Article 10: what to actually demand from your AI hiring vendor about their data
Edition 21. A reading time of about 5 minutes.
The hook
Ask a vendor selling an AI screening or ranking tool how their model was trained, and most answers you get back are marketing, not evidence: "diverse dataset," "bias-tested," "fair by design." Article 10 of the EU AI Act turns those phrases into a checklist with named parts. It does not tell you whether a specific tool is fair. It tells you exactly what a provider has to be able to show about the data behind it, and once you know the checklist, you know what to ask for instead of taking the marketing at its word.
What this means
Article 10 applies to high-risk AI systems that are trained on data, and for hiring that means the tools in Annex III, point 4: systems used to place targeted job ads, to filter or rank applications, or to evaluate candidates (AI Act, Annex III). Paragraph 1 sets the frame: training, validation and testing datasets have to meet quality criteria "whenever such data sets are used" (AI Act, Article 10(1)). Two paragraphs do the real work.
Paragraph 2 lists eight things a provider's data governance has to cover: the design choices behind the dataset, where the data came from and, for personal data, what it was originally collected for, how it was prepared (annotation, labelling, cleaning, enrichment), the assumptions baked into what the data is meant to represent, whether the data available is actually sufficient for the purpose, an examination for biases likely to harm health and safety, harm fundamental rights, or lead to discrimination, measures to detect and mitigate any bias found, and an honest accounting of the gaps or shortcomings in the data (AI Act, Article 10(2)). That is the difference between "we tested for bias" and a paper trail: origin, preparation, assumptions, gaps, and what was done about what was found.
Paragraph 3 sets the quality bar itself: datasets must be "relevant, sufficiently representative, and to the best extent possible, free of errors and complete in view of the intended purpose," with the right statistical properties for the people the system will be used on (AI Act, Article 10(3)). For a hiring tool, "representative" is not abstract. It means the training data reflects the kind of candidates the tool will actually screen, not a narrower population that happened to be convenient to collect.
Paragraph 5 covers a case worth knowing exists: providers are allowed, exceptionally, to process special categories of personal data (the kind protected under GDPR Article 9, such as data revealing ethnic origin or health) specifically to detect and correct bias in a high-risk system, but only under strict conditions: no other data would do the job, the data is subject to technical limits on reuse and state-of-the-art security, access is tightly controlled, the data is never shared with other parties, it is deleted once the bias is corrected, and the provider keeps a documented reason why this was strictly necessary (AI Act, Article 10(5)). If a vendor tells you they used sensitive demographic data to bias-test their model, this paragraph is the only lawful basis for that, and it comes with a paper trail you can ask to see. Paragraph 6 narrows the whole article for systems that are not trained on data at all: for those, only the testing dataset has to meet these criteria.
None of this makes a tool "compliant" on its own, and Article 10 does not certify fairness. It sets a floor for what a provider's data practices have to look like and be documented, which is exactly what a customer doing due diligence is entitled to ask to see.
On timing: obligations for high-risk systems, Article 10 included, sit in Chapter III and apply from the Act's general application date. Article 113 states plainly, "It shall apply from 2 August 2026" (AI Act, Article 113). That date is currently in motion. The Council gave its final green light to the Digital Omnibus package on 29 June 2026, which would defer stand-alone Annex III high-risk obligations, this one included, to 2 December 2027. As of this writing, that package is not yet published in the EU Official Journal, and until it is, the original Act remains binding law and the 2 August 2026 date formally stands. Publication is expected in July 2026. Plan for Article 10 as a duty that could bind from 2 August 2026, and watch for the date to move.
What to do with this
You are very likely the deployer here, not the provider, so Article 10 obligations sit with your vendor. That does not make it someone else's problem. What a vendor cannot show you becomes your risk the day you use their tool on real candidates.
- Ask for the eight-point paragraph 2 answer, in writing. Where did the training data come from, what was it originally collected for, how was it prepared, what bias examination was run, what did it find, and what data gaps does the vendor admit to. A vendor that cannot answer this in specifics is not ready for Article 10, regardless of what the sales deck says.
- Ask what "representative" means for their dataset, concretely. Representative of what population, tested against what benchmark, and how that compares to the pool of candidates you actually screen.
- Ask directly whether they process special-category data to detect bias. If yes, paragraph 5's conditions apply, and you are entitled to see how they document necessity, access control, and deletion. If a vendor is vague here, treat it as a flag, not a formality.
- Get it in the contract, not just the sales call. A data governance and bias-testing summary, refreshed on model updates, is a reasonable ask for any tool in Annex III scope, and cheap for a vendor with a real answer to provide.
- Track the date, and keep the file either way. 2 August 2026 is the working deadline under the Act as published; the Digital Omnibus would push it to 2 December 2027 once formally published. Whichever date ends up binding, the due diligence itself, what you asked, what the vendor answered, is the record that shows you took data governance seriously before you had to.
Article 10 will not tell you if a specific tool is unbiased. It gives you the vocabulary to ask a vendor to prove their homework, and to notice when they cannot.
This is educational material and a starting point, not legal advice. The EU AI Act is still being implemented, and the application date for the high-risk provider obligations discussed here is among the provisions proposed for change under the Commission's Digital Omnibus package, which the Council approved on 29 June 2026 but which is not yet published in the Official Journal and not yet final law. Under the Act as published the obligation applies from 2 August 2026; the Omnibus would move the stand-alone high-risk obligations to 2 December 2027 once in force. Whether a specific tool or dataset meets Article 10 depends on the facts of that system. For your situation, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.
Not sure which of your hiring tools count as high-risk under the AI Act? Take the free AI Hiring Risk Self-Assessment to see where you stand, then see the same evidence-first discipline applied to what your AI sends out: the free local trial of the Signato chamber blocks a draft that pairs the wrong person with the wrong subject before it leaves, no card, nothing leaves your machine.
Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. Know someone buying or building AI hiring tools in the EU? Forward this to them.
Sources (primary, read 2026-07-13):
- AI Act, Article 10 (Data and data governance): sets quality criteria and data governance practices (paragraphs 2-3), the exceptional basis for processing special categories of personal data for bias detection and correction (paragraph 5), and the narrower scope for systems not trained on data (paragraph 6), for high-risk AI systems. - AI Act, Article 113 (Entry into force and application): the Regulation shall apply from 2 August 2026 (general application date), with earlier dates for prohibitions (2 February 2025) and governance/conformity-assessment provisions (2 August 2025). Article 10 sits in Chapter III and applies from the general date under the Act as published. - AI Act, Annex III (High-risk AI systems referred to in Article 6(2)), point 4: AI systems used in employment, workers management and access to self-employment, including for recruitment or selection, to analyse and filter applications and to evaluate candidates, are high-risk. - Digital Omnibus status (dates in motion, read 2026-07-13, no change vs docs/radar.md passada of 2026-07-11): the Council gave final approval on 29 June 2026 (secondary sources citing Council of the EU press release, direct fetch of consilium.europa.eu blocked/403); the package would defer stand-alone Annex III high-risk obligations to 2 December 2027 but is not yet published in the Official Journal, so the 2 August 2026 date formally stands until publication. Secondary corroboration: Gibson Dunn, DLA Piper. - Canonical text: Regulation (EU) 2024/1689, EUR-Lex CELEX:32024R1689.
Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.
Know someone who hires in the EU? Forward this to them.