The EU AI Act for recruitment agencies
If your agency uses a tool that finds, sorts or scores candidates with AI, the EU AI Act applies to you. The rules for high-risk systems, which include recruitment, apply from 2 December 2027, and a few rules already apply today. This article covers what the Act means for an agency using a vendor's tool, and what to ask that vendor. It's practical guidance, not legal advice.
Recruitment is high-risk
Annex III, point 4(a), names it outright: "AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates". A tool that ranks candidates for a role fits that description.
Article 6(3) lets some Annex III systems out if they only perform a narrow procedural or preparatory task. In recruitment that exit rarely opens, because the same article says an Annex III system is always high-risk when it profiles people. Under Article 4(4) of the GDPR, profiling includes analysing or predicting a person's performance at work, which is exactly what ranking candidates does.
Provider or deployer
The Act splits the duties between two roles. The provider builds the system and puts it on the market, and carries the heavy requirements: risk management, data governance, technical documentation, logging, instructions for use, human oversight designed into the system, accuracy, a conformity assessment and registration in the EU database.
The deployer uses the system in its business. An agency using a vendor's sourcing tool is a deployer.
The roles can shift. Under Article 25(1), a deployer becomes a provider if it puts its own name or trademark on a high-risk system, modifies it substantially, or puts an AI system to a high-risk use it wasn't intended for, general-purpose AI included. Ask a general chatbot to rank a pile of CVs, and your agency may have made itself the provider of a high-risk system, with every duty that comes with it.
What applies when
- 2 February 2025. The prohibitions in Article 5 apply. One of them hits recruitment directly: AI that infers emotions in the workplace is banned, and the Commission's guidelines state that this covers the recruitment process too. The duty on AI literacy (Article 4) started the same day.
- 2 August 2025. Denmark's supplementary act came into force. It makes the Danish Agency for Digital Government (Digitaliseringsstyrelsen) the single point of contact, and splits supervision of the prohibitions between that agency, the Danish Data Protection Agency (Datatilsynet) and the Danish Court Administration.
- 27 July 2026. The Digital Omnibus, Regulation (EU) 2026/1744, came into force. It postponed the high-risk rules and softened AI literacy: providers and deployers must take measures to support their staff's AI literacy, without having to guarantee any particular level.
- 2 December 2027. The high-risk rules apply to Annex III systems, recruitment included. The original date was 2 August 2026.
A high-risk system placed on the market before 2 December 2027 is only caught if its design changes significantly after that date (Article 111(2)). Ask your vendor how it reads that, rather than assuming a tool that ships updates every month is exempt.
What your agency must do once the rules apply
Article 26 collects the deployer's duties. For an agency they come down to this:
- Use the system as instructed. The provider must supply instructions for use. Read them, and use the system for what it was built for.
- Give oversight to the right people. Human oversight must sit with people who have the competence, training and authority it needs, and the support (Article 26(2)). In practice: recruiters who know what the system can and can't do, and who are allowed to overrule it.
- Control your input. To the extent you control the input data, it must be relevant and sufficiently representative for the purpose (Article 26(4)). For an agency, the input is the job ad and its requirements. A requirement that has nothing to do with the job doesn't belong there.
- Monitor and act. Watch how the system behaves. If it presents a risk, inform the provider and the authority and suspend its use (Article 26(5)).
- Keep the logs. Logs the system generates automatically must be kept for at least six months, to the extent they are under your control (Article 26(6)).
- Tell candidates. Deployers that make, or help make, decisions about people must inform them that they are subject to a high-risk AI system (Article 26(11)).
- Use the provider's information in your DPIA. The Act expects you to use it for the data protection impact assessment the GDPR requires (Article 26(9)). Datatilsynet's list of processing that always needs a DPIA includes new technologies combined with one further risk criterion, and profiling on a large scale.
Breaching the deployer's duties can cost up to EUR 15 million or 3% of worldwide annual turnover. For small and medium-sized businesses the lower of the two applies (Article 99).
Human oversight is more than a click
The Act names the danger itself: the tendency to rely automatically, or too much, on a system's output, which it calls automation bias (Article 14(4)(b)). A recruiter who approves a ranked list without looking at it isn't overseeing anything.
Oversight that works looks like this:
- A person makes every yes and no, and can see what each assessment rests on.
- The recruiter can overrule the system and bring back a candidate it filtered out.
- Every decision is saved, with who made it and when.
- What search data can't know, such as languages and education, a person checks.
The GDPR pulls the same way. Article 22 gives people the right not to be subject to a decision based solely on automated processing that significantly affects them, and Recital 71 gives "e-recruiting practices without any human intervention" as its example.
Being open with candidates
A candidate is owed three things:
- Notice of AI. From 2 December 2027, you must tell candidates that a high-risk AI system is being used (Article 26(11)).
- Information about the processing. When you collect a candidate's data from sources other than the person, you owe them the information in Article 14 of the GDPR, and at the latest when you first contact them, if you use the data to contact them.
- An explanation. Article 86 gives anyone affected by a decision taken on the basis of a high-risk Annex III system's output the right to a clear and meaningful explanation of the AI system's role in the decision and of its main elements. You can only give one if you can find the reasoning again.
So say in your privacy notice that you use AI to find and rank candidates, that a person makes the decisions, and how a candidate can ask for an explanation.
What to ask your vendor
- Do you treat the system as high-risk under Annex III, and if not, why not?
- How will you meet the provider requirements by 2 December 2027: technical documentation, conformity assessment and registration?
- Where are the instructions for use, and what do they say about human oversight?
- What does the system log, for how long, and can we access the logs?
- Can we see what each assessment rests on, and can a person always overrule it?
- What does the model see? Are names, photos and protected characteristics such as gender and age kept out, and how do you test for bias?
- Are you our data processor, which sub-processors do you use, and when are candidates deleted?
- Does the system use emotion recognition or biometric categorisation? The answer should be no.
- What will you give us for our DPIA, and for explaining a decision to a candidate?
How Navigent handles it
In Navigent, the recruiter makes every yes and no, and every decision is saved. Every assessment cites the jobs in the candidate's history it rests on, and what search data can't answer is marked "To clarify". You're the data controller and Navigent is the processor, and roles, assessments and decisions are never shared with other customers.
See what an assessment with its evidence looks like on How it works.
Sources
- Regulation (EU) 2024/1689 on artificial intelligence (the AI Act), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (checked 30 September 2026)
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2026/1744/oj (checked 30 September 2026)
- Council of the European Union, the adopted text, PE-CONS 30/26: https://data.consilium.europa.eu/doc/document/PE-30-2026-INIT/en/pdf (checked 30 September 2026)
- European Parliamentary Research Service, "Digital Omnibus on AI", June 2026: https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/782651/EPRS_BRI(2026)782651_EN.pdf (checked 30 September 2026)
- European Parliament, Legislative Train, "Digital Omnibus on AI" (adopted by the Council on 29 June 2026, signed on 8 July 2026): https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai (checked 30 September 2026)
- Cuatrecasas, "Digital Omnibus on AI has been published", 24 July 2026: https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published (checked 30 September 2026)
- European Commission, Guidelines on prohibited AI practices, paragraph 254: https://ai-act-service-desk.ec.europa.eu/sites/default/files/2025-08/guidelines_on_prohibited_artificial_intelligence_practices_established_by_regulation_eu_20241689_ai_act_english_ied3r5nwo50xggpcfmwckm3nuc_112367-1.PDF (checked 30 September 2026)
- Danish Act no. 467 of 14 May 2025 supplementing the AI Act: https://www.retsinformation.dk/eli/lta/2025/467 (checked 30 September 2026)
- Datatilsynet, list of processing that always requires a DPIA (in Danish): https://www.datatilsynet.dk/Media/4/1/Datatilsynets%20liste%20over%20behandlinger%20der%20altid%20er%20underlagt%20kravet%20om%20en%20konsekvensanalyse%20(2).pdf (checked 30 September 2026)
- Regulation (EU) 2016/679 (GDPR), Articles 4, 14 and 22 and Recital 71: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (checked 30 September 2026)