Is your matching or screening "high-risk"? How to read Annex III (employment)
Annex III point 4 marks much of hiring AI as high-risk. The Article 6.3 exception is narrower than it looks.
Regulation (EU) 2024/1689 classifies certain AI uses as high-risk, and employment is one of the areas expressly named. If you build matching or screening, this is a reading you cannot fully delegate to legal: part of the analysis is about what your product actually does in practice.
What Annex III point 4 says
Annex III, point 4, flags as high-risk AI intended for:
- Selection and recruitment: placing targeted job ads, filtering applications and evaluating candidates.
- Decisions on promotion or termination of working relationships.
- Task allocation and performance monitoring.
Most functions of an AI hiring product fall within that description without much ambiguity. Filtering applications and evaluating candidates is, almost by definition, the core function of these tools.
The Article 6.3 exception is narrow
Article 6.3 allows a system to be treated as not high-risk when it does not pose a significant risk to health, safety or rights. But the exception is narrower than many expect: it does not apply if the system performs profiling of people, nor when it merely orders or prioritises in a way that, in practice, conditions the human decision. And the burden is not informal: the provider must carry out the assessment and document it.
Here is the honest point. Code alone cannot determine a system's purpose. You have to walk the decision tree case by case, looking at what the tool does and how it is really used. The classic example is the ranking that "only orders" candidates: on paper it does not decide, but if in practice no one looks past the top positions, that order discards. That kind of nuance is not settled by reading the repository.