If you build or use AI for hiring, promotion, or workforce management, the EU AI Act treats you differently from almost every other software category. Employment sits at the top of Annex III, point 4 — which means most serious HR AI is presumptively high-risk, with the heaviest obligation set in the regulation attached.
That's the headline. The useful part is what decides whether it applies to you: what your system actually does to a candidate or employee, and whether you built it or licensed it.
What counts as high-risk in HR
Annex III 4(a)–(b) covers AI systems intended for recruitment or selection — advertising vacancies, screening or filtering applications, evaluating candidates — and for decisions affecting work relationships: promotion, termination, task allocation based on behaviour or traits, and monitoring or evaluating performance.
| System | Likely classification | Why |
|---|---|---|
| CV ranking / candidate scoring | High-risk | Screens and evaluates candidates — the textbook Annex III 4(a) case, and it profiles individuals |
| AI-assessed video interviews | High-risk | Evaluates candidates; emotion recognition in a work context can even cross into Article 5 territory |
| Attrition prediction / flight-risk scoring | High-risk | Evaluates and predicts employee behaviour |
| Performance-review drafting from manager notes | Possibly exempt via 6(3) | May improve the result of a completed human activity — if it evaluates nothing itself |
| Interview scheduling bot | Limited / minimal | Logistics, not assessment — but Article 50 disclosure applies if it chats with candidates |
| Checking applications for completeness | Likely exempt via 6(3) | Narrow procedural task, no profiling |
The line that decides most cases: does the system evaluate the person, or something else? Parsing a document is fine. Scoring the human who wrote it is profiling — and profiling kills the Article 6(3) exemption absolutely.
Vendor or employer — whose duties are these?
This is where HR AI differs most from other categories, because there are always two companies in the room.
If you build and sell the tool, you're the provider: risk management (Art 9), bias-examined data governance (Art 10), technical documentation, logging, human-oversight design, conformity assessment and CE marking, registration — by 2 December 2027. Your Article 13 instructions for use are also your customers' compliance dependency: their legal teams cannot meet their own duties without documentation from you, which makes producing it early a sales asset, not a cost.
If you license and use the tool, you're the deployer — Article 26: competent human oversight, relevant input data, informing workers and applicants that AI is used on them. No conformity assessment, no CE marking. But note: substantially modifying the vendor's system — or using it for something the vendor didn't intend — can quietly convert you into a provider. The full role test.
What's enforceable today (not 2027)
- Article 50 — candidates must know AI is involved. Disclosure buried in a customer's privacy policy does not reach the applicant. Visible at the point of application, since 2 August 2026.
- Article 5 — emotion recognition in the workplace is banned, not high-risk. If any part of your pipeline infers emotional state of employees or candidates, that's a product decision to make this week.
- Article 4 — AI literacy for the people operating the system: a recorded half-day session is the entire compliance.
The overlaps that save you work
Three regimes hit HR AI at once, and they share evidence. GDPR Article 22 gives candidates a right to human intervention in significant automated decisions — coordinate it with your Article 14 oversight design rather than solving it twice. A DPIA (GDPR Art 35) is almost certainly required — and it feeds your Article 9 risk-management file directly. National anti-discrimination law (Germany's AGG, and its equivalents) already applies to your outputs today, with no 2027 grace period — which is why a bias audit of outcomes is the single highest-value piece of work on the list.
Where to start
Run the free two-minute check to confirm your tier, then work the sequence: candidate-facing disclosure this week (it's live law and takes an afternoon), the role question in writing, the 6(3) analysis if you think you're the exception — documented, because an undocumented exemption is not a position — then DPIA and bias audit. Our sample report is a real HR-tech case: an 11-person Berlin candidate-screening startup, published with permission, showing exactly what the full assessment returns.
Check your HR tool in two minutes
Vendor or employer — the free check tells you your likely tier. The full report maps every obligation with its deadline, like the real HR-tech case in our sample.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.