All insights
Compliance

EU AI Act recruitment compliance checklist for 2026

A deployer checklist for the EU AI Act and high-risk hiring tools before 2 August 2026, with the Digital Omnibus delay to 2 December 2027 explained.

RE
Recruitifly Editorial
Editorial
2026-06-13·8 min read
On this page

Before 2 August 2026, any recruiter or agency that uses an automated tool to screen, rank, or shortlist candidates should treat that tool as a high-risk AI system and work through a deployer checklist, because the EU AI Act puts independent obligations on the organisation using the tool, not only on the company that built it. The catch in 2026 is timing: a proposed delay called the Digital Omnibus may push the high-risk deadline to December 2027, but it is not law yet.

This article is practitioner guidance, not legal advice. National implementations differ; confirm specifics for your market with counsel.

Is my recruitment tool actually “high-risk” under the EU AI Act?

Most candidate-screening tools are high-risk. Annex III point 4 of Regulation (EU) 2024/1689 classifies AI systems “intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates” as high-risk. That language captures the everyday hiring stack: CV parsers that score and rank applicants, matching engines that shortlist, and tools that decide which candidates see which adverts.

The phrase “intended to be used” matters. Classification follows the purpose the system is built or marketed for, even where a human makes the final call and the tool is only one input. A pure keyword search or a manual spreadsheet is not in scope. An engine that infers a fit score, ranks a pipeline, or filters people out is. For the detailed boundary, see our guide to when hiring AI counts as high-risk.

There is a narrow carve-out in Article 6(3) for systems that perform a purely preparatory or narrow procedural task and do not materially influence the outcome. Do not lean on it for a tool that ranks or filters candidates. If the output shapes who advances, assume high-risk.

Am I a “deployer,” and why does that change my obligations?

You are a deployer if you use a high-risk AI system under your own authority in a professional capacity, which describes almost every employer and recruitment agency that runs screening software it did not build. The EU AI Act splits duties between the provider (the company that develops and places the system on the market) and the deployer (you). Article 26 sets out the deployer obligations, and they cannot be contracted away in a vendor agreement.

This split trips people up because vendor marketing absorbs the compliance conversation. The provider handles conformity assessment, technical documentation, CE marking, and EU-database registration. The deployer is on the hook for how the tool is used day to day: oversight, instructions, logs, monitoring, and transparency to the people affected. An agency placing candidates and the client employer can both be deployers of the same chain of tools, so map who controls what.

What is the deployer checklist before 2 August 2026?

Work through these ten obligations. They map to Article 26 unless noted, and they are the operational core of EU AI Act readiness for recruitment.

  1. Confirm scope. Document whether each hiring tool meets Annex III point 4. Keep the reasoning in writing so you can show why a tool is, or is not, treated as high-risk.
  2. Use the system per the provider’s instructions (Art 26(1)). Deploying a CV screener outside the job categories or use cases the provider validated is a breach. The instructions define the boundary of lawful use.
  3. Assign competent human oversight (Art 26(2)). Name people with the training, authority, and time to review, question, and override automated outputs. Oversight has to be real, not a rubber stamp.
  4. Control input data where you supply it (Art 26(4)). Ensure the data you feed in is relevant and sufficiently representative for the intended purpose.
  5. Monitor operation and report (Art 26(5)). Watch for malfunction or risk in live use. Inform the provider and the relevant market surveillance authority of serious incidents without undue delay, and suspend use where needed.
  6. Retain logs for at least six months (Art 26(6)). Keep the automatically generated logs the system produces, unless a longer period applies under other law.
  7. Inform workers and their representatives (Art 26(7)). Before putting a high-risk system into use in the workplace, tell affected workers and any workers’ representatives. National worker-consultation rules may add steps.
  8. Inform affected candidates (Art 26(11)). Tell people they are subject to a high-risk AI system in a hiring decision. A short, plain-language disclosure works; see our candidate disclosure notice template.
  9. Handle requests for explanation (Art 86). A candidate adversely affected by a decision based on the system’s output can ask for a clear, meaningful explanation of the system’s role and the main elements of the decision.
  10. Run a fundamental rights impact assessment only if in scope (Art 27). Most private employers are not, but check (see below) and keep your reasoning on file.

Do I need a fundamental rights impact assessment, and how does GDPR overlap?

Probably not a FRIA, but almost certainly a GDPR data protection impact assessment. Article 27 of the AI Act limits the fundamental rights impact assessment mainly to public bodies, private entities providing public services, and the credit-scoring and life-and-health insurance categories in Annex III points 5(b) and 5©. A typical private employer or recruitment agency screening candidates is outside that requirement.

The data-protection side is separate and broader. Screening, scoring, and ranking candidates is high-risk processing under the GDPR, so you owe a data protection impact assessment under Article 35 GDPR. Article 26(9) of the AI Act says you should use the provider’s information to help meet that obligation, but it stays a GDPR duty. The two regimes also collide on automated decisions:

Topic EU AI Act GDPR
Core obligation Deployer duties for high-risk hiring tools (Art 26) Lawful, fair processing of candidate data
Impact assessment FRIA only for limited deployers (Art 27) DPIA for high-risk processing (Art 35)
Automated decisions Right to explanation, even with a human in the loop (Art 86) Right not to be subject to solely automated decisions (Art 22)
Transparency to candidate Inform them a high-risk system is used (Art 26(11)) Inform them of automated decision logic

A practical trap: GDPR Article 22 covers decisions made solely by automated means, while AI Act Article 86 reaches decisions a deployer takes on the basis of the system’s output, which includes the common “machine recommends, human signs off” pattern. For the data-protection foundations, start with our GDPR for recruiters guide.

What vendor due diligence and AI literacy do I owe?

You must check that the provider has done its job, and you must train your staff. Even though provider duties are not yours, deploying a non-compliant system exposes you. Before you sign or renew, ask the vendor to evidence the following.

  1. The system has undergone the conformity assessment under Article 43 and carries a CE marking under Article 48.
  2. There is an EU declaration of conformity and the system is registered in the EU database under Article 49.
  3. You receive clear instructions for use that define the validated job categories and the limits of the tool.
  4. The provider supplies the information you need to run your own DPIA and human oversight.

Separately, AI literacy is already live. Under Article 4, providers and deployers must ensure a sufficient level of AI literacy among staff and others operating systems on their behalf, and that obligation has applied since 2 February 2025. For recruitment teams, that means the people running and overseeing the screening tools understand what the system does, where it can go wrong, and when to override it. Keep a record of the training, and treat it as a standing requirement.

Does the Digital Omnibus delay change the deadline?

It might, but it is not law yet, so plan against 2 August 2026. The Digital Omnibus on AI, published by the European Commission on 19 November 2025, proposes moving the application of standalone high-risk obligations (which include Annex III recruitment systems) from 2 August 2026 to 2 December 2027, and high-risk systems embedded in regulated products from 2 August 2027 to 2 August 2028. Negotiators reached a provisional political agreement on 6 May 2026, confirmed by member-state representatives on 13 May 2026.

The decisive caveat: a provisional agreement has no binding force until it is formally adopted and published in the Official Journal. If publication slips past 2 August 2026, the original deadline applies as drafted. Treat the delay as likely but not banked, and keep your checklist on the 2026 timeline. Several obligations, including AI literacy and the GDPR duties above, apply regardless of the Omnibus, so the readiness work is not wasted whatever the final date.

How Recruitifly helps

Recruitifly is built EU-first, which keeps candidate data inside the boundary you can audit and gives you the controls Article 26 expects. Posting compliance checks flag job-ad issues before they go out, the Fly assistant operates behind a propose-then-confirm gate so a human approves actions rather than the tool acting alone, and candidate-data controls support retention limits, disclosure, and the transparency duties you owe applicants. For agencies, the Agency Hub keeps each client’s pipeline scoped and isolated, which makes mapping deployer responsibilities across the chain far cleaner. Explore the feature set to see how oversight and logging fit your workflow.

Recruitifly is in private beta. If you want help mapping your hiring tools to these deployer obligations before the deadline, talk to us and join the beta.

Frequently asked questions

When do EU AI Act obligations for high-risk hiring tools apply?

The original date was 2 August 2026. The Digital Omnibus on AI, provisionally agreed on 6 May 2026, proposes moving standalone high-risk obligations to 2 December 2027. Until that change is published in the Official Journal, 2 August 2026 remains the active legal date, so plan against it.

Is a recruitment AI tool high-risk under the EU AI Act?

Usually yes. Annex III point 4 classifies AI systems intended to be used for recruitment or selection, including placing targeted job ads, filtering applications, and evaluating candidates, as high-risk. CV-screening and candidate-ranking tools fall squarely inside that category for both employers and agencies.

What does a deployer of high-risk hiring AI have to do?

Under Article 26, deployers must use the system per the provider's instructions, assign competent human oversight, keep automatically generated logs for at least six months, monitor operation, report serious incidents, and inform workers, their representatives, and affected candidates that the system is in use.

Do private recruiters need a fundamental rights impact assessment?

Generally no. Article 27 requires a fundamental rights impact assessment mainly from public bodies and private entities providing public services, plus specific Annex III categories. Most private employers and agencies are out of scope, but you still owe a GDPR data protection impact assessment for high-risk candidate processing.

RE

Recruitifly Editorial

Editorial

Related reading

Want to see how this looks on your own data?

No hard promises. Just a straight conversation about exports, stages, and your current stack.

Contact us