Skip to content

EU AI Act High-Risk Series, Part 1: Recruitment & HR Tech

CV screening, candidate ranking and performance monitoring tools are high-risk under the EU AI Act, and one interview-scoring feature is banned outright. What a recruitment business or HR technology vendor has to build by December 2027, and why the commercial effect arrives sooner.

Cameron Mukherjee, Director · · Updated

For: Recruitment agencies, RPOs and HR technology vendors using AI in hiring

Key points

  • The Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) moved the deadline for standalone high-risk AI systems, including recruitment and HR tools, to 2 December 2027.
  • AI that infers emotions from biometric data in the workplace has been prohibited since 2 February 2025 and was not delayed; interview tools that score tone or facial expression are banned, not merely high-risk.
  • CV screening, candidate ranking, ad targeting by profile, interview scoring, and performance monitoring are high-risk under Annex III point 4.
  • By December 2027 in-scope systems need bias testing before deployment, meaningful human review of outcomes, logged and reconstructable decisions, transparency to candidates, and ongoing monitoring.
  • Penalties for high-risk non-compliance reach €15M or 3% of global turnover; for SMEs the lower figure applies.

Part 1 of our five-part series on high-risk AI under the EU AI Act, written for the directors who have to decide what to build, buy and sign off. Each instalment covers one regulated sector: what "high-risk" means for it, what the current timeline requires, and what has to be different about how you build or buy AI in that space. Part 2 covers finance and insurance; Part 3 covers education and EdTech; Part 4 covers healthcare and MedTech; Part 5 covers critical infrastructure.


If your business uses AI anywhere in the hiring pipeline, whether a screening tool you bought or a matching engine you built, the EU has just given you sixteen more months to comply. That is welcome. It is also easy to draw the wrong conclusion from it.

Two things matter more than the delay. One use of AI in hiring was not delayed at all: it has been banned since February 2025, and some interview-scoring products still ship it. And sixteen months is not long once you are building risk management, audit trails and human oversight into a live system rather than reading about them. This article sets out what has changed, what has not, and what a recruitment business or HR technology vendor should do about it, in the order that protects revenue.


What has changed

On 24 July 2026 the EU published the "Digital Omnibus on AI", Regulation (EU) 2026/1744, which entered into force on 27 July 2026. It moves the compliance deadline for standalone high-risk AI systems under Annex III, which includes recruitment and HR tools, from 2 August 2026 to 2 December 2027. That is a fixed date. An earlier proposal tied it to whether technical standards were ready; that mechanism was dropped in negotiation.

What the delay did not touch:

  • Since 2 February 2025: prohibited AI practices are banned outright, and staff AI-literacy obligations apply. The Omnibus softened the literacy standard from an obligation to ensure staff literacy to one to support it, and added two new prohibitions (non-consensual intimate imagery and child sexual abuse material, from 2 December 2026). Neither is relevant to hiring; both show Article 5 is still moving.
  • Since 2 August 2025: obligations for general-purpose AI models, and the Act's governance and penalty framework.
  • From 2 August 2026, unaffected by the delay: transparency duties, such as telling people they are dealing with an AI system.

The prohibited-practices point matters more for recruitment than for almost any other sector, because one banned practice is a feature some interview-scoring tools already sell.


Which hiring AI is high-risk, and which is banned

The Act names employment, workers' management and access to self-employment as a high-risk category (Annex III, point 4). In practice that covers AI used to:

  • Screen or rank CVs and applications
  • Target job adverts using candidate profiling
  • Score interviews, written, voice or video, on what a candidate says or demonstrates
  • Assess skills, personality or aptitude
  • Monitor or evaluate workforce performance
  • Inform decisions on promotion, task allocation or termination

The line that matters is between AI that helps a recruiter (drafting an advert, summarising a call) and AI that decides or meaningfully narrows outcomes for a candidate. The second is regulated.

There is a sharper line inside that. Article 5(1)(f) prohibits AI that infers a person's emotions from biometric data (facial expression, voice tone, physiological signals) in the workplace, with narrow medical and safety exceptions. That ban has applied since February 2025. If an interview tool analyses a candidate's tone or expression to infer how they feel, it is not "high-risk with a 2027 deadline". It is a feature that should not be running in an EU hiring process today. Scoring what a candidate actually says or demonstrates remains permitted, and high-risk.

The Commission has draft guidelines on high-risk AI in employment open for comment, with final guidance expected later in 2026.


What has to be in place by December 2027

For a system in scope, the obligations translate into work that has to be built, evidenced and maintained:

  • Bias testing before deployment. Evidence the tool performs consistently across protected characteristics, not a fairness statement.
  • A human who can override. Someone able to review and reverse an automated reject or shortlist decision. The pipeline cannot be end-to-end automated.
  • A reconstructable record. Every automated score or decision logged and retained, so a challenged decision can be explained.
  • Candidates told AI was used. This overlaps with GDPR Article 22 rights on automated decision-making, which have applied to hiring tools since 2018.
  • Ongoing monitoring. Bias and performance drift checked after launch, not certified once.

None of this is quick from a standing start. Sixteen months is comfortable only if the work begins with the roadmap it has to run alongside.


What is at stake commercially

Fines under Article 99 are tiered, and the Omnibus changed none of them:

  • Up to €35M or 7% of global annual turnover, whichever is higher, for breaching a prohibition such as the emotion-recognition ban.
  • Up to €15M or 3% for non-compliance with the high-risk obligations above.
  • Up to €7.5M or 1% for supplying incorrect information to a regulator.
  • For small and medium-sized enterprises, each cap applies as whichever figure is lower.

The fine is rarely the largest cost. A biased screening tool is an AI Act problem and an employment tribunal problem on the same facts. And the commercial effect arrives before any regulator does: enterprise and public-sector clients are already asking AI Act questions in supplier due diligence. A recruitment platform that cannot answer them credibly is not shortlisted.

The upside is equally commercial. A business that can show its classification, its testing and its oversight process wins the tenders that ask, and can sell into the EU without a caveat in the contract.


What to do now

  1. Inventory every AI system in the hiring process, bought or built, and classify it against Annex III and Article 5. Most tools turn out to be limited risk; the ones that are not need a dated plan.
  2. Check any interview or assessment tool for emotion inference from biometrics. If it is there, switch it off now.
  3. Establish whether you are a deployer or a provider. Buyers of third-party tools carry lighter obligations, but retraining or substantially modifying a vendor's model can make you a provider.
  4. Put the record-keeping in first. Logging and human review are the foundations everything else sits on, and the cheapest to add early.
  5. Answer the due-diligence questionnaire before a client sends it.

How Hexploits helps

We do the engineering and operational side of readiness: EU AI Act readiness covers inventory and classification, the documentation, logging and oversight for high-risk systems, and bias testing on your own data. We have built AI-driven candidate matching and scoring pipelines ourselves, for JobVantage, so we know where in that kind of pipeline these obligations bite. And we are the core team behind swarmd.ai, an EU AI Act readiness platform for governing AI agents in regulated industries.

If you are not sure where you stand, request a proposal or talk to an engineer. You will have a written scope and an indicative price within two working days.

This is our view of the operational and technical side of compliance, not legal advice. Pair it with your legal counsel for formal sign-off. Next in the series: Part 2, finance and insurance.

Questions this raises

Is CV screening high-risk under the EU AI Act?
Yes. AI used to screen or rank applications, target job adverts, score interviews, assess candidates or monitor workers is listed in Annex III point 4 as high-risk.
When is the recruitment AI deadline?
2 December 2027 for standalone high-risk systems, following the Digital Omnibus. Prohibited practices have applied since 2 February 2025.
Does the ban on emotion recognition affect interview tools?
Yes. Inferring emotions from facial expression, voice tone or physiological signals in the workplace is prohibited, with narrow medical and safety exceptions. Scoring what a candidate says or demonstrates remains permitted but high-risk.
Does this apply to a UK recruitment firm?
It applies where the system’s output is used in the EU, including UK firms placing candidates into EU roles or supplying tools to EU customers.

How Hexploits helps

  • EU AI Act readiness for UK businesses

    EU AI Act readiness is the work of classifying each AI system against the Act’s risk tiers, and building the risk management, technical documentation, logging, human oversight and post-market monitoring that high-risk systems must have before their deadline.

  • AI document and email processing

    AI document processing extracts structured data from unstructured inputs such as invoices, contracts, claims, CVs and correspondence, classifies them and routes them, with a person reviewing the cases the model is unsure about.

Have a question this raised?

Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.