
EU AI Act and recruitment: what staffing agencies need to know
Is AI in recruitment high-risk under the EU AI Act? What staffing agencies must do, the dates after the AI Omnibus, GDPR Article 22 and a risk table.
Most AI that screens, ranks or matches candidates is high-risk under the EU AI Act, but high-risk does not mean banned. It means duties: the vendor that builds the system (the provider) must design and document it to strict requirements, and the agency that uses it (the deployer) must follow the instructions for use, put a qualified person in charge, keep the logs and tell candidates and workers. Since the AI Omnibus, these high-risk rules apply from 2 December 2027, while the ban on emotion recognition at work already applies.
General information, not legal advice. Checked against the AI Act, the AI Omnibus and the GDPR in the Official Journal and the European Commission's AI Act pages on 1 October 2026.
Is AI in recruitment high-risk under the EU AI Act?
Yes, for the uses that matter most. Annex III, point 4 of the AI Act lists two groups of high-risk AI in employment:
- Recruitment and selection (4a): AI intended to recruit or select people, in particular to place targeted job ads, to analyse and filter job applications, and to evaluate candidates.
- Managing people at work (4b): AI intended to make decisions on terms of work, promotion or termination, to allocate tasks based on individual behaviour or personal traits, or to monitor and evaluate performance and behaviour.
For a staffing agency, point 4b matters as much as 4a. Your temps and contractors are in work relationships, so AI that hands out shifts based on how people behave, or rates their performance, can fall under it too.
There is an exception. Under Article 6(3), a system listed in Annex III is not high-risk if it does not pose a significant risk of harm, including by not materially influencing the outcome of a decision, and it meets one of four conditions, such as performing only a narrow procedural task or a preparatory task. But a system that profiles people is always high-risk, and a provider that relies on the exception must document its assessment (Article 6(4)). In practice: a tool that scores or ranks candidates stays high-risk; a tool that only books an interview slot is unlikely to be.
When do the EU AI Act rules apply to recruitment?
The dates changed in 2026. The AI Omnibus, Regulation (EU) 2026/1744 of 8 July 2026, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the high-risk dates and rewrote the AI literacy article. The timeline that applies now:
- 1 August 2024: the AI Act enters into force.
- 2 February 2025: prohibited practices apply, including emotion recognition in the workplace, together with the general provisions such as AI literacy.
- 2 August 2026: most of the Act applies, including the transparency rules in Article 50, and national and EU enforcement starts.
- 2 December 2027: the high-risk rules for Annex III apply, which covers recruitment, selection and managing workers.
- 2 August 2028: the high-risk rules for AI built into regulated products (Annex I) apply, rarely relevant for an agency.
Many articles still give 2 August 2026 for the high-risk rules. That was the original date and no longer applies; see the Commission's implementation timeline.
A high-risk system already placed on the market or put into service before 2 December 2027 is only caught if its design changes significantly after that date (Article 111(2)). Do not count on this for a vendor product that keeps changing; ask the vendor how it applies.
Outside the EU. In Sweden and Denmark the AI Act applies directly as EU law. Norway's government considers it EEA-relevant, so it is expected to be taken into Norwegian law through the EEA Agreement; check the current Norwegian status before relying on the EU dates. A UK agency is covered where the output of its AI system is used in the EU (Article 2(1)(c)), which can be the case when shortlists go to clients in the EU. UK data protection law applies alongside; the ICO has key questions to ask before buying an AI recruitment tool.
What already applies: emotion recognition, AI literacy and chatbots
- Emotion recognition is banned at work. Article 5(1)(f) prohibits AI that infers the emotions of a person in the workplace or in education from biometric data such as face or voice, except for medical or safety reasons, and has done so since 2 February 2025. The Commission's guidelines say this covers candidates during recruitment. If a video interview tool claims to read enthusiasm, stress or honesty from faces or voices, ask the vendor in writing what it infers and stop using that feature until you have an answer.
- AI literacy is now a duty to support, not to guarantee. The original Article 4 required providers and deployers to ensure, to their best extent, a sufficient level of AI literacy among their staff. The AI Omnibus replaced it: they must take measures to support the development of AI literacy of staff who operate and use AI, and the duty does not require any specific level for any individual. Training still matters where it counts: from 2 December 2027, anyone overseeing a high-risk system must have the necessary competence, training and authority (Article 26(2)).
- Chatbots must say they are AI. From 2 August 2026, AI systems that interact directly with people must be designed so that people know they are talking to an AI, unless that is obvious (Article 50(1)). Check that your candidate chatbot says so.
Provider or deployer: who is responsible for what?
The provider is whoever develops the AI system and puts it on the market under its own name, usually your software vendor. Under Article 16 it must meet the high-risk requirements, among them risk management, data quality, logging for traceability, technical documentation, clear instructions for use and human oversight by design. It also needs a quality management system, a conformity assessment, an EU declaration of conformity, CE marking and registration.
The deployer is the organisation that uses the system, usually your agency. Article 26 requires a deployer of a high-risk system to:
- use it according to the provider's instructions for use;
- assign human oversight to people with the necessary competence, training, authority and support;
- make sure input data under its control is relevant and sufficiently representative;
- monitor the system, suspend it and inform the provider if it presents a risk, and report serious incidents;
- keep the logs the system generates, where they are under its control, for at least six months unless other law requires otherwise;
- as an employer, inform workers' representatives and affected workers before using the system at the workplace;
- inform people that they are subject to the system when it makes or assists decisions about them;
- use the provider's information when carrying out a data protection impact assessment under the GDPR.
On top of that, Article 86 gives a person affected by a decision based on the output of an Annex III high-risk system, where the decision has legal or similarly significant adverse effects on them, the right to a clear and meaningful explanation from the deployer of the role the AI played and the main elements of the decision. If a candidate asks why they were not put forward, you need to be able to answer.
When the agency becomes the provider. Under Article 25(1), a deployer takes on the provider's obligations if it puts its own name on a high-risk system, makes a substantial modification to one, or changes the intended purpose of an AI system, including a general-purpose one, so that it becomes high-risk. Building your own CV ranking on top of a general chatbot can turn your agency into the provider of a high-risk system.
GDPR Article 22 and automated decisions in recruitment
The GDPR applies today, whatever the AI Act dates. Article 22 gives a person the right not to be subject to a decision based solely on automated processing, including profiling, that has legal effects or similarly significant effects on them. The exceptions are narrow: a decision necessary for a contract, one authorised by law with suitable safeguards, or one based on explicit consent. Under the contract and consent exceptions, the person keeps at least the right to human intervention, to give their view and to contest the decision.
For an agency, the practical rule is simple: an AI may sort, suggest and prepare, but a person with real authority makes the decisions that shut someone out, such as rejecting an applicant or excluding a temp from work. Approving hundreds of AI rejections in one click is hard to defend as human involvement. Add a lawful basis, clear information to candidates and, for most AI screening, a data protection impact assessment.
Is this use high-risk? A table for typical agency AI uses
| AI use in the agency | Likely class | First practical step |
|---|---|---|
| CV screening, scoring or ranking applicants | High-risk Annex III 4(a): analysing and filtering applications, evaluating candidates. Scoring people is likely to count as profiling. | Ask the vendor for its classification and instructions for use. A person reviews every rejection. |
| Matching candidates to jobs or shifts, shortlisting | High-risk When it evaluates or ranks people for a role, it is selection. | Name the person who oversees it and decide what the AI may do alone and what waits for approval. |
| Targeting who sees a job ad | High-risk Placing targeted job ads is named in Annex III 4(a), for systems intended for recruitment. A general ad platform's audience tools are less clear. | Find out how the targeting works and whether it uses personal traits. |
| Sourcing: searching databases or the web for candidates | Often high-risk If it scores or ranks people, yes. A plain keyword search, unlikely. | Check whether it ranks people and what data it collects; tell sourced candidates under the GDPR. |
| Allocating shifts or assignments to temps | Depends Annex III 4(b) covers allocating tasks based on behaviour or personal traits. Rules on availability, location and valid documents are less clear. | List what the allocation uses. Inform temps and their representatives before use. |
| Monitoring or rating temps' performance | High-risk Annex III 4(b): monitoring and evaluating performance and behaviour. | Keep a person in any decision on pay, extension or termination. |
| Reading emotions in video interviews or at work | Prohibited Article 5(1)(f), since 2 February 2025. | Switch the feature off and get the vendor's answer in writing. |
| Chatbot that answers candidates' questions | Transparency Must say it is an AI (Article 50, from 2 August 2026). High-risk if it also screens people out. | Check that it says it is an AI and hands over to a person. |
| Interview scheduling and availability checks | Usually not high-risk A narrow procedural task, as long as it does not decide who gets an interview. | GDPR basics: data minimisation and clear information. |
| Reading client job requests from email or VMS | Usually not high-risk It structures job requests, it does not evaluate people. | Treat email as data, keep a record of what was created from it. |
| Drafting emails and job ad text with a chat assistant | Minimal risk No specific AI Act duties beyond AI literacy. | A short policy on what candidate data may be pasted in. |
The class follows the intended purpose the provider sets, and the same product can contain high-risk and ordinary features. Ask each vendor which features it treats as high-risk and why.
A worked example: a healthcare staffing agency
Take a typical agency placing nurses with hospitals in Norway and Sweden. It runs an ATS, a busy job request inbox and a handful of ChatGPT licences, and uses AI in four places:
- Job intake. An AI reads shift requests from client emails and creates jobs. It structures requests and does not evaluate people, so it is outside Annex III. The GDPR still applies to names in the emails.
- Shift matching. For each shift, the system ranks nurses and sends offers to the top five. It evaluates people and allocates work, so the agency treats it as high-risk. Before 2 December 2027 (for its Norwegian work, once the Act applies in Norway) it gets the vendor's classification and instructions for use, names a coordinator who oversees matching, decides that the AI may send offers but only a person may exclude a nurse, makes sure every offer can be traced to the shift and nurse with logs kept for at least six months, and informs nurses and their representatives.
- CV ranking in a chat window. A consultant pastes ten CVs into ChatGPT and asks for the best three for a client. This is the riskiest use in the building: a general tool used to evaluate candidates, no instructions for that purpose, no record tied to the candidates in the ATS, candidate data pasted into another service, and possibly the agency becoming a provider under Article 25. The fix is to stop it, or move the work into a system built for screening.
- Job ad text. ChatGPT drafts ads. Minimal risk: a short policy and some training are enough.
The outcome is one page: a register of AI uses (tool, purpose, likely class, owner, vendor documents), one named owner, and 2 December 2027 in the plan.
What the EU AI Act does not do
- It does not ban AI in hiring. Only the practices in Article 5 are prohibited. Screening, matching and ranking are allowed, with duties.
- It does not ask for candidates' consent. It asks for information, oversight and logs. The lawful basis for processing candidate data comes from the GDPR.
- It does not make a deployer certify the product. Conformity assessment and CE marking are the provider's job; yours is to use the system properly.
- It does not regulate everyday writing help. The Commission says most AI systems in use in the EU are minimal risk with no new rules.
- It does not replace other law. The GDPR, employment law and anti-discrimination law still apply in full.
- The Omnibus delayed the high-risk rules, it did not remove them.
What this means for a staffing agency
In most cases you are the deployer, and the work is less about legal theory than about evidence. By December 2027 you should be able to show which AI systems you use and for what, which vendor documentation and instructions you follow, who oversees each system and with what authority, and what the AI did on which candidate, job or shift, with logs kept for at least six months. When a candidate asks why they were not put forward, someone must be able to explain it.
General chat tools alone do not give you that. A consultant ranking CVs in ChatGPT, Claude, Gemini or Copilot leaves no record tied to the candidate in your ATS, has no instructions for use for that purpose and puts the oversight in one person's head. That is why agencies that use AI for screening and matching need a system where the AI works on the records themselves, under rules you set, with a person in the loop and a trail of what it did.
Globus.ai is one example: a full AI Agent ATS for staffing and recruitment agencies, where all AI agent activity is visible in a real-time Control Room with people in the loop, and AI shortlists come with explanations. An agency can also keep its current ATS, such as Bullhorn, Recman or Carerix, and connect the AI agents to it. Whichever vendor you consider, put the questions in the table above to it.
Updated 1 October 2026. Related: What is an AI agent? Explained for staffing and recruitment and ChatGPT vs Claude vs Gemini vs Copilot for recruitment agencies.
Frequently asked questions
Is CV screening high-risk under the EU AI Act?
In most cases, yes. Annex III point 4(a) lists AI used to analyse and filter job applications and to evaluate candidates, and a system that scores or ranks people is likely to count as profiling, which makes it high-risk regardless of the exception in Article 6(3). The high-risk rules apply from 2 December 2027.
When does the EU AI Act apply to recruitment?
The ban on emotion recognition at work has applied since 2 February 2025, and transparency rules for chatbots since 2 August 2026. After the AI Omnibus, Regulation (EU) 2026/1744, the high-risk rules for recruitment and managing workers apply from 2 December 2027.
Does the EU AI Act apply to UK recruitment agencies?
It can. The Act covers providers and deployers outside the EU where the output of the AI system is used in the EU (Article 2(1)(c)), for example shortlists for EU clients. UK data protection law applies alongside it.
Is AI in recruitment allowed under GDPR?
Yes, with care: a lawful basis, clear information to candidates, minimal data and usually a data protection impact assessment. GDPR Article 22 gives people the right not to be subject to a decision based solely on automated processing that significantly affects them, so keep a person in decisions such as rejections.
Does the EU AI Act ban AI in hiring?
No. It bans a short list of practices, such as inferring emotions at work. Screening, matching and ranking candidates are allowed, but count as high-risk, with duties for the vendor and the agency.
Want to see how AI agents handle job requests, matching and screening with a person in the loop? Book a meeting with Globus.ai.


