
Janne Malmisaari
•
Published
30.09.2026
•
11 min read
In short
A recruiter has 240 applications for a customer service role, a hiring manager who wants a shortlist "by tomorrow, ideally today," and zero time. So she copies a handful of CVs into an AI chatbot and asks it to rank them. Ten minutes later she has a tidy list. Problem solved.
Except it isn't. Those CVs, with names, phone numbers, work histories, and maybe a photo or two, just left the building. Nobody on the team knows exactly where they went or whether they can be deleted, and an AI tool nobody vetted just influenced who gets a phone call.
The scenario depicted above is something the EU AI Act will tackle. Although what the recruiter did was something very human, hiring is one of the areas the law regulates most strictly.
This article is for the people living this scenario: recruiters, TA leads, HR directors and hiring managers. It covers what the EU AI Act means for you, where many teams are tripping up right now, and how to get ready.
Disclaimer: this is practical guidance, not legal advice. For your organization's specific obligations, please consult your legal or data protection team.
The EU AI Act is the European Union's law for artificial intelligence. It's widely considered the world's first comprehensive AI law, and it takes a risk-based approach: the riskier the AI system, the stricter the rules.
The Act sorts AI into four risk levels:
AI used in recruitment and employment is generally classified as high-risk (listed in the Act's Annex III). That covers AI used to target job ads, screen or filter applications, rank or evaluate candidates, and make or support decisions about hiring, promotion or termination. Not every AI feature in a recruitment tool is automatically high-risk, though: narrow, preparatory tasks like drafting a job ad may fall outside it, so classification is done feature by feature.
Why is the EU AI Act's classification for recruitment so strict? Because a hiring decision shapes someone's livelihood. An AI system that quietly filters out qualified people because of a biased pattern in its training data could mean someone doesn't get a job they might have deserved.
The Act also splits responsibility between two roles. Providers are the companies that build AI systems (like HR tech vendors). Deployers are the organizations that use them – which means you, if your hiring team uses AI.
Vendors carry the heavier load, but deployers have real duties of their own. More on those below.
If you've been following the news, you might have noticed that the dates have changed.
The AI Act entered into force in August 2024 and was designed to phase in over several years. The original plan had the high-risk rules for recruitment AI kicking in on 2 August 2026. Then, in November 2025, the European Commission proposed a "Digital Omnibus" package to simplify EU digital rules – including a delay to the high-risk obligations. EU lawmakers reached a provisional agreement in May 2026, and the AI Omnibus was formally adopted and entered into force in July 2026.
Here's where things stand now:
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Banned AI practices (incl. emotion recognition at work) and AI literacy | Already in force |
| 2 August 2025 | Rules for general-purpose AI models (the big LLMs behind many AI tools) | Already in force |
| 2 August 2026 | Transparency duties, e.g. disclosing when people interact with AI such as chatbots | Now in force |
| 2 December 2027 | Full high-risk rules for recruitment and employment AI (Annex III) | Postponed from August 2026 |
| 2 August 2028 | High-risk rules for AI embedded in regulated products (machinery, medical devices, etc.) | Postponed from August 2027 |
So hiring teams got roughly 16 extra months. However, three things are worth knowing:
As we put it in our Responsible AI in Recruitment webinar: the deadline moved; the work didn't. Change management takes time, and December 2027 is closer than it looks. Especially for teams that haven't started preparing yet.
Before we get into the pitfalls, here's a quick glossary of the key terms.
GDPR – The EU's data protection law, in force since 2018. It governs how you collect, use, store and delete candidate data like CVs, interview notes and assessment results. GDPR protects the data; the AI Act governs the AI that uses it. You need both.
Automated decision-making – A decision made by a system with no meaningful human involvement, like an AI that auto-rejects everyone below a certain score. GDPR restricts decisions based solely on automated processing when they significantly affect people, such as being rejected from a job.
Human-in-the-loop – AI recommends, a human decides. The AI highlights candidates who match the job profile and shows why; the recruiter reviews the reasoning and makes the call.
Shadow AI – AI tools used at work that the employer hasn't provided or approved. According to Ivanti's Technology at Work report, 46% of office workers use AI tools their employer didn't provide. In recruitment, that looks like pasting CVs into a free chatbot, recording interviews with a personal transcription app, or asking an AI to "pick the top 10" from an applicant spreadsheet.
GPT wrapper – A tool that looks purpose-built but is little more than an interface on top of a general-purpose AI model. Your data is passed on to the model provider, sometimes without personal data filtering, EU data residency or a way to delete it later.
Most organizations aren't breaking the rules on purpose. They're simply moving faster than their processes. Here are the two traps we see most often.
"If you tell people they can't use AI, they'll find a way to use it anyway – because the amount of work isn't going down, and AI helps them keep up."
Shadow AI rarely starts with bad intentions, but with a gap:
As Oskari Valkama, TalentAdore's Head of Product, said in our webinar: "If you tell people they can't use AI, they'll find a way to use it anyway – because the amount of work isn't going down, and AI helps them keep up."
That's why banning AI doesn't fix shadow AI. It just makes it harder to see. And from the AI Act's point of view, an organization that doesn't know which AI tools influence its hiring decisions will struggle to meet its duties as a deployer: human oversight, monitoring, informing candidates and keeping logs.
The second trap is less visible, which makes it easy to miss. It happens when candidate data is sent to external AI providers without anyone checking what happens to it next. There are two routes:
Route 1: Through shadow AI. Every pasted CV and uploaded interview recording is a data transfer. With free consumer tools, the terms may allow the provider to store inputs and even use them to improve their models. Your candidate's work history could end up in someone's training data.
Route 2: Through company-approved tools. Even officially approved software can pipe data out – especially GPT wrappers inside your ATS or HR tech stack. Before using tools like these, stop to ask:
The data security concern is real, and HR professionals know it. When we asked our webinar audience whether data security concerns had slowed their AI adoption in recruitment, 96% of respondents said yes (22% significantly, 74% somewhat). That caution is justified, but the answer isn't to stop using AI. It's to choose AI tools you can vouch for.
Preparing for the AI Act doesn't have to be a massive legal project. It's mostly good recruitment hygiene with a clear owner. Here's a practical, step-by-step plan.
Start with a thorough inventory. List every tool with AI features used anywhere in recruitment – your ATS, sourcing tools, assessment platforms, video interview software, notetakers, chatbots, scheduling tools. Then ask your team what they might use on the side. An anonymous survey can help surface tools people might not otherwise mention.
For each tool, note what it does, what data it handles, and whether it influences who moves forward. Anything that screens, ranks, scores or filters candidates is likely high-risk under the AI Act.
Check your stack for AI practices that have been prohibited since February 2025 – most relevantly for recruiters, tools that claim to detect emotions from facial expressions, voice or body language during interviews (banned outright, subject to a narrow medical/safety exception). Tools that claim to assess personality or honesty are not banned, but they typically fall under the Act's high-risk rules for recruitment, so they need the oversight, documentation and transparency measures covered below, not an outright stop.
We recommend this order: tools first, policy second. A policy that says "don't use AI" without offering an alternative is likely to be ignored.
Once your team has secure tools that actually help, write a human-readable AI policy. Cover which tools are approved, what data can never go into unapproved tools (hint: any candidate personal data), and who to ask when in doubt.
Look at every point in your process where AI is involved and ask: where does a human need to make the call here? Then design for it:
Being open about how you use AI in recruitment is often a legal requirement, it's fair to your candidates, and it's good for your employer brand.
Candidates should know when AI is part of your process, what it's used for, and that a trained person oversees the AI's role in the decision and can explain it on request. The EU AI Act gives affected candidates a right to a clear and meaningful explanation of how a high-risk AI system factored into a decision about them, when that decision significantly affects them and they consider the effect adverse. Update your privacy notice and candidate communications accordingly, and make sure any candidate-facing chatbot clearly identifies itself as AI.
And frankly, "we use AI to help us respond to everyone faster, and a real person makes the final call" is a message many candidates will appreciate in a world where ghosting is still far too common.
Your recruiters and hiring managers don't need to become engineers. But they should understand the basics: what the AI tools they use actually do, where they can go wrong (bias, hallucinations, overconfidence), what data they must never share, and how to question an AI recommendation.
A short training session and a few real-life examples go a long way.
Your vendors are typically the providers under the AI Act – but you choose them, and you're responsible for how you use them. Before renewing or buying, ask:
If the answers are vague, that tells you a lot. If the vendor can't explain their own AI architecture, they probably shouldn't be handling your candidates' data.
Recruitment doesn't happen in isolation. Bring in your data protection officer, IT security and legal teams early. In particular, most recruitment AI use cases will trigger the duty to carry out a Data Protection Impact Assessment (DPIA) under Article 35 GDPR, which the AI Act's Article 26(9) ties directly to the information your AI vendor must provide. The AI Act also requires employers to inform workers' representatives and affected employees before putting a high-risk AI system into use at the workplace, and local labor laws may add requirements of their own.
We've been building AI for recruitment since 2016, well before it became a boardroom buzzword. Our guiding principle hasn't changed: AI is a good servant, but a bad master.
In practice, that means TalentAdore Hire is built so that you don't have to choose between modern AI and peace of mind:
And yes, we want your recruiters to enjoy using AI – because one of the most effective ways to reduce shadow AI is an approved tool people actually prefer to use. That's the idea behind Taika, our AI assistant for recruitment.
Read more about our approach to responsible AI and how TalentAdore Hire supports GDPR and EU AI Act compliance.
The EU AI Act isn't here to take AI away from recruiters. It aims to make sure the AI that helps decide who gets a job is fair, transparent and supervised by people.
Which is exactly how good recruiters want to work anyway.
Want to see what EU AI Act–ready recruitment AI looks like in practice? Book a meeting with our team and we'll walk you through how we've prepared.
The EU AI Act generally classifies AI used in recruitment and employment – such as screening, ranking or evaluating candidates – as high-risk. Once the high-risk rules apply, organizations using these tools need to ensure human oversight, use the systems according to the provider's instructions, monitor them, keep logs and inform candidates when AI is used. Vendors who build the tools carry stricter requirements for risk management, data quality, documentation and transparency.
The full high-risk rules for recruitment and employment AI apply from 2 December 2027. They were originally due on 2 August 2026 but were postponed by the AI Omnibus, which entered into force in July 2026. Some rules already apply: bans on certain AI practices, such as emotion recognition at work, have applied since February 2025, and transparency duties, such as disclosing AI chatbots, apply from August 2026.
Pasting candidate CVs into a consumer AI tool your organization hasn't approved is risky under GDPR: the data may be stored outside the EU, retained or used to train models, and you may not be able to delete it on request. Using AI to screen or rank candidates is also a high-risk use under the EU AI Act. A safer route is an approved, purpose-built recruitment tool with EU data processing and human oversight.
Shadow AI means using AI tools at work that the employer hasn't provided or approved – for example, pasting CVs into a free chatbot or recording interviews with a personal transcription app. It creates data protection risks and makes it hard for the organization to meet its EU AI Act duties, because it can't oversee tools it doesn't know about.
In automated decision-making, a system makes a decision without meaningful human involvement – for example, auto-rejecting candidates below an AI score. In a human-in-the-loop model, AI recommends and a person reviews the reasoning and makes the final decision. GDPR restricts decisions based solely on automated processing that significantly affect people, and the EU AI Act requires human oversight of high-risk AI.
A GPT wrapper is a tool that looks purpose-built but is little more than an interface on top of a general-purpose AI model. In HR tech, the risk is that candidate data is passed on to the model provider without personal data filtering, EU data residency or a way to delete it later. Before using an AI feature, ask the vendor which model it uses, where the data is processed and whether it can be deleted.
GDPR protects personal data, while the EU AI Act regulates AI systems themselves. In recruitment, both apply at the same time: GDPR governs how you process candidate data, and the AI Act governs how AI tools used in hiring are built, supervised and disclosed. Complying with one doesn't automatically mean complying with the other.