Skip to content

Applied AI

EU AI Act for recruitment and HR: high-risk hiring AI explained

The EU AI Act names AI used in recruitment and employment as high-risk: systems that place targeted job advertisements, filter or screen applications, evaluate candidates, decide on promotion or termination, allocate tasks, or monitor and evaluate performance. Emotion recognition in the workplace is prohibited outright. UK agencies, RPOs and HR software vendors are in scope where candidates, employees or clients are in the EU, or where the system’s output is used there. Hexploits does the engineering side of alignment: classification, documentation, logging, bias testing and human oversight built into the systems rather than written up afterwards.

A named engineer replies within one working day. A written scope and an indicative price within two.

  • UK recruitment agencies and RPOs placing candidates into EU roles or working for EU clients.
  • HR technology vendors selling screening, matching or performance tools into the EU, who carry the heavier provider obligations.
  • In-house HR and talent teams using bought AI tools for screening, and now responsible for them as deployers.
  • Compliance and legal functions asked whether the tools already in use are in scope.

Deliverables, not slogans. Each one appears in the statement of work.

  • An inventory of every AI use in hiring and employment, bought or built, classified against Annex III with the reasoning written down.
  • Provider or deployer determination per system, including whether configuring or fine-tuning a vendor tool has made you a provider.
  • For high-risk systems: risk management records, technical documentation, automatic logging, human-oversight procedures and a post-market monitoring plan.
  • Bias testing against your own candidate data across protected characteristics, with results on file and refreshed on a schedule.
  • Transparency notices for candidates and employees, and the worker-information duties met before deployment.
  • A dated plan to the December 2027 deadline and a completed AI section for client and candidate due-diligence questionnaires.

Our engineers work across the major languages, frameworks and cloud platforms. We build on the stack you already run, with technology choices explained in writing before work begins.

The same four stages as every Hexploits engagement, applied to this capability.

  1. Stage 1

    Inventory and classify

    Two to four weeks. Every AI use in the hiring and employment flows is listed and mapped to the Act’s categories and prohibitions. Most turn out to be limited risk; screening, ranking and evaluation tools do not.

  2. Stage 2

    Gap analysis

    Current controls, documentation and the vendor’s own conformity evidence are compared with what the Act requires, and gaps are ranked by deadline and exposure.

  3. Stage 3

    Build the controls

    Logging, oversight points, bias testing and documentation are built into the systems and the release process, so the evidence is produced by the system running.

  4. Stage 4

    Monitor and maintain

    Post-market monitoring, incident handling and periodic review under deployment and monitoring, with the inventory kept current as tools and guidance change.

We are the core engineering team behind swarmd.ai

swarmd.ai is an EU AI Act readiness platform for governing AI agents in highly regulated industries: policy enforced on every action, tamper-evident audit trails, per-tenant isolation and customer-owned identity. The same patterns are what we apply to a recruitment business’s own screening and matching systems, and to the bought tools it deploys.

Every engagement agrees its measures and the measurement period in writing before work starts.

  • Every hiring and employment AI use classified, with reasoning a client or regulator can be shown.
  • High-risk systems with complete documentation and logging before the deadline.
  • Bias test results across protected characteristics on file and refreshed on schedule.
  • Client due-diligence questionnaires answered from evidence rather than assertion.

Case studies with numbers, and reviews linked to Google where they were left there.

  • Director, JobVantage

    Working with Hexploits has genuinely been a pleasure, and I see them as my scaling partner for the foreseeable future as JobVantage grows. If you’re looking for a development team who combine strong AI/engineering capability with honesty, flexibility and a real interest in your business, I’d strongly recommend them.

    Brandon BowdenDirector, JobVantageRead the review
  • Director, IO Solutions

    Fantastic to work with. High level of attention to detail and flawless communication throughout. Would recommend to anyone looking to develop or improve a software product.

    Christian LorzaDirector, IO SolutionsRead the review
Why is recruitment AI high-risk under the EU AI Act?
Because it decides who gets access to work. Annex III lists AI used to recruit or select people, including targeted job adverts, filtering applications and evaluating candidates, and AI used for decisions on promotion, termination, task allocation and performance monitoring. The Act treats these as affecting fundamental rights, so providers and deployers carry obligations.
We are a UK agency. Does it apply to us?
It applies where the AI system is placed on the EU market, where a deployer is established in the EU, or where the output of the system is used in the EU. A UK agency placing candidates into EU roles, screening EU candidates, or working for an EU client is commonly in scope for that work.
What about the screening tool we buy from a vendor?
As the deployer you must use it according to its instructions, ensure human oversight, keep its logs, inform workers and candidates, and monitor it. If you retrain it or change its purpose substantially, you may become a provider under Article 25. We determine this per tool during inventory.
When is the deadline?
Following the Digital Omnibus, standalone high-risk systems under Annex III, which include hiring and employment AI, must comply by 2 December 2027. The prohibition on emotion recognition in the workplace has applied since 2 February 2025.
What does UK law say?
UK GDPR restricts solely automated decisions with legal or similarly significant effects and requires safeguards, and the ICO’s 2024 audits of AI recruitment tools set out expectations on fairness, transparency and data minimisation. The evidence built for the EU AI Act covers most of it, and we map the two so the work is done once.
Is this legal advice?
No. We do the engineering and operational side and work alongside your legal counsel, who sign off the legal position.

Request a proposal.

Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.