AiCore logo

Lesson 2 — Employment, Equality and Responsible AI

Unit 4 | Lesson 2 of 3

By the end of this lesson, you will be able to:

  • Explain how the Equality Act 2010 applies to AI, and why a technically neutral model can still discriminate (K2, K7)
  • Distinguish direct from indirect discrimination and recognise both in AI systems (K2)
  • Identify when AI that changes a job role triggers employment-law flags (K2, K7)
  • Recognise the legal and ethical limits of AI-enabled workplace monitoring (K2)
  • Describe the UK's principles-based approach to responsible AI regulation (K7)

📅 Legal position correct as of September 2026. Legislation and regulator guidance change; every claim below links to its source, so check the source before relying on the claim.

AI is not exempt from the Equality Act

The Equality Act 2010 protects nine characteristics — age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation. AI systems are not exempt because they are automated. The Act covers two kinds of harm — direct and indirect discrimination:

Direct discriminationIndirect discrimination
WhatTreating someone less favourably because of a protected characteristicA neutral rule or model that puts a protected group at a disadvantage
Intent needed?NoNo — disproportionate impact is enough
AI exampleA model explicitly filters out candidates over 50A model trained on biased history disadvantages a group with no protected characteristic as input
Legal testWas this person treated worse because of who they are?Does this practice produce a worse outcome for a protected group, and can it be objectively justified?
Justifiable?No (very limited exceptions)Only if a proportionate means of a legitimate aim

How it happens in practice: the most common route is training data. Amazon built and then scrapped an AI recruiting tool that learned to down-rank CVs containing the word "women's" — because a decade of historic hiring data was mostly male. The model was technically neutral; the outcome was discriminatory. The legal test is not whether discrimination was intended, but whether a protected group was disadvantaged and whether that can be objectively justified.

Curious Cat

Did you know?

Amazon began developing this AI recruiting tool in 2014 and had disbanded the team by early 2017 after discovering the bias problem; it became public when Reuters reported it in October 2018, which is why that is the date usually attached to the story. The tool had been trained on CVs submitted over a ten-year period — most of which came from men, reflecting the historic gender imbalance in the tech industry. The model taught itself that male candidates were preferable. Amazon's engineers tried to adjust the system to remove the bias, but could not guarantee it would not find other proxies for gender. The story became one of the most widely cited examples of algorithmic bias in recruitment.

Further reading:

When AI changes the job

Employment law is not just an HR matter separate from the build. When an AI system materially changes a role — the tasks, the skills required, how performance is measured, or the level of autonomy — it can trigger obligations before deployment:

  • Change to terms and conditions — a substantial change to what a job requires may need to be agreed, not imposed.
  • Redundancy — removing or reducing roles engages redundancy law; larger programmes (20 or more redundancies at one establishment within 90 days) engage collective consultation duties under section 188 of the Trade Union and Labour Relations (Consolidation) Act 1992. The threshold counts per site, not organisation-wide.
  • Consultation obligations — even short of redundancy, the Information and Consultation of Employees Regulations 2004 may require the employer to inform and consult. They are narrower than often described: they apply to undertakings of 50 or more employees, and the duty to set up arrangements is triggered by the employer's initiative or by a request from 2% of the workforce (minimum 15 people, capped at 2,500). Where arrangements exist, they cover decisions likely to lead to substantial changes in work organisation — which an AI system can be.

You do not run the redundancy process — but if your automation would substantially change what people do, flag it to HR/leadership before implementation. The flag protects both the affected staff and the organisation.

Monitoring and surveillance

AI-enabled monitoring of employees (productivity tracking, communication analysis, keystroke logging) carries significant legal and ethical risk. The ICO is clear that monitoring must have a lawful basis, be proportionate, and be transparent — staff must be told what is monitored and why. Covert monitoring is only permissible in narrow circumstances. Monitoring risks compound equality risks: time-on-task metrics can disproportionately affect employees with disabilities or caring responsibilities. Recognise when a proposed automation crosses from workflow management into monitoring, and get the legal and HR implications assessed before it runs.

The UK's approach to responsible AI

The UK has no single AI Act (unlike the EU), and the government's position through 2026 has been that there will not be one in the short to medium term. It takes a principles-based, sector-led approach — five cross-sector principles all AI should meet, with sector regulators applying them:

  1. Safety, security and robustness
  2. Appropriate transparency and explainability
  3. Fairness
  4. Accountability and governance
  5. Contestability and redress

These are not legislation, but they are increasingly embedded in regulator expectations: the FCA's AI Update in financial services, the NHS England AI knowledge repository and MHRA rules in healthcare, and the Algorithmic Transparency Recording Standard in the public sector — mandatory since 2025 for central government departments and arm's-length bodies that deal with the public. Check whether your sector's regulator has published AI guidance. Frontier-model testing sits with the AI Security Institute rather than with a regulator.

Unlike the UK's principles-based approach, the EU AI Act (Regulation (EU) 2024/1689) takes a legislative, risk-tiered approach that applies to any organisation whose AI outputs are used by people in the EU — regardless of where it is based, mirroring the jurisdictional reach of EU GDPR. It phases in over several years: the prohibitions have applied since 2 February 2025, the transparency duties apply from 2 August 2026, and the high-risk obligations were pushed back by the AI Omnibus to 2 December 2027 (2 August 2028 for AI embedded in regulated products). It sorts AI systems into four tiers:

  • Unacceptable riskbanned outright (e.g. real-time remote biometric identification in publicly accessible spaces for law enforcement, emotion recognition at work, and social scoring). Two of those carry narrow exceptions — biometric identification for named law-enforcement objectives, authorised in advance by a judicial or independent administrative authority, and emotion recognition put in place for medical or safety reasons. Social scoring carries none, and the ban covers private organisations too, not just public authorities.
  • High risk — strict obligations before market entry, most relevant here: recruitment, performance evaluation, promotion/termination decisions, and workplace monitoring all count as high-risk employment uses, alongside credit scoring and access to essential services. These obligations apply from 2 December 2027.
  • Limited risktransparency duties only, from 2 August 2026: a system interacting with people directly must make clear it is AI, generated audio, image, video and text must be marked in a machine-readable format so it is detectable as artificial, and deepfakes must be disclosed to the people who see them.
  • Minimal risk — no specific obligations (most everyday applications).

pyramid diagram illustrating the EU AI Act's four risk tiers

If your organisation operates only in the UK today, the Act does not bind you directly — and no UK equivalent is on the way in the short to medium term. Any EU-facing employment, recruitment, or credit automation should still be checked against it.

📚 Extended reading — depth in Module 10. The full direct-vs-indirect legal tests, employment-consultation duties, workplace-monitoring rules, and the risk-tiered EU AI Act for cross-border work are revisited at governance-documentation depth in Module 10.


An AI recruitment tool is trained on ten years of an organisation's hiring decisions. No protected characteristic is an explicit input, yet its shortlists disproportionately exclude one ethnic group. Which best describes the legal risk?

A practitioner's automation will reduce a team of four doing a manual task to one, with AI handling the rest. Three staff will need redeploying or making redundant. What should the practitioner do?


📝 Activity — Equality & employment self-check

Complete Section 2 of your Module 1 Workbook (Unit 4 section). The questions guide you through:

  1. Whether your AI component could disadvantage a protected group — directly, or through proxy variables in the data
  2. Whether the automation materially changes anyone's role — task change, transformation, or headcount reduction
  3. Whether it involves any monitoring of staff behaviour, and whether lawful basis, proportionality, and transparency are addressed
  4. A Flag for what needs input from HR, legal, or equality colleagues before your project proceeds

These notes also feed your Module 2 Responsible AI Adoption Plan.


⏭️ Up next — Lesson 3: the five ethical principles, transparency in practice, and who is accountable when AI causes harm.