Signato signato.ai

Is my AI hiring tool high-risk under the EU AI Act?

A plain-language answer, verified at source. About 4 minutes.

Short answer

If the tool screens, ranks, filters, or profiles candidates, then yes: it is almost certainly high-risk under the EU AI Act. And the duty to handle that does not sit only with the vendor who sold it. It sits with you, the employer using it.

Why it lands in the high-risk tier

The EU AI Act sorts AI systems by the risk they pose, and recruitment is named explicitly. Annex III, point 4 of Regulation (EU) 2024/1689 lists as high-risk the AI systems intended to be used for the recruitment or selection of people, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates (read it on EUR-Lex).

Read that against what your tool actually does. If it sorts a stack of CVs, scores applicants, matches people to a role, or decides who advances, it is doing the things that paragraph describes. The label is not about how advanced the model is or how the vendor markets it. It is about the job the system performs: judging people in hiring.

There is one narrow off-ramp. Article 6(3) lets a system that would otherwise be high-risk fall out of the tier if it performs only a narrow procedural task, or merely improves the result of work a person already did, and does not profile people. A tool that ranks or filters candidates is doing the opposite of narrow, so most hiring software will not qualify. Treat the exemption as the exception to argue and document, not the default to assume.

What "high-risk" actually triggers for you

The Act splits duties between the provider (the company that builds and sells the system) and the deployer (the company that uses it under its own authority). As an employer running a hiring tool, you are the deployer, and Article 26 sets out your obligations (AI Act, Article 26). In plain terms, the deployer is expected to:

There is also a separate question of whether you must run a fundamental-rights impact assessment before you deploy. That duty, in Article 27, falls on certain deployers, and a private employer is not always in scope, so it is worth checking rather than assuming (AI Act, Article 27). The point is that the deployer's side of high-risk is a real, documentable program, not a box the vendor ticks for you.

A note on timing

The high-risk obligations are not all live yet. The headline deadline for these duties has moved, from 2 August 2026 toward 2 December 2027, under a simplification package the EU has provisionally agreed but not yet finalised in the Official Journal. The obligation itself has not gone away; the clock has shifted. The sensible read is to use the extra runway to get your inventory and oversight in order, not to file the question away until 2027.

What to do with this

Before you build a compliance program, find out whether you even need one, and for which tools. The fastest way is to check your own use against the law, tool by tool.

Take the free, two-minute self-assessment. Five questions tell you whether your hiring tool is likely high-risk and what the first step is. No email needed to see your result.

Take the free 2-minute check

Want the full checklist and the editable files your team fills in? See the Toolkit (US$ 99, one-time).


This is educational material and a starting point, not legal advice. The EU AI Act is detailed and still evolving, and the high-risk timeline rests on an agreement not yet final in the Official Journal. Whether a specific tool is high-risk, and which obligations attach, depends on your facts; for that, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.

Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.

Do your teams also keep confidentiality walls?

If your work depends on internal walls as well as hiring rules, ethical walls in a law firm, segregated deal teams in private equity, conflict walls in wealth management, the same discipline applies to what AI can say and to whom. Signato is a deterministic chamber that checks every AI output against who-can-know-what and blocks the wrong send before it leaves. It runs 100% local. Start the free 30-day local trial →

Signato · Minas Gerais, Brazil · hello@signato.ai