- Why are hiring tools classified as high-risk?
- Provider or deployer — which role are you?
- What do AI Act breaches cost?
- How do recruiters get compliant? A six-part roadmap
- Summary — key takeaways
- FAQ
From 2 August 2026, AI systems used to recruit, select and evaluate people are regulated as high-risk under the EU AI Act. Any algorithmic candidate ranking, CV filtering or interview scoring must be transparent, supervised by trained humans and tested for bias — with fines up to €35 million or 7% of global turnover at the top of the scale, and non-EU recruiters hiring into the EU fully in scope.
Any agency ranking candidates with an algorithm, any HR team filtering CVs with machine learning, and any platform scoring video interviews will need to show the technology is transparent, supervised and tested for bias. This article explains what counts as high-risk, who carries which obligations, what the fines look like, and how recruitment businesses get compliant without abandoning AI’s productivity gains.
Why are hiring tools classified as high-risk?
Annex III of the AI Act designates AI intended for recruitment or selection — placing targeted job adverts, analysing and filtering applications, evaluating candidates — and AI used for decisions on promotion, termination, task allocation and worker monitoring as high-risk. These systems shape livelihoods, and errors or embedded bias replicate at scale.
Two earlier milestones already apply: since February 2025, prohibited practices — including emotion recognition in the workplace — are banned outright, and organisations owe a duty of AI literacy to staff operating AI tools. The August 2026 date adds the full high-risk regime for systems placed on the market or put into service. Elements of the timetable have been discussed for postponement under the Commission’s digital omnibus proposals — planning should assume the deadline holds.
Provider or deployer — which role are you?
| Role | Typical example | Core obligations |
| Provider | HR-tech vendor building CV screening tools or interview scoring engines | Risk management system, data governance and bias testing, technical documentation, accuracy and robustness, conformity assessment, CE marking |
| Deployer | Agency or employer using the vendor’s system on candidates | Use per instructions, trained human oversight, relevant input data, keep logs, monitor operation, inform workers and representatives, cooperate with authorities |
Most agencies and employers are deployers — but substantially modifying a vendor tool, or white-labelling it under your own brand, can promote you to provider status with far heavier duties. Deployers in the employment context must inform affected workers and representatives before use, candidates must not be misled about interacting with AI, and GDPR Article 22 rights on automated decisions operate alongside the Act — handle the two regimes together.
What do AI Act breaches cost?
AI Act fines are calibrated to turnover and rank among the largest in EU law: up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for breaching high-risk obligations; up to €7.5 million or 1% for supplying misleading information to authorities. Enforcement machinery scales up from 2027, but obligations bind from the applicable dates — and reputational damage from a biased hiring tool rarely waits for a regulator. The Act is also extraterritorial: a UK or US agency screening applicants for roles in Germany cannot sit this one out.
How do recruiters get compliant? A six-part roadmap
- Inventory: catalogue every tool in the hiring stack — sourcing, advert targeting, CV parsing, ranking, chatbots, assessments, interview analytics — and flag the high-risk ones.
- Vendor due diligence: obtain conformity documentation, instructions for use and bias-testing evidence; oblige vendors contractually to maintain them.
- Human oversight: designate trained reviewers with genuine authority to override the system — a rubber stamp is not oversight.
- Bias testing and monitoring: run adverse-impact analysis on your own candidate data, not just the vendor’s test set, on an agreed cadence, and log outcomes.
- Candidate and worker communication: update privacy notices, inform works councils, prepare explanations for significant automated decisions.
- Governance: assign ownership, train recruiters under the AI-literacy duty, and document everything — the Act rewards evidence.
Summary — key takeaways
- From 2 August 2026, recruitment and worker-management AI must meet the high-risk regime.
- Prohibited practices (incl. workplace emotion recognition) and AI-literacy duties have applied since February 2025.
- Deployers owe oversight, input-data quality, logging and worker information; providers carry design, documentation and bias-testing duties.
- Fines reach €35m/7% of global turnover, and non-EU companies hiring into the EU are in scope.
- Start with the tool inventory and vendor due diligence now — the clock is running.
FAQ
Is AI recruitment high-risk under the AI Act?
Is AI recruitment high-risk under the AI Act? Yes. Annex III expressly lists AI systems intended for recruitment or selection — targeted job advertising, application filtering, candidate evaluation — and for workplace decisions on promotion, termination, task allocation and monitoring. Such systems must meet the high-risk requirements, including risk management, bias testing, logging and effective human oversight, from 2 August 2026.
Does the AI Act apply to non-EU companies?
Does the AI Act apply to non-EU companies? Yes, where their AI systems are placed on the EU market, used in the EU, or their outputs affect people located in the EU. A recruiter based in London or New York screening candidates for EU-based roles falls within scope, so global staffing groups should apply one EU-grade compliance standard across their hiring stack.
What are the AI Act penalties?
The AI Act penalties are tiered: up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for breaching high-risk system obligations; and up to €7.5 million or 1% for supplying incorrect information to authorities. National enforcement scales up from 2027, but obligations — and civil and reputational exposure — apply from the earlier compliance dates.
Related reading: EU Platform Work Directive · Global staffing industry trends 2026 · Services for recruitment agencies