If you're using an AI tool anywhere in your hiring pipeline and any part of that pipeline touches the EU — you're hiring in an EU member state, or you're evaluating candidates who are physically located there — the EU AI Act almost certainly classifies your tool as "high-risk." That classification isn't a warning label. It's a specific, enforceable set of obligations, with penalties that scale into the tens of millions of euros for the worst violations. Most employers we've spoken to know the Act exists. Very few can tell you what it actually requires of them by name.
This piece is a practical walkthrough: what "high-risk" means for a recruiting AI tool specifically, what the compliance timeline actually looks like, who's responsible for what between vendor and employer, and what the real exposure is if you do nothing.
Why Hiring AI Is Automatically High-Risk
The EU AI Act (Regulation (EU) 2024/1689) sorts AI systems into four risk tiers: unacceptable (banned outright), high-risk, limited-risk, and minimal-risk. Annex III of the Act lists the specific use cases that count as high-risk by default, and employment is one of them — explicitly. AI systems used for recruitment or selection of natural persons, including targeted job ads, analysing and filtering applications, and evaluating candidates, are named directly. So is AI used to make decisions on promotion, termination, task allocation, or performance monitoring once someone is hired.
This isn't a marginal or debatable interpretation. If your tool screens resumes, scores video interviews, ranks candidates, or flags applicants for rejection using anything resembling machine learning or automated pattern-matching, it falls inside Annex III by design. There's no exemption for "we're a small startup" or "the AI only assists, a human makes the final call" — a human-in-the-loop reduces some obligations but does not remove the high-risk classification itself.
What "High-Risk" Actually Requires
The obligations differ depending on whether you're the provider (the vendor building the AI system) or the deployer (the employer using it) — and this is the distinction most employers miss. Both carry real legal duties.
Provider obligations (the vendor — HireVue, Eightfold, Paradox, or whoever you're buying from) include: a risk management system covering the tool's full lifecycle, technical documentation demonstrating how the system works and was tested, data governance requirements ensuring training data is relevant, representative, and checked for bias, human oversight mechanisms built into the product, accuracy and robustness testing, and — critically — registration in the EU's public database of high-risk AI systems before the tool goes to market.
Deployer obligations (you, the employer) include: using the system only for its stated intended purpose, assigning human oversight to people with the competence and authority to actually intervene, monitoring the system's operation and reporting risks back to the provider, keeping automatically generated logs for at least six months, running a Fundamental Rights Impact Assessment before deploying the system for the first time, and — for many public-facing or public-sector employers — informing affected workers and their representatives that a high-risk AI system will be used before it's put into service.
Buying a "compliant" tool from a vendor doesn't discharge your own deployer obligations. The Fundamental Rights Impact Assessment, human oversight assignment, and log retention are yours to do, not the vendor's — and this is the piece most companies we've reviewed simply haven't started.
The Timeline
The Act entered into force on August 1, 2024, but obligations phase in over several years rather than all at once:
- February 2025: Bans on unacceptable-risk practices took effect (this includes emotion recognition in the workplace, which is directly relevant — several older AI interview tools that scored facial expression and vocal tone as proxies for "enthusiasm" or "confidence" are now squarely prohibited in EU employment contexts).
- August 2025: Governance rules and obligations for general-purpose AI models took effect.
- August 2026: The bulk of high-risk system obligations — including those covering employment and recruitment AI — become enforceable.
- August 2027: Extended transition period ends for high-risk AI systems that are components of products already regulated under other EU product-safety legislation.
The August 2026 date is the one that matters most for recruiting teams reading this: if you haven't started your Fundamental Rights Impact Assessment or confirmed your vendor's registration status, the runway is short, not comfortable.
Penalties
The Act's penalty structure is tiered by violation severity, and it's steep by design — modelled on GDPR's enforcement approach:
| Violation | Maximum Penalty |
|---|---|
| Use of banned (unacceptable-risk) AI practices | €35 million or 7% of global annual turnover, whichever is higher |
| Non-compliance with high-risk system obligations | €15 million or 3% of global annual turnover, whichever is higher |
| Supplying incorrect, incomplete, or misleading information to authorities | €7.5 million or 1% of global annual turnover, whichever is higher |
"Whichever is higher" is the operative phrase for large employers — for a multinational, 3% of global turnover dwarfs €15 million. SMEs and startups get proportionally reduced caps, but the structural exposure is the same.
How This Connects to What We've Already Covered
Readers of our algorithmic hiring bias dossier and our bias research summary will recognise the underlying pattern: US litigation against AI hiring vendors (the Workday and Eightfold cases) has been proceeding on a theory that these tools function as unlicensed consumer reporting agencies, largely because there's no equivalent to the EU AI Act's proactive registration and impact-assessment regime in US federal law yet. The EU took the opposite approach — building the compliance obligation in up front, before litigation forces the issue case by case. If you operate across both jurisdictions, that means materially different playbooks: in the US, the exposure is largely reactive (react to a lawsuit or an EEOC complaint); in the EU, it's proactive (you're required to document and assess before you deploy, regardless of whether anyone ever complains).
This also reframes a point from our 2026 platform comparison: the categories we found to be lowest-risk from a US litigation standpoint — startup async video tools and interview intelligence layers that don't make autonomous pass/fail decisions — aren't automatically lower-risk under the EU AI Act. Annex III classification is based on the use case (recruitment and selection), not on how sophisticated or "autonomous" the tool markets itself as. A cheap async video tool used to filter applicants is still high-risk under EU law even if it would fly under the radar of an FCRA-style US claim.
What to Actually Do Before August 2026
- Inventory every AI tool touching your hiring pipeline — including ATS features you might not think of as "AI," like automated resume ranking or keyword-match scoring.
- Ask each vendor directly whether their system is registered in the EU database of high-risk AI systems, and request their technical documentation and bias-testing results in writing.
- Run the Fundamental Rights Impact Assessment yourself as deployer — this cannot be outsourced entirely to the vendor.
- Assign named human overseers with actual authority to override or halt the system, not just a nominal sign-off role.
- Set up log retention meeting the six-month minimum, and confirm your vendor's platform actually supports exporting the logs you'd need.
- Check for emotion-recognition features specifically — if any tool in your stack scores facial expression, tone, or "engagement" as a proxy signal, that's a banned practice as of February 2025, not a future risk.
The EU AI Act doesn't ask employers to prove their AI hiring tool is fair after something goes wrong. It requires proof, in advance, that you understood the risk before you deployed the tool at all — and that's a fundamentally different compliance posture than most US-based hiring teams are used to operating under.
This is the thirteenth piece in our AI recruitment research series. We'll be tracking enforcement actions as the August 2026 deadline approaches. Sharingan AI evaluates recruitment technology and policy independently, without vendor sponsorships or affiliate relationships.