Skip to main content

Recruitment and the EU AI Act

This is not the front door. The recruitment work is on the embedded recruitment page. This page explains the legal boundary around that work.

Two duties already apply. The rest is designable.

Most of what gets written about the AI Act and hiring is a date, pointed at you like a threat. Start with what is already true instead. The AI literacy duty and the prohibited practices already apply. Inferring emotion from a candidate's face or voice is a prohibited practice, not a high-risk one, and that prohibition is already in force.

The wider picture is calmer than the headlines. AI used in recruitment and employment is treated as high risk under the EU AI Act. That is not a ban. An ATS that scores or ranks candidates will normally be a high-risk AI system, and the employer using it is the deployer. High risk means documented, governed and explainable, and that is a system you can design.

This page sets out what the Act means for a company running AI in hiring: what you owe, what you do not, and what Solvism builds around it. Solvism is not a law firm and does not give legal advice.

Verified
9 August 2026, against EUR-Lex
Recheck by
9 November 2026
Covers
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
This is not
Legal advice, or a compliance guarantee

Who owes what

You are the deployer. Your vendor is the provider.

These are different duty sets, and the difference decides most of what you actually have to do. You are the deployer. Your vendor is the provider. The vendor builds the system and places it on the market. You use it inside your hiring.

Having a recruiter review the output does not, on its own, change how the system is classified. Human oversight is real design work, not a person glancing at a ranked list before it goes out.

The classification decision is the provider's. As a buyer you can check whether they made it, documented it, and registered it. Solvism does not classify your system for you and does not tell you it is not high risk. It checks what the provider did and writes down what is missing.

What you own, as the deployer

  • Using the system in line with the vendor's instructions, and assigning human oversight to named people with real authority
  • Informing workers' representatives and affected workers before the system is put into service
  • Informing candidates that a system makes or assists a decision about them, and keeping the logs for at least six months

What your vendor owns, as the provider

  • The classification decision, and the documented assessment if they conclude the system is not high risk
  • Conformity assessment, CE marking and registration before the system reaches the market
  • The twelve provider obligations: logging, documentation and corrective action among them

That is the vendor's work, not yours, and you can ask to see it documented. These deployer duties apply from 2 December 2027, verified against the consolidated EUR-Lex text on 9 August 2026. That date has already moved once, so it is worth checking again before you plan around it.

You can be pulled into provider duties yourself if you rebrand the tool, substantially modify it, or wire a general-purpose model into your funnel. Buying a tool rather than building one does not, on its own, keep you out.


Where GDPR and the AI Act meet

Two things worth raising before you sign anything.

When Solvism reviews a hiring stack, two points come up more than any other. Neither is a scare tactic. Both are places where the law and the tool meet in a way most buyers have not been shown.

A vendor match score can already be a regulated decision.

The Court of Justice has held that a probability score produced by one company can be an automated decision under the GDPR where the company that receives it draws strongly on it. Both of the cases so far are about credit scoring, not hiring, so this is a direction of travel, not a hiring ruling. Under the GDPR, meaningful human involvement can take a decision outside Article 22. Under the AI Act, it does not take a system outside Annex III. Two different regimes, two different tests, and it is easy to satisfy one while assuming it covers the other.

Token human review is not oversight.

Endorsed EDPB guidance says the review has to be meaningful rather than a token gesture, carried out by someone with the authority and competence to change the decision. A person clicking approve on a ranked list, without the standing to override it, does not meet that bar. Human oversight design means naming who decides, at which step, on what evidence.

The GDPR applies today, and the AI Act's later date changed nothing in it.


What you do not owe

Three obligations most vendors sell that you do not have.

A surprising amount of AI Act selling points at a private employer a duty that actually sits somewhere else, or nowhere. Before you buy a compliance product, check whether the duty is even yours.

  • A fundamental rights impact assessment

    Article 27 covers public bodies, private entities providing public services, and creditworthiness and life-and-health-insurance systems. A private employer running recruitment AI is not on that list, so this duty does not arrive for you, at any date.

  • EU database registration

    That is Article 26(8), which covers public authorities, and Article 49, which is the vendor's. If someone is selling you EU database registration as your obligation, check who actually registers.

  • AI literacy certification

    The AI literacy duty already applies, and it asks you to support your people's understanding of the systems they use. It does not require a specific level for any individual, and no harmonised standard has been published, so no system can be certified or presumed conforming against one today.


Vendor due diligence

Eight questions Solvism asks your vendor, in writing.

Whether a specific feature is in scope turns on documented facts about that system, not on a five-minute call. These are the eight questions, with the article each one turns on.

  1. Intended purpose

    What is the documented intended purpose in the instructions for use and in the sales materials, and does the sales pitch agree with it? (Art. 3(12), Annex III point 4(a))

  2. Scoring, or plumbing

    Does the feature score, rank, shortlist, grade or categorise candidates, or does it only parse, deduplicate, reformat, schedule or search without applying evaluative weight? (Art. 6(3)(a) and (d))

  3. Profiling

    Does it process personal data to evaluate or predict personal aspects of a candidate? If yes, no carve-out is available at all. (Art. 6(3), third subparagraph)

  4. The provider's own classification

    Has the provider concluded the system is not high risk, documented that assessment, and registered it? Ask for the document and the registration entry. (Art. 6(4), Art. 49(2))

  5. Timing and changes

    Was the system placed on the market before the relevant Chapter III date, and does your release cadence amount to a significant change in its design? (Art. 111(2))

  6. What you did to it

    Have you rebranded it, materially modified it, or wired a general-purpose model into the hiring funnel? (Art. 25(1)(a) to (c))

  7. Emotion inference

    Does any component infer emotion, affect, sentiment or personality from a candidate's voice, face or video? This is a prohibition question, not a classification one, and it is live now. (Art. 5(1)(f))

  8. Agentic or chained

    Is any part of it agentic, or chained into a larger decision pipeline? A system can stay high risk even where one piece, taken alone, would not.

Parsing, deduplicating, scheduling and searching without evaluative weight are treated differently from scoring and ranking. That distinction is what these questions pin down, in writing, so the answer sits on the record rather than on a sales call.


What Solvism produces

Process and documentation, built to be explained.

Solvism designs the process and produces the documentation: risk management, data governance, logging, human oversight design, bias monitoring, vendor due diligence. Human oversight design means naming who decides, at which step, on what evidence.

Built to be explained to a regulator, a works council, a client's legal team, or a candidate who asks.


The honest boundary

Where Solvism stops.

Legal responsibility stays with the client. Solvism designs and builds the hiring system and the documentation that makes it explainable. It does not certify anyone and does not guarantee anyone's compliance.

Solvism is not a law firm and does not give legal advice.

The Commission's classification guidelines referred to on this page are still in draft, published 19 May 2026, with a final version expected later. No harmonised standard has been published under the Act, so no system can be certified or presumed conforming against one today.

Sources and recheck date

Verified against primary sources on 9 August 2026. Recheck by 9 November 2026, and sooner if the Commission adopts final Article 6(5) guidelines, a further amendment to the Act lands, or a harmonised standard is cited in the Official Journal.


Next step

This is solvable, and there is a method.

The gap between an AI hiring stack you can explain and one you cannot is a design problem with a known shape. Talk to Jonathan about what you are already running, or start with the fixed-price assessment if you want it mapped first: what you use, who your provider is, what they classified, and where your documentation stops.