GenAI and ethics in HR: What HR tech leaders must know

Bagikan di

Daftar Isi

Don’t just deploy AI. Govern it.

Generative AI has moved through HR faster than almost any workplace technology before it. Gartner surveys of 197 HR leaders in June 2023 and January 2025 found that the share of organisations piloting or implementing generative AI rose from 19% to 61% in under two years, and Gartner predicts that half of all current HR tasks will be automated or managed by AI agents by 2030.

Value has not kept pace with deployment. In a Gartner survey of 110 heads of HR in the fourth quarter of 2025, 95% of organisations had implemented AI in some form over the previous year, yet only one in five reported significant or transformational value from it. A December 2025 Gartner survey of 197 CxOs and senior business leaders found that only 27% of executives have a comprehensive AI strategy, and just 20% believe their workforce is genuinely AI-ready.

That gap — between what has been switched on and what has been thought through — is precisely where ethical risk accumulates. And the consequences are already visible in workforce structure: in the same fourth-quarter survey, 22% of CHROs said their organisations had reduced entry-level hiring because of AI, a decision with long-term implications for talent pipelines that few organisations have modelled.

Employee resistance is not the obstacle. A Gartner survey of 2,986 employees in July 2025 found 65% were excited about using AI at work. People are willing. What they are entitled to is a reasonable account of how these systems affect them.

GenAI and ethics in HR: What HR tech leaders must know 1

Bias is not a solved problem — and it is not a static one

The most widely cited evidence remains stark. Research by Kyra Wilson and Aylin Caliskan of the University of Washington, presented at the 2024 AAAI/ACM Conference on AI, Ethics, and Society, simulated CV screening across nine occupations using more than 500 real CVs and 500 job descriptions. The text-embedding models tested favoured white-associated names in 85.1% of cases and female-associated names in only 11.1% of cases. Black male candidates were disadvantaged in up to 100% of cases.

More recent work points in different directions. A February 2025 study in PNAS Nexus found that four of the five models it assessed gave significantly higher average scores to female or Black candidates than to otherwise equivalent white male candidates. A 2026 audit of fourteen models using a paired-CV methodology found that models released from 2024 onwards showed either no measurable gap or a reversal in the opposite direction.

These findings do not cancel each other out. Read together, they say something more useful and more uncomfortable: the direction and size of bias vary by model, by version, by prompt and by task. Assurance cannot be inherited — not from a published paper, not from a vendor’s marketing, and not from a test you ran on last year’s model. It has to be measured on your own configuration, with your own data, and measured again whenever the underlying model changes.

GenAI and ethics in HR: What HR tech leaders must know 2

Accountability does not transfer to your vendor

The assumption that buying a tool transfers the legal risk to whoever built it is being tested in court and rejected in legislation.

In Mobley v. Workday in the Northern District of California, Judge Rita Lin granted preliminary certification of a nationwide collective under the US Age Discrimination in Employment Act in May 2025. The court authorised notice on 17 February 2026 to anyone aged 40 or over who had applied for jobs through the platform since 24 September 2020, with the opt-in window closing on 7 March 2026.

In March 2026 the court rejected the argument that age discrimination protections against disparate impact do not extend to job applicants, and in a further order on 22 June 2026 it allowed claims under California’s Fair Employment and Housing Act to proceed on the basis that the screening tools were designed and operated from the vendor’s California headquarters. The case is still in its merits phase, and allegations are not findings — but the direction of travel is unmistakable, and it points at both the vendor and the employers using the tool.

European law makes the same point structurally. The EU AI Act distinguishes between providers, who build AI systems, and deployers, who use them, and places obligations on both. An employer screening CVs with a purchased tool is a deployer, and carries duties of its own.

The rules that matter for HR leaders in Asia

GenAI and ethics in HR: What HR tech leaders must know 3

The EU AI Act reaches further than Europe

The AI Act entered into force on 1 August 2024 and applies wherever the output of an AI system is used in the EU, regardless of where the provider or deployer sits. AI used for recruitment, candidate selection, performance evaluation, task allocation, worker monitoring, promotion and termination is classified as high-risk under Annex III. Prohibited practices — including emotion recognition in the workplace — have applied since 2 February 2025, alongside AI literacy obligations.

The high-risk obligations themselves were scheduled to apply from 2 August 2026. Under the Digital Omnibus package, agreed in 2026, the application date for Annex III high-risk systems including employment has been postponed to 2 December 2027. A postponement is not a repeal: risk management, data governance, technical documentation, record-keeping, transparency, human oversight and accuracy requirements all remain, and the preparatory work — bias testing, documentation, oversight design — takes longer than the extension allows for.

Singapore: frameworks with teeth in practice

Singapore has deliberately avoided a single binding AI statute in favour of frameworks and sectoral guidance. The Personal Data Protection Commission’s Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems, issued in March 2024, set expectations on consent, notification and the role of service providers as data intermediaries. In January 2026, IMDA and AI Verify published a Model AI Governance Framework for Agentic AI — the first of its kind globally — which places human accountability at the centre and pushes organisations towards structural controls rather than prompt-level instructions, with explicit reference to HR and finance use cases.

Malaysia: enforceable obligations are already live

The Personal Data Protection (Amendment) Act 2024 came into force in stages through 2025. From 1 June 2025, both data controllers and processors must appoint a Data Protection Officer and register the appointment with the Commissioner, and controllers must notify the Commissioner of personal data breaches. The maximum fine for breaching the data protection principles rose from RM300,000 to RM1 million, with imprisonment of up to three years. Biometric data is now expressly within the definition of sensitive personal data — directly relevant to attendance, access and identity verification systems that many HR teams already run.

Sri Lanka: build for it before it commences

Sri Lanka was the first country in South Asia to enact standalone data protection legislation, with the Personal Data Protection Act, No. 9 of 2022. It grants data subjects the right to request a review of automated decision-making, subject to conditions. The Personal Data Protection (Amendment) Act, No. 22 of 2025 removed the fixed grace periods for operationalisation, leaving the remaining substantive parts to commence on a date appointed by the Minister and published in the Gazette. Organisations should treat the absence of a commencement date as preparation time rather than an exemption.

Six controls to put in place now

GenAI and ethics in HR: What HR tech leaders must know 4
  1. Inventory every AI system that touches an employment decision. Include features embedded in platforms you already own — ranking, matching, summarisation and scoring often arrive as product updates rather than procurement decisions.
  2. Classify by consequence, not by novelty. Screening, ranking, performance evaluation and pay recommendations sit in the highest tier. A chatbot answering leave-policy questions does not.
  3. Test for adverse impact before go-live, and again after every model change. Record the methodology, the results and the decision taken. Testing you cannot evidence is testing you did not do.
  4. Make human oversight real. A reviewer needs the authority to overturn the system, the information to know why it recommended what it did, and enough time to use both. Log overrides — a system that is never overturned is not being supervised.
  5. Tell candidates and employees. Explain where AI is used, what it influences, and how a person can ask for a review. Transparency is a requirement under the EU regime and simply good practice everywhere else.
  6. Contract for evidence, not assurances. Require technical documentation, instructions for use, bias-testing evidence, notification of material model changes and audit rights. If a vendor cannot supply these, that is itself a finding.

Ethics is a design decision, not a disclaimer

The organisations getting this right are not the ones with the longest AI policy. They are the ones that decided early which decisions a machine may recommend and which a person must make and then built their systems so that the distinction holds under pressure — at volume, at quarter-end, when the shortlist is due tomorrow. That principle shapes how we build at MiHCM.

Our ISO/IEC 27701:2025 certification, covering our Malaysia and Sri Lanka operations, reflects the same conviction: privacy and governance belong in the architecture, not in the footnotes.

The regulatory deadlines will move again — they already have. The underlying expectation will not. If an AI system helped decide who gets hired, promoted, monitored or paid, someone will eventually ask you to explain how. The work is being able to answer.

Transparency and sources

All statistics, statutory references and case details in this article are drawn from the named sources listed below and were accurate at the time of writing (August 2026). Regulatory commencement dates in several jurisdictions remain subject to change, and Mobley v. Workday is ongoing litigation in which allegations have not been determined as findings of fact. This article is general information for business readers and does not constitute legal advice; organisations should obtain qualified local legal advice before making compliance decisions.

  • Gartner — press release, top trends shaping HR priorities (17 November 2025); surveys of 197 HR leaders, June 2023 and January 2025.
  • Gartner — fourth quarter 2025 survey of 110 heads of HR (AI adoption, realised value, entry-level hiring).
  • Gartner — press release, people-centric AI strategy (13 May 2026); December 2025 survey of 197 CxOs and senior business leaders.
  • Gartner — press release, employee attitudes to AI (16 December 2025); survey of 2,986 employees, July 2025.
  • Wilson, K. and Caliskan, A. (2024), ‘Gender, Race, and Intersectional Bias in Resume Screening via Language Model Retrieval’, Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society; University of Washington.
  • PNAS Nexus (2025), ‘Measuring gender and racial biases in large language models: intersectional evidence from automated resume evaluation’, Oxford Academic.
  • Gao, Z., Jiang, W. and Yan, Y. (2026), ‘Can LLMs Hire Fairly? Racial Bias in Resume Screening’, CUHK Business School (preprint, arXiv).
  • Mobley v. Workday, Inc., No. 3:23-cv-00770-RFL, US District Court for the Northern District of California — court orders of May 2025, 17 February 2026, March 2026 and 22 June 2026, as reported by Duane Morris LLP, Holland & Knight LLP and Norton Rose Fulbright.
  • Regulation (EU) 2024/1689 (EU AI Act) and the Digital Omnibus on AI — European Commission; analysis by DLA Piper, McCann FitzGerald and Ogletree Deakins on the deferral of Annex III high-risk obligations to 2 December 2027.
  • Personal Data Protection Commission, Singapore — Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (March 2024); IMDA and AI Verify Foundation — Model AI Governance Framework for Agentic AI (January 2026).
  • Personal Data Protection (Amendment) Act 2024, Malaysia; Personal Data Protection Department guidelines on DPO appointment and data breach notification (25 February 2025, effective 1 June 2025).
  • Personal Data Protection Act, No. 9 of 2022 and Personal Data Protection (Amendment) Act, No. 22 of 2025, Sri Lanka; Data Protection Authority of Sri Lanka.

Ditulis oleh : Marianne David

Menyebarkan berita
Facebook
X
LinkedIn
SESUATU YANG MUNGKIN MENARIK BAGI ANDA
Aug 26 - Bangladesh Labour Amendment Act 2026
The Bangladesh Labour (Amendment) Act 2026: What changed and what HR must do now

Bangladesh has just rewritten the rules of employment. The Bangladesh Labour (Amendment) Act 2026 was

Aug 24 - HR Compliance ASEAN South Asia Cross Border Payroll
One region, many rules: The new reality of HR and payroll compliance across ASEAN and South Asia

For a regional HR leader, there is rarely such a thing as “Asian payroll”. There

Aug 21 - AI Ethics and Governance in HR
AI in HR needs more than intelligence: A practical guide to ethics and governance

Artificial intelligence is becoming part of everyday HR. It can help employees find information faster,