Compliance8 min read

The EU AI Act and Recruiting: What HR Leaders Actually Have to Do in 2026

AI that screens or evaluates candidates is high-risk under the EU AI Act. The obligations that actually apply to hiring teams, and what to do about them.

Andreas Amann

AI systems that screen, rank or evaluate job candidates are classified as high-risk under Annex III, point 4 of the EU AI Act, Regulation (EU) 2024/1689. That creates duties for whoever does the hiring, not just the vendor: real human oversight, information to candidates and workers, record-keeping, and an explanation on request. Agencies and in-house teams carry the same obligations.

Most of what is written about the AI Act and hiring is either alarmist or too vague to act on. I built a recruiting product, so discount my reading accordingly. Making these calls in practice is a different exercise from writing about them.

Why recruiting is high-risk, and why the exemption probably does not save you

Article 6(2) makes the systems listed in Annex III high-risk. Point 4(a) covers AI intended for the recruitment or selection of natural persons, naming three things explicitly: placing targeted job advertisements, analysing and filtering job applications, and evaluating candidates. Point 4(b) covers promotion and termination decisions, task allocation, and performance monitoring.

Article 6(3) then carves out an exemption for Annex III systems that pose no significant risk to fundamental rights and only perform a narrow procedural task, improve the result of completed human work, or do preparatory work. Vendors will point at this.

Then read the closing sentence of Article 6(3). A system referred to in Annex III is always considered high-risk where it performs profiling of natural persons. Profiling, as GDPR defines it, is automated processing used to evaluate personal aspects of someone: performance at work, reliability, behaviour. A fit score, a shortlist rank, a percentage match against a brief: all profiling. The exemption is real, but it does not cover what most recruiting AI is sold to do.

Article 6(4) requires a provider claiming the exemption to document that assessment before placing the system on the market. So the question to that vendor is not "are you high-risk?" It is: send me the Article 6(3) assessment. If it does not exist, neither does the claim.

When the EU AI Act rules for hiring actually apply

DateWhat starts applying
1 August 2024Regulation enters into force
2 February 2025Prohibited practices (Article 5), AI literacy duty (Article 4)
2 August 2025Governance, penalties, national authorities, general-purpose AI
2 August 2026General application: Annex III high-risk obligations, Article 50 transparency
2 August 2027High-risk AI inside products already regulated under EU product law

One caveat: the Commission has proposed adjustments to parts of the high-risk timetable, tied to the availability of harmonised standards. Check its status with counsel before you set an internal deadline, including against the dates in this article. The substance does not move.

Are you a deployer, or did you accidentally become a provider?

An employer or agency using a vendor's screening tool is a deployer, and Article 26 is your chapter.

Article 25 is the trap. You become the provider if you put your own name on a high-risk system, substantially modify one, or change its intended purpose so that it becomes high-risk. That last clause is the one in-house teams and agencies walk into. Wiring a general-purpose model into a homemade CV-screening script is not a small internal automation project: it makes your company the provider of a high-risk AI system, with risk management, data governance, technical documentation, conformity assessment and registration attached. Building it yourself is usually the most heavily regulated option available, and nobody costs it that way.

The six things a hiring team actually has to do

ObligationSourceWhat it means in practice
Know the classificationArticle 6Ask the vendor in writing. If they say not high-risk, ask for the Article 6(3) assessment
Get the instructions for useArticle 13The provider owes you documented capabilities, limitations, accuracy levels and oversight measures. A vendor who cannot produce these has answered your buying question
Assign oversight to named peopleArticles 14, 26(2)The provider must design for oversight; you must assign it to people with the competence, training and authority to override the output
Inform workers and candidatesArticles 26(7), 26(11), 50Tell workers' representatives and affected workers before go-live, tell individuals they are subject to it, and if a candidate is talking to an AI, say so
Keep the logsArticle 26(6)Retain system logs under your control for at least six months
Explain one decision on demandArticle 86An affected person can require a clear explanation of the AI's role and the main elements of the decision

One clarification that saves money: the fundamental rights impact assessment in Article 27 does not bind most private employers. It applies to public bodies, private entities providing public services, and deployers of the creditworthiness and insurance systems in Annex III point 5. If a consultancy quotes you a mandatory FRIA on your ATS, ask which limb of Article 27 you fall under.

Where the AI Act meets GDPR Article 22

The AI Act does not replace GDPR. Both apply to the same rejection email. Article 22 gives a candidate the right not to be subject to a decision based solely on automated processing that significantly affects them. Being screened out of a job qualifies, and most employers believe they have solved it because a human clicks the final button.

The CJEU's SCHUFA judgment (C-634/21) is why that belief is unsafe. The Court treated an automated score as itself the decision where the recipient draws strongly on it. Translate that to hiring: if your recruiter reviews the top twelve candidates the model surfaced and never sees the two hundred and forty it filtered out, the model decided those rejections. Review of the shortlist is not review of the screening.

That produces three design requirements, the same ones the AI Act's oversight and explanation duties push you toward:

  • The rejected set stays visible and reviewable, not silently truncated below a threshold.
  • The reasoning has to be legible enough to disagree with. A score of 71 with no evidence attached cannot be overridden on any rational basis, so the oversight is theatre.
  • Every outcome needs an author and a reason recorded at the time. Reconstructing a rationale eleven months later, when a candidate asks under Article 86, is a fire drill, not a process.

The GDPR obligations your ATS has to handle overlap heavily with that list, and the GDPR-compliant recruiting software checklist turns most of it into vendor questions.

What is genuinely still unsettled

Harmonised European standards are unfinished, so there is no meaningful conformity badge for most Annex III systems yet. If a vendor says they are "AI Act certified", ask what they were certified against and by whom.

The scope of the Article 5(1)(f) prohibition on emotion inference in the workplace is still argued at the edges, particularly whether the recruitment stage sits inside it. The prudent reading is that inferring emotional state from a candidate's face or voice is prohibited.

In Germany and Austria the earlier gate is often national labour law: works council co-determination over performance-monitoring systems and selection guidelines can stop a rollout months before any AI Act deadline matters. Talk to the works council before you talk to the vendor.

What Pickr does about it, and what I will not claim

Pickr is the AI-native recruiting platform built so that the AI proposes and a named person decides. That is a deliberate design decision, not a compliance feature bolted on after the Regulation passed.

Every candidate score carries the evidence behind it, so a recruiter can disagree with a specific claim rather than with a number. Advances and rejections are recorded with an author and a reason, and Pickr challenges a significant decision that has no documented reasoning at the moment it is made, which is the record Article 86 later assumes exists. Interview transcripts and pre-filled scorecards map evidence to each criterion and are reviewed by the interviewer before they count, which is the difference between interview intelligence and automated evaluation. Data is hosted in Germany, the product is built in Austria, a data processing agreement is included, and personally identifying information is redacted from AI prompts by default.

What I will not claim: Pickr is not "EU AI Act certified", because for a system of this kind that certification does not yet meaningfully exist, and classification depends partly on how you configure and use the system.

If you do not know whether your process can produce a documented reason for each rejection, the deeper version of Pickr's free recruiting audit connects read-only to your ATS and reports scorecard and interview compliance stage by stage. The key is never stored, the data stays in the EU, and it is deletable at any time.

The decision in front of you is not whether to use AI in hiring. It is whether, for any candidate you rejected in the last six months, you can name the person who decided, the reason they gave, and the part the AI played. If you can, 2026 changed your paperwork. If you cannot, it changed your exposure.

Frequently Asked Questions

Is AI used for recruiting high-risk under the EU AI Act?

Yes, in almost every practical case. Annex III, point 4(a) of Regulation (EU) 2024/1689 lists AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates. Article 6(3) contains a narrow exemption for systems that only perform preparatory or procedural tasks, but the same article states that a system is always high-risk where it performs profiling of natural persons. Any tool that scores, ranks or shortlists candidates is profiling, so the exemption rarely applies.

When do the EU AI Act rules for hiring AI apply?

Under Article 113 of the Regulation, the general application date is 2 August 2026, and that is the date on which the obligations for Annex III high-risk systems and the Article 50 transparency duties bite. Two earlier tranches are already in force: the prohibited practices in Article 5 and the AI literacy duty in Article 4 applied from 2 February 2025, and the governance, penalty and general-purpose AI provisions from 2 August 2025. The Commission has proposed amendments to parts of the high-risk timetable, so confirm the current status with your own counsel before setting an internal deadline.

What does an employer have to do when using an AI screening tool?

As a deployer under Article 26, you must use the system according to the provider's instructions for use, assign human oversight to named people who have the competence, training and authority to override the output, make sure the input data is relevant for the purpose, monitor operation, and keep the system logs for at least six months. Article 26(7) additionally requires you to inform workers' representatives and affected workers before putting a high-risk system into service at the workplace, and Article 26(11) requires you to inform the individuals subject to it. Under Article 86, a rejected candidate can ask you for a clear and meaningful explanation of the role the AI played in the decision.

Does the EU AI Act ban AI in hiring?

No, and high-risk is not the same as prohibited. The Act permits AI in recruitment provided the provider meets the requirements in Chapter III and the deployer meets Article 26. One recruiting-adjacent practice is genuinely banned: Article 5(1)(f) prohibits AI systems that infer the emotions of a natural person in the workplace, which has applied since 2 February 2025. The safe reading is that inferring a candidate's emotional state from their face or voice during an interview is out of bounds.

How does the EU AI Act interact with GDPR Article 22?

They stack; neither replaces the other. GDPR Article 22 gives candidates the right not to be subject to a decision based solely on automated processing that significantly affects them, with a right to human intervention and to contest the outcome. The CJEU's SCHUFA ruling (C-634/21) held that an automated score which the recipient draws strongly on can itself be the decision, which means a recruiter who rubber-stamps a ranking without seeing what it filtered out has not provided meaningful human involvement. The AI Act adds oversight, information, logging and explanation duties on top of that, and both regimes can be enforced against the same hiring process.

Free recruiting audit · 2 minutes

Find out what your hiring process is actually costing you.

Answer eight questions, or connect your current system read-only, and get a report on where your funnel loses candidates and which changes are worth making. No signup, no API key stored, data stays in the EU.

A

Written by Andreas Amann

Founder of Pickr. Former operator at startups in Berlin and Silicon Valley, where he helped scale companies from 40 to 200+ people. Built Pickr after years of using every major ATS as a recruitment agency owner at ScalingPPL.

Read more