Compliance · July 18, 2026 · 6 min read
The EU AI Act and hiring: what 'high-risk' means for your assessments
The EU AI Act classes employment-related AI as high-risk, with duties around documentation, human oversight, logging and transparency. What that means in practice for hiring assessments.
← Part of Hiring AI is high-risk AI: building for NYC LL144 and the EU AI Act from day one
On this page
A deep dive from our guide to compliance-first hiring AI: the EU AI Act.
Why hiring is high-risk
The Act takes a risk-tiered approach. Employment sits in Annex III, Area 4 — 'employment, workers management and access to self-employment' — which explicitly names AI used to recruit, screen, filter and evaluate candidates, and to make or support decisions on promotion, termination and task allocation. If your tool influences who gets hired, it is high-risk by definition, not by argument.
The core obligations
- Risk management and data governance across the system's lifecycle
- Technical documentation and record-keeping (logging)
- Human oversight — meaningful, not a rubber stamp
- Transparency to the people the system is used on
Human oversight as a feature, not a policy
Article 14 is specific about what oversight means: the people responsible must be able to understand the system's limits, monitor it for anomalies, correctly interpret its output — and, critically, stay alert to automation bias (the pull to over-trust a confident machine) while retaining the power to disregard the output or not use it at all. A recruiter review queue where you approve, edit or reject, with every action logged, is that requirement made concrete. Oversight you can evidence beats a policy document nobody can prove was followed.
The through-line of both LL144 and the EU AI Act is the same: generate records and keep a human in the loop. Build for that and most of the paperwork writes itself.
The clock: 2 August 2026
The high-risk obligations for Annex III systems become enforceable on 2 August 2026, backed by penalties reaching into the tens of millions of euros or a share of global turnover. Providers carry the heaviest load — risk management, data governance, technical documentation, logging, conformity assessment and post-market monitoring — while deployers must run the human oversight in practice and keep their own records. The safe posture is the same for both: a human in the loop, and logs that prove it.
Written by
Jakir Patel · Founder, Hanzomon
Building H-Evaluate — AI-native, quality-gated hiring assessments. Writes about assessment engineering, hiring integrity and compliance-first AI.