PowerQuantEU

AI Recruitment Screening — High-Risk Obligations for HR Deployers under EU AI Act

AI Recruitment Screening and the EU AI Act

AI-powered recruitment screening tools — resume parsers, candidate ranking engines, video interview analysers and automated shortlisting systems — fall squarely under the high-risk classification in Regulation (EU) 2024/1689 ("EU AI Act"), Annex III, point 4.

As an organisation that deploys such a system in your hiring process, you are a deployer under the Regulation. This carries concrete obligations that cannot be contracted away to your HR software vendor.

Why Recruitment Screening AI Is High-Risk

Annex III, point 4 covers AI systems used in "employment, workers management and access to self-employment", specifically including systems used for:

  • "recruitment or selection of natural persons, notably for advertising vacancies, screening or filtering applications, evaluating candidates in the course of interviews or tests".

The key question is function, not technology. Whether a system uses keyword matching, machine-learning ranking, large language models or video sentiment analysis, if it screens or ranks candidates it is high-risk.

The narrow exception under Article 6(3) — for systems that pose no significant risk to health, safety or fundamental rights — does not apply to systems that perform profiling of individuals. Screening systems that score, rank or filter individual applicants always involve profiling and cannot rely on this exception.

Obligations for Deployers (Article 26)

Human Oversight (Article 14)

The system must be designed and used in a way that enables natural persons to effectively oversee it. Concretely:

  • A qualified member of staff must be able to understand the output — not just receive a shortlist, but understand why candidates were ranked as they were.
  • That person must have the authority and the practical means to override or disregard the system's output.
  • Oversight must be genuine: a rubber-stamp review process that systematically confirms the AI's output does not satisfy Article 14.

Log Retention (Article 26(6))

Deployers must retain operational logs generated by the AI system during its lifecycle, to the extent these are under their control. The minimum retention period is six months, subject to longer periods under GDPR or national law. Logs must enable reconstruction of which decisions or recommendations the system made.

Information to Job Applicants (Article 50)

Where applicants interact with an AI system — for example through an automated video interview or AI-scored test — they must be informed. This obligation applies from 2 August 2026. For systems that use general-purpose AI (GPAI) models as their underlying layer, transparency obligations under the GPAI rules apply earlier.

Informing Workers and Representatives

Before deploying a high-risk AI system that affects existing employees (for example, an internal mobility ranking tool), you must inform and consult employees and their representatives (Article 26(7)). This supplements any applicable labour law obligations under national law.

AI Literacy (Article 4)

Article 4 has been applicable since 2 February 2025. It requires you to ensure that staff who work with or make decisions based on the AI system have sufficient AI literacy — an adequate level of understanding of the system's capabilities, limitations, and potential for bias. This applies now, not in 2026.

Practically: recruiters and hiring managers who use AI-assisted shortlisting should receive documented training before they use the tool.

Key Dates

DateEvent
2 February 2025Article 4 (AI literacy) applicable
2 August 2026Full EU AI Act applicability, including enforcement and fines
2 December 2027Digital Omnibus (adopted EP 16 June 2026, Council 29 June 2026) defers Annex III obligations; awaiting Official Journal publication

Until the Digital Omnibus is published in the Official Journal and enters into force, the applicable date remains 2 August 2026.

Documentation You Need

A minimum documentation set for high-risk recruitment AI includes:

  1. A system identification record: what the system does, who the vendor is, what Annex III category it falls under.
  2. A risk assessment: known bias risks, mitigation controls, residual risk acceptance.
  3. A human oversight policy: who reviews outputs, with what authority, how overrides are recorded.
  4. AI literacy training records: who was trained, when, on what curriculum.
  5. Log retention policy: where logs are stored, for how long, who has access.
  6. Applicant information: how and when you inform candidates about AI use.

PowerQuant Module 1 delivers this documentation as a structured evidence pack — source-cited against the Regulation, with a defined delivery schedule.

Explore Module 1 → | Contact us →