AI in hiring
The EU AI Act and hiring: what changes for recruiters, and when
The Itya team · Updated · 7 min read
The short answer
The EU AI Act treats AI used to recruit, filter or evaluate candidates as high-risk. One use is already banned: AI that infers emotions in the workplace, since 2 February 2025. The duty to tell people they are talking with an AI applies from 2 August 2026, and the Digital Omnibus moved the high-risk duties for hiring tools to 2 December 2027.
The timeline at a glance
| Date | What applies | What it means for hiring |
|---|---|---|
| 1 August 2024 | The AI Act enters into force | The clock starts. Most duties come later. |
| 2 February 2025 | Chapters I and II, including the Article 5 bans | AI that infers emotions at work, including of candidates, is banned. |
| 27 July 2026 | The Digital Omnibus enters into force | High-risk deadlines move back. Disclosure stays on schedule. |
| 2 August 2026 | General application, including Article 50 transparency | AI that talks with candidates must be built to tell them it is an AI. |
| 2 December 2026 | Marking grace period ends for AI-generated content on systems already on the market; new bans on AI that generates non-consensual intimate imagery | Rarely relevant to hiring tools. |
| 2 December 2027 | High-risk rules for Annex III systems, including recruitment | Employer (deployer) duties under Article 26 apply. |
| 2 August 2028 | High-risk rules for AI built into regulated products (Annex I) | Not usually relevant to hiring software. |
Why hiring AI counts as high-risk
Annex III, point 4(a), lists "AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates". Point 4(b) adds AI used for decisions on promotion and termination, to allocate tasks, or to monitor and evaluate performance.
Article 6(3) says an Annex III system is not high-risk if it poses no significant risk, including by not materially influencing decisions, and it is intended to do one of these:
- perform a narrow procedural task;
- improve the result of a previously completed human activity;
- detect decision-making patterns or deviations, without replacing or influencing the human assessment without proper human review;
- perform a preparatory task to an assessment.
There is a catch. An Annex III system "shall always be considered to be high-risk where the AI system performs profiling of natural persons". A provider that decides its system is not high-risk must document that assessment. Ask your vendor, in writing, which view it takes and why.
Already banned: emotion recognition at work
Since 2 February 2025, Article 5(1)(f) has prohibited "the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions". The only exception is a system put in place for medical or safety reasons.
The ban reaches hiring. According to Lewis Silkin, the Commission's non-binding guidelines on prohibited practices extend it to "candidates in a recruitment cycle or probationary period". Their examples include AI that infers emotions from keystrokes, facial expressions, body postures or voice. The definition of emotion recognition rests on biometric data, so sentiment analysis of written text falls outside it.
Telling candidates they are talking with an AI
Article 50(1) says providers "shall ensure that AI systems intended to interact directly with natural persons are designed and developed" so that people are informed they are interacting with an AI, unless that is obvious. The information must come "at the latest at the time of the first interaction". It has applied since 2 August 2026; the Omnibus left it on schedule (Cooley).
Note who carries the duty: the provider, meaning the company that builds the AI interviewer. An employer that builds its own is the provider. Either way, say it in the interview invitation too. Candidates notice when nobody does: in a Greenhouse survey from May 2026, 70% of US job seekers who had faced an AI interview were not told upfront that AI would evaluate them.
What employers must do from 2 December 2027
When you use a high-risk system, the Act calls you a deployer. Article 26 sets your duties. The main ones for recruiters:
- Use it as instructed. Take appropriate technical and organizational measures to use the system according to the provider's instructions.
- Assign human oversight to people "who have the necessary competence, training and authority".
- Check your input data. Where you control it, it must be relevant and sufficiently representative for the intended purpose.
- Monitor, and stop if needed. Watch how the system performs, tell the provider about risks, and suspend use if you have reason to think the system presents one.
- Keep the logs the system generates, where they are under your control, for at least six months unless other law says otherwise.
- Tell workers first. Employers must inform workers' representatives and the affected workers before a high-risk system is used at the workplace.
- Use the provider's information for your data protection impact assessment, where one applies.
- Tell the people affected. Deployers of Annex III systems that make or help make decisions about people must inform those people.
Article 86 adds a right to an explanation. A person affected by a decision based on a high-risk system's output, which they consider has an adverse impact on their health, safety or fundamental rights, can ask for "clear and meaningful explanations of the role of the AI system" and the main elements of the decision.
What the Digital Omnibus changed
Regulation (EU) 2026/1744 was adopted on 8 July 2026, published on 24 July and in force from 27 July. For hiring, three changes matter:
- High-risk duties for Annex III systems, including recruitment, moved from 2 August 2026 to 2 December 2027 (Hunton).
- Article 50 disclosure stayed on schedule from 2 August 2026. Only the duty to mark AI-generated content got a grace period to 2 December 2026, for systems already on the market (Cooley).
- The AI-literacy duty in Article 4 was rewritten in softer terms: support for staff AI literacy rather than a duty to ensure a set level of it.
The emotion-recognition ban did not move. It has applied since 2 February 2025.
GDPR Article 22 applies today
The AI Act sits on top of the GDPR; it does not replace it. Under Article 22, a person has "the right not to be subject to a decision based solely on automated processing", including profiling, that has legal or similarly significant effects on them. Exceptions exist for contracts, Union or member-state law, and explicit consent. In the contract and consent cases, the employer must offer at least "human intervention", a chance to express a view, and a way to contest the decision.
So a rejection made solely by software has been a GDPR question for years, whatever the AI Act dates say.
What to do now
- Remove emotion inference. Ask every vendor whether any feature infers emotions or intentions from face, voice or typing. If one does, switch it off for EU hiring.
- Disclose AI at the first touch. Name the AI in the invitation and again at the start of the conversation.
- Map your tools against Annex III. Note which ones score, rank, filter or evaluate candidates, and get each provider's written view on high-risk status.
- Design human oversight now. Name the people who review outputs and make decisions, train them, and make sure they have the authority to disagree with the system.
- Plan for logs. Confirm you can keep system logs for at least six months.
- Talk to employee representatives early, where you have them.
- Keep GDPR in view. Run a data protection impact assessment where the GDPR requires one, and offer human review of any solely automated decision.
Itya runs structured interviews: one rubric per job, consent capture before recording, transcripts with speaker attribution, and scorecards that cite the moment behind each rating. Records like these can help you meet specific duties, such as giving a reviewer the evidence to exercise oversight and explaining a decision on request. They do not carry your obligations for you. Our trust page lists our DPA and subprocessors, and our jurisdiction guide covers the rules outside the EU.
Questions people ask
- Is AI résumé screening high-risk under the EU AI Act?
- It is listed. Annex III names AI used "to analyse and filter job applications". Article 6(3) carves out narrow procedural and preparatory tasks, but a system that profiles people is always high-risk. The high-risk duties apply from 2 December 2027.
- Can I use AI to analyze a candidate's facial expressions or voice in the EU?
- Not to infer emotions. Since 2 February 2025, Article 5(1)(f) has banned AI that infers emotions in the workplace, and the Commission's guidelines apply this to candidates in a recruitment cycle. The only exceptions are medical or safety reasons.
- Does the AI Act apply to companies outside the EU?
- It can. Article 2 covers providers placing AI systems on the EU market wherever they are based, deployers established or located in the EU, and providers and deployers elsewhere when the system's output is used in the EU.
- Do I have to tell candidates that an AI is interviewing them?
- Since 2 August 2026, Article 50 has required providers to design AI systems that interact with people so those people are told, unless it is obvious, at the latest at the first interaction. Employers should say it too, in the invitation.
- Did the Digital Omnibus delay everything?
- No. It moved the high-risk duties for hiring tools to 2 December 2027. The Article 5 bans have applied since 2 February 2025, and Article 50 disclosure since 2 August 2026.
Sources
Every source was opened and checked on 10 October 2026.
- Annex III: High-risk AI systems referred to in Article 6(2), artificialintelligenceact.eu
- Article 5: Prohibited AI practices, artificialintelligenceact.eu
- Article 6: Classification rules for high-risk AI systems, artificialintelligenceact.eu
- Article 26: Obligations of deployers of high-risk AI systems, artificialintelligenceact.eu
- Article 50: Transparency obligations, artificialintelligenceact.eu
- Article 86: Right to explanation of individual decision-making, artificialintelligenceact.eu
- Article 99: Penalties, artificialintelligenceact.eu
- Article 113: Entry into force and application, artificialintelligenceact.eu
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal of the European Union
- EU Digital Omnibus on AI enters into force, Hunton
- Digital AI Omnibus delays key deadlines, introduces new rules, Cooley
- Understanding the EU AI Act's prohibited practices: key workplace and advertising insights from the new draft guidelines, Lewis Silkin
- Art. 22 GDPR: Automated individual decision-making, including profiling, gdpr-info.eu
- 63% of job seekers have faced an AI interview. Most haven't had a good one yet, Greenhouse
The AI listens. People decide.
See how Itya handles consent, notices and candidate data, and what we deliberately do not claim.