Start with Maditon
← Back to Resource Center
EU AI Act · HR-tech 7 min read

EU AI Act for HR-tech and recruitment AI

Most HR and recruitment AI is high-risk under Annex III point 4. What the EU AI Act requires of ATS, candidate scoring, and performance management tools.


The EU AI Act puts HR and recruitment AI in one of its most heavily regulated buckets. Annex III point 4 — “employment, workers management, and access to self-employment” — catches almost every modern HR-tech product, from ATS systems to performance management to algorithmic shift allocation. This guide is the practical interpretation for HR-tech vendors and HR teams buying their tools.

Why HR-tech almost always lands in Annex III

Annex III point 4 covers AI systems intended for:

  • Recruiting or selecting candidates — placing targeted job ads, analysing or filtering applications, evaluating candidates
  • Making decisions affecting work relationships — promotions, terminations, task allocation based on individual traits, monitoring and evaluating workers

The list is broader than most HR-tech vendors initially assume. It catches:

| Product type | Annex III? | |---|---| | ATS with AI résumé screening / ranking | Yes | | AI that scores video interview responses | Yes | | AI-driven candidate-job matching | Yes | | Performance management tools that score employees | Yes | | Promotion-decision support AI | Yes | | AI-driven shift scheduling based on individual traits | Yes | | Job-board search engine (general matching, no individual scoring) | Maybe — Article 6(3) carve-out possible | | HR analytics dashboards (aggregate, anonymised) | No (no individual decisions) | | Onboarding chatbots | No — limited risk under Article 50 | | AI workplace surveillance for emotion or sentiment | Banned under Article 5(1)(f) |

The clearest disqualification: anything that profiles natural persons — scores, ranks, categorises individuals — falls in Annex III and cannot use the Article 6(3) carve-out.

What HR-tech providers owe

If you build HR-tech with AI features and place it on the EU market from 2 December 2027 (postponed from 2 August 2026 to 2 December 2027 under the Digital Omnibus, agreed May 2026 and pending formal adoption) onward, the full provider obligations apply (Articles 9–17):

  1. Risk management system across the lifecycle — including discrimination risk, accuracy gaps, bias against protected groups
  2. Data governance — training and validation data examined for representativeness across gender, age, ethnicity, disability
  3. Technical documentation per Annex IV
  4. Logging — at minimum, what inputs the system received and what outputs it produced
  5. Transparency to deployers — instructions for use covering the system’s limitations, accuracy levels, and known bias profiles
  6. Human oversight design — the deployer must be able to override or disagree with AI outputs; AI must not produce final hiring decisions autonomously
  7. Accuracy, robustness, cybersecurity — documented testing against bias benchmarks
  8. Conformity assessment under Annex VI (internal control)
  9. CE marking and declaration of conformity
  10. Registration in the EU database under Article 49
  11. Post-market monitoring — track real-world outcomes, watch for drift
  12. Serious-incident reporting under Article 73 — particularly if outputs lead to discrimination claims or adverse impact

The bias-testing requirement is the one that catches most HR-tech vendors off guard. Documenting that your model doesn’t disadvantage applicants of a particular gender, age band, or ethnicity is now a substantive engineering deliverable — not a one-paragraph statement.

What HR teams buying HR-tech owe

HR teams using high-risk AI in recruitment or workforce management are deployers under Article 26:

  • Use the system per the provider’s instructions
  • Assign human oversight to a competent named person who actually reviews AI outputs and has authority to override
  • Ensure input data (job descriptions, candidate profiles) is relevant and representative
  • Monitor the system for drift or anomalies
  • Retain logs for at least 6 months
  • Inform workers’ representatives before deploying the system (works council, union)
  • Inform affected persons (candidates, employees) that a high-risk AI system is part of the decision

A Fundamental Rights Impact Assessment under Article 27 is not mandatory for private deployers using HR-tech AI (Article 27 mandates FRIA only for public bodies and specific listed cases like credit and insurance). However, conducting one as good practice is recommended — and a strong vendor will provide most of the input data.

Intersection with GDPR Article 22

HR decisions made solely by automated processing with significant effects trigger Article 22 GDPR. Candidate rejection by automated screening, automated termination decisions, and automated promotion decisions all qualify. See Article 22 GDPR and AI.

The interaction: a high-risk AI system under the AI Act can also be Article 22 GDPR under specific deployment conditions. If your HR-tech is deployed in a way that produces solely-automated decisions, both regimes apply. The cleanest fix is the same in both regimes: build a named human into the decision flow, with substantive review and authority to disagree.

Bias and discrimination — the practical pressure point

EU equal-treatment law (Race Equality Directive 2000/43, Employment Equality Directive 2000/78, Gender Recast Directive 2006/54) applies in parallel. The AI Act doesn’t replace existing anti-discrimination law; it adds to it.

Practical implications:

  • Even a “compliant” high-risk system that produces disparate impact can be challenged under equality law
  • HR-tech vendors should provide deployers with fairness evaluation data — performance broken out by gender, age, and other protected categories where data exists
  • Deployers should document their human-oversight reviews of AI outputs to demonstrate non-discriminatory final decisions

What to do this quarter — HR-tech vendor

  1. Confirm Annex III classification. Most products fall in. Document the reasoning.
  2. Start technical documentation now. Annex IV is 30–80 pages depending on system complexity.
  3. Set up bias evaluation. Pick a methodology (equality of opportunity, demographic parity, equalised odds — document which and why).
  4. Design the human-oversight pattern. The deployer’s review must be substantive. Build the UI accordingly.
  5. Start the conformity assessment workflow. See Conformity assessment for high-risk AI.

What to do this quarter — HR team deployer

  1. List every AI tool in your HR stack. ATS, scheduling, performance reviews, learning platforms.
  2. Demand classification info from each vendor. Risk tier, conformity assessment status, EU database ID.
  3. Identify the human-oversight role. Name the person, confirm their authority.
  4. Update candidate-facing disclosures. Career page text, ATS application emails, employment contracts.
  5. Brief the works council before any new high-risk deployment.

Where Maditon fits

Maditon runs the inventory, classification, and audit-trail layer that HR teams need to satisfy Article 26, and that HR-tech vendors need to satisfy the provider chapter. The transparency-page output gives candidates a single URL where they can see which AI systems an employer uses and how they’re classified — a small thing that turns a potential complaint into a non-event.