Recruitment AI is high-risk, but not illegal: what you should know about the EU AI Act
George Stephens ·
Originally published on LinkedIn
If your recruitment stack filters CVs, prioritises applicants, generates a suitability score, scores an interview response, measures potential through a game or recommends who to progress, this is relevant to you. This is the first of three parts of an article where I attempt to explain what the regulation is, both in the EU & UK, what validation means, and how to properly manage a high-risk system.
EU AI Act
The EU AI Act, in one sentence, aims to make AI trustworthy by putting controls around uses that can affect health, safety and fundamental rights.
Recruitment is on the high-risk list because decisions about work affect people's livelihoods. AI used to filter applications, rank candidates or evaluate them is normally high-risk. High-risk applications are often confused with two other categories:
- Admin tools, such as interview scheduling, acknowledgement emails or neutral file organisation, will normally sit outside the high-risk category if it does not evaluate a candidate or materially influence selection.
- Video & Audio: some uses are prohibited. In ordinary EU employment, using biometric cues to infer emotion or intention is prohibited (I've seen an 'Enthusiasm' score marketed). A transcript-based assessment of what a candidate said can still be high-risk if it evaluates them, but it is not prohibited biometric emotion inference.
What changes on 2 December 2027?
The EU's high-risk rules for employment systems will apply from 2 December 2027. Ranking, scoring and assessment will not become illegal on that date, but a provider and deployer will need to meet the relevant high-risk controls: a clear purpose, risk management, data governance, human oversight, accuracy measures, and monitoring after deployment, among others.
Therefore if you intend to use a high-risk recruitment system with EU reach after that date, start now to define what it is for, what it is allowed to influence and how you will know when it is wrong.
GDPR is material for AI systems already
GDPR restricts solely automated decisions that have legal or similarly significant effects. Rejecting an applicant without meaningful human involvement is the obvious recruitment example.
Under EU GDPR Article 22, that type of decision needs one of three routes: necessity for a contract (e.g. high volume), authorisation by law or valid explicit consent. The right to human intervention and to challenge the result are safeguards required whichever of the three routes you go down.
High application volume, itself enabled by AI, is an obvious application, but it does not on its own prove that a fully automated rejection is necessary. On the other hand, neither the AI Act nor GDPR says a recruiter must manually reread every application. The dividing line is whether a human could assess the candidate and change the outcome, or merely confirm what the model has already decided.
Waivers/disclaimers do not provide a workaround - candidate notice is needed for transparency, but cannot waive the AI Act, data-protection, discrimination or reasonable-adjustment duties.
UK law: AI in recruiting
The UK has no equivalent AI Act high-risk category; Recruitment AI is governed through UK data-protection law, equality law and employment law. Following the Data (Use and Access) Act 2025, solely automated decisions using ordinary personal data can be made more broadly than under EU GDPR, if there is an appropriate lawful basis.
The safeguards are fairly practical: tell the person about the decision, let them make representations, let them obtain human intervention and let them challenge it.
A UK employer filling a UK role is not automatically within the EU AI Act merely because an applicant happens to be in the EU. The Act's extra-territorial test looks at whether the AI output is used in the EU. EU GDPR has its own territorial test.
Who is responsible?
The provider is responsible for the system it supplies, its purpose, supported claims, testing, technical controls and instructions. The employer is responsible for how it is deployed: the lawful basis, configuration, training, adjustments, candidate recourse and what happens in real decisions. An employer could concievably break a law when using a compliant system through misuse.
At Decision Agent , we accept that role assessment sits in the high-risk category. We build role-specific Scenarios and Conversations, but keep our present AI claim deliberately narrow - whether a candidate displayed a predefined behaviour in a specified response. Recruiters can inspect the source evidence and agree or disagree with the finding. We do not infer emotion or intention from voice, and we do not say that one finding proves overall suitability or future performance.
This does not eliminate the regulatory work, but it does make the intended purpose, evidence and human oversight much easier to define. When considering AI recruiting tools, ask yourself if you could explain how the results are arrived at.
Why use high-risk AI at all?
Opportunity cost. The alternative is not neutral - human judgment can be inconsistent, opaque and biased. If a defined AI-assisted process is prospectively shown to be more accurate and fairer than the actual human alternative, avoiding it because it is AI makes little sense.
This a high bar, but it is also an incentive to begin to gather the right dataset now, investing in the corporate asset that is proprietary data, and setting yourself up to be able exploit AI as it evolves.
Part Two asks the next question: when a recruitment provider says its system is validated, predictive, fair or explainable, what has it actually proved?