SimpleAct Logo
Back to BlogAI in Recruiting: What the New High-Risk Guidelines Mean for HR
Best Practices

AI in Recruiting: What the New High-Risk Guidelines Mean for HR

"The AI only pre-sorts, people decide." Under the Commission's draft guidelines, that is no longer enough. Which HR tools count as high-risk, what has been prohibited since February 2025, and why using ChatGPT to rank applicants is the biggest trap.

September 30, 2026
Yannick | SimpleAct Team
8 min read
EU-LeitlinienKIRecruiting
AI in Recruiting: What the New High-Risk Guidelines Mean for HR

AI-generated image

EU AI Act · Human resources

"The AI only pre-sorts, people still make the decisions here." Many HR departments reassure themselves with that sentence. The European Commission's draft guidelines take the comfort out of it.

On 19 May 2026 the Commission published its draft guidelines on classifying high-risk AI systems. They run to roughly 170 pages of interpretation and practical examples. For hardly any area are they as concrete as for human resources, and for hardly any area are they as clear-cut.

The consultation has closed, and the final version is due to be adopted by the end of 2026. Even then the guidelines will not be legally binding. But they will be the yardstick market surveillance authorities work from.

Prohibited since

2 February 2025

Emotion recognition in the workplace, including job interviews. This is not a future issue.

High-risk obligations from

2 December 2027

For AI systems under Annex III, including recruitment and workforce management. Postponed by the Digital Omnibus.

What counts as high-risk in HR

The relevant provision is point 4 of Annex III to the AI Act. It covers two phases, and the guidelines show how far both reach.

POINT 4(A)

Before and during hiring

Targeted placement of job ads, active candidate sourcing, CV screening, applicant ranking and background checks.

POINT 4(B)

During employment

Task allocation based on behaviour or personal traits, pay, performance evaluation, promotion, behavioural monitoring and termination.

The second block is often overlooked. A company running AI-assisted performance management, or allocating shifts on the basis of a behavioural profile, is just as affected as the recruiting team.

"A human decides" is not enough

The central criterion in the guidelines is the material influence of the AI output on the decision. Even if a recruiter formally makes the final call, the system can still be high-risk if its output largely determines who moves forward.

That describes the typical workflow exactly. A tool ranks 400 applications, and a recruiter looks at the top 30. Formally, she decides. In practice, the system has filtered out the other 370 without a human ever seeing them.

The exemption never applies to profiling

Article 6(3) allows Annex III systems to be exempted from high-risk status in individual cases, for example where they perform only a narrow procedural task. That exemption is closed as soon as a system profiles natural persons. A tool that scores applicants, categorises them or predicts their suitability is almost always profiling. A human in the loop alone changes nothing, because neither the purpose nor the area of use changes.

What is already prohibited today

The genuinely urgent point gets lost in the debate about 2027. Emotion recognition in the workplace has been prohibited under Article 5 since February 2025, with exceptions only for medical or safety reasons. That includes job interviews.

This covers video interview tools that infer enthusiasm, nervousness, resilience or honesty from facial expression, voice or word choice. The Commission's draft explicitly warns about the lack of scientific basis for such systems and makes clear the concept is not to be read narrowly. A vendor that markets "attitudes" or "soft-skill signals" instead of emotions is still caught.

There is no transition period to 2027 for these tools. They should be switched off, or the relevant feature disabled, today, and breaches fall into the highest penalty tier of Article 99.

A first classification of typical tools

Use case Likely classification
Video interview analysing emotions or personality from face and voice Prohibited since February 2025
CV screening, matching score, applicant ranking High-risk
Targeted delivery of job ads to selected audiences High-risk
AI-assisted performance review, task allocation by behavioural profile High-risk
Parsing CVs into a standard format, with no assessment Art. 6(3) exemption possible, only without profiling and documented
Drafting job ad text without steering who sees it Usually not high-risk
Chatbot answering questions about process, deadlines and documents Usually not high-risk, but disclosure duty under Art. 50

This classification is guidance based on the draft guidelines. In each case what matters is the system's intended purpose and how strongly its output shapes the employment decision.

The underrated trap: ChatGPT as a recruiting tool

Many HR teams do not use a specialised recruiting system at all. They paste CVs into a general-purpose AI assistant and ask for a ranking or a suitability assessment. That feels more harmless than a bought-in screening tool. Legally, it is the opposite.

Under Article 25, anyone who changes the purpose of an AI system so that it becomes high-risk is treated as a provider. That expressly includes general-purpose AI systems. Using a chatbot to rank applicants means you are no longer merely a deployer; from December 2027 you potentially carry a provider's obligations: risk management, technical documentation, conformity assessment. Since the Digital Omnibus, this role shift is also expressly subject to fines.

Practical consequence: a clear internal rule that general-purpose AI assistants are not to be used to assess or sort applicants is the simplest and most effective safeguard. It belongs in every AI policy.

What employers as deployers must do from December 2027

An employer using a bought-in high-risk system is a deployer. The obligations come mainly from Article 26.

Use as instructed

Use the system only in line with the provider's instructions and, where you control the input data, make sure it is relevant.

Human oversight

By people with the necessary competence, training and authority. This is where Article 26 meets the AI literacy duty in Article 4.

Monitoring and logs

Monitor operation, report risks and incidents, and keep automatically generated logs for at least six months.

Information before rollout

Inform workers' representatives and affected employees before use in the workplace, and inform applicants about use in decisions concerning them.

On top of that, Article 86 gives affected persons the right to an explanation of the role the system played in a decision about them. A company that cannot explain a rejection because nobody understands the ranking has a problem at exactly this point.

What already applies in Germany

The postponement to 2027 creates the impression that nothing needs doing in recruiting for now. For employers in Germany that is not true, because two other frameworks already apply.

Works Constitution Act

AI tools capable of evaluating behaviour or performance regularly trigger co-determination under section 87(1) no. 6 BetrVG. Systems that set selection criteria for hiring touch section 95 BetrVG. Under section 90 BetrVG, the works council must be informed as early as the planning stage of AI use.

GDPR

Article 22 protects against solely automated decisions with significant effects. A data protection impact assessment is practically always required for AI-assisted applicant assessment, and the processing belongs in the Article 30 record.

Then there is the General Equal Treatment Act (AGG). A ranking model trained on historical hiring data adopts its patterns. If a rejected applicant raises discrimination, the burden of proof under section 22 AGG can shift quickly to the employer, and "the tool suggested it" is no defence.

Five steps before December 2027

1

Record all AI in HR

Not only the official applicant tracking system, but also AI features in existing HR software and individual recruiters' use of general-purpose assistants.

2

Switch off prohibited features now

Check video interview tools for emotion or personality analysis and disable it. This is the one item with no time buffer.

3

Classify and clarify your role

For each system, record whether it falls under Annex III, whether the exemption is realistically available, and whether you are the deployer or, through your own change of purpose, the provider.

4

Hold vendors to account

Ask how the vendor classifies the system, whether it will meet the high-risk requirements by the end of 2027, and what instructions for use and logging it provides. If you get no clear answer, price that into the next contract renewal.

5

Set up oversight, works council and notices

Name and train the people responsible for human oversight, prepare a works agreement, and draft the information notices for employees and applicants.

The point that matters

The high-risk obligations for recruiting arrive only at the end of 2027. But the question they are designed to answer already arises today: can a company explain why an application was rejected, and who is responsible for that?

A company that cannot has not just an AI Act problem in fourteen months, but a works council, data protection and equal treatment problem from the next batch of applications onwards. The inventory needed for 2027 resolves those questions along the way.

With SimpleAct

Know which AI helps decide about your applicants.

EU AI Act and GDPR in one platform: register AI systems centrally, classify them rule-based, assign responsibilities and export audit-ready evidence at any time. Made in Germany, hosted in Germany.

Start your AI inventory →

This article is for general information only and does not constitute legal advice. It is based on the Commission's draft guidelines of 19 May 2026; the final version may differ. Last updated: 28 September 2026.

Tags

EU-LeitlinienKIRecruiting

Ready to put EU AI Act compliance on autopilot?

SimpleAct helps you inventory AI systems, classify risk, and generate the required documentation automatically.

Y

Yannick | SimpleAct Team

Author · SimpleAct Team