The company
- Sector
- HR technology — AI-assisted candidate screening
- Size
- 11 people, Berlin, ~€1.4M ARR
- Their AI
- Ranks and shortlists applicants for mid-market employers, built on a commercial LLM with light fine-tuning
- Why they ran it
- An enterprise prospect's legal team asked for their AI Act position in writing. They had 10 days to answer.
This is a self-assessment tool, not legal advice. For binding determinations, consult a qualified EU AI Act compliance advisor.
Regulation status: reflects the June 2026 AI Omnibus amendments.
You build and sell an AI system that ranks job applicants for employers. That places you in Annex III, point 4(a) — employment and worker management — and you are the provider, because the system is offered to others under your own name. We checked whether the Article 6(3) exemption could remove you from High Risk. It cannot, and the reason is specific: your system ranks and materially influences shortlisting decisions rather than preparing them, and it profiles individuals. Either fact alone would close that door.
What This Means for You
- Your main compliance deadline is 2 December 2027, not August 2026. The June 2026 Omnibus deferred Annex III high-risk obligations by 18 months. A great deal of published advice has not caught up.
- That is not as much time as it sounds. Conformity assessment, technical documentation and a working risk-management system realistically take 12–18 months for a team your size.
- Two duties are already enforceable: Article 50 transparency and Article 4 AI literacy, both live since 2 August 2026.
- You are not a GPAI provider. Light fine-tuning on a small in-domain dataset keeps you downstream of the model, so Article 53 does not apply to you. This is worth stating plainly to anyone who has told you otherwise.
- On penalties: as an SME your fine is the lower of the fixed amount or the percentage of turnover (Article 99(6)) — the inverse of the rule for large firms. At your revenue the theoretical Tier-2 ceiling is roughly €42,000, not €15M. Your realistic near-term cost is not a fine at all — it is the enterprise deal that stalls in procurement, which is exactly why you are reading this.
Obligations That Apply
These apply to you as a provider. Deadlines are the current post-Omnibus dates.
| Obligation | Article | Deadline |
|---|---|---|
| Risk management system — continuous, documented, covering the full lifecycle | Art 9 | 2 Dec 2027 |
| Data governance — training and test sets examined for bias. Acute for you: shortlisting models replicate historical hiring patterns unless actively corrected | Art 10 | 2 Dec 2027 |
| Technical documentation — Annex IV, before placing on the market | Art 11 | 2 Dec 2027 |
| Automatic logging — you answered "partially". Needs to be complete and retained | Art 12 | 2 Dec 2027 |
| Instructions for use — your employer customers are deployers with their own Article 26 duties. They cannot meet them without documentation from you | Art 13 | 2 Dec 2027 |
| Human oversight by design — a recruiter must be able to understand and override a ranking, not just see it | Art 14 | 2 Dec 2027 |
| Accuracy, robustness, cybersecurity — you answered "informally tested". This becomes a documented obligation | Art 15 | 2 Dec 2027 |
| Quality management system | Art 17 | 2 Dec 2027 |
| Conformity assessment + CE marking | Art 43 | 2 Dec 2027 |
| Registration in the EU database | Art 49 | 2 Dec 2027 |
| Serious-incident reporting — you answered you were unaware of this. Needs a written procedure | Art 73 | 2 Dec 2027 |
| Transparency to candidates — applicants must know AI is involved. Your current disclosure sits in your customers' privacy policies, which is not sufficient | Art 50 | Live now |
| AI literacy — staff building and supporting the system need documented competence | Art 4 | Live now |
Overlaps worth knowing
- GDPR Article 22 — automated decisions with legal or similarly significant effect. Shortlisting sits close to this line, and candidates have a right to human intervention. Coordinate this with your Article 14 oversight design rather than solving it twice.
- GDPR Article 35 — a DPIA is almost certainly required. You answered "in progress". Finish it; it feeds your Article 9 risk-management work directly.
- German AGG — national anti-discrimination law already applies to your outputs, independently of the AI Act and with no 2027 grace period.
Not Your Responsibility
Your employer customers are deployers. These duties are theirs, not yours — and knowing the split is worth money in a sales conversation, because their legal team will ask:
- Assigning competent human oversight inside their organisation (Art 26(2))
- Ensuring input data is relevant for their own use (Art 26(3))
- Informing their workers and applicants (Art 26(7))
- A fundamental-rights impact assessment where they are a public body or provide public services (Art 27)
What they need from you is your Article 13 instructions for use. Producing those early turns a compliance obligation into a sales asset.
What you're already doing right
- You document your training data sources and hold a copyright/TDM policy. Most teams at your stage do not, and this is direct evidence for Article 10.
- Recruiters make the final decision and can override rankings. That is the substance of Article 14 — it needs documenting, not inventing.
- You identified biased shortlisting as your worst realistic failure. Naming your own highest risk accurately is what a regulator wants to see, and most self-assessments dodge it.
Your Remediation Checklist
- Publish a candidate-facing AI disclosure. Enforceable now. Not in your customers' privacy policy — visible to the applicant at the point of application. Draft wording is in your Document Pack. Cost: an afternoon.
- Run and record an AI literacy session. Enforceable now. Half a day, minuted, attendance kept. Covers what the model does, its limits, and how to spot a bad ranking.
- Write your Article 13 instructions for use. Not due until 2027, but your customers need it for their own compliance — and your next enterprise deal will ask for it.
- Finish the DPIA. Already in progress. It is the foundation of your Article 9 work; doing them separately duplicates months of effort.
- Commission a bias audit of shortlisting outputs. Article 10 plus AGG exposure, and the single most likely source of a real complaint. Budget for an external reviewer.
- Complete your logging. "Partially" becomes non-compliance in 2027, and logs are your only defence if an output is challenged.
- Draft a serious-incident procedure. Two pages. Define what counts, who reports, to which authority.
- Scope conformity assessment with an external advisor by Q2 2027. Working backwards from 2 Dec 2027, that is the last comfortable moment to begin.
Next Steps
- This week: ship the candidate disclosure and answer your prospect in writing — you now have a dated document that says exactly where you stand.
- This month: finish the DPIA and draft the instructions for use.
- This quarter: commission the bias audit and get a fixed quote for conformity assessment.
Report details
- Company
- redacted at customer's request
- Report reference
- RGL-2026-0037
- Assessment date
- 29 July 2026
- Assessed against
- Regulation (EU) 2024/1689 as amended by the June 2026 Digital Omnibus
- Issued by
- Reglynn · reglynn.eu — self-assessment, not a conformity assessment or certification
- How it was made
- Generated by an AI system (Reglynn, built on Anthropic's Claude) from your assessment answers, against Reglynn's question set and risk logic. Reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50 and discloses AI involvement wherever it occurs — our own self-assessment.
- Verification
- The issuer can confirm this report was generated by Reglynn on the date above — hello@reglynn.eu
Yours will be about your product.
Same structure, your answers. Roughly 10 minutes of questions, then the report lands in your inbox in about five.
Get your report — €59 Or start with the free scanBuyers of the €139 Document Pack also receive three draft compliance documents built from their own answers: a risk management plan, a transparency notice and a human oversight procedure.