The EU AI Act for HR & recruitment software
If your company builds or uses AI to hire, promote, or manage people, the EU AI Act treats that as one of its most sensitive categories. HR and recruitment AI sits squarely in the high-risk tier — which carries the Act's substantive obligations. Here is what that means, whether you make the software or just use it.
This is an information service to help you orient, not legal advice. For the obligations tied to your own AI use, see which apply to your company.
Why HR AI is high-risk
The Act lists specific "high-risk" use cases in Annex III, and employment and worker management is one of them. In practice that covers AI used to:
- recruit or select — advertise roles, screen applications, filter or rank candidates;
- decide on promotion or termination of working relationships;
- allocate tasks based on individual behaviour or traits; and
- monitor and evaluate the performance and conduct of workers.
So the common HR-tech tools — CV parsers, candidate-ranking engines, video-interview scorers, performance-analytics dashboards — are exactly what Annex III has in mind. (For the full test and the narrow exemption, see is your AI system high-risk?)
Two roles, two sets of duties
The Act splits responsibility between the provider (who builds the tool) and the deployer (the employer who uses it).
If you're the HR-tech provider, you carry the heavy stack: a risk-management system, data governance (your training data can't bake in bias), technical documentation, logging, human-oversight design, accuracy and cybersecurity, a quality-management system, a conformity assessment, and registration in the EU database before you go to market.
If you're the employer deploying the tool (Article 26), your duties are lighter but real:
- use the system according to the provider's instructions;
- assign competent human oversight — a person who can actually override it;
- keep the logs, and monitor for problems;
- inform the workers who are subject to it; and
- for many organisations, carry out a fundamental-rights impact assessment (Article 27) before first use.
A trap worth flagging: if you substantially modify a bought-in tool, or put your own branding on it, you can become its provider in the eyes of the law — and inherit the heavier duties.
The deadline just moved — but don't down-tools
The high-risk obligations for Annex III use cases were deferred by the Digital Omnibus from 2 August 2026 to 2 December 2027 (Regulation (EU) 2026/1744, in force since 27 July 2026). See what the Digital Omnibus changed.
That is runway, not a reprieve. Two duties are not deferred and can bite sooner:
- AI literacy (Article 4) — already in force: your staff operating the tool need a sufficient understanding of it.
- Transparency (Article 50) — if candidates interact with a recruitment chatbot, you must tell them they are dealing with AI.
What to do next
- List your HR AI and mark, for each, whether you're the provider or the deployer.
- Assume high-risk for anything that screens, ranks, or decides about people — and document the reasoning if you claim the Article 6(3) exemption.
- Start the deployer basics now — human oversight, worker notice, and logging are process changes that take time.
The fastest way to get your own dated list: answer three questions about your AI use and we'll show the verified obligations that match, sorted by deadline. Because these dates move — as the Digital Omnibus just showed — join the waitlist to be told the moment something that affects you changes.
The official text is Regulation (EU) 2024/1689. This article is an information service to help you orient — it is not legal advice.
Frequently asked questions
Is AI used in HR and recruitment high-risk under the EU AI Act?
Generally yes. AI used to recruit or select candidates (including CV screening and ranking), to decide on promotion or termination, to allocate tasks, or to monitor and evaluate performance is listed in Annex III as a high-risk use case. Systems doing that work are high-risk, with obligations for both the provider and the deploying employer.
When do the EU AI Act rules for HR AI apply?
The high-risk obligations for Annex III use cases — which include employment and worker management — were deferred by the Digital Omnibus from 2 August 2026 to 2 December 2027. The Article 4 AI literacy duty and any Article 50 transparency duties (for example a recruitment chatbot) already apply on their own timelines. Confirm the current date against the Official Journal.
We only buy an HR tool, we didn't build it — are we still covered?
Yes. As the employer using the system you are a 'deployer', and deployers have their own obligations: using the tool per the provider's instructions, ensuring meaningful human oversight, monitoring it, keeping logs, and informing affected workers. Certain deployers must also carry out a fundamental-rights impact assessment.
Can an HR AI tool avoid being high-risk?
Only narrowly. Article 6(3) exempts a system that performs a purely narrow procedural or preparatory task and poses no significant risk — but a system that profiles people is always high-risk, and most screening and ranking tools influence a real decision about a person. Assume high-risk and document any exemption you claim.
See which obligations apply to your company → or join the waitlist
This is an information service, not legal advice.