High-Risk AI — Employment

EU AI Act for HR and Recruitment: Is Your Hiring AI High-Risk?

Annex III of the EU AI Act explicitly classifies AI used in recruitment, CV screening, interview evaluation, performance monitoring, and task allocation as high-risk. If you use AI tools in any part of your HR process, this guide tells you exactly what obligations apply to you before the August 2, 2026 deadline.

10 min read·Deadline: August 2, 2026·Annex III, Section 4

Key takeaways

  • CV screening AI, interview scoring tools, and performance monitoring AI are explicitly high-risk under Annex III Section 4 of the EU AI Act.
  • Most businesses using these tools are deployers — you don't need to build AI to have obligations.
  • Six deployer obligations apply: use as intended, human oversight, data governance, worker/candidate notification, log retention, and a duty to suspend non-compliant tools.
  • Emotion recognition in workplaces is already banned since February 2025 — not August 2026. Review any "wellbeing AI" immediately.
  • Using ChatGPT to screen CVs can make you the de facto provider of a high-risk AI system — not just a deployer.

What counts as high-risk HR AI

Section 4 of Annex III lists two categories of employment AI that are explicitly high-risk under the EU AI Act. Unlike the risk classifier, which requires you to determine risk level, the EU AI Act has already answered this question for HR tools that fit these descriptions.

Annex III, 4(a)

Recruitment and candidate selection

AI systems used in advertising vacancies, screening or filtering applications, and evaluating candidates during interviews or tests.

Examples in scope

  • CV screening tools that score or rank applicants
  • AI that parses CVs and shortlists candidates automatically
  • Video interview platforms that analyse body language, tone, or facial expressions to rate candidates
  • Automated job-matching tools that filter out candidates based on predicted fit
  • Assessment tools that use AI to score personality, cognitive ability, or culture fit
Annex III, 4(b)

Promotion, termination, and work management

AI used to make or influence decisions about promoting, demoting, or ending work relationships, allocating tasks, or monitoring and evaluating worker performance and behaviour.

Examples in scope

  • Performance management tools that use AI to score employee productivity
  • Workforce scheduling software that uses AI to assign shifts or tasks
  • AI that monitors employee behaviour (keystrokes, screen time, location data) to flag risk
  • Systems that recommend promotion or pay-raise decisions based on AI analysis
  • AI-driven termination support tools that flag employees for dismissal

HR AI that is NOT high-risk

Not every AI tool used by an HR team creates high-risk obligations. The test is whether the AI evaluates, scores, ranks, or makes decisions about people — not whether it is used in an HR context. These common tools fall outside Annex III Section 4:

HR toolWhy it is NOT high-risk
AI job description writerAssists with drafting text — no decision-making or evaluation of a person.
AI interview scheduling assistantLogistics only — no evaluation, ranking, or scoring of candidates.
HR chatbot for employee FAQsAnswering general questions is not an employment decision. Still needs Article 50 chatbot disclosure.
Spell-checker or grammar tool used in performance reviewsText editing with no independent evaluation of the employee.
AI that summarises a job posting from a provided briefContent generation with no candidate or employee assessment.
Sentiment analysis on anonymous employee surveysAggregate analysis not linked to individual evaluation or decisions. If it creates individual profiles, reassess.

Note: Even if a tool is not high-risk, it may still trigger other obligations — for example, Article 50 transparency requirements for AI chatbots that interact with employees or candidates.

Are you a provider or a deployer?

The EU AI Act draws a sharp distinction between providers (organisations that develop and place AI systems on the market) and deployers (organisations that use AI systems in their own context). Most businesses using commercial HR software are deployers — and deployers have a distinct, lighter set of obligations than providers, but those obligations are real and enforceable.

You are a provider if…

  • • You build a CV screening or ranking tool for sale or internal use
  • • You develop a custom performance monitoring system
  • • You use an API (e.g. OpenAI) to create an AI hiring tool for your own business
  • • You are an HR software vendor

Provider obligations include technical documentation, risk management, conformity assessment, and EU registration — significantly more than deployer obligations.

You are a deployer if…

  • • You subscribe to Workday, SAP, or similar HR software
  • • You use HireVue or a similar video interview platform
  • • You use LinkedIn Talent Solutions with AI matching
  • • Your ATS has AI-powered candidate ranking that you did not build

Most SMBs fall here. The six deployer obligations below apply to you — read them carefully.

The 6 deployer obligations for high-risk HR AI

If you deploy a high-risk HR AI system — even if you bought it from a reputable vendor — these obligations apply to you directly under Article 26 of the EU AI Act. They are not optional and cannot be delegated to your vendor.

01

Use the system only as the provider intended

Article 26(1)

You must use the AI system in accordance with the provider's instructions for use. Do not repurpose a recruitment AI tool for a different task (e.g., using a CV-screening tool to also evaluate employees for promotions) without confirming the provider has covered that use case in their documentation.

02

Assign a qualified human for oversight

Article 26(2)

You must designate specific individuals to perform human oversight of the AI system. These individuals need sufficient competence, training, and authority to override AI outputs. For HR: a hiring manager or HR professional must review all AI-generated shortlists, scores, or recommendations before a decision is made. The AI cannot be the sole decision-maker.

03

Ensure input data is relevant and representative

Article 26(3)

If you control the data fed into the AI system (e.g., uploading CV data, providing custom training data), you are responsible for ensuring that data is appropriate, relevant, and does not introduce biased or irrelevant signals. This is particularly important for AI trained on historical hiring data, which can perpetuate past discriminatory patterns.

04

Notify workers and candidates that AI is being used

Article 26(6)

You must inform employees and candidates that a high-risk AI system is being used in decisions that concern them. For recruitment: notify applicants in the job advertisement or application process that AI tools are used to screen or evaluate applications. For performance management: notify employees in employment contracts, handbooks, or direct notice. This is not optional — it is a binding obligation.

05

Keep logs for at least six months

Article 26(5)

Where your system generates logs automatically (as required of the provider), you must retain those logs. If you cannot access logs from the AI provider's system, request them — or document your own oversight records (who reviewed each AI output, what decision was made, and why any AI recommendation was overridden). Retention period: at least 6 months from each use of the system.

06

Suspend use if the system poses an unacceptable risk

Article 26(4)

If you believe the AI system is not conforming to the EU AI Act — for instance, because the provider cannot provide required documentation, or because the tool's outputs show signs of discriminatory patterns — you must suspend its use and notify the provider. You cannot simply continue using a non-compliant tool because it came from a reputable vendor.

The GPAI edge case: using ChatGPT to screen CVs

A recruiter who asks ChatGPT to "review these 50 CVs and rank the top 10" is not simply a deployer of a GPAI model. Under Article 28(1)(b) of the EU AI Act, if you use a general-purpose AI model and deploy it specifically for a high-risk use case listed in Annex III — such as candidate evaluation — you may become the provider of the resulting high-risk AI system.

This matters because providers face significantly heavier obligations than deployers: technical documentation, a risk management system, a conformity assessment, logging capability built into the system, and potentially EU database registration. OpenAI put ChatGPT on the market as a general-purpose tool, not as a recruitment-decision system. If you repurpose it for that, the Act treats the resulting system as your product.

Practical guidance for GPAI-assisted hiring:

  • Never use AI output as the sole or primary basis for a hiring or rejection decision
  • Document the human review step — a hiring manager must see every CV and exercise independent judgement
  • Disclose to candidates that AI tools are used in the screening process
  • Keep records of what prompts were used and what decisions were made from the output

Common HR tools: high-risk or not?

This table is illustrative — the actual risk classification of any tool depends on whether and how AI features are used, not the vendor brand. Always confirm with your provider whether their tool uses AI for candidate evaluation or employee decision-making.

Workday (with AI talent matching)HIGH-RISK

AI ranking of candidates or employees for promotion triggers Annex III 4(a)/(b).

You are a deployer. Review Annex III deployer obligations below.

SAP SuccessFactors (AI features)HIGH-RISK

AI-assisted performance scoring and succession planning falls under Annex III 4(b).

You are a deployer. Obtain provider documentation and implement oversight.

HireVue or similar video interview AIHIGH-RISK

Evaluating candidates via AI analysis of video responses is explicit Annex III 4(a).

You are a deployer. Must notify candidates, ensure human review, keep logs.

LinkedIn Talent Insights / AI matchingREVIEW REQUIRED

LinkedIn is the provider. If you use AI-ranked shortlists to make final hire/no-hire calls, you have deployer obligations.

Ensure a human reviews all shortlists. Do not rely solely on AI-ranked results.

ChatGPT / Copilot used by recruiters to screen CVsCAUTION

You may become the effective provider (Article 28). See the GPAI section below.

Do not make hiring decisions based solely on AI output. Add human review.

Standard ATS (no AI features)NOT HIGH-RISK

A database of applications with no AI ranking or scoring is not in scope.

No Annex III obligations. Check if you layer any AI tools on top.

Calendly-style interview schedulerNOT HIGH-RISK

Availability matching with no candidate evaluation.

None required under EU AI Act. Ordinary data protection rules apply.

Already banned: emotion recognition at work (since February 2025)

Article 5(1)(f) of the EU AI Act prohibits the use of AI systems that infer emotions of natural persons in the context of the workplace and educational institutions. This is not a future obligation — it has been enforceable since February 2, 2025.

If your HR tech stack includes any of the following, review it immediately:

  • AI tools that analyse facial expressions, vocal tone, or body language of employees or job candidates to infer mood, engagement, stress, or personality
  • Video interview platforms with "emotion AI" or "behavioural analysis" features that score candidate affect
  • Wellbeing monitoring tools that infer employee mental state from biometric or behavioural data

Using a prohibited AI system today — even a commercial product from a reputable vendor — exposes you to Tier 1 fines (up to €35M or 7% of global turnover). The vendor's own compliance does not transfer to you.

Your August 2026 action plan for HR teams

1

Audit your HR tech stack

List every software tool used in recruitment, performance management, task allocation, and employee monitoring. Note whether each has AI features that evaluate or rank people.

2

Check for prohibited tools

For any tool that analyses emotions, facial expressions, or mood of employees or candidates: stop using it now or remove the AI feature. This obligation is already in effect.

3

Identify your high-risk tools

Any tool with AI-powered CV ranking, candidate scoring, interview analysis, performance scoring, or task allocation AI is high-risk under Annex III. Contact your vendor to confirm whether their AI features are covered by the Act and to request their technical documentation and instructions for use.

4

Implement and document human oversight

For each high-risk HR tool, designate a named individual responsible for reviewing AI outputs before decisions are made. Document this in your HR procedures: "AI output is a recommendation; [role] reviews and records their independent decision."

5

Add candidate and employee notifications

Update your job advertisement template, application form, or privacy notice to disclose that AI tools are used in recruitment. Update employee handbooks or contracts to disclose use of AI in performance management or scheduling.

6

Set up log retention

Confirm with your vendor that their tool generates logs. If so, ensure you retain them for at least 6 months. If not, implement your own record-keeping: for each hiring decision, log what AI tools were used, what the AI output was, and what the human reviewer decided.

Frequently asked questions

Our ATS shortlists candidates but a human always makes the final call. Are we still high-risk?

Yes. Annex III 4(a) covers AI systems that screen or filter applications — the AI does not need to make the final decision. If AI produces the shortlist a human then reviews, you are deploying a high-risk AI system. The human review is good practice and required, but it does not remove the classification. You still have all six deployer obligations.

We use ChatGPT to help score CVs in a spreadsheet. Are we a provider or a deployer?

This is one of the EU AI Act's trickiest grey areas. OpenAI is the provider of the GPAI model. But when you build a workflow (even an informal one) that uses that model to make employment decisions, you may become the "provider" of the resulting HR AI system under Article 28(1)(b). This means provider-level obligations could apply to you — including technical documentation, conformity assessment, and registration. At minimum, treat yourself as a deployer with a human reviewing every AI output, and do not use AI-generated scores as the sole basis for any hiring decision.

Does the AI Act apply to UK businesses?

Yes, if you process data or make decisions affecting EU residents — for example, hiring EU-based employees or screening EU candidates for remote roles. The EU AI Act has extraterritorial reach similar to GDPR: it covers AI systems that are placed on the EU market or whose outputs are used within the EU, regardless of where the provider or deployer is based.

Do we need to do a Fundamental Rights Impact Assessment (FRIA)?

Under Article 27, a FRIA is required for public bodies, and for private organisations deploying high-risk AI systems under an obligation stemming from Union or national law (such as regulated employment services, financial institutions hiring for regulated roles, or public-sector contract holders). Most private SMBs using commercial HR software do not need a formal FRIA — but you do need to document your human oversight process and have a proportionate risk assessment on file.

Our HR software vendor says their tool is "EU AI Act compliant". Does that mean we have no obligations?

No. Provider compliance and deployer compliance are separate. Even if your vendor has completed all provider-side obligations (technical documentation, conformity assessment, CE marking), you still have your own deployer obligations: implementing human oversight, notifying workers, keeping logs, and using the system only as intended. "Our vendor is compliant" does not satisfy your obligations.

We only have 12 employees. Does this still apply to us?

The EU AI Act does not have a headcount exemption for deployers. Micro-enterprises and SMEs get proportional fines and some regulatory support (Article 55), but the underlying obligations apply regardless of company size. The good news: if you only use basic commercial HR software with no AI ranking features, you are probably not deploying a high-risk AI system at all.

What about AI tools for wellbeing or mental health screening at work?

Proceed with extreme caution. Any AI that analyses emotional states of employees — including stress, burnout, or mood — in a workplace setting is likely prohibited under Article 5(1)(f), which bans emotion recognition in work and educational settings. This is already enforceable since February 2, 2025, not August 2026. If your HR tech stack includes any employee "wellbeing AI" with emotion or sentiment analysis, review it against the Prohibited Practices guide immediately.

When does the August 2026 deadline actually apply?

The full high-risk AI system obligations under Chapter III of the EU AI Act apply from August 2, 2026. This covers deployer obligations including human oversight documentation, worker notification, and log retention. Note that two obligations are already in effect earlier: the Prohibited Practices (including workplace emotion recognition) have been enforceable since February 2, 2025, and AI literacy obligations (Article 4) have also applied since February 2025.

Not sure if your HR tool is high-risk?

Use the free EU AI Act risk classifier. Answer 5 questions about your AI system and get a classification — Prohibited, High-Risk, Limited Risk, or Minimal Risk — with your specific obligations listed.

Classify your HR AI system — free

Related guides