ISHIGHRISK AI
Sector guide

Recruitment and HR AI under the AI Act

Annex III point 4 covers job ads, CV filtering, interviews, promotion and monitoring. Which HR tools are high-risk and which clear the derogation.

Reviewed 22 July 2026Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Annex III point 4 makes almost the entire hiring and worker-management stack high-risk: targeted job advertising, application filtering, candidate evaluation, promotion and termination, task allocation, and performance and behaviour monitoring are all named in the text. The Article 6(3) derogation is far narrower than vendor marketing suggests, and any system that profiles natural persons is high-risk with no way out. High-risk obligations apply from 2 December 2027, but emotion recognition in the workplace has been prohibited outright since 2 February 2025.

Annex III point 4: the six employment uses that make AI high-risk

Annex III point 4 covers employment, worker management and access to self-employment. It is the entry on the high-risk list that catches the most ordinary business software, because it does not describe exotic technology: it describes what an applicant tracking system, an assessment platform and a workforce analytics dashboard already do. You do not have to build AI to be caught. Buying a product with a matching score in it puts a high-risk system inside your hiring process, and from 2 December 2027 the full Chapter III obligation stack attaches to it.

The point has two limbs. Point 4(a) is the hiring side: systems intended for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates. Point 4(b) is the in-role side: systems used to make decisions affecting the terms of work-related relationships, promotion and termination, to allocate tasks based on individual behaviour or personal traits, and to monitor and evaluate performance and behaviour. Between them they cover a person from the advert they never saw to the exit interview.

HR use caseAnnex III limbHigh-risk?Why
Targeted job advertisingPoint 4(a)YesIt decides who is shown the vacancy. A person excluded from the audience never gets the chance to apply, so the harm lands before any application exists.
Application filtering and CV screeningPoint 4(a)YesAnalysing and filtering job applications is named in the text. Volume does not soften it: removing people before a human reads them is a decision about access to work.
Candidate evaluation, scoring and rankingPoint 4(a)YesEvaluation of candidates is named. Ranking is evaluation expressed as an order, and it also engages the profiling bar in Article 6(3).
Promotion and termination decisionsPoint 4(b)YesThese change or end the work relationship itself. A system that recommends who goes on a redundancy list is inside the limb even if a manager signs off.
Task allocation by behaviour or personal traitsPoint 4(b)YesAllocation driven by individual characteristics, not by a neutral queue. Shift and route assignment engines in logistics and gig work sit here.
Performance and behaviour monitoringPoint 4(b)YesMonitoring and evaluating workers is named. Productivity scoring, call quality scoring and activity tracking with an inferred rating all qualify.

Two things follow. First, the classification attaches to the function, not the vendor label, so a single ATS can contain one non-high-risk module and three high-risk ones. Second, none of these are edge cases invented by regulators: they are the standard feature list of the category. If you are running any modern recruitment software, assume you are inside the Annex III high-risk classification until you can write down why you are not.

Emotion recognition at work is prohibited, not merely high-risk

Before you classify anything, screen for the hard bans. Article 5(f) prohibits AI systems that infer emotions of natural persons in the area of the workplace and in education, with narrow exceptions for medical or safety reasons. Article 5(g) separately prohibits biometric categorisation that infers sensitive traits such as race, political opinion, religion or sexual orientation. Both have applied since 2 February 2025, and both sit in the top penalty tier of 35,000,000 EUR or 7 percent of total worldwide annual turnover.

This matters in recruitment because any video-interview feature that scores enthusiasm, confidence or engagement from face or voice is inferring emotional state. That is not a compliance project with a 2027 deadline, it is a practice to stop now. Assessing the substance of what a candidate writes or says against a documented competency framework remains a lawful high-risk activity. Inferring how they felt while saying it does not.

The prohibitions do not wait for 2027. The Digital Omnibus moved the high-risk regime for standalone Annex III systems to 2 December 2027. It did not postpone the prohibitions already in force since 2 February 2025. If an interview tool in your stack scores emotional state, the exposure is live now, at the highest tier, and the Article 4 AI-literacy duty on the HR team using it has also applied since 2 February 2025.

Applying the Article 6(3) derogation to real HR tooling

Article 6(3) is the only off-ramp, and it is a two-part test that is easy to quote at half length. The system must not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making. And it must meet at least one of four conditions: (a) it performs a narrow procedural task; (b) it improves the result of a previously completed human activity; (c) it detects decision-making patterns or deviations from prior patterns and does not replace or influence the previously completed human assessment without proper human review; or (d) it performs a preparatory task to an assessment relevant to an Annex III use case. Failing the first part ends the analysis regardless of the four conditions.

HR toolDerogation arguedHolds up?Reasoning
CV parser that lifts dates, job titles and contact details verbatim into fields(a) narrow procedural taskPlausibleIt transcribes, it does not judge. The moment it decides what counts as a relevant skill or infers seniority, the extraction has become evaluation and the argument collapses.
Interview scheduler matching calendar availability(a) narrow procedural taskPlausibleThe decision it makes is about time slots, not about people. Nobody is selected out of the process by it.
Job-ad checker flagging non-inclusive wording to the writer(b) improving a completed human activityPlausibleA human wrote the advert; the tool improves the text. No candidate is assessed, and no audience is selected.
Shortlisting tool that returns 20 of 200 applicants to a recruiter(d) preparatory taskNoThe 180 are gone and no human will ever read them. That is material influence on the outcome, which fails the first part of the test before condition (d) is reached.
Matching engine scoring candidates against a role profile(a) or (d)NoScoring people is profiling, and profiling is an absolute bar. Human review of the ranked list does not rescue it.
Attrition-risk model flagging teams with unusual leaver patterns(c) detecting patterns and deviationsDependsDefensible at team or site level. Once it produces a per-employee flight risk score attached to a named person, it profiles and the bar applies.

The common over-claim is to call filtering procedural. It is not. A narrow procedural task is one where the output does not turn on a judgement about the person: converting a date format, deduplicating two applications from the same candidate, routing a form to the right hiring manager. As soon as the system decides which humans are worth a human, it is materially influencing the outcome, and the significant-risk gate closes. The deeper treatment of all four conditions and how they are argued sits on the Article 6(3) derogation page.

Claiming the derogation is not a way to make paperwork disappear. Article 6(4) requires the provider to document the assessment before placing the system on the market, and under the Digital Omnibus a system self-assessed as non-high-risk must still be registered in the EU database. The Commission proposed dropping that registration duty; it did not survive negotiations and was reinstated in simplified form. So the realistic comparison is not obligations versus nothing. It is the full Chapter III stack versus a documented, registered, defensible assessment you have to stand behind.

Why profiling forecloses the derogation for most AI hiring tools

Article 6(3) ends with an override that does more work in recruitment than anywhere else on the Annex III list: a system performing profiling of natural persons is always high-risk. There is no balancing, no significant-risk assessment, no human-in-the-loop cure. If the system profiles, the four conditions are irrelevant.

Be blunt about what that means for the market. Recruitment tooling that ranks or scores people is the product category. Fit scores, match percentages, skill graphs inferred from a CV, culture-add ratings, stack-ranked shortlists, predicted performance, predicted retention: each of these evaluates personal aspects of a person in order to predict something about them. That is profiling in ordinary usage, and the conservative reading is that it triggers the override. Any vendor claiming Article 6(3) for a product whose headline feature is a candidate score is asking you to bet your classification on an argument the text does not obviously support.

There is no authoritative worked example to lean on. The Commission missed its February 2026 statutory deadline for the Article 6 high-risk classification guidelines, so there is no official set of accepted derogation cases to point at. Until that changes, the defensible posture is the conservative one: document thoroughly, register, and assume profiling forecloses the off-ramp. Run your own tools through the free seven-stage triage classifier and keep the dated output as the start of the record.

Who the provider is in a typical HR stack

In almost every HR deployment the roles are the same. The ATS or assessment vendor developed the system and put it on the market under its own name, so it is the provider and carries the Article 16 obligation set. The employer bought it and uses it under its own authority, so the employer is the deployer. One entity can hold several roles at once.

ActorUsual roleWhat it carries
ATS or assessment vendorProviderArticles 9 to 15, Annex IV technical documentation, conformity assessment under Article 43, the EU declaration of conformity under Article 47 and registration under Article 49.
Employer running the tool on its own vacanciesDeployerUse in line with the instructions, human oversight staffed by competent people, input data control, log retention, worker information, and the Article 4 AI-literacy duty.
Recruitment agency screening for clientsDeployerThe same deployer duties. Acting for someone else does not move the obligation to the client.
Reseller placing a non-EU platform on the EU marketImporter or distributorVerification duties, plus provider status the moment it rebrands under Article 25.

The mistake to avoid is assuming vendor compliance covers you. It does not. The provider owes the conformity work; the deployer owes its own duties and answers for them separately to a national market surveillance authority. A CE-marked ATS used without meaningful human oversight, on input data the employer chose and the vendor never anticipated, is a deployer failure regardless of how good the vendor documentation is.

How an employer becomes the provider under Article 25

Article 25 converts a deployer into a provider, inheriting the entire Article 16 obligation set, on any of three triggers. All three are routine in HR.

Putting your name or trademark on it

A white-labelled careers portal is the clearest example. If the vendor system is presented to candidates as your own branded hiring product, you have put your name on a high-risk system already on the market and you are its provider. Nothing about the underlying model changed. The label did.

Substantially modifying it

Article 3(23) defines a substantial modification as a post-market change not foreseen in the initial conformity assessment that affects compliance or changes the intended purpose. Retraining the ranking model on your own hiring history, adding your own scoring layer on top of the vendor output, or wiring in an internal competency taxonomy the vendor never assessed are all candidates. If the system stays high-risk after the change, you are the provider of it.

Changing the intended purpose so it becomes high-risk

This one catches employers who never bought an HR tool at all. Take a general-purpose AI system or a generic analytics product, point it at promotion recommendations or performance ratings, and you have modified the intended purpose of a system so that it becomes high-risk. You are the provider, with no vendor documentation to inherit and no conformity assessment in existence. Prompting a general-purpose model to rank a folder of CVs is the same move at smaller scale. The mechanics of all three triggers, and the contract language that keeps you out of them, are set out on the provider and deployer roles page.

What to fix in HR procurement before 2 December 2027

Standalone Annex III obligations apply from 2 December 2027, a seventeen-month extension from the original 2 August 2026 date. That is not comfortable headroom. Multi-year ATS agreements signed this quarter will still be live on the day the regime bites, and conformity assessment is not something a vendor completes in a sprint.

2 Feb 2025Article 5 prohibitions, including workplace emotion recognition, and the Article 4 AI-literacy duty. Already binding.
2 Aug 2025Penalties enforceable. Article 99 tiers are live against the duties already in force.
2 Dec 2027High-risk obligations apply to standalone Annex III systems, which is where recruitment and worker-management AI sits.

Six asks that belong in the contract and the vendor questionnaire now:

  1. A written intended purpose. Get the vendor statement of intended purpose in the agreement, not the brochure. It is the reference point against which any later change of yours is judged substantial under Art 3(23).
  2. A per-module classification. Ask which modules the vendor classifies as high-risk and which it claims under Art 6(3), and ask for the documented assessment behind each claim. Under Art 6(4) it must exist before market placement, so there is no good reason it cannot be shown.
  3. A commitment to conformity assessment and registration. A dated commitment to complete the assessment, issue the EU declaration of conformity and register under Art 49 ahead of 2 December 2027, with the Annex IV technical documentation available to you on request.
  4. Notification of substantial modifications. Both directions. The vendor tells you when it changes the system; you tell the vendor before you change it, so nobody discovers the Article 25 flip during an inspection.
  5. A branding clause. State explicitly whether the vendor name stays visible. If your brand goes on the candidate-facing product, price the provider obligations into the decision, because you are taking them on.
  6. Oversight that is real. Human oversight has to be a person with the authority, time and information to overturn the output. A recruiter who reviews a ranked list of 20 and cannot see the 180 that were removed is not oversight, and it will not save a derogation argument either.

Alongside procurement, build the inventory. Every AI-assisted step from advert to exit, the vendor, the module, the Annex III limb it touches, the role you hold, and whether a derogation is being claimed by anyone. That inventory is the evidence a market surveillance authority will ask for. Getting the classification wrong is expensive, with the detail on the penalties and enforcement page. The primary text is on EUR-Lex.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Is an applicant tracking system high-risk under the EU AI Act?

If it analyses, filters, scores or ranks applicants, yes. Annex III point 4 names the analysis and filtering of job applications and the evaluation of candidates as high-risk uses, so an ATS with matching or ranking built in sits squarely inside the regime. An ATS that only stores records, moves candidates between stages a human selects, and sends templated email is not performing an Annex III function at all. The distinction is not the product category, it is the feature set: ask the vendor which modules infer, score or rank, and treat those modules as the system being classified.

Does the EU AI Act ban AI in recruitment?

No. Recruitment AI is high-risk, not prohibited, which means it is allowed if it meets the Chapter III requirements: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment and registration. Two hard bans touch hiring. Article 5(f) prohibits emotion recognition in the area of the workplace and in education, with narrow medical and safety exceptions, and Article 5(g) prohibits biometric categorisation that infers sensitive traits such as race, political opinion, religion or sexual orientation. The conservative reading is that a recruitment process forms part of that workplace context, so an AI that infers a candidate emotional state from a video interview is not a compliance project, it is off the table.

When do EU AI Act rules for HR and recruitment apply?

The high-risk obligations for standalone Annex III systems apply from 2 December 2027, seventeen months later than the original 2 August 2026 date, after the Digital Omnibus amendment. Two things already bind you: the Article 5 prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025, and penalties have been enforceable since 2 August 2025. The 2027 date is not a reason to wait. Conformity assessment, Annex IV documentation and registration take a full development cycle, and ATS contracts signed today will still be running then.

Can a CV parser use the Article 6(3) derogation?

Possibly, if it genuinely only extracts. A parser that lifts dates, job titles, employer names and contact details verbatim into structured fields is a strong candidate for the narrow procedural task condition, because it makes no judgement about the person. The moment it decides what counts as a relevant skill, infers seniority, or normalises experience into a comparable score, it is evaluating, and evaluation is not procedural. The provider must document the assessment before placing the system on the market under Article 6(4), and register the system in the EU database even when the derogation is claimed.

Is my company the provider or the deployer of our recruitment AI?

In a typical HR stack the ATS or assessment vendor is the provider and the employer is the deployer. That split holds only while you use the tool as supplied, for the intended purpose the vendor documented. Article 25 flips you into provider status if you put your own name or trademark on the system, make a substantial modification that keeps it high-risk, or change the intended purpose so that a system becomes high-risk. Retraining the ranking model on your own hiring history, or pointing a general workforce analytics tool at promotion decisions, are two flips employers trip on.

Can we use AI to analyse candidate emotions in video interviews?

No. Article 5(f) prohibits AI systems that infer emotions of natural persons in the workplace, with narrow exceptions for medical and safety purposes, and that prohibition has applied since 2 February 2025. It sits in the highest penalty tier: up to 35,000,000 EUR or 7 percent of total worldwide annual turnover. Biometric categorisation that infers sensitive traits is separately prohibited under Article 5(g). Assessing what a candidate says, in text, against a documented competency framework is a high-risk activity you can run compliantly. Reading their face is not.

What are the fines for non-compliant AI hiring tools?

Breaching the high-risk regime sits in the middle Article 99 tier: up to 15,000,000 EUR or 3 percent of total worldwide annual turnover, whichever is higher for a company. SMEs and start-ups pay the lower of the two figures under Article 99(6). Using a prohibited practice, such as workplace emotion recognition, sits in the top tier at 35,000,000 EUR or 7 percent. Supplying incorrect or misleading information to a market surveillance authority carries 7,500,000 EUR or 1 percent. Penalties have been enforceable since 2 August 2025.

This page is triage guidance, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, reviewed 22 July 2026, when the Omnibus was adopted and signed but awaiting Official Journal publication. Final classification for ambiguous cases needs qualified counsel.