Yes, AI systems are already used to help screen job applicants and score loan applications, and whether that is legal depends almost entirely on where you live and how the tool is used — in some places it is allowed with conditions, and in others it is restricted or banned for certain decisions.
The short version: the technology is real and widespread, but the law has not settled into one global answer. The European Union's AI Act, for example, classifies systems used to make decisions about hiring and access to credit as "high-risk," which means they can be used only if the provider meets a long list of obligations around testing, documentation, and human oversight. In the United States, there is no single federal AI hiring law; instead, a patchwork of existing anti-discrimination rules applies, enforced agency by agency.
So the honest answer to "is that legal?" is: sometimes, under conditions, and the rules are still being written.
To understand why this matters, it helps to see how the decision actually gets made. A hiring tool does not usually watch a video and announce "hire this person." It takes structured data — a resume, a work sample, answers to a standardized test — and produces a score or a ranking.
A lender's system does something similar with credit history, income, and debt. The output is a number, and a human is supposed to make the final call. The legal risk lives in that number.
If the score correlates with a protected characteristic like race, gender, or disability, the tool can produce discrimination even when no one intended it, because it learned patterns from historical data that already contained bias. That is the core mechanism: the model optimizes for whatever it was trained to predict, and if past hiring or lending was biased, the model can faithfully reproduce that bias at scale.
This is why regulators focus less on whether AI is used and more on whether the outcomes can be explained, audited, and challenged.
A concrete example makes the stakes clear. Imagine a mid-sized company that adopts a resume-screening tool to cut down a pile of 5,000 applications. The tool ranks candidates by similarity to past successful hires.
If the company's previous hires were mostly from a handful of universities, the model learns to favor those universities — not because the tool "believes" anything, but because that pattern predicted success in the training data. A qualified candidate from a different background gets filtered out before a human ever reads the resume.
Under the EU's high-risk classification, that deployment would require the company to document how the system works, test it for bias, keep human oversight, and give candidates information about the automated processing. Under U.S. anti-discrimination law, the company could still be liable if the tool's outcomes disproportionately exclude a protected group, even without intent.
In both cases, the fix is not to ban the tool but to audit it, keep a human in the loop, and be able to explain why any given candidate was rejected.
Now the limits. First, the law is genuinely unsettled and varies enormously by country, so any specific legal claim should be checked against current local rules rather than treated as fixed. Second, our own AI tool database — an internally verified snapshot of 360 AI tools, most recently checked on 2026-09-18 — tracks pricing and capability, not legal compliance, so it cannot tell you whether a particular hiring or lending tool is lawful in your jurisdiction.
Third, transparency is hard: many vendors treat their scoring models as trade secrets, which makes independent bias testing difficult even when regulators require it. Fourth, even a well-audited system can fail on edge cases the training data never covered. If you are deploying or subject to one of these systems, the practical move is to ask three questions: what data trained it, what outcome it is optimizing for, and who can override it.
If the vendor cannot answer those, that is your signal to slow down. For a broader look at how AI handles sensitive personal information, see Can AI tools really leak my private data, and how do I stop it from happening?.