Is your hiring tool high-risk? The EU just opened the rulebook for comment
Edition 19. A reading time of about 4 minutes.
The hook
If you use AI anywhere in hiring, there is a draft document open for public comment right now that decides whether your tool is treated as high-risk under the EU AI Act, and you have until 23 July to read it. On 19 May 2026 the European Commission published draft guidelines on how to classify high-risk AI systems under Article 6, with practical examples of what counts and what does not. The consultation was meant to close on 23 June. After requests from industry, the Commission extended it by four weeks, to 23 July 2026. The final guidelines are due by the end of this year. This is not a new obligation and not a change to the law. It is the Commission showing its work on a question that decides how much of the AI Act lands on you: is the tool in your hiring stack high-risk, or not.
What this means
Start with the default, because it is stricter than most teams assume. AI used in recruitment and employment is named directly in Annex III of the AI Act, point 4. Read at the source, point 4 covers AI intended "for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates", and AI used to "make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships" (AI Act, Annex III). If that describes a tool you run, the starting point is high-risk. The burden is on you to show it is not.
There is an off-ramp, and the draft guidelines are about how narrow it is. Article 6(3) says an Annex III system is not high-risk if it does "not pose a significant risk of harm", and it lists four ways that can happen: the system performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations and is "not meant to replace or influence the previously completed human assessment, without proper human review"; or it performs a preparatory task to an assessment (AI Act, Article 6). Notice what is not on that list: "we keep a human in the loop." Adding a reviewer at the end is not, by itself, one of the four conditions. The conditions are about what the system actually does, a narrow, procedural or preparatory job, not about who signs off afterward. A tool that analyses, filters, ranks or scores candidates is doing the assessment, not preparing for one, and that is the heart of what Annex III point 4 names.
And there is a hard stop that overrides all four conditions. The same Article 6(3) states that an Annex III system "shall always be considered to be high-risk where the AI system performs profiling of natural persons" (AI Act, Article 6). Profiling is not left to interpretation here: the AI Act borrows the meaning from EU data protection law, defining it in Article 3(52) as "profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679" (AI Act, Article 3), which is the automated processing of personal data to evaluate personal aspects of someone, such as their performance at work, reliability or behaviour. That is a wide net, and many hiring tools that score, rank or predict things about candidates fall inside it. If yours profiles candidates, the off-ramp is closed, full stop, regardless of how narrow the task looks or how many humans review the output.
This is why the consultation matters even though it changes no law. Article 6(5) requires the Commission to issue guidelines with practical examples of which use cases are high-risk and which are not, and these drafts are that exercise. When the final version lands at the end of 2026, it will be the reference your market surveillance authority, your customers and your own counsel reach for when they ask "is this tool high-risk?". Reading the draft now tells you how the line is likely to be drawn before it hardens, and the window to put your own examples in front of the Commission closes on 23 July. We are stating the consultation dates and scope as published by the Commission on its official consultation page; the substance of Annex III and Article 6 is quoted from the AI Act text itself. What the final guidelines will say is still open, which is the honest reason to read the draft rather than wait.
What to do with this
You do not need a lawyer for the first pass. You need an inventory and an honest read of the draft.
- List every place AI touches a hiring or workforce decision. Sourcing and targeted job ads, application screening and filtering, ranking or scoring, interview tools, and anything that feeds promotion, task allocation or performance management. Annex III point 4 reaches all of these, not just the obvious resume screener. You cannot classify what you have not listed.
- For each tool, test it against Article 6(3) honestly, then check for profiling. Ask whether it genuinely does only a narrow, preparatory or procedural job, or whether it analyses, filters or evaluates people. Then ask the override question: does it profile candidates? If yes, treat it as high-risk and stop debating the carve-out. Write the reasoning down for each tool; that record is what an auditor or a customer will ask to see.
- Read the draft guidelines against your real examples, and consider commenting before 23 July. The Commission published practical examples for exactly this. Find the ones closest to your tools and see which side of the line they fall on. If a real-world case of yours is unclear or wrongly placed, the consultation is the moment to say so, in writing, while the text is still a draft.
- Do not wait for the final guidelines to start the inventory. The classification question does not change with the calendar. The tools you run today are the tools you will have to classify, and the inventory is useful no matter how the final text reads.
This is educational material and a starting point, not legal advice. The EU AI Act is still being implemented, and the guidelines described here are a draft in public consultation until 23 July 2026, not final law; the Commission has said the final guidelines will be adopted by the end of 2026 and they may differ from the draft. Whether a specific tool is high-risk under Article 6 and Annex III depends on the facts of that tool and on national implementing rules. For your situation, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.
Not sure whether your hiring tools count as high-risk under the AI Act? Take the free AI Hiring Risk Self-Assessment to see where you stand, then see the same evidence-first discipline applied to what your AI sends out: the free local trial of the Signato chamber blocks a draft that pairs the wrong person with the wrong subject before it leaves, no card, nothing leaves your machine.
Every claim here is traced to the primary regulation and to the Commission's official consultation page, with each checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. Know someone who uses AI in hiring in the EU? Forward this to them.
Sources:
Primary (read at the source):
- European Commission, Targeted consultation on the draft guidelines for the classification of high-risk AI systems: consultation opened 19 May 2026, originally open until 23 June, extended by four weeks to 23 July 2026; final guidelines to be adopted by the end of 2026; the guidelines contain, in accordance with Article 6(5) AI Act, practical examples of AI systems that should or should not be classified as high-risk. - European Commission, Draft Commission guidelines on the classification of high-risk AI systems (library). - AI Act, Article 6 (Classification rules for high-risk AI systems): Article 6(3) sets the four conditions under which an Annex III system is not high-risk and provides that a system "shall always be considered to be high-risk where the AI system performs profiling of natural persons"; Article 6(5) requires Commission guidelines with practical examples. - AI Act, Article 3 (Definitions), point (52): "'profiling' means profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679", carrying the GDPR meaning of profiling into the AI Act. - AI Act, Annex III, point 4 (Employment, workers management and access to self-employment): covers AI for recruitment or selection, including placing targeted job advertisements, analysing and filtering applications, and evaluating candidates, and AI used to make or support work-related decisions and to monitor and evaluate performance and behaviour. - Canonical text: Regulation (EU) 2024/1689, EUR-Lex CELEX:32024R1689.
Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.
Know someone who hires in the EU? Forward this to them.