The average enterprise uses between 8 and 15 AI-powered tools across its recruitment and HR function — applicant tracking systems, CV screening software, video interview analysis, employee monitoring dashboards, and performance management platforms. Under the EU AI Act, the majority of these are classified as high-risk AI systems under Annex III, Category 4. This article explains exactly which HR tools are in scope, what it means for your organisation as a provider or deployer, and what you need to do before 2 August 2026.
- Annex III, Category 4 is one of the broadest high-risk categories — covering AI used in recruitment, selection, promotion decisions, performance monitoring, and task allocation.
- This applies to your organisation whether you built the HR AI tool (Provider) or simply use a vendor’s tool (Deployer) — both carry mandatory legal obligations.
- The most commonly overlooked in-scope systems: ATS ranking algorithms, video interview scoring, employee monitoring software, and workforce management tools.
- HR technology vendors who have not completed their conformity assessment by August 2026 create direct compliance risk for their deployer customers.
- The legal basis: Annex III, Category 4 in full
- Which HR AI systems are in scope?
- What is NOT in scope under Category 4
- Obligations for HR technology providers (vendors)
- Obligations for deployers (employers using HR AI)
- The GDPR overlap: dual compliance in employment AI
- How to audit your HR tech vendor for EU AI Act compliance
- Your August 2026 action plan
- FAQ
1. The Legal Basis: Annex III, Category 4 in Full
Annex III, Category 4 of the EU AI Act covers AI systems used in the context of employment, workers management, and access to self-employment. The category is one of the most expansive in Annex III — deliberately so, because lawmakers recognised that AI-driven employment decisions affect individuals’ fundamental rights at scale and often without their knowledge.
“AI systems intended to be used for recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates in the course of interviews or tests.”
“AI systems intended to be used to make decisions on promotion and termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics as well as to monitor and evaluate performance and behaviour of persons in such relationships.”
The category spans the entire employment relationship — from pre-hiring through to termination. This is not limited to recruitment software. If AI is involved in any employment decision affecting an individual, Category 4 is likely in scope.
2. Which HR AI Systems Are In Scope?
The following categories of HR AI tools are presumptively high-risk under Category 4. Note that classification depends on function, not what the vendor calls the product.
3. What Is NOT In Scope Under Category 4
Not all AI in the HR function is high-risk. These use cases are generally outside Category 4’s scope — though each requires individual assessment based on its specific implementation:
4. Obligations for HR Technology Providers (Vendors)
If you develop and sell HR AI software, you are a Provider under the EU AI Act and carry the full weight of high-risk AI obligations. This is non-negotiable — your terms of service cannot contract out of these obligations or transfer them to your customers.
| Obligation | Article | What it means for HR tech vendors |
|---|---|---|
| Risk Management System | Art. 9 | Document all foreseeable risks including bias, discrimination, and misuse. Include recruitment-specific failure modes: protected characteristic bias, automation bias by recruiters, gaming of the scoring system by candidates. |
| Data Governance & Bias Testing | Art. 10 | Training data must be examined for bias across protected characteristics (gender, age, race, disability, nationality, religion). Bias testing results must be documented with actual numbers — not just assertions of fairness. Disaggregated performance metrics across demographic groups are required. |
| Technical Documentation | Art. 11 + Annex IV | Full Annex IV documentation including model architecture, training data provenance, bias testing methodology and results, accuracy benchmarks, and post-market monitoring plan. |
| Human Oversight Design | Art. 14 | Build override mechanisms enabling recruiters to reject AI recommendations without friction. Surface confidence scores and contributing factors for each candidate ranking. Design dashboards showing aggregate bias metrics that deployers can monitor. |
| Conformity Assessment | Art. 43 | Self-assessment is permitted for most Category 4 systems. Complete against Articles 8–15 with documented evidence. CE marking follows. (Note: the Digital Omnibus package proposes a potential 1-year extension for Category 4 specifically — but do not pause based on an uncommitted proposal.) |
| EU AI Database Registration | Art. 49 | Register before market placement. Include your product name, version, Annex III category, intended purpose, and Declaration of Conformity reference. Your customers can — and should — verify your registration. |
5. Obligations for Deployers (Employers Using HR AI)
If your organisation uses a third-party HR AI tool, you are a Deployer — and Article 26 assigns you specific obligations that sit alongside your vendor’s Provider obligations. These are not dischargeable simply because you didn’t build the tool.
6. The GDPR Overlap: Dual Compliance in Employment AI
Almost all Category 4 HR AI systems process personal data about identifiable individuals — making GDPR simultaneously applicable. The two frameworks overlap substantially in the employment context, requiring compliance with both sets of obligations.
| Topic | GDPR Requirement | EU AI Act Requirement |
|---|---|---|
| Automated decisions | Art. 22 GDPR: right not to be subject to solely automated decisions; right to explanation | Art. 14: human oversight capability required; Art. 26: deployer must inform individuals of AI use |
| Legal basis | Legitimate interest, contract performance, or (rarely) consent for employment data processing | No separate legal basis required — but AI Act compliance does not substitute for GDPR legal basis |
| Impact assessment | DPIA required for systematic automated processing of employees/candidates | FRIA required under Art. 27; EDPB recommends integrating DPIA and FRIA into a single exercise |
| Data retention | Retention only as long as necessary for the processing purpose | 6-month use logs required (Art. 26); training data documentation retained 10 years (Art. 18) |
7. How to Audit Your HR Tech Vendor for EU AI Act Compliance
As a deployer, your vendor’s compliance is your compliance risk. If your ATS vendor has not completed their conformity assessment by August 2026, your use of their system creates exposure. Send the following questions to every HR AI vendor before August 2026:







