EU AI Act

Is AI in recruitment and HR high-risk under the EU AI Act, and what must employers do?

EU AI Act and HR: banned since 2 Feb 2025, emotion inference at work; high risk from 2 Dec 2027, AI for recruitment and selection, and for decisions on work terms, promotion, termination, task allocation and monitoring. Employer duties: human oversight, logs for six months, inform workers before use.

Yes. The EU AI Act lists AI used to recruit, select, promote, dismiss, allocate work to or monitor people as high-risk, in Annex III, point 4. An employer using such a system is a deployer, with its own duties under Article 26. After the July 2026 amendment, those duties apply from 2 December 2027. Two other rules already apply: the ban on emotion inference at work, and the AI literacy duty.

2 Feb 2025Emotion inference at work banned
2 Dec 2027HR high-risk rules apply
6 monthsMinimum log retention
Before useInform workers

Every quotation is from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, read in the consolidated text of 27 July 2026 on 2 October 2026. This is not legal advice.

Which HR uses of AI are high-risk?

Annex III, point 4, "Employment, workers' management and access to self-employment", lists two groups:

  • Point 4(a): "AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates".
  • Point 4(b): AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behavior or personal traits or characteristics, or to monitor and evaluate the performance and behavior of people in those relationships.

That covers CV screening, candidate scoring, targeted job ads, promotion and dismissal support, algorithmic task allocation and performance monitoring. Article 6(3) can take a system out of high-risk status if it poses no significant risk of harm and meets one of four narrow conditions, but never where the system profiles people. Our guide to the Annex III areas and the Article 6(3) test walks through it.

What is already banned in the workplace?

Emotion inference. Article 5(1)(f) prohibits "the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons". It has applied since 2 February 2025, and it is in the top fine tier: up to EUR 35 million or 7% of worldwide turnover. Check any tool that claims to read mood, stress or engagement from staff video, voice or text against it.

What must an employer do as a deployer?

Article 26 sets the deployer's duties for high-risk systems. For an HR team, the ones that matter are:

Article 26Duty
(1)Use the system in line with the provider's instructions for use
(2)Assign human oversight to people with "the necessary competence, training and authority, as well as the necessary support"
(4)Where you control the input data, make sure it is relevant and sufficiently representative for the intended purpose
(5)Monitor the system and report risks to the provider and the market surveillance authority
(6)Keep the logs the system generates, where under your control, for at least six months
(7)Before use at the workplace, inform workers' representatives and the affected workers
(9)Use the provider's Article 13 information for your GDPR data protection impact assessment
(11)Tell people that they are subject to a high-risk system that makes or assists decisions about them

Article 26(7) is the one most HR teams have not planned for. It reads: "Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system." Under the amended Article 113, these duties apply from 2 December 2027 for Annex III systems.

HR AI system checklist

AI system,Vendor (provider),What HR uses it for,Annex III point 4 (a) recruitment or (b) work decisions or monitoring? ,Infers emotions at work? (prohibited since 2 Feb 2025 unless medical or safety),Instructions for use on file (Art. 26(1)),Human overseer named and trained (Art. 26(2)),Input data relevant and representative where we control it (Art. 26(4)),Monitoring and risk reporting route (Art. 26(5)),Logs kept at least six months (Art. 26(6)),Workers and representatives informed before use (Art. 26(7)),Candidates or employees told they are subject to it (Art. 26(11)),DPIA done using provider's Article 13 information (Art. 26(9)),Owner,Review date
Example: CV screening tool,Vendor name,Shortlisting applicants,4(a),no,,,,,,,,,,
,,,,,,,,,,,,,,
,,,,,,,,,,,,,,
"Deployer duties in Article 26 of the EU AI Act apply to Annex III high-risk systems from 2 December 2027, as amended by Regulation (EU) 2026/1744. Article 4 (AI literacy) and Article 5(1)(f) (no emotion inference at work) already apply. Template from credentialpress.com/guides/eu-ai-act-ai-in-recruitment-and-hr. Not legal advice.",,,,,,,,,,,,,,

What rights do candidates and employees get?

Two sets. Under the AI Act, Article 86 gives a person subject to a decision taken on the basis of an Annex III high-risk system's output, with legal or similarly significant adverse effects, the right to "clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken". Under the GDPR, Article 22(1) gives a person "the right not to be subject to a decision based solely on automated processing, including profiling" with legal or similarly significant effects, subject to the exceptions in Article 22(2). A rejection by a fully automated screening tool engages both.

Does an employer need a fundamental rights impact assessment?

Usually not. Article 27(1) requires one from deployers that are bodies governed by public law or private entities providing public services, and from deployers of the credit scoring and life and health insurance systems in Annex III, point 5(b) and (c). A private employer outside those groups is not covered. Public sector employers are. A GDPR data protection impact assessment may still be required, and Article 26(9) tells deployers to use the provider's information for it.

Who is responsible, the vendor or the employer?

Usually the vendor is the provider, responsible for the system meeting the high-risk requirements, its documentation and its conformity assessment. The employer is the deployer, responsible for how the system is used. If an employer puts its own name on the system, substantially modifies it, or changes its intended purpose so that it becomes high-risk, Article 25 can make the employer a provider. Our guide to provider and deployer roles sets out when that happens.

What should HR do before December 2027?

Our suggestion, in order:

  1. List every AI system HR uses, and mark which fall under Annex III, point 4(a) or 4(b). The checklist above has a column for each Article 26 duty.
  2. Switch off any feature that infers emotions at work now, since that ban already applies.
  3. Ask each vendor whether it treats the system as high-risk, and for its instructions for use.
  4. Name and train the human overseers. AI literacy under Article 4 already applies to them; our Article 4 guide covers what that needs.
  5. Plan how you will inform workers' representatives and staff before use, and how you will tell candidates.

What should you do this week?

Download the checklist and list the AI systems in your hiring and people processes. Credential Press is independent of the EU institutions. For the people who will run AI governance in HR, the role-by-role certification guide shows where the AIGP fits.

Frequently asked questions

Is AI used in recruitment high-risk under the EU AI Act?

Yes. Annex III, point 4(a) lists AI systems intended to be used for the recruitment or selection of people, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates. Point 4(b) adds AI used for decisions on work terms, promotion, termination, task allocation and monitoring performance.

When do the high-risk rules for HR AI apply?

From 2 December 2027, after Regulation (EU) 2026/1744 moved the date for Annex III systems. The ban on emotion inference at work and the AI literacy duty have applied since 2 February 2025.

Can employers use emotion recognition on staff?

No. Article 5(1)(f) prohibits AI systems that infer the emotions of a person in the workplace, except where the system is intended for medical or safety reasons. The ban has applied since 2 February 2025.

Must employers tell staff before using high-risk AI?

Yes. Article 26(7) requires employers to inform workers' representatives and the affected workers before putting a high-risk AI system into service or using it at the workplace.

Does an employer need a fundamental rights impact assessment for recruitment AI?

Not as a rule. Article 27 requires it of deployers that are bodies governed by public law or private entities providing public services, and of deployers of credit scoring and life and health insurance pricing systems. A private employer outside those groups is not covered, though a GDPR DPIA may still be needed.

Who is responsible, the vendor or the employer?

Both, for different things. The vendor is usually the provider and must meet the requirements for high-risk systems. The employer is the deployer and has the Article 26 duties: use per the instructions, human oversight, logs, monitoring, and informing workers and candidates.

EU AI Act: test yourself in five minutes

Which books go deeper on the EU AI Act?

Cover of AI Governance Framework

AI Governance Framework

Building one that survives the EU AI Act. 22 chapters, 384 pages.

Cover of AI Governance Worked Scenarios

AI Governance Worked Scenarios

24 worked situations under the EU AI Act, decided against the Articles. 81 pages.