Is Your Hiring AI High-Risk Under the EU AI Act?
Yes. Almost all AI used in hiring is classified as "high-risk" under the EU AI Act. Annex III of the Regulation lists AI systems used for recruitment, candidate selection, and employment decisions as high-risk, which triggers mandatory obligations: risk management, data governance, human oversight, technical documentation, and conformity assessment before the system goes to market. If your organization recruits, screens, or evaluates candidates inside the EU using automated tools, those tools likely fall under the Act's strictest tier short of an outright ban.
The practical consequence is direct. You cannot deploy a resume-screening model, an interview-scoring tool, or a candidate-ranking algorithm in the EU and treat compliance as optional. The obligations attach to both the provider (the company that builds or sells the tool) and the deployer (the employer who uses it), with separate duties for each.
What does the EU AI Act say about hiring AI?
The EU AI Act (Regulation (EU) 2024/1689) is the first horizontal law to regulate artificial intelligence by risk level. It sorts AI systems into four tiers: unacceptable risk (banned), high-risk (heavily regulated), limited risk (transparency duties), and minimal risk (largely unregulated).
Employment and recruitment AI sits in the high-risk tier. Annex III, point 4, names two categories of high-risk employment systems:
AI used for recruitment or selection, in particular to place targeted job ads, filter or screen applications, and evaluate candidates.
AI used to make decisions affecting work-related terms, including promotion, termination, task allocation, and the monitoring or evaluation of performance.
The regulation reaches beyond the initial hire. A tool that decides who gets promoted, who is assigned which shifts, or whose performance is flagged for review is regulated on the same terms as a resume filter.
Which specific hiring tools count as high-risk?
The Act is technology-neutral, so it captures a range of systems rather than a fixed product list. Tools that commonly fall in scope include:
Resume and CV screening algorithms that rank, score, or reject applicants.
Sourcing and matching engines that surface candidates or push job ads to defined audiences.
Video interview analysis that scores tone, word choice, or facial expression.
Assessment and gamified testing platforms that infer aptitude or personality.
Chatbot screeners that ask qualifying questions and route or filter applicants.
Performance and promotion models that rank existing employees for advancement or layoff.
A tool can avoid high-risk status only through the narrow Article 6(3) exemption, discussed below. The default for hiring AI is high-risk.
Who is responsible: the vendor or the employer?
Both. The Act assigns distinct duties to providers and deployers, and an employer who buys an off-the-shelf screening tool still carries obligations of its own.
Role: Provider
Who it is: The organization that develops an AI system or places it on the EU market under its own name.
Core obligations: Establish a risk management system, implement data governance, prepare technical documentation, complete conformity assessments, obtain CE marking, register the system in the EU database (where required), and perform post-market monitoring.
Role: Deployer
Who it is: The employer or organization that uses the AI system as part of its business operations.
Core obligations: Use the AI system according to the provider's instructions, ensure appropriate human oversight, monitor system operation, maintain logs, inform affected workers where required, and conduct a Fundamental Rights Impact Assessment (FRIA) when applicable.
Important note: A deployer can be reclassified as a provider if it markets the AI system under its own name, substantially modifies the system, or repurposes a general-purpose AI system for a high-risk hiring use case. In these situations, the employer assumes the full set of provider obligations under the EU AI Act.
What does a deployer have to do specifically?
If you are the employer deploying a high-risk hiring tool, your duties include:
Operate within the provider's instructions for intended use and known limitations.
Assign competent human oversight to people who can interpret outputs and override them.
Monitor the system and suspend use if it presents a risk at national level.
Keep automatically generated logs for the period the system is in use.
Inform workers and their representatives before putting a high-risk system into use in the workplace.
Tell affected candidates when a decision about them was made or assisted by the system, on request, with a meaningful explanation.
Conduct a fundamental rights impact assessment (FRIA) if you are a public body or provide public services, and cooperate with the provider's data protection requirements.
What are the penalties for non-compliance?
Penalties scale with the severity of the violation. They are calculated as a percentage of worldwide annual turnover or a fixed sum, whichever is higher.
Violation type: Prohibited AI practices (banned uses).
Maximum fine: Up to €35 million or 7% of the organization's global annual turnover, whichever is higher.
Violation type: Breach of high-risk obligations (including most AI hiring compliance violations).
Maximum fine: Up to €15 million or 3% of the organization's global annual turnover, whichever is higher.
Violation type: Supplying incorrect or misleading information to regulatory authorities.
Maximum fine: Up to €7.5 million or 1% of the organization's global annual turnover, whichever is higher.
For most hiring scenarios, the relevant ceiling is the €15 million / 3% of turnover band, because recruitment systems are high-risk rather than prohibited. The figures apply to the higher of the two amounts, so for a large multinational the percentage will usually govern. Small and medium-sized enterprises, including start-ups, are subject to the lower of the percentage or the fixed amount.
When do the EU AI Act hiring rules take effect?
The Act entered into force in August 2024 and applies in phases:
February 2025: Bans on prohibited AI practices and AI literacy obligations began to apply.
August 2025: Rules for general-purpose AI models and the governance structure took effect.
High-risk obligations, including the Annex III employment rules: originally set for August 2026, but deferred. Under the EU's "Digital Omnibus" package, the EU institutions reached a provisional agreement in May 2026 and the European Parliament voted in favor on June 16, 2026, to move the Annex III stand-alone high-risk deadline to December 2, 2027. These deferred dates take legal effect only on formal adoption and publication in the Official Journal, expected before August 2026. High-risk AI embedded in regulated products under Annex I moves to August 2028.
The operative deadline for most stand-alone hiring tools is December 2, 2027, assuming the Omnibus enters into force as expected before the original August 2026 date. Until formal adoption is published, treat August 2026 as the fallback. Either way, providers and deployers of recruitment and employment AI should have conformity work, documentation, and oversight structures in place well ahead of the applicable date.
Does the EU AI Act apply to companies outside the EU?
Yes. The Act has extraterritorial reach. It applies to providers and deployers established outside the EU when the output of the AI system is used in the EU. A US-based company that screens candidates for roles located in the EU, or whose hiring tool produces outputs used to evaluate EU-based applicants, falls within scope.
This parallels the structure of the GDPR. A vendor selling an applicant-tracking add-on to European employers, or a US multinational hiring across its EU subsidiaries, cannot assume the regulation stops at the border. Non-EU providers must also appoint an authorized representative in the EU.
How is the EU AI Act different from US hiring AI laws?
The EU AI Act is a single, comprehensive law that imposes obligations before a system is deployed. The US has no equivalent federal statute. Instead it relies on a mix of existing anti-discrimination law and a growing set of state and city rules. For a fuller state-by-state breakdown, see our guide to AI hiring laws by state.
Key contrasts:
NYC Local Law 144 requires a bias audit of automated employment decision tools and candidate notice, with enforcement that began in July 2023. It is a disclosure-and-audit rule, not a full lifecycle regime.
The EEOC has issued technical guidance applying Title VII and the Americans with Disabilities Act (ADA) to AI hiring tools, using existing disparate-impact and reasonable-accommodation doctrine rather than a new framework.
The Illinois Artificial Intelligence Video Interview Act (effective January 2020) requires consent and disclosure when AI analyzes video interviews.
The Colorado AI Act (SB 24-205) creates consumer-protection duties for developers and deployers of high-risk AI, including employment uses, and takes a risk-based approach closer in spirit to the EU model. Its effective date has been postponed and remains subject to amendment.
The practical difference: the EU Act front-loads compliance through conformity assessment and documentation, while most US rules operate through audit, notice, and after-the-fact liability under discrimination statutes.
What real cases show the risk of biased hiring AI?
The legal exposure is not hypothetical. Documented examples include:
Amazon's internal recruiting tool, reported and scrapped in 2018 after it learned to down-rank resumes associated with women, having been trained on a male-skewed history of past hires.
The iTutorGroup EEOC settlement (2023), where recruiting software was configured to automatically reject older applicants. The company agreed to a settlement of $365,000.
Mobley v. Workday, an age, race, and disability discrimination suit alleging that AI screening tools produced biased rejections. A court allowed the case to proceed, testing whether an AI vendor can be liable as an "agent" in the hiring process.
These cases illustrate the failure modes the EU Act's data-governance and oversight rules are written to prevent: training data that encodes past discrimination, automated rejection without human review, and opaque scoring that affected candidates cannot contest.
How do you assess whether your hiring AI is high-risk?
Work through the system in order. The default for hiring is high-risk, and the exemptions are narrow.
Identify the function. Does the tool recruit, screen, rank, assess, allocate work, evaluate performance, or inform promotion and termination? If yes, it is in the Annex III employment category.
Check the Article 6(3) exemption. A system is not high-risk if it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing human judgment, or does only preparatory work. Profiling of natural persons always remains high-risk, which removes most candidate-evaluation tools from the exemption.
Determine your role. Are you a provider, a deployer, or both? Putting your name on the tool or substantially modifying it pulls you into provider duties.
Confirm geographic reach. Is the output used in the EU? If yes, the Act applies regardless of where you are based.
Map the obligations that attach to your role and document the analysis.
If a tool clears the Article 6(3) exemption, the provider must still document the assessment and register the system in the EU database before placing it on the market. The exemption is not a paperwork-free pass.
Next Steps Checklist
Step: 1
Action: Inventory every AI tool used for recruitment, candidate selection, performance evaluation, or promotion decisions.
Owner: HR and IT.
Step: 2
Action: Classify each AI system against Annex III and assess whether the Article 6(3) exemption applies.
Owner: Legal and compliance.
Step: 3
Action: Determine whether your organization is acting as the provider or deployer for each AI system, including any modified tools.
Owner: Legal.
Step: 4
Action: Request conformity assessment documentation, CE marking, and operating instructions from every AI vendor.
Owner: Procurement.
Step: 5
Action: Establish human oversight, logging, and worker notification processes for high-risk AI systems.
Owner: HR and compliance.
Step: 6
Action: Inform workers and their representatives before deploying high-risk AI systems.
Owner: HR.
Step: 7
Action: Implement processes for providing explanations and handling appeals for automated decisions.
Owner: HR and legal.
Step: 8
Action: Confirm that a non-EU AI provider has appointed an authorized representative within the European Union, where required.
Owner: Legal.
Step: 9
Action: Track internal readiness for the high-risk AI compliance deadline and monitor whether the proposed December 2027 deferral is formally adopted.
Owner: Program lead.
Treat the high-risk deadline as a hard planning anchor and watch the Omnibus adoption status, because the date can still settle at August 2026 if formal publication slips. Vendors that cannot produce conformity documentation, a data-governance record, and clear use instructions should be flagged now, because deployer obligations cannot be satisfied on top of a tool that was never built to be assessed.
Frequently Asked Questions
Is all hiring AI automatically high-risk under the EU AI Act?
Nearly all of it. Annex III classifies AI used for recruitment, selection, and employment decisions as high-risk by default. The only escape is the narrow Article 6(3) exemption for tools doing purely procedural or preparatory work. Because most hiring tools profile or evaluate candidates, and profiling is always high-risk, the exemption rarely applies to real screening, ranking, or assessment systems.
Does the EU AI Act apply to a US company hiring in Europe?
Yes. The Act applies when the output of an AI system is used in the EU, regardless of where the provider or deployer is established. A US company screening candidates for EU-based roles is in scope and, as a non-EU provider, must also appoint an authorized representative inside the EU. The structure parallels the GDPR's extraterritorial reach.
What is the difference between a provider and a deployer?
A provider develops the AI system or places it on the market under its own name and carries the heavier burden: conformity assessment, technical documentation, and registration. A deployer uses the system in its operations and must ensure human oversight, monitor it, keep logs, and inform affected workers. An employer is usually a deployer, but becomes a provider if it rebrands or substantially modifies a tool.
When do the high-risk hiring rules start to apply?
Originally August 2026, now expected to move to December 2, 2027, for stand-alone Annex III systems under the EU's Digital Omnibus, which the European Parliament backed in June 2026 pending formal adoption. Earlier dates already apply to other parts of the Act: prohibited-practice bans and AI literacy duties began in February 2025, and general-purpose AI model rules took effect in August 2025.