The EU AI Act names recruitment as a high-risk use of AI. Annex III, point 4(a) covers AI systems “intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates”. If you build, sell or use software that screens resumes, scores candidates or ranks a shortlist, this article is the checklist to work through.
It reflects the text as amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on 27 July 2026 and moved the high-risk deadlines. It is written for product, HR and compliance teams and is not legal advice: confirm your own classification with counsel.
Key dates after the Digital Omnibus
The Commission first proposed to tie the high-risk rules to the availability of harmonised standards. The adopted Omnibus dropped that mechanism and set fixed dates instead.
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices (Article 5), including emotion inference in the workplace, and the original AI literacy duty (Article 4). |
| 2 August 2025 | Penalties: the Article 5 bans can be fined. |
| 27 July 2026 | The Omnibus enters into force. The lighter AI literacy wording of Article 4 applies from this date. |
| 2 August 2026 | General date of application, including the Article 50 transparency obligations. |
| 2 December 2027 | High-risk rules for Annex III systems, recruitment included: classification, requirements, provider and deployer obligations. |
| 2 August 2028 | High-risk rules for Annex I systems (safety components of regulated products). |
Amended Article 111(2) adds a grace period: a high-risk system placed on the market before 2 December 2027 only falls under the high-risk rules if its design changes significantly after that date. Do not plan around it if your models are retrained or updated often, because what counts as a significant change for a continuously updated service is not settled.
Step 1: is your recruiting tool high-risk?
Article 6(2) makes every Annex III system high-risk by default. Article 6(3) lets a provider argue otherwise when the system does not materially influence the outcome of decisions and meets at least one of four conditions: it performs a narrow procedural task, improves the result of a completed human activity, detects patterns without replacing human assessment, or performs a preparatory task.
Two rules limit that exception for recruiting tools. First, an Annex III system that profiles natural persons is always high-risk, and scoring a candidate’s fit evaluates personal aspects such as performance at work. Second, the Commission’s draft guidelines of 19 May 2026, which are not final yet, give concrete examples:
- High-risk: an automated job matching and ranking tool that compares CVs with job descriptions to produce scores, rankings such as a “top 5”, or fit categories. It stays high-risk even when recruiters can review and override it.
- High-risk: candidate sourcing tools that search for and profile people across platforms.
- Can use the exception: a system that recognises and organises the information in CVs into a searchable database, in other words plain resume parsing.
- Can use the exception: checking accreditations against an official register, scheduling interviews, or drafting a job description from criteria a human defined. A job description tool that also scores CVs against the description is high-risk.
- Outside point 4(a): tools used only by candidates, such as CV tailoring, and tools that check job ads for discriminatory wording.
Your checklist for this step:
- List every AI feature in your hiring flow and its intended purpose.
- Mark each one as high-risk, exception under Article 6(3), or out of scope, with the reasoning.
- If you rely on the exception, write the assessment down before the product is placed on the market (Article 6(4)) and plan the registration in the EU database (Article 49(2)).
- Re-check the classification when the Commission publishes its final guidelines.
Step 2: what already applies today
Some obligations are not waiting for 2027. Check these now, whatever your classification:
- No emotion inference at work (Article 5(1)(f)). The ban covers inferring emotions from biometric data in the workplace, and the Commission’s guidelines apply it to candidates during recruitment: no emotion scoring from faces, voices or keystrokes in video interviews.
- No biometric categorisation (Article 5(1)(g)). No system that deduces race, political opinions, trade union membership, religion, sex life or sexual orientation from a photo or a video.
- No social scoring (Article 5(1)(c)). Be careful with tools that score people from their social media behaviour or personality traits and use that score against them.
- AI literacy (Article 4, as amended). Providers and deployers must “take measures to support the development of AI literacy” of the staff who operate and use AI systems. Since 27 July 2026 the text no longer requires a guaranteed level for each person, but you should be able to show what you did: training for recruiters, written guidance on how to read scores, a named owner.
Fines for the Article 5 bans go up to EUR 35 million or 7% of worldwide turnover. The Omnibus applies the lower of the two amounts to small mid-caps.
Step 3: provider checklist (vendors and ATS builders)
The provider is whoever places the high-risk system on the market under its own name. From 2 December 2027, an Annex III provider needs:
- Risk management (Article 9) across the whole lifecycle of the system.
- Data governance (Article 10), including an examination of possible biases in training, validation and test data. New Article 4a lets providers process special category data when strictly necessary to detect and correct bias, with pseudonymisation, access controls and deletion once the bias is corrected.
- Technical documentation (Article 11 and Annex IV). SMEs, start-ups and small mid-caps can use a simplified form.
- Automatic logging (Article 12) over the system’s lifetime, and logs kept for at least six months (Article 19).
- Instructions for use (Article 13) with the intended purpose, accuracy metrics, known limitations, performance on specific groups, input data specifications and the information needed to explain outputs.
- Human oversight by design (Article 14): interfaces that let a person understand, review and override the output.
- Accuracy, robustness and cybersecurity (Article 15).
- A quality management system (Article 17), proportionate to the size of the provider. EN 18286, the first harmonised standard for AI quality management, was made available in July 2026; it gives a presumption of conformity once it is cited in the Official Journal.
- Conformity assessment by internal control (Article 43(2)). For employment systems this is a self-assessment under Annex VI, with no notified body.
- EU declaration of conformity, digital CE marking and registration (Articles 47 to 49) before the system is placed on the market.
- Post-market monitoring and serious incident reporting (Articles 72 and 73), and documentation kept for 10 years (Article 18).
See per-criterion explanations in practice
Run a resume and a job description through the demo and look at how each criterion comes back with a status and an explanation a recruiter can check.
Step 4: deployer checklist (employers and recruiters)
The deployer is the organisation that uses the system, usually the employer or the recruitment agency. From 2 December 2027, Article 26 requires it to:
- Use the system according to the provider’s instructions for use.
- Assign human oversight to people with “the necessary competence, training and authority”.
- Make sure the input data it controls, such as job requirements, is relevant and sufficiently representative.
- Monitor the system, suspend it and inform the provider if it presents a risk, and report serious incidents.
- Keep the logs under its control for at least six months, unless other law, such as the GDPR, requires otherwise.
- Inform workers’ representatives and affected workers before using the system at the workplace.
- Inform candidates that a high-risk AI system is used in decisions about them (Article 26(11)).
- Use the provider’s information to carry out the GDPR data protection impact assessment.
A fundamental rights impact assessment (Article 27) is only required from public bodies and private entities providing public services, so a public employer or a public employment service needs one and most private employers do not. Article 86 also gives a candidate who is adversely affected by a decision based on a high-risk system’s output the right to clear and meaningful explanations of the role of the AI system and the main elements of the decision.
Step 5: GDPR and French rules
The AI Act does not replace the GDPR. For hiring, three points matter most:
- Article 22 GDPR gives candidates the right not to be subject to a decision based solely on automated processing with significant effects. Keep a real human review of every rejection, and be ready to explain the logic involved: in C-203/22 the Court of Justice said people can ask for the procedure and principles actually applied, in an intelligible form.
- The CNIL recruitment guide warns that a ranking tool can amount to a fully automated decision when the volume means low-ranked candidates are never looked at, or when recruiters cannot explain the reasons for a decision the tool proposed. It also asks recruiters to check that tools use clear criteria related to professional aptitudes only, and to keep candidate pools for no more than two years after the last contact.
- The French Labour Code requires recruitment methods to be relevant to the job and disclosed to candidates beforehand (articles L.1221-6 to L.1221-9), and the works council (CSE) to be informed before new recruitment techniques are introduced (article L.2312-38).
Who is the provider when you buy an API?
Many ATS vendors build screening features on top of third-party APIs. Under Article 25, a company becomes the provider of a high-risk system if it puts its own name on it, substantially modifies it, or changes its intended purpose so that it becomes high-risk. The Omnibus also requires a written agreement between a provider and the third parties whose tools, components or models are integrated into a high-risk system, covering the information, capabilities and technical access the provider needs.
In practice: decide early who is the provider of the screening feature your customers see, write it into your contracts, and make sure your API supplier can give you the documentation, known limitations and test access you will need for your own conformity assessment.
Twelve questions to ask a recruiting AI vendor
- Which features do you consider high-risk under Annex III point 4(a), and which fall under the Article 6(3) exception? Is that assessment written?
- If we embed your API in our own product, who is the provider? Will you sign the written agreement required by Article 25(4)?
- What do your instructions for use contain: accuracy metrics, known limits, performance by language and country, input requirements?
- Does every score or rank come with the criteria met or missed and the evidence from the CV?
- Can recruiters review, override and re-rank results? Is there any automatic rejection or hard filter by default?
- What is logged for each call, and can we export logs and keep them for at least six months?
- Can we turn off data retention per request? Do you train on our data? Where is the data processed, and who are your sub-processors?
- How do you test for bias, how often, and with which metrics?
- Can you confirm in writing that you do not infer emotions, categorise people biometrically or score social media behaviour?
- How are model changes versioned and announced before they reach production?
- What is your roadmap for 2 December 2027: quality management, technical documentation, declaration of conformity, registration?
- What material do you provide for our own duties: candidate information, a works council briefing, inputs for our impact assessment?
How the HireLayer API fits this checklist
HireLayer provides recruiting APIs that other software calls: resume parsing, job criteria extraction, candidate matching and ranking. Some of its observable behaviour maps directly onto the points above:
- Criteria a human can review. Job criteria are extracted as a separate step and passed back explicitly to the matching call, so a recruiter can read, edit or remove them before any candidate is scored.
- Explanations per criterion. Each evaluated criterion comes back with a match status and an explanation of what the CV shows, or does not show, for that requirement, which supports human review and answers to candidates.
- No retention on request. Setting
do_not_store_datatotrueon a parsing request means the file is not stored and the parsed data is not retained.
These features help a team meet its oversight and transparency duties; they do not make an integration compliant by themselves. Matching and ranking candidates is the kind of use the draft guidelines list as high-risk, so the classification, documentation and deployer duties above still apply to the product you build with it.
Frequently asked questions
When do the high-risk rules apply to recruiting AI?
From 2 December 2027 for Annex III systems, which include recruitment and selection tools. The Digital Omnibus on AI (Regulation (EU) 2026/1744) set that date. The bans in Article 5 and the AI literacy duty in Article 4 already apply.
Is a resume parser high-risk under the AI Act?
Not necessarily. The Commission’s draft guidelines treat a system that only organises CV information into a searchable database as able to use the Article 6(3) exception. The provider must still document that assessment and register the system. Scoring or ranking candidates is a different use and is listed as high-risk.
Does a human in the loop make a ranking tool low-risk?
No. The draft guidelines say a matching and ranking tool stays high-risk even when recruiters can review and override its output. Human oversight is one of the requirements for high-risk systems, not a way out of them.
Do private employers need a fundamental rights impact assessment?
Generally not. Article 27 applies to public bodies, private entities providing public services, and some credit and insurance uses. Private employers still need a GDPR impact assessment and must inform candidates and workers.
Who checks compliance for recruiting AI?
For employment systems, the provider assesses conformity itself under Annex VI, without a notified body. National market surveillance authorities enforce the rules. In France the designation of these authorities is still being finalised, and the CNIL already supervises the GDPR side of recruitment.
Sources and further reading
- Regulation (EU) 2024/1689 (Artificial Intelligence Act)
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- European Commission: draft guidelines on the classification of high-risk AI systems (19 May 2026)
- European Commission: guidelines on prohibited artificial intelligence practices
- Regulation (EU) 2016/679 (GDPR)
- CNIL: Le guide du recrutement
- CJEU, C-203/22 Dun & Bradstreet Austria (press release)
- CEN-CENELEC: EN 18286 AI quality management standard
Louis Desclous
Published on · Reading time: 12 minutes

