The AI That Screens Your CV on Its Own Is Illegal in Europe
The robot that rejects your CV alone, with no recourse, is largely a fantasy and mostly illegal in Europe. The sense of injustice, though, is very real.

The AI That Screens Your CV on Its Own Is Illegal in Europe
You hit send on your application. Somewhere, a machine reads it in a few milliseconds, ranks it, and you never hear back. No human eye, no explanation, no way to appeal.
That picture has a name: the ATS, the software that filters applications. It feeds a genuine anxiety. In its scariest version, it is also largely wrong.
Wrong in practice, because these tools are configured and monitored by humans. Wrong in law, because fully automated CV screening is largely banned in Europe. What is left is very real: the sense of injustice. And that one does not get settled by citing a statute.
What an ATS Actually Does
An ATS (applicant tracking system) centralizes applications, sorts them, and ranks them against criteria the recruiter sets: keywords, experience, location. Think of a search engine pointed at a stack of CVs, with a human at the controls.
Adoption is climbing without being universal. According to APEC, 27% of French companies used an ATS in 2025, a share that rises to 68-75% at organizations with more than 200 employees. On the recruiter side, Hellowork found in 2024 that 80% use one or plan to, up from 64% in 2018.
The fantasy is automatic rejection. The documented reality is duller. When asked, 92% of recruiters say their ATS does not remove an application on its own because of format, content, or design (2025 recruitment barometer).
What is actually happening is ranking. Out of 200 applications received for a management role, a recruiter reviews 30 to 50 on average. The rest are not deleted: they are buried at the bottom of the stack, too far down to be seen. The outcome looks like a rejection, but the mechanism is a visibility sort.
The Legal Wall Most People Ignore
Beyond practice, there is the law, and it is firmer than most assume. Since May 2018, GDPR Article 22 has laid down a clear principle: no one may be subject to a decision based solely on automated processing, profiling included, when that decision produces legal effects or significantly affects them. A hiring rejection issued by a machine alone lands squarely in that box.
Exceptions exist, such as a contract, a law, or explicit consent. Even then, the GDPR requires human intervention, the right to express your point of view, and the right to contest the decision. France's data protection authority, the CNIL, spells it out in black and white.
The AI Act adds another layer. It does not ban AI in recruitment; it classifies it as high-risk. Its Annex III explicitly places in that category systems that target job ads, filter applications, or evaluate candidates.
That label triggers obligations, the heaviest of which sits in Article 14: effective human oversight. The adjective is not decorative. The text wants a person able to understand what the system does, to override its recommendation, even to stop it. A recruiter who rubber-stamps without looking does not tick the box.
The Safeguard That Would Reassure People Just Got Postponed
This is where the story gets complicated. The guarantee many candidates would demand, real human oversight over hiring, does exist on paper. Its entry into force, however, has just been pushed back.
The Digital Omnibus, adopted in spring 2026, delays the obligations for high-risk systems from August 2026 to December 2027. Recruitment is part of the package. The rule meant to reassure candidates was therefore postponed by the very institutions that wrote it. We covered this gap between what citizens want and what their elected officials decide in a dedicated piece.
The Real Signal Is Not in the Code, It Is in People's Heads
So much for the myth. The unease remains, and it does not dissolve in the law. The feeling that the machine is deciding for you produces very concrete effects, even when the machine decides nothing on its own.
A study by Writer and Workplace Intelligence, conducted in late 2025 among 2,400 employees and executives in Europe and the United States, measures a form of pushback: 29% of employees admit to sabotaging their company's AI strategy, a share that climbs to 44% among the under-30s. In practice, they distort data, work around the tools, or feed them badly. AI has often been rolled out with a layoff threat in the background, and part of the workforce answers with quiet resistance, at the keyboard.
The context feeds the distrust. Unemployment among recent U.S. graduates aged 22 to 27 reached 5.6% in late 2025, against 4.2% for the workforce as a whole, according to the Federal Reserve Bank of New York. In computer science, it climbed to 7%. Automation is no longer content with repetitive tasks: it is moving up toward white-collar work and advanced degrees, the very people who thought a diploma kept them safe.
This is where the stakes shift. Knowing how many jobs AI actually destroys remains a number nobody controls. Measuring the political effects of the perception of that destruction is another matter, and probably the real one. A sense of injustice, once condensed onto a single word, AI, the algorithm, the ATS, becomes a force in its own right, whatever the figures behind it.
The French are already voicing it. According to an OpinionWay poll for CeSIA, 78% of them, from the far right to the socialists, back international agreements to ban uses of AI that threaten fundamental rights. This is not a lawyers' demand. It is a response to a fear. And a fear is not fixed by quoting GDPR Article 22.



