AI with Michal

EU AI Act (hiring use cases)

The EU AI Act classifies hiring-related AI systems as high-risk, requiring transparency, human oversight, bias testing, and technical documentation before deployment in recruitment or employment decisions for roles with EU-based workers or applicants.

Michal Juhas · Last reviewed May 26, 2026

What is the EU AI Act and how does it affect hiring?

The EU AI Act is a binding regulation that classifies AI systems by risk level and imposes obligations before those systems can be deployed. Annex III of the Act lists employment, worker management, and access to self-employment as a high-risk category, which means AI tools used to screen, rank, or evaluate candidates for EU-based roles carry significant compliance obligations.

The obligations are not hypothetical or future-dated. The high-risk employment AI provisions are phasing in from 2026 onward, and any company that uses AI in its EU hiring process, whether as an ATS feature or a standalone tool, needs to understand what is required before deployment rather than after a complaint.

Illustration: hiring AI system passing a high-risk classification gate under a compliance requirements band, flowing through a documentation node and human review gate before reaching a candidate outcome, with an audit log strip beneath

In practice

  • When an ATS vendor adds an AI matching score to candidate profiles and that score influences which candidates a recruiter views first for EU roles, that is a high-risk AI system under the Act regardless of whether the vendor calls it a recommendation or a filter.
  • A TA ops team building a custom AI screening workflow in Make or n8n for EU-based roles has the same high-risk classification obligations as the ATS vendor, because the deploying organization is considered a provider under the Act when they configure a general-purpose AI into a specific hiring application.
  • An HR legal team that asks for a vendor risk assessment before a new AI hiring tool goes live for EU roles is not being cautious for its own sake; they are responding to documentation and audit requirements that will be enforced by national supervisory authorities.

Quick read, then how hiring teams use it

This is for recruiters, TA leads, HR legal partners, and people ops teams who use AI tools in hiring for EU-based roles. Skim the first section for a working vocabulary to use in vendor conversations. Use the second when you are auditing your current toolstack, preparing for a legal review, or designing human oversight into a new AI-assisted workflow.

Plain-language summary

  • What it means for you: If your ATS, sourcing tool, or screening workflow uses AI to score or filter candidates for EU roles, the EU AI Act likely applies. You need documentation, human oversight, and a disclosure process before you deploy.
  • How you would use it: Start with an inventory of every AI feature in your current HR tech stack that touches EU-role candidates. Flag which ones make or influence a ranking, scoring, or filtering decision.
  • How to get started: Ask each of your HR tech vendors whether their AI features are classified as high-risk under Annex III. The response quality tells you how seriously they have engaged with compliance.
  • When it is a good time: Now. The conformity assessment, documentation, and oversight design all take time. Starting after the enforcement date is the most expensive approach.

When you are running live reqs and tools

  • What it means for you: The human-in-the-loop requirement under the Act is not optional. A qualified person must be able to review AI outputs and override them before any candidate outcome is determined. This changes how you design screening workflows, not just what you document.
  • When it is a good time: Every time you configure a new AI-assisted step in your EU hiring workflow. The oversight design should be built in from the start, not retrofitted after the workflow is running.
  • How to use it: Map each AI-assisted step in your hiring process. For each step, name the person responsible for reviewing the AI output, define what override authority they have, and log the review. That log is part of your compliance documentation.
  • How to get started: Take one AI feature you currently use for EU roles. Write a one-page description of what it does, what data it uses, how the output affects candidate outcomes, and who reviews it. That document is the start of your technical file.
  • What to watch for: Vendors who describe their AI features as recommendations or assists to avoid the high-risk classification, ATS configurations where AI scores are visible to recruiters before they review the underlying profile, and any workflow that advances or rejects candidates based on AI output without a documented human review step.

Where we talk about this

On AI with Michal live sessions, EU AI Act questions come up when participants are mapping their current toolstack and discovering that features they use daily, such as ATS ranking scores or async video interview evaluation, carry compliance obligations they have not yet addressed. The conversation usually moves quickly from vocabulary to vendor audit questions. Start at Sourcing Lab if you want the room discussion, or bring specific vendor questions to membership office hours where the compliance conversation can go deeper than a single session allows.

Around the web (opinions and rabbit holes)

Third-party creators move fast. Treat these as starting points, not endorsements, and verify any legal interpretation with your employment counsel before acting.

YouTube

Reddit

Quora

High-risk vs general-purpose AI in hiring

Use caseHigh-risk (Annex III)General-purpose (lower risk)
CV ranking or scoringYesNo
Async video interview evaluationYesNo
Chatbot FAQ responseNoYes
AI-assisted JD draftingNoYes
Candidate filtering in ATSYesNo
Interview summary generationBorderline: depends on how output is usedOften lower risk

Related on this site

Frequently asked questions

Which hiring use cases does the EU AI Act classify as high-risk?
Annex III of the EU AI Act lists employment, worker management, and access to self-employment as a high-risk domain. This covers AI tools that sort or filter job applications, evaluate or score candidates in the hiring process, and support decisions about promotion, task allocation, or workforce monitoring. In practice, this includes ATS ranking engines, automated resume screening tools, AI video interview scoring systems, and AI scheduling tools with automated filtering. The key test is whether system outputs materially affect hiring decisions for workers or applicants located in the EU at the time the decision is made, regardless of where the vendor or employer is headquartered.
What compliance obligations does the Act impose on employers?
Employers deploying high-risk AI in hiring must register the system in the EU AI Act database before use, obtain or complete a conformity assessment showing the system meets accuracy and bias requirements, implement a human oversight mechanism so a qualified person can override AI outputs, maintain technical documentation and logs for at least 10 years, and disclose to affected candidates and workers when AI materially influences decisions about them. For most TA teams, the immediate practical implication is that AI-assisted resume ranking for EU roles cannot operate as a silent background process. It must be documented, disclosed, and connected to a reviewable human decision step before any candidate outcome is determined.
When does the EU AI Act apply to my company's hiring process?
The Act applies when you deploy a high-risk AI system to make or materially influence decisions about people located in the EU at the time the decision is made, regardless of your company's headquarters. A US-based company using an AI screening tool for roles in its Amsterdam office is in scope. The high-risk employment AI provisions phase in from August 2026, with Member State enforcement timelines still developing. Companies purchasing AI HR tools from vendors should begin compliance conversations now: request conformity documentation, bias audit results, and transparency reports before the 2026 deadline. Starting late produces the highest compliance cost because remediation under active enforcement is more expensive than proactive design.
How does the Act interact with existing GDPR requirements?
The EU AI Act and GDPR overlap but address different obligations. GDPR for recruiting data already requires a lawful basis for processing candidate data, data minimization, and the right to explanation for automated decisions under Article 22. The AI Act adds technical requirements on top: formal logging, accuracy validation, and documented human oversight processes that go further than a standard DPIA covers. Some vendors are designing compliance documentation to satisfy both frameworks. Ask specifically whether vendor material addresses both the GDPR Article 22 transparency requirement and the AI Act high-risk technical file. If the answer is unclear, you likely need two separate legal reviews before deploying the system for EU roles.
What should TA teams ask vendors about AI Act compliance?
Five questions matter most. First: is this system classified as high-risk under Annex III? Second: if yes, has a conformity assessment been completed and can you provide the documentation? Third: what bias testing methodology was used and when was the last audit? Fourth: what human oversight controls are built into the product and who is the qualified person responsible for override decisions in our workflow? Fifth: what happens to our compliance obligations if the vendor updates the underlying model version mid-contract? Vendors who cannot answer these questions clearly are not ready for EU deployments of high-risk hiring AI. Log the answers as part of your vendor risk management record.
How should TA teams prepare internally before the 2026 deadline?
Three steps matter most. First, inventory every AI tool currently used in hiring for EU-based roles: vendor name, function performed, and whether a human review step happens before any output affects a candidate. Second, classify each tool against the high-risk criteria and flag which require formal conformity documentation from the vendor. Third, define your human oversight workflow: who reviews AI outputs before they influence a candidate's progress, what qualifications does that person hold, and how is the review logged. This inventory will also surface where your ATS data logs fall short of the 10-year retention requirement, which is a separate but related remediation project.
Where can TA teams discuss EU AI Act compliance with practitioners?
Practical EU AI Act questions for hiring teams, specifically which tools need compliance review and how to structure human oversight workflows, come up in AI in recruiting live sessions when participants map their toolstack. Bring the names of the AI tools you use in EU hiring, the functions they perform, and the EU countries where you hire; the room conversation gets specific fast. For policy context, the European Commission's published guidance and the Ada Lovelace Institute's Act coverage are useful external starting points. Ongoing compliance discussion as enforcement guidance develops through 2026 runs through membership office hours.

← Back to AI glossary in practice