Is my AI hiring tool high-risk under the EU AI Act?
A plain-language answer, verified at source. About 4 minutes.
If the tool screens, ranks, filters, or profiles candidates, then yes: it is almost certainly high-risk under the EU AI Act. And the duty to handle that does not sit only with the vendor who sold it. It sits with you, the employer using it.
Why it lands in the high-risk tier
The EU AI Act sorts AI systems by the risk they pose, and recruitment is named explicitly. Annex III, point 4 of Regulation (EU) 2024/1689 lists as high-risk the AI systems intended to be used for the recruitment or selection of people, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates (read it on EUR-Lex).
Read that against what your tool actually does. If it sorts a stack of CVs, scores applicants, matches people to a role, or decides who advances, it is doing the things that paragraph describes. The label is not about how advanced the model is or how the vendor markets it. It is about the job the system performs: judging people in hiring.
There is one narrow off-ramp. Article 6(3) lets a system that would otherwise be high-risk fall out of the tier if it performs only a narrow procedural task, or merely improves the result of work a person already did, and does not profile people. A tool that ranks or filters candidates is doing the opposite of narrow, so most hiring software will not qualify. Treat the exemption as the exception to argue and document, not the default to assume.
What "high-risk" actually triggers for you
The Act splits duties between the provider (the company that builds and sells the system) and the deployer (the company that uses it under its own authority). As an employer running a hiring tool, you are the deployer, and Article 26 sets out your obligations (AI Act, Article 26). In plain terms, the deployer is expected to:
- Use the system in line with the provider's instructions, rather than off-label.
- Assign real human oversight to people with the competence and authority to act on what they see, not a rubber stamp.
- Keep the logs the system generates, so a decision can be reconstructed later.
- Monitor how the tool performs in practice and flag serious problems to the provider and the authorities.
- Tell candidates, where required, that a high-risk AI system is being used in a decision about them.
There is also a separate question of whether you must run a fundamental-rights impact assessment before you deploy. That duty, in Article 27, falls on certain deployers, and a private employer is not always in scope, so it is worth checking rather than assuming (AI Act, Article 27). The point is that the deployer's side of high-risk is a real, documentable program, not a box the vendor ticks for you.
A note on timing
The high-risk obligations are not all live yet. The headline deadline for these duties has moved, from 2 August 2026 toward 2 December 2027, under a simplification package the EU has provisionally agreed but not yet finalised in the Official Journal. The obligation itself has not gone away; the clock has shifted. The sensible read is to use the extra runway to get your inventory and oversight in order, not to file the question away until 2027.
What to do with this
Before you build a compliance program, find out whether you even need one, and for which tools. The fastest way is to check your own use against the law, tool by tool.
Take the free, two-minute self-assessment. Five questions tell you whether your hiring tool is likely high-risk and what the first step is. No email needed to see your result.
Take the free 2-minute checkWant the full checklist and the editable files your team fills in? See the Toolkit (US$ 99, one-time).
This is educational material and a starting point, not legal advice. The EU AI Act is detailed and still evolving, and the high-risk timeline rests on an agreement not yet final in the Official Journal. Whether a specific tool is high-risk, and which obligations attach, depends on your facts; for that, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.
Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.