Annex III point 4: the six employment uses that make AI high-risk
Annex III point 4 covers employment, worker management and access to self-employment. It is the entry on the high-risk list that catches the most ordinary business software, because it does not describe exotic technology: it describes what an applicant tracking system, an assessment platform and a workforce analytics dashboard already do. You do not have to build AI to be caught. Buying a product with a matching score in it puts a high-risk system inside your hiring process, and from 2 December 2027 the full Chapter III obligation stack attaches to it.
The point has two limbs. Point 4(a) is the hiring side: systems intended for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates. Point 4(b) is the in-role side: systems used to make decisions affecting the terms of work-related relationships, promotion and termination, to allocate tasks based on individual behaviour or personal traits, and to monitor and evaluate performance and behaviour. Between them they cover a person from the advert they never saw to the exit interview.
| HR use case | Annex III limb | High-risk? | Why |
|---|---|---|---|
| Targeted job advertising | Point 4(a) | Yes | It decides who is shown the vacancy. A person excluded from the audience never gets the chance to apply, so the harm lands before any application exists. |
| Application filtering and CV screening | Point 4(a) | Yes | Analysing and filtering job applications is named in the text. Volume does not soften it: removing people before a human reads them is a decision about access to work. |
| Candidate evaluation, scoring and ranking | Point 4(a) | Yes | Evaluation of candidates is named. Ranking is evaluation expressed as an order, and it also engages the profiling bar in Article 6(3). |
| Promotion and termination decisions | Point 4(b) | Yes | These change or end the work relationship itself. A system that recommends who goes on a redundancy list is inside the limb even if a manager signs off. |
| Task allocation by behaviour or personal traits | Point 4(b) | Yes | Allocation driven by individual characteristics, not by a neutral queue. Shift and route assignment engines in logistics and gig work sit here. |
| Performance and behaviour monitoring | Point 4(b) | Yes | Monitoring and evaluating workers is named. Productivity scoring, call quality scoring and activity tracking with an inferred rating all qualify. |
Two things follow. First, the classification attaches to the function, not the vendor label, so a single ATS can contain one non-high-risk module and three high-risk ones. Second, none of these are edge cases invented by regulators: they are the standard feature list of the category. If you are running any modern recruitment software, assume you are inside the Annex III high-risk classification until you can write down why you are not.
Emotion recognition at work is prohibited, not merely high-risk
Before you classify anything, screen for the hard bans. Article 5(f) prohibits AI systems that infer emotions of natural persons in the area of the workplace and in education, with narrow exceptions for medical or safety reasons. Article 5(g) separately prohibits biometric categorisation that infers sensitive traits such as race, political opinion, religion or sexual orientation. Both have applied since 2 February 2025, and both sit in the top penalty tier of 35,000,000 EUR or 7 percent of total worldwide annual turnover.
This matters in recruitment because any video-interview feature that scores enthusiasm, confidence or engagement from face or voice is inferring emotional state. That is not a compliance project with a 2027 deadline, it is a practice to stop now. Assessing the substance of what a candidate writes or says against a documented competency framework remains a lawful high-risk activity. Inferring how they felt while saying it does not.
The prohibitions do not wait for 2027. The Digital Omnibus moved the high-risk regime for standalone Annex III systems to 2 December 2027. It did not postpone the prohibitions already in force since 2 February 2025. If an interview tool in your stack scores emotional state, the exposure is live now, at the highest tier, and the Article 4 AI-literacy duty on the HR team using it has also applied since 2 February 2025.
Applying the Article 6(3) derogation to real HR tooling
Article 6(3) is the only off-ramp, and it is a two-part test that is easy to quote at half length. The system must not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making. And it must meet at least one of four conditions: (a) it performs a narrow procedural task; (b) it improves the result of a previously completed human activity; (c) it detects decision-making patterns or deviations from prior patterns and does not replace or influence the previously completed human assessment without proper human review; or (d) it performs a preparatory task to an assessment relevant to an Annex III use case. Failing the first part ends the analysis regardless of the four conditions.
| HR tool | Derogation argued | Holds up? | Reasoning |
|---|---|---|---|
| CV parser that lifts dates, job titles and contact details verbatim into fields | (a) narrow procedural task | Plausible | It transcribes, it does not judge. The moment it decides what counts as a relevant skill or infers seniority, the extraction has become evaluation and the argument collapses. |
| Interview scheduler matching calendar availability | (a) narrow procedural task | Plausible | The decision it makes is about time slots, not about people. Nobody is selected out of the process by it. |
| Job-ad checker flagging non-inclusive wording to the writer | (b) improving a completed human activity | Plausible | A human wrote the advert; the tool improves the text. No candidate is assessed, and no audience is selected. |
| Shortlisting tool that returns 20 of 200 applicants to a recruiter | (d) preparatory task | No | The 180 are gone and no human will ever read them. That is material influence on the outcome, which fails the first part of the test before condition (d) is reached. |
| Matching engine scoring candidates against a role profile | (a) or (d) | No | Scoring people is profiling, and profiling is an absolute bar. Human review of the ranked list does not rescue it. |
| Attrition-risk model flagging teams with unusual leaver patterns | (c) detecting patterns and deviations | Depends | Defensible at team or site level. Once it produces a per-employee flight risk score attached to a named person, it profiles and the bar applies. |
The common over-claim is to call filtering procedural. It is not. A narrow procedural task is one where the output does not turn on a judgement about the person: converting a date format, deduplicating two applications from the same candidate, routing a form to the right hiring manager. As soon as the system decides which humans are worth a human, it is materially influencing the outcome, and the significant-risk gate closes. The deeper treatment of all four conditions and how they are argued sits on the Article 6(3) derogation page.
Claiming the derogation is not a way to make paperwork disappear. Article 6(4) requires the provider to document the assessment before placing the system on the market, and under the Digital Omnibus a system self-assessed as non-high-risk must still be registered in the EU database. The Commission proposed dropping that registration duty; it did not survive negotiations and was reinstated in simplified form. So the realistic comparison is not obligations versus nothing. It is the full Chapter III stack versus a documented, registered, defensible assessment you have to stand behind.
Why profiling forecloses the derogation for most AI hiring tools
Article 6(3) ends with an override that does more work in recruitment than anywhere else on the Annex III list: a system performing profiling of natural persons is always high-risk. There is no balancing, no significant-risk assessment, no human-in-the-loop cure. If the system profiles, the four conditions are irrelevant.
Be blunt about what that means for the market. Recruitment tooling that ranks or scores people is the product category. Fit scores, match percentages, skill graphs inferred from a CV, culture-add ratings, stack-ranked shortlists, predicted performance, predicted retention: each of these evaluates personal aspects of a person in order to predict something about them. That is profiling in ordinary usage, and the conservative reading is that it triggers the override. Any vendor claiming Article 6(3) for a product whose headline feature is a candidate score is asking you to bet your classification on an argument the text does not obviously support.
There is no authoritative worked example to lean on. The Commission missed its February 2026 statutory deadline for the Article 6 high-risk classification guidelines, so there is no official set of accepted derogation cases to point at. Until that changes, the defensible posture is the conservative one: document thoroughly, register, and assume profiling forecloses the off-ramp. Run your own tools through the free seven-stage triage classifier and keep the dated output as the start of the record.
Who the provider is in a typical HR stack
In almost every HR deployment the roles are the same. The ATS or assessment vendor developed the system and put it on the market under its own name, so it is the provider and carries the Article 16 obligation set. The employer bought it and uses it under its own authority, so the employer is the deployer. One entity can hold several roles at once.
| Actor | Usual role | What it carries |
|---|---|---|
| ATS or assessment vendor | Provider | Articles 9 to 15, Annex IV technical documentation, conformity assessment under Article 43, the EU declaration of conformity under Article 47 and registration under Article 49. |
| Employer running the tool on its own vacancies | Deployer | Use in line with the instructions, human oversight staffed by competent people, input data control, log retention, worker information, and the Article 4 AI-literacy duty. |
| Recruitment agency screening for clients | Deployer | The same deployer duties. Acting for someone else does not move the obligation to the client. |
| Reseller placing a non-EU platform on the EU market | Importer or distributor | Verification duties, plus provider status the moment it rebrands under Article 25. |
The mistake to avoid is assuming vendor compliance covers you. It does not. The provider owes the conformity work; the deployer owes its own duties and answers for them separately to a national market surveillance authority. A CE-marked ATS used without meaningful human oversight, on input data the employer chose and the vendor never anticipated, is a deployer failure regardless of how good the vendor documentation is.
How an employer becomes the provider under Article 25
Article 25 converts a deployer into a provider, inheriting the entire Article 16 obligation set, on any of three triggers. All three are routine in HR.
Putting your name or trademark on it
A white-labelled careers portal is the clearest example. If the vendor system is presented to candidates as your own branded hiring product, you have put your name on a high-risk system already on the market and you are its provider. Nothing about the underlying model changed. The label did.
Substantially modifying it
Article 3(23) defines a substantial modification as a post-market change not foreseen in the initial conformity assessment that affects compliance or changes the intended purpose. Retraining the ranking model on your own hiring history, adding your own scoring layer on top of the vendor output, or wiring in an internal competency taxonomy the vendor never assessed are all candidates. If the system stays high-risk after the change, you are the provider of it.
Changing the intended purpose so it becomes high-risk
This one catches employers who never bought an HR tool at all. Take a general-purpose AI system or a generic analytics product, point it at promotion recommendations or performance ratings, and you have modified the intended purpose of a system so that it becomes high-risk. You are the provider, with no vendor documentation to inherit and no conformity assessment in existence. Prompting a general-purpose model to rank a folder of CVs is the same move at smaller scale. The mechanics of all three triggers, and the contract language that keeps you out of them, are set out on the provider and deployer roles page.
What to fix in HR procurement before 2 December 2027
Standalone Annex III obligations apply from 2 December 2027, a seventeen-month extension from the original 2 August 2026 date. That is not comfortable headroom. Multi-year ATS agreements signed this quarter will still be live on the day the regime bites, and conformity assessment is not something a vendor completes in a sprint.
Six asks that belong in the contract and the vendor questionnaire now:
- A written intended purpose. Get the vendor statement of intended purpose in the agreement, not the brochure. It is the reference point against which any later change of yours is judged substantial under Art 3(23).
- A per-module classification. Ask which modules the vendor classifies as high-risk and which it claims under Art 6(3), and ask for the documented assessment behind each claim. Under Art 6(4) it must exist before market placement, so there is no good reason it cannot be shown.
- A commitment to conformity assessment and registration. A dated commitment to complete the assessment, issue the EU declaration of conformity and register under Art 49 ahead of 2 December 2027, with the Annex IV technical documentation available to you on request.
- Notification of substantial modifications. Both directions. The vendor tells you when it changes the system; you tell the vendor before you change it, so nobody discovers the Article 25 flip during an inspection.
- A branding clause. State explicitly whether the vendor name stays visible. If your brand goes on the candidate-facing product, price the provider obligations into the decision, because you are taking them on.
- Oversight that is real. Human oversight has to be a person with the authority, time and information to overturn the output. A recruiter who reviews a ranked list of 20 and cannot see the 180 that were removed is not oversight, and it will not save a derogation argument either.
Alongside procurement, build the inventory. Every AI-assisted step from advert to exit, the vendor, the module, the Annex III limb it touches, the role you hold, and whether a derogation is being claimed by anyone. That inventory is the evidence a market surveillance authority will ask for. Getting the classification wrong is expensive, with the detail on the penalties and enforcement page. The primary text is on EUR-Lex.