EU AI Act Guide · Updated August 2026

High-risk AI, made easier to navigate.

A working guide to the EU rules around AI used in recruitment, candidate evaluation, and employment decisions.

ProhibitedUnacceptable risk
High riskEmployment & recruitment
TransparencySpecific disclosure duties
Minimal riskNo additional AI Act duties

Regulatory snapshot. The implementation timetable has changed during 2026. This guide reflects the European Commission’s position available on 10 August 2026 and links to the primary sources below.

01

When employment AI is high-risk

Annex III covers AI systems intended for certain employment and worker-management uses. Examples include placing targeted job advertisements, analysing or filtering applications, and evaluating candidates.

Start with intended use, not the label on the software.

Does it analyse or filter job applications?
Does it evaluate or rank candidates?
Does it support decisions about promotion, termination, or task allocation?
Does it monitor or evaluate people in a work relationship?

Some Annex III systems may fall outside the high-risk classification in limited circumstances under Article 6(3). Profiling of natural persons remains high-risk. Classification should be documented and reviewed against the system’s actual intended purpose.

02

Provider and deployer are different roles.

The obligations depend on how an organisation participates in the system. A provider develops or places the system on the market under its name; a deployer uses it under its authority. An organisation can move between roles when it substantially modifies a system or changes its intended purpose.

Provider

Builds and demonstrates conformity.

Owns the quality-management system, technical documentation, conformity assessment, registration, and post-market responsibilities.

Deployer

Uses, monitors, and oversees.

Follows the instructions for use, assigns capable human oversight, monitors operation, and meets applicable information duties.

03

The obligation set is a connected system.

For high-risk systems, compliance is not one disclosure or one document. The requirements connect design, data, operation, oversight, and evidence.

01

Risk management

Identify foreseeable risks, define controls, and keep the process active throughout the system lifecycle.

02

Data governance

Assess the relevance, representativeness, and quality of data used for the intended purpose.

03

Documentation & logs

Maintain technical documentation and automatic records that support traceability.

04

Transparency

Give deployers clear information about the system, its intended purpose, limits, and expected oversight.

05

Human oversight

Design and operate the system so an equipped person can understand, monitor, and intervene.

06

Accuracy & security

Set and maintain appropriate levels of accuracy, robustness, and cybersecurity.

04

The current implementation timeline

The original Act used a phased timetable. A political agreement announced in May 2026 moved the Annex III high-risk rules to December 2027. Teams should monitor the Commission’s implementation pages as the legal and standards work continues.

  1. 1 Aug 2024

    The AI Act entered into force

    The regulation began its phased application.

  2. 2 Aug 2026

    Most provisions apply

    This includes the Article 50 transparency rules for certain AI systems.

  3. 2 Dec 2027

    Current high-risk implementation date

    Following the 2026 political agreement on simplification, Annex III high-risk rules, including employment use cases, are scheduled for this date.

05

Questions to bring into the next review

01

What decision is the system actually influencing?

02

Which organisation is the provider, and which is the deployer?

03

Can a reviewer trace an output back to its inputs and criteria?

04

Who is equipped and authorised to exercise human oversight?

05

How are affected workers or candidates informed where required?

06

What changes would trigger a new classification or conformity review?

06

Read the primary sources

This guide is an orientation layer. Use the current official text and implementation guidance for legal analysis.

Related resource

See the wider people-compliance map.

Put AI governance alongside working-time records, equality planning, pay transparency, and people-data responsibilities.

Open the Compliance Center

This guide provides general information and is not legal advice. The AI Act’s implementation and related guidance continue to evolve. Obtain advice for your organisation’s specific role and use case.