Tutorials12 min read

AI Agents for HR and Recruiting: Screening, Onboarding, and Automation (Done Safely)

AI agents can now run most of the HR lifecycle, from candidate screening to onboarding to employee support. But recruiting is legally high-risk, so the deployment model matters more than the model. Here is what HR agents actually do, and how to deploy them without creating bias, privacy, and compliance exposure.

In September 2023, a tutoring company agreed to pay $365,000 after the U.S. Equal Employment Opportunity Commission found its hiring software had been programmed to automatically reject more than 200 applicants because of their age. No recruiter made that call. A rule did. That case, EEOC v. iTutorGroup, is the clearest signal yet of where AI agents for HR go wrong: not in what they automate, but in what they are allowed to decide without a human watching.

This guide covers what AI agents actually do across the HR lifecycle, from candidate screening to onboarding to employee support, and then the part every vendor page skips: how to deploy them without creating legal, bias, and privacy exposure.

In a hurry? Deploy a governed HR agent you can watch work.

Rerun autonomous AI agents you can watch work live on a dashboard

What are AI agents for HR?

An AI agent for HR is software that perceives context, reasons over it, and takes multi-step action across your tools, all within boundaries you define. It does not just answer a question. It reads the resume, checks it against the role, schedules the interview, updates the ATS, and notifies the hiring manager, then stops and asks for approval before doing anything consequential.

That is a different thing from the two tools HR teams usually mean when they say "AI."

Chatbots, workflows, and agents are not the same thing

People conflate three categories that behave very differently in practice.

CapabilityHR chatbotZapier / Make / n8n workflowGoverned AI agent
Answers employee questionsYesNoYes
Takes multi-step action across toolsNoFixed path onlyYes
Handles ambiguity and reasonsNoNoYes
Waits for human approval on decisionsNoNoYes
Logs every action for auditPartialNoYes
Least-privilege access to HR dataPartialBroad tokensYes

A chatbot talks. A flowchart in Zapier or n8n fires a fixed if-this-then-that path and breaks the moment reality does not match the diagram. An agent reasons through the messy middle of a real HR request, and a governed agent does it while keeping a human in control of anything that matters. If you want the deeper distinction, our breakdown of an AI agent versus a chatbot walks through it.

Why HR is different from other agent use cases

Most agent use cases fail quietly. An HR agent fails loudly, in front of a regulator. HR is the one function where an automated decision touches sensitive personal data, protected-class information, and outcomes like screening, ranking, promotion, and termination that the law treats as high-stakes. That is the whole reason the deployment model matters more than the model.

Where AI agents actually help HR teams

Start with the wins, because they are real. HR runs on repetitive, high-volume work that reasoning agents handle well. IBM's own HR agent, AskHR, now automates more than 80 HR processes and handles millions of employee interactions a year, according to IBM. A PwC analysis of the hire-to-retire lifecycle found that more than half of HR subprocesses can be agent-assisted or agent-driven.

Here is where they land first.

Recruiting and candidate screening

This is where AI recruiting agents earn their keep, and where they carry the most risk. A well-scoped agent handles the top-of-funnel grind: parsing inbound resumes, matching skills to the role, scheduling interviews, and answering candidate questions around the clock. The workflow looks like this. The agent ingests every application, runs AI candidate screening against the role's real requirements, builds a ranked shortlist, and then stops. It does not send a single rejection on its own. A recruiter reviews the shortlist and approves each pass or reject, and that approval is logged.

That last step is the whole game. Recruiters lose hours to resume review, and triage is exactly the kind of high-volume work agents accelerate. But screening and ranking candidates is also the single activity regulators scrutinize most, so this is where human approval and bias controls are non-negotiable, not optional. The agent shortlists. A human decides.

Onboarding and offboarding

AI onboarding is the smartest place to start, because it is high-volume and low-risk. A single new hire kicks off a long checklist, and an agent can run all of it: provisioning accounts, requesting equipment, collecting signed documents, scheduling first-week sessions, and delivering the right policies to the right person. Offboarding runs the same checklist in reverse, which matters for security and compliance. A concrete first-week flow an agent can own:

Because none of this touches a protected-class hiring decision, it is the ideal place to prove your governance model before extending agents into recruiting. If you are mapping the broader pattern, our guide to AI agents for small business shows how the same operational agents scale down.

Employee service and HR help desk

PTO balances, benefits questions, policy lookups, and payroll basics, answered instantly instead of piling up in a shared inbox. This is where deflection numbers get real, and where an agent that can actually act (file the request, update the record) beats a chatbot that can only point at a policy PDF.

Performance, engagement, and retention

Drafting review summaries, surfacing attrition signals, and prepping managers for one-on-ones. Useful, but note the flag: anything touching performance evaluation or termination is legally sensitive, so keep the agent in a drafting and surfacing role, never a deciding one.

Workforce planning and analytics

Pulling from your HRIS and finance data to model headcount scenarios and answer "what if" questions that used to take an analyst a week.

Match the control to the risk

Not every HR workflow carries the same legal weight. Map each use case to its risk tier and the control it requires before you deploy anything.

HR use caseRisk tierRequired control
Onboarding and offboarding opsLowStandard action logging
Employee HR help deskLowLogging, escalation to a human
Workforce planning and analyticsMediumHuman review of outputs
Performance and engagement draftsMediumAgent drafts, human decides
Candidate screening and rankingHighHuman approval on every reject, bias audit
Promotion and termination inputsHighHuman approval, documented oversight

Read this table as your deployment order. Start at the top, earn trust, and only move down to the high-risk rows once your approval gates and audit trail are proven.

Connect Gmail, Slack, HubSpot, Notion and your HRIS to Rerun agents

The part vendors skip: HR agents are legally high-risk

Every use-case article stops here. This is where the real work starts, because HR is one of the few domains where an autonomous decision can be independently unlawful.

Bias and adverse impact are the core failure mode

An HR agent learns from historical data, and historical hiring data encodes historical bias. The canonical example is Amazon, which scrapped an internal AI recruiting tool after discovering it penalized resumes that included the word "women's." In the US, the EEOC's four-fifths rule is the practical test for adverse impact: if a selection process passes a protected group at less than 80 percent of the rate of the highest-passing group, that is a red flag. An agent that screens at scale can produce adverse impact at scale.

The risk is not that the agent is malicious. The risk is that it is fast, confident, and wrong in a way nobody can see until 200 people have already been rejected.

US enforcement is already here

This is not hypothetical. The iTutorGroup settlement put a dollar figure on automated age discrimination. New York City's Local Law 144 now requires independent bias audits for automated employment decision tools. Illinois regulates AI in video interviews, and Colorado passed a broad AI Act covering high-risk employment decisions. The direction is one way.

The EU AI Act classifies recruiting and HR AI as high-risk

Under the EU AI Act, AI systems used for recruitment, selection, promotion, termination, task allocation, and performance monitoring are named explicitly in Annex III as high-risk. That is not an interpretation, it is the text. High-risk classification brings hard obligations: risk management, data governance, record-keeping, and designed-in human oversight under Article 14. The high-risk obligations for Annex III systems apply on a 24-month timeline from the Act's entry into force, which puts them in effect in 2026.

High-level summary of the AI Act | EU Artificial Intelligence Actartificialintelligenceact.eu

GDPR and automated decisions

For anyone processing EU employee or candidate data, GDPR Article 22 gives people the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. Rejecting a job application qualifies. Add data minimization and purpose limitation over sensitive PII, and the message is consistent: a human has to be meaningfully in the loop, and you have to be able to prove it.

Why DIY automation and plain chatbots fail HR

Here is the uncomfortable part. The most common way teams "add AI to HR" is precisely the way that fails an audit: a chain of Zapier, Make, or n8n webhooks, or a chatbot bolted onto the careers page. Both break on the requirements above.

This is the anti-positioning that matters. A no-code automation tool wires triggers. It does not do the work, it does not reason, and it definitely does not defend a hiring decision to a regulator. If your "AI recruiting" is a pile of webhooks nobody can audit, you have automated the liability, not the work. Our take on AI workflow automation explains why the flowchart model hits a ceiling exactly here.

How to deploy HR agents safely: a governance checklist

The good news is that the requirements from regulators and the requirements for a good deployment are the same list. Meet these and you get both compliance and an agent your HR team can trust.

Human-in-the-loop is the load-bearing item here. If you only implement one control, make it the approval gate on consequential decisions. Our deep dive on human-in-the-loop AI agents covers how to design approvals that people actually use instead of rubber-stamping.

Human-in-the-Loop AI Agents: The Complete Guide to Building Agents You Can Actually Deploy

Human-in-the-Loop AI Agents: The Complete Guide to Building Agents You Can Actually Deploy

Human-in-the-loop AI agents pause on high-stakes actions to get human approval. Here are the approval gates, confidence thresholds, and escalation patterns that make agents production-ready.

How Rerun deploys governed HR agents

Rerun is built for exactly this problem: autonomous agents you can watch work, with the human in control of anything that matters.

  • Human-in-the-loop, natively. An agent pauses and asks for approval before a consequential action, and you approve it from the app or from Slack. It resumes exactly where it stopped. A screening rejection never fires on its own.
  • Full observability. Every action, tool call, and token is logged and visible live on a dashboard anyone can read. When a decision is questioned, you have the record, not a shrug.
  • Least-privilege connectors. Connect your ATS, HRIS, Gmail, and Slack with scoped access per agent, not a blanket token sprayed across a webhook chain.
  • Model-agnostic. Run on Claude, ChatGPT, Gemini, or your own key. Your governance posture is not hostage to one model vendor.
  • No code, no black box. HR owns the workflow, and nothing about the agent's reasoning is hidden.

The shift is simple: move from a flowchart nobody can audit to an agent everyone can watch. That is the difference between automating HR and governing it.

Approve agent actions from the app or Slack with human-in-the-loop control

You can start with the lowest-risk, highest-volume workflow, onboarding operations or the HR help desk, prove the governance model, then extend toward recruiting with approval gates already in place. It works the same way governed agents do in other regulated functions, like AI agents for finance and AI agents for healthcare.

The takeaway

AI agents can now run most of the HR lifecycle, and the productivity case is settled. What is not settled, for most teams, is the deployment model. Recruiting and HR decisions are legally high-risk, so the question is not "can an agent do this," it is "can I prove a human approved it and see exactly what happened." A chatbot cannot. A webhook chain cannot. A governed, observable, human-in-the-loop agent can, and that is the only version of HR automation worth deploying.

Deploy agents where they save real time, keep a human approving every consequential decision, and run them somewhere you can watch the work happen.

Frequently asked questions

Are AI agents for HR legal and compliant?

Yes, when deployed with human oversight. HR and recruiting AI is classified as high-risk under the EU AI Act (Annex III), and US rules like NYC Local Law 144 require bias audits, so compliant use means keeping a human in the loop on consequential decisions, logging every action for audit, and documenting oversight. A raw chatbot or an unaudited webhook chain does not meet that bar.

What is the difference between an AI agent and an HR chatbot?

A chatbot answers questions. An AI agent perceives context, reasons over it, and takes multi-step action across your tools, such as screening a resume, scheduling an interview, and updating the ATS. A governed agent does this while pausing for human approval on anything consequential, which a chatbot cannot do.

Can AI agents make hiring decisions?

They should assist, not decide. Screening and ranking candidates is high-risk under the EU AI Act, and GDPR Article 22 gives people the right not to be subject to solely automated decisions with significant effects. The safe pattern is an agent that shortlists and drafts, with a human approving every rejection, offer, and hire.

Is AI recruiting high-risk under the EU AI Act?

Yes. The EU AI Act names AI used for recruitment, selection, promotion, termination, task allocation, and performance monitoring as high-risk in Annex III. That triggers obligations including risk management, data governance, record-keeping, and human oversight under Article 14.

What HR tasks should you automate with agents first?

Start with the lowest-risk, highest-volume work: onboarding operations and the employee HR help desk. These deliver fast ROI without touching protected-class hiring decisions, and they let you prove your governance model before extending agents into recruiting with approval gates in place.

Why not just use Zapier or n8n for HR automation?

Flowchart tools fire fixed if-this-then-that paths automatically, with no reasoning, no approval gates on consequential decisions, no audit trail of why a decision was made, and broad API tokens across your HR systems. That is the opposite of what regulators and HR risk require. A governed agent reasons through ambiguity and keeps a human in control.

How do you prove human oversight of an HR agent to an auditor?

You need a logged, replayable record of every action the agent took and every decision a human approved. That is why observability and human-in-the-loop approvals are the core controls: they map directly to EU AI Act Article 14 and to bias-audit requirements like NYC Local Law 144.

Clément Janssens

Written by

Clément Janssens

Related articles

Your first agent is
three minutes away

Start for free
Rerun

Run your work on agents. Build them, watch them work, and keep your eyes on everything.

Rerun - Build, monitor and share self-improving autonomous agents | Product Hunt

© 2026 Rerun. All rights reserved.