The EU AI Act entered into force on 1 August 2024. Recruitment and employment-related AI can fall within Annex III high-risk use cases, but classification depends on the system's intended purpose and deployment context. As of this review, the European Commission states that rules for high-risk systems in sensitive areas, including employment, apply from 2 December 2027.

This guide explains the current framework, the questions HR teams should ask their vendors, and practical readiness steps. It is written for HR professionals and recruitment leaders, not lawyers; involve qualified counsel for a classification and compliance assessment.

Legal disclaimer

This is not legal advice, consult qualified legal counsel for your specific situation.

What Is the EU AI Act and Why Does It Matter for Recruitment

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It establishes a risk-based classification system: AI applications are categorised as unacceptable risk, high-risk, limited risk, or minimal risk, with corresponding regulatory obligations.

Annex III lists AI systems intended for recruitment or selection, including targeted job advertisements, analysing or filtering applications, and evaluating candidates. Whether a particular tool is high-risk still requires a fact-specific classification, including the provider's intended purpose and any relevant Article 6 exceptions.

Do not assume that every automated feature is high-risk, or that a system avoids the rules merely because a human is involved. Document what the tool does, which decisions it influences and who can meaningfully intervene.

Why Recruitment AI Is Classified as High-Risk

The rationale for high-risk classification is straightforward: AI-driven hiring decisions directly affect people's livelihoods. A flawed algorithm that systematically disadvantages candidates based on gender, age, ethnicity, or disability status causes measurable harm at scale, potentially affecting thousands of applicants before anyone detects the pattern.

The EU legislators identified several specific concerns:

  • Power asymmetry. Candidates have limited ability to understand or challenge AI-driven decisions. They often do not know AI is being used, much less how it scored them.
  • Scale of impact. A single biased algorithm deployed across thousands of applications causes more harm than any individual recruiter's unconscious bias.
  • Historical bias amplification. AI models trained on historical hiring data can encode and amplify past discrimination patterns, as demonstrated by Amazon's abandoned CV screening tool in 2018.
  • Opacity. Many AI scoring systems operate as black boxes, making it impossible for candidates or employers to understand why a particular score was assigned.

Current Timeline: What to Prepare For

The Regulation contains detailed requirements for high-risk systems, but they are not a blanket rule that every ATS must meet immediately. The Commission's current public timeline says the employment high-risk rules apply from 2 December 2027. Before then, teams should identify affected use cases, obtain provider documentation and plan the controls they may need.

RequirementArticleWhat It Means for Your ATS
Risk management systemArt. 9Documented risk identification and mitigation for applicable high-risk systems
Data governanceArt. 10Relevant data-governance controls for applicable high-risk systems
Technical documentationArt. 11Provider technical documentation for the system's intended purpose and operation
Record-keepingArt. 12Logging and record-keeping requirements under the Regulation
TransparencyArt. 13Information enabling deployers to interpret output and use the system appropriately
Human oversightArt. 14Measures that enable effective human oversight where the rule applies
Accuracy and robustnessArt. 15Accuracy, robustness and cybersecurity controls relevant to the system
CybersecurityArt. 15Protection against manipulation and security risks

The Act contains administrative-fine tiers that vary by infringement and organisation. Check the Regulation and applicable Member State law for the current figures and enforcement rules; the existence of a maximum fine does not make every recruitment tool immediately subject to high-risk obligations.

Human Oversight When High-Risk Rules Apply

Where a system is classified as high risk and the relevant rules apply, Article 14 requires it to be designed and developed so it can be effectively overseen by natural persons while in use.

For a current readiness review:

  • Meaningful review. Evaluate whether the process lets people understand and challenge a recommendation rather than merely confirming it.
  • Intervention. Confirm who can pause, override or escalate a result and how that action is recorded.
  • Comprehensible outputs. Ask the provider to explain the output, material limits and expected conditions of use.
  • Separate legal review. Other rules, including GDPR and employment law, can affect automated decisions even where Article 14 is not yet applicable.

How Treegarden addresses human oversight

Treegarden's AI output is advisory and requires manual review. These safeguards can support a human-review process, but they are not a legal determination or a compliance guarantee for a particular deployment.

Transparency Obligations for AI Hiring Tools

For applicable high-risk systems, the Regulation includes transparency requirements that help deployers interpret output and use a system appropriately. Candidate-facing information can also be governed by GDPR and national employment law.

  1. Information for deployers. Ask for the intended purpose, input data, known limitations, human-oversight design and logging information.
  2. Information for candidates. Assess the relevant AI Act, GDPR and national employment-law obligations for the recruitment process; the duty and timing depend on the classification and role.

A provider should be able to explain how its tool is intended to be used and its material limits. That explanation supports assessment, but does not by itself determine the system's legal classification.

Clear explanations support better review

Clear communication about a process can support candidate trust. It is not a substitute for determining the legal status of a particular AI system or for implementing the controls that apply to it.

Technical Requirements: Logging, Accuracy, and Robustness

Where the high-risk requirements apply, the Regulation also addresses logging, accuracy, robustness and cybersecurity:

Automatic Logging (Article 12)

The Regulation includes logging requirements for applicable high-risk systems. The records to keep and the allocation between provider and deployer depend on the role, classification and current implementation schedule. A readiness review should consider:

  • The input data used for each AI decision (candidate profile, job requirements)
  • The AI output (score, recommendation, ranking position)
  • Any human override or intervention
  • Timestamps and user identification for audit traceability

Accuracy and Robustness (Article 15)

For applicable high-risk systems, the Regulation addresses an appropriate level of accuracy, robustness and cybersecurity throughout the lifecycle. A readiness review can include:

  • Regular validation of AI scoring accuracy against real hiring outcomes
  • Protection against adversarial inputs (e.g., CV manipulation to game AI scores)
  • Graceful degradation, the system must remain functional even when the AI component encounters errors
  • Security measures to prevent tampering with AI model outputs

Practical Compliance Checklist for HR Teams

Use this checklist to prepare for a classification conversation with your provider and counsel; it is not a determination that the Act applies to a particular system:

  1. Inventory your AI tools. List every AI component in the hiring process and document its intended purpose, inputs, output and influence on decisions.
  2. Ask the provider for documentation. Request its role, intended purpose, classification analysis, instructions for use, known limits and roadmap.
  3. Map human review. Document where people review, override or escalate recommendations and whether that review is meaningful.
  4. Review outputs. If the tool scores candidates, assess what users can understand about its output and limitations.
  5. Plan records. Identify the logs and evidence needed for an assessment and any applicable requirements.
  6. Review candidate information. Assess the relevant AI Act, GDPR and national employment-law notices with counsel.
  7. Consider testing. Use risk-appropriate testing and bias review rather than relying only on vendor assurances.
  8. Document decisions. Keep a record of the assessment, ownership and mitigation decisions.
  9. Train the team. Ensure users understand the tool's intended use, limits and escalation path.
  10. Assign responsibility. Designate an internal owner for the assessment and implementation work.

Penalties for Non-Compliance: What Is at Stake

The EU AI Act establishes tiered maximum administrative fines. The applicable tier depends on the infringement, the organisation and the current enforcement framework:

  • Prohibited AI practices: up to €35 million or 7% of global annual turnover
  • Other obligations: the Regulation sets separate maximums that should be read in the current legal text
  • Information to authorities: separate maximums can apply to inaccurate, incomplete or misleading information

The Regulation assigns duties differently to providers and deployers. Do not assume a vendor roadmap transfers all responsibility to the employer or vice versa; assign ownership after assessing the tool and your role.

Employment, anti-discrimination and data-protection rules may create separate risk. Obtain advice for the jurisdictions and use cases involved rather than treating a general penalty summary as a decision rule.

How Treegarden Supports Responsible AI Workflows

Treegarden's AI output is advisory and requires manual review. These product controls can support an organisation's review process, but the organisation and its advisers remain responsible for assessing the applicable obligations:

  • Explainable scoring. Every AI candidate score includes a detailed breakdown showing which skills, experience factors, and qualification matches contributed to the score. Recruiters see strengths and weaknesses, not just a number.
  • Human-in-the-loop architecture. Treegarden's AI operates in suggest mode by default. AI recommends pipeline stages and scores candidates, but all decisions require human confirmation. No candidate is automatically rejected based on AI scoring alone.
  • Comprehensive audit trails. Every AI decision, human override, pipeline movement, and score explanation is logged with timestamps and user identification. These logs are exportable for regulatory audit.
  • Candidate transparency. Treegarden supports AI disclosure notices in the application process and provides mechanisms for candidates to request explanation of AI-assisted decisions.
  • Bias monitoring dashboard. Score distribution analytics allow HR teams to monitor AI scoring patterns across demographic groups and detect potential bias before it becomes a compliance issue.
  • GDPR Article 22 integration. Treegarden includes opt-out mechanisms for automated processing and a human review workflow for candidates who exercise their rights.

Support for accountable AI workflows

Treegarden can support workflow documentation, review and auditability. It does not provide a legal determination or guarantee of EU AI Act compliance for a specific deployment. Book a demo to see the workflow controls in context.

Related: Global Compliance & Data Privacy

Explore workflow controls that can support a compliance program alongside legal and operational review.

Explore compliance features →

FAQ

Does the EU AI Act apply to companies outside the EU?

It can apply to organisations outside the EU when their role and AI system activity fall within the Regulation's territorial scope. A US or UK company should not treat the location of an applicant alone as a complete answer; assess the provider or deployer role, intended use and EU-market connection with qualified counsel.

Is basic CV parsing considered high-risk AI under the Act?

It depends on intended purpose and whether the system materially influences recruitment or selection. A feature that only extracts fields may be assessed differently from a scoring or ranking system, but classification must follow the Regulation and current Commission guidance; do not use a generic rule of thumb as a legal determination.

What should I ask my ATS vendor about EU AI Act compliance?

Ask about the system's intended purpose, the provider's role and classification analysis, technical documentation, instructions for use, human-oversight design, logging, known limits and current timeline. A roadmap or feature list is not itself a legal conclusion, so involve counsel in the assessment.

Use the current implementation timeline to plan rather than relying on an earlier date. Prioritise inventory, intended-purpose assessment, provider documentation, human review and records. Treegarden's AI output is advisory and requires manual review; request a demo to see the workflow controls in context.

Authoritative sources and scope

EU AI Act applicability and timing depend on the system's intended purpose, deployment context, and the current legal framework. This guide is general information, not legal advice. Last reviewed: .