All insights
Compliance

Is your hiring software high-risk under the EU AI Act?

Under Regulation (EU) 2024/1689, recruitment and candidate-evaluation tools are high-risk. What it triggers, the 2 August 2026 deadline, and the Omnibus delay.

RE
Recruitifly Editorial
Editorial
2026-06-13·9 min read
On this page

AI systems used to recruit, filter applications, or evaluate candidates are classified as high-risk under the EU AI Act (Regulation (EU) 2024/1689), specifically Annex III, point 4, because they decide who gets access to work. That classification triggers a stack of obligations covering data governance, human oversight, logging, and transparency, and it pulls in the recruiters and agencies who use these tools, not just the vendors who build them.

This article is practitioner guidance, not legal advice. National implementations differ; confirm specifics for your market with counsel.

Why is recruitment software classified as high-risk?

Recruitment software is high-risk because Annex III of the AI Act lists it explicitly. Point 4(a) covers AI systems “intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates.” Point 4(b) extends this to systems that make or support decisions on the terms of work, promotion, termination, task allocation, and performance monitoring.

The logic is in Recital 57 of the regulation: these systems “may have an appreciable impact on future career prospects, livelihoods and workers’ rights,” and they can perpetuate historical discrimination, for example against women, certain age groups, people with disabilities, or particular racial or ethnic origins. The legislator treats access to employment as a fundamental-rights issue, which is why hiring tools sit in the same Annex III tier as systems used for credit scoring, law enforcement, and access to essential public services.

If you screen, rank, score, or match candidates with software that learns or infers, assume Annex III applies until you can show otherwise.

What exactly does “high-risk” trigger?

High-risk classification triggers a defined set of obligations split between the vendor (the provider) and the user (the deployer). Providers carry the heavier build-side burden under Articles 8 to 17; deployers carry operational duties under Article 26.

Provider obligations include:

  1. A documented risk-management system across the lifecycle (Article 9).
  2. Data and data-governance practices, including examining training, validation, and test datasets for bias (Article 10).
  3. Technical documentation and instructions for use (Articles 11 and 13).
  4. Automatic event logging so decisions are traceable (Article 12).
  5. Human oversight designed into the system (Article 14).
  6. Appropriate accuracy, robustness, and cybersecurity (Article 15).
  7. A conformity assessment, a CE marking, an EU declaration of conformity, and registration in the EU database under Article 49 before the system goes on the market.

Deployer obligations under Article 26 are lighter but real: use the system per the provider’s instructions, assign human oversight to competent and authorised people, ensure input data you control is relevant, monitor operation, keep logs you generate, and cooperate with authorities. For recruiters, the practical headline is that you cannot let the tool make the hiring decision on its own; meaningful human review is mandatory, not optional.

Provider or deployer: which one is a recruiter?

A recruiter or agency that buys an off-the-shelf hiring tool and uses it under its own name is a deployer, not a provider. The provider is the company that develops the system and places it on the EU market. This split matters because it determines which articles bind you.

There is a trap, though. Under Article 25, a deployer can be reclassified as a provider, picking up the full provider obligations, if it puts its own name or trademark on a high-risk system, makes a substantial modification to it, or modifies the intended purpose of a system so that it becomes high-risk. An agency that white-labels a sourcing tool, or heavily customises a screening model, should check whether it has crossed that line.

Question Provider Deployer (most recruiters and agencies)
Who is it? Builds the system and places it on the market Uses the system under its own authority
Core article Articles 8 to 17, plus Article 49 registration Article 26
Conformity assessment and CE marking Yes No
Assign human oversight Designs the capability Assigns competent people to use it
Inform affected workers No specific duty Yes, under Article 26(7)
Risk of reclassification n/a Yes, under Article 25 if rebranded or substantially modified

For a deeper walk-through of the provider/deployer split and what to ask a vendor, see the EU AI Act and recruitment software.

Can a hiring tool avoid high-risk status?

Sometimes, but the exemption is narrow and easy to overstate. Article 6(3) says an Annex III system is not high-risk if it “does not pose a significant risk of harm” and meets one of four conditions: it performs a narrow procedural task, improves the result of a completed human activity, detects deviations from prior decision patterns without replacing human review, or performs a preparatory task to an assessment.

The Commission’s guidance gives a clean recruitment example: a tool that drafts a job description from a list of tasks and qualifications a human recruiter already defined can fall under the “narrow procedural task” carve-out. Converting a CV from unstructured text into structured fields, or detecting duplicate applications, can also qualify.

What does not qualify is anything that ranks, scores, or labels candidates as more or less suitable, because that is a value judgement that materially influences the decision. And there is a hard stop: Article 6(3) explicitly states the exemption never applies where the system performs profiling of natural persons. Most candidate-scoring and matching features involve exactly that, so the safe default for any tool that evaluates people is to treat it as high-risk. If you rely on the exemption, document your reasoning, because the provider must register that assessment under Article 6(4).

What is the EU AI Act timeline for hiring tools?

The phased timeline runs from 2024 to 2026, with the high-risk hiring obligations landing last. Here is the sequence under the regulation as published.

Date What applies
1 August 2024 Regulation (EU) 2024/1689 enters into force
2 February 2025 Prohibited AI practices (Article 5) and AI literacy duties (Article 4) apply
2 August 2025 General-purpose AI rules, governance bodies, notifying authorities, and most penalty provisions apply
2 August 2026 Annex III high-risk obligations apply, including for recruitment and employment systems
2 August 2027 High-risk AI embedded in regulated products (Annex I) becomes subject to the rules

Two earlier obligations already bite on hiring teams. Since February 2025, Article 4 has required providers and deployers to ensure a sufficient level of AI literacy among staff who operate these tools, so your recruiters should already understand what the system does and where it fails. And the Article 5 prohibitions are in force now, which is why emotion-recognition systems in the workplace are off the table except in narrow safety or medical cases.

For a structured readiness list against these dates, use the EU AI Act recruitment compliance checklist for 2026.

Is the 2 August 2026 deadline actually changing?

Possibly, but it is not safe to assume so yet. In May 2026, EU institutions reached a provisional political agreement on the “Digital Omnibus” package, a set of targeted amendments to the AI Act. The provisional deal, agreed on 6 May 2026 and confirmed by Member State representatives on 13 May 2026, would defer the application of standalone Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and push Annex I embedded-product obligations to 2 August 2028.

Treat this as pending, not done. The amended dates only take legal effect once the Omnibus is formally adopted and published in the Official Journal, which is expected before 2 August 2026 but has not happened at the time of writing. Until publication, 2 August 2026 remains the binding deadline. Plan to the original date and adjust if and when the delay is law, because building a compliance file is slow and you do not want to start from zero if adoption slips.

Note that the Article 4 literacy duty and the Article 5 prohibitions are already in force regardless of the Omnibus, and Article 50 transparency obligations for AI-generated content are scheduled for 2 August 2026 independently of the high-risk timeline.

What happens if you get it wrong?

The penalty structure under Article 99 is tiered and large. Using a prohibited practice can cost up to EUR 35,000,000 or 7% of total worldwide annual turnover for the preceding year, whichever is higher. Breaching most other obligations, including the deployer duties in Article 26 and the high-risk requirements generally, can cost up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher. Supplying incorrect or misleading information to authorities carries a cap of EUR 7,500,000 or 1%. For SMEs and start-ups, the fine is the lower of the cap or the percentage, not the higher.

Beyond fines, GDPR runs in parallel. A candidate evaluated by a high-risk hiring tool also has rights under Article 22 of the GDPR on automated individual decision-making, and you still need a lawful basis to process their data. The two regimes overlap, so a defensible hiring stack has to satisfy both. See our GDPR for recruiters candidate-data guide for that side of the picture, and the AI Act candidate disclosure notice template for the transparency wording you owe applicants.

How Recruitifly helps

Recruitifly is built EU-first, and the platform is designed to make your deployer obligations easier to discharge rather than harder. The features that matter here are practical: posting compliance checks that flag risk in a vacancy before it goes live, candidate-data controls and retention settings that support your GDPR lawful-basis and oversight obligations, and an audit trail of changes so human review is visible and traceable. The Fly assistant is built around a propose-then-confirm model, so a person stays in the loop on actions rather than the tool deciding alone, which is exactly the posture Article 26 expects from a deployer. You can see the current capabilities on the features page.

To be precise about scope: deciding whether a given system is high-risk, who the provider is, and what your conformity file must contain are legal determinations for you and your counsel. Recruitifly gives you the controls and the record-keeping to operationalise those decisions.

Recruitifly is in private beta. If you want to see how posting compliance checks, candidate-data controls, and the Fly assistant fit your hiring workflow under the AI Act, talk to us and join the beta.

Frequently asked questions

Is recruitment software high-risk under the EU AI Act?

Yes. Under Regulation (EU) 2024/1689, Annex III point 4, AI systems used to recruit or select people, place targeted job ads, analyse and filter applications, or evaluate candidates are classified high-risk. Systems that decide on promotion, termination, or task allocation are also high-risk. A narrow Article 6(3) exemption exists but never applies to profiling.

When do EU AI Act high-risk obligations for hiring tools start?

The original date for Annex III high-risk obligations is 2 August 2026. However, a provisional Digital Omnibus agreement reached in May 2026 would defer standalone Annex III obligations to 2 December 2027. That change is not yet adopted or published in the Official Journal, so 2 August 2026 remains the live deadline until then.

Are recruiters providers or deployers under the EU AI Act?

Recruiters and agencies that buy and use a third-party hiring tool are almost always deployers, not providers. Deployer duties under Article 26 include following the provider's instructions, assigning competent human oversight, ensuring input data is relevant, monitoring use, and (as an employer) informing affected workers and their representatives before deployment under Article 26(7).

What are the fines for breaching the EU AI Act in recruitment?

Under Article 99, breaching the prohibited-practice rules can cost up to EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher. Most high-risk breaches, including deployer obligations, carry fines up to EUR 15,000,000 or 3% of turnover, whichever is higher. For SMEs, the lower of the cap or percentage applies.

RE

Recruitifly Editorial

Editorial

Related reading

Want to see how this looks on your own data?

No hard promises. Just a straight conversation about exports, stages, and your current stack.

Contact us