Most companies using AI do not have a high-risk system. But a fair share of those that do have no idea. And the usual way in is recruitment.
Not through a major implementation project with a budget and a steering committee. Through a tool the HR department bought on its own, on a subscription, because it cut application review from three days to two hours.
What the provision actually says
Annex III to the AI Act, point 4, covers AI systems intended for the recruitment or selection of natural persons, in particular for placing targeted job advertisements, analysing and filtering applications, and evaluating candidates.
The same point covers systems used to take decisions affecting the terms of employment, promotion and termination, as well as to allocate tasks and to monitor and evaluate workers.
In other words: the whole path from advertisement to exit.
Three misconceptions you hear most often
"But a human takes the decision." That does not remove the classification. The provision covers systems used for screening and evaluation, not only those that decide autonomously. Human oversight is one of the obligations attached to high-risk systems, not a way out of the category.
"That is not AI, it is just filtering." The line can be thin and is worth checking rather than assuming. A filter that rejects applications lacking a required qualification is a rule. A system that learns from historical data, scores fit or ranks candidates is something else. In borderline cases what matters is how the tool works, not what the vendor calls it in marketing material.
"We never bought any AI for recruitment." The most common answer and the most dangerous. AI features are often embedded in ATS platforms a company has used for years, and switch on with an update. Nobody bought anything, and yet the tool started scoring candidates.
What it involves
The high-risk regime is markedly wider than the obligations applying today to any company using AI. On the deployer side, meaning the company that bought and uses the tool:
- using the system in line with the provider's instructions,
- monitoring how it operates,
- informing workers that such a system is in use,
- retaining the logs the system generates,
- ensuring genuine human oversight, by someone with the competence and the authority to intervene.
Conformity assessment of the system and any notified body certificate are the provider's obligations, not yours. But it is on you to check that the provider has met them before you put the tool to work.
One misconception about the fundamental rights impact assessment, or FRIA, is worth clearing up straight away. That obligation does not cover every deployer of a high-risk system. It applies to bodies governed by public law, private entities providing public services, and those deploying credit scoring systems or risk assessment and pricing systems in life and health insurance. A private company recruiting for itself is usually outside its scope.
Deadlines, or why this is not a 2027 problem
Obligations for Annex III systems apply from 2 December 2027. The Digital Omnibus moved that date from August 2026, so there are sixteen months of headroom.
It sounds like a lot. In practice it means the advisory, audit and legal market will be booked solid through the second half of 2027, and companies that start at the last minute will queue with everyone else.
Beyond that, the delay touches nothing else. A company with a recruitment tool is subject today to the AI literacy obligation, the prohibited practices and the transparency obligations, exactly like any other. And from 28 October 2026 a candidate who concludes that something went wrong can file a complaint with the Polish supervisory authority.
What to do this month
Classification, unlike full implementation of the regime, is possible today and takes days rather than months.
Step one: list what HR actually uses. Not just tools with their own invoice. Also AI features inside your ATS, profile-screening plugins, interview recording analysis, recruitment question generators.
Step two: check each tool against point 4 of Annex III. The control question is simple: does this tool differentiate between candidates or employees in any way? If so, it deserves a closer look.
Step three: ask the vendor. Do they consider their system high-risk within the meaning of the AI Act? What documentation and instructions do they provide? Do they plan a conformity assessment before December 2027? The answer, or its absence, will tell you a great deal about who you are working with.
Step four: train the people who use it. Human oversight of a system whose operating logic that human does not understand is oversight on paper only. It is also a separate obligation, in force since February 2025.
The perspective nobody offers
A fair amount of anxiety has built up around this topic, so the other side is worth stating. A company that has an Annex III system and knows it is in a far better position than one that has it and does not.
It has time until December 2027. It can choose a vendor that takes compliance seriously. It can put the process in order before anyone asks. And it can turn that into an argument in conversations with candidates, because transparency toward the people an algorithm decides about is an advantage, not a cost.
The worst case is not an inspection. The worst case is discovering in mid-2027 that a tool bought three years earlier falls under the provision, the vendor has no plans for a conformity assessment, and replacing a recruitment system takes six months.
Check whether this applies to you
We set out who falls into this category, what obligations come with it and what can be done today on our page about high-risk AI systems.
If you would rather start with a quick diagnosis, the AI Ready Check takes three minutes and is free.
Sources
- Regulation (EU) 2024/1689 (AI Act) - Annex III point 4 (employment and worker management), Article 6 (classification), Article 26 (deployer obligations), Article 27 (fundamental rights impact assessment), Article 14 (human oversight): eur-lex.europa.eu
- European Commission - Annex III to the AI Act, the full list of high-risk use cases (AI Act Service Desk): ai-act-service-desk.ec.europa.eu
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) - moving the high-risk deadlines to 2 December 2027 and 2 August 2028: eur-lex.europa.eu
- Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003) - complaints, inspections and penalties from 28 October 2026: dziennikustaw.gov.pl
This article was written with the help of artificial intelligence and reviewed before publication by the author, who takes editorial responsibility for it.