What the EU AI Act Means for Hiring Teams

The EU AI Act treats hiring AI as high-risk. Here's what it means for recruiters and hiring teams, the new deadlines, the shadow AI trap, and how to prepare.

What the EU AI Act Means for Hiring Teams

In short

  • The EU AI Act treats AI that screens, ranks or evaluates candidates as high-risk, with duties for vendors and for the employers using it.
  • The high-risk rules for recruitment AI apply from 2 December 2027, but bans such as emotion recognition at work already apply.
  • The most common pitfalls today are shadow AI and candidate data sent to external AI tools without checks.
  • Prepare by mapping your AI tools, offering approved ones, keeping a human in every hiring decision and telling candidates when AI is used.

A recruiter has 240 applications for a customer service role, a hiring manager who wants a shortlist "by tomorrow, ideally today," and zero time. So she copies a handful of CVs into an AI chatbot and asks it to rank them. Ten minutes later she has a tidy list. Problem solved.

Except it isn't. Those CVs, with names, phone numbers, work histories, and maybe a photo or two, just left the building. Nobody on the team knows exactly where they went or whether they can be deleted, and an AI tool nobody vetted just influenced who gets a phone call.

The scenario depicted above is something the EU AI Act will tackle. Although what the recruiter did was something very human, hiring is one of the areas the law regulates most strictly.

This article is for the people living this scenario: recruiters, TA leads, HR directors and hiring managers. It covers what the EU AI Act means for you, where many teams are tripping up right now, and how to get ready.

Disclaimer: this is practical guidance, not legal advice. For your organization's specific obligations, please consult your legal or data protection team.

What is the EU AI Act? How does it affect recruitment?

The EU AI Act is the European Union's law for artificial intelligence. It's widely considered the world's first comprehensive AI law, and it takes a risk-based approach: the riskier the AI system, the stricter the rules.

The Act sorts AI into four risk levels:

  • Unacceptable risk – banned outright. Think social scoring, or AI that infers people's emotions at work.
  • High risk – allowed, but with strict requirements for transparency, human oversight, documentation and data quality.
  • Limited risk – mainly transparency duties, like telling people when they're talking to a chatbot.
  • Minimal risk – spam filters, spell checkers and the like. Carry on.

AI used in recruitment and employment is generally classified as high-risk (listed in the Act's Annex III). That covers AI used to target job ads, screen or filter applications, rank or evaluate candidates, and make or support decisions about hiring, promotion or termination. Not every AI feature in a recruitment tool is automatically high-risk, though: narrow, preparatory tasks like drafting a job ad may fall outside it, so classification is done feature by feature.

Why is the EU AI Act's classification for recruitment so strict? Because a hiring decision shapes someone's livelihood. An AI system that quietly filters out qualified people because of a biased pattern in its training data could mean someone doesn't get a job they might have deserved.

The Act also splits responsibility between two roles. Providers are the companies that build AI systems (like HR tech vendors). Deployers are the organizations that use them – which means you, if your hiring team uses AI.

Vendors carry the heavier load, but deployers have real duties of their own. More on those below.

How the EU AI Act deadlines have moved

If you've been following the news, you might have noticed that the dates have changed.

The AI Act entered into force in August 2024 and was designed to phase in over several years. The original plan had the high-risk rules for recruitment AI kicking in on 2 August 2026. Then, in November 2025, the European Commission proposed a "Digital Omnibus" package to simplify EU digital rules – including a delay to the high-risk obligations. EU lawmakers reached a provisional agreement in May 2026, and the AI Omnibus was formally adopted and entered into force in July 2026.

Here's where things stand now:

DateWhat appliesStatus
2 February 2025Banned AI practices (incl. emotion recognition at work) and AI literacyAlready in force
2 August 2025Rules for general-purpose AI models (the big LLMs behind many AI tools)Already in force
2 August 2026Transparency duties, e.g. disclosing when people interact with AI such as chatbotsNow in force
2 December 2027Full high-risk rules for recruitment and employment AI (Annex III)Postponed from August 2026
2 August 2028High-risk rules for AI embedded in regulated products (machinery, medical devices, etc.)Postponed from August 2027

So hiring teams got roughly 16 extra months. However, three things are worth knowing:

  1. Some rules already apply. The bans on unacceptable AI practices have applied since February 2025. That includes AI that infers emotions in the workplace – so a video interview tool that claims to read a candidate's "enthusiasm" from their facial expressions is very likely already prohibited.
  2. AI literacy is still in the law. The Omnibus softened the obligation (the wording shifted from ensuring a sufficient level of AI literacy to supporting its development), but the idea remains: the people using AI should understand it. And you can't have meaningful human oversight if the humans don't know what they're overseeing.
  3. Do not forget GDPR. The data protection rules for candidate data have applied since 2018, and they already overlap with much of what the AI Act covers.

As we put it in our Responsible AI in Recruitment webinar: the deadline moved; the work didn't. Change management takes time, and December 2027 is closer than it looks. Especially for teams that haven't started preparing yet.

The key terminology of the EU AI Act for HR and talent acquisition professionals

Before we get into the pitfalls, here's a quick glossary of the key terms.

GDPR – The EU's data protection law, in force since 2018. It governs how you collect, use, store and delete candidate data like CVs, interview notes and assessment results. GDPR protects the data; the AI Act governs the AI that uses it. You need both.

Automated decision-making – A decision made by a system with no meaningful human involvement, like an AI that auto-rejects everyone below a certain score. GDPR restricts decisions based solely on automated processing when they significantly affect people, such as being rejected from a job.

Human-in-the-loop – AI recommends, a human decides. The AI highlights candidates who match the job profile and shows why; the recruiter reviews the reasoning and makes the call.

Shadow AI – AI tools used at work that the employer hasn't provided or approved. According to Ivanti's Technology at Work report, 46% of office workers use AI tools their employer didn't provide. In recruitment, that looks like pasting CVs into a free chatbot, recording interviews with a personal transcription app, or asking an AI to "pick the top 10" from an applicant spreadsheet.

GPT wrapper – A tool that looks purpose-built but is little more than an interface on top of a general-purpose AI model. Your data is passed on to the model provider, sometimes without personal data filtering, EU data residency or a way to delete it later.

The most common pitfalls: what hiring teams get wrong right now

Most organizations aren't breaking the rules on purpose. They're simply moving faster than their processes. Here are the two traps we see most often.

"If you tell people they can't use AI, they'll find a way to use it anyway – because the amount of work isn't going down, and AI helps them keep up."

Pitfall #1: Shadow AI fills the gap left by missing processes and tools

Shadow AI rarely starts with bad intentions, but with a gap:

  • No process. There's no AI policy, no list of approved tools, no guidance on what data can go where. So everyone improvises.
  • No tools. The company has banned or ignored AI, but the workload hasn't gone anywhere. Recruiters still need to screen 240 applications by Friday.
  • The wrong tools. The company has approved tools, but they're clunky, generic or not built for recruitment. People often go back to whatever works for them.

As Oskari Valkama, TalentAdore's Head of Product, said in our webinar: "If you tell people they can't use AI, they'll find a way to use it anyway – because the amount of work isn't going down, and AI helps them keep up."

That's why banning AI doesn't fix shadow AI. It just makes it harder to see. And from the AI Act's point of view, an organization that doesn't know which AI tools influence its hiring decisions will struggle to meet its duties as a deployer: human oversight, monitoring, informing candidates and keeping logs.

Pitfall #2: Piping candidate data to external AI vendors

The second trap is less visible, which makes it easy to miss. It happens when candidate data is sent to external AI providers without anyone checking what happens to it next. There are two routes:

Route 1: Through shadow AI. Every pasted CV and uploaded interview recording is a data transfer. With free consumer tools, the terms may allow the provider to store inputs and even use them to improve their models. Your candidate's work history could end up in someone's training data.

Route 2: Through company-approved tools. Even officially approved software can pipe data out – especially GPT wrappers inside your ATS or HR tech stack. Before using tools like these, stop to ask:

  • Which AI model does this feature actually use, and who runs it?
  • Is personal data filtered out before it reaches the model?
  • Where is the data processed and stored – inside the EU or not?
  • Is our data used to train the model?
  • If a candidate asks to be forgotten, can we delete their data everywhere, including on the AI provider's side?
  • Can the tool explain why it recommended one candidate over another?

The data security concern is real, and HR professionals know it. When we asked our webinar audience whether data security concerns had slowed their AI adoption in recruitment, 96% of respondents said yes (22% significantly, 74% somewhat). That caution is justified, but the answer isn't to stop using AI. It's to choose AI tools you can vouch for.

How hiring teams can (and should) prepare for the EU AI Act

Preparing for the AI Act doesn't have to be a massive legal project. It's mostly good recruitment hygiene with a clear owner. Here's a practical, step-by-step plan.

1. Map every AI tool that touches your hiring process

Start with a thorough inventory. List every tool with AI features used anywhere in recruitment – your ATS, sourcing tools, assessment platforms, video interview software, notetakers, chatbots, scheduling tools. Then ask your team what they might use on the side. An anonymous survey can help surface tools people might not otherwise mention.

For each tool, note what it does, what data it handles, and whether it influences who moves forward. Anything that screens, ranks, scores or filters candidates is likely high-risk under the AI Act.

2. Stop anything that's already banned

Check your stack for AI practices that have been prohibited since February 2025 – most relevantly for recruiters, tools that claim to detect emotions from facial expressions, voice or body language during interviews (banned outright, subject to a narrow medical/safety exception). Tools that claim to assess personality or honesty are not banned, but they typically fall under the Act's high-risk rules for recruitment, so they need the oversight, documentation and transparency measures covered below, not an outright stop.

3. Give people good, approved tools – then write the rules

We recommend this order: tools first, policy second. A policy that says "don't use AI" without offering an alternative is likely to be ignored.

Once your team has secure tools that actually help, write a human-readable AI policy. Cover which tools are approved, what data can never go into unapproved tools (hint: any candidate personal data), and who to ask when in doubt.

4. Put a human in the loop – always

Look at every point in your process where AI is involved and ask: where does a human need to make the call here? Then design for it:

  • AI can highlight and recommend – people shortlist and decide.
  • No automatic rejections based on AI scores alone.
  • Make sure recruiters and hiring managers can see why the AI recommended something, so they can challenge it.
  • Give reviewers enough time. Approving hundreds of recommendations in a few minutes isn't meaningful oversight.

5. Tell candidates when and how you use AI

Being open about how you use AI in recruitment is often a legal requirement, it's fair to your candidates, and it's good for your employer brand.

Candidates should know when AI is part of your process, what it's used for, and that a trained person oversees the AI's role in the decision and can explain it on request. The EU AI Act gives affected candidates a right to a clear and meaningful explanation of how a high-risk AI system factored into a decision about them, when that decision significantly affects them and they consider the effect adverse. Update your privacy notice and candidate communications accordingly, and make sure any candidate-facing chatbot clearly identifies itself as AI.

And frankly, "we use AI to help us respond to everyone faster, and a real person makes the final call" is a message many candidates will appreciate in a world where ghosting is still far too common.

6. Build AI literacy in your team

Your recruiters and hiring managers don't need to become engineers. But they should understand the basics: what the AI tools they use actually do, where they can go wrong (bias, hallucinations, overconfidence), what data they must never share, and how to question an AI recommendation.

A short training session and a few real-life examples go a long way.

7. Ask your vendors the hard questions

Your vendors are typically the providers under the AI Act – but you choose them, and you're responsible for how you use them. Before renewing or buying, ask:

  • Is your AI system designed to comply with the EU AI Act's high-risk requirements?
  • Where is candidate data processed and stored, including by AI models?
  • Is personal data filtered before it reaches a language model?
  • Can candidate data be fully deleted on request?
  • Can your AI explain its recommendations and link them back to source data?
  • How do you test for and mitigate bias?
  • What documentation and instructions for use do you provide to deployers like us?

If the answers are vague, that tells you a lot. If the vendor can't explain their own AI architecture, they probably shouldn't be handling your candidates' data.

8. Involve your data protection, IT and legal people early

Recruitment doesn't happen in isolation. Bring in your data protection officer, IT security and legal teams early. In particular, most recruitment AI use cases will trigger the duty to carry out a Data Protection Impact Assessment (DPIA) under Article 35 GDPR, which the AI Act's Article 26(9) ties directly to the information your AI vendor must provide. The AI Act also requires employers to inform workers' representatives and affected employees before putting a high-risk AI system into use at the workplace, and local labor laws may add requirements of their own.

How TalentAdore approaches responsible AI in recruitment

We've been building AI for recruitment since 2016, well before it became a boardroom buzzword. Our guiding principle hasn't changed: AI is a good servant, but a bad master.

In practice, that means TalentAdore Hire is built so that you don't have to choose between modern AI and peace of mind:

  • Human-in-the-loop by design. AI provides insights; your team makes every hiring decision. No automated rejections, no black-box gatekeeping.
  • Explainable recommendations. AI suggestions link back to their source – CV content, application answers or matching criteria – so you can always see the "why."
  • EU-only data processing. All data, including data used by AI features, stays on EU servers.
  • PII filtering. Personally identifiable information is filtered before data reaches a language model.
  • Deletion that actually works. Candidate data can be deleted completely on request.
  • Transparency support. Built-in labeling of AI usage and privacy policy templates to help you inform candidates.
  • Certified security. GDPR-native and ISO 27001-certified, with AI features assessed against EU AI Act requirements during development.

And yes, we want your recruiters to enjoy using AI – because one of the most effective ways to reduce shadow AI is an approved tool people actually prefer to use. That's the idea behind Taika, our AI assistant for recruitment.

Read more about our approach to responsible AI and how TalentAdore Hire supports GDPR and EU AI Act compliance.

The bottom line

The EU AI Act isn't here to take AI away from recruiters. It aims to make sure the AI that helps decide who gets a job is fair, transparent and supervised by people.

Which is exactly how good recruiters want to work anyway.

Want to see what EU AI Act–ready recruitment AI looks like in practice? Book a meeting with our team and we'll walk you through how we've prepared.

Frequently asked questions

What does the EU AI Act mean for recruitment?

The EU AI Act generally classifies AI used in recruitment and employment – such as screening, ranking or evaluating candidates – as high-risk. Once the high-risk rules apply, organizations using these tools need to ensure human oversight, use the systems according to the provider's instructions, monitor them, keep logs and inform candidates when AI is used. Vendors who build the tools carry stricter requirements for risk management, data quality, documentation and transparency.

When does the EU AI Act apply to recruitment AI?

The full high-risk rules for recruitment and employment AI apply from 2 December 2027. They were originally due on 2 August 2026 but were postponed by the AI Omnibus, which entered into force in July 2026. Some rules already apply: bans on certain AI practices, such as emotion recognition at work, have applied since February 2025, and transparency duties, such as disclosing AI chatbots, apply from August 2026.

Can I use ChatGPT or other free AI tools to screen CVs?

Pasting candidate CVs into a consumer AI tool your organization hasn't approved is risky under GDPR: the data may be stored outside the EU, retained or used to train models, and you may not be able to delete it on request. Using AI to screen or rank candidates is also a high-risk use under the EU AI Act. A safer route is an approved, purpose-built recruitment tool with EU data processing and human oversight.

What is shadow AI in recruitment?

Shadow AI means using AI tools at work that the employer hasn't provided or approved – for example, pasting CVs into a free chatbot or recording interviews with a personal transcription app. It creates data protection risks and makes it hard for the organization to meet its EU AI Act duties, because it can't oversee tools it doesn't know about.

What is the difference between human-in-the-loop and automated decision-making?

In automated decision-making, a system makes a decision without meaningful human involvement – for example, auto-rejecting candidates below an AI score. In a human-in-the-loop model, AI recommends and a person reviews the reasoning and makes the final decision. GDPR restricts decisions based solely on automated processing that significantly affect people, and the EU AI Act requires human oversight of high-risk AI.

What is a GPT wrapper, and why does it matter in HR tech?

A GPT wrapper is a tool that looks purpose-built but is little more than an interface on top of a general-purpose AI model. In HR tech, the risk is that candidate data is passed on to the model provider without personal data filtering, EU data residency or a way to delete it later. Before using an AI feature, ask the vendor which model it uses, where the data is processed and whether it can be deleted.

How does GDPR relate to the EU AI Act?

GDPR protects personal data, while the EU AI Act regulates AI systems themselves. In recruitment, both apply at the same time: GDPR governs how you process candidate data, and the AI Act governs how AI tools used in hiring are built, supervised and disclosed. Complying with one doesn't automatically mean complying with the other.

Book a demo

Let's spar on your hiring puzzles