What the EU AI Act requires of companies using AI in hiring

Recruitment AI is high risk under the EU AI Act, the Digital Omnibus moved the deadline to 2 December 2027, and here is what a hiring team owes.


The EU AI Act classes AI used to advertise, filter or evaluate candidates as high risk. Buy such a tool and you are its deployer, not its provider: you owe human oversight, logs, worker and candidate notice. Most of those duties now apply from 2 December 2027, not August 2026.

This is a plain-language reference, not legal advice. Every date and article number is cited so you can check it.

Recruitment is named in the law, by name

Most regulation reaches hiring by accident. This one does not. Annex III, point 4(a) of Regulation (EU) 2024/1689 covers “AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates”. Point 4(b) extends the same treatment to promotion, termination, task allocation and performance monitoring (Annex III).

Sourcing tools, CV screeners, ranking engines and interview scorers are in scope by design. Job-ad targeting is in there too.

There is an escape hatch, narrower than vendors imply. Article 6(3) exempts a system that only performs a narrow procedural task, improves completed human work, detects patterns in prior decisions, or does preparatory work. But the same article ends with a sentence that swallows most of it: a system that performs profiling of natural persons is always high risk (Article 6). Anything that scores or ranks a person against a role profile is doing exactly that, on a plain reading.

Geography does not save you. Article 2(1)(c) catches deployers outside the Union “where the output produced by the AI system is used in the Union” (Article 2). A US screening tool used for an Amsterdam role is in scope.

The dates moved, and here is where they landed

If you read anything on this before mid-2026, the date you remember is wrong. The AI Act entered into force on 1 August 2024 on a staged timetable, and the Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026, deferred the high-risk chapter (EUR-Lex, Hunton).

DateWhat applies
2 February 2025Article 5 prohibitions and Article 4 AI literacy. Already binding.
2 August 2025General-purpose AI model rules, governance, penalties regime.
2 August 2026General application, including Article 50 transparency. Supervision of Article 4 follows on 3 August 2026.
2 December 2026Marking of AI-generated content for systems already on the market.
2 December 2027Annex III high-risk obligations: Articles 26, 27 and 86, and the penalties attached to them.
2 August 2028High-risk AI embedded in regulated products (Annex I).

The Future of Privacy Forum’s timeline breakdown confirms Articles 26, 27 and 86 all moved to 2 December 2027. Sixteen months is one procurement cycle plus one ATS migration.

Provider or deployer: the split that decides your workload

Almost every hiring team is a deployer. You become a provider only by building the system, badging someone else’s as your own, or substantially modifying it.

Provider (the vendor)Deployer (your hiring team)
Risk management, data governance, bias testingYesNo
Technical documentation, conformity assessment, EU database registrationYesNo
Designing oversight so a human can interveneYesNo
Naming competent people to exercise that oversightNoYes
Keeping logsProvides the capabilityRetains them, at least six months
Telling workers and candidatesNoYes
GDPR data protection impact assessmentSupplies the informationPerforms it

That table is the useful part of the regime. You are not being asked to audit a model, you are being asked to run a process around it.

What a deployer actually has to produce

Article 26 is short and concrete (full text). From 2 December 2027, a company using high-risk recruitment AI must:

  1. Use it according to the vendor’s instructions. Off-label use shifts liability toward you.
  2. Assign human oversight to named people with “the necessary competence, training and authority, as well as the necessary support”. Authority is the word that bites: a reviewer who cannot overturn the system is not oversight.
  3. Keep input data relevant and sufficiently representative, where you control it. Your own historic hires count as your input data.
  4. Monitor operation and notify the provider and your market surveillance authority of risks or serious incidents.
  5. Retain the automatically generated logs for at least six months.
  6. Inform workers’ representatives and affected workers before putting the system into service.
  7. Inform individuals that they are subject to a high-risk AI system: a line in the candidate privacy notice, and in the job ad.
  8. Perform your GDPR Article 35 DPIA, using the information the provider gives you.

Then Article 86: an affected person can ask for “clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken” (Article 86). A rejected candidate can ask why. If your tool cannot show its reasoning, you cannot answer, which is why explainable matching stopped being optional.

One thing you probably do not owe: the fundamental rights impact assessment under Article 27 binds public bodies, private entities providing public services, and deployers of credit-scoring and insurance pricing systems (Article 27). A private company hiring for itself is outside that list, whatever the compliance blogs say. Read the scope sentence.

Deployer breaches carry penalties up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs and start-ups the cap is the lower of the two (Article 99).

Three things that bind you today, not in 2027

Emotion inference in hiring is already banned. Article 5(1)(f) prohibits AI that infers emotions from biometric data in the workplace, except for medical or safety reasons, and the Commission’s February 2025 guidelines read “workplace” to include hiring processes (Future of Privacy Forum). Facial expression and voice tone scoring of candidates is out. The biometric wording is the limit of the ban, so scoring the sentiment of written answers sits outside it, but it still has to clear the high-risk rules and GDPR. Top penalty band: EUR 35 million or 7%.

AI literacy applies now. Article 4 has applied since 2 February 2025, and the Commission’s own Q&A confirms supervision and enforcement rules apply from 3 August 2026 (European Commission). The Omnibus softened the wording so no specific level is mandated, but high-risk deployers must still train the people doing oversight.

GDPR did not go anywhere. In SCHUFA Holding, Case C-634/21, decided 7 December 2023, the Court of Justice held that generating a probability score counts as automated individual decision-making under Article 22 where a third party draws strongly on it (A&O Shearman). Read across to hiring: a shortlist score that a manager rubber-stamps can itself be the decision. The separate Digital Omnibus on data, which proposes changes to Article 22, is still in Parliament and Council and is not law, so today’s Article 22 applies. Our note on GDPR-compliant sourcing covers the lawful-basis side.

What to ask a vendor before you sign

Three questions, all answerable in writing:

  • Do you classify this as high risk under Annex III point 4? If not, which Article 6(3) limb are you relying on, and how do you handle the profiling sentence?
  • What logs does it generate, can we export them, and what explanation can we show a rejected candidate?
  • Will you commit contractually to supplying the Article 13 instructions for use and our DPIA inputs before December 2027?

Ask us the same. Anyone selling AI recruiting software in Europe should answer without a call, and a vendor who bristles at question one has told you something.

What is still genuinely uncertain

Three things, said plainly. Harmonised standards for high-risk systems are not finished, so what “sufficient” documentation looks like is unsettled. The reach of the Article 6(3) carve-outs for sourcing tools that surface candidates without scoring them has not been tested by a regulator or a court. And the data-side Omnibus could still change the GDPR overlay before 2027. Anyone who says these are resolved is guessing.

The practical move for an in-house team is unglamorous: list which tools touch candidates, name the humans with override authority, check your logs export, fix the candidate notice. That is most of the work, and it improves your hiring whether or not anyone audits you. For the day-to-day version, see how recruiters catch what the system misses and why your skeptics are your best allies.

If you would rather talk it through with someone who has read the whole thing, book a call.