Signato signato.ai

A human reviewer does not take your hiring tool out of high-risk. The Commission just said so in writing.

Edition 14. A reading time of about 5 minutes.

The hook

Here is a sentence we hear from HR and legal teams almost every week: "Our AI tool only ranks candidates, a person makes the final call, so we are fine." It is a reasonable instinct. It is also the assumption the European Commission has just pushed back on, in writing. In its new draft guidelines on what counts as a high-risk AI system, the Commission is clear that putting a human in the loop does not, on its own, lift an AI hiring tool out of the high-risk category. Human oversight is something you owe once a system is high-risk, not a way to make it stop being one. If your plan rested on "a human reviews it", this is the week to find out whether that plan holds.

What this means

On 19 May 2026 the Commission published draft guidelines on the classification of high-risk AI systems under Article 6 of the EU AI Act, and opened them for public consultation (European Commission, targeted consultation on the draft Article 6 guidelines). Two things to hold steady before anything else. These are guidelines, not new law: they interpret the Article that already exists, they do not amend it. And the Commission is explicit that the guidelines are non-binding: they are a draft reading, and the authoritative interpretation of the AI Act ultimately rests with the Court of Justice of the EU. So nothing here is a fresh obligation landing on you. What it is, is the clearest signal yet of how the regulator reads a rule that already governs hiring tools, and that is worth knowing before someone asks you to defend your setup.

Start with why hiring is in scope at all. The Act treats AI systems listed in Annex III as high-risk (AI Act, Article 6(2)), and Annex III point 4 is the employment line. It covers AI "intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates", and AI used "to make decisions affecting terms of work-related relationships", promotion, termination, task allocation, or to "monitor and evaluate the performance and behaviour" of workers (AI Act, Annex III point 4). If a tool in your hiring stack does any of that, the starting position is high-risk. And it is not limited to permanent staff. The heading itself speaks of "access to self-employment", and the text says "natural persons", not "employees". Early readings of the draft take this scope broadly, extending point 4 to freelancers, service providers and platform workers regardless of contractual status. If you use these tools to source contractors or rank gig workers, treat yourself as in scope, and the open consultation is the place to press the point if your case is borderline.

Now the part that upends the common assumption. Article 6 does contain an exit: under Article 6(3), an Annex III system is not high-risk where it "does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons" and it falls into one of four narrow boxes, a "narrow procedural task", something that only improves "the result of a previously completed human activity", a tool that flags deviations from prior decisions "without proper human review", or a purely "preparatory task". The draft guidelines do two things with this exit. First, they reinforce the same hard line the Act already draws: an Annex III system "shall always be considered to be high-risk where the AI system performs profiling of natural persons" (Article 6(3)), and scoring or ranking candidates on personal characteristics is exactly that. Second, and this is the heart of it, the guidance separates two things that teams routinely blur. Whether a system is high-risk turns on what the system is for. Whether a human reviews its output is a separate question that goes to how you comply once it is high-risk. Human oversight is the Article 14 duty you take on for a high-risk system; it is not a lever that reaches back and changes the classification. Adding a reviewer does not narrow a tool that screens and ranks into a "narrow procedural task", because the tool still does the substantive work, the human is checking it, not replacing it.

The practical translation is uncomfortable but clean. If your screening or ranking tool meaningfully shapes who advances, a person signing off at the end does not move you out of high-risk. It may well be part of how you meet your obligations, which is a good thing, but it is not the get-out many teams assume it is. The teams most exposed here are the ones who reassured themselves with "there's always a human", and then built no further.

A word on timing, because the calendar has moving pieces and it is easy to reach for the wrong date. The high-risk obligations for hiring flow from Annex III through Article 6(2), and under the Act as published they apply with the general application date of 2 August 2026. That is the date to plan around. Two traps to name. The 2 August 2027 date you may see quoted is the separate route for AI built into regulated products under Annex I, Article 6(1); it is not the hiring date. And under the Commission's provisional Digital Omnibus package, Annex III employment systems would move to 2 December 2027 (with AI embedded in products to 2 August 2028), but that change is provisional, pending publication in the Official Journal, and is not yet law. Treat the published 2 August 2026 date as the one that binds until the Official Journal says otherwise. We will flag it here the moment it is settled.

What to do with this

There is a real, time-limited action this week, and you do not need a lawyer for the first steps.

  1. Send a comment to the consultation, while it is open. This is the rare moment when the people who actually run hiring tools can shape how the rule is read, and the window was just extended. The consultation runs to 23 July 2026 (the Commission extended the original 23 June deadline), it is open to "anyone with an interest in the development, deployment, supervision or use of AI systems", and responses go through an online questionnaire (consultation page). If the freelancer or platform scope, or the line between "support tool" and "decision tool", matters to your business, say so now rather than after the guidelines are final.
  2. Pressure-test your "human in the loop" before someone else does. For each AI tool in your hiring stack, write one honest line: does the system do the substantive work (screen, rank, score, evaluate) with a person checking it, or does the person genuinely do the assessment and the tool only assists at the edges? If it is the former, plan as if you are high-risk. The point is not to panic; it is to stop a misread assumption from becoming the foundation everything else sits on.
  3. Turn "a human reviews it" into evidence, not a verbal reassurance. If oversight is part of your compliance story, make it real and recorded: who reviews, what they can actually change, and a trail showing they did. The value when a regulator, a client, or your own board asks is not the sentence "we have a human in the loop", it is being able to show how that oversight works. That record is what stands up; the sentence on its own does not.

Read this way, the draft guidance is not a new burden, it is a correction to a comfortable assumption, delivered early enough to act on. The teams that quietly relied on a final human sign-off to make the problem go away now know it does not. The ones who treat oversight as a documented practice, and place each tool in the right category, are the ones who will have an answer ready when the question comes.


This is educational material and a starting point, not legal advice. These Commission guidelines are in draft, are expressly non-binding, and may change after consultation; authoritative interpretation of the AI Act rests with the Court of Justice of the EU. The Act itself is still being amended, and parts of the high-risk timetable are among the provisions proposed for change under the Commission's Digital Omnibus package, which is not yet final law. How classification and oversight apply to your specific tools, roles and contracts depends on the facts and on national implementing rules. For your situation, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.

Not sure whether your "human in the loop" actually changes anything? Take the free AI Hiring Risk Self-Assessment to see where you stand, then see the same evidence-first discipline applied to what your AI sends out: the free local trial of the Signato chamber blocks a draft that pairs the wrong person with the wrong subject before it leaves, no card, nothing leaves your machine.

Every claim here is traced to the primary regulation and the Commission's own text, and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. Know someone who uses AI in hiring in the EU? Forward this to them.


Sources (primary, read 2026-06-13):

- European Commission, targeted consultation on the draft guidelines on the classification of high-risk AI systems (Article 6 AI Act), draft guidelines published 19 May 2026; consultation deadline extended to 23 July 2026 (from 23 June); open to anyone with an interest in the development, deployment, supervision or use of AI systems; responses via the online questionnaire only. - European Commission, library page for the draft Commission guidelines on classification of high-risk AI systems, confirms publication 19 May 2026 and that the guidelines address Article 6 of the AI Act (three documents: general principles, Annex I, Annex III). - AI Act, Article 6 (Classification rules for high-risk AI systems), Article 6(2) routes Annex III systems into high-risk; Article 6(3) sets the four derogation conditions (narrow procedural task; improving the result of a previously completed human activity; detecting deviations without replacing or influencing the human assessment, without proper human review; preparatory task) and provides that an Annex III system shall always be high-risk where it performs profiling of natural persons. - AI Act, Annex III point 4 (Employment, workers management and access to self-employment), 4(a) recruitment or selection of natural persons, including targeted job advertisements, analysing and filtering applications, and evaluating candidates; 4(b) decisions on terms, promotion or termination of work-related relationships, task allocation, and monitoring or evaluating performance and behaviour. - Canonical text: Regulation (EU) 2024/1689, EUR-Lex CELEX:32024R1689. The guidelines' non-binding character (General principles, para. 6: not binding; authoritative interpretation of the AI Act rests only with the CJEU) is confirmed across first-reads (Modulos citing para. 6, CMS, Bird & Bird); the official PDF was not read directly, so this edition paraphrases rather than quotes the Commission.

Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.

Know someone who hires in the EU? Forward this to them.

AI hiring law, made operational. Free, weekly.

Plain-language, sourced intelligence for HR and legal teams. Start with the free Starter Kit.

No spam. Unsubscribe in one click. See our Privacy Policy.

Run a newsletter on Beehiiv? Add Signato to your recommendations in one click, and send your readers a clear, sourced read on AI compliance.

Add Signato to your recommendations →