LinkedInInstagramXTikTok

AI in recruitment: what the EU AI Act means for hiring in 2026

Artificial intelligence has quietly become part of everyday recruitment. Job adverts are targeted algorithmically, applications are ranked automatically, and video interviews are scored by software before a human ever reads a CV. For employers this promises speed and consistency. Under the EU AI Act, it also places recruitment squarely in the regulation’s highest-risk category outside of critical infrastructure.

Why recruitment is treated as high-risk

The EU AI Act classifies AI systems according to the risk they pose to health, safety and fundamental rights. Annex III of the Regulation lists the use cases that count as high-risk, and employment is one of them. Specifically, the Annex covers AI systems intended to be used for the recruitment or selection of natural persons – in particular to place targeted job advertisements, to analyse and filter applications, and to evaluate candidates.

The logic is straightforward. A hiring decision determines whether a person gets access to work, income and career progression. If an algorithm systematically disadvantages applicants with a particular background, gender or age, the harm is both individual and structural – and it is invisible, because the applicant never learns why they were filtered out.

The classification does not stop at hiring. Annex III also captures AI used for decisions affecting the terms of an employment relationship, promotion and termination, task allocation based on behaviour or personal traits, and the monitoring and evaluation of performance.

Are you a provider or a deployer?

The AI Act allocates obligations by role, and this is where many companies misread their exposure.

Providers

A provider develops an AI system and places it on the market under its own name or trade mark. Providers carry the heaviest burden: a risk management system, data governance and bias testing, technical documentation, logging, conformity assessment, CE marking and registration in the EU database.

Deployers

A deployer uses an AI system under its own authority. Most employers are deployers – they buy a recruitment platform rather than build one. Deployer duties are lighter but real: use the system in accordance with the provider’s instructions, assign competent human oversight, ensure input data is relevant, monitor operation and report serious incidents, keep logs, and inform affected workers and candidates that a high-risk AI system is being used.

One trap deserves emphasis. A deployer that puts its own name on a high-risk system, substantially modifies it, or repurposes a general system for a high-risk use can be reclassified as a provider – inheriting the full compliance load. Building an in-house CV-screening layer on top of a general-purpose model is exactly the kind of step that triggers this.

The timeline: what actually applies, and when

This is the point on which the most confusion currently exists, and it deserves precision.

The AI Act originally set 2 August 2026 as the date on which the full high-risk regime for Annex III systems became applicable. In November 2025 the European Commission proposed a simplification package – the Digital Omnibus on AI – deferring that date. Following a political agreement in May 2026 and the European Parliament’s endorsement in June 2026, the Council gave its final green light on 29 June 2026. Under the agreed text, high-risk obligations for stand-alone Annex III systems move to 2 December 2027, and AI embedded in regulated products under Annex I moves to 2 August 2028.

Two caveats matter for planning. First, the new dates take legal effect only once the act is published in the Official Journal and enters into force. Second, the deferral does not touch everything. The prohibitions in Article 5 have applied since 2 February 2025 – including the ban on emotion-recognition systems in the workplace, which directly affects AI interview tools that infer a candidate’s emotional state. The AI literacy duty in Article 4 has also applied since that date, and general-purpose AI obligations have applied since 2 August 2025.

In practice, an extra sixteen months is time to do the work properly, not a reason to stop. And nothing in the AI Act suspends the obligations that already bite: the GDPR, the Swedish Discrimination Act and co-determination duties apply to algorithmic hiring today.

GDPR runs in parallel

Automated screening is processing of personal data, and often processing on a large scale with significant effects. Three GDPR provisions deserve particular attention.

Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects. A model that auto-rejects candidates without meaningful human review falls within it. Meaningful review means a person with the authority and information to reach a different conclusion – not a click-through approval of the ranking.

Articles 13 and 14 require transparency. Candidates must be told that automated tools are used and given meaningful information about the logic involved. Article 35 requires a data protection impact assessment for systematic evaluation of personal aspects, which algorithmic recruitment plainly is.

Practical example: the ranking model that learned the wrong lesson

A Swedish technology company deploys a screening tool trained on ten years of its own hiring outcomes. Historically the company hired mostly from three universities and mostly candidates who had never taken a career break. The model has no protected characteristic in its input data – but it learns to score continuous employment history and specific alma maters highly.

The result is indirect discrimination against applicants who took parental leave and against candidates educated abroad, produced by a system that was never told anyone’s gender or nationality. Under the Discrimination Act the employer is liable regardless of intent. Under the AI Act, the deployer should have monitored operation and flagged the pattern; the provider should have tested for bias in the training data. Bias testing on outcomes, not just inputs, is what catches this.

Common mistakes companies make

Assuming the vendor has handled compliance. A provider’s conformity assessment does not discharge deployer duties, and vendor claims of “AI Act ready” should be tested against the instructions for use and the technical documentation.

Failing to inventory AI in HR. Many organisations do not know how many tools in their recruitment stack contain AI features, because those features arrived through product updates rather than procurement decisions.

Treating human oversight as a formality. If the reviewer sees only a score and has no time or mandate to overturn it, the oversight is nominal and the Article 22 protection fails.

Overlooking co-determination. In Sweden, introducing systems that materially change how work is organised or how employees are evaluated typically triggers negotiation obligations under the Employment (Co-Determination in the Workplace) Act before deployment, not after.

Ignoring emotion recognition. Tools that analyse tone of voice, facial expression or micro-expressions to infer a candidate’s state fall under a prohibition that is already in force.

Recommended actions

Start with an inventory: every tool used in sourcing, screening, interviewing, performance management and workforce planning, mapped against whether it contains AI functionality and which Annex III use case it touches.

Classify your role for each system – provider, deployer, or both – and record the reasoning. Review supplier contracts for the information you will need: instructions for use, documentation, logging access, bias testing results, incident notification, and audit rights.

Design human oversight that can actually change an outcome, and document how. Run a DPIA and, where relevant, a fundamental rights impact assessment. Update candidate privacy notices to describe the automated processing in plain language. Deliver AI literacy training to recruiters and hiring managers, which is a standing obligation, not a project. Finally, test outcomes for disparate impact at intervals, and keep the records – they are your evidence if a decision is challenged.

Frequently asked questions

Does the AI Act apply to companies outside the EU?

Yes, where the output of the system is used in the EU. A recruitment platform operated from outside the Union that screens candidates for EU roles falls within scope.

Can we still use AI to write job adverts?

Drafting copy with a general-purpose assistant is not itself a high-risk use. Targeting or distributing adverts to selected groups of candidates is expressly listed in Annex III and is treated as high-risk.

What are the penalties?

Breach of the Article 5 prohibitions carries fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Non-compliance with high-risk obligations carries up to €15 million or 3%. Supplying incorrect or misleading information to authorities carries up to €7.5 million or 1%.

Does the deferral to December 2027 mean we can pause?

No. The prohibitions, the AI literacy duty, the GDPR and discrimination law all apply now. The deferral affects the high-risk conformity regime only, and the preparatory work – inventory, contracts, oversight design, bias testing – takes longer than most organisations expect.

Conclusion

AI in recruitment is not going away, and the regulatory answer is not to abandon it. It is to know which systems you use, what role you play in relation to each, and whether a human being can genuinely intervene in the decisions they produce. Companies that build that picture now will find the December 2027 deadline a formality rather than a scramble – and will be better protected against the discrimination and data protection claims that can arise long before then.

At Lawgent we help employers map their AI systems, classify their obligations under the AI Act, review supplier contracts and build human oversight that stands up to scrutiny. If you would like to understand where your recruitment process sits, get in touch for an initial conversation.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop