GovCompass

AI in recruitment: risks, bias and what the EU AI Act already requires

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

AI recruitment systems fall under Annex III of the EU AI Act as high-risk, which triggers the full deployer obligations of Article 26, human oversight, data quality, monitoring, log retention, and a Fundamental Rights Impact Assessment under Article 27. These duties cannot be transferred to the software vendor.

For any overloaded HR department the promise is appealing. Instead of manually reviewing hundreds of CVs, an algorithmalgorithmThe learning procedure (e.g. gradient descent, tree induction); running it on training data produces a model. Controls attach to models and systems, not algorithms in the abstract.Open full entry → reads, analyses and ranks candidates in seconds. The best-fitting talent rises to the top; the rest receive an automated rejection. It is efficient, scalable, and it appears objective.

But that objectivity is misleading. Automated candidate screening is one of the most legally exposed applications of artificial intelligence in business. While HR managers welcome the efficiency, their organizations quietly enter the highest riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → category of the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry →, with obligations that are far-reaching and cannot be delegated to the software vendor.

The objective machine is an illusion

An algorithm has no intrinsic understanding of "talent" or "suitability". It recognizes patterns in historical data, in this case, the hiring decisions your organization made in the past. The model does not learn who the best candidate is, but who most resembles the people who were hired successfully before.

If your IT department has historically been predominantly male, or if certain backgrounds were consistently and unconsciously rejected, the algorithm encodes these patterns and repeats them at scale.

This is not theory. In 2018, Amazon found that its internally developed AI recruitment system systematically disadvantaged women for technical roles, because the model had been trained on ten years of hiring data from a male-dominated sector. The system did exactly what it was trained to do. That was the problem. Amazon ended the project.

A tool meant to remove human biasbiasA systematic skew in data, model behavior, or outcomes that treats one group differently from another without justification. Bias usually enters through training data that reflects historical patterns. For high-risk AI systems, Article 10 of the EU AI Act requires examination of datasets for possible biases and measures to detect, prevent, and mitigate them. See fairness, proxy discrimination.Open full entry → works in practice as an amplifier of historical inequality.

Annex III: recruitment and selection is explicitly high-risk

The European legislature recognizes the societal impact of algorithmic decisions in the labor market. Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry → of the EU AI Act explicitly classifies AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → used for recruitment, selection, filtering of applications or evaluation of candidates as high-risk.

This is not a grey area. The moment your organization deploys an AI tool that scores CVs, ranks candidates or supports hiring decisions, a demanding compliance regime takes effect. The core obligations for deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → under Article 26:

  • Demonstrable human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry →, you designate per system a trained, authorized person who can override the AI outcome; their interventions are logged (Art. 26.2)
  • Input data monitoring, you are responsible for the quality of the data the system works with (Art. 26.4)
  • Ongoing monitoring, you actively monitor whether the system performs as intended, even after deployment (Art. 26.5)
  • Log retention, decisions and interventions are recorded for the full period of use (Art. 26.6)
  • Fundamental Rights Impact Assessmentfundamental rights impact assessmentAn assessment that certain deployers of high-risk AI must perform to identify and mitigate the system's risks to people's fundamental rights.Open full entry → (FRIAFRIAFundamental Rights Impact Assessment: required of public bodies and certain private deployers before using some high-risk AI systems under the EU AI Act.Open full entry →), a prior, documented assessment of the impact on fundamental rights, required under Art. 27 only for public-law bodies, private providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → of public services and deployers of Annex III 5(b)/(c) systems, so not for an ordinary private employer (see below)

When does the FRIA apply, and for whom?

The Omnibus did not change the scope of Art. 27. An ordinary private employer using a CV-screening tool is not subject to the FRIA duty, though all other Art. 26 obligations still apply. The FRIA duty attaches to public-law bodies, private providers of public services, and deployers of Annex III point 5(b)/(c) systems (creditworthiness of natural personsnatural personA living human individual, as distinct from a legal person such as a company; the holder of data-protection and AI-Act rights.Open full entry →, and risk assessment and pricing in life and health insurance). A bank or insurer is therefore always FRIA-liable; a private employer screening CVs is not.

The FRIA is not a short questionnaire, but a structured examination across seven fundamental rights dimensions: equality, non-discrimination, privacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry →, human dignity, freedom of occupational choice, the right to a fair process and protection of personal data. For each dimension, you assess the potential impact, the associated risks and the controlcontrolThe concrete, testable measure that reduces a specific risk, and through that risk protects the principle behind it. Also called a risk management measure, risk response, or risk treatment. Always traceable to the risk it addresses: under EU AI Act Art. 9 every control must map back to a specific risk, and controls recorded separately from their risks is a recognized compliance failure. It works in one of three types: preventive, detective, or corrective. See risk, control types, evidence.Open full entry → measures you apply.

The FRIA must be completed before deployment and reviewed periodically. A FRIA produced after an incident does not constitute compliance.

The certified vendor is a myth

The most common defense offered by HR directors: "We use a tool from a major, reputable software vendor. They are certified, so we are compliant."

This misreads the law. When you procure an AI system for recruitment and selection, you are the deployer under the AI Act. Your vendor can guarantee that the software was built correctly, the CE markingCE markingThe mark affixed to products (including high-risk AI systems) indicating conformity with applicable EU requirements.Open full entry → or declaration of conformitydeclaration of conformityThe provider's signed statement that a high-risk AI system meets the AI Act's requirements, drawn up before the system is placed on the market.Open full entry → covers their share of the responsibility. But you are responsible for how and on whom you deploy that system.

No vendor can conduct your FRIA. No vendor can establish your human oversight protocol. No vendor is responsible for the quality of the input data your HR department supplies. These obligations are structurally the deployer's.

Informing applicants (Art. 26(11) and Art. 86)

The duty to inform a person assessed by an Annex III system is Art. 26(11); the right to an explanation of an individual decision is Art. 86. Art. 50 covers a different set, chatbots, synthetic content, emotion recognitionemotion recognitionAn AI system that infers a person's emotions from biometric data; its use in workplaces and education is restricted under the AI Act.Open full entry → and deepfakesdeepfakeAI-generated or manipulated audio, image or video that convincingly depicts real people or events that did not occur; subject to labeling duties under the EU AI Act's transparency tier.Open full entry →. Because the individual-information duty sits in the Annex III regime, it follows the Annex III timeline (2 December 2027), not the 2 August 2026 date that applies to Art. 50. In practice it still means active, comprehensible notice at the moment of assessment, not small print buried in the privacy policy.

In a recruitment context, applicants must know that their CV is assessed by an algorithm, what information is used and how they can contest the outcome. Failing to do so violates both the AI Act and potentially GDPRGDPRRegulation (EU) 2016/679, the General Data Protection Regulation, the EU's law on the processing of personal data. It applies to AI wherever personal data enters training, inputs, outputs, or logs, and it operates alongside the EU AI Act rather than being replaced by it. See controller, processor, lawful basis, DPIA.Open full entry → rights on automated decision-makingautomated decision-makingDecisions based solely on automated processing with legal or similarly significant effects. GDPR Article 22 restricts them to three exception grounds, with human-intervention safeguards.Open full entry → (Art. 22 GDPR).

AI literacy as a legal obligation (Art. 4)

Article 4 of the AI Act has applied since 2 February 2025. It requires organizations to give employees who work with AI systems an appropriate level of AI knowledge, tailored to the specific system and their role.

For an HR employee who uses the output of a screening algorithm daily, this means understanding how the system reaches a ranking, which factors weigh most, how bias can arise and when professional judgment should take precedence over the algorithmic outcome. Demonstrably, with training recordstraining recordsEvidence of who completed which training content version, when, with results, the artifact that makes training function as a compliance control.Open full entry → you can produce at audit. Generic "AI awareness training" does not suffice.

Supervisory scrutiny is no longer theoretical. In its March 2026 Report AI & Algorithms Netherlands, the Dutch Data Protection Authority, the coordinating supervisor for algorithms and AI, devoted a chapter to AI in recruitment and selection. Its conclusion: these systems must be accurate, non-discriminatory, and explainable for candidates, and most currently fall short. A first selection is often made without clarity on how the system predicts suitability, how a judgment forms, or how candidates can contest it. For organizations using AI in hiring, the duties this article describes are already the benchmark a supervisor applies.

Five steps to workable governance

Step 1, Inventory comprehensively. Start with an honest overview of all AI functionality that touches your recruitment process. Not just the visible screening tool, but also the AI features in your Applicant Tracking System, the "smart" search on your careers site, scheduling assistants and video analysis in digital interviews. Shadow AI, AI operating outside the view of IT and compliance, is especially common in HR environments.

Step 2, Conduct the FRIA before going live. Treat the FRIA not as a formality but as a substantive exercise. Involve not only HR but also your privacy officer, legal adviser and, where applicable, the works council. In many jurisdictions, the works council has co-determination rights over the introduction of systems that assess employees or applicants.

Step 3, Establish human oversight as a process, not a principleprincipleOne of the seven responsible-AI values a governed system should live up to (fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, human oversight). A principle is abstract: it states an outcome, not a lever you can pull. It becomes governable by naming the harm that would breach it, assessing the risk that harm carries, and placing controls against that risk. Held this way, a principle becomes a pillar. See pillar, harm, risk.Open full entry →. "Human-in-the-loophuman-in-the-loopOversight configuration where a human approves or decides each case the system recommends. It fits high-stakes individual decisions and is meaningful only with authority, information and time.Open full entry →" is not a philosophical position, it is an operational requirement with a named individual, defined authority and documented evidenceevidenceThe concrete proof that a control is designed, implemented, and working: a test report, an audit trail, an impact assessment, a monitoring log. Each link in the governance chain produces an artifact, and together they are what an organization hands to its own board, a regulator, a customer, or an affected person to show, not say, that a system is governed. Its absence is itself the failure: a risk register without test results, or a mitigation claimed without validation, is a governance gap, not a paperwork one. The closing link of the governance chain. See control, governance.Open full entry →. Designate an oversight officer per system, establish how their interventions are recorded and ensure they can genuinely override the AI outcome.

Step 4, Inform your applicants actively. Build the information obligation into your recruitment communications: state in the confirmation email after an application that the initial screening is partially algorithmic, what information is used and how the individual can contest the outcome.

Step 5, Monitor for distributional bias. Periodically analyze whether AI outcomes systematically diverge along demographic lines. Record the findings and the measures taken. This satisfies your monitoring obligation under Art. 26.5 and provides your strongest defense against a discrimination claim.

Timeline: when do you need to Act?

DateObligationStatus
2 Feb 2025Art. 4 AI LiteracyAI literacySufficient understanding of AI's workings, capabilities and risks for one's role, an explicit expectation for provider and deployer staff under the EU AI Act.Open full entry → in force✅ Required now
2 Aug 2026Art. 50 TransparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → obligations (incl. information duty towards individuals)⚠️ Approaching
2 Dec 2027Full high-risk obligations (Art. 26, FRIA, log retention)🔜 Prepare now

The December 2027 deadline for full high-risk compliance sounds distant, but a FRIA process, establishing human oversight procedures and ensuring AI Literacy each require months of preparation. Organizations that start in 2026 are ahead; those who wait until 2027 will build under time pressure.

What is actually at stake

Organizations deploying AI for recruitment without the corresponding governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry → accumulate a compliance liability that can be called in on two fronts: by the supervisory authority through fines of up to €15 million or 3% of global annual turnover, and through the courts via discrimination proceedings brought by rejected candidates who can show that an algorithm determined their chances.

Organizations that do build the governance achieve something harder to quantify but equally valuable: they can demonstrate that their recruitment process is fair, not because they say so, but because they can prove it.

Continue withFairness
Share Share on LinkedIn

More on Fairness

FRIA step by step: how to conduct a Fundamental Rights Impact Assessment

Guide

A Fundamental Rights Impact Assessment (FRIA) under Art. 27 is conducted step by step: describe the system and its purpose, identify affected persons, assess the impact on each fundamental rights dimension, define mitigation measures, and document the residual risk before deployment.

Art. 10 EU AI Act: data and data governance for high-risk AI

Reference

Art. 10 requires that the training, validation, and testing data for high-risk AI systems meets quality criteria: relevant, sufficiently representative, and as free of errors and complete as possible for the intended purpose. It also requires documented data governance practices covering collection, preparation, bias examination, and gap mitigation, and it permits the limited processing of special-category data where strictly necessary to detect and correct bias, under safeguards.

Art. 27 EU AI Act: Fundamental Rights Impact Assessment (FRIA)

Reference

Art. 27 requires certain deployers, public bodies and private deployers in defined sectors such as credit and insurance, to conduct a Fundamental Rights Impact Assessment (FRIA) before deploying a high-risk AI system, examining the impact on fundamental rights and the mitigation measures.

Art. 5 EU AI Act: all 8 prohibited AI practices explained

Reference

Art. 5 lists the eight prohibited AI practices, including subliminal manipulation, exploitation of vulnerable groups, social scoring, and untargeted facial-recognition scraping. These prohibitions are absolute, apply to every organization regardless of size, and have been in force since 2 February 2025.

More on Human oversight

Agentic AI: what changes when the system acts, not just decides

Analysis

Agentic AI is AI that carries out a chain of actions on its own rather than producing a single output for a human to review. That shift does not add a new responsible-AI principle; it changes how every existing principle has to be governed. The human checkpoint moves from inside each decision to around the whole system: setting the bounds the agent operates within, monitoring the chain as it runs, and holding the ability to intervene.

From Copilot to autopilot: governance in the age of AI agents

Analysis

AI agents do not just answer, they take actions in your systems, amplifying both the value and every failure mode. Governing them means governing the actions, not only the decisions: action allowlists, approval gates for high-consequence steps, full logging, and a kill switch.

Human oversight: keeping people in control of AI

Analysis

Human oversight means AI serves people rather than replacing their judgment. It keeps a competent person meaningfully in control of an AI system, with the authority and the information to intervene, and it keeps that control in proportion to what is at stake. The deeper idea behind it is human-centricity: AI should support human judgment, respect autonomy and dignity, and remain accountable to the people it affects, not only the people who use it. The practical core is choosing the right oversight pattern for the stakes, because oversight that is too light fails to catch harm and oversight that is too heavy fails to scale.

Progressive autonomy: a maturity model for agent deployment

Analysis

The safest way to deploy an agent is to grant it the least autonomy that lets it do its job, then widen that autonomy only as evidence of reliable behavior accumulates. Progressive autonomy is to agentic governance what the three control layers are to the seven pillars of responsible AI: the operating discipline that turns a pillar into a practice. This article sets out a maturity model for agent deployment along three dimensions, decision authority, process autonomy, and accountability, and the controls that should be in place at each level.