AI Compliance

EU AI Act for HR: Recruitment, Workforce AI and What Employers Must Do by December 2027

AI that recruits, selects, promotes, dismisses, allocates work or monitors staff is high-risk under Annex III of the EU AI Act, with obligations from 2 December 2027, and emotion recognition at work is already banned. What employers owe as deployers, when a fundamental rights impact assessment applies, how GDPR Article 22 fits, and a buying checklist.

The EU AI Act for HR treats AI that recruits or selects people, or that decides on promotion, dismissal, terms of work, task allocation or performance monitoring, as high-risk under Annex III point 4. After the Digital Omnibus, those obligations apply from 2 December 2027. Inferring the emotions of employees or job candidates from biometric data has been banned since 2 February 2025.

Which HR systems are high-risk under Annex III

Annex III point 4 has two entries. Point 4(a) covers AI intended for the recruitment or selection of natural persons, in particular placing targeted job ads, analysing and filtering applications and evaluating candidates. Point 4(b) covers AI intended to make decisions on the terms of work relationships, promotion or termination, to allocate tasks based on individual behaviour or personal traits, or to monitor and evaluate the performance and behaviour of workers. Classification follows the intended purpose, so the same language model can be high-risk inside a screening tool and outside Annex III inside a policy chatbot.

In May 2026 the Commission published draft guidelines on high-risk classification for consultation, with worked HR examples. They were still a draft in October 2026 (verified October 2026), so read the right-hand column as an indication:

HR useView in the Commission’s draft guidelines
Matching and ranking candidates against a vacancy, with scores or fit labelsHigh-risk under point 4(a)
Sourcing candidates from job boards, social media and CV databases into shortlistsHigh-risk under point 4(a)
Scoring written or video interview answers to decide who goes to interviewHigh-risk under point 4(a)
Background-check risk scores used to filter applicantsHigh-risk, and no exemption because it profiles
Targeted job ads that rely on profilingHigh-risk; contextual placement and employer branding are outside
Shift allocation using punctuality, acceptance rates or ratingsHigh-risk under point 4(b)
Suspending or deactivating platform workers when ratings fall below a thresholdHigh-risk under point 4(b), as functional termination
Scheduling interviews, parsing CVs into a searchable database, checking credentials against registersExempt as narrow procedural or preparatory tasks
Auditing past hiring decisions for bias, using anonymised dataExempt under Article 6(3)(c)
Onboarding assistant answering policy questionsOutside point 4(a); inside 4(b) only if it feeds evaluations or monitors staff
Polishing the wording of a promotion report a manager has already completedExempt under Article 6(3)(b)

Two points in the draft matter most in practice. A human reviewer does not change the classification, because classification follows the intended purpose and oversight is a requirement placed on high-risk systems. And any Annex III system that profiles people stays high-risk whatever task it performs, which is written into the last subparagraph of Article 6(3) itself.

Dates HR teams should plan around

  • 2 February 2025. The Article 5 bans took effect, including emotion recognition at work and biometric categorisation that infers trade union membership or political opinions. So did the AI literacy duty in Article 4, which the Omnibus later softened to taking measures that support staff literacy; the AI compliance training agent addresses that duty.
  • 2 August 2026. Article 50 transparency applies, so a recruiting chatbot must tell candidates they are dealing with AI unless that is obvious. See our note on Article 50 disclosure.
  • 2 December 2026. Member States must have transposed the Platform Work Directive, (EU) 2024/2831. Its Article 7 stops digital labour platforms from using automated systems to process data on the emotional or psychological state or private conversations of people doing platform work, or to infer their trade union membership.
  • 2 December 2027. The high-risk obligations for Annex III systems apply, including the deployer duties below.

Article 111(2) adds a transition rule: high-risk systems placed on the market or put into service before 2 December 2027 fall under the high-risk rules only if their design changes significantly after that date, and systems used by public authorities must comply by 2 August 2030 regardless. The Omnibus recitals apply the test to the type and model of system. Ask vendors how they will treat model upgrades and new features under that rule, since frequently updated software may not stay grandfathered for long.

Employer duties as a deployer

Most employers are deployers: they use a system under their own authority. Article 26 sets out what that means once the Annex III rules apply.

DutyArticleWhat it looks like in HR
Use the system according to the provider’s instructions for use26(1)Obtain the instructions before go-live and keep the tool within its stated purpose
Assign human oversight to people with the competence, training, authority and support to exercise it26(2)Name the recruiters or managers who review outputs, and give them the power to override
Keep input data relevant and sufficiently representative, where you control it26(4)Job criteria, scorecards and historical hiring data you feed in
Monitor operation, suspend use if the system presents a risk, and report serious incidents26(5)A route for recruiters to escalate odd results, and someone who owns the decision to stop
Keep the logs the system generates, where under your control, for at least six months unless other law provides otherwise26(6)Reconcile with GDPR retention limits for candidate data
Inform workers’ representatives and affected workers before use at the workplace26(7)Follow national information and consultation procedures
Use the provider’s information to carry out the GDPR data protection impact assessment26(9)Request it during procurement
Tell people when decisions about them are made or assisted by the system26(11)Candidate and employee notices
Explain the system’s role and the main elements of a decision on request86Applies to decisions with legal or similarly significant adverse effects

Our guide to human oversight requirements covers how to design review points that people actually use.

When HR becomes the provider

Article 25(1)(c) turns a deployer into the provider of a high-risk system when it changes the intended purpose of a system that was not high-risk, including a general-purpose assistant, so that it becomes high-risk. An HR team that points a general chatbot or an in-house language model at CV ranking takes on the provider’s obligations under Article 16, among them a quality management system, technical documentation, a conformity assessment, the CE marking and registration in the EU database. The same applies to a screening tool you build and put into service under your own name. For Annex III point 4 systems, Article 43(2) prescribes the internal-control route, without a notified body, so the burden is documentation rather than an external audit.

Does HR need a fundamental rights impact assessment?

Article 27 asks for a fundamental rights impact assessment before first use from three kinds of deployer: bodies governed by public law, private entities providing public services, and deployers of the credit scoring and life and health insurance systems in Annex III points 5(b) and (c). Recital 96 ties public services to areas such as education, healthcare, social services, housing and the administration of justice. A ministry, a public hospital or a private operator running a public service therefore needs one for its high-risk HR tools; most private employers do not.

Where it applies, the assessment describes the processes the system supports, how often it runs, who is affected, the specific risks to them, the oversight measures and what happens if a risk materialises, and the results go to the market surveillance authority. The Omnibus lets deployers cross-refer to their GDPR data protection impact assessment instead of duplicating it. Even without a FRIA, Article 35(3)(a) GDPR requires a DPIA for systematic and extensive evaluation based on automated processing, including profiling, that leads to significant decisions, a description that fits many screening tools. Our DPIA and FRIA use case shows how to run both from one set of evidence.

Emotion recognition at work is already prohibited

Article 5(1)(f) has banned AI that infers the emotions of people at work since 2 February 2025, with an exception for medical or safety reasons. The Commission’s guidelines on prohibited practices fill in the detail:

  • The workplace is broad. It covers any physical or virtual place where people carry out work, whatever their status as employee, contractor, trainee or volunteer, and it covers candidates during selection.
  • Named examples. Emotion recognition during recruitment and during probation, webcam and voice tracking of call-centre staff, and mood monitoring of hybrid teams on video calls are all prohibited.
  • Biometric data is the trigger. Inferring emotions from faces, voice, gestures or keystrokes is caught; sentiment analysis of written text is not, although it can still be a monitoring system under Annex III point 4(b).
  • The exceptions are narrow. Medical use means uses such as CE-marked medical devices, and safety means protecting life and health. Burnout, stress or boredom detection does not qualify. Emotion recognition used only for an employee’s own training is allowed when the results never reach HR and cannot affect assessment or promotion.

The same article bans biometric categorisation that infers political opinions or trade union membership, which rules out inferring union sympathies from images or video of staff. Our overview of Article 5 prohibited practices covers the other bans and the fines.

How GDPR Article 22 fits with the AI Act

The AI Act does not replace data protection law, and for HR the most important GDPR provision is Article 22. It gives candidates and employees the right not to be subject to a decision based solely on automated processing, including profiling, with legal or similarly significant effects. Such a decision is allowed only where necessary for a contract, authorised by law with safeguards, or based on explicit consent. In the first and last cases the employer must offer human intervention, a chance for the person to express their view and a way to contest the decision. Under Article 13(2)(f), privacy notices must disclose such decision-making and give meaningful information about the logic involved.

The two regimes overlap without matching. The AI Act requires human oversight of every high-risk system, however its outputs are used, while Article 22 is triggered only by decisions based solely on automated processing. A review that is only nominal does not help under either: the Article 29 Working Party’s guidelines on automated decision-making say human involvement must be meaningful, carried out by someone with the authority and competence to change the decision.

Two further points matter for employers. Article 88 GDPR lets Member States and collective agreements set more specific rules for employee data, so check local law before rollout. And in SCHUFA (C-634/21, December 2023), the Court of Justice held that a credit agency’s automated score can itself be an Article 22 decision when a third party draws strongly on it. Whether that reasoning reaches vendor scores that recruiters lean on heavily is a question to put to counsel.

Checklist for HR teams buying AI tools

For anything that screens, scores, schedules or monitors people:

  1. Intended purpose. Ask the vendor to state it in writing and to say whether they classify the product under Annex III point 4. If they rely on Article 6(3), ask for the documented assessment Article 6(4) requires.
  2. Emotion features. Confirm that the product infers no emotions from video, voice or keystrokes, and get that in the contract. Switch off “engagement” or “sentiment” scoring in interview and meeting tools.
  3. Instructions for use. Obtain them before go-live, and design your oversight and input data around them.
  4. Logs. Confirm you can access and export the logs for at least six months, and that retention can be set to fit your GDPR policy.
  5. Oversight design. Decide who reviews outputs, with what training and authority, and track how often reviewers override the system.
  6. Bias evidence. Ask what testing the provider ran, on which groups, and how you can repeat it on your own data.
  7. Worker information. Plan information and consultation with employee representatives under national law before the system goes live.
  8. Notices. Prepare candidate and employee notices covering Article 26(11), any chatbot disclosure under Article 50, and GDPR information on automated decisions.
  9. Explanations and contests. Set up a route for Article 86 explanation requests, Article 22 objections and data subject access requests.
  10. Change control. Agree how model and feature updates will be notified, since a significant design change ends grandfathering and may require you to reclassify the tool.
  11. Data location and exit. Establish where candidate and employee data is processed and by which sub-processors, and make sure you can export decision records and logs if you change vendor.

How VDF AI fits

Deployed on-premises or in your private cloud, VDF AI keeps CVs, assessments and decision records inside your own estate. The AI recruiting agent turns a job description into explicit requirements, assesses each candidate against them with the evidence quoted, and leaves every progression decision to a named human reviewer without producing a ranking. That is still evaluating candidates under point 4(a), so plan for it as a high-risk use whatever tool you choose.

VDF AI Networks provides Human Approval nodes for placing review steps in a workflow, with audit logs that stay inside your perimeter in an on-premises deployment, and role-based access control is available on every plan. The HR use cases set out where governed agents fit from helpdesk to onboarding. None of this classifies a system or settles your obligations; that stays with your legal and HR teams.

Sources

Frequently asked questions

Is AI used in recruitment high-risk under the EU AI Act?

Usually, yes. Annex III point 4(a) lists AI intended for recruiting or selecting people, in particular placing targeted job ads, analysing and filtering applications, and evaluating candidates. A provider can claim the Article 6(3) exemption for narrow procedural or preparatory tasks, and the Commission's draft guidelines give scheduling interviews and parsing CVs into a database as examples, but never for a system that profiles people. Under the same draft, a human in the loop does not change the classification. The obligations apply from 2 December 2027.

When does the EU AI Act apply to HR systems?

In stages. The ban on emotion recognition at work and the other Article 5 prohibitions have applied since 2 February 2025, together with the AI literacy duty, which the Digital Omnibus has since softened to taking measures that support staff literacy. Transparency duties for chatbots and generated content followed on 2 August 2026. The Omnibus, Regulation (EU) 2026/1744, moved the high-risk obligations for Annex III systems, including recruitment and workforce management tools, from 2 August 2026 to 2 December 2027.

Do employers have to inform employees and works councils before using AI?

For high-risk systems, yes. Article 26(7) requires employers to inform workers' representatives and the affected workers before putting a high-risk AI system into service or using it at the workplace, following national rules and practice on informing workers. Article 26(11) adds that people subject to decisions made or assisted by an Annex III system must be told. National labour law and collective agreements may also require consultation, and Article 2(11) lets Member States keep rules that protect workers more strongly.

Do HR teams need a fundamental rights impact assessment under the EU AI Act?

Most private employers do not. Article 27 limits the fundamental rights impact assessment to deployers that are bodies governed by public law, private entities providing public services, and deployers of credit scoring and life and health insurance systems. A public authority, or a private organisation running a public service such as healthcare or education, that uses high-risk HR AI must carry one out before first use. A GDPR data protection impact assessment will often be needed anyway for systematic profiling of candidates or staff.

Can we use emotion recognition in job interviews?

No. Inferring a candidate's emotions or intentions from video, voice or other biometric data has been prohibited since 2 February 2025. The Commission's guidelines treat candidates in a selection process as part of the workplace, and they name emotion recognition during recruitment and during probation as prohibited examples. The exception for medical or safety reasons is narrow and does not cover gauging a candidate's interest, motivation or stress. Breaches can draw fines of up to 35 million euros or 7% of worldwide annual turnover.

How does GDPR Article 22 apply to AI hiring decisions?

Article 22 gives candidates and employees the right not to be subject to a decision based solely on automated processing, including profiling, that has legal or similarly significant effects, and it applies alongside the AI Act. A fully automated rejection is allowed only where it is necessary for a contract, authorised by law with safeguards, or based on explicit consent. The employer must then offer human intervention, a chance to give one's view and a way to contest, and privacy notices must give meaningful information about the logic involved.

Filed under
EU AI ActAI complianceAI governancehuman oversightGDPRregulated AI
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading