Blindstairs
Choose language. Current language: English
Merified HRISRequest demo

EU AI Act guide · Updated August 2026

High-risk employment AI, made easier to navigate.

A working guide to the EU rules around AI used in recruitment, evaluation, promotion, and other consequential employment decisions.

ProhibitedUnacceptable risk
High riskEmployment and People Operations
TransparencySpecific disclosure duties
Minimal riskNo additional AI Act duties

Regulatory snapshot. The implementation timetable changed in 2026. This guide reflects official EU information available on 16 August 2026 and links to the primary sources below.

01

When employment AI is high-risk

Annex III covers AI systems intended for certain employment and worker-management uses. Examples include analysing or filtering applications, evaluating candidates, and supporting decisions that affect promotion, termination, task allocation, monitoring, or evaluation.

Start with intended use, not the label on the software.

Does it analyse or filter job applications?
Does it evaluate or rank candidates?
Does it support decisions about promotion, termination, or task allocation?
Does it monitor or evaluate people in a work relationship?

Article 6(3) provides limited conditions under which some Annex III systems may not be classified as high-risk. Profiling of natural persons remains high-risk. Classification should be documented against the system's actual intended purpose.

02

Provider and deployer are different roles.

The obligations depend on how an organisation participates in the system. A provider develops or places the system on the market under its name. A deployer uses it under its authority. An organisation can move between roles when it substantially modifies a system or changes its intended purpose.

Provider

Builds and demonstrates conformity.

Owns the quality-management system, technical documentation, conformity assessment, and post-market responsibilities.

Deployer

Uses, monitors, and oversees.

Follows the instructions for use, assigns capable human oversight, monitors operation, and meets applicable information duties.

03

The obligation set is a connected system.

For high-risk systems, compliance is not one disclosure or one document. The requirements connect design, data, operation, oversight, and evidence.

01

Risk management

Identify foreseeable risks, define controls, and keep the process active throughout the system lifecycle.

02

Data governance

Assess the relevance, representativeness, and quality of data used for the intended purpose.

03

Documentation and logs

Maintain technical documentation and automatic records that support traceability.

04

Transparency

Give deployers clear information about the system, its intended purpose, limits, and expected oversight.

05

Human oversight

Design and operate the system so an equipped person can understand, monitor, and intervene.

06

Accuracy and security

Set and maintain appropriate levels of accuracy, robustness, and cybersecurity.

04

The current implementation timeline

The AI Omnibus entered into force on 27 July 2026. The updated EU timetable moves the rules for Annex III high-risk systems, including employment use cases, to 2 December 2027.

  1. 1 Aug 2024

    The AI Act entered into force

    The regulation began its phased application.

  2. 2 Aug 2026

    Most provisions apply

    This includes the Article 50 transparency rules for certain AI systems.

  3. 2 Dec 2027

    Annex III high-risk rules apply

    Employment and other stand-alone high-risk use cases move to the updated application date.

05

Questions to bring into the next review

01

What decision is the system actually influencing?

02

Which organisation is the provider, and which is the deployer?

03

Can a reviewer trace an output back to its inputs and criteria?

04

Who is equipped and authorised to exercise human oversight?

05

How are affected workers or candidates informed where required?

06

What changes would trigger a new classification or conformity review?

06

Read the primary sources

This guide is an orientation layer. Use the current official text and implementation guidance for legal analysis.

Put the evidence into practice

Apply it to one workflow

See what a reviewable decision path looks like.

Bring a consequential People Operations decision and explore how standards, evidence, logging, and accountable human authority fit together.

Talk with us

This guide provides general information and is not legal advice. The AI Act and its implementation guidance continue to evolve. Obtain advice for your organisation's specific role and use case.