No items found.

EU AI Act Recruiting: Which Obligations Actually Apply?

By Jürgen Ulbrich

Short answer: EU AI Act recruiting does not make every HR tool high-risk by default. But an AI system intended to place targeted job ads, analyse or filter applications, or evaluate candidates is generally listed in Annex III, point 4 of Regulation (EU) 2024/1689. That creates duties for the organisation using the system, not only for its software vendor: it must govern use, provide meaningful human oversight, retain controlled logs and inform affected people. Legal position in this article: 20 August 2026.

Important: This is practical orientation, not legal advice. The answer depends on the system’s intended purpose, configuration, deployment country and applicable employment arrangements.

Why is recruiting AI classed as high risk?

A high-risk AI system is one whose intended use can materially affect health, safety or fundamental rights. In hiring, a filter, ranking or score can determine who gets access to work in the first place. Annex III therefore expressly covers systems intended to recruit or select people, including targeted job advertising, analysing and filtering applications, and evaluating candidates. The Regulation connects employment systems to possible effects on career prospects, livelihoods and workers’ rights.

The key test is intended purpose, not a vendor’s product label. A scheduling assistant that does not influence selection is not automatically high-risk. Article 6(3) also allows a narrow exception for procedural or preparatory tasks that do not materially influence the outcome. However, a system that profiles natural persons is always high-risk under that provision. For teams handling high application volumes with CV screening workflows, that means mapping each point at which AI can change a candidate’s path, rather than adding every AI-enabled ATS feature to one undifferentiated register.

Provider and deployer duties are not interchangeable

The provider develops a high-risk system or places it on the market under its name. Its obligations are primarily about the system itself: risk management, suitable data governance, technical documentation, logging capability, instructions for use, human-oversight measures, accuracy, robustness and cybersecurity. Article 16 also assigns the provider quality-management, conformity-assessment, EU declaration of conformity, CE-marking and registration duties before the system is placed on the market or put into service.

The deployer is the organisation using the system under its authority. An employer, staffing firm or talent-acquisition team applying a system to real candidate decisions will usually be a deployer. Vendor paperwork therefore does not remove deployer responsibilities. There is a further boundary to watch: an organisation that white-labels a system, substantially modifies it, or changes its intended purpose so that it becomes high-risk can itself become a provider with the much broader Article 16 burden.

What does a deployer have to do in day-to-day recruiting?

Article 26 turns compliance into operating discipline. Deployers must take technical and organisational measures to use the system in line with its instructions. In a hiring workflow, that includes permitted data, user permissions, approved settings, known limitations and the decisions the system may support. Before a pilot, write down where AI can advise and where it must not decide.

Human oversight is not a nominal approval button. The deployer must assign oversight to people with sufficient competence, training, authority and support. In practice, a recruiter or hiring manager needs both context and authority to challenge a ranking, override an output, pause the workflow and escalate a concern. Seeing a score and routinely accepting it is not a credible control.

Where deployers control input data, they must ensure that those inputs are relevant and sufficiently representative for the intended purpose. They must monitor operation too. If use in accordance with instructions may create a risk, they need to inform the provider or distributor and the competent market-surveillance authority and suspend use. This matters particularly where a tool can exclude candidates automatically rather than simply draft interview questions.

Logging is also a deployer responsibility. Deployers must retain automatically generated logs under their control for a period appropriate to the intended purpose and for at least six months, unless applicable Union or national law – especially data-protection law – provides otherwise. The Article 26 rule does not mean retaining applicant data indefinitely. It means deciding, and documenting, what is logged, who can access it, how it is protected and when it is deleted.

People affected by Annex III systems that make or assist decisions about them must be informed that they are subject to use of a high-risk AI system. Article 86 adds a right to clear, meaningful explanations of the AI system’s role and the main elements of an adverse decision that has legal or similarly significant effects. Candidate communication and an answer process are therefore operational controls, not just wording for a privacy footer.

When do the high-risk recruiting rules apply?

The timetable changed through the AI Omnibus. The Regulation entered into force on 1 August 2024. General provisions, prohibitions and AI-literacy requirements have applied since 2 February 2025. From 2 August 2026, the Regulation applies generally, including transparency rules for certain direct interactions with AI.

The specific Chapter III rules for stand-alone high-risk systems under Article 6(2) and Annex III – the core provider and deployer obligations for recruiting AI – apply from 2 December 2027. Rules for high-risk AI embedded in regulated products apply from 2 August 2028 and are not the usual recruiting case. These dates follow the consolidated AI Act text and its amending Regulation (EU) 2026/1744. The later date is preparation time, not a reason to postpone procurement controls, testing or workforce consultation.

The AI Act sits alongside GDPR and works-council rules

The AI Act and the GDPR answer different questions. GDPR Article 22 gives a person the right not to be subject to a decision based solely on automated processing, including profiling, where it has legal or similarly significant effects. The provision has limited exceptions. For decisions necessary for a contract or based on explicit consent, the GDPR requires safeguards including the ability to obtain human intervention, express a view and contest the decision. A documented human review is useful, but it must reflect the real decision process and should be assessed against GDPR Article 22.

A data-protection impact assessment is required under GDPR Article 35 where processing is likely to create a high risk to people’s rights and freedoms. The Regulation specifically highlights systematic and extensive automated evaluation of personal aspects on which significant decisions are based. Article 26 of the AI Act tells high-risk deployers to use the provider information available to them where such a DPIA is applicable.

A fundamental-rights impact assessment under Article 27 AI Act is distinct. It is mandatory before deployment for public-law bodies, private entities providing public services, and specified creditworthiness and life- or health-insurance systems. A normal private employer does not become subject to this assessment merely by using recruiting AI. Public employers should plan for it early; private employers may still use a voluntary rights assessment as a sound governance control.

For Germany, employment law adds another layer. Before deploying a high-risk system in the workplace, Article 26 requires employers to inform workers’ representatives and affected workers. Section 90 of the German Works Constitution Act also requires timely information on planned work processes that include AI. Where a system is intended to monitor employees’ performance or conduct, Section 87(1)(6) is especially relevant. Section 95(2a) confirms that selection-guideline rules also apply when AI is used; in workplaces with more than 500 employees, the works council can require such guidelines. Whether a particular external applicant-screening workflow triggers a specific rule requires employment-law assessment, but involving the works council before a pilot is usually the practical path.

Make documentation capability a buying criterion

When comparing AI recruiting tools, do not ask only whether a product can produce a score. Ask whether your organisation can explain and control its use later. A procurement record should cover intended purpose and known limitations, instructions for use, the human-oversight design, available logs and exports, access and deletion controls, candidate information and the information needed for privacy assessment.

A practical decision rule is simple: if a provider cannot show in writing what the system may decide or influence, who can override it and which logs will be available afterwards, the system is not ready for a decision-relevant pilot. That is deliberately stricter than a successful feature demonstration. It distinguishes an assistive tool from a system whose impact on a candidate cannot later be reconstructed.

This applies to CV-screening workflows as much as it does to AI-assisted first conversations. For AI interviews and voice recruiting, teams should establish whether AI merely asks questions, summarises responses or evaluates candidates. A voice-interview workflow does not replace a reasoned selection decision or a personal conversation.

An open limitation: Complete documentation, logs and a human sign-off do not prove that a hiring process is free of discrimination or that every outcome is correct. They make risks visible, reviewable and correctable. That is why realistic pre-launch testing, an escalation route and regular review should be part of implementation.

A practical pre-deployment checklist

  1. Classify every AI use by actual purpose: assistance, preparation, ranking, filtering or evaluation.
  2. Document whether and how the output changes a candidate’s route through the process.
  3. Request instructions, known limitations, human-oversight measures and logging information from the provider.
  4. Assign and train people who can review, override or stop the system.
  5. Define log retention, access and deletion with privacy and IT colleagues.
  6. Assess GDPR Articles 22 and 35 and any applicable fundamental-rights impact assessment.
  7. Involve the works council or other employee representatives before pilot and rollout.
  8. Prepare candidate information and a route for explanation and complaint requests.

Frequently asked questions about the EU AI Act in recruiting

Is every AI recruiting tool high risk?

No. The high-risk category covers the intended uses listed in Annex III, especially systems that filter applications, evaluate candidates or influence selection. Narrow preparatory tasks without material influence may be different, while profiling is a significant exception. Record the assessment instead of relying on a product name.

Do candidates have to be told that AI is used?

For Annex III high-risk systems that make or assist decisions about people, yes. GDPR information obligations and, for significantly adverse decisions, a right to explanation may also apply. The notice should explain where AI is used and how people can exercise their rights.

Does human review automatically solve GDPR Article 22?

No. Article 22 asks whether the decision is solely automated and has a significant effect. A genuine, authorised and documented human assessment is important, but it must match the organisation’s actual practice. Have the specific design reviewed under data-protection law.

Does every private employer need a fundamental-rights impact assessment?

No. Article 27 AI Act principally targets public-law bodies, private providers of public services and specified financial-services uses. A GDPR DPIA may nevertheless be required for recruiting AI. A voluntary rights assessment can still improve governance for private employers.

Should teams wait until December 2027?

No. The Annex III high-risk rules for recruiting apply from that date, but privacy, employment law and practical preparation do not begin then. Teams that establish an inventory, evidence package, human oversight and consultation now will have a more defensible process when the deadline arrives.

Jürgen Ulbrich

CEO & Co-Founder of Sprad

Jürgen Ulbrich has more than a decade of experience in developing and leading high-performing teams and companies. As an expert in employee referral programs as well as feedback and performance processes, Jürgen has helped over 100 organizations optimize their talent acquisition and development strategies.

Free Templates &Downloads

Become part of the community in just 26 seconds and get free access to over 100 resources, templates, and guides.

No items found.

The People Powered HR Community is for HR professionals who put people at the center of their HR and recruiting work. Together, let’s turn our shared conviction into a movement that transforms the world of HR.

Similar Posts