← Back to analysis
ResearchBy David CedilloAugust 5, 20266 min read

Spanish HR-tech under the microscope: 44 of 59 fall under Annex III, 45 never mention the AI Act

Our own research across 59 HR-tech companies active in Spain and Europe. We measured what is published, not what is complied with — and the gap between the two is the story.

We reviewed more than 100 HR-tech companies and brands active in Spain or the wider European market, and verified and included 59 of them in an analysis of exposure to Annex III of Regulation (EU) 2024/1689. We are publishing the aggregate result here. No company is named, and none will be: the point is to describe the state of the market, not to single anyone out.

How we did it

The primary and decisive source was each company's own website: home page, product pages, dedicated AI pages, trust centres, legal notices and blog. The starting universe came from sector directories, exhibitor lists from Spanish HR trade fairs, and startup lists published by specialist media. Press coverage was used only for size, funding or acquisitions, never to attribute product features. Data cut-off: the first days of August 2026.

We looked at two things per company. First, whether the public product description includes features that would fall under Annex III point 4: targeted job advertising, analysis and filtering of applications, candidate matching, ranking or scoring, automated interviewing or assessment, and decisions on performance or promotion. Second, whether any public material — product, legal documentation, trust centre or blog — mentions the Regulation at all, using targeted searches across each domain.

What this work does not measure

This has to be said before the numbers, because it changes how they should be read: we measured public communication, not compliance. A vendor may have complete technical documentation and have published not one line about it; in our count it would appear as "no mention found". And the reverse holds too: publishing an explainer article about the Regulation proves nothing. There are also material limits: several sites block automated access, some trust centres render in JavaScript and we could not read their contents, and the exposure classification is our reading of marketing copy, not of a technical architecture that may differ in either direction. Nothing that follows claims that any company is in breach.

The numbers

Across the 59 verified and included companies:

  • 44 of 59 (75%) describe on their own website features that would fall under Annex III point 4.
  • 33 of 59 (56%) show high exposure: screening, matching, ranking or scoring, automated interviewing or assessment described explicitly.
  • 14 of 59 (24%) mention the EU AI Act in some public material.
  • 4 of 59 (7%) mention it only in the marketing blog, not in product or documentation.
  • 45 of 59 (76%) with no mention found at all.
  • 1 of 59 (2%) explicitly self-classifies as a high-risk system.
  • 2 of 59 (3%) declare ISO/IEC 42001.

The cross-tabulation that interests us most combines both columns: 21 of 59 (36%) describe features with high Annex III exposure and, at the same time, have no mention of the Regulation in any public material we were able to read. One in three vendors in this market sits in that box.

Four patterns

First: the gap is not in the technology, it is in the narrative. Four out of five companies describe features that would fall within the scope of Annex III, and fewer than one in three mention the Regulation. Technical capability has been deployed far faster than the account that should accompany it, and that is not an engineering problem but a positioning one.

Second: when the AI Act does appear, it almost always lives in the blog rather than in the product. Of the 16 that mention it, 6 do so exclusively in marketing content, the "what the AI Act is and how it affects you" genre. In other words: the company knows how to explain it to its customer, but has not published what it does about it itself. The knowledge exists, the evidence does not.

Third: the ones automating most are the ones talking least. Vendors with the most aggressive functionality — automatic candidate scoring and ranking, voice interviewers, end-to-end automated screening — are systematically the ones with the thinnest public position. Those who do publish a solid position tend to be assessment providers with decades of validation culture, or startups that made compliance an argument from day one. The bulk of the market sits in the middle, and in silence.

Fourth is specifically Spanish. Incumbents — large staffing groups and traditional HR software — have their AI deployment documented in press releases and trade media, yet almost invisible on their own site. Native startups do the reverse: AI is in the headline of the home page. The incumbent ends up under-documented externally; the native, over-exposed.

Why it matters before December 2027

The Digital Omnibus package deferred the Annex III high-risk obligations to December 2027, and it shows: the market has lowered its guard. But the regulatory and the commercial calendar are not the same calendar. Enterprise procurement questionnaires already include AI questions, and they are not waiting for the date of application to ask them. That 36% with high exposure and no public position is exactly who will go silent in front of a questionnaire — not sixteen months from now, but in the next renewal cycle. Going silent is not a fine: it is a contract that slips or is lost.

And there is a Spanish obligation that has not been deferred. Article 64.4 d) of the Workers' Statute requires employers to inform workers' legal representatives about the parameters and rules underlying the algorithms or AI systems that affect access to and retention of employment, including profiling. It applies today. The party who has to satisfy it is your customer, and to satisfy it they will come and ask you.

The inverted sales argument

The qualitative finding that struck us most is this: at least one Spanish vendor has turned Annex III into an inverted sales argument. It advertises explicitly that its AI does not score, does not rank, does not classify and does not recommend candidates, and cites the AI Act to explain why the product was designed that way. It is not defending itself against an obligation: it is selling with it. That is the first clear sign that here compliance is starting to work as a differentiator and not only as a cost.

If we were one of those 19 companies, we would not start by commissioning a legal opinion. We would start with the boring, verifiable part: inventory which AI systems are actually in the product and for what purpose, classify each one against Annex III point 4, write a single page on what the company does about it, and publish it where procurement can find it. That is not conformity — full conformity is dated 2027 — but it turns silence into an answer.