EU AI Act and recruitment: what high-risk means for hiring teams
On this page
- The timeline, as amended
- What makes a recruitment tool high-risk
- Providers and deployers: who does what
- Deployer duties in practice for employers and agencies
- Transcription tools versus scoring tools
- What already applies: emotion recognition and disclosure
- An AI hiring tool register you can start now
- Penalties and enforcement
- Questions people ask
Under the EU AI Act, AI systems intended to be used for recruitment or selection, "in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates," are high-risk (Annex III, point 4(a)). Most obligations fall on the vendor, the provider, but employers and agencies that use these tools are deployers with their own duties: human oversight, monitoring, keeping logs and telling people the system is used. Those high-risk rules apply from 2 December 2027, after a 2026 amendment moved the original August 2026 date. The ban on emotion recognition in recruitment already applies.
This guide sets out the dates, the classification test, who carries which obligation, and how to think about interview tools that transcribe versus tools that score. It explains the rules; it does not classify your tool.
This is not legal advice. It summarizes Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 and the European Commission's guidance as of September 2026. The Commission's guidelines on high-risk classification were still in draft when we checked, and none of its guidance is binding; only the Court of Justice gives authoritative interpretations. National rules on penalties and employment also apply. Confirm your position with qualified EU counsel.
The timeline, as amended
The AI Act (Regulation (EU) 2024/1689) was published on 12 July 2024 and applies in stages under Article 113. The Digital Omnibus on AI (Regulation (EU) 2026/1744), adopted on 8 July 2026, published on 24 July 2026 and in force from the third day after publication, rewrote part of that schedule.
| Date | What applies | Relevance to hiring |
|---|---|---|
| 2 February 2025 | Chapters I and II: definitions, AI literacy (Article 4), prohibited practices (Article 5) | No emotion recognition of candidates; staff using AI need AI literacy measures |
| 2 August 2025 | Governance, general-purpose AI model rules, penalties chapter | Mostly affects model developers; penalty regimes set nationally |
| 2 August 2026 | General date of application, including Article 50 transparency duties | AI that talks directly to candidates must disclose it is AI unless obvious |
| 2 December 2027 | Chapter III, Sections 1 to 3 for Annex III systems: classification, provider and deployer obligations | The main recruitment rules start here (originally 2 August 2026) |
| 2 August 2028 | The same for Annex I product-safety systems | Rarely relevant to hiring |
The Omnibus also replaced Article 4. Providers and deployers must now "take measures to support the development of AI literacy" of staff using AI, and the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual." Training interviewers on what a tool's output means, and what it does not mean, is still expected.
One transitional rule matters for buyers. Under Article 111(2) as amended, the Act applies to high-risk systems placed on the market or put into service before the Chapter III date "only if, as from that date, those systems are subject to significant changes in their designs." How that plays out for continuously updated software is a question for counsel, not a reason to assume an existing tool is exempt.
What makes a recruitment tool high-risk
Article 6(2) makes the systems listed in Annex III high-risk. Point 4 covers employment: 4(a) for recruitment and selection, and 4(b) for decisions after hiring, such as promotion, termination, task allocation and performance monitoring. Classification follows the system's "intended purpose," which Article 3(12) defines as the use intended by the provider "as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation." Marketing claims count.
The Article 6(3) filter
An Annex III system is not high-risk if it "does not pose a significant risk of harm ... including by not materially influencing the outcome of decision making," and it meets one of four conditions:
- it is intended to perform a narrow procedural task;
- it is intended to improve the result of a previously completed human activity;
- it detects decision-making patterns or deviations without replacing or influencing the completed human assessment, without proper human review; or
- it performs a preparatory task to an assessment relevant to the Annex III use.
Two limits. A system that performs profiling of natural persons is always high-risk. And a provider relying on the filter must document its assessment before sale and register the system in the EU database under Article 49(2); the Omnibus kept that registration but simplified its content.
What the Commission's draft guidance says about hiring tools
On 19 May 2026 the Commission published draft guidelines on high-risk classification for consultation (the targeted consultation closed on 23 July 2026; no final version as of September 2026). The Annex III document reads "evaluate candidates" broadly: evaluation is "any assessment of a candidate's ... suitability, merit or potential, whether through scoring, ranking, predictive modelling, or qualitative judgements," and it need not decide the outcome, only appreciably influence it. Its examples:
| Draft guidance example | Draft conclusion |
|---|---|
| Job matching tool that scores and ranks candidates against a job description | High-risk |
| Agency sourcing tool that searches job boards and CV databases and shortlists profiles | High-risk |
| System that scores applicants' written or oral answers and ranks who is invited to interview | High-risk |
| Background check tool producing risk scores or "high risk" flags | High-risk (profiling) |
| Interview scheduling assistant, including accessibility preferences | In the use case but filtered out as a narrow procedural task |
| Parsing CVs into a searchable database; verifying a credential against an official register | Filtered out |
| Checker that flags non-inclusive wording in job ads | Outside the use case |
The draft also says tools "that merely present factual information without involving evaluative weight" may fall outside scope if they do not generate assessments of suitability. It does not give an example of interview transcription or note-taking.
Providers and deployers: who does what
A provider develops an AI system, or has one developed, and places it on the market or puts it into service "under its own name or trademark." A deployer is anyone "using an AI system under its authority" in a professional capacity (Article 3). A software vendor is normally the provider. The employer, the in-house recruiting team and the staffing agency using the tool are normally deployers.
| Area | Provider (vendor) | Deployer (employer or agency) |
|---|---|---|
| Risk and quality | Risk management, data governance, technical documentation, quality management system | Use the system according to the instructions for use (Art. 26(1)) |
| Conformity | Conformity assessment, CE marking, EU database registration | No conformity assessment; public-authority deployers register their use |
| Human oversight | Design the system so people can oversee it | Assign oversight to people with the competence, training, authority and support (Art. 26(2)) |
| Data | Training data quality and bias examination | Where you control input data, make sure it is relevant and sufficiently representative (Art. 26(4)) |
| Monitoring and incidents | Post-market monitoring, serious incident reporting | Monitor operation, suspend and report if a risk emerges, report serious incidents (Art. 26(5)) |
| Logs | Build automatic logging | Keep logs under your control for at least six months, unless other law says otherwise (Art. 26(6)) |
| People affected | Instructions and transparency to deployers | Inform workers' representatives and affected workers before workplace use (Art. 26(7)); inform people subject to decisions (Art. 26(11)); give explanations on request (Art. 86) |
When a deployer becomes the provider
Article 25(1) treats a deployer as a provider if it puts its name or trademark on a high-risk system, makes a substantial modification to one, or modifies the intended purpose of a system that was not high-risk "in such a way that the AI system concerned becomes a high-risk AI system." For hiring teams, the third case is the one to watch: a general-purpose chatbot is not a recruitment tool until you build a workflow that uses it to score or rank candidates. An agency that builds its own candidate-matching model is a provider from the start.
Territorial reach
Article 2(1)(c) covers providers and deployers located outside the EU "where the output produced by the AI system is used in the Union." A US or UK agency evaluating candidates for EU roles should not assume the Act stops at the border.
Deployer duties in practice for employers and agencies
From 2 December 2027, for any recruitment tool that is high-risk, plan for these:
- Read and follow the instructions for use. Providers must supply them. Using a tool outside them weakens your position and may change who is the provider.
- Name the overseers. Human oversight is a role with training and authority, not a checkbox. Someone must be able to disregard or override the output.
- Control your inputs. Job descriptions, knockout criteria and scoring rubrics you feed into a tool are input data you control.
- Keep logs for at least six months, reconciled with your GDPR retention periods; Article 26(6) defers to data protection law.
- Inform before use. Workers' representatives and affected workers before workplace use under Article 26(7); candidates who are subject to decisions under Article 26(11).
- Be ready to explain. Article 86 gives a person subject to a decision based on an Annex III system's output, with legal or similarly significant effects, the right to "clear and meaningful explanations of the role of the AI system." Article 86 sits outside Chapter III, so it is not named in the postponement, but the classification rules it depends on are; how it applies before December 2027 is unsettled.
- Use the provider's information in your DPIA. Article 26(9) links the AI Act to the GDPR's data protection impact assessment, which already applies today.
The fundamental rights impact assessment in Article 27 is required of public bodies, private entities providing public services, and deployers of certain credit and insurance systems. Most private employers and agencies using recruitment AI are not on that list, but check whether you provide public services.
Transcription tools versus scoring tools
AI interview tools usually bundle several functions, and the Act classifies by intended purpose, so look at each function. The table below points to the relevant text and the question to ask. It does not conclude for any tool.
| Function | Relevant text | Question to answer |
|---|---|---|
| Transcript of the interview | Draft guidance: tools that "merely present factual information without involving evaluative weight" may fall outside scope | Is the output only a record of what was said? |
| Summary of the conversation | "Qualitative judgements" count as evaluation | Is it a neutral summary, or does it characterize the candidate as strong, weak or a fit? |
| Question guide from a job description | Article 6(3)(a) and (d): narrow procedural or preparatory tasks | Does it only shape what the interviewer asks, or does it filter who gets asked? |
| Ratings per competency or an overall score | "scoring, ranking, predictive modelling"; appreciable influence on the decision | Who produces the rating, and how much weight does it carry in the decision? |
| Ranking or advance/reject recommendation | The draft's job-matching and answer-scoring examples | Does it shortlist or order candidates? |
| Tone, sentiment or emotion reading | Article 5(1)(f) prohibition, in force since 2 February 2025 | Does any feature infer emotions or intentions from voice or face? |
| AI interviewer or avatar that talks to candidates | Article 50(1) disclosure since 2 August 2026; answer scoring is a draft high-risk example | Is it clear to candidates they are talking to AI, and does it score them? |
The same questions apply to every vendor, including Interview Signal, whose scorecards attach ratings to evidence quotes from the transcript. What the provider says the feature is for, and how your team uses its output, both matter. A transcription feature does not make the whole product low-risk, and the Commission's examples are a draft.
What already applies: emotion recognition and disclosure
Article 5(1)(f) bans placing on the market, putting into service or using AI "to infer emotions of a natural person in the areas of workplace and education institutions," except for medical or safety reasons. The Commission's guidelines on prohibited practices say "workplace" should "also be understood to apply to candidates during the selection and hiring process," and give as an example that "using emotion recognition AI systems during the recruitment process is prohibited" (paragraph 254). Fines for prohibited practices reach EUR 35 million or 7% of worldwide annual turnover, whichever is higher, under Article 99(3).
Since 2 August 2026, Article 50(1) has required providers to design AI systems that interact directly with people so those people are told they are dealing with AI, unless that is obvious. If you use a voice or chat AI to screen candidates, check that the disclosure happens at the first interaction.
None of this replaces the GDPR, which already governs recordings, transcripts and automated decisions about EU candidates. The guide to recording interviews under UK GDPR covers lawful basis, notices, DPIAs and retention, with a section on EU differences.
An AI hiring tool register you can start now
About fifteen months is not long for an inventory, vendor questions and interviewer training. One entry per tool feature, kept with your DPIAs:
AI hiring tool register (one entry per feature)
Tool / vendor: [name, version, contract owner]
Feature: [e.g. transcript, summary, competency ratings]
Provider's stated purpose: [quote the vendor's documentation or sales page]
Roles and countries: [EU roles? candidates located in the EU?]
Output type: [record / summary / score / ranking / recommendation]
How the output is used: [who sees it, weight in the decision, can it be overridden]
Emotion or biometric?: [does anything infer emotions, voiceprints, faces]
Our classification view: [not in use case / 6(3) filter / high-risk / unsure]
Basis and date: [counsel, date, documents relied on]
Are we a provider?: [our name on it? modified? changed its purpose?]
Human overseer(s): [names, training date]
Logs kept and for how long: [location, retention]
Notices: [candidates, workers' representatives, privacy notice]
DPIA reference: [link]
Vendor answers outstanding: [conformity plan, instructions for use, 6(3) registration]
Review date: [before 2 December 2027, and on any product change]
Questions worth sending to each vendor now:
- Do you consider this product, or any feature, to fall within Annex III point 4(a)? On what basis?
- If you rely on Article 6(3), which condition, and will you register under Article 49(2)?
- If high-risk, what is your conformity plan for 2 December 2027, and when will we receive instructions for use?
- Does any feature infer emotions, intentions or personality from voice, video or text?
- Can scoring or ranking features be switched off while keeping the rest?
Penalties and enforcement
Member States set the penalty rules and appoint market surveillance authorities. The Act caps administrative fines by tier in Article 99:
| Breach | Maximum fine |
|---|---|
| Prohibited practices (Article 5), including emotion recognition of candidates | EUR 35,000,000 or 7% of worldwide annual turnover, whichever is higher |
| Deployer obligations (Article 26), provider obligations, Article 50 transparency | EUR 15,000,000 or 3%, whichever is higher |
| Incorrect, incomplete or misleading information to authorities | EUR 7,500,000 or 1%, whichever is higher |
For SMEs and start-ups, each cap is whichever of the two figures is lower (Article 99(6)). The Article 26 duties sit in the postponed part of Chapter III and apply from 2 December 2027; the Article 5 ban and Article 50 duties apply now.
If you also hire in the United States, the rules there are local and very different in shape; the summary of AI hiring laws by state links to guides on NYC Local Law 144, Illinois and Colorado.
Questions people ask
When do the EU AI Act's high-risk rules apply to recruitment tools?
From 2 December 2027 for Annex III systems, which include recruitment and selection. The original date was 2 August 2026; Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved it. The ban on emotion recognition in the workplace has applied since 2 February 2025.
Does the EU AI Act apply to a US company hiring people in the EU?
It can. Article 2(1)(c) covers providers and deployers established outside the EU where the output produced by the AI system is used in the Union. A non-EU employer or agency using an AI tool to evaluate candidates for EU roles should assume the Act may reach it and take advice.
Is using ChatGPT to rank CVs a high-risk use?
Possibly, and it can make you the provider. Under Article 25(1)(c), a deployer that changes the intended purpose of a general-purpose AI system so that it becomes high-risk is treated as a provider, with the provider's much heavier obligations.
Can we use AI that reads candidates' emotions in video interviews?
Article 5(1)(f) prohibits AI that infers emotions in the workplace except for medical or safety reasons, and the Commission's guidelines on prohibited practices say that includes candidates during selection and hiring. Do not use such features with EU candidates without specific legal advice.
Do we have to tell candidates we use a high-risk AI system?
When the high-risk rules apply, Article 26(11) requires deployers of Annex III systems that make or help make decisions about people to inform those people. GDPR transparency duties apply already, whatever the AI Act classification.