EU AI Act

Is hiring and employment AI high-risk under the EU AI Act?

Yes. Hiring and employment AI is named in EU AI Act Annex III point 4, so almost any tool that screens candidates or evaluates workers is high-risk by listing rather than by assessment. This guide walks the recruitment funnel stage by stage, sets out what an employer owes candidates under Articles 26 and 86, and covers the Article 12 logging that has to be in place before any of it can be demonstrated.

12 min read
Joe Braidwood
Joe Braidwood
CEO, GLACIS
12 min read

Quick Answer: HIGH-RISK

Employment AI is explicitly listed in Annex III, Category 4 of EU Regulation 2024/1689 (the AI Act). This includes AI used for:

  • Recruitment and candidate screening
  • Performance monitoring and evaluation
  • Promotion and termination decisions

Compliance deadline: August 2, 2026 in the current legal text. A "Digital Omnibus" provisional agreement (May 2026) would push standalone high-risk (Annex III) obligations to no later than December 2, 2027, but it is pending formal adoption — treat August 2, 2026 as the operative date until then. Penalty: Up to €15 million or 3% of global turnover.

Annex III Employment Category Explained

The EU AI Act creates a risk-based classification system. Annex III exhaustively lists high-risk use cases requiring full compliance with Articles 8-15. Employment is Category 4:

Annex III, Point 4: Employment, Workers Management, and Access to Self-Employment

"AI systems intended to be used for:

  • (a) recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates;
  • (b) making decisions affecting terms of work-related relationships, promotion or termination of work-related contractual relationships, allocating tasks based on individual behaviour or personal traits or characteristics, or monitoring and evaluating the performance and behaviour of persons in such relationships."

— EU Regulation 2024/1689, Annex III, Point 4[1]

The language is deliberately broad. The regulation doesn’t just cover final hiring decisions—it covers any AI system involved in the employment lifecycle from job advertisement through termination.

Full Scope of Covered Employment AI

Many organizations underestimate the breadth of employment AI subject to high-risk requirements. The following systems are explicitly covered:

Recruitment and Hiring

Job Advertisement Targeting

AI systems that determine which candidates see job postings—including LinkedIn’s ad targeting, programmatic job advertising platforms, and audience optimization tools.

Resume Screening

Automated filtering of applications based on keywords, qualifications, or predicted job fit. Includes ATS scoring systems, resume parsers, and candidate ranking algorithms.

Interview Analysis

AI that evaluates video interviews, analyzes speech patterns, assesses body language, or scores candidate responses. HireVue, Pymetrics, and similar platforms fall squarely within scope.

Candidate Assessment

Psychometric testing, game-based assessments, skills verification, and predictive analytics that estimate candidate success or cultural fit.

Workforce Management

Performance Monitoring

AI tracking employee productivity, analyzing keystroke patterns, monitoring communications, or evaluating output quality. Includes warehouse tracking systems, call center analytics, and remote work monitoring.

Task Allocation

Systems assigning work based on predicted performance, availability algorithms, or behavioral analysis. Gig economy platforms (Uber, DoorDash, Deliveroo) use such systems extensively.

Promotion Decisions

AI recommending or ranking employees for advancement, succession planning algorithms, or "high-potential" identification systems.

Termination Recommendations

Systems flagging employees for performance improvement plans, predicting attrition risk, or recommending layoff candidates based on algorithmic criteria.

Key Determining Factors

Not every HR software tool is automatically high-risk. The classification depends on whether the AI system:

  1. Makes or materially influences employment decisions—filtering candidates, scoring performance, recommending actions
  2. Processes personal data to evaluate individuals—analyzing behavior, traits, or characteristics
  3. Affects employment relationship terms—compensation, scheduling, task assignment, contractual status

Examples that ARE high-risk:

Examples that may NOT be high-risk:

When uncertain, classify conservatively. Regulators may disagree with narrow interpretations, and the penalty asymmetry favors over-compliance.

The hiring funnel, stage by stage

Employers ask whether the EU AI Act applies to hiring and get a yes, which is accurate and not very actionable, because a recruitment process is six or seven distinct systems rather than one. The table below walks a standard funnel and marks what actually attaches at each stage. Two stages that many teams assume are safe are not.

Stage Typical AI use In Annex III scope? What attaches
Sourcing Targeted job advertising, candidate discovery in a talent pool Yes Annex III names targeted job advertisements explicitly, so exposure begins before anyone applies
Application screening CV parsing, keyword filtering, knock-out questions Yes Filtering applications is named directly; automated rejection is the highest-exposure step in the funnel
Ranking Match scoring, shortlist ordering Yes Ranking is profiling, which removes access to the Article 6(3) derogation
Assessment Games-based testing, coding assessment scoring, personality inference Yes Evaluating candidates in tests is named; inference of traits raises fundamental-rights exposure
Interview Transcription, scoring, video or voice analysis Yes for scoring Transcription alone is weaker, but any scoring or inference makes it an evaluation system
Candidate chatbot Screening questions, scheduling, FAQ handling Depends Scheduling only is generally out; asking screening questions that gate progress puts it in, and Article 50 transparency applies either way
Offer Compensation banding, offer-acceptance prediction Yes where it affects terms Decisions affecting the terms of the relationship fall inside point 4

The derogation is the part worth reading carefully. Article 6(3) lets a system named in Annex III escape high-risk treatment where it performs a narrow procedural task, improves the result of a previously completed human activity, or does only preparatory work, and does not pose a significant risk of harm. Employers reach for it often. It rarely holds in recruitment, because the same provision states that a system always counts as high-risk where it performs profiling of natural persons — and scoring, ranking, or matching candidates is profiling. A CV parser that only extracts fields into a form may genuinely qualify. The moment it orders candidates, it does not.

Two practical consequences follow. Sourcing is in scope, so an organization that has audited its screening tool and left its advertising platform unexamined has assessed the second half of its exposure and not the first. And a funnel assembled from four vendors is four separate provider relationships, each owing documentation, with the employer sitting as deployer across all of them and carrying the duties in the next section for each.

What an employer owes candidates and workers: Articles 26 and 86

Most coverage of high-risk employment AI concentrates on Articles 9 to 15, which bind the provider that builds the system. An employer buying a hiring tool is usually a deployer, and the deployer obligations sit elsewhere in the Regulation. Two are routinely missed, and both are owed directly to people rather than to a regulator.

Article 26(7): tell the workforce before you switch it on

Before putting a high-risk AI system into service at the workplace, a deployer who is an employer must inform workers’ representatives and the affected workers that they will be subject to it. The obligation runs ahead of deployment rather than alongside it, and it is independent of whether any works council or co-determination process applies under national law — those add to it, as the German and French sections below describe, they do not substitute for it.

The other Article 26 duties frame the same relationship. Deployers must use the system in accordance with the provider’s instructions for use, assign human oversight to people with the competence, training and authority to exercise it, monitor operation and inform the provider of risks or serious incidents, and keep the logs the system generates for a period appropriate to its purpose and in any event at least six months. That last duty is why the Article 12 logging discussed below is a deployer problem as well as a provider one: the employer has to hold the records, not merely rely on the vendor holding them.

Article 86: the rejected candidate can ask why

Article 86 gives any person affected by a decision taken on the basis of the output of an Annex III high-risk system — with the sole exception of point 2, critical infrastructure — the right to obtain from the deployer a clear and meaningful explanation of the role the AI system played in the decision and the main elements of the decision taken. Employment is point 4, so it is squarely covered.

Read plainly, that means a rejected candidate can write to the employer and ask what part the AI played in rejecting them, and the employer owes an answer. Not the vendor. The employer. Three things follow that are worth deciding before the first request arrives rather than after.

The uncomfortable case is the one where a candidate asks and the employer cannot reconstruct what happened. The tool ran months ago, the model has been updated since, the logs rolled off, and nobody recorded which version scored this application or what it returned. That is not a documentation failure discovered at audit; it is a failure discovered in correspondence with a person who has a statutory right to an answer, and it is the practical reason Article 12 logging matters more in employment than in most other high-risk domains.

High-Risk Compliance Requirements (Articles 9-15)

Employment AI systems must satisfy the full suite of high-risk requirements. The EU AI Act mandates seven categories of obligations:

Article 9: Risk Management System

Continuous, iterative process throughout the AI system lifecycle:

  • Identify and analyze foreseeable risks to health, safety, and fundamental rights
  • Estimate and evaluate risks from intended use and reasonably foreseeable misuse
  • Adopt appropriate risk mitigation measures

Article 10: Data Governance

Training, validation, and testing datasets must be:

  • Relevant, sufficiently representative, and free of errors
  • Examined for possible biases likely to affect fundamental rights
  • Subject to appropriate data governance measures

Article 11: Technical Documentation

Comprehensive documentation per Annex IV:

  • General system description, intended purpose, and developer information
  • Detailed development process and elements
  • Validation, testing procedures, and risk management documentation

Article 12: Record-Keeping (Logging)

Automatic recording of events throughout operation:

  • Logging capabilities ensuring traceability of decisions
  • Records of inputs, outputs, and persons involved in verification
  • Tamper-evident logs retained for appropriate periods

Article 13: Transparency

Enable deployers to understand and interpret:

  • System capabilities and limitations
  • How to interpret system output appropriately
  • Instructions for use in digital or non-digital format

Article 14: Human Oversight

Enable effective oversight by natural persons:

  • Fully understand capacities and limitations
  • Ability to override, disregard, or reverse AI output
  • Awareness of automation bias risk

Article 12 Logging: The GLACIS Connection

Article 12 is where employment AI compliance becomes operationally complex—and where GLACIS provides critical value. The regulation requires:

"High-risk AI systems shall technically allow for the automatic recording of events (’logs’) over the lifetime of the system... ensuring a level of traceability of the AI system’s functioning throughout its lifecycle that is appropriate to the intended purpose of the system." — EU AI Act, Article 12(1)

For employment AI, this means logging:

Logs must be tamper-evident and retained appropriately. In employment contexts, this often means years—discrimination claims can be filed long after the decision occurred.

Fairness, Bias, and Discrimination Requirements

The EU AI Act places extraordinary emphasis on preventing discrimination in employment AI. Article 10 requires:

Bias Examination Requirement

"Training, validation and testing data sets shall be examined in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law."

— Article 10(2)(f)

For employment AI, this intersects with existing anti-discrimination frameworks:

Organizations must demonstrate they’ve tested for bias across protected characteristics and implemented mitigation measures. This requires:

  1. Demographic analysis of training data representation
  2. Disparate impact testing across protected groups
  3. Ongoing monitoring for bias drift in production
  4. Documentation of bias findings and remediation steps

Interaction with Employment Law

The EU AI Act doesn’t exist in isolation. Employment AI must also satisfy national employment laws, which often impose additional requirements:

Germany: Works Council Co-Determination

Under the Betriebsverfassungsgesetz (Works Constitution Act), works councils have mandatory co-determination rights over:

Deploying employment AI without works council consultation can result in injunctions, even if the system itself is EU AI Act compliant.

France: CNIL and Labor Code

The CNIL (data protection authority) has issued specific guidance on AI-assisted recruitment. The Labor Code requires informing employees of surveillance methods and consulting comités sociaux et économiques (CSE).

Netherlands: Employee Consent

Dutch data protection authority guidelines require explicit consent for AI-based profiling in employment contexts, beyond GDPR’s legitimate interest basis.

US Regulatory Comparison

While the EU AI Act represents the most comprehensive framework, US employers face a growing patchwork of employment AI regulations:

Jurisdiction Regulation Key Requirements
Federal (EEOC) Title VII, ADA AI tools that produce disparate impact can violate Title VII; employers liable even if vendor-provided
New York City Local Law 144 Bias audits required for automated employment decision tools; candidate notice; annual public reporting
Illinois AI Video Interview Act Notice and consent required for AI video interview analysis; data destruction upon request
Colorado SB 26-189 (Automated Decision-Making Technology) Repealed and replaced the 2024 Colorado AI Act; pre-use notice, post-adverse-outcome disclosure, data-correction and human-review rights for covered ADMT used in consequential decisions. Substantive compliance from January 1, 2027
Maryland Facial Recognition Ban Prohibits facial recognition in hiring without explicit consent
California CCPA/CPRA Right to opt out of automated decision-making; transparency requirements

US multinational companies must increasingly manage compliance across both EU AI Act requirements and this fragmented US landscape.

Evidence Requirements for Regulators

When regulators—or litigants—come asking questions about your employment AI, you’ll need evidence that your controls actually work. Documentation alone isn’t sufficient.

Regulators may request:

  1. Technical documentation per Annex IV—system architecture, training data details, validation results
  2. Risk assessment records—identified risks, probability/severity estimates, mitigation measures
  3. Bias audit results—disparate impact analysis across protected groups, remediation evidence
  4. Decision logs—complete audit trails for specific candidates or employees
  5. Human oversight records—evidence that humans reviewed and could override AI decisions
  6. Incident reports—any serious incidents reported per Article 73

The distinction between policy documentation and execution evidence is critical. A policy stating "humans review all AI recommendations" means nothing without logs proving that review actually occurred.

Implementation Checklist

Employment AI Compliance Checklist

Inventory all employment AI systems

Recruitment tools, performance monitoring, scheduling algorithms, termination analytics

Classify each system’s risk level

Document rationale for classification; conservatively classify uncertain cases as high-risk

Establish risk management process

Identify, analyze, evaluate, and mitigate risks to health, safety, and fundamental rights

Conduct bias audits

Test for disparate impact across protected characteristics; document findings and remediation

Implement Article 12 logging

Automatic, tamper-evident logging of all decisions, inputs, outputs, and human interventions

Design human oversight controls

Ensure humans can understand, override, and reverse AI decisions; train oversight personnel

Prepare technical documentation

Compile Annex IV documentation including system description, data governance, validation results

Consult works councils / employee representatives

Where applicable (Germany, France, Netherlands, etc.), engage employee bodies before deployment

Establish post-market monitoring

Ongoing monitoring for performance degradation, bias drift, and serious incidents

Train HR and management

Ensure human overseers understand AI capabilities, limitations, and their oversight responsibilities

Deadline reminder: The legal text sets August 2, 2026 for high-risk employment AI. A Digital Omnibus provisional agreement (May 2026) would postpone Annex III obligations to no later than December 2, 2027, pending formal adoption — so plan to August 2, 2026 until that change is adopted. Start now—implementation typically takes 6-12 months.

Frequently Asked Questions

Is employment AI high-risk under the EU AI Act?

Yes. Employment AI is explicitly classified as high-risk under Annex III, Category 4: "Employment, workers management and access to self-employment." This includes AI used for recruitment, job advertising, application screening, interview analysis, performance monitoring, promotion decisions, task allocation, and termination recommendations. The compliance deadline in the legal text is August 2, 2026 — though a Digital Omnibus provisional agreement (May 2026) would postpone standalone high-risk (Annex III) obligations to no later than December 2, 2027, pending formal adoption. Plan to the August 2, 2026 date until that change is adopted.

What employment AI systems are covered by EU AI Act Annex III?

Annex III covers AI systems used to: place targeted job advertisements, analyse and filter job applications, evaluate candidates in interviews and tests, monitor and evaluate work performance, make decisions on promotion or termination, allocate tasks based on behavior or traits, and affect contractual relationships. Both recruitment and ongoing workforce management are included.

Does the EU AI Act apply to job advertising?

Yes. Annex III point 4 explicitly names AI systems used to place targeted job advertisements, so exposure begins at sourcing, before anyone has applied. This is the stage employers most often overlook: an organization that has assessed its CV screening tool but not its advertising platform has examined only half of its recruitment exposure.

Can hiring AI avoid high-risk classification under Article 6(3)?

Rarely. Article 6(3) allows a system named in Annex III to escape high-risk treatment where it performs only a narrow procedural task, improves the result of a previously completed human activity, or does preparatory work, and poses no significant risk of harm. The same provision states that a system is always high-risk where it performs profiling of natural persons. Scoring, ranking, or matching candidates is profiling, so the derogation closes for most recruitment tools. A parser that only extracts fields into a form may qualify; the moment it orders candidates, it does not.

Can a rejected candidate ask why the AI rejected them?

Yes. Article 86 gives any person affected by a decision taken on the basis of the output of an Annex III high-risk system, with the sole exception of point 2 covering critical infrastructure, the right to obtain from the deployer a clear and meaningful explanation of the role the AI system played in the decision and the main elements of the decision taken. Employment is point 4, so it is covered. The obligation falls on the employer as deployer, not on the vendor, and the explanation has to be specific to that candidate’s application rather than a general description of how the tool works.

Do we have to tell employees before deploying an AI system at work?

Yes. Under Article 26(7), before putting a high-risk AI system into service at the workplace, a deployer who is an employer must inform workers’ representatives and the affected workers that they will be subject to it. The duty runs ahead of deployment rather than alongside it, and it is independent of national co-determination rules such as German works council consultation, which add to the obligation rather than replacing it.

What are the compliance requirements for high-risk employment AI?

Providers must satisfy Articles 9 to 15: a risk management system, data governance and bias testing, technical documentation, automatic logging, transparency and instructions for use, human oversight, and accuracy, robustness and cybersecurity. Deployers carry Article 26 duties, including using the system per its instructions, assigning competent human oversight, monitoring operation, keeping the generated logs for at least six months, and informing workers before deployment.

How does Article 12 logging apply to employment AI?

Article 12 requires employment AI systems to automatically log all decisions including candidate evaluations, rejection reasons, performance assessments, and termination recommendations. Logs must be tamper-evident, retained for appropriate periods, and enable traceability for regulatory audits and discrimination claims. This creates an audit trail for every employment decision influenced by AI, and it is what makes an Article 86 explanation answerable months after the decision was taken.

How do works councils affect employment AI deployment in Germany?

German works councils hold co-determination rights over the introduction of technical systems capable of monitoring employee performance or behavior, which covers most employment AI. In practice this means agreement has to be negotiated before deployment, not sought afterwards, and it sits on top of the Article 26(7) duty to inform workers and their representatives rather than replacing it.

Does our US-based recruitment platform need to comply?

If the platform is used to make employment decisions affecting EU workers or candidates, yes. The EU AI Act has extraterritorial reach: it applies wherever AI system output is used in the EU, regardless of where the provider or deployer is located. The platform may also need to comply with NYC Local Law 144, Illinois requirements, or other US regulations depending on where candidates are located.

What is the difference between provider and deployer for employment AI?

The provider is the entity that develops or places the AI system on the market. The deployer is the entity using the system, such as a company using a screening tool for interviews. Both have obligations: providers must ensure the system enables compliance through logging, transparency and documentation; deployers must implement human oversight, monitor for issues, keep the system’s logs, and use the system as intended. If you customize a general-purpose AI for employment use, you may become the provider.

Can we use ChatGPT or Claude to screen resumes?

You can, but you become the "provider" of a high-risk AI system. General-purpose AI models are subject to GPAI obligations (Articles 53-55), but when you integrate them into a high-risk use case like employment screening, you bear full responsibility for Articles 8-15 compliance—including risk management, bias testing, logging, human oversight, and conformity assessment. The foundation model provider (OpenAI, Anthropic) doesn’t assume your employment AI liability.

How do we handle employee monitoring tools already deployed?

Existing systems must be brought into compliance by August 2, 2026 under the current legal text — a Digital Omnibus provisional agreement (May 2026) would push Annex III high-risk obligations to no later than December 2, 2027, but it is pending formal adoption, so plan to the August 2, 2026 date. Conduct a gap assessment against Articles 9-15 requirements, implement required controls (especially logging and human oversight), document your risk management process, and test for bias. If a system can’t be made compliant, you may need to discontinue or replace it. Don’t forget to consult works councils where applicable.

What penalties apply for non-compliant employment AI?

Non-compliance with high-risk system obligations (Articles 8-15) carries penalties up to €15 million or 3% of total worldwide annual turnover, whichever is higher. For fundamental rights violations including discrimination, the actual penalty may be higher when combined with GDPR, employment law, and anti-discrimination enforcement. Reputational damage from publicized violations often exceeds regulatory fines.

References

  1. [1] European Union. "Regulation (EU) 2024/1689 of the European Parliament and of the Council." Official Journal of the European Union, July 12, 2024. EUR-Lex 32024R1689
  2. [2] European Commission. "Annexes to Regulation (EU) 2024/1689 - Annex III High-Risk AI Systems." EUR-Lex, July 12, 2024.
  3. [3] EEOC. "The Americans with Disabilities Act and the Use of Software, Algorithms, and Artificial Intelligence." Guidance, May 2022. eeoc.gov
  4. [4] NYC Department of Consumer and Worker Protection. "Automated Employment Decision Tools (Local Law 144)." Rules and Guidance, 2023. nyc.gov
  5. [5] Illinois General Assembly. "Artificial Intelligence Video Interview Act." 820 ILCS 42, 2020.
  6. [6] Colorado General Assembly. "Colorado Artificial Intelligence Act." SB24-205, 2024 — repealed and replaced before taking effect by SB 26-189 ("Automated Decision-Making Technology"), signed May 14, 2026.
  7. [7] German Bundestag. "Betriebsverfassungsgesetz (Works Constitution Act)." §87, §94, §95.
  8. [8] European Parliament. "Directive 2000/78/EC Establishing a General Framework for Equal Treatment in Employment." November 27, 2000.

Prove Your Employment AI Complies

GLACIS generates cryptographic evidence that your HR AI systems meet EU AI Act Article 12 logging requirements. Every decision. Every audit trail. Every override. Provably compliant.

Start Your Compliance Sprint

Related Guides