Short answer: Under the EU AI Act, recruitment AI, such as tools that filter or evaluate candidates, is high-risk. The main high-risk duties apply from 2 December 2027. Some rules already apply: the ban on inferring emotions at work from biometric data such as a face or voice, AI literacy, and telling people they are dealing with AI. The GDPR applies today.
If your hiring process uses AI to screen applications, run interviews or evaluate candidates, the EU AI Act applies to you. The deadlines moved this summer. The direction did not.
Key dates
| Date | What applies | What it means for recruitment |
|---|---|---|
| 2 February 2025 | The ban on inferring emotions at work from biometric data such as face or voice (Article 5(1)(f)); AI literacy (Article 4) | No emotion recognition in interviews. Take measures to build AI literacy among the staff who use your hiring tools. |
| 27 July 2026 | The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force | The high-risk duties for recruitment AI moved from 2 August 2026 to 2 December 2027. |
| 2 August 2026 | The duty to tell people they are interacting with an AI system (Article 50) | Providers must design automated interviewers so candidates are told, unless it is obvious. Check that yours does. |
| 2 December 2027 | The main duties for high-risk systems listed in Annex III, including recruitment | Deployer duties apply: oversight, monitoring, logs and informing candidates. |

Key takeaways for frontline hiring
- Oversight has to work at your real volume, not on paper.
- Candidate information has to work in the languages your candidates use.
On this page: Is recruitment AI high-risk? · Provider or deployer · What changed with the Digital Omnibus · Why the delay is not a reprieve · Rules that already apply · Duties from 2 December 2027 · Enforcement and fines · The GDPR today · Frontline and high-volume hiring · Dutch law · Preparation checklist · FAQ
Is AI used in recruitment high-risk?
Yes. AI used to recruit or select people is high-risk under Annex III of the EU AI Act. After the Digital Omnibus on AI (Regulation (EU) 2026/1744), the main high-risk duties apply from 2 December 2027. Some rules already apply: the ban on inferring emotions at work from biometric data such as face or voice (since 2 February 2025), AI literacy duties (since 2 February 2025), and the duty to tell people when they are interacting with an AI system (since 2 August 2026).
Annex III, point 4(a) of the AI Act, Regulation (EU) 2024/1689, names in particular systems that:
- place targeted job advertisements
- analyse and filter job applications
- evaluate candidates
Under Article 6(3), an Annex III system can fall outside the high-risk category only in narrow cases, and never when it profiles people. A system that evaluates candidates' answers against job requirements should be assumed to be high-risk. That includes Radius Hire's own interviewer.
Under Annex III we treat Radius Hire as a high-risk AI system and design it for human oversight ahead of 2 December 2027. Our guide to AI in hiring sets out what technology should evaluate and what people must decide.
Provider or deployer: which one are you?
The AI Act gives different duties to different roles.
- Provider: the company that builds the AI system and places it on the market. This is usually your software vendor.
- Deployer: the organisation that uses the system under its own authority. An employer that uses a recruitment AI system bought from a vendor is a deployer.
Most employers are deployers. Your duties are different from your vendor's, but they are real.
Two situations can make you a provider, with the provider's duties (Article 25). The first is putting your own name or trademark on a high-risk system, or substantially modifying it. The second is putting a general-purpose AI system, such as a chatbot, to a high-risk use, for example asking it to filter CVs or evaluate candidates. Take legal advice before doing either.
What changed with the Digital Omnibus on AI?
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was signed on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It moved:
- the high-risk requirements for Annex III systems, which include employment, from 2 August 2026 to 2 December 2027
- the requirements for AI built into products covered by Annex I to 2 August 2028
The Digital Omnibus on AI amends the AI Act. It does not amend the GDPR. A separate Commission proposal from November 2025, also called the Digital Omnibus, would change parts of the GDPR, including the rules on automated decisions. As of August 2026 it was still at an early stage: neither the Parliament nor the Council had adopted a position. Until it is adopted, the GDPR rules described below apply unchanged.
Why the delay is not a reprieve
Our view. It is tempting to read the Digital Omnibus as "we have more time". We think that is the wrong lesson.
A later date changes the timing, not the direction. A tool you adopt now will be judged under the GDPR and equal treatment law today. Whether the AI Act's high-risk duties also reach a system already in use before December 2027 depends on how much it changes after that date. Ask counsel. Either way, the records you need are the same.
Those records cover:
- the criteria used
- the human oversight arrangement
- the monitoring carried out
They overlap substantially with the records that make a hiring process defensible under equal treatment law today. That is an argument for documenting your process now, whatever tools you choose.
Which AI Act rules already apply to recruitment?
Three rules and one permission already apply: the ban on emotion recognition at work, the duty to tell people they are dealing with AI, AI literacy, and a permission to use sensitive data to detect bias.
1. The ban on emotion recognition at work
Since 2 February 2025, Article 5(1)(f) has banned AI systems that infer the emotions of people in the workplace. The ban covers inferring emotions from biometric data such as a face or voice, with exceptions for medical or safety reasons. The European Commission's guidelines, which are not binding, say it also covers job candidates (C(2025) 5052 final).
2. Must candidates be told they are dealing with AI?
Yes. Since 2 August 2026, Article 50(1) requires providers to design AI systems intended to interact directly with people so that those people are told they are interacting with an AI system, unless this is obvious from the circumstances. The Commission approved draft guidelines on these transparency duties on 20 July 2026 (C(2026) 5054 final). This is a duty on the provider: as an employer, check that your provider meets it before candidates meet the system. From 2 December 2027, employers using high-risk recruitment AI must also inform candidates themselves (Article 26(11)), and GDPR information duties apply today.
3. AI literacy
Article 4 has applied since 2 February 2025. The Digital Omnibus replaced its text. Providers and deployers must take measures to support the development of AI literacy among staff and others who operate or use AI systems on their behalf, taking account of their knowledge, the context of use and the people affected. The amended text adds that this does not require them to ensure any specific level of literacy for any individual.
4. A permission to detect bias
A new Article 4a allows providers and deployers to process special categories of personal data where strictly necessary to detect and correct bias, under strict conditions. It is a permission, not a duty, and it does not endorse any method.
What must employers do from 2 December 2027?
From 2 December 2027, employers that deploy a high-risk recruitment system will have duties under Article 26. These include:
- Using the system as instructed. Use it in line with the provider's instructions for use, and make sure the input data you control, such as the job requirements, is relevant (Article 26(1) and (4)).
- Human oversight. Article 14 requires providers to build high-risk systems so the people overseeing them can understand their limits, stay alert to over-reliance and override the output. Article 26(2) requires employers to give that oversight to people with the competence, training and authority to use it.
- Monitoring the operation of the system (Article 26(5)).
- Keeping the logs that are under their control, for at least six months (Article 26(6)).
- Informing workers' representatives, and any staff affected, before the system is used at the workplace (Article 26(7)).
- Informing candidates that a high-risk AI system is used in decisions about them (Article 26(11)).
Candidates may also have a right to an explanation of a decision based on the output of a high-risk system (Article 86). Ask counsel whether and when this applies to your process.
The fundamental rights impact assessment in Article 27 applies mainly to public bodies and to private entities providing public services. It will therefore not apply to most private employers.
Who enforces the AI Act, and what are the fines?
Under Article 99 of the AI Act, Regulation (EU) 2024/1689, fines can reach €35 million or 7% of worldwide annual turnover for prohibited practices, such as emotion recognition at work, and €15 million or 3% for breaches of other duties, including those of deployers. In the Netherlands, supervision is organised around the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur (RDI).
How does the GDPR apply to AI recruitment today?
The AI Act dates do not change your GDPR duties. These apply now, whatever screening method you use.
- Automated decisions (Article 22). Under Article 22 of the GDPR, a decision about a candidate that has significant effects may not be based solely on automated processing, unless a narrow exception applies, such as necessity for entering into a contract. The Autoriteit Persoonsgegevens says employers must be able to show that necessity.
- Information duties (Articles 12, 13 and 14). Candidates must be told how their data is used, in concise, clear and plain language.
- Data protection impact assessment (Article 35). AI screening of applicants will very likely require one. Confirm with counsel and start it before you go live.
- Retention (Article 5(1)(e)). The GDPR sets no fixed retention period: data must not be kept longer than necessary for its purpose. The Autoriteit Persoonsgegevens says it is customary to delete an unsuccessful applicant's data within four weeks of the procedure ending, or up to one year with their consent. Document your own period for applications, interview recordings and verification results, and ask counsel how it fits the AI Act's duty to keep system logs for at least six months from December 2027.
What this means for frontline and high-volume hiring
Most guidance on the AI Act is written for large corporate recruitment teams. Frontline hiring has its own pressure points.
Volume screening is where the high-risk classification bites. The tools frontline employers adopt to cope with volume, such as application filters, automated first interviews and answer evaluation, are exactly the uses Annex III names. If a tool is doing the work of a first screen at scale, assume it is high-risk and plan for the deployer duties.
Voice and video interviews need a specific check. Asynchronous voice and video interviews are increasingly used for shift-based roles. The ban on inferring emotions from a face or voice already applies, and the Commission's guidelines say it covers candidates. Ask every provider directly whether the system infers emotions or assesses tone, accent or appearance.
Candidate information has to work for your candidates. Frontline applicants often apply on a phone, and many are not native Dutch speakers. The GDPR already requires information in concise, clear and plain language, and EU data protection guidance says it should be translated where you target people who speak other languages (WP260rev.01). Telling candidates that they are speaking with an automated interviewer, what is recorded and who decides only works if they can understand it.
Oversight has to be designed for volume. Human oversight by competent people is easy to promise and hard to deliver at 200 applications a week. If one recruiter "oversees" hundreds of automated outputs without time to look at the evidence, the oversight exists on paper only. Plan the reviewer hours as part of the process: our guide on how to run structured interviews at high volume shows the arithmetic, and human oversight in hiring sets out what real oversight looks like.
Staffing agencies should clarify their role. An agency that uses a recruitment AI system under its own authority to screen candidates is likely to be a deployer for that use. An agency that offers a screening system to clients under its own name, or substantially modifies it, may take on provider duties (Article 25). Where the agency and its client both use the outputs, for example when a client selects from an AI-assisted shortlist, the roles and duties of each party should be assessed with counsel and set out in the contract.
Dutch law: where things stand
No Dutch law currently requires employers to use a documented recruitment and selection procedure. Equal treatment law, including the Algemene wet gelijke behandeling, already prohibits discrimination in recruitment.
The bill that would have introduced such a duty, the Wet toezicht gelijke kansen bij werving en selectie (35673), passed the Tweede Kamer on 14 March 2023. The Eerste Kamer rejected it on 26 March 2024, by 38 votes to 37.
A new bill by MPs Ergin and Van Baarle (36908), submitted on 3 March 2026, would require employers and intermediaries with 25 or more employees to use a working method that makes recruitment and selection objective, and those with 50 or more to put it in writing. The Raad van State advised on 4 May 2026 not to proceed with the bill unless it is amended. The initiators consulted on a revised version from 4 June to 3 July 2026. At the time of writing, no parliamentary debate or vote had been scheduled.
Your works council may also have a say. Introducing an AI screening tool can change your hiring policy, and Article 27(1)(d) of the Wet op de ondernemingsraden covers hiring policy. Ask counsel whether your works council has a right of consent.
A preparation checklist for employers
- List every tool in your hiring process that uses AI, and what it does with candidate data.
- Ask each provider whether it infers emotions or assesses accent, appearance or background. Our guide to choosing AI recruitment software sets out the full ten questions to ask any provider.
- Review candidate information texts: do candidates know when they deal with AI, what is recorded and who decides, in language they understand?
- Confirm that no candidate is rejected or moved forward without a person reviewing their case.
- Name the people responsible for oversight, make sure they understand the tools they oversee, and give them time to do it at your real volume.
- Write down the criteria used for each role, and keep a record of who decided and on what evidence.
- Set and document retention periods for applications, recordings and verification results.
- Start a data protection impact assessment before go-live, and confirm its scope with counsel.
- Ask counsel whether your works council has a right of consent.
- Check data processing agreements and subprocessors with every provider.
- If you are a staffing agency, agree roles and responsibilities for AI-assisted screening with each client, and check whether offering a tool under your own name makes you a provider.
- Plan how you will monitor outcomes, including lawful checks for differences between groups.
FAQ
Is AI screening of candidates legal in the EU?
It is not banned, but it is regulated. Recruitment AI is high-risk under the AI Act, inferring emotions at work from biometric data such as a face or voice is already banned, and the GDPR, including its limits on solely automated decisions in Article 22, applies today.
When do the AI Act high-risk rules apply to recruitment?
From 2 December 2027. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the date from 2 August 2026. Some rules, such as the ban on inferring emotions at work, already apply.
Is emotion recognition in job interviews allowed?
No. Since 2 February 2025, the AI Act has banned inferring emotions at work from biometric data such as a face or voice, except for medical or safety reasons. The European Commission's guidelines, which are not binding, say this covers job candidates.
Is a staffing agency a provider or a deployer?
An agency that uses a recruitment AI system under its own authority is likely to be a deployer for that use. An agency that offers a screening system to clients under its own name, or substantially modifies it, may take on provider duties (Article 25). Where the agency and its client share the outputs, assess the roles with counsel.
Is using ChatGPT to screen CVs high-risk?
It can be. If you use a general-purpose AI system to filter or evaluate candidates, you may become the provider of a high-risk system, with the provider's duties (Article 25). Take legal advice before doing it.
How long can we keep interview recordings?
The GDPR sets no fixed period. The Autoriteit Persoonsgegevens says it is customary to delete an unsuccessful applicant's data within four weeks of the procedure ending, or up to one year with their consent. Document your own period, and ask counsel how it fits the AI Act's six-month log duty from December 2027.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744: Articles 4, 4a, 5, 6, 14, 25, 26, 27, 50, 86 and 99; Annex III, point 4(a). EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI). Signed 8 July 2026; Official Journal 24 July 2026; in force 27 July 2026. EUR-Lex
- European Commission. AI Act, Shaping Europe's digital future (timeline). European Commission
- European Commission (2025). Guidelines on prohibited artificial intelligence practices, C(2025) 5052 final, 29 July 2025 (first published 4 February 2025), para. 254. Not binding. European Commission
- European Commission (2026). Draft guidelines on the transparency obligations in Article 50 of the AI Act, C(2026) 5054 final, 20 July 2026. European Commission
- Regulation (EU) 2016/679 (GDPR): Articles 5, 12, 13, 14, 22 and 35. EUR-Lex
- Article 29 Working Party. Guidelines on transparency under Regulation 2016/679, WP260rev.01, para. 13. European Commission
- Autoriteit Persoonsgegevens. Personal data of applicants. Autoriteit Persoonsgegevens
- Algemene wet gelijke behandeling. wetten.overheid.nl
- Wet op de ondernemingsraden, Article 27. wetten.overheid.nl
- Eerste Kamer. Wet toezicht gelijke kansen bij werving en selectie (35673). Eerste Kamer
- Tweede Kamer. Initiatiefwetsvoorstel Ergin en Van Baarle (36908). Tweede Kamer
- Raad van State (4 May 2026). Advies over initiatiefvoorstel Wet toezicht gelijke kansen bij werving en selectie. Raad van State
- Internetconsultatie. Wet gelijke kansen bij werving en selectie (4 June to 3 July 2026). Internetconsultatie
- Radius Hire (2026). The Radius Papers 01: A New Standard for Frontline Hiring. Sections 4.6, 4.7, 6.3 and 8.
