AI in HR and Recruitment: Why Most Hiring Tools Are Now "High-Risk"
AI in HR and Recruitment: Why Most Hiring Tools Are Now “High-Risk”

AI in HR and Recruitment: Why Most Hiring Tools Are Now “High-Risk”

HR & Employment AI · 11 min read · Updated March 2026

The average enterprise uses between 8 and 15 AI-powered tools across its recruitment and HR function — applicant tracking systems, CV screening software, video interview analysis, employee monitoring dashboards, and performance management platforms. Under the EU AI Act, the majority of these are classified as high-risk AI systems under Annex III, Category 4. This article explains exactly which HR tools are in scope, what it means for your organisation as a provider or deployer, and what you need to do before 2 August 2026.

Key Takeaways
  • Annex III, Category 4 is one of the broadest high-risk categories — covering AI used in recruitment, selection, promotion decisions, performance monitoring, and task allocation.
  • This applies to your organisation whether you built the HR AI tool (Provider) or simply use a vendor’s tool (Deployer) — both carry mandatory legal obligations.
  • The most commonly overlooked in-scope systems: ATS ranking algorithms, video interview scoring, employee monitoring software, and workforce management tools.
  • HR technology vendors who have not completed their conformity assessment by August 2026 create direct compliance risk for their deployer customers.

Annex III, Category 4 of the EU AI Act covers AI systems used in the context of employment, workers management, and access to self-employment. The category is one of the most expansive in Annex III — deliberately so, because lawmakers recognised that AI-driven employment decisions affect individuals’ fundamental rights at scale and often without their knowledge.

Annex III, Category 4 — Full Legal Text

“AI systems intended to be used for recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates in the course of interviews or tests.”

“AI systems intended to be used to make decisions on promotion and termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics as well as to monitor and evaluate performance and behaviour of persons in such relationships.”

The category spans the entire employment relationship — from pre-hiring through to termination. This is not limited to recruitment software. If AI is involved in any employment decision affecting an individual, Category 4 is likely in scope.

Why HR AI specifically?
The OECD’s AI in Work reports and the European Parliament’s own research documented consistent evidence of algorithmic bias in hiring — AI systems that systematically disadvantaged women, older candidates, non-native speakers, and members of ethnic minorities. Amazon’s infamous internal AI recruiting tool that downgraded CVs containing the word “women’s” became a widely cited case study that directly informed the legislative debate. Category 4’s broad scope is a deliberate response to this evidence base.

2. Which HR AI Systems Are In Scope?

The following categories of HR AI tools are presumptively high-risk under Category 4. Note that classification depends on function, not what the vendor calls the product.

High-Risk ✓ CV Screening and Applicant Ranking AI

What it covers: Any AI system that scores, ranks, filters, or shortlists job applicants based on their CVs, cover letters, application forms, or linked professional profiles (LinkedIn, GitHub, etc.).

Examples: ATS ranking engines (Workday, Greenhouse, Lever AI features), LinkedIn Recruiter AI matching, CV parsing tools that weight applicant attributes, “talent intelligence” platforms that score candidate-job fit.

Most organisations using any major ATS platform are already deploying Category 4 high-risk AI without realising it. The ranking algorithm is embedded in the platform, not a separate product purchase.
High-Risk ✓ Video Interview Analysis AI

What it covers: AI that analyses recorded or live video job interviews — assessing speech patterns, word choice, facial expressions, body language, or vocal tone — to produce a candidate score or recommendation.

Examples: HireVue AI (now reformed following regulatory pressure but still scoring candidates), Pymetrics, Retorio, Talview, and many others. Any vendor claiming to assess “culture fit” or “soft skills” through AI analysis of video.

Additional risk: Facial expression analysis for emotion inference in workplace contexts is prohibited under Article 5(1)(f) with narrow exceptions. Verify that your video interview AI does not cross into prohibited emotion recognition before treating it as merely high-risk.
High-Risk ✓ Employee Performance Monitoring and Evaluation AI

What it covers: AI systems that monitor employee work activity, evaluate output quality, calculate productivity scores, or generate performance assessments that materially influence employment decisions.

Examples: Productivity monitoring software that tracks keystrokes, mouse movements, screen content, or application usage to generate employee productivity scores. AI-driven call centre performance scoring. Algorithmic performance review systems that generate ratings fed into promotion or bonus decisions.

This category became one of the most controversial in EU AI Act negotiations. Remote work surveillance tools that became widespread during COVID-19 are precisely the systems Category 4 is designed to regulate.
High-Risk ✓ Algorithmic Task Allocation and Workforce Management

What it covers: AI systems that autonomously allocate tasks, shifts, routes, or work assignments to individuals based on their performance history, behaviour data, or predicted capability — particularly where the allocation has material consequences for pay or employment status.

Examples: Delivery driver routing algorithms that affect earnings through delivery assignment patterns. Gig economy dispatch systems (Uber, Deliveroo, Amazon Flex). Contact centre workforce management platforms. Algorithmic shift scheduling systems that use performance data to allocate premium shifts.

High-Risk ✓ AI-Driven Promotion, Demotion, and Termination Recommendations

What it covers: Any AI system whose output materially influences decisions about employee career progression, grade changes, contract renewals, or termination — including “attrition risk” scoring systems that identify employees likely to leave or to be made redundant.

Examples: People analytics platforms that provide “flight risk” or “promotion readiness” scores. HR HRIS systems with AI-driven succession planning features. Redundancy selection support tools that score employees for restructuring decisions.

3. What Is NOT In Scope Under Category 4

Not all AI in the HR function is high-risk. These use cases are generally outside Category 4’s scope — though each requires individual assessment based on its specific implementation:

HR chatbots and employee FAQ tools — AI that answers employee questions about policies, benefits, or processes without influencing employment decisions. These may trigger Article 50(1) chatbot disclosure obligations but are not Category 4 high-risk.
AI-assisted job description writing — generative AI used to draft job postings for human review and approval. The AI is a writing tool, not a decision-making system affecting candidates.
Payroll processing AI — systems that automate payroll calculations based on defined rules. These apply fixed logic to known inputs; they do not assess individual behaviour or make employment-related decisions about specific persons.
Learning and development recommendation engines — AI that recommends training courses to employees based on their role or learning history, where these recommendations have no material effect on their employment status, pay, or career progression.
People analytics dashboards (borderline) — Analytics tools providing aggregate workforce data to managers are generally not high-risk. However, if the dashboard surfaces individual-level scores, flags, or predictions about specific employees that managers use in employment decisions, it may be in scope. Assess based on how the output is actually used.

4. Obligations for HR Technology Providers (Vendors)

If you develop and sell HR AI software, you are a Provider under the EU AI Act and carry the full weight of high-risk AI obligations. This is non-negotiable — your terms of service cannot contract out of these obligations or transfer them to your customers.

ObligationArticleWhat it means for HR tech vendors
Risk Management SystemArt. 9Document all foreseeable risks including bias, discrimination, and misuse. Include recruitment-specific failure modes: protected characteristic bias, automation bias by recruiters, gaming of the scoring system by candidates.
Data Governance & Bias TestingArt. 10Training data must be examined for bias across protected characteristics (gender, age, race, disability, nationality, religion). Bias testing results must be documented with actual numbers — not just assertions of fairness. Disaggregated performance metrics across demographic groups are required.
Technical DocumentationArt. 11 + Annex IVFull Annex IV documentation including model architecture, training data provenance, bias testing methodology and results, accuracy benchmarks, and post-market monitoring plan.
Human Oversight DesignArt. 14Build override mechanisms enabling recruiters to reject AI recommendations without friction. Surface confidence scores and contributing factors for each candidate ranking. Design dashboards showing aggregate bias metrics that deployers can monitor.
Conformity AssessmentArt. 43Self-assessment is permitted for most Category 4 systems. Complete against Articles 8–15 with documented evidence. CE marking follows. (Note: the Digital Omnibus package proposes a potential 1-year extension for Category 4 specifically — but do not pause based on an uncommitted proposal.)
EU AI Database RegistrationArt. 49Register before market placement. Include your product name, version, Annex III category, intended purpose, and Declaration of Conformity reference. Your customers can — and should — verify your registration.

5. Obligations for Deployers (Employers Using HR AI)

If your organisation uses a third-party HR AI tool, you are a Deployer — and Article 26 assigns you specific obligations that sit alongside your vendor’s Provider obligations. These are not dischargeable simply because you didn’t build the tool.

1
Verify vendor conformity assessment. Before deploying any Category 4 HR AI tool, verify that your vendor has completed their conformity assessment and is registered in the EU AI database. Request a copy of their Declaration of Conformity. If your vendor cannot provide this by August 2026, deploying their system creates compliance risk for your organisation.
2
Implement the vendor’s specified human oversight measures. Your vendor’s Instructions for Use will specify what human oversight procedures must be in place. Designate named oversight officers for each HR AI system. Train recruiters and HR managers to understand the AI’s outputs, recognise automation bias, and exercise override authority.
3
Maintain 6-month use logs. Article 26(5) requires deployers to retain logs of the AI system’s use for a minimum of 6 months. For HR AI this means: candidate ranking data, decisions taken and whether the AI recommendation was followed or overridden, and the outcome (hire/reject). These logs are producible to national authorities and potential claimants in discrimination cases.
4
Conduct a Fundamental Rights Impact Assessment (FRIA). Article 27 requires deployers using Category 4 AI in regulated contexts to complete a FRIA before deployment. For HR AI, this means assessing the potential impact on candidates’ and employees’ rights — including freedom from discrimination, right to work, and data subject rights. The FRIA must be documented and available to authorities on request.
5
Inform employees and candidates. Article 26(6) requires deployers using Category 4 HR AI that affects individuals to inform those individuals. Candidates must be told their application is being processed by AI. Employees must be informed when AI is used in monitoring or performance evaluation. This has significant implications for recruitment communications and employee handbook policies.

6. The GDPR Overlap: Dual Compliance in Employment AI

Almost all Category 4 HR AI systems process personal data about identifiable individuals — making GDPR simultaneously applicable. The two frameworks overlap substantially in the employment context, requiring compliance with both sets of obligations.

TopicGDPR RequirementEU AI Act Requirement
Automated decisionsArt. 22 GDPR: right not to be subject to solely automated decisions; right to explanationArt. 14: human oversight capability required; Art. 26: deployer must inform individuals of AI use
Legal basisLegitimate interest, contract performance, or (rarely) consent for employment data processingNo separate legal basis required — but AI Act compliance does not substitute for GDPR legal basis
Impact assessmentDPIA required for systematic automated processing of employees/candidatesFRIA required under Art. 27; EDPB recommends integrating DPIA and FRIA into a single exercise
Data retentionRetention only as long as necessary for the processing purpose6-month use logs required (Art. 26); training data documentation retained 10 years (Art. 18)
Practical recommendation for HR and legal teams
Run a single joint assessment covering both GDPR and EU AI Act obligations for each Category 4 HR AI system. Map your existing DPIA to include FRIA questions. Ensure your DPO and HR compliance lead work together — this is not a task either can complete in isolation. The EDPB’s Opinion on AI Act and GDPR interaction is essential reading for anyone coordinating these two compliance programmes.

7. How to Audit Your HR Tech Vendor for EU AI Act Compliance

As a deployer, your vendor’s compliance is your compliance risk. If your ATS vendor has not completed their conformity assessment by August 2026, your use of their system creates exposure. Send the following questions to every HR AI vendor before August 2026:

HR AI Vendor Due Diligence Questionnaire
1
Have you classified your [product name] as a high-risk AI system under Annex III, Category 4 of the EU AI Act? If not, please provide your written classification rationale.
2
Have you completed or do you have a documented plan to complete your EU AI Act conformity assessment by 2 August 2026? What is your current estimated completion date?
3
Please provide or describe your bias testing methodology and results across protected characteristics, as required by Article 10 of the EU AI Act.
4
Does your system’s human-machine interface enable our recruiters to override AI recommendations with a single action, without requiring additional approval? Please describe the override mechanism.
5
Will you be registered in the EU AI Act database (Article 49) before we begin using your system in EU operations? Please confirm your expected registration date and how we can verify your registration.
6
What are your contractual commitments regarding EU AI Act compliance? Will you indemnify us for any regulatory penalties we incur as a result of your non-compliance with provider obligations?

8. Your August 2026 Action Plan

Q1
Now — April 2026: Inventory and Classification
List every HR and recruitment AI tool in use. Classify each against Category 4. Use our free risk assessment tool for each system. Send vendor due diligence questionnaires. Appoint an HR AI compliance lead.
Q2
April — June 2026: Assessment and Gap Analysis
Complete FRIA for each deployed Category 4 system. Integrate with existing GDPR DPIAs. Review vendor responses and escalate non-compliant vendors. Begin training HR and recruitment teams on oversight obligations and anti-bias procedures.
Q3
June — August 2026: Implementation and Documentation
Implement Article 26(6) candidate and employee AI disclosures across recruitment communications and employee handbooks. Activate 6-month use log retention. Verify all vendor registrations in EU AI database. Run tabletop oversight exercises with HR team.
The complete Category 4 compliance checklist
Our 4-phase compliance checklist covers every Category 4 obligation for both providers and deployers — with article references and practical tips for each step.
View Compliance Checklist →

9. Frequently Asked Questions

Can we use a high-risk HR AI tool if the vendor hasn’t completed their conformity assessment? +
Technically, as a Deployer you have separate obligations from the Provider — your obligations under Article 26 do not require your vendor to have completed their conformity assessment before you deploy. However, if the vendor has not completed their conformity assessment by August 2026, this is a strong indicator that their system may not meet the technical requirements of Articles 9–15. Using a non-conformant high-risk AI system creates reputational, legal, and regulatory risk. Contractually, ensure your vendor agreement requires EU AI Act conformity and indemnifies you against regulatory penalties arising from their non-compliance.
We only use AI to score candidates — a human makes the final decision. Does Category 4 still apply? +
Yes. Category 4 covers AI that “filters job applications” and “evaluates candidates” — it does not require the AI to make the final decision autonomously. Even where a human makes the formal hiring decision, an AI system that produces a ranked shortlist, a pass/fail recommendation, or a numerical score that materially influences the human’s decision is in scope. The “human in the loop” argument does not remove Category 4 classification — it is relevant to the compliance approach (Article 14 human oversight) but not to whether the system is high-risk in the first place.
What must we tell candidates about AI use in our recruitment process? +
Article 26(6) requires deployers to inform individuals subject to decisions made with high-risk AI. For candidates, this means: disclosing in your privacy notice and application process communications that AI is used to evaluate applications; explaining what the AI assesses (CV data, video interview responses, etc.); informing candidates of their right to explanation for AI-influenced decisions; and providing information on how to request human review of their application. This information must be provided before or at the point of data collection — not after a decision has been made. Work with your legal team to update recruitment privacy notices and application communications before August 2026. For more on the full EU AI Act obligations, see our EU AI Act Summary.
Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like