On 21 May 2024, the European Council approved the AI Regulation. This Regulation will enter into effect soon. It contains a number of transition periods that will delay the applicability of certain obligations. The Regulation sets requirements and frameworks for the development and use of AI systems by, among others, employers. It is intended to give room to innovation and economic development while protecting important values, such as privacy.
Employers are increasingly using AI for purposes of recruitment and selection. Examples are a tool that screens the CVs of applicants and sequences them according to suitability; automated video interviews that analyse the applicant's body language or facial expression; or Unilever that uses Pymetrics: a program that assesses applicants online by making them play games for one hour and assessing their traits shown in this process, such as curiosity, adaptivity and risk tolerance. The deployment of AI often allows employers to work cost-efficiently.
Regulation on AI
The deployment of such systems may be covered by the new AI regulation, to be discussed below. In fact, the Netherlands already has many regulations that currently apply to the deployment of AI by employers. AI systems use enormous quantities of data, process this data in real time and make decisions based on this data in the form of recommendations or predictions. In recruitment and selection, this entails risks in the fields of privacy and unequal treatment (discrimination).
Anti-discrimination
For example, the algorithm's original (training) data may give rise to discriminatory bias, for example if the AI system uses a data set that is not representative. Take the recruitment tool of Amazon, which was able to make automated analyses of the CVs of many applicants. However, this tool later turned out to discriminate between men and women in its selection of applicants. The reason was that the tool had learned which applicants to select by analysing all CVs the company had received since 2004. As most of these came from men, the application robot learned that men should be given preference. CVs that contained the word ‘women’, as well as graduates from schools for women or CVs with typically female traits such as perfectionism, empathy and helpfulness, were therefore disadvantaged.
Discrimination based on gender is prohibited in the Netherlands. Indirect discrimination is also prohibited; this refers to unequal treatment that is not in itself discriminatory (for example, the criterion of 'successive employment' is not in itself discriminatory), but that does affect one specific group more than another group. In this case, women.
This risk not only plays a role in discrimination based on gender, but also in discrimination based on migration background or disability. As described above, AI differs from other selection methods in that not only its search criteria can be indirectly discriminatory, but also the data to which the information searched is compared. Take the existing male workforce at Amazon. This problem could be prevented if the output of AI tools could be tested constantly, which would allow the tools to be improved; but this is precisely where things go wrong in practice. On the one hand it is not considered a priority, and on the other hand privacy laws prohibit the processing of certain data (and therefore the auditing of systems). Think of special personal data, such as data on race or data on an applicant’s health. This means that employers often do not even know and cannot know whether an applicant has a migrant background, or whether remarkably few candidates with a migrant background have passed the selection process, whereas the system has indeed indirectly discriminated against this group.
Options for job applicants and employees
Violation of anti-discrimination regulations when AI is used may lead to claims for liability from applicants, or to higher severance payments in dismissal proceedings. The first place candidates turn to is often the Netherlands Institute for Human Rights (College voor de Rechten van de Mens), which will then rule on their complaint. With that ruling in hand, it is easier for candidates to claim damages. On the basis of its rulings the Institute has developed guidelines for the deployment of AI in recruitment and selection, and it tests complaints against these guidelines. The key point is that employers must be able to explain in what ways the algorithms work, and must be able to explain why they believe there is an objective justification for indirect discrimination. The selection procedures have to be transparent, verifiable and systematic, and the employer – not the provider of the software – is legally responsible for the AI tools it uses. If you, as an employer, are confronted with an employee's complaint to the Institute, you should ensure not only to act in line with anti-discrimination laws, but also to follow the Institute's specific guidelines.
The Netherlands Institute for Human Rights protects and promotes compliance with human rights in the Netherlands through education, research, advice, cooperation and monitoring of equal treatment issues. While digitisation offers opportunities for more effective human rights protection, such as access to information and care, it also involves risks, such as discrimination by automated processes and irreducible decisions taken by algorithms. This is the reason why the Institute launched the Digitisation and Human Rights Strategic Program in 2020.
Privacy
The GDPR and the GDPR Implementation Act (“GDPR IA”) prohibit the processing of special personal data, like data on race or ethnic origin, health, and biometric data, unless there is a statutory exception for such processing. These are the prohibitions employers have to take into account when implementing AI tools. Besides, a wide range of regulations apply to the deployment of monitoring of job applicants. Monitoring is broader than AI and regards the deployment of digital systems that monitor the conduct and performance of applicants. European human rights protection laws, the Netherlands constitution and the GDPR and GDPR IA contain regulations on the deployment of monitoring, as does the Works Councils Act, which requires that the consent of the Works Council is sought for any projected decision to implement a staff tracking system. In practice, we see that the courts are judging the deployment of monitoring ever more strictly if the results of monitoring are used to substantiate a dismissal. When monitoring is found to have been used unlawfully, the courts regularly impose a fair compensation or even brush evidence aside. It is to be expected that the courts will take an equally critical stance on decisions that are based on AI.
Supervision of Equal Opportunities in Recruitment and Selection Act
On the AI front, it is interesting to note that in March 2024, the Dutch Senate rejected (by a small majority) the Supervision of Equal Opportunities in Recruitment and Selection Act. This Act contained specific obligations for employers who use AI in recruitment and selection, such as the introduction of anti-discrimination policies, the obligation to verify with AI systems that they do not cause discrimination, and a record-keeping obligation. The Dutch Labour Inspectorate would become responsible for enforcement, which would mean that breach of this Act could lead not only to liability and high severance payments, but also to fines for employers. The current government makes it unlikely that a similar act will still be introduced any time soon.
AI Act
Obligations similar to the above are indeed set out in the AI Regulation, which applies to the deployment of high-risk AI systems. AI systems intended to be used for recruitment or selection of candidates, notably for advertising vacancies, screening or filtering applications, evaluating candidates in the course of interviews or tests, are qualified as high-risk AI systems. It would lead too far afield to go into all obligations for employers in the Regulation, but it is important to be aware of the following rules:
(i) employers have to comply with the instructions of use of the AI software. The instructions of use must contain human oversight;
(ii) The input data must be relevant in view of the intended purpose;
(iii) if there is an increased risk, the employer has to notify the Dutch Data Protection Authority thereof;
(iv) it is mandatory to perform a DPIA; and
(v) there is an obligation to provide employees with information.
Failure to comply with the obligations from the Regulation carries a potentially high sanction for employers: a maximum penalty of EUR 15 million or 3% of their total annual turnover.
Conclusion
Although we already have relevant legislation in the Netherlands, the AI Regulation seems to be a welcome instrument for the protection of employees. The common denominator of all obligations is to increase transparency about the use and the consequences of AI systems. This is something employers can already start working on.