RegTech

AI Act and HR Recruitment: Compliance Requirements for Hiring AI Tools

Igera Solutions
June 12, 2026
7 min read
Featured image for ai-act-hr-recruitment

EU AI Act and HR Recruitment: What Every HR Department Needs to Know in 2026

The EU AI Act (Regulation 2024/1689) classifies AI systems used for recruitment, CV screening, and employee management as HIGH-RISK under Annex III, point 4. From August 2026, deployers must implement risk management systems, ensure human oversight, conduct fundamental rights impact assessments, and register their systems in the EU AI database. Non-compliance risks fines of up to €15 million or 3% of global annual turnover.

Legal Framework

The EU AI Act — Regulation (EU) 2024/1689 of 13 June 2024 — entered into force on 1 August 2024. Article 6 defines high-risk AI systems by reference to Annex III. Annex III, point 4 explicitly lists: AI intended to be used for recruitment or selection of natural persons, notably for advertising vacancies, screening or filtering applications, evaluating candidates in the course of interviews or tests. Point 4 also covers: AI for making decisions on promotion and termination of work-related contractual relationships, for task allocation based on individual behaviour or personal traits or characteristics, for monitoring and evaluating performance and behaviour of persons in such relationships.

Article 26 sets out obligations for deployers of high-risk AI systems: use systems in accordance with instructions, assign human oversight to qualified persons, monitor performance, report serious incidents, and conduct a fundamental rights impact assessment (Art. 27) when the system affects employees or job applicants. Article 5 prohibits specific AI practices outright: emotion recognition systems in the workplace (Art. 5.1.f) — banned from 2 February 2025 — and real-time remote biometric identification in public spaces (Art. 5.1.h).

The AI Act intersects with GDPR Article 22 (automated decision-making), which already applies to recruitment AI. Companies must comply with both — the AI Act does not replace GDPR but adds new layers of obligation. In Spain, the AESIA (Agencia Española de Supervisión de la IA), created under Royal Decree 729/2023, is the national supervisory authority and will be responsible for enforcement of the AI Act from August 2026. Spanish data protection law (Ley Orgánica 3/2018, LOPDGDD) also applies in the HR context alongside the AI Act and GDPR.

Step-by-Step Compliance

  1. Audit all AI tools used in HR against Annex III point 4. Create an inventory of every AI-powered tool in your HR stack: ATS (Applicant Tracking Systems), CV parsing tools, video interview analysis tools (HireVue, Retorio), psychometric testing platforms, performance management AI, workforce scheduling algorithms. For each tool, determine: does it make or inform decisions about hiring, promotion, termination, or task allocation? If yes, it is likely high-risk under Annex III point 4. Document your findings in a structured AI inventory. This audit should involve HR, Legal, IT and the tool vendors. Ask vendors for their AI Act compliance roadmap and whether they will provide the technical documentation required by Art. 11. Tools that merely help schedule interviews or send reminder emails are not high-risk and require no special compliance steps under the AI Act.
  2. Register high-risk AI systems in the EU AI database. Article 71 requires providers of high-risk AI systems to register in the EU database managed by the European AI Office. Deployers (companies using, not building, the AI) must also register certain high-risk systems. The database is public and searchable. Non-registration is itself a regulatory violation independent of the underlying AI risk. If you use a third-party ATS like Workday or SAP SuccessFactors, check whether the vendor has already registered the system — if so, confirm your deployment is covered. For internally built tools (custom candidate scoring models, internal performance tracking AI), your company is the provider and must register as such. Registration requires: description of the AI system, intended purpose, performance metrics, and data governance information.
  3. Implement a risk management system (Art. 9). Establish a documented, iterative risk management process covering the entire lifecycle of each high-risk HR AI system. This includes: defining the intended purpose and foreseeable misuse scenarios, identifying and assessing risks to fundamental rights (discrimination, privacy, dignity), implementing technical and organisational measures to mitigate identified risks, and periodic testing before deployment and throughout the system's operational life. The risk management system must be updated whenever the AI system is substantially modified or when new risks are identified through monitoring. Document every step and retain records for at least 10 years (Art. 18).
  4. Ensure meaningful human oversight (Art. 14). High-risk AI systems must be designed and deployed so that humans can effectively oversee, understand, intervene in, and where necessary stop them. For HR specifically: no CV rejection should be final without human review, no interview score should directly determine a hiring decision without a recruiter reviewing and being able to override it, and the system must provide explainable outputs — not just a score but a basis for the score. Document your human oversight procedures in writing. Train recruiters on how to interpret AI outputs, what the system's known limitations are, and when and how to override AI recommendations. The human review must be genuine and not a rubber stamp.
  5. Conduct a Fundamental Rights Impact Assessment (Art. 27). Deployers of high-risk AI in employment contexts must assess the impact on fundamental rights before deployment and update it whenever the system or its context changes materially. The assessment must cover: non-discrimination (Art. 21 EU Charter), privacy and data protection (Art. 8 EU Charter), dignity (Art. 1), and fair and just working conditions (Art. 31). Identify protected groups that could be disproportionately affected, the data used for training and inference, potential for proxies that correlate with protected characteristics (postal code, names, educational institution), and mitigation measures. The completed assessment must be notified to the relevant market surveillance authority (in Spain: AESIA). Engage your Works Council or employee representatives where legally required.
  6. Train HR staff on AI literacy (Art. 4). The AI Act requires that all persons dealing with the operation of high-risk AI systems have sufficient AI literacy for their role. This is not optional: it is a legally binding obligation on the deployer. Recruiters using CV screening tools must understand how they work, what data they use, what their known limitations and error rates are, and how to detect and correct problematic outputs. Training must be documented with dates, attendees and content covered. Providers of high-risk AI must supply instructions for use (Art. 13) that enable deployers to train their staff appropriately. Incorporate AI literacy into your annual HR training calendar and keep records available for audit.
  7. Maintain technical documentation and logs (Arts. 11–12). High-risk AI systems must keep logs automatically for the entire operational lifecycle. As a deployer, you must retain these logs for at least 6 months (Art. 12.1) and make them available to national authorities on request. The technical file (Art. 11) — which the provider must maintain — must document the system's design, training data characteristics, validation and testing results, performance metrics, known limitations, and cybersecurity measures. If you use a third-party provider, your Data Processing Agreement must include provisions for access to logs, technical documentation and audit rights. For internally built systems, your company maintains the technical file directly. All documentation must be kept for 10 years after the system is placed on the market or put into service.

Required Documentation

  • AI inventory spreadsheet: listing all HR AI tools, their function, risk classification, vendor name and vendor compliance status. Updated at least annually or when new tools are deployed.
  • Vendor AI Act compliance letters: written confirmation from each vendor of their compliance roadmap, system registration status in the EU AI database, and commitment to provide Art. 11 technical documentation.
  • Fundamental Rights Impact Assessment (FRIA): completed for each high-risk HR AI system before deployment, documenting protected groups, bias risks, mitigation measures and notification to AESIA.
  • Human oversight procedure document: describing exactly how human review works for each AI-assisted HR decision, who is responsible, what override mechanisms exist, and how overrides are recorded.
  • AI literacy training records: dates, attendees, content covered, and assessment results for all HR staff who operate high-risk AI systems. Renewed at least annually.
  • System registration confirmation: proof of registration in the EU AI database (or confirmation that the vendor has registered and your deployment is covered).
  • Art. 13 instructions for use from each vendor: the mandatory documentation that enables deployers to understand and correctly operate each high-risk AI system.

Enforcement Timeline

Date Obligation Who Notes
1 Aug 2024 AI Act enters into force All companies Start auditing HR AI tools now. Two-year runway for high-risk compliance.
2 Feb 2025 Prohibited practices apply All companies Emotion recognition in workplace banned (Art. 5.1.f). Immediate action required.
2 Aug 2025 GPAI model obligations apply AI providers (foundation models) Mainly affects AI vendors, not deployers. Review vendor compliance.
2 Aug 2026 High-risk HR AI obligations fully apply All deployers Full Arts. 9–27 compliance required. AESIA enforcement begins in Spain.
2 Aug 2027 Extended scope: Annex I products Specific regulated sectors Additional high-risk AI categories. Limited HR relevance.
2 Aug 2030 Legacy system retrofit deadline All deployers High-risk AI systems already on market before Aug 2026 must comply by this date.

Tens dubtes sobre el compliment del AI Act? IgeraFincas respon automàticament citant l'article exacte del Reglament UE 2024/1689 i la normativa espanyola aplicable. Descobreix com →

Common Mistakes

  • Assuming your ATS vendor handles all compliance. Deployers have independent obligations under Art. 26 regardless of vendor compliance status. Even if your vendor has registered their system, you as deployer must still: complete the FRIA, implement human oversight, train your staff on AI literacy, and retain logs. The vendor's compliance is necessary but not sufficient. Get a written confirmation from every HR AI vendor of exactly which Art. 26 obligations they support and which fall to you.
  • Thinking GDPR Art. 22 compliance is sufficient. The AI Act adds entirely new obligations on top of GDPR — they are cumulative, not alternative. GDPR Art. 22 addresses automated individual decision-making and gives candidates the right to human review and explanation. The AI Act adds risk management systems, technical documentation, mandatory registration, fundamental rights impact assessments, and AI literacy requirements. A company that complies fully with GDPR Art. 22 still needs to do significant additional work to comply with the AI Act.
  • Forgetting internally built AI tools. Custom-built candidate scoring models, internal performance management dashboards with AI features, or workforce planning tools built by your own data science team are subject to the AI Act as internally developed systems — your company is both provider and deployer. These tools often receive less compliance scrutiny than third-party vendors because there is no external contract forcing due diligence. Audit all internal data science and analytics tools used in HR decisions as part of your initial inventory.
  • Not involving the Works Council. In Germany (Betriebsverfassungsgesetz §87), France (Code du Travail L2312-38), Spain (Estatuto de los Trabajadores art. 64.5.d) and other Member States, deploying AI systems for employee monitoring and performance evaluation requires prior consultation with employee representatives independently of the AI Act. Failure to consult the Works Council can result in the deployment being challenged and annulled at national labour law level, even if you are otherwise AI Act compliant. Check national labour law requirements in every jurisdiction where you operate.

Frequently Asked Questions

Which specific HR AI tools are high-risk under the AI Act?

Any AI tool that makes or significantly influences decisions about: hiring (CV screening, interview scoring, candidate ranking), promotion, demotion, termination of employment, task allocation based on behaviour or performance monitoring, or salary decisions based on AI output. Concretely: HireVue video interview analysis, Pymetrics (now Harver) psychometric testing, Workday AI Recruiting, SAP SuccessFactors Talent Intelligence, LinkedIn Recruiter AI-powered candidate ranking, IBM Watson Talent, and similar tools. Tools that merely help schedule interviews, send automated acknowledgement emails, or post jobs to multiple boards without ranking candidates are generally not high-risk under Annex III point 4 and require no special compliance steps beyond standard GDPR obligations.

What is prohibited outright for HR AI under Art. 5 from February 2025?

Article 5.1.f prohibits AI systems that infer emotions of natural persons in the workplace and in education institutions. This bans emotion detection software during video interviews — tools that claim to detect enthusiasm, deception, stress, or personality traits from facial expressions, micro-expressions, voice tone or word choice during interviews. The ban applies even if the output is described as a "soft skill assessment" or "candidate engagement score" rather than an emotion classification. It also prohibits AI systems that exploit subliminal techniques to manipulate candidates. Real-time biometric categorisation of individuals based on sensitive characteristics (race, sexual orientation) is also banned. These prohibitions applied from 2 February 2025 — if you are still using emotion detection in your hiring process, you are already non-compliant and face fines of up to €35 million.

Does GDPR Art. 22 still apply alongside the AI Act?

Yes, fully. GDPR Article 22 (the right not to be subject to solely automated decision-making with significant effects) continues to apply in parallel with the AI Act. The AI Act does not replace or supersede GDPR — it adds additional obligations. For HR AI, this means: you need a lawful basis under GDPR (typically legitimate interest or consent for recruitment AI), an Art. 22 exemption (e.g., the decision is necessary for entering a contract) or genuine human review, AND compliance with all the AI Act risk management obligations. Importantly, GDPR Art. 22 requires that the data subject (the job candidate) must be able to obtain human intervention, express their point of view, and contest the decision. Document how your HR process satisfies both sets of requirements simultaneously.

What are the penalties for non-compliance with the AI Act?

The AI Act sets a tiered penalty structure. Violations of prohibited practices (Art. 5) — including using emotion recognition in the workplace: up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Violations of obligations for high-risk systems (Arts. 9–27) — failing to implement risk management, human oversight, FRIA, or AI literacy training: up to €15 million or 3% of total worldwide annual turnover. Providing incorrect or misleading information to national authorities: up to €7.5 million or 1% of turnover. For SMEs and startups, fines are calculated at the lower of the two thresholds. Spain's AESIA will be responsible for investigation and enforcement of these penalties from August 2026.

Do SMEs have lighter obligations under the AI Act?

SMEs and startups receive some procedural relief: reduced technical documentation requirements (Art. 11.2 allows a simplified technical file), priority access to regulatory sandboxes (Art. 57) where they can test AI systems in a supervised environment before full deployment, and a proportionate enforcement approach articulated in the European AI Office's guidelines. However, the substantive obligations — risk management system (Art. 9), human oversight (Art. 14), fundamental rights impact assessment (Art. 27), AI literacy (Art. 4), logging (Art. 12) — apply to all companies deploying high-risk AI, regardless of size. If you use a major vendor's ATS, much of the technical compliance burden falls on the vendor as provider, but you retain your deployer obligations in full.

When does enforcement actually start for HR AI in Spain?

The prohibited practices (Art. 5) — including emotion recognition in the workplace — applied from 2 February 2025. If you are using such tools, you are already non-compliant. High-risk AI obligations (Arts. 9–27) apply from 2 August 2026: by this date you must have registered your systems, implemented risk management, completed your FRIA, trained your staff, and have all documentation ready. In Spain, AESIA (Agencia Española de Supervisión de la IA) is the designated national supervisory authority and will begin active enforcement from August 2026. For high-risk AI systems already on the market before August 2026 that have not undergone substantial modification, there is an additional transitional period of 2 years (until August 2028) to bring them into compliance.

Vols automatitzar les consultes de compliance del AI Act? IgeraFincas és el chatbot RAG que respon citant l'article exacte del Reglament 2024/1689 i la normativa espanyola (LOPDGDD, Estatuto Trabajadores). Sol·licita demo gratuïta →

Conclusion

The EU AI Act represents the most significant change to HR technology compliance since GDPR. From August 2026, every company using AI to screen CVs, score video interviews, allocate tasks based on performance data, or monitor employee behaviour must have implemented a full compliance programme covering risk management, human oversight, fundamental rights impact assessment, AI literacy training and system registration. The obligations are not optional and the penalty exposure is substantial — up to €15 million or 3% of global turnover for violations of high-risk AI rules. The good news is that the compliance framework is predictable and manageable with the right preparation: audit your HR AI tools now, engage your vendors on their AI Act compliance roadmaps, build your documentation, train your recruiters, and complete your FRIA before the August 2026 deadline. Companies that treat AI Act compliance as a one-time registration exercise will face enforcement action. Companies that embed it into their ongoing HR technology governance will be well positioned to use AI responsibly, defensibly and competitively in the years ahead.

#AI Act HR#recruitment AI compliance#hiring AI regulation#EU AI Act high-risk

COMPARTIR

Comparte el conocimiento con tu red