HR AI: Explicitly High-Risk
The EU AI Act explicitly classifies several HR and recruitment AI systems as high-risk (Annex III, Category 4). This is one of the most practically impactful categories — nearly every large enterprise uses AI somewhere in their hiring or workforce management process. The requirements apply from 2 December 2027 (postponed from the original August 2026 date by the EU's 2026 Digital Omnibus).
What's High-Risk in HR
Recruitment (Art. 6 + Annex III, 4(a))
- CV screening and ranking: AI that filters, scores, or ranks job applications — HireVue, Pymetrics, any ATS with AI screening
- Automated video interviews: AI analysing facial expressions, tone of voice, or word choice to assess candidates
- Job advertisement targeting: AI deciding which candidates see which job postings (if it materially affects access to employment)
- Chatbot screening: Conversational AI that pre-screens candidates and decides who advances
Workforce Management (Art. 6 + Annex III, 4(b))
- Performance evaluation: AI systems used for promotion decisions, performance ratings, or identifying underperformers
- Task allocation: AI assigning work, shifts, or projects based on worker profiling — especially in gig economy and warehouse/logistics
- Monitoring and surveillance: AI-driven employee monitoring (keystroke tracking, email analysis, productivity scoring) when used for employment decisions
- Termination decisions: AI systems influencing who gets terminated, made redundant, or not renewed
Compliance Requirements
For HR Technology Providers (Providers)
- Conformity assessment: Internal conformity assessment (no third-party audit needed for HR AI). Self-certification with technical documentation.
- Bias testing: Test for discrimination across protected characteristics — gender, age, ethnicity, disability. Document results and mitigation measures.
- Technical documentation: Training data description, model architecture, performance metrics, limitations, intended use
- Human oversight: Design the system so a human can effectively oversee and override AI decisions
- Transparency: Inform users (employers) that the system is high-risk AI. Provide clear instructions for deployment.
- EU database registration: Register the system in the EU AI Act database before placing it on the market
For Employers (Deployers)
- Fundamental rights impact assessment: Before deploying high-risk HR AI, assess impact on workers' fundamental rights (Art. 27)
- Inform workers: Employees and candidates must be told that AI is being used in decisions affecting them
- Inform works council: In EU countries with mandatory worker representation, works councils must be informed before deployment
- Human oversight: Ensure trained humans review AI recommendations before final decisions. Never fully automate hiring or termination.
- Data protection: GDPR Art. 22 already restricts automated decision-making. EU AI Act adds additional obligations.
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Practical Implementation
- Inventory all HR AI: Map every tool in your recruitment and HR stack that uses AI — ATS, video interview platforms, performance management, workforce scheduling
- Classify risk: Which are high-risk under Annex III? Some HR tools use only basic automation (not AI) — these may not be in scope.
- Vendor due diligence: Ask HR tech vendors: Are you compliant with the EU AI Act? Can you provide conformity documentation? What bias testing have you performed?
- Human-in-the-loop: Redesign processes so AI recommends, humans decide. Document the human review process.
- Transparency notices: Update candidate communication and employee handbooks to disclose AI use in HR processes
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton