AI Recruitment

Claude Cowork, the GDPR and the EU AI Act: what recruiters can actually do

7 Aug 2026·7 min read
Marcel van der Meer
Marcel van der MeerFounder, Klikwork
AI Recruitment article on Klikwork

TL;DR

Recruitment and candidate selection are high-risk use cases under the EU AI Act, which means obligations, not a ban. Most agent work for recruiters, research, briefs, reporting, document handling, involves no candidate data at all. The first question is not how much access to give, it is whether you are permitted to use that data with this tool. Three guardrails cover most of it: allowed and anonymised, human in the loop, judge the role not the person. Your working folder and your connectors are your practical privacy controls, so keep both narrow.

Most AI-for-recruitment content skips this part, which is strange, because it is the first question any serious recruiter asks. You are handling other people's personal data for a living, in a use case European law has specifically singled out.

The good news: almost everything that makes an agent useful to a recruiter is nowhere near the danger zone. The part that is loaded is loaded for good reasons, and it is workable if you set it up deliberately.

This is practical guidance from training practice, not legal advice. Your own legal and compliance team has the final word, and rules keep evolving.

Why recruitment gets special treatment

Under the EU AI Act, AI systems used in employment, worker management and access to self-employment are classified as high-risk. That covers systems used to recruit or select people, and to filter applications or evaluate candidates.

High-risk does not mean forbidden. It means the use comes with obligations: transparency about what is being used, human oversight, and being able to explain what happened and why. There is also a broader AI literacy expectation, which is one reason organisations are training their teams rather than quietly hoping nobody notices.

Alongside that sits the GDPR, which has applied all along. A CV is personal data. So is an interview note, a rejection reason, and the message thread where you discussed a candidate.

The distinction that keeps you safe

Here is the practical line that matters more than any legal summary.

Work with no candidate dataWork with candidate data
Company research before a pitchScreening CVs
Market and salary researchBuilding shortlists
Turning intake notes into a briefCandidate communication
Weekly reporting from your own notesInterview notes and scorecards
Working through policies and contractsAnything with a name attached
Building and testing skillsAnything that feeds a decision about a person

Nearly everything in the left column is safe to automate enthusiastically today. That is also where most of the wasted hours in a recruiter's week live. Start there, get good at the tool, and approach the right column deliberately rather than by accident.

The question that comes before "how much access"

Recruiters usually jump straight to permissions: which folder, which connector, how much can it see. Important, but there is a question before it.

Are you allowed to use this data with this tool at all?

In some organisations the answer is simply no, for reasons that have nothing to do with the tool's quality: data residency requirements, a policy on non-European providers, sector rules, or client contracts that specify where candidate data may be processed. If that is your situation, no clever configuration makes it acceptable. You ask first, and you get the answer in writing.

So the order is: am I permitted, then how little access is enough, then how do I keep a human deciding.

The three guardrails we teach in every training

1. Allowed and anonymised. Only use data you are permitted to use, and strip out what the task does not need. If a shortlist comparison works on skills and experience, it does not need dates of birth, photos, addresses or names.

2. Human in the loop, always. The agent proposes, you decide. No automated rejection, no automated advance, no "it scored them so I went with it". If you could not explain your decision to the candidate without pointing at the tool, the tool made the decision, and that is the thing to avoid.

3. Judge the role, not the person. Score against the stated requirements only. Never on a name, age, gender, nationality, photo or background, and be alert to proxies that smuggle those back in, like a graduation year or a postcode.

Hold those three and you can use an agent in daily practice with a clear conscience.

Your practical privacy controls

The comforting thing about an agent that works on folders is that the controls are physical and obvious.

  • The working folder is a boundary. Claude sees what you put in it. So put only what belongs to the task in it, and do not point it at your entire drive because it is convenient.
  • Connectors are access you grant on purpose. A connector is a live link into a real system, which is exactly why you only connect what a task actually needs, and switch it off when you are done. Start with something low-stakes, like your calendar, rather than a system full of candidate records.
  • Prefer drafts over sends. Let it prepare communication, keep the sending in your hands.
  • Screen recordings capture everything. If you use Record a skill, described in Claude skills for recruiters, close unrelated tabs first, never type a password, and keep candidate data out of the recording entirely.

What good looks like in a shortlist task

A concrete example, because this is where recruiters most want a straight answer.

Instead of "rank these candidates and tell me who to hire", the responsible instruction is: "Compare these CVs against the requirements in the vacancy file. For each one, list the evidence for and against on the stated requirements only, and note what is missing. Do not rank or recommend anyone."

What you get back is evidence you can check, tied to criteria you wrote down, with the gaps visible. What you do with it is your call, which is precisely the point. You also end up with something you could show a candidate who asks why they were not progressed, which is a good test of whether your process is defensible.

Does this slow you down?

Slightly, and mostly at the start. Deciding what you are allowed to use, narrowing a folder, and writing criteria down takes some thought the first time. After that it is habit, and it makes the work better anyway, because vague criteria produce vague shortlists regardless of who does the comparing.

There is also a commercial angle worth naming. Clients increasingly ask how you use AI on their vacancies. Being able to answer clearly, with guardrails you can describe, is becoming a differentiator rather than a compliance chore.

Where to learn this properly

Most AI trainings for recruiters either ignore this entirely or reduce it to a disclaimer slide. In the AI Recruitment Engineer Starter the loaded use cases are taught the responsible way as part of the course, not as an afterthought: human in the loop, transparent criteria, and never an autonomous decision about a person. It is self-paced, about four hours, 297 euro.

For the tasks that carry no compliance weight at all, and are the right place to start, see seven recruitment tasks to hand to Claude Cowork. For the tool itself, see what is Claude Cowork, and for the wider process view, our recruitment process automation guide.

Frequently asked questions

Is using AI for CV screening legal in the EU? It is not banned, it is regulated. Recruitment and candidate selection are high-risk under the EU AI Act, which brings obligations around transparency, human oversight and explainability, alongside GDPR duties for personal data.

Can I upload candidate CVs to Claude Cowork? That depends on your organisation's policy, your client contracts and any data residency requirements, so check before you do it. If you are permitted, minimise what you upload, strip what the task does not need, and keep a human making every decision.

What does human in the loop actually mean? A person makes every real decision about a candidate, with enough information to disagree with the tool. If the outcome would have been the same whether or not a human looked, it was not meaningful oversight.

Do I have to tell candidates that I use AI? Transparency obligations are part of both the AI Act and the GDPR, and expectations are rising. Being upfront about how AI supports your process, and where humans decide, is the safer and increasingly the expected position. Check your own legal guidance for exact wording.

Is this legal advice? No. This is practical guidance from training practice. Your legal and compliance team has the final word, and the rules keep evolving.