The EU AI Act is the world's first comprehensive law governing artificial intelligence, and recruitment sits close to its centre. Hiring is explicitly classified as a high-risk use of AI, and some hiring practices are banned outright. For recruiters, HR leaders and the vendors who serve them, this is no longer a distant policy debate — it is a compliance programme with real deadlines and severe penalties. This guide sets out what you need to know, without the legalese.
Why Recruitment Is Treated as High-Risk
The Act sorts AI systems into tiers by the risk they pose to people. Recruitment lands in the high-risk category because hiring decisions materially affect people's livelihoods and access to opportunity. Systems used to recruit or select people — to screen or filter applications, to rank candidates, or to evaluate them — are named as high-risk uses in the Act's Annex III.
Being high-risk does not mean banned. It means permitted only under strict conditions: risk management, transparency, human oversight, record-keeping and monitoring. The logic is that AI can play a role in hiring, but only when the organisation can demonstrate the system is safe, fair and accountable.

The Deadlines — and an Important Nuance
The Act applies in phases, and getting the timeline right matters.
The prohibitions took effect first. Since 2 February 2025, the practices the EU considers unacceptable have been banned — including the use of AI to infer emotions in the workplace. This is already in force. If you use a tool that reads candidates' emotions from their face or voice, you are not preparing for a future rule; you are potentially in breach today.
The high-risk obligations — the ones that apply to CV-screening and candidate-ranking systems — come later, and here is where recruiters must be careful. The obligations for high-risk systems were originally set to apply from 2 August 2026. However, the EU has moved to defer parts of the high-risk regime, with proposals pushing key obligations for Annex III systems into late 2027 — commonly discussed around December 2027. You will see different dates cited, some referencing August 2027, because the deferral has been evolving. The safe posture is to treat the timeline as firming up toward late 2027 for full high-risk obligations, while recognising the prohibitions already bite now, and to build compliance capability rather than betting on the latest possible date.
The penalties concentrate the mind regardless of the exact date. Breaching the prohibitions can cost up to €35 million or 7% of global annual turnover. Non-compliance with high-risk obligations can reach €15 million or 3% of turnover. These are ceilings scaled to global revenue, not token fines.
Are You a Provider or a Deployer?
The Act assigns different duties depending on your role. A provider builds or substantially modifies an AI system and places it on the market. A deployer uses one under its own authority. Most recruiters and employers are deployers: they buy a tool from a vendor and apply it to their candidates.
This distinction matters because it defines what you are responsible for. As a deployer of a high-risk recruitment system, your obligations are substantial and cannot be fully outsourced to the vendor.
What Deployers Must Do
Several duties fall specifically on the organisation using the tool.
Ensure meaningful human oversight. A competent person must oversee the system's use and be genuinely able to override it. Oversight that rubber-stamps every recommendation does not satisfy the requirement.
Be transparent with candidates. People are entitled to know when a high-risk AI system is being used in decisions that affect them. Disclosure is not optional courtesy; it is a legal expectation, and it aligns with candidate-notice rules already live in jurisdictions such as New York City and Illinois.
Keep records. High-risk systems generate logs of their operation, and deployers are expected to retain them so that decisions can be reviewed and, if necessary, defended. Retained logs are both a compliance duty and your best evidence if a decision is challenged.
Monitor and use the system as intended. Deployers must use the tool in line with its instructions and keep an eye on how it performs in practice, escalating problems rather than letting a drifting system run unchecked.
Use the provider's information. Providers must supply instructions and documentation about the system's capabilities, limitations and appropriate use. Deployers are expected to act on that information, not file it away unread.
What to Ask Your Vendors
Because much of the technical burden sits with providers, your due diligence on vendors is now a compliance activity in its own right. Ask each vendor to confirm, in writing, how their system meets the Act's requirements: what data it was trained on, what it was validated against, how bias is tested, what logging it provides, and how human oversight is supported. A vendor that cannot answer these questions is selling you not just a tool but a liability.
This is more than caution. Litigation elsewhere has already tested whether tool vendors can be held responsible for discriminatory outcomes, and the direction of travel is toward shared accountability. The contract and documentation you secure now are what will protect you later.
A Practical Preparation Plan
Start by building an inventory. List every AI or automated tool touching your hiring process, what each one does, and what data it uses. You cannot comply with rules for systems you have not catalogued.
Next, triage against the Act. Identify anything that infers emotion from biometric data — that is prohibited now and should be stopped. Then flag your screening, ranking and evaluation tools as high-risk and subject to the deployer obligations above.
Then close the gaps. For each high-risk system, confirm you have meaningful human oversight, candidate transparency, retained logs, and monitoring in place — and gather the vendor documentation that supports them. Assign a named owner for AI compliance in hiring, so the responsibility does not fall between HR, legal and procurement.
Finally, treat this as ongoing, not a one-time project. The regime is still settling, deadlines are firming up, and your own tools will change. Organisations that stand up a durable compliance capability now — rather than scrambling as each deadline arrives — will find the EU AI Act a manageable framework rather than a crisis. The law is demanding, but it rewards those who prepare deliberately over those who wait to be caught out.
