EuroComply
Free assessment

EU AI Act · use case

EU AI Act for Recruitment and CV Screening Tools: High-Risk Obligations

AI that ranks candidates, filters CVs or targets job ads is high-risk under Annex III of the EU AI Act. What providers and employers must do before December 2027.

Classify my system in 3 minutes

Free, no account. Pre-filled for this use case.

Risk tier

High-risk

High-risk (Annex III, point 4(a))

When it applies

Full high-risk obligations apply from 2 December 2027. Emotion-recognition bans already apply since 2 February 2025.

Regulation (EU) 2024/1689, Art. 6(2) and Annex III(4)(a); Art. 26 deployer duties; Art. 5(1)(f) emotion recognition ban

Any AI system used to recruit or select people is on the EU AI Act’s high-risk list by name. That covers tools that place targeted job advertisements, screen or filter applications, rank candidates, score video interviews, or evaluate people during the hiring process. It does not matter whether the tool makes the final decision or only suggests a shortlist: the Annex III entry is about intended use, not autonomy.

The obligations land on two parties. The provider (the company that builds and sells the tool) carries the heavier load: risk management, data governance, technical documentation, human oversight design, conformity assessment, CE marking and registration in the EU database. The deployer (the employer using it) must use the system according to the instructions, assign trained human overseers, inform workers’ representatives and affected candidates, keep logs, and in many cases complete a fundamental rights impact assessment.

Classification

Why this classification applies

Annex III, point 4(a) lists “AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates”. A CV parser that scores fit, a chatbot that pre-qualifies applicants, or an ad platform that decides which people see a vacancy all fit that description.

The Article 6(3) carve-out (systems that only perform a narrow procedural task or prepare a human decision) rarely helps here. The regulation states that a system that profiles natural persons is always high-risk, and candidate evaluation is profiling. A tool that merely extracts dates and job titles from a CV without scoring may qualify for the carve-out, but the moment it ranks or filters, it is high-risk.

Separately, Article 5 prohibits AI that infers emotions of people in the workplace, including during interviews, except for medical or safety reasons. “Engagement” or “confidence” scoring of interview video is a prohibited practice, not a high-risk one, with fines up to €35M or 7% of global turnover.

Obligations

What you have to do

  • Risk management system across the lifecycle, with specific attention to discrimination risks against protected groups (Art. 9).
  • Data governance for training and testing data: representativeness for the labour markets and roles targeted, bias examination and mitigation (Art. 10).
  • Technical documentation to Annex IV before the tool is placed on the market (Art. 11) and automatic logging of use (Art. 12).
  • Human oversight built into the product: recruiters must be able to see why a candidate was ranked, override the ranking, and stop the system (Art. 14).
  • Accuracy, robustness and cybersecurity appropriate to the purpose, with documented metrics (Art. 15).
  • Conformity assessment by internal control, EU declaration of conformity, CE marking and registration in the EU database (Arts. 43, 47, 48, 49).
  • Deployer duties for employers: inform workers’ representatives and affected workers before deployment, keep logs for at least six months, assign competent human oversight (Art. 26).
  • Candidates subjected to a decision must be able to obtain a clear explanation of the role the AI played (Art. 86).

Paperwork

Documents to have on file

Annex IV technical documentation
Risk management file (Art. 9)
Data governance records per dataset (Art. 10)
Instructions for use for employers (Art. 13)
Human oversight procedure (Art. 14)
EU declaration of conformity (Art. 47)
EU database registration entry (Art. 49)
Worker information notice (Art. 26(7))
Fundamental rights impact assessment where the deployer is a public body or provides public services (Art. 27)

Get these documents drafted for your system

Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

Common mistakes

Where companies get this wrong

  • Treating a “recommendation only” tool as low-risk. Recruiters follow the shortlist; the law assumes they will.
  • Training on historical hiring data without documenting the bias examination. Past hiring patterns are the textbook source of proxy discrimination.
  • Video-interview scoring that infers emotion or personality from facial expressions or voice. This is a prohibited practice, not a documentation gap.
  • Assuming GDPR compliance covers it. GDPR Art. 22 and the AI Act overlap but the AI Act adds product-safety-style duties (technical file, conformity assessment) that GDPR does not have.
  • Non-EU vendors ignoring the rules because they are not established in the EU. The AI Act applies wherever the output is used in the EU, and non-EU providers must appoint an authorised representative (Art. 22).

FAQ

Frequently asked questions

Our tool only parses CVs into structured fields. Is it high-risk?

Pure extraction without scoring, ranking or filtering can fall under the Article 6(3) exception for narrow procedural tasks. Document that reasoning in writing, because the moment a “fit score” or ranking is added, the exception no longer applies and the system becomes high-risk.

We are an employer using a third-party screening tool. What do we have to do?

As a deployer you must use the tool according to its instructions, assign trained human oversight, inform workers’ representatives and candidates, keep the automatically generated logs for at least six months, and monitor for problems. If you substantially modify the tool or use it for a purpose the provider did not intend, you become the provider with the full set of obligations.

When do these rules apply?

The high-risk regime for Annex III systems applies from 2 December 2027 under the Digital Omnibus timetable. The ban on emotion recognition in the workplace has applied since 2 February 2025, and AI literacy duties for staff also apply now.

This page is general information about Regulation (EU) 2024/1689, updated 2026-09-17. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026. Leer en español.

Related use cases

High-risk

Employee monitoring & performance

Read →

Limited risk

Customer service chatbots

Read →

Depends on use

Biometric identification & categorisation

Read →

Guide

EU AI Act compliance guide

Read →