Sector guide
The EU AI Act for HR and recruitment
Recruitment is the most explicitly covered commercial use in the Act. Annex III point 4 names it directly, which means most hiring tools are high-risk by description rather than by argument — and one common HR use is prohibited outright.
What the Act actually names in this sector
These are the provisions that reach hr and recruitment, quoted from the Official Journal. Everything below follows from them.
AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates
Annex III, 4(a) →AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics
Annex III, 4(b) →the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions
Article 5(1)(f) →
Common use cases, classified
Prohibited
Banned outright. There is no compliance route — the practice has to stop or change.
- Emotion recognition on staff
Inferring emotions of a natural person in the workplace is a prohibited practice, not a high-risk one — there is no compliance route for it.
Article 5(1)(f) allows a narrow exception where the system is put in place for medical or safety reasons.
Article 5(1)(f) →
High-risk
Permitted, but carries the full Chapter III obligations: risk management, data governance, documentation, logging, human oversight, accuracy and cybersecurity.
- CV screening and candidate ranking
Annex III point 4(a) names systems used to recruit or select people, and specifically to analyse and filter job applications and evaluate candidates.
Annex III, 4(a) → - Targeted job advertising
Point 4(a) names placing targeted job advertisements explicitly — this is high-risk even though no application has been made yet.
Annex III, 4(a) → - Promotion, termination and task allocation
Point 4(b) covers decisions affecting terms of work-related relationships, promotion or termination, and allocating tasks based on behaviour or personal traits.
Annex III, 4(b) → - Performance and behaviour monitoring
Point 4(b) reaches monitoring and evaluating the performance and behaviour of people in work-related relationships.
Annex III, 4(b) → - Interview or screening chatbot
If it evaluates or filters candidates it falls under point 4(a) like any other screening tool; the conversational interface changes nothing.
Annex III, 4(a) →
What gets misread here
Over-classification is the quieter failure: treating something as high-risk when the Act carves it out costs real money and never triggers a complaint, so nobody catches it.
“Emotion or sentiment analysis on staff is high-risk, so we can do it with a conformity assessment.”
It is prohibited, not high-risk. There is no conformity route — the practice stops. The only exception in the provision is use put in place for medical or safety reasons.
Article 5(1)(f) →“Advertising is marketing, so job adverts sit outside the hiring obligations.”
Point 4(a) names placing targeted job advertisements explicitly. The obligation attaches before anyone has applied.
Annex III, 4(a) →“We bought the tool, so the obligations are the vendor's.”
Deployers carry their own obligations, and putting your name on a system, substantially modifying it, or changing its intended purpose makes you the provider of it.
Article 25 →
Dates that matter in this sector
- 2 Dec 2027Annex III high-risk obligations apply — Providers of Annex III high-risk systems (including AI used in employment, education, credit scoring, life and health insurance pricing, essential services, law enforcement and migration) must meet the full Chapter III requirements from 2 December 2027. (date changed by the Omnibus)
- 2 Feb 2025Prohibited practices and AI literacy apply — Since 2 February 2025 the first eight prohibited AI practices in Article 5 have been unlawful across the EU, and every provider and deployer has owed an AI literacy duty under Article 4. Two further prohibitions were added later and apply from 2 December 2026.
Dates are as amended by the Digital Omnibus. See the full timeline for what each one covers.
What the Commission has said
These guidelines are not binding, but they are the Commission’s own reading of the provisions above, and they are the first place a supervisory authority will look. Where they and this guide differ, follow them.
- Guidelines on prohibited AI practices ↗European Commission, February 2025 — interprets Article 5
- Guidelines on transparency obligations for providers and deployers ↗European Commission, 2025 — interprets Article 50
What to do next
Screen your own systems with the scope finder, run a single system through the risk classifier, or work the obligations in order with the checklist.
This guide points you at the provisions that govern your sector. It is not legal advice, and whether a particular system meets a provision turns on facts about that system and on whether you hold it as provider or deployer — see Article 3 and Article 25.