EU AI Act High-Risk Series, Part 1: Recruitment & HR Tech
CV screening, candidate ranking, and performance-monitoring tools are named high-risk under the EU AI Act. The compliance deadline just moved to December 2027 - but not everything did. Heres what actually applies to hiring AI, and when.
This is Part 1 of our five-part series on high-risk AI under the EU AI Act. Each instalment covers one regulated vertical - what "high-risk" means for it, what the current timeline actually requires, and what has to be different about how you build or buy AI in that space. Part 2 covers finance and insurance; Part 3 covers education and EdTech; Part 4 covers healthcare and MedTech; Part 5 covers critical infrastructure.
If you build or buy AI anywhere in the hiring pipeline, you've probably heard that the EU just pushed the AI Act's high-risk compliance deadline back by sixteen months. That's true, and if you've been quietly dreading a scramble this August, it's genuinely good news.
But two things are easy to miss in that relief. First, one specific use of AI in hiring wasn't delayed at all - it's been banned outright since February 2025. Second, sixteen months disappears fast once you're actually building risk management systems and audit trails, rather than just reading about them. This post covers what's changed, what hasn't, and what a recruitment or HR tech platform actually needs to do about it.
What just changed
On 24 July 2026 the EU published the "Digital Omnibus on AI" - Regulation (EU) 2026/1744 - and it entered into force three days later, on 27 July 2026. It postpones the compliance deadline for standalone high-risk AI systems under the Act's Annex III, which includes recruitment and HR tools, from 2 August 2026 to 2 December 2027. That's a fixed calendar date - the original proposal would have tied it to whether technical standards were ready, but that conditional mechanism was dropped in favour of a hard deadline during negotiation.
What wasn't touched by the delay:
- Since 2 February 2025: prohibited AI practices are banned outright, and staff AI-literacy obligations apply. The Digital Omnibus didn't weaken any existing prohibition - though it did soften the AI-literacy standard itself, from an obligation to ensure staff literacy to one to support its development. It also added two new prohibited practices on top of the original list - AI that generates non-consensual intimate imagery and AI that generates child sexual abuse material - both effective from 2 December 2026. Neither is directly relevant to hiring, but it shows Article 5 is still actively evolving, not frozen.
- Since 2 August 2025: obligations for general-purpose AI models, plus the Act's governance and penalty framework, apply.
- From 2 August 2026 (unaffected by the delay): transparency duties apply wherever relevant - for example, telling people they're interacting with an AI system.
The prohibited-practices point matters more for recruitment than almost any other vertical, because one of the banned practices is built directly into a feature some interview-scoring tools already ship.
Why recruitment AI counts as "high-risk" - and where it tips into "banned"
The Act names employment, workers' management, and access to self-employment as a high-risk category (Annex III, point 4). In plain terms, that covers AI used to:
- Screen or rank CVs and applications
- Target job adverts based on candidate profiling
- Score interviews - written, voice, or video, based on what a candidate actually says or demonstrates
- Assess skills, personality, or aptitude
- Monitor or evaluate workforce performance
- Inform decisions on promotion, task allocation, or termination
The line that matters is between AI that helps a recruiter (drafting a job ad, summarising a call) and AI that decides or meaningfully narrows outcomes for a candidate. The second category is what's regulated.
There's a sharper line inside that, though: Article 5(1)(f) separately prohibits AI systems used to infer a person's emotions from biometric data - facial expression, voice tone, physiological signals - in the workplace, with narrow exceptions for medical or safety reasons. That ban has applied since February 2025 - it wasn't part of the delay, and it isn't a documentation-and-oversight problem you can work through like the high-risk obligations below. If an interview-scoring tool analyses a candidate's tone or facial expression to infer how they're feeling, that's not "high-risk with a 2027 deadline" - it's a feature that shouldn't exist in an EU hiring process today. Scoring based on what a candidate actually says or demonstrates sits in the high-risk-but-permitted category above; scoring based on inferred emotional state does not.
The European Commission has draft guidelines on high-risk AI in employment open for stakeholder feedback, with final guidance expected later in 2026 - worth watching if you want the most precise, current reading of how these categories apply in practice.
What actually has to change by December 2027
For the high-risk obligations that were postponed, here's what a recruitment platform in scope will need to demonstrate:
- Bias testing before deployment, not after a complaint. Evidence the tool performs consistently across protected characteristics, not just a fairness statement.
- A human in the loop on outcomes that matter. Someone has to be able to review or override an automated reject or shortlist decision - it can't be the whole pipeline, end to end.
- A paper trail. Every automated score or decision logged, retained, and reconstructable if a candidate challenges it.
- Candidates told AI was used. Transparency toward the people the system is actually deciding about - this overlaps with existing GDPR Article 22 rights around automated decision-making, which has applied to hiring tools since 2018, independently of the AI Act.
- Ongoing monitoring, not a one-off sign-off. Performance and bias drift get checked after launch, not just certified before it.
None of this is quick to build from scratch. Sixteen extra months sounds generous until you map out how long a genuine risk management system, a real audit log, and a documented human-oversight process actually take to stand up properly - especially alongside a product roadmap that isn't going to pause and wait.
What we've left out of this piece, on purpose
To keep this readable, we've deliberately skipped some detail: the difference between a provider obligation and a deployer obligation (most recruitment teams reading this are deployers - the obligations are heavier if you're the one building and selling the tool), the general-purpose AI model rules (a separate part of the Act), and the procedural detail of conformity assessment and EU database registration. This is a primer to help you work out whether you should be paying closer attention, not a compliance manual.
What's actually at stake
Fines follow a tiered structure under Article 99, and none of these tiers were changed by the Digital Omnibus:
- Up to €35M or 7% of global annual turnover, whichever is higher - reserved for violations of the Act's outright prohibitions, like the emotion-recognition ban above.
- Up to €15M or 3% - the tier that actually applies to non-compliance with the high-risk obligations this post is about (risk management, documentation, human oversight, and so on).
- Up to €7.5M or 1% for supplying incorrect or misleading information to a regulator.
- For SMEs, including startups, each of these caps applies as whichever figure is lower, not higher - a meaningful difference from the rule for larger companies.
For recruitment specifically, an AI Act breach rarely arrives alone. Discrimination claims under existing employment and equality law tend to follow the same fact pattern - a biased screening tool is an AI Act problem and an employment tribunal problem at once. Enterprise and public-sector customers are already asking AI Act questions in procurement due diligence, well ahead of the 2027 deadline - a hiring tool that can't answer them credibly doesn't get shortlisted itself.
We've built AI-driven candidate matching and scoring pipelines ourselves - see our work with JobVantage - so we know firsthand where in that kind of pipeline these obligations actually bite.
Getting ready
If you're building or running AI anywhere in the hiring pipeline and aren't sure where you stand, get in touch - we'll help you work out whether you're in scope, what's already binding today, and what to prioritise before December 2027 arrives faster than expected.
This is our take on the operational and technical side of compliance, not legal advice - pair it with your own legal counsel for formal sign-off. Next in the series: Part 2, Finance & Insurance.