The answer in thirty seconds
Yes: screening, ranking or assessing candidates with AI is a high-risk use, expressly covered by Annex III of the regulation. But the obligations that come with it only start to apply on 2 December 2027 — the Digital Omnibus postponed them by sixteen months. So you have time, provided you do not confuse them with what already applies.
What is covered, precisely
- The targeting and placing of job advertisements.
- The filtering and ranking of applications.
- The evaluation of candidates during interviews or tests.
- Decisions on promotion, assignment, task allocation and termination.
- The monitoring and evaluation of workers’ performance and behaviour.
In other words, the subject does not stop at recruitment: it covers the whole life of the employment contract.
What applies right now, and gets forgotten
Emotion recognition is prohibited in the workplace, since February 2025. A tool that analyses tone of voice, facial expressions or a candidate’s stress during an interview falls under a prohibition, not under an obligation to prepare for. That is the highest penalty tier.
The GDPR, for its part, is not waiting. A candidate has the right not to be subject to a decision based solely on automated processing which produces legal effects or similarly significantly affects them. A fully automatic pre-selection that rejects without human intervention is therefore a problem today, regardless of the AI Act timetable.
Transparency towards individuals applies as well: if a chatbot conducts a first interview, the candidate must know they are talking to a machine.
A real example
A small business receives three hundred applications per vacancy and uses the automatic screening in its recruitment software. Two habits are enough to change its position: have the tool rank without rejecting — a human decides who is set aside — and have that human oversight written down somewhere, with a name. On the day the December 2027 obligations apply, the essentials will already be in place.
What you can do between now and December 2027
- Ask your vendor, in writing, whether it considers its tool to be high-risk and how far along it is with compliance. Its answer — or its silence — will tell you what you need to know.
- Check that none of the tools you use analyses emotions: that is the only genuinely urgent point.
- Make sure a human decides, and write down who.
- Keep a record of decisions and criteria, with a view to the documentation that will be required.
- Tell candidates that AI is used in the process.
Common mistakes
‘High-risk means banned.’ No. High-risk means regulated: it is allowed, subject to conditions.
‘That’s for 2026.’ No: December 2027 for Annex III, which includes recruitment. Many websites still show the old timetable.
‘Our vendor is handling it.’ It carries the provider’s obligations. Yours — human oversight, informing individuals, monitoring use — remain yours.
Your next step
Compare this page with how you actually work, then ask the community if anything is still unclear.
Ask the community →Reference sources
Going further
This page is based on the consolidated text of Regulation (EU) 2024/1689 in its version of 27 July 2026. Verified 26 August 2026. General information: it does not constitute individual legal advice.