EU AI Act and recruitment: when is candidate screening high-risk?
A practical matrix for separating interview coordination from AI that filters, ranks or evaluates candidates, with current EU AI Act dates and launch tests.
Updated:
The short answer
AI that analyses or filters job applications, evaluates candidates, or influences recruitment and selection can fall within the employment category in Annex III of the EU AI Act. Interview scheduling and factual intake can remain administrative when the system does not score, rank, reject, recommend, profile or materially influence the employment decision.
Classify the actual workflow, not the product name. A tool sold as an assistant can still evaluate people, while a conversational system can stay within a narrow coordination role. Record that boundary before procurement and test it again after the ATS, prompts and downstream rules are connected.
Candidate workflow decision matrix
This matrix is a screening tool for the governance review, not a legal conclusion. The intended purpose, configuration and use of the output decide the classification. A later ATS rule can change the answer even when the conversation itself stays the same.
| Use case | Likely boundary | Question to answer | Acceptance evidence |
|---|---|---|---|
| Confirm identity, availability and book an interview from approved slots | Administrative support if the output stops there | Does any answer change priority, access or suitability? | No score or recommendation is written to the candidate record |
| Summarise stated answers for a recruiter | Depends on design and downstream use | Does the summary infer traits, omit contrary facts or trigger filtering? | Reviewer can see source answers and correct the summary before use |
| Analyse or filter CVs and applications | Annex III recruitment use, generally high-risk | Which criteria exclude or advance a person? | Criteria, logs, data quality, oversight and challenge route are documented |
| Score suitability or predict reliability, performance or retention | Candidate evaluation, generally high-risk | Does the output influence selection even if a person clicks approve? | No automatic rejection and the authorised reviewer can disregard the output |
| Infer emotion from voice or video during an interview | Do not deploy for recruitment | Is the feature inferring emotion from biometric data in a workplace context? | The feature is disabled and blocked in supplier and acceptance tests |
The Article 6(3) exception is narrow
An Annex III system may avoid high-risk classification only when it does not pose a significant risk to health, safety or fundamental rights and does not materially influence the outcome of decision-making. The assessment must be documented. A system that profiles a person remains high-risk under the Act.
Do not treat a final human click as an exemption. If a score, ranking or recommendation shapes the shortlist, the system may still be intended to evaluate candidates. Human review is a control, not a label that changes the function. The Commission's May 2026 classification guidance is still presented as draft guidance, so use the consolidated Regulation as the legal source and record any interpretation that needs specialist review.
Model scenario: a candidate changes an interview time
Model scenario, not a customer case: a candidate calls to move an interview and asks whether their stated language level is sufficient. The assistant may confirm identity, offer approved slots, update the appointment, record the level the candidate states and route the eligibility question to the recruiter.
The same flow crosses the boundary if it converts accent, hesitation, vocabulary or tone into a suitability score, predicts reliability, changes queue priority or recommends rejection. Keep those actions out of the coordination workflow. The candidate-facing notice should also make clear that the person is interacting with AI.
Map data and human authority
The AI Act does not replace GDPR. Document the purpose, lawful basis, data minimisation, notice, access, retention, suppliers, international transfers and the route for rights requests. Free speech and transcripts can capture more personal information than a form, including details the organisation did not ask for.
Name the person who can review, correct and disregard the output before it affects a candidate. Give that person the source information, enough time and real authority. Under GDPR, token involvement does not make a solely automated decision meaningfully human. Keep a route for a candidate to ask for human contact and challenge an outcome.
What applies now and what comes next
The consolidated EU AI Act prohibits workplace emotion recognition, apart from the narrow medical or safety exception. Article 50 transparency duties for direct interaction with AI have applied since 2 August 2026. The AI Omnibus moved the application of Annex III high-risk rules, including relevant employment uses, to 2 December 2027.
The later high-risk date is not a permission to ignore current law. GDPR, equality and employment rules continue to apply, prohibited practices remain prohibited, and a buyer still needs a defensible intended purpose, data flow and decision boundary before launch.
Procurement questions that expose the real function
Ask the supplier to list every field the system creates, including hidden scores, tags, summaries, confidence values and recommended actions. Ask which fields are sent to the ATS and which rules use them. A harmless-looking status can become a filter after integration.
Request separate answers for scheduling, factual intake, summarisation, filtering, ranking and evaluation. Confirm whether voice or video is used to infer emotion, personality, reliability, health or protected characteristics. Record model and prompt changes that can alter the boundary, and make regression testing part of change control.
Six acceptance tests before launch
1. Book an interview with neutral answers and confirm that no score, ranking or suitability tag appears in the ATS. 2. Give an ambiguous answer and confirm that the system routes it to a person instead of guessing. 3. Ask for human contact and verify an owned handoff with context.
4. Compare the generated summary with the source answers and test correction. 5. Trace a rejected or deprioritised candidate to a documented human decision, not an administrative status. 6. Change the prompt, model or ATS rule in a test environment and rerun the boundary tests before release.
FAQ
Is AI interview scheduling high-risk under the EU AI Act?
Not by itself when it only confirms facts and books approved slots without scoring, ranking, filtering, recommending or materially influencing selection. The full configured workflow and downstream ATS use still need review.
Does a human final decision make AI candidate ranking low-risk?
No. A system intended to analyse, filter or evaluate candidates can remain an Annex III high-risk use even when a person makes the final decision. Human oversight is an important control, but it does not automatically change the system's intended function.
When do the relevant EU AI Act rules apply?
Article 50 transparency duties apply from 2 August 2026. After the AI Omnibus, Annex III high-risk rules apply from 2 December 2027. Prohibited practices and existing GDPR, equality and employment obligations must be addressed now.
Sources and further reading
- EUR-Lex: consolidated Regulation (EU) 2024/1689
- European Commission: AI Omnibus enters into force
- European Commission: Article 50 transparency guidelines
- European Commission: draft high-risk classification guidelines
- EUR-Lex: Regulation (EU) 2016/679 (GDPR)
- EDPB: automated decision-making and profiling guidelines
