May 15, 202610 min
EU AI Act and Recruiting: What HR Teams Need to Know in 2026
Much of the coverage of the EU AI Act focuses on general-purpose AI models and foundation model providers. Less attention has gone to the category that directly affects HR professionals: high-risk AI systems in employment. This article translates the regulatory text into practical implications for recruiting teams.
- EU AI Act
- GDPR
- Compliance
- AI Recruiting
- Germany
What the EU AI Act says about employment AI
The EU AI Act (Regulation (EU) 2024/1689) establishes a risk-based framework for AI systems used in the EU. High-risk AI systems face the most stringent requirements — including conformity assessments, technical documentation, human oversight obligations, and transparency requirements.
- Annex III, Point 4 explicitly lists as high-risk: AI systems used for 'recruitment or selection of natural persons, notably for advertising vacancies, screening or filtering applications, and evaluating candidates in the course of interviews or tests'
- AI systems for 'promotion and termination of work-related contractual relationships' are also high-risk
- High-risk AI obligations apply to both providers (companies that develop the AI) and deployers (companies that use it — i.e., your HR team)
- The Act applies to all AI systems placed on the market or put into service in the EU, regardless of where the provider is based
- Free and open-source AI systems are largely exempt, with some exceptions for prohibited use cases
What 'high-risk' means in practice for HR teams
Being classified as a deployer of a high-risk AI system creates a set of obligations that sit alongside — and in some areas overlap with — existing GDPR requirements. The obligations are not identical to GDPR and cannot be satisfied solely by GDPR compliance documentation.
- Human oversight: you must ensure meaningful human oversight of the AI system's outputs — not just technical availability of override buttons, but actual operational practice
- Technical documentation: you must maintain documentation of the AI system as deployed, including its intended purpose, performance data, and known limitations
- Instructions of use: the AI provider must provide documentation you can rely on; if they do not, you must produce your own
- Fundamental rights impact assessment (FRIA): deployers of high-risk AI in certain sectors (including employment) must conduct a FRIA under specific conditions
- Candidate transparency: you must inform candidates when an AI system has been used in decisions significantly affecting them
- Record-keeping: logs of AI system operation must be maintained for a period sufficient to allow post-hoc review
Timeline: what is active in 2026
The EU AI Act has a phased implementation timeline. For HR teams, the most important dates are:
- February 2025: Prohibited AI practices provisions entered into force (these include real-time biometric surveillance and social scoring — not directly relevant to standard ATS use)
- August 2025: Codes of practice for general-purpose AI models applicable
- August 2026: High-risk AI system requirements begin applying to new systems — this is the critical date for ATS and recruiting AI tools being deployed for the first time
- August 2027: High-risk AI requirements apply to existing systems already in service (the transition period for tools currently deployed)
- In practice, preparation should start now — conformity documentation, vendor questionnaires, and internal impact assessments take longer than the deadlines suggest
Obligations for deployers: the HR team's checklist
The EU AI Act creates direct obligations for organisations that deploy high-risk AI systems — which in recruiting means the company running the ATS, not only the ATS vendor. Here is what deployers must do.
- Identify which AI tools you use that fall under Annex III, Point 4 (recruitment and employment AI)
- Verify that your AI provider has completed or is completing a conformity assessment and can provide an EU Declaration of Conformity
- Implement the provider's instructions for use — including human oversight procedures, as specified in the documentation
- Ensure you can demonstrate that human oversight is genuinely operational, not just technically possible
- Update candidate privacy notices to disclose AI use, its purpose, and candidates' right to explanation
- Maintain a log of AI system use and outputs sufficient for post-hoc review
- Conduct a Fundamental Rights Impact Assessment if your use case triggers the conditions under Art. 27
- Designate internal accountability: someone in your organisation should own AI Act compliance for HR tools
Obligations for providers: what to ask your ATS vendor
Your ATS or recruiting AI vendor is subject to provider obligations under the EU AI Act. If they cannot answer these questions with documentation, that is a procurement risk for your organisation.
- Is this AI system registered in the EU AI Act high-risk AI database (required for systems in Annex III use cases)?
- Has a conformity assessment been completed, and is an EU Declaration of Conformity available?
- What technical documentation exists covering the system's intended purpose, training data, performance metrics, and known limitations?
- What bias testing has been conducted? What demographic groups were evaluated? When were the last tests run?
- What instructions for use do you provide to deployers — specifically regarding human oversight and operating limitations?
- What data practices apply to training and model improvement — particularly regarding candidate data?
The overlap with GDPR: what is covered and what is not
Many HR teams assume that GDPR compliance covers the EU AI Act obligations. The overlap is real but incomplete. Understanding where they diverge matters for compliance planning.
- Both frameworks require: candidate transparency about AI use, human oversight of automated decisions (GDPR Art. 22 / AI Act Art. 14), and documentation of data processing
- GDPR does not require: conformity assessments of AI systems, registration in the EU AI Act database, or the specific technical documentation the AI Act mandates
- The AI Act does not replace GDPR: both apply simultaneously. AI Act conformity does not exempt you from GDPR compliance
- For many HR teams, the most practical additional step is updating the candidate privacy notice and requesting EU AI Act documentation from ATS vendors
- Works Councils may also require specific documentation and agreement (Betriebsvereinbarung) about AI tools — this sits alongside both frameworks
What to do this quarter
For HR teams that have not yet started EU AI Act preparation, here is a realistic priority list for the next 90 days.
- Inventory your AI recruiting tools: list every tool that uses AI for screening, scoring, ranking, or evaluation of candidates
- Assess risk classification: do any fall under Annex III Point 4? (If they score or rank candidates, the answer is probably yes)
- Send vendor questionnaires: ask for conformity assessment status, bias testing results, and instructions for use documentation
- Update candidate disclosures: add a short statement to job posting privacy notices about AI use and its purpose
- Document human oversight procedures: write down — not just assume — how your team reviews and can override AI outputs
- Flag to your DPO or legal team: they should be involved in the AI Act compliance workstream alongside your existing GDPR review
How Virkla supports your EU AI Act obligations
Virkla is designed to help you meet the obligations the EU AI Act places on both provider and deployer. Our approach is to make the supporting infrastructure available by default — not configurable as an add-on.
- Human-in-the-loop by design: no candidate can be rejected, advanced, or hired based on AI output alone — every AI output is input to a human decision
- Explainable AI scoring: every candidate score is tied to specific criteria defined by the recruiter, not a black-box output
- Bias monitoring: AI outputs are evaluated for disparate impact across demographic categories as part of ongoing model review
- Candidate disclosure materials: employers using AI Score Matching receive disclosure language for privacy notices and job postings
- Audit logs: every AI interaction and every human decision is logged separately, supporting both GDPR and AI Act record-keeping requirements
- We actively monitor EU AI Act implementation guidance and update documentation as requirements become enforceable
Frequently asked questions
Does the EU AI Act apply to non-EU ATS vendors used by EU companies?
Yes. The EU AI Act applies to AI systems placed on the market or put into service in the EU, regardless of where the provider is established. A US-based ATS vendor whose system is used by EU employers is subject to the Act's provider obligations.
Is a CV ranking algorithm always high-risk under the EU AI Act?
If the system is used to screen, filter, or rank candidates in the course of a recruitment process, the default classification under Annex III Point 4 is high-risk. Some narrow exceptions apply (e.g., purely keyword-search tools with no predictive or scoring element), but purpose-built AI scoring and ranking tools will almost always qualify.
What is a Fundamental Rights Impact Assessment and does our team need one?
Under EU AI Act Art. 27, public authorities and private operators providing public services must conduct a FRIA before deploying high-risk AI. For most private-sector employers, the FRIA is not mandatory — but it is considered best practice and many legal advisors recommend it as a risk management measure, particularly for large-scale or AI-intensive hiring processes.
What should we tell candidates about AI use in our hiring process?
Your candidate privacy notice should state: that AI tools are used in the screening or evaluation process, what the AI does (e.g., ranks applications against role criteria), what the legal basis is for this processing, and that candidates can request information about AI-assisted decisions. Brief, clear disclosure at the point of application is better than a lengthy annex.
