Skip to content
SimpleAct Logo

Industry · HR

As of 6 October 2026, after the Digital Omnibus

AI in HR and recruiting under the AI Act

If you screen applications automatically or evaluate performance with AI, you are usually using high-risk AI. This page explains what Annex III No. 4 covers, which duties follow for you as an employer and what is banned anyway.

Short answer

AI systems intended to be used for recruitment or selection of persons, or for decisions during the employment relationship, are high-risk AI (Annex III point 4 in conjunction with Art. 6(2)). As an employer you are usually the deployer and must, among other things, ensure human oversight, keep logs for at least six months and inform workers' representatives and the affected workers before use (Art. 26(1), (2), (6) and (7)). For Annex III systems these duties apply from 2 December 2027 (Art. 113(3)(c) as amended by Regulation (EU) 2026/1744). Inferring emotions in the workplace is already banned, except for medical or safety reasons (Art. 5(1)(f)).

High-risk

What Annex III point 4 covers

Annex III point 4 is headed "Employment, workers' management and access to self-employment" and lists two groups of systems intended to be used for:

  • Annex III point 4(a)

    Recruitment and selection

    Recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates.

  • Annex III point 4(b)

    Decisions in the employment relationship

    Decisions affecting the terms of work-related relationships, promotion or termination, allocating tasks based on individual behaviour or personal traits or characteristics, and monitoring and evaluating the performance and behaviour of persons in such relationships.

The intended purpose is what counts. A tool does not become high-risk because it sits in the HR department, but because it is intended for one of these purposes.

Typical tools

Which HR tools are affected?

A guide, not a final classification. The intended purpose and functioning of the specific product are decisive.

An Annex III system is exceptionally not considered high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, for example because it only performs a narrow procedural task or a preparatory task (Art. 6(3), first and second subparagraphs). If it performs profiling of natural persons, it is always considered high-risk (Art. 6(3), third subparagraph). For candidate selection, profiling will often be the case.

UseClassificationSource
Automatically screen, filter or rank applicationsHigh-riskAnnex III point 4(a)
Automatically evaluate candidates, for example video or test analysisHigh-risk; inferring emotions would additionally be bannedAnnex III point 4(a); Art. 5(1)(f)
Place targeted job ads with AIHigh-riskAnnex III point 4(a)
Evaluate employee performance or behaviourHigh-riskAnnex III point 4(b)
Allocate tasks by individual behaviour or characteristicsHigh-riskAnnex III point 4(b)
Support promotion or termination decisionsHigh-riskAnnex III point 4(b)
Draft texts or job descriptions, coordinate appointmentsNo Annex III purpose; observe Art. 4 and, where relevant, Art. 50Art. 4, Art. 50

Obligations

What employers have to do as deployers

The full list with a checklist is on the page about deployer obligations. For HR these points matter most:

  • Art. 26(1)

    Use according to the instructions

    Use the screening tool only as the provider intended, with appropriate technical and organisational measures.

  • Art. 26(2)

    Human oversight

    Trained, empowered people review the results. Purely automatic rejection without real oversight does not meet this.

  • Art. 26(4)

    Input data

    To the extent you control the input data, it must fit the intended purpose and be sufficiently representative.

  • Art. 26(6)

    Logs

    Keep automatically generated logs for at least six months unless Union or national law provides otherwise. Applicant data is also subject to data protection deletion periods.

  • Art. 26(7)

    Inform workers' representatives

    Before putting the system into service or using it at the workplace, employers inform workers' representatives and the affected workers that they will be subject to the system, in line with Union and national rules and practices.

  • Art. 26(11)

    Inform affected persons

    Deployers of Annex III systems that make or assist in making decisions about natural persons inform those persons about it. In candidate selection these are the applicants.

Note: co-determination and consultation rights of works councils follow national law and go beyond the information duty in Art. 26(7). This is not legal advice; clarify it with your legal department.

Data protection

Interplay with the GDPR

The AI Act does not replace the GDPR. Art. 26(9) expressly requires deployers to use the information provided by the provider under Art. 13 to comply with their obligation to carry out a data protection impact assessment under Art. 35 GDPR. For applicant and employee data this check is therefore a fixed part of introducing a tool.

A fundamental rights impact assessment under Art. 27 only concerns certain deployers, such as bodies governed by public law and private entities providing public services (Art. 27(1)). A private company using recruiting software is usually not covered. Where a data protection impact assessment has been carried out, the fundamental rights impact assessment may refer to it (Art. 27(4) as amended).

Prohibitions

What is banned in HR anyway

  • Art. 5(1)(f)

    Emotion recognition in the workplace

    Banned is the use of AI systems to infer emotions of a natural person in the areas of the workplace and education, except where the system is intended for medical or safety reasons. Whether a job interview counts as "workplace" is a matter of interpretation; consult the Commission guidelines on prohibited practices.

  • Art. 5(1)(g)

    Biometric categorisation

    Banned are systems that categorise persons based on biometric data to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. This is also relevant for applicant or employee analysis.

  • Art. 5(1)(c)

    Social scoring

    Banned is evaluating or classifying persons over a period of time based on their social behaviour or personal traits where this leads to unrelated or disproportionate detrimental treatment.

All prohibitions at a glance: see the page on prohibited AI practices. The prohibitions apply since 2 February 2025 (Art. 113(3)(a)); infringements can be fined up to EUR 35 million or 7 % of worldwide annual turnover (Art. 99(3)).

Role

When HR becomes a provider

If you develop a screening tool yourself, distribute it under your own name or change the intended purpose of a standard tool so that it serves candidate selection, you may be a provider (Art. 3(3), Art. 25(1)). Then the provider obligations under Art. 16 apply, not only Art. 26. The page on deployer obligations explains the distinction.

Deadlines

What applies when

TopicDateSource
Prohibitions, including emotion recognition in the workplaceSince 2 February 2025Art. 113(3)(a)
AI literacy of staff operating AISince 2 February 2025Art. 4; Art. 113(3)(a)
High-risk obligations for Annex III systems, including point 42 December 2027Art. 113(3)(c)(i) as amended

Implementation

How SimpleAct supports HR teams

  • Inventory

    Record HR systems

    Applicant management, performance evaluation and assistants with intended purpose, role and risk class in one register.

  • Classification

    Check Annex III point 4

    The check shows whether a tool is high-risk or falls under the Art. 6(3) exemption, and records the reasoning.

  • Evidence

    Prove information and oversight

    Document training, oversight persons, information given to workers' representatives and applicants, and the log concept in one place.

FAQ

Frequently asked questions on AI in HR

Systems intended to analyse or filter applications or evaluate candidates are listed in Annex III point 4(a). An exemption under Art. 6(3) only comes into question if there is no significant risk; where the system profiles natural persons, it is always considered high-risk.
Yes, employers must inform workers' representatives and the affected workers before a high-risk AI system is put into service or used at the workplace (Art. 26(7)). Further participation rights follow national law.
Inferring emotions in the workplace and in education is banned, except for medical or safety reasons (Art. 5(1)(f)). Whether a recruitment process falls under it is a matter of interpretation to be clarified legally in each case.
For high-risk systems under Annex III, including point 4, from 2 December 2027 (Art. 113(3)(c) as amended by Regulation (EU) 2026/1744). The prohibitions and the AI literacy duty have applied since 2 February 2025.
Deployers of Annex III systems that make or assist in making decisions about natural persons inform those persons that they are subject to the system (Art. 26(11)).
At least six months, to the extent the logs are under your control and Union or national law does not provide otherwise (Art. 26(6)). Data protection deletion periods for applicant data have to be observed.

More questions? We're happy to help. Send email · Get started

Sources and status

As of · SimpleAct editorial team

Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.

Record, classify and evidence HR AI

We will show you how to classify applicant and performance tools in the AI inventory and evidence the deployer obligations.