EU AI Act: what it is, who it binds and what it means for your HR tech
The AI Act is Regulation (EU) 2024/1689, the first horizontal artificial intelligence framework in the world. This guide explains what the regulation says, why recruitment software appears explicitly in its high-risk list, and what changes in practice for a company that already runs AI in production.
Updated August 2026
Most companies that fall within the scope of the AI Act do not know it yet. Almost everything written about the regulation talks about foundation models and existential risk, and very little about the concrete case that is actually in the text: software that filters CVs. This guide is about that.
What the AI Act is and who it binds
The AI Act is Regulation (EU) 2024/1689, adopted in June 2024. It is the first horizontal artificial intelligence framework in the world: it does not regulate a specific sector, it regulates AI systems according to the risk their use creates for health, safety and fundamental rights. Being a regulation, it applies directly across every member state with no need for national transposition.
The regulation distinguishes two main roles, defined in Article 3, and obligations differ substantially depending on which one applies to you:
- Provider: whoever develops an AI system and places it on the market or puts it into service under its own name or trademark. It carries the bulk of the obligations when the system is high risk: risk management, data governance, technical documentation, logging, human oversight and conformity assessment.
- Deployer: whoever uses the system under its authority in its professional activity. Its obligations are lighter but real: use the system in line with the instructions, ensure human oversight and inform the people affected.
The regulation has extraterritorial reach. It also binds companies outside the European Union when they place a system on the EU market, put it into service here, or when its output is used within the Union. Being incorporated in Delaware or London does not take you out of scope if your customers recruit in Europe.
There is also one obligation that applies to everyone, providers and deployers alike, whatever the risk level: Article 4 requires ensuring a sufficient level of AI literacy among the staff dealing with the operation and use of these systems. It has been in force since 2 February 2025.
The four risk levels
The AI Act does not classify technologies, it classifies uses. The same language model can sit in minimal risk inside an internal documentation assistant and in high risk inside a product that scores candidates. The pyramid has four levels:
| Level | What it is | Example | What it requires of you |
|---|---|---|---|
| Unacceptable risk | Practices prohibited across the Union (Art. 5) | Inferring emotions of a person in the workplace or in educational institutions, except for medical or safety reasons (Art. 5(1)(f)) | Prohibited since 2 February 2025. Top-tier penalties: up to 35 million euros or 7 % of worldwide turnover |
| High risk | Systems listed in Annex III or embedded in already regulated products under Annex I | AI intended for the recruitment or selection of natural persons (Annex III, point 4) | Risk management, data governance, technical documentation, event logging, human oversight, conformity assessment and registration in the EU database |
| Limited risk | Systems subject to transparency duties (Art. 50) | A chatbot handling candidate queries; job descriptions or videos generated with AI | Inform the person that they are interacting with an AI system and mark synthetic content. Separate timeline, from August 2026 |
| Minimal risk | Everything else | Candidate database deduplication, spam filters | No specific obligations beyond the AI literacy duty in Art. 4 |
A single product can have pieces at different levels. An ATS with a candidate-facing chatbot, a matching engine and a job description generator is touching three cells of that table at once. Classification is done per system and per intended purpose, not per company.
Why HR tech is squarely in scope
Employment is not an expansive reading of the regulation: it is an express entry. Annex III, point 4, includes among high-risk systems those intended for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter applications and to evaluate candidates. The same point covers systems intended to make decisions on promotion or termination of contractual relationships, to allocate tasks and to monitor and evaluate performance and behaviour.
Translated into product features, that reaches things that are standard in any HR tech today:
- Automated CV screening that rejects or flags applications before a human sees them.
- Matching engines that rank a list of candidates by fit with the vacancy.
- Interview copilots that transcribe, summarise and score the person being interviewed.
- Publication of job advertisements targeted at specific population segments.
- Continuous performance evaluation or task allocation tools already inside the company.
The consequence is uncomfortable but clear: if you sell recruitment software with AI in it, the default position is that you are in Annex III. The relevant question is not whether the regulation applies to you, but whether you can justify in writing that a specific system of yours falls outside it.
The Article 6.3 exception and why it is narrower than it looks
Article 6.3 allows a system listed in Annex III not to be considered high risk when it does not pose a significant risk of harm to health, safety or fundamental rights, and in particular when it does not materially influence the outcome of decision making. The article itself lists the cases:
- The system performs a narrow procedural task.
- The system improves the result of a previously completed human activity.
- The system detects decision-making patterns or deviations from prior patterns, without replacing or influencing the human assessment already carried out.
- The system performs a preparatory task for an assessment.
There are two reasons why this door is narrower than people usually assume. The first is the profiling cut-off: the exception never applies if the system performs profiling of natural persons. A good share of matching engines build exactly that, an inferred profile of the candidate from their data, even if internally you call it scoring or fit.
The second is the ranking argument. It is common to argue that a matching engine only sorts and that the decision remains with the recruiter. In practice, if the system returns 400 ranked candidates and the recruiter opens the first ten, the ranking decided. Material influence on the outcome is measured by the real effect on the decision, not by where the final button sits.
And even if you conclude that the exception applies, it is not a silent self-exemption: the provider must document its assessment before placing the system on the market. Article 6.3 does not remove the analysis work, it turns it into a document you will have to show.
Provider or deployer: Article 25
Many engineering teams assume that because the model belongs to someone else, so do the obligations. Article 25 says otherwise. A deployer, distributor or importer is considered to be a provider of a high-risk system, with everything that entails, in three cases:
- It puts its name or trademark on a high-risk system already placed on the market.
- It makes a substantial modification to a high-risk system already on the market or in service.
- It modifies the intended purpose of an AI system, including a general-purpose one, in a way that makes it high risk.
The typical HR tech case is "we only call the OpenAI API". If you wrap that model in your product, sell it under your brand and give it a purpose of screening or evaluating candidates, you are in the first and the third case at the same time. The heaviest obligations then travel with you and not with the lab that trained the model, and you will need enough technical information from it to be able to meet them.
The real timeline, including the Digital Omnibus deferral
The AI Act did not become applicable all at once: each block of obligations has its own date, and in 2026 that timeline moved. This is the current state:
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Prohibited practices (Art. 5) and the AI literacy obligation (Art. 4) | In force |
| August 2026 | Transparency duties under Art. 50: disclose AI interaction and mark synthetic content | In force, separate timeline |
| 2 August 2026 | AESIA reaches full capacity in Spain to inspect, request evidence and impose penalties | In force |
| 2 December 2027 | Obligations for high-risk systems under Annex III, employment included | Deferred from 2 August 2026 by the Digital Omnibus |
| 2 August 2028 | Obligations for high-risk systems under Annex I, already regulated products | Deferred from 2 August 2027 |
The provisional Digital Omnibus agreement of 7 May 2026 introduced the first amendments to the AI Act and deferred the Annex III obligations by sixteen months, from 2 August 2026 to 2 December 2027. The reason was technical: the harmonised standards being prepared by CEN and CENELEC through committee JTC 21 were not ready, and might not be ready before December 2026. Without a published standard there is no presumption of conformity.
That presumption is often misread. Whoever develops in line with a harmonised standard enjoys a presumption of conformity with the corresponding requirements of the regulation, but only once that standard has been published in the Official Journal of the European Union. Working from a draft is prudent and saves redoing the work, but it grants no presumption at all.
In Spain, the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) has full capacity to inspect, request evidence and impose penalties since 2 August 2026. Spanish law splits competences between AESIA and other authorities depending on the domain: the data protection authority AEPD, the General Council of the Judiciary, the Bank of Spain and the securities regulator CNMV. Top-tier fines reach 35 million euros.
What this means in practice for your HR tech
Here is the point that usually gets missed. The Omnibus deferral moved the date of the legal obligation, but not the date on which your customer asks. Procurement questionnaires and enterprise due diligence already include AI Act questions, because the buyer in turn needs to answer to its own risk function. A contract stalled by an unanswered questionnaire is a problem this quarter; a 2027 penalty can be planned for.
What those questionnaires ask is fairly consistent:
- Risk classification of the system and a written justification, including the Article 6.3 assessment if you rely on the exception.
- Your role in each system, provider or deployer, and how you determined it in light of Article 25.
- Inventory of models and versions in production, including third-party ones and dependencies on their APIs.
- What data is used to train or fine-tune and what bias testing has been carried out on the outputs.
- How human oversight is implemented: what the person sees, what they can change and whether it is logged.
- Traceability: which events are logged, how long they are retained and whether they allow a decision to be reconstructed months later.
- What the candidate is told and when, and how it fits with the GDPR: legal basis, Article 22 and the impact assessment.
The difference between answering that well or badly is rarely technological. It is documentary. Teams that get stuck do not have a worse system, they have the same information spread across the heads of two engineers, an outdated Notion page and a repository with no inventory. What has to be produced is verifiable evidence, not statements of intent.
What the AI Act is not
Three misunderstandings come up in almost every conversation, and all three lead to spending money in the wrong place:
- It is not a certification. There is no "AI Act certified company" badge you can buy and display on your website. For high risk what exists is a conformity assessment and the CE marking, and the technical route to evidence it will be the harmonised standards once they are published.
- It does not ban AI in human resources. It bans specific practices under Article 5, such as inferring the emotions of a person in the workplace except for medical or safety reasons, and subjects the remaining recruitment uses to quality, documentation and oversight requirements. Using AI for hiring is lawful if it is done with the controls the regulation demands.
- It does not replace the GDPR. They apply in parallel. A recruitment process involves personal data of candidates, frequently an automated individual decision within the meaning of Article 22 GDPR and, almost always, the need for an impact assessment. In Spain, AESIA supervises the AI Act and the AEPD supervises data protection.
Frequently asked questions about the AI Act
The EU AI Act is Regulation (EU) 2024/1689, adopted in June 2024, and it is the first horizontal artificial intelligence framework in the world. It classifies AI systems into four levels according to the risk of their use: unacceptable risk (practices prohibited by Article 5), high risk (Annexes I and III), limited risk (transparency duties under Article 50) and minimal risk. Being a regulation, it applies directly in every member state.
It applies mainly to providers, who develop an AI system and place it on the market under their own name or trademark, and to deployers, who use it under their authority in their professional activity (Article 3). It also reaches companies established outside the European Union when they place a system on the EU market, put it into service here, or when its output is used within the Union.
By default, yes. Annex III, point 4, of the AI Act classifies as high risk those AI systems intended for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter applications and to evaluate candidates, as well as systems intended to decide on promotion or termination, allocate tasks and monitor performance. A specific system may fall outside through the Article 6.3 exception, but that has to be assessed and documented before placing it on the market.
The provisional Digital Omnibus agreement of 7 May 2026 deferred the obligations for high-risk systems under Annex III by sixteen months, from 2 August 2026 to 2 December 2027. Those under Annex I, covering already regulated products, moved from 2 August 2027 to 2 August 2028. The reason was that the harmonised standards from CEN and CENELEC, drafted by committee JTC 21, were not ready. The prohibited practices in Article 5 and the AI literacy duty in Article 4 have applied since 2 February 2025.
It is possible, but the door is narrow. Article 6.3 exempts Annex III systems that do not pose a significant risk of harm, for example when they perform a narrow procedural task, improve the result of a previously completed human activity, detect decision-making patterns without replacing the human assessment, or carry out a preparatory task. The exception never applies if the system performs profiling of natural persons, and the provider must document its assessment before placing the system on the market.
It can. Article 25 of the AI Act establishes that a deployer, distributor or importer is considered a provider of a high-risk system if it puts its name or trademark on it, makes a substantial modification, or modifies its intended purpose in a way that makes it high risk. Wrapping a third-party model inside your product, selling it under your brand and giving it a purpose of screening or evaluating candidates fits those cases, and shifts the heaviest obligations to your company.
There is no badge certifying a company as compliant with the AI Act. For high-risk systems the regulation provides for a conformity assessment and the CE marking. Whoever develops in line with a harmonised standard will enjoy a presumption of conformity, but only once that standard is published in the Official Journal of the European Union: working from a draft is prudent, but grants no presumption.
No. Both apply in parallel and cover different things. A recruitment process involves personal data of candidates, frequently an automated individual decision within the meaning of Article 22 GDPR and the need for an impact assessment. In Spain, AESIA supervises the AI Act from 2 August 2026 and the AEPD supervises data protection; complying with one does not exempt you from the other.
Keep reading
- RegulationHow a financial regulator tests AI (and what your HR-tech learns from it)
- Prohibited practicesEmotion recognition at work is not ‘high-risk’: it is prohibited
- SpainAESIA can now inspect and fine: what it looks for in an HR-tech
- RegulationThe Omnibus moved 2 August to December 2027. Your procurement will not wait
- ConformityWhy December 2027 is no breather: harmonised standards and presumption of conformity
- ClassificationIs your matching or screening "high-risk"? How to read Annex III (employment)
- ClassificationYou put your brand on OpenAI or Gemini: are you a provider? (Art. 25)
- Data protection‘Hired by an algorithm’: the AI Act does not free you from the GDPR