run for a long time.

That deadline is also due to move. Parliament has already legislated to raise it to six months, in Schedule 12 to the Employment Rights Act 2025, which changes the three in the Equality Act to a six. That paragraph is not yet in force. The government's timetable puts the tribunal time-limit changes at 1 October 2026, and the regulations doing the same job for several other claim types come into force on that date.

So set your own figure from your data-protection policy, not from this article, and do not land on six months just because your software happens to keep six months. A vendor log expiring at six months will often be gone before anyone asks, which is why the note has to sit in your own records rather than the vendor's.

Could the note be used against us?

This is the question three separate readers asked before we published. Yes, the note is disclosable. If a claim is brought, a document recording how a decision was made is very likely to be handed over. It will then be read by people who were not there.

Two things follow, and neither is "write less".

First, write it as if it will be read, because it may be. That means writing the reason, not your impression of the person. "Dropped, no operations experience" is a reason. "Not a fit" is not, and it reads badly in a hearing precisely because it says nothing.

And write the reason you actually used. Do not go back later and supply a better-sounding one. The record is only worth having if it describes the decision that was really made.

Second, having no note does not leave you where you started. It puts you in front of a tribunal with a burden that has already moved and nothing to discharge it with. If you cannot write a real reason for a decision, the problem is the decision, not the note.

Keeping this proportionate

None of this asks for a management system. The Financial Reporting Council, writing about AI in audit, made the point that proportionate documentation matters because "over-documentation can divert time and resource from areas where they can better enhance audit quality". The same is true here, and it is why two lines will do rather than a form.

Where to start this week

  1. Name the decisions in your firm where AI scores, ranks or recommends an outcome affecting a person. There will be fewer than you fear, probably four or five.
  2. Decide which need the two lines and which need the fuller table.
  3. For each one, name the single place the note will live, and name the person responsible for writing it. A rule nobody owns does not happen.
  4. Add it to whatever form or record already exists there, so nobody has to remember a new habit.
  5. Look at one decision you made last month and try to reconstruct why you made it. Whatever you cannot recover is the argument for the other four steps.

Want us to look at which of your decisions AI is already shaping, and what a proportionate record looks like for a firm your size? Book a conversation and we will work through it with you.

Common questions

Does this apply if a person makes the final call? Yes. A real human decision takes you outside the Article 22C safeguards. It does not take you outside Article 5(2) accountability, and it does not affect the burden of proof in a discrimination claim.

Is a written policy enough? No. A policy says what should happen. The record says what actually happened. In a case earlier this year, the court's judgment quoted the firm's own written AI policy, and the firm still put a made-up case citation before the court on two separate occasions. We covered that in our piece on what to do when AI goes wrong.

What if we have been doing this for two years with no records? Start recording properly now, and never write a note that reads as though it was made at the time when it was not. If an earlier decision genuinely needs reconstructing, label it as a reconstruction, say when you wrote it and what you based it on, and say plainly what you can no longer establish. That is honest and still useful. A note that is backdated by implication is neither.

Do we have to tell candidates we use these tools? Your privacy notice has to be specific enough for people to understand what happens to their data. The ICO's finding was that most of the privacy information it reviewed was not specific enough. That sits outside the decision log, and it needs doing too.


This is general information, not legal advice. It describes the position in the United Kingdom as at 3 August 2026. If a decision matters enough to be challenged, take advice on your own facts.

Work with Good Transformer

Turn this thinking into working practice.

Explore team advisory

Newsletter

Get new Insights by email

Practical notes on using AI with judgement, and the AI news leaders actually need. No hype, no spam, unsubscribe anytime.

Choose how often you want the digest

Keep reading

AI procurement15 min read

The four things to check before you buy an AI tool

Before you sign up to any AI tool, check four things: whether it trains on your data, where it is stored, what it can do once connected, and how you leave. The catch nobody mentions: at the tiers small firms buy, no one answers your email, so the answers are in the vendor's own terms.

22 July 2026

Client confidentiality22 min read

Keeping client confidentiality when you use AI

Client information may only leave the firm if the law allows it or the client agrees. An AI tool is run by another company, so that agreement belongs in your engagement letter.

30 July 2026