Regulatory snapshot. The implementation timetable changed in 2026. This guide reflects official EU information available on 16 August 2026 and links to the primary sources below.
When employment AI is high-risk
Annex III covers AI systems intended for certain employment and worker-management uses. Examples include analysing or filtering applications, evaluating candidates, and supporting decisions that affect promotion, termination, task allocation, monitoring, or evaluation.
Start with intended use, not the label on the software.
Article 6(3) provides limited conditions under which some Annex III systems may not be classified as high-risk. Profiling of natural persons remains high-risk. Classification should be documented against the system's actual intended purpose.
Provider and deployer are different roles.
The obligations depend on how an organisation participates in the system. A provider develops or places the system on the market under its name. A deployer uses it under its authority. An organisation can move between roles when it substantially modifies a system or changes its intended purpose.
Builds and demonstrates conformity.
Owns the quality-management system, technical documentation, conformity assessment, and post-market responsibilities.
Uses, monitors, and oversees.
Follows the instructions for use, assigns capable human oversight, monitors operation, and meets applicable information duties.
The obligation set is a connected system.
For high-risk systems, compliance is not one disclosure or one document. The requirements connect design, data, operation, oversight, and evidence.
Risk management
Identify foreseeable risks, define controls, and keep the process active throughout the system lifecycle.
Data governance
Assess the relevance, representativeness, and quality of data used for the intended purpose.
Documentation and logs
Maintain technical documentation and automatic records that support traceability.
Transparency
Give deployers clear information about the system, its intended purpose, limits, and expected oversight.
Human oversight
Design and operate the system so an equipped person can understand, monitor, and intervene.
Accuracy and security
Set and maintain appropriate levels of accuracy, robustness, and cybersecurity.
The current implementation timeline
The AI Omnibus entered into force on 27 July 2026. The updated EU timetable moves the rules for Annex III high-risk systems, including employment use cases, to 2 December 2027.
- 1 Aug 20241
The AI Act entered into force
The regulation began its phased application.
- 2 Aug 20262
Most provisions apply
This includes the Article 50 transparency rules for certain AI systems.
- 2 Dec 20273
Annex III high-risk rules apply
Employment and other stand-alone high-risk use cases move to the updated application date.
Questions to bring into the next review
What decision is the system actually influencing?
Which organisation is the provider, and which is the deployer?
Can a reviewer trace an output back to its inputs and criteria?
Who is equipped and authorised to exercise human oversight?
How are affected workers or candidates informed where required?
What changes would trigger a new classification or conformity review?
Read the primary sources
This guide is an orientation layer. Use the current official text and implementation guidance for legal analysis.