Policy

No US Law Gives Candidates a Right to a Human Reviewer. Europe Does.

A candidate rejected by an automated hiring tool has no right in the US to have a person look again: no statute in force in 2026 grants one. New York City requires a notice on how to request an alternative selection process where one is available, not a duty to grant one. In the EU, GDPR Article 22 bars a solely automated decision with significant effects; where contract or consent permits one, the person can demand human intervention. Where the GDPR reaches the processing, that right follows the candidate.

The takeOffer the review only if the workflow performs it. The reason is not the statute. A promise on a careers page is a representation a regulator can read back to you, and an appeal route landing in an unread inbox is a documented one. A genuine second look is also cheap at the volumes where automated rejection gets contested, and ten minutes spent on a decision that shapes someone's year is not a generous budget.

Where Olive fits

Open a role and see what the work shows

A person writes every word of an Olive report, so there is no automated outcome for a candidate to appeal. The candidate is granted the identical report the employer reads, free, on every tier.

Rank your shortlist

Which candidates can actually demand a person?

Candidates covered by EU data protection law. Article 22 of the GDPR gives a person the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects, and Recital 71 names e-recruiting practices without human intervention as an example. Where contract or consent permits such a decision, the safeguards include obtaining human intervention, expressing a point of view and contesting the outcome 1.

Everything turns on the word solely, and the word is doing more work than it looks. In the SCHUFA case the Court of Justice held that a credit agency's automated establishment of a probability value is itself automated individual decision-making where a third party receiving it draws strongly on that value 2. The case is about credit scoring, and no court has applied it to a candidate. What travels is the structural point: a formally human decider does not automatically move an automated output outside Article 22.

Nobody gets a right to be assessed by a person in the first instance. The right arises only after a decision that was already solely automated, and it attaches to that decision rather than to the tool, so publishing an explanation of how the system works does not answer it.

So the operative test is behavioral. A reviewer who has authority to reach a different answer, who occasionally does, and whose reasoning is written down looks like intervention. A reviewer who confirms the ordering every time is closer to ratification, whatever the process diagram says.

What does US law actually require?

Notice in a few places, and review nowhere. New York City's rule requires a bias audit within the prior year, a published summary and candidate notice at least 10 business days before an automated employment decision tool is used 3. The notice must say how to request an alternative selection process where one is available 7. No US statute in force requires you to have one, or to re-decide anything by hand.

That is the gap compliance templates get wrong. Candidate appeal turns up as a line item in policy drafts and vendor decks, sourced to nothing, and once it is written into a careers page it stops being optional in the only way that matters.

One state changes this, and not yet. Colorado's replacement law takes effect January 1, 2027 and requires notice at the point of interaction, a plain-language description of the technology's role after an adverse outcome, and a right to request meaningful human review 4. Read the verb: request. Note also that this law replaced an earlier act that was repealed before it ever applied, so a 2025 compliance memo about Colorado is describing a statute that never bound anyone. Confirm which rules reach you before building to any of them, because the map of what applies today has changed twice in two years.

Why offer a review nobody requires?

Three reasons, none of them a statute. A human who genuinely re-decides is the fact pattern that keeps a tool clear of the substantially-assist trigger in New York City's rule. A person on the other end is how a request for an accommodation on an assessment gets received at all. And the review produces the record a challenge asks for: a named person, a date, a reason.

There is a fourth if you hire into Europe. Article 86 of the EU AI Act gives a person affected by a decision taken on the basis of an Annex III high-risk system, where the decision significantly affects them adversely, the right to obtain clear and meaningful explanations of the system's role in the decision and the main elements of the decision taken 5. That right runs against the deployer, which is the employer, not the vendor. The substantive high-risk obligations for recruitment systems apply from 2 December 2027 after the Digital Omnibus moved the date 6, so this is a build-now, owe-later item rather than a live duty.

The thing being asked for is modest, which is easy to miss when it is described as a right. Article 86 covers the role of the system and the main elements of the decision, not the model, the weights or the training data. Most of it is answerable from records you should already hold. That is also most of what a candidate wants when they ask why the automated screen rejected them.

Write the promise you can actually keep

Write the sentence last, after the workflow exists. Decide who receives a request, what they re-read, how long they have, and what a reversal does to a requisition that may already be closed. Then write one line of notice describing exactly that. A published appeal route with no owner is worse than silence, because it is a written statement about a process nobody runs.

The spec fits on one page:

  • Owner. A named role, not a shared inbox, with a backup.
  • Window. A stated number of business days, short enough that the requisition is still open.
  • Scope. What the reviewer reads: the application, the output, the stage it failed, and the reason recorded at the time.
  • Authority. What the reviewer may change, and who signs off if the outcome moves.
  • Record. Who looked, what they saw, what they decided, kept on the same schedule as the original decision.

Set the window against your own calendar, because the requisition is the thing that closes. If requests routinely arrive after the role is filled, the honest promise is a re-read against the next opening instead of a reversal, and saying that plainly beats implying a door that has already closed.

And write down what you are not promising: a different outcome, a phone call, or an account of how the system works internally. A short, accurate description of a real process survives scrutiny. An expansive one drafted by somebody who has never run it becomes the first exhibit. This belongs in the same document as the rest of it, which is what an AI hiring policy needs to contain.

Read the evidence

Common questions

Does a recruiter glancing at a machine-ordered list count as human intervention?

Not automatically. Article 22 turns on the word solely, and a reviewer who never varies the output is doing something closer to ratification. In a credit-scoring case the EU court held that an automated probability value can itself be the decision where the party receiving it draws strongly on that value, and no court has applied that to a candidate. The workable reading: intervention means a person with authority to reach a different answer, who sometimes does, and whose reasoning is recorded.

Does the EU right apply if we are a US company?

Possibly, yes: what matters is the processing rather than where you are incorporated. Where the GDPR reaches your recruiting of candidates located in the EU, Article 22 travels with it. That is a question for counsel on your specific setup. The planning assumption is simpler than the analysis: if you accept applications from people sitting in the EU, do not build a flow whose rejection is fully automatic and unappealable.

What do we owe a candidate who asks why the AI rejected them?

In the US, no statute requires an explanation of the decision itself. What you owe is accuracy. Do not describe a process you did not run, and if a tool was used, saying so plainly costs nothing and matches any notice you already publish. Decide in advance how specific the answer gets, so two recruiters do not give two different accounts of the same system to two candidates.

If we offer human review, do we have to document it?

Nothing compels it, and the documentation is the point. The value of a review is the record it creates: who looked, what they saw, what they decided, when. Without that, an offered review is indistinguishable from a form reply, both to a regulator and to the candidate who asked. Keep it on the same retention schedule as the underlying decision, because the two documents only mean anything together.

Does offering human review take our tool outside the New York City rule?

It can help, and it is not a switch. The rule reaches tools that substantially assist or replace discretionary decision-making, and the employer makes that determination itself, with no advance blessing from the agency. A review nobody performs changes nothing. A documented step where a person reads the file and sometimes disagrees is a different fact pattern, and the documentation is what makes it one.

References

  1. 1. Regulation (EU) 2016/679 (General Data Protection Regulation), Article 22 - Automated individual decision-making, including profiling Official Journal of the European Union / Publications Office of the EU, 2016. publications.europa.eu Supports the Article 22 right against solely automated decisions and the human-intervention safeguard, with Recital 71 naming e-recruiting.
  2. 2. Judgment of the Court (First Chamber) of 7 December 2023, Case C-634/21, OQ v Land Hessen (SCHUFA Holding AG intervening) Court of Justice of the European Union / Publications Office of the EU, 2023. publications.europa.eu Supports the holding that an automated probability value can itself be automated individual decision-making where a third party draws strongly on it.
  3. 3. Automated Employment Decision Tools: Frequently Asked Questions NYC Department of Consumer and Worker Protection (DCWP), 2023. nyc.gov Supports the Local Law 144 bias-audit-within-a-year, published-summary and 10-business-day candidate-notice duties.
  4. 4. SB26-189 Automated Decision-Making Technology - Bill Summary Colorado General Assembly, 2026. leg.colorado.gov Supports the January 1, 2027 effective date, the plain-language description after an adverse outcome, and the right to request meaningful human review.
  5. 5. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Article 86 Official Journal of the European Union / Publications Office of the EU, 2024. publications.europa.eu Supports the Article 86 right to clear and meaningful explanations of the AI system's role, owed by the deployer.
  6. 6. Timeline: implementation of the EU AI Act European Commission - AI Act Service Desk, 2026. ai-act-service-desk.ec.europa.eu Supports the 2 December 2027 application date for Annex III high-risk systems, which is the category containing recruitment AI.
  7. 7. Notice of Adoption of Final Rule, 6 RCNY § 5-304 (Notice to Candidates and Employees), Subchapter T - Automated Employment Decision Tools NYC Department of Consumer and Worker Protection (DCWP), 2023. rules.cityofnewyork.us Supports that the notice must include instructions for requesting an alternative selection process if available, and that nothing in the subchapter requires an employer to provide one.

7 sources, numbered by first appearance. How Olive sources claims

General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.

Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.

Back to answers

Open your first role Ten attempts a month against a live item bank, with a human-written report on every one.