EU AI Act and Recruitment: The Annex III(4) Guide to High-Risk HR AI Systems
Why HR software is squarely in scope
Annex III, point 4 of the EU AI Act classifies AI systems used in employment, workers management and access to self-employment as high-risk. That single paragraph covers most of the AI your People and Talent Acquisition teams have already bought: applicant tracking systems with resume ranking, chatbot screeners, video-interview scoring tools, promotion and performance-scoring dashboards, and workforce monitoring software.
Specifically, Annex III(4) catches AI systems intended to be used for:
- Recruitment or selection - placing targeted job advertisements, analysing and filtering applications, and evaluating candidates
- Decisions affecting the terms of a work-related relationship, promotion or termination
- Allocating tasks based on individual behaviour, personal traits or characteristics
- Monitoring and evaluating the performance and behaviour of people in work-related relationships
The trigger isn't "does a human make the final call." It's whether the AI system materially influences the decision. A tool that ranks 400 CVs down to a shortlist of 10 materially influences who gets an interview, even if a recruiter clicks the final "reject" button - which is why most CV-screening and candidate-ranking software falls inside Annex III(4) rather than outside it. Pitch's overview of AI in HR and recruitment under the Act and DeepInspect's Annex III point 4 breakdown both walk through this "materially influences" framing in more detail.
What changes once a system is classified high-risk
Once an HR tool is high-risk under Annex III, the obligations are the same full stack that applies to any other high-risk AI system: a risk management system across the tool's lifecycle, data governance over training and evaluation data, technical documentation and record-keeping, transparency toward the people the tool evaluates, meaningful human oversight (not rubber-stamping), and demonstrated accuracy, robustness and cybersecurity. Providers of these systems - often the HR-tech vendor, not the employer - carry the heaviest burden, but deployers (the employer using the tool) inherit real duties too: instructions for use, human oversight in practice, and informing works councils and affected employees that an AI system is being used to evaluate them.
The timeline actually moved - here's what didn't
The Digital Omnibus on AI entered into force on 27 July 2026 and pushed the application date for Annex III high-risk obligations - including everything in point 4 - from 2 August 2026 to 2 December 2027. If you were racing toward an August deadline for your HR AI programme, you now have roughly 16 months more runway.
Two things did not move. Article 4 AI literacy obligations for staff operating or overseeing AI systems have applied since February 2025 regardless of the Annex III timeline, and GDPR obligations around employee monitoring and automated decision-making (Article 22 GDPR in particular) apply independently of the AI Act's own schedule. An employee-monitoring tool that is compliant on AI Act grounds can still be a GDPR problem, and vice versa.
The Commission has also circulated draft guidelines specifically on high-risk classification for employment AI, refining where the "materially influences" line sits for borderline tools like scheduling software or basic keyword-matching search - worth watching if your stack sits close to that boundary. McCann FitzGerald's employment spotlight and DLA Piper's GENIE coverage both cover the draft guidelines as they stand today.
What to do now, despite the extended deadline
The extra runway is real, but it is not a reason to shelve the programme. Three moves are worth making immediately:
- Inventory every HR tool that touches sourcing, screening, scoring, promotion, task allocation or monitoring, and tag which ones plausibly fall under Annex III(4)'s "materially influences" test.
- Push vendor conversations now. Ask HR-tech vendors directly whether they consider their tool high-risk, what technical documentation they can provide, and what their conformity assessment plan looks like ahead of December 2027.
- Keep AI literacy and GDPR workstreams moving on their own clocks - they don't get the Digital Omnibus extension, and enforcement on both fronts is already active.
Treat the December 2027 deadline as a target for having a working risk management system and documentation trail in place, not as license to wait until late 2027 to start.
Related reading

Does the EU AI Act Apply to My US Company? A Plain-English Guide to Article 2 Extraterritorial Scope
No EU office, no EU servers, no EU sales team - and still in scope. Article 2(1)(c) catches any third-country provider or deployer whose AI output is used in the Union. Here is exactly how each limb of Article 2 works, which exclusions are real, and what enforcement looks like since 2 August 2026.

EU AI Act and Medical Devices: How the MDR/IVDR Interplay Actually Works After the Digital Omnibus
AI-enabled medical devices now have until 2 August 2028 - but the notified body infrastructure still is not there. A plain-English guide to Article 6(1), the Article 43(3) integrated conformity assessment, and what MDCG 2025-6 says (and no longer says correctly).

Agentic AI and the EU AI Act: What the Rules Actually Say About Autonomous AI Agents
"AI agent" appears nowhere in the EU AI Act as a defined term - but the Act already binds them. Here is what the July 2026 Article 50 Guidelines, the draft high-risk Guidelines and the Digital Omnibus mean for anyone shipping autonomous agents into the EU.