EU AI Act high-risk rules for HR tools: what is covered, what is banned, and a checklist
Under the EU AI Act, AI used to recruit or select people, or to decide on promotion, termination, task allocation or the monitoring and evaluation of workers, is high-risk under Annex III, point 4. After the Digital Omnibus, Regulation (EU) 2026/1744, these high-risk duties apply from December 2, 2027, while the ban on emotion recognition at work and the AI literacy duty have applied since February 2, 2025. Employers carry their own duties as deployers, including trained human oversight, logs kept for at least 6 months and informing workers' representatives before use.
- Tools that screen, rank or assess candidates, allocate tasks by behavior, or evaluate workers' performance are high-risk under Annex III, point 4.
- An Annex III tool that profiles people is always high-risk, so scoring resumes or rating performance cannot use the Article 6(3) exception.
- Emotion recognition on employees and job candidates has been banned since February 2, 2025, except for medical or safety reasons.
- The Digital Omnibus moved the high-risk deadline for HR uses from August 2, 2026, to December 2, 2027.
- Companies outside the EU are covered when they sell AI into the EU or when the output of an AI system is used in the EU.
The EU AI Act high-risk rules for HR reach further into the everyday recruiting and people stack than many teams expect. Screening, ranking and assessing candidates count, and so do tools that allocate shifts by behavior or rate performance. This guide explains where the lines run, what has been banned since February 2025, and what the Digital Omnibus changed when it moved the high-risk deadline to December 2, 2027.
We read the regulation on the European Commission's AI Act Service Desk, followed the Omnibus from the European Parliament's legislative record to the Commission's notice of its entry into force, and checked the Commission's guidance and analysis by law firms, all as of September 24, 2026. The examples come from tools in our directory, checked on the vendors' own pages. This is general information, not legal advice.
Which HR tools are high-risk under the EU AI Act
Annex III of the AI Act lists the areas where AI counts as high-risk, and point 4 covers employment. Point 4(a) covers AI intended for recruiting or selecting people, in particular to place targeted job ads, to analyze and filter applications and to evaluate candidates. Point 4(b) covers AI intended to make decisions on the terms of work relationships, on promotion or termination, to allocate tasks based on individual behavior or personal traits, or to monitor and evaluate the performance and behavior of workers.
The European Commission published draft guidelines on this classification on May 19, 2026, and final guidelines are expected by the end of 2026. According to summaries by the law firms McCann FitzGerald and DLA Piper, the draft treats tools that score, rank or shortlist candidates, job ads targeted through profiling, shift schedulers that allocate work from behavioral signals and systems that adjust pay from ratings as high-risk. Employer branding that is not tied to a vacancy, CV help that candidates use for themselves and onboarding chatbots that answer policy questions fall outside. A human signing off at the end does not change the result when the AI output heavily influences who advances or how workers are rated.
Article 6(3) offers an exception for Annex III systems that do not pose a significant risk, for example because they perform a narrow procedural task, improve work a human already finished, flag deviations from past decisions without replacing human review, or do preparatory work. The exception ends where profiling starts: an Annex III system that profiles people is always high-risk, and scoring a resume or rating performance evaluates personal aspects of a person. The draft guidelines name organizing a CV database without scoring and scheduling interviews as possible exceptions, so for CV screening tools the answer depends on the feature, not the product. A provider that relies on the exception must document its assessment and register the system.
Tools from our directory show how this plays out. TestGorilla rates each resume from 0 to 5 on job criteria, converts the result into a percentile and surfaces a ranked shortlist, which is the evaluation of candidates that point 4(a) names. Textkernel separates a parser that extracts resume data from an engine that matches people and jobs, and only the parser resembles the procedural tasks the draft names as possible exceptions. 15Five drafts performance reviews from its performance data, which likely falls under point 4(b) even though 15Five stresses that a human makes every decision, while the OKR generator from Workpath drafts goals and evaluates no one.
Our reading of Annex III point 4, Article 6(3) and Article 5(1)(f), with examples from the Commission's draft guidelines, September 2026.
Tools in our directory per niche, main or secondary focus. Whether a tool is high-risk depends on the intended purpose of each feature, not on the niche.
Banned since February 2, 2025: emotion recognition at work
Article 5(1)(f) prohibits AI systems that infer the emotions of a person at the workplace or in education, unless the system is meant for medical or safety reasons. The Act defines an emotion recognition system as one that identifies or infers emotions or intentions from biometric data, such as a face or a voice. Article 5(1)(g) adds a second ban that matters in HR: biometric categorization that sorts individuals by their biometric data to infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. Both bans have applied since February 2, 2025, and breaches carry fines of up to €35 million or 7 percent of worldwide annual turnover, whichever is higher.
The Commission's guidelines on prohibited practices, published February 4, 2025, are not binding, but they show how the ban is read. They treat the workplace broadly, covering the whole employment relationship from recruitment to dismissal, including probation, so job candidates are protected as well. Tracking the emotions of customers is outside this specific ban, although such systems can still be high-risk, and inferring emotions from written text is outside it too, because the definition rests on biometric data.
That line matters for interview tools. Sapia.ai runs chat interviews that assess soft skills and behavior traits from typed answers, which keeps it outside the ban but inside point 4(a) as candidate evaluation. For video tools, ask what feeds the score: HireVue stopped using candidates' facial expressions in its assessments years before the ban, and Fortune reported in 2021 that nonverbal data had contributed about 0.25 percent to a model's predictive power in most cases.
The new deadline: December 2, 2027, after the Digital Omnibus
The AI Act, Regulation (EU) 2024/1689, entered into force on August 1, 2024, and applies in stages. The bans and the AI literacy duty came first, on February 2, 2025, followed by the rules for general-purpose AI models on August 2, 2025. Most remaining rules, including enforcement and the transparency duties in Article 50, have applied since August 2, 2026.
The high-risk rules for HR were due on that date as well, until the Digital Omnibus on AI, Regulation (EU) 2026/1744, moved them. The European Parliament approved it on June 16, 2026, the Council on June 29, and it entered into force on July 27, 2026, 3 days after its publication in the Official Journal. High-risk systems under Annex III, which includes employment, now have to meet the rules from December 2, 2027, and high-risk AI built into regulated products under Annex I from August 2, 2028.
The delay moves the date, not the duties. Article 50 already requires providers to design AI systems that talk to people so that those people learn they are dealing with an AI, unless that is obvious, which reaches candidate-facing chatbots, and new bans on AI-generated intimate imagery and child sexual abuse material apply from December 2, 2026. The Omnibus also created a legal basis for providers and deployers to process special categories of personal data to detect and correct bias, under a strict necessity test.
Dates as amended by Regulation (EU) 2026/1744, according to the European Commission's AI Act Service Desk, September 2026.
Provider or deployer: who owes what
The Act splits duties between the provider, which develops a system and places it on the market under its own name, and the deployer, which uses it under its own authority. In HR, the vendor of a screening or review tool is usually the provider and the employer is the deployer. Providers carry the heavier load under Article 16: meeting the technical requirements, running a quality management system, keeping documentation and logs, passing a conformity assessment, issuing an EU declaration of conformity, affixing the CE marking and registering the system.
Employers have their own list in Article 26. They must use the system according to the provider's instructions, assign human oversight to people with the necessary competence, training and authority, and make sure that input data they control is relevant and sufficiently representative. They must monitor the system, inform the provider and the market surveillance authority and suspend use if they have reason to think it presents a risk, and keep the logs it generates for at least 6 months where those logs are under their control.
The Act adds 2 duties that are specific to work. Before a high-risk system is put into service at the workplace, the employer must inform workers' representatives and the affected workers, and people subject to decisions that an Annex III system makes or supports must be told as well. Under Article 86, a person adversely affected by such a decision can ask the deployer for a clear explanation of the role the AI played and the main elements of the decision.
An employer can also turn into a provider. Article 25 says so when a company puts its own name on a high-risk system, makes a substantial modification, or changes the intended purpose of a system, including a general-purpose one, so that it becomes high-risk, which is the case to check when someone ranks applicants with a general chatbot. Assistants built into HR suites deserve the same review, and our comparison of the AI assistants inside HR suites shows which tasks they take on today.
Every employer that uses high-risk HR tools must run a fundamental rights impact assessment.
The assessment is required from public bodies, private entities providing public services and deployers of credit scoring or insurance pricing systems. Most private employers are outside it, while a data protection impact assessment under the GDPR can still be required.
Article 26(9) tells deployers to use the information from the provider for that data protection assessment.
AI literacy: the duty that already applies
Article 4 has applied since February 2, 2025, to providers and deployers of every AI system, high-risk or not, so it already covers a company whose recruiters use a writing assistant. The Digital Omnibus rewrote it: providers and deployers must now take measures to support the development of AI literacy among their staff and other people operating AI systems on their behalf, taking into account their knowledge, experience, training and the context of use.
The Commission's questions and answers on AI literacy, updated July 27, 2026, say the duty remains an obligation but that no specific or sufficient level is mandated, and that providers and deployers need not guarantee any individual's level. For deployers of high-risk systems, the obligation to train staff for human oversight stays in place. No certificate is needed, an internal record of trainings and guidance is enough, and national market surveillance authorities supervise the duty from August 2026.
In practice, that means training by role. Recruiters who read AI rankings need to know how the ranking is built and when to override it, and managers who receive AI-drafted reviews need to know what the draft leaves out. HR operations staff who set screening criteria need to understand how their settings shape results, and each group's training belongs in a dated record.
How the EU AI Act reaches companies outside the EU
The Act follows the market and the output, not the headquarters. Article 2(1) covers providers that place AI systems on the EU market wherever they are established, deployers established or located in the EU, and providers and deployers in other countries where the output of the AI system is used in the EU.
Ogletree Deakins, a US employment law firm, lists what this means for US employers without an EU presence: using AI screening tools for roles open to EU candidates, applying AI to performance, promotion or termination decisions about EU-based employees, and running global HR platforms with AI features that EU establishments use. A provider outside the EU that sells a high-risk system into the EU must first appoint an authorized representative in the Union by written mandate, under Article 22.
The same logic applies to vendors and employers in Türkiye, India or Brazil. IKAI HR, which sells in Türkiye, scores resumes from 0 to 100 with Google's Gemini 2.0 Flash model and markets compliance with the Turkish data protection law KVKK. Used to hire in Türkiye, it is outside the AI Act, but used by the same employer to rank applicants for a job in an EU country, it produces output used in the Union. Hiring rules outside the EU work differently, and our guide to AI hiring bias audits covers the rules in New York City, Illinois and Colorado.
Member states may also keep or add laws that protect workers more than the Act does, or encourage collective agreements that do, under Article 2(11). National rules on informing and consulting works councils or unions therefore still apply on top of the Act.
Checklist: EU AI Act high-risk duties for HR teams
Start with an inventory, because classification follows the intended purpose of each feature rather than the product name. The list starts with the inventory and the rules that already apply, then moves to the duties that start on December 2, 2027, and the vendor questions belong in contracts as well as in demos.
Treat the list as a starting point for your own legal review. Where workers' representatives exist, bring them in before a tool goes live, since Article 26(7) requires informing them in any case.
A checklist in 9 steps for employers that use AI in recruiting or people management in the EU.
- Inventory every AI feature in your HR stack, including assistants built into your HR suiteClassification follows the intended purpose of each feature
- Flag features that screen, rank or score candidates, allocate tasks by behavior, or evaluate performanceAnnex III, point 4
- Switch off any emotion recognition on employees or candidates based on face or voiceBanned since February 2, 2025
- Ask vendors for their Article 6(3) assessment wherever they call a feature not high-riskProfiling rules the exception out
- Name the people who oversee each high-risk tool and record their trainingArticles 4 and 26(2)
- Keep the logs each high-risk system generates for at least 6 monthsArticle 26(6)
- Inform workers' representatives and affected workers before go-live, and tell people when AI supports decisions about themArticles 26(7) and 26(11)
- Check whether anyone uses a general-purpose chatbot to rank or assess peopleArticle 25 can make you the provider
- Plan for December 2, 2027, and review the final Commission guidelines when they appearRegulation (EU) 2026/1744
Tools in this article
Frequently asked questions
Is an applicant tracking system high-risk under the EU AI Act?
It depends on what the AI inside it does. Storing applications or scheduling interviews can fall outside point 4 or under the Article 6(3) exception, while screening, ranking or scoring candidates is high-risk under Annex III, point 4(a). Because scoring people is profiling, the exception does not apply to those features.
When do the EU AI Act high-risk rules apply to HR software?
After the Digital Omnibus, Regulation (EU) 2026/1744, which entered into force on July 27, 2026, the high-risk rules for Annex III uses such as recruitment and worker management apply from December 2, 2027. The ban on emotion recognition at work and the AI literacy duty have applied since February 2, 2025, and the transparency duties in Article 50 since August 2, 2026.
Do employers need a fundamental rights impact assessment for HR AI?
Usually not. Article 27 requires it from public bodies, private entities providing public services and deployers of credit scoring or insurance pricing systems. Most private employers instead need to check whether a data protection impact assessment under the GDPR is required, using the information the provider must supply.
Is sentiment analysis of employee surveys banned under the EU AI Act?
The workplace ban covers systems that infer emotions from biometric data such as faces or voices. The Commission's guidelines place inferring emotions from written text outside the ban, so analyzing typed survey answers is not prohibited on that ground. If the results are used to evaluate individual workers, the tool can still be high-risk under point 4(b).
Does the EU AI Act apply to US companies hiring in Europe?
In many cases, yes. It covers providers that sell AI systems into the EU wherever they are based, and providers and deployers outside the EU when the output is used in the EU, such as rankings of applicants for jobs in the EU. Non-EU providers of high-risk systems must also appoint an authorized representative in the EU.
Sources
- European Commission, AI Act Service Desk: Annex III
- European Commission, AI Act Service Desk: Article 6
- European Commission, Draft guidelines on the classification of high-risk AI systems (May 19, 2026)
- McCann FitzGerald, Employment Spotlight: EU AI Act Draft Guidelines on High-Risk AI Classification
- DLA Piper, EU Commission Publishes Draft Guidelines on High-Risk AI in Employment
- Mayer Brown, EU AI Act News: Digital Omnibus on AI and New Guidance on Risk Classification
- TestGorilla, AI resume scoring
- Textkernel, Parser, matching and skills products
- 15Five, 15Five AI
- Workpath, OKR software with AI features
- European Commission, AI Act Service Desk: Article 5
- European Commission, AI Act Service Desk: Article 3 (definitions)
- European Commission, AI Act Service Desk: Article 99
- European Commission, Guidelines on prohibited AI practices (February 4, 2025)
- Wolters Kluwer, Global Workplace Law and Policy: The Prohibition of AI Emotion Recognition in the Workplace
- Future of Privacy Forum, Red Lines under the EU AI Act: Emotion Recognition in the Workplace
- Sapia.ai, AI Chat Interview
- Fortune, HireVue Stops Using Facial Expressions to Assess Job Candidates (January 19, 2021)
- European Commission, AI Act Service Desk: Timeline for the implementation of the AI Act
- European Commission, AI Act Service Desk: Article 113 (entry into force and application)
- European Commission, AI Omnibus enters into force (July 27, 2026)
- Official Journal of the European Union, Regulation (EU) 2026/1744
- European Parliament, Legislative Train: Digital Omnibus on AI
- K&L Gates, Cyber Law Watch: EU Digital Omnibus on AI Enters Into Force (July 31, 2026)
- Kinstellar, The AI Act after the Digital Omnibus
- European Commission, AI Act Service Desk: Article 50
- European Commission, AI Act Service Desk: Article 16
- European Commission, AI Act Service Desk: Article 25
- European Commission, AI Act Service Desk: Article 26
- European Commission, AI Act Service Desk: Article 27
- European Commission, AI Act Service Desk: Article 86
- European Commission, AI Literacy: Questions and Answers (updated July 27, 2026)
- EU Artificial Intelligence Act (Future of Life Institute), Article 4: AI Literacy, amended text
- Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes
- European Commission, AI Act Service Desk: Article 2
- European Commission, AI Act Service Desk: Article 22
- Ogletree Deakins, The EU AI Act Is Here: What It Means for U.S. Employers (October 31, 2025)
- IKAI HR, AI CV analysis

