Guides 16 min read

AI in Hiring: The Compliance Minefield Most Companies Are Ignoring

If your company uses AI to screen CVs, rank candidates, or automate interviews, you're operating a high-risk AI system under the EU AI Act. Most HR departments don't know this yet. Here's what must change before August 2026.

By Sarah Jenkins · Published

The HR Department's Blind Spot

Across Europe, thousands of companies have quietly adopted AI tools in their recruitment pipelines. CV screening algorithms, video interview analysis, psychometric profiling, automated candidate ranking — these tools promise efficiency and objectivity. What most HR teams don't realize: every single one of these tools is classified as high-risk under the EU AI Act.

This isn't a gray area. Annex III, Section 4 of the AI Act explicitly lists AI systems used in "employment, workers management and access to self-employment" as high-risk. This covers recruitment, screening, hiring decisions, task allocation, performance monitoring, and promotion or termination decisions influenced by AI.

The deadline for full compliance is August 2, 2026. After that, operating these systems without meeting the AI Act's requirements means fines of up to €15 million or 3% of global turnover.

What Qualifies as "AI in Hiring"?

The scope is broader than most companies expect. If any of these tools are used anywhere in your recruitment or workforce management process, they are high-risk:

Recruitment and Selection

  • CV/resume screening tools that filter, rank, or score applicants (e.g., HireVue, Pymetrics, Textio)
  • Automated interview platforms that analyze speech patterns, facial expressions, or word choice
  • Candidate matching algorithms that recommend candidates based on profile data
  • Chatbot-based screening that asks pre-qualifying questions and filters candidates
  • Psychometric or game-based assessments that use AI to evaluate cognitive abilities or personality traits

Workforce Management

  • Performance monitoring systems that use AI to track productivity, flag underperformance, or recommend disciplinary action
  • Task allocation algorithms (especially in gig economy platforms)
  • Promotion prediction models that assess employee potential
  • Workforce planning tools that predict attrition or recommend layoff targets

The 7 Requirements You Must Meet

For each high-risk AI system used in hiring or workforce management, the AI Act requires all of the following:

1. Risk Management System (Article 9)

You must implement a continuous risk management process that identifies and mitigates risks throughout the AI system's lifecycle. For hiring AI, this means documenting risks such as discrimination based on gender, ethnicity, age, disability, or socioeconomic background; proxy discrimination through correlated features (e.g., postcode, university name, gaps in employment); and feedback loops that reinforce historical hiring biases.

2. Data Governance (Article 10)

Training data must be relevant, representative, and as free of errors as possible. For hiring AI, this means auditing training data for demographic representation, documenting data sources and any known biases, and ensuring GDPR-compliant data processing for candidate information.

3. Technical Documentation (Article 11)

Detailed technical documentation must be maintained before the system is placed on the market or put into service. This includes the system's intended purpose, design decisions, performance metrics, and known limitations.

4. Record-Keeping and Logging (Article 12)

The system must automatically log its operations to enable traceability. For hiring AI, this means keeping records of every candidate decision, the factors that influenced it, and the confidence scores involved.

5. Transparency and Information (Article 13)

Deployers must provide candidates with clear information that an AI system is being used in the hiring process. Candidates have the right to know that AI is being used to assess their application, what the AI evaluates and how it influences decisions, and how to request human review of an AI-assisted decision.

6. Human Oversight (Article 14)

This is the big one for HR. The AI Act requires that high-risk systems are designed to allow effective human oversight. Critically, this means a qualified human must be able to understand the system's outputs, a human must be able to override or reverse any AI-assisted decision, and the human overseer must have the authority and competence to intervene — not just a rubber-stamp role. "Human-in-the-loop" is not enough if the human simply approves whatever the AI recommends.

7. Accuracy, Robustness, and Cybersecurity (Article 15)

The system must achieve appropriate levels of accuracy and be resilient to errors and adversarial attacks. For hiring AI, this includes regular accuracy testing across different demographic groups, protection against adversarial inputs (e.g., resume keyword stuffing), and cybersecurity measures to protect candidate data.

The Vendor Trap

Many companies assume their AI vendor handles compliance. This is wrong. Under the AI Act, the deployer (your company) has independent obligations that cannot be outsourced to the vendor. Even if your vendor provides an "AI Act compliant" tool, you are still responsible for conducting a Fundamental Rights Impact Assessment (FRIA) before deployment, ensuring adequate human oversight within your organization, informing candidates and worker representatives about AI use, registering the high-risk system in the EU database, and maintaining your own logs and documentation.

5-Step Action Plan for HR Leaders

Step 1: AI Inventory (Do This Week)

List every AI or automated decision-making tool used in recruitment, onboarding, performance management, promotion, and termination. Include tools embedded in your ATS (Applicant Tracking System), HRIS, and any standalone assessment platforms.

Step 2: Vendor Due Diligence (This Month)

Contact every AI vendor and request their AI Act conformity documentation, technical documentation as required by Article 11, bias testing results across protected characteristics, and their contractual commitments to AI Act compliance.

Step 3: FRIA for Each System (Q2 2026)

Conduct a Fundamental Rights Impact Assessment for each high-risk AI system. This is legally required under Article 27 for deployers of high-risk systems in employment contexts.

Step 4: Implement Real Human Oversight (Q2-Q3 2026)

Redesign your recruitment workflow so that human overseers have genuine authority: ensure humans review candidates the AI rejected (not just those it approved), provide overseers with training on the AI system's logic and limitations, and document every human override decision and the rationale.

Step 5: Update Candidate Communications (Before August 2026)

Revise all job postings, privacy notices, and candidate communications to disclose AI use. Include information about which AI systems are used and at which stage, what the AI evaluates, how candidates can request human review, and relevant contact information for queries.

The Clock Is Ticking

August 2026 is less than 6 months away. HR departments that haven't started their AI compliance journey are now in crisis territory. The gap between "we use AI in hiring" and "our AI hiring tools are fully compliant" is substantial — involving technical documentation, bias testing, process redesign, staff training, and vendor negotiations.

Start today. Not next quarter.

Need help with AI hiring compliance? Search our directory for consultants specializing in employment AI and Annex III high-risk systems.