Europe decided that software which helps choose who gets a job matters as much as software in a medical device - and regulated it accordingly. The AI Act places recruitment and selection systems in its high-risk class, wraps them in obligations, and bans a few practices outright. The deadline recently moved to December 2027, which changes the urgency but not the direction. Here is the employer's version, in plain language.
- AI used for recruiting, screening and selection is classed as high-risk under the AI Act's Annex III - the strictest tier that remains legal.
- The compliance deadline for these standalone high-risk systems moved from August 2026 to December 2027 under the Digital Omnibus - time to prepare, not to ignore.
- Employers using hiring AI are deployers: human oversight with real authority, candidate transparency, log retention and correct use are your side of the bargain.
- Some practices are banned outright already - emotion recognition at work among them - and choosing well-designed tools now spares a painful 2027.
Why is hiring AI high-risk?
Annex III of the Act lists employment as a high-risk domain: systems for advertising to, recruiting, screening, evaluating and selecting candidates, and for decisions on promotion, task allocation and termination. The logic is straightforward - these systems gatekeep livelihoods, and a biased or opaque one does damage at scale, the same concern that drives blind screening thinking. High-risk does not mean discouraged; it means allowed under discipline: documented, tested, overseen, explainable.

Your obligations as a deployer
- Use as directed. Operate the system per the provider's instructions - the compliance chain assumes you do not improvise around it.
- Real human oversight. Assign people with the training and the authority to question and override the system - oversight on paper with no power in practice fails the test.
- Tell the candidates. People screened by AI must know AI is involved and how it influences the process - a plain sentence in the application flow does it.
- Keep the logs. Retain the system's automatically generated logs, at minimum six months, so decisions can be reconstructed.
- Feed it properly. Ensure the input data you control is relevant and appropriate for the tool's purpose - garbage in is now a compliance issue, not just a quality one.
The provider's side - and why your choice of tool is the decision
Risk management, technical documentation, bias testing, accuracy standards, CE-style conformity - that stack belongs to the provider, not to you. Which turns compliance into a procurement question: a tool built on explainable scores, human decision points and clean data practices carries you with it; a black box with an accuracy slide deck leaves you deploying something you cannot answer for. The questions to ask a vendor are the same four from our AI hiring agent guide, plus one: show me the documentation you will hand my regulator.
The GDPR is still here too
The AI Act layers onto data protection rather than replacing it: candidate data minimisation, retention limits, access and erasure rights, and Article 22's guardrails on solely automated decisions all continue to apply - the working rules from GDPR for recruiters. The combined message of both regimes is identical and simple: automate the funnel, never the verdict; explain everything; keep a human in charge of people's chances.
What to do this quarter
Inventory the AI already in your hiring - including features inside tools you do not think of as AI. Drop anything in the banned tier, especially emotion-reading claims. Ask each vendor three written questions: your high-risk classification plan, your documentation, your human-oversight design. Put one sentence of AI transparency into your application flow. And when choosing new tools, prefer compliance-by-design over promises of a 2027 retrofit - the deadline moved once; the direction never has.
The takeaway
The AI Act draws the line where good practice already stood: AI that gatekeeps jobs must be transparent, overseen and explainable, with humans owning the decisions. Deployers who choose well-built tools inherit most of their compliance and gain the actual prize - hiring that is faster and fairer at the same time, provable on request.
Compliance by design.
Qwiza was built the way the AI Act points: explained scores, no automatic rejections, a human making every decision that matters. Screen faster and sleep well - 48-hour pilot target.
See how Qwiza worksFrequently asked questions
Does the AI Act apply to a small business using an AI hiring tool?
Yes - the Act regulates by use, not company size. If you use AI to recruit, screen, rank or select candidates in the EU, you are a deployer of a high-risk system, with deployer-sized obligations: use the tool per its instructions, keep a trained human genuinely overseeing it, inform candidates that AI is involved, and retain the system's logs. The heavy lifting - conformity assessment, technical documentation, bias testing - sits with the provider, which is why choosing the right provider is most of a small employer's compliance.
What is actually banned, as opposed to regulated?
The prohibited tier applies now and includes practices employers should avoid regardless: emotion-recognition systems in the workplace and in hiring, social scoring, and biometric categorisation by sensitive traits. A video-interview tool claiming to read candidates' emotional states is not a compliance risk to manage - it is a product to walk away from.
What changed with the December 2027 deadline?
The Digital Omnibus package, adopted mid-2026, pushed the compliance date for standalone Annex III high-risk systems - which includes recruitment and HR tools - from August 2026 to December 2027, giving providers and standards bodies time to finish the technical framework. Nothing about the destination changed: the obligations arrive, and systems built compliant-by-design now will simply not notice the deadline.


