Advice for Employers and Recruiters
Did the UK & EU make it illegal to use AI to match, rank, or score? | Job Board Leaders’ Roundtable | Sep 2026
Today’s Job Board Leaders’ Monthly Roundtable call featured a lively and incredibly informative conversation with Isvari Maranwe, founder and CEO of Yuvoice and The Sentinel by Yuvoice; award-winning cyber and tech attorney; global policy thought leader and AI speaker. What she says matters, and her 350k+ followers on LinkedIn surely agree.
Host Steven Rothberg of College Recruiter job search site asked some questions to start and then, as has become our custom, opened the floor to questions and comments from attendees.
By the end of the hour, it became apparent that the use of AI by job boards is not just a legal matter for the regulatory authorities, but also a financial and public relations risk. That’s not to say that job boards shouldn’t use AI, but there are risks and some of those risks can be greatly reduced. Isvari offers a number of specific recommendations for how to do that, and some of those are surely going to surprise viewers.
AI-generated summary:
- Introduction and Overview: Steven Rothberg introduced the job board leaders monthly roundtable, noting the session’s focus on the intersection of technology, legal requirements, and the use of artificial intelligence within the industry. They welcomed Isvari Maranwe, a CEO and attorney who specializes in technology law and international policy, to discuss the risks and regulatory environment facing job boards regarding AI usage.
- Legal Status of AI in Job Boards: Isvari Maranwe clarified that using AI to rank, screen, or match candidates is not currently illegal in the UK or EU, but they cautioned that it is “high risk”. Potential legal vulnerabilities exist under the EU AI Act, data privacy laws, and anti-discrimination legislation, though consistent enforcement has yet to materialize.
- Enforcement Reality vs. Legal Theory: Steven Rothberg and Isvari Maranwe discussed the distinction between formal legality and practical enforcement. Isvari Maranwe noted that regulators often focus on large, high-profile companies, comparing the situation to minor traffic violations where enforcement is inconsistent. Companies that fall out of favor with regulators are at higher risk of being targeted for non-compliance, regardless of their size.
- Small Business Risk Factors: Isvari Maranwe suggested that smaller job boards are less likely to face immediate, aggressive enforcement compared to larger entities. They advised that smaller companies should focus on staying informed, perhaps by communicating with government bodies, nonprofits, or institutions like the Royal Academy of Engineering to understand current expectations.
- Future Outlook on AI Risks: Looking one year ahead, Isvari Maranwe predicted that regulatory enforcement will likely be triggered by a specific disaster or security incident, similar to the Uber Eats facial recognition discrimination case. They argued that the primary threat to companies will not be regulatory, but technical—specifically issues like “garbage in, garbage out,” info-stealer malware, and AI-driven phishing scams.
- Technical Security and Data Integrity: Discussing the security risks of AI, Steven Rothberg and Isvari Maranwe highlighted the dangers of AI hacking, referencing recent instances where AI agents at organizations like Hugging Face were compromised. Isvari Maranwe emphasized that the technical conversation regarding security, such as protecting candidate data and securing systems, must outpace the regulatory conversation.
- Legal Jurisdiction for US Companies: Isvari Maranwe clarified that US companies are not immune to UK and EU regulations if they conduct business with citizens in those regions. They noted that having different systems for different jurisdictions is burdensome, leading many companies to adopt the highest standard across the board to ensure compliance.
- Meaningful Human Oversight and Vendor Liability: Discussion centered on the requirement for “meaningful human oversight” in AI-driven candidate ranking. Isvari Maranwe stressed that simply clicking a reject button is insufficient; if AI creates a discriminatory outcome, the liability generally rests with the employer using the system. However, vendors can minimize third-party liability by using robust contracts and disclaimers that clearly define the human role in the review process.
- Contractual Tactics for Risk Mitigation: To protect against liability, Isvari Maranwe advised job board operators to use standardized contracts for all clients. They recommended that these documents should look like standard, unobtrusive terms and conditions, as lengthy or complex formatting often discourages unnecessary legal redlining from clients.
- Recommendations for Job Board Leaders: Isvari Maranwe advised that leaders should prioritize security and data practices over aggressive AI deployment. They warned that many companies, including large firms, have found that complex AI often underperforms compared to simpler, hardcoded machine learning, while increasing token costs and technical risks.
- Rogue AI and Auditing Challenges: Isvari Maranwe warned of “rogue” AI behavior, where systems left without oversight may prioritize tasks in destructive ways, such as deleting data. Regarding auditability, they noted that asking AI to self-report on its ranking logic often leads to hallucinations rather than factual explanations, necessitating encoded, predefined labels for error tracking.
- Collaboration as Risk Mitigation: Mike Corso shared an experience building the Talent Acquisition Portal, noting that they consulted with the Equal Opportunity Employment Commission (EEOC) before building their matching system. Isvari Maranwe praised this approach, noting that early collaboration with government entities creates a protective relationship that reduces the likelihood of future regulatory targeting.
- Enforcement Mechanisms and Unintended Discrimination: When asked about the “teeth” of UK and EU regulations, Isvari Maranwe explained that while fines are a primary tool, there is a push toward mandated operational changes and oversight. They emphasized that the greatest legal risk remains unintended discrimination against protected characteristics, which is actionable under existing laws regardless of AI’s involvement.
- The Changing Landscape of AI Protection: Discussing the “money-at-all-costs” approach, Isvari Maranwe noted that attitudes in Silicon Valley are shifting following recent settlements, such as the Meta case. They argued that companies can no longer assume that profitability or providing a good service will shield them from regulatory scrutiny.
- PR and Political Engagement: Isvari Maranwe advised that investing in public relations can serve as a form of insurance, as regulators are less likely to pursue popular, ethical companies. They also encouraged leaders to engage directly with elected representatives and their staff, noting that government committees are actively seeking public comments on AI policy.
- Integration of Organizational Silos: Isvari Maranwe stressed that companies fail when they silo their tech, legal, and PR/marketing departments. They recommended that a centralized authority within the organization synthesize these perspectives to ensure the company is protected from both technical and PR-related fallout.
- Spam Filtering and Security: Regarding the problem of fake resumes, Jonathan Duarte asked about using AI for security. Isvari Maranwe explained that using AI for anti-spam and anti-bot filtering is low risk, provided it is classified as a security measure rather than a ranking or screening tool. They cautioned that companies must still ensure that these security filters do not disproportionately affect protected groups, which would create a new liability.
- The Cybersecurity Arms Race: Steven Rothberg and Isvari Maranwe discussed the ongoing effort to manage platform traffic, referencing the use of tools like Cloudflare. Isvari Maranwe noted that hackers and malicious AI will likely always be faster to develop new exploits than defenders are to patch them, reinforcing the need for constant vigilance.
- Authentication and Economic Impact: Steven Rothberg highlighted the rising costs of “verified applications” due to new authentication layers like multifactor authentication, noting that costs for some employers have increased tenfold. Isvari Maranwe concluded by reiterating that AI is fundamentally and permanently altering the global economy, resulting in immediate, high costs related to hacking and data security that organizations are currently ill-prepared to handle.
- Upcoming Episode Guest: Steven Rothberg announced that the next episode, scheduled for one month from now, will feature Bill Borman as the guest. Bill Borman is described as an experienced individual in the industry who has been contributing writing to the AIM group for several months.
- Analysis of Publicly Traded Job Boards: Steven Rothberg shared that Bill Borman recently completed a comprehensive analysis of 17 globally publicly traded job boards using information found in their respective public filings. By reviewing these 17 organizations collectively, Bill Borman identified interesting hidden trends that would not be apparent if the organizations were examined individually. Steven Rothberg noted that they look forward to learning about these 17 specific findings during the upcoming episode.
- Meeting Conclusion: Steven Rothberg expressed gratitude to Isvari Maranwe and the other attendees for participating in the session, describing the meeting as fantastic. Isvari Maranwe thanked Steven Rothberg for the invitation, and the participants exchanged parting well-wishes before concluding the meeting.