The EU AI Act and HR: Why Human Resources Is Among the First Functions in the Enforcement Crosshairs

A human hand interacts with a translucent AI interface displaying candidate ranking scores and star ratings, connected by glowing lines to compliance document icons, set against a dark office background — illustrating the intersection of algorithmic HR decision-making and EU AI Act documentation obligations.

Most HR teams are not thinking about the EU AI Act. They should be.

The regulation does not require a company to build AI. It does not require a dedicated AI department. It does not distinguish between a company that develops its own algorithms and one that subscribes to an off-the-shelf ATS. What it requires is that any organisation deploying AI systems classified as high-risk — in recruitment, performance management, promotion decisions or employee monitoring — meets a defined set of obligations around documentation, risk management, human oversight and fundamental rights.

And HR, more than almost any other corporate function, is already running high-risk AI at scale — largely without knowing it.


Why HR Is Directly in the Line of Fire

The EU AI Act’s Annex III lists the categories of AI systems automatically classified as high-risk. Section 4 of that annex covers employment, workers management and access to self-employment. It captures any AI system used for recruitment or selection of natural persons, screening or filtering of applications, evaluating candidates, or making decisions on promotion and termination — as well as monitoring and evaluating performance and behaviour in work-related relationships.

This is not a narrow provision. In operational terms, it covers the majority of AI-enabled tools already deployed across European HR functions: CV screening tools, candidate ranking algorithms, automated interview scoring platforms, performance evaluation models, promotion decision support systems, and employee monitoring and behavioural analytics. Each of these falls under the high-risk regime unless a specific exemption applies.

The enforcement timeline matters. Prohibited practices under Article 5 have been in force since 2 February 2025. High-risk system obligations — documentation, risk management, human oversight, FRIA — apply from December 2, 2027 under the Digital Omnibus extension. That window is not a reprieve. It is preparation time. And most organisations have not yet started.


The AI Systems Already Running in Your HR Function

For most HR teams, the compliance journey begins with a confrontation: the inventory exercise. When HR systematically maps every tool used in recruitment, performance management, workforce analytics and monitoring against the Annex III definitions, the scope is almost always wider than anticipated.

The core HR AI systems typically in scope include:

CV and application screening tools — automated parsing, filtering and shortlisting based on skills, keywords, scores or predicted fit. These systems are high-risk under Annex III regardless of whether the employer built them or subscribed to a third-party ATS.

Candidate ranking and matching algorithms — ML systems ordering candidates by predicted suitability, matching talent pools to requisitions, or recommending “top N” profiles to hiring managers. The fact that a human ultimately decides does not automatically remove the high-risk classification if the AI output materially influences that decision.

Automated interview analysis tools — asynchronous video interview platforms scoring responses, analysing speech, tone, pace and hesitation, or applying psychometric components. These sit at the intersection of the Annex III high-risk regime and, in some implementations, the Article 5 prohibited practices on emotion recognition.

Psychometric and personality AI — trait prediction systems, cultural fit scoring, cognitive testing via adaptive algorithms. Often deployed as standalone assessments or embedded in ATS platforms, these tools generate consequential outputs about candidates with limited external validation.

Employee monitoring systems — keystroke logging, activity dashboards, time-at-desk metrics, webcam monitoring, wearable-based tracking. The CNIL fine against Amazon France Logistique — €32 million for excessive automated monitoring of workers — established a clear precedent for what “disproportionate intrusion” looks like under existing law, before the AI Act even applies.

Productivity and behavioural tracking — dashboards combining system logins, app usage, email and chat metadata, ticketing and CRM data to infer productivity, collaboration or engagement. Many of these fall under the “monitoring and evaluating behaviour” limb of Annex III.

Promotion and performance prediction models — ML models predicting potential, performance trajectory or attrition risk, feeding into talent programmes and succession planning. High-risk where they materially inform decisions about promotion or termination.

Generative AI in HR — an important boundary case. GenAI used only for drafting job descriptions, interview questions or communications is generally limited-risk. The moment GenAI outputs are used to evaluate candidates or employees — scoring interview transcripts, summarising assessment responses, generating performance ratings — the system crosses into high-risk territory under Annex III.

For most organisations, completing this mapping is the mirror moment: once HR sees how many systems involve algorithmic decision-making about people, it becomes immediately obvious that the AI Act is already a live HR topic — not a future one.


The Most Dangerous Technical Combination in HR AI

Among the technical patterns present in current HR software, one stands out as particularly high-risk from a compliance and fundamental rights perspective: a supervised ranking model trained on historical hiring data, wrapped in an LLM summary layer.

The ranking model encodes bias structurally and invisibly. If historical hiring data reflects patterns of discrimination — by gender, ethnicity, age, educational institution, or any correlated proxy — the model learns and reproduces those patterns. This is not a hypothetical. It is the documented failure mode of every major AI hiring scandal of the past decade.

The LLM layer compounds the problem rather than correcting it. The LLM adds fluent, confident language to the ranking model’s outputs — narrative summaries that give the output false authority and an appearance of objectivity. The bias is in the numbers; the LLM puts it in sentences. And sentences are harder to challenge than scores.

University of Washington research published in 2025 confirms the mechanism: humans tend to mirror and accept AI hiring biases rather than correct them, particularly when AI output arrives with apparent algorithmic authority. The oversight that Article 14 requires — real, meaningful human review — fails precisely when it is most needed. MIT Sloan frames the same dynamic: “A manager’s judgment can be questioned; an algorithm’s ranking arrives with an aura of neutrality.”

Academic benchmarking of leading LLMs in hiring contexts has found race-based differences in approximately 10% of generated candidate summaries, with non-uniform selection patterns across demographic groups. This is not a corner case. It is a mainstream risk embedded in tools already in production.

The full technical architecture of HR AI systems — covering machine learning classification, NLP, computer vision, behavioural anomaly detection and predictive models, with their compliance implications mapped against the AI Act — is covered in detail in the sector report.


Model Drift: The Compliance Time Bomb Most HR Teams Have Not Connected to Their Obligations

A second critical and underappreciated risk is model drift — and its intersection with Article 9 risk management obligations.

The problem is straightforward. AI models learn from historical data. As the world changes, the patterns the model learned become progressively less accurate — and progressively more biased — as the conditions that produced the training data diverge from current reality.

Harvard Business Review research found that 30% of AI-driven hiring tools lose up to 15% accuracy within the first six months of deployment due to data drift and shifting labour market patterns. For models trained on pre-2020 hiring data, the divergence from current labour market reality is severe. For models trained on 2020–2022 data — capturing hiring freezes, mass layoffs, remote-first pivots and Great Resignation dynamics — the problem is arguably worse: those models learned from a historically anomalous period that has since partially reversed.

Drift and bias also reinforce each other in a feedback loop. Stale model predictions become new training data when the system incorporates deployment outcomes — embedding the original distortion more deeply with each cycle.

Under Article 9 of the AI Act, high-risk AI system operators are required to maintain a continuous risk management system that includes periodic monitoring and re-validation of model performance. This is not a one-time conformity assessment. It is an ongoing obligation. Almost no HR deployer currently tracks model drift or schedules re-validation cycles — meaning Article 9 compliance gaps are already accumulating in deployed systems.


The Risk Exposure Heatmap

Not all HR AI systems carry equal enforcement risk. The table below provides a practical view of risk level, prevalence in European HR functions, and projected enforcement priority for 2026–2027. This is an analytical heatmap, not a legal classification.

Use caseAI Act risk levelPrevalenceEnforcement risk 2026–2027
CV / application screeningHigh-risk (Annex III)Very highHigh
Candidate ranking / matchingHigh-risk (Annex III)HighHigh
Automated interview scoringHigh-risk (Annex III; potential biometric overlaps)Medium–highHigh
Psychometric / personality AIHigh-risk (employment + profiling)MediumMedium–high
Performance / promotion modelsHigh-risk (employment decisions)Medium–highHigh
Employee monitoring toolsHigh-risk (workers management)HighVery high
Behavioural / sentiment analyticsHigh-risk, proximity to prohibited practicesMediumVery high
GenAI drafting for HR contentLimited risk (if purely assistive)Very highMedium
GenAI-assisted evaluationHigh-risk (if used in decisions)EmergingHigh

The enforcement risk column reflects two factors: prevalence of the use case in European organisations, and the degree of regulatory and political sensitivity. Employee monitoring and behavioural analytics are both high-prevalence and politically charged — they sit at the intersection of AI Act obligations, GDPR enforcement, and labour rights frameworks. They are strong candidates for early enforcement actions.


Article 5 Prohibited Practices: Already In Force

Before any discussion of high-risk obligations and their 2027 timeline, a more urgent compliance question applies to any organisation using AI in HR: are any current deployments touching the Article 5 prohibited practices that have been in force since 2 February 2025?

Four prohibited practices are particularly relevant to HR:

Emotion recognition in the workplace. Any AI system inferring emotions from workers for decision-making purposes is at or directly under Article 5. This includes sentiment analytics applied to customer service calls where agent emotional states are scored, video interview platforms with emotional scoring components, and engagement tools that infer mood from communication patterns.

Biometric categorisation for sensitive inferences. Systems inferring race, political opinion, religious beliefs or sexual orientation from biometric data are prohibited. Facial action coding in video interviews — where facial muscle movements are mapped to personality traits or emotional states — directly intersects this prohibition.

Social scoring in employment contexts. AI scoring workers based on social behaviour or personal characteristics in a way that leads to detrimental treatment unrelated to the context of the original data generation is prohibited. This provision catches some behavioural analytics platforms that produce aggregate “risk scores” or “compliance scores” for workers.

Subliminal manipulation. AI exploiting psychological vulnerabilities to influence behaviour in harmful ways — relevant to some persuasion-based employee engagement tools.

There is no transition period for these prohibitions. Any system in use today that falls under Article 5 is already in violation.


Compliance Requirements for HR Deployers

For most organisations, the relevant AI Act role in the HR context is deployer — the employer or staffing firm that decides to use an AI system, regardless of whether it built it or subscribed to it from a SaaS vendor. This distinction is critical: deploying a tool does not transfer compliance obligations to the vendor.

The key obligations for deployers of high-risk HR AI systems include:

AI system inventory and documentation (Articles 11 and 26). Maintain a register of all AI systems used in recruitment and workers management, including purpose, provider, version, data inputs and outputs. Ensure that technical documentation supplied by providers is available, current and sufficient to understand how the system works, its limitations and its risks.

Risk management (Article 9). Establish a risk management system covering identification, analysis, evaluation and mitigation of risks to health, safety and fundamental rights. Carry out risk assessments at selection, deployment and periodically during use — particularly after model updates or changes in use context. This is where the model drift obligation lives.

Data and data governance (Article 10). Ensure training, validation and testing data is relevant, representative and free of errors where possible, with bias controls appropriate for the HR context. Verify that protected characteristics are handled in a way that avoids discriminatory outcomes consistent with EU equality law.

Human oversight (Article 14). Define concrete oversight roles — who reviews AI outputs, in which scenarios, with what powers to override or contest. Ensure reviewers understand the system’s capabilities and limits. Avoid rubber-stamping: oversight must be substantive, not merely formal.

Fundamental Rights Impact Assessment (Article 27). Conduct FRIAs prior to deploying high-risk HR AI systems, identifying affected rights, affected groups, potential harms and mitigation measures. Document consultation with works councils, staff representatives or unions where required by national labour law.


The Vendor Layer

Most HR AI is consumed as SaaS. The AI Act does not change the fundamental commercial relationship — but it changes its compliance implications significantly.

Three structural realities define the vendor risk layer in HR: providers are unevenly prepared for AI Act obligations; documentation gaps are pervasive, with most vendors unable to provide meaningful technical documentation on request; and liability stays with the deployer regardless of what the vendor contract says.

The practical signal for HR leaders is simple: request Article 11 technical documentation from your key HR SaaS vendors now. The response — or absence of one — will immediately reveal your supply chain risk exposure.

The sector report covers the vendor landscape in detail, including procurement strategy, contractual safeguards, and how to structure documentation requests that will actually produce usable responses.


Three Dominant Risks for Organisations

Across the full landscape of HR AI compliance, three risks are most widespread and most operationally urgent:

Unmapped high-risk exposure. CV screening, ranking, interview scoring, performance evaluation and monitoring are already in use but have not been classified as high-risk AI systems — or in many cases even recognised internally as AI. The inventory gap is the most common and most consequential problem.

Vendor dependency with weak documentation. HR relies heavily on SaaS tools whose providers have not yet completed AI Act readiness programmes. Deployers lack the technical documentation, model cards and data governance evidence needed to discharge their own obligations under Articles 9–11 and 14.

Fundamental rights and labour-law collisions. Discrimination, opaque profiling, intrusive monitoring and emotion analytics create direct conflicts with EU fundamental rights, national labour law and collective bargaining commitments. In Germany, France and the Netherlands, this adds co-determination law to AI Act obligations — meaning works councils have information and consultation rights before HR AI systems are deployed or significantly changed.


Enforcement Reality: Why HR Will Attract Early Cases

Even before full AI Act enforcement, the enforcement signals from existing supervisory action are clear.

The CNIL fine against Amazon France Logistique — €32 million in December 2023 for excessive automated monitoring of workers — established the template. Under the AI Act, the same conduct would also trigger Article 9 risk management failures, Article 14 human oversight gaps, and Article 27 FRIA obligations.

EU fundamental rights bodies and the European Parliament have explicitly called on regulators to prioritise recruitment and HR in AI enforcement. The political salience of worker rights, algorithmic discrimination and workplace surveillance is high and sustained. First AI Act cases targeting HR will be high-visibility, landmark actions with sector-wide impact.

The enforcement phases for HR AI are likely to follow this pattern: an orientation phase through 2026 focused on DPA guidance and prohibited practice investigations; complaint-driven enforcement in 2027 targeting biometric violations, egregious HR-AI cases and GPAI transparency failures; and systematic proactive market inspections from 2028 onwards.


Three Common Misconceptions

“We don’t build AI, so it’s not our problem.” Even where all HR tools are third-party subscriptions, the employer is a deployer with direct obligations under Article 26 for high-risk systems under Annex III. Building nothing does not reduce obligations.

“The vendor is responsible for everything.” Providers have their own obligations, but deployers must ensure appropriate use, conduct FRIAs where required, inform workers and ensure human oversight. Contracting out does not eliminate legal exposure.

“Only large companies are affected.” The AI Act applies based on use of systems, not company size. SME simplifications exist but do not remove core obligations around high-risk HR systems or prohibited practices. A 30-person company using an AI-powered ATS to screen candidates is deploying a high-risk AI system under Annex III.


Where to Start: The First 30 Days

A 90-day sprint gives any HR function a realistic path from blind spots to a credible AI Act baseline. The starting point — and the most important single step — is the inventory.

In the first 30 days: run workshops with HR, IT and procurement to identify all tools involved in recruitment, performance management, monitoring and workforce analytics. Build a simple inventory — system name, provider, purpose, data used, decision impact, user groups. Flag obvious high-risk candidates and any potential prohibited-practice overlaps under Article 5.

This exercise alone will surface the scope of exposure. Everything else — classification, vendor engagement, FRIA, oversight design, training — follows from having a complete picture of what is actually running.

The full 90-day framework, including classification methodology, standardised vendor documentation request templates, FRIA methodology and oversight design, is covered in the sector report.


Signals to Watch: 2026–2027

Two signals in particular will shape the HR compliance landscape over the next 18 months.

The first AI Act enforcement action in HR will function as a sector-wide benchmark. How regulators frame it — documentation failure versus accountability failure — will determine which lesson the sector draws. A documentation-focused verdict generates better paperwork. An accountability-focused verdict puts board agendas in a different place entirely.

SaaS vendor compliance moves will reset buyer expectations faster than regulatory guidance. The moment major HR platforms begin publishing model cards and supporting customer FRIAs as standard practice, organisations without equivalent documentation from their own vendors will face procurement and reputational pressure.


Conclusion

HR is not waiting for the AI Act. The AI Act is already here for HR. Prohibited practices have been in force since February 2025. High-risk obligations are approaching. And most organisations have not yet completed the first step — the inventory — that makes everything else possible.

The compliance challenge in HR is not primarily technical. It is organisational: closing the gap between the AI tools already running in recruitment, performance management and monitoring, and the documentation, oversight and risk management frameworks those tools legally require. That gap is wide, the enforcement signals are clear, and the window for structured preparation is closing.


This analysis is drawn from the AI Act in HR & Recruitment sector report — a comprehensive intelligence brief covering technical architecture, risk classification, compliance requirements for all operator profiles, vendor risk, compliance cost bands, and the full 90-day implementation framework. The report is part of a growing library of EU AI Act sector and country intelligence available at ovidiusuciu.com. Country-specific reports covering Germany, France and Romania are available for free download. This is not legal advice.