The Week in One Line
If your company uses AI to screen CVs, rank candidates, target job advertisements, or monitor employee performance, those systems are likely classified as high-risk under the EU AI Act.
What the Act Actually Says
Employment and worker management is explicitly listed as one of the eight high-risk domains under Annex III.
The covered use cases include:
• filtering or ranking job applications • evaluating candidates during interviews • influencing promotion or termination decisions • assigning tasks • monitoring employee behaviour or performance • distributing targeted job advertisements
This is broader than many organisations realise.
The Act does not only apply to dedicated HR software. If a general-purpose AI system is being used in hiring or workforce decision-making, the classification can still apply.
That includes informal or shadow AI usage by recruiters and managers. A recruiter using a general AI assistant to summarise CVs, rank candidates, or generate interview evaluations may already be introducing high-risk AI into the hiring workflow.
Under Article 26, deployers of high-risk systems must:
• use the system according to provider instructions • assign meaningful human oversight • retain automatically generated logs for at least six months • actively monitor system operation • report serious incidents where required
One detail that catches many companies off-guard is targeted job advertising. If AI is being used to distribute job ads toward specific candidate profiles, the system may already fall within the high-risk framework.
Source: artificialintelligenceact.eu – Annex III (Point 4), Article 26
What This Means for Your Business
Many HR teams still assume compliance responsibility sits with the software vendor. Under the Act, it does not.
Buying an AI-enabled ATS or HR platform does not transfer deployer obligations to the provider. Your organisation remains responsible for how the system is actually used internally.
Human oversight must be operationally real.
Someone must actually: • understand the system • be able to intervene • override outputs when necessary • follow a documented escalation process
An org chart alone does not satisfy this requirement.
Log retention is another area many companies have not operationalised yet. Your vendor may generate automated decision logs, but you still need to ensure:
• you can access them • they are retained correctly • they can be produced during an investigation or audit
Most organisations are still underestimating how much informal AI usage is already happening inside hiring processes. Recruiters, managers, and HR teams are experimenting with AI tools daily, often without governance visibility.
That gap between actual usage and documented oversight is where a large percentage of future compliance problems will emerge.
The extraterritorial rule matters here too. If you are screening or evaluating candidates located in the EU, the Act can apply regardless of where your company is based.
This Week’s Action Point
Contact every HR, ATS, recruitment, or workforce platform vendor your company currently uses that includes AI functionality.
Ask them:
• How have you classified this system under the EU AI Act? • Can you provide the technical documentation relevant to deployer obligations? • What automated logs are generated, and can we retain them? • What human oversight assumptions does your system expect from deployers?
If the answers are vague, incomplete, or unclear, that risk currently sits with your organisation.
Further Reading
Guide for HR & Staffing Businesses: artificialintelligenceact.eu/what-the-act-means-for-staffing-businesses
Article 26 – Deployer Obligations: artificialintelligenceact.eu/article/26
Annex III – High-Risk AI Systems: artificialintelligenceact.eu/annex/3
Next Tuesday: The deployer problem, and why buying an enterprise AI platform does not remove your own legal and operational responsibilities.