EU AI Act · use case
EU AI Act for Recruitment and CV Screening Tools: High-Risk Obligations
AI that ranks candidates, filters CVs or targets job ads is high-risk under Annex III of the EU AI Act. What providers and employers must do before December 2027.
Classify my system in 3 minutesFree, no account. Pre-filled for this use case.
Risk tier
High-risk
High-risk (Annex III, point 4(a))
When it applies
Full high-risk obligations apply from 2 December 2027. Emotion-recognition bans already apply since 2 February 2025.
Regulation (EU) 2024/1689, Art. 6(2) and Annex III(4)(a); Art. 26 deployer duties; Art. 5(1)(f) emotion recognition ban
Any AI system used to recruit or select people is on the EU AI Act’s high-risk list by name. That covers tools that place targeted job advertisements, screen or filter applications, rank candidates, score video interviews, or evaluate people during the hiring process. It does not matter whether the tool makes the final decision or only suggests a shortlist: the Annex III entry is about intended use, not autonomy.
The obligations land on two parties. The provider (the company that builds and sells the tool) carries the heavier load: risk management, data governance, technical documentation, human oversight design, conformity assessment, CE marking and registration in the EU database. The deployer (the employer using it) must use the system according to the instructions, assign trained human overseers, inform workers’ representatives and affected candidates, keep logs, and in many cases complete a fundamental rights impact assessment.
Classification
Why this classification applies
Annex III, point 4(a) lists “AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates”. A CV parser that scores fit, a chatbot that pre-qualifies applicants, or an ad platform that decides which people see a vacancy all fit that description.
The Article 6(3) carve-out (systems that only perform a narrow procedural task or prepare a human decision) rarely helps here. The regulation states that a system that profiles natural persons is always high-risk, and candidate evaluation is profiling. A tool that merely extracts dates and job titles from a CV without scoring may qualify for the carve-out, but the moment it ranks or filters, it is high-risk.
Separately, Article 5 prohibits AI that infers emotions of people in the workplace, including during interviews, except for medical or safety reasons. “Engagement” or “confidence” scoring of interview video is a prohibited practice, not a high-risk one, with fines up to €35M or 7% of global turnover.
Obligations
What you have to do
- Risk management system across the lifecycle, with specific attention to discrimination risks against protected groups (Art. 9).
- Data governance for training and testing data: representativeness for the labour markets and roles targeted, bias examination and mitigation (Art. 10).
- Technical documentation to Annex IV before the tool is placed on the market (Art. 11) and automatic logging of use (Art. 12).
- Human oversight built into the product: recruiters must be able to see why a candidate was ranked, override the ranking, and stop the system (Art. 14).
- Accuracy, robustness and cybersecurity appropriate to the purpose, with documented metrics (Art. 15).
- Conformity assessment by internal control, EU declaration of conformity, CE marking and registration in the EU database (Arts. 43, 47, 48, 49).
- Deployer duties for employers: inform workers’ representatives and affected workers before deployment, keep logs for at least six months, assign competent human oversight (Art. 26).
- Candidates subjected to a decision must be able to obtain a clear explanation of the role the AI played (Art. 86).
Paperwork
Documents to have on file
Get these documents drafted for your system
Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.
Common mistakes
Where companies get this wrong
- Treating a “recommendation only” tool as low-risk. Recruiters follow the shortlist; the law assumes they will.
- Training on historical hiring data without documenting the bias examination. Past hiring patterns are the textbook source of proxy discrimination.
- Video-interview scoring that infers emotion or personality from facial expressions or voice. This is a prohibited practice, not a documentation gap.
- Assuming GDPR compliance covers it. GDPR Art. 22 and the AI Act overlap but the AI Act adds product-safety-style duties (technical file, conformity assessment) that GDPR does not have.
- Non-EU vendors ignoring the rules because they are not established in the EU. The AI Act applies wherever the output is used in the EU, and non-EU providers must appoint an authorised representative (Art. 22).
FAQ
Frequently asked questions
Our tool only parses CVs into structured fields. Is it high-risk?
Pure extraction without scoring, ranking or filtering can fall under the Article 6(3) exception for narrow procedural tasks. Document that reasoning in writing, because the moment a “fit score” or ranking is added, the exception no longer applies and the system becomes high-risk.
We are an employer using a third-party screening tool. What do we have to do?
As a deployer you must use the tool according to its instructions, assign trained human oversight, inform workers’ representatives and candidates, keep the automatically generated logs for at least six months, and monitor for problems. If you substantially modify the tool or use it for a purpose the provider did not intend, you become the provider with the full set of obligations.
When do these rules apply?
The high-risk regime for Annex III systems applies from 2 December 2027 under the Digital Omnibus timetable. The ban on emotion recognition in the workplace has applied since 2 February 2025, and AI literacy duties for staff also apply now.
This page is general information about Regulation (EU) 2024/1689, updated 2026-09-17. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026. Leer en español.