Using AI to screen, rank or assess candidates? Learn when recruitment AI can be high-risk under the EU AI Act and what HR teams should check.
When can recruitment AI become high-risk?
The EU AI Act identifies certain systems used in employment, worker management and access to self-employment as high-risk. The classification follows the system's intended purpose, not the vendor's marketing language.
Recruitment technology can fall within Annex III where it is intended to place targeted job advertisements, analyse or filter applications, or evaluate candidates. The reason is practical: those systems can influence a person's access to work and affect fundamental rights and equality of opportunity.
- Screening or automatically filtering CVs.
- Scoring or ranking applicants.
- Evaluating candidates or recommending who should progress.
- Targeting job advertisements using AI.
Not every use of AI in recruitment is high-risk
Using ChatGPT, Copilot, Gemini or Claude to improve a vacancy description, summarise notes or draft a routine email does not automatically make that activity high-risk.
The question changes when AI begins analysing people, filtering applications, ranking candidates or materially influencing a hiring decision. Context and intended purpose matter. Human review is an important control, but it does not by itself remove a system from the high-risk category.
Third-party recruitment platforms still matter
Most recruitment businesses do not build their own AI. It may already sit inside an applicant tracking system, sourcing platform, interview tool or candidate-screening service.
The software vendor may be the provider while the recruitment company or employer using the system may be a deployer. The exact role depends on the facts, but buying the technology from someone else does not make governance responsibility disappear.
A better question than 'Do we develop AI?' is: 'Do any of our systems make or influence decisions about candidates?'
What applies now, and what changes in 2027?
Following the AI Omnibus reforms, the main high-risk requirements for Annex III employment systems apply from 2 December 2027. Some prohibited practices already apply. This includes certain uses of AI to infer emotions in workplaces, subject to limited medical or safety exceptions.
The July 2026 AI Omnibus also changed Article 4. Providers and deployers remain required to take measures supporting the development of AI literacy, but they do not have to guarantee a specific level for every individual. Clear training and usage rules are particularly important where staff use AI in decisions affecting people.
Ireland uses a distributed enforcement model. The AI Office of Ireland coordinates implementation alongside designated competent authorities that include the Workplace Relations Commission, Data Protection Commission and Health and Safety Authority. Which authority is relevant depends on the system and issue involved.
What should recruitment businesses check now?
- Ask vendors which features use AI and what those features are intended to do.
- Identify any function that filters, scores, ranks or evaluates candidates.
- Define meaningful human oversight, including when a recommendation must be challenged or overridden.
- Record what candidate data is processed and review the overlap with GDPR requirements.
- Give recruiters clear rules for public generative AI tools and AI embedded in recruitment platforms.
Blanche perspective
AI compliance in recruitment should begin with visibility, not a hundred-page policy.
Which tools are being used? What do they actually do? Do they influence decisions about people? Who remains responsible for the final decision? If those answers are unclear, that is the place to start.
Blanche AI Governance helps businesses identify AI systems, review higher-risk uses and put practical controls around third-party recruitment technology. Or start with the AI Risk Check for a preliminary indication of where your governance needs sit.
Sources
Primary and authoritative sources used for this Insight.