EU AI Act · GDPR
Written for recruiters and hiring managers: which laws govern AI in European hiring, what is legal today, what changes in December 2027 — and, because we build resume screening software ourselves, an honest audit of exactly where our own product complies and where it doesn't yet.
Last reviewed August 8, 2026. Every claim links to the official text below. A summary, not legal advice.
Yes — AI in recruitment is legal in every EU and EEA country. No European law bans AI resume screening, CV filtering, or candidate ranking. What EU law does is regulate it: the AI Act classifies hiring AI as high-risk and attaches obligations that phase in through December 2, 2027, GDPR already restricts fully automated rejections today, and discrimination law applies to an algorithm exactly as it applies to a person. A short list of practices is banned outright — emotion recognition in the workplace above all.
We publish this guide because we sit on the regulated side of it: we build resume screening software, so we read this law the way an airline reads aviation law — because we have to. Further down you'll find the part most vendor pages omit: an item-by-item audit of our own compliance, including what isn't done.
The EU AI Act (Regulation (EU) 2024/1689) classifies AI systems used "for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates" as high-risk (Annex III, point 4(a)). That is a literal description of resume screening software, including ours.
High-risk status brings a long list of provider obligations: a risk management system (Art. 9), data and bias governance (Art. 10), technical documentation (Art. 11), automatic logging (Art. 12), transparency and instructions for use (Art. 13), human oversight by design (Art. 14), accuracy and robustness (Art. 15), a quality management system (Art. 17), a conformity assessment with CE marking (Arts. 43–48), and registration in the public EU database (Art. 49). These were due on August 2, 2026, but the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) moved the deadline to December 2, 2027. Deferred — not diluted.
GDPR applies right now, with no grace period. Article 22 restricts decisions based solely on automated processing, and the Court of Justice's SCHUFAjudgment (C-634/21) established that an automated score is itself such a decision when the human relying on it doesn't genuinely deviate from it. Employers screening EU candidates also generally owe a data protection impact assessment (Art. 35). That is why our answer to the EU today is a pause, not a disclaimer.
The legal map
The AI Act gets the headlines, but a recruiter using AI in the EU answers to all of these at once.
Regulation (EU) 2024/1689. Classifies recruitment and selection AI as high-risk (Annex III 4(a)) and phases in duties from February 2025 to December 2027. Also covers workplace AI beyond hiring: promotion, termination, task allocation, and monitoring systems are high-risk too (Annex III 4(b)).
Regulation (EU) 2016/679. Applies in full today. Article 22 restricts solely automated decisions, Articles 13–15 give candidates transparency and access rights, and Article 35 requires a DPIA for systematic candidate evaluation.
Directives 2000/78/EC, 2000/43/EC, and 2006/54/EC. EU discrimination law is technology-neutral: an algorithm that disadvantages candidates by age, ethnicity, sex, disability, religion, or sexual orientation creates the same liability as a biased human — and the employer carries it.
Directive (EU) 2024/2831, to be transposed by December 2, 2026. Gives platform workers rights against opaque algorithmic management — human review of significant decisions, transparency about automated monitoring. The clearest signal of where EU law on algorithmic management at work is heading.
Member states add their own layer: in Germany, works councils have co-determination rights when AI is introduced at work; France’s CNIL has issued recruitment-specific guidance; several labour codes require consultation before automated monitoring. Check the countries you hire in.
The timeline
Many sites still cite August 2, 2026 as the deadline for hiring AI. That date moved.
The EU AI Act (Regulation (EU) 2024/1689) enters into force.
Prohibited practices banned — including emotion recognition in the workplace (Art. 5(1)(f)) — plus the AI literacy duty (Art. 4).
Obligations for general-purpose AI models apply (Arts. 51–56).
The Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force, postponing the high-risk deadline for Annex III systems.
Art. 50 transparency duties apply — chatbot disclosure and AI-generated content labelling. The high-risk deadline originally set for this date no longer applies.
High-risk obligations for hiring AI (Annex III, incl. resume screening) apply — the operative deadline for this product.
High-risk rules for AI embedded in Annex I regulated products apply.
For employers
The AI Act splits duties between the provider (the software vendor) and the deployer (you, the employer). Some duties bind you today; the rest arrive on December 2, 2027 — and we're designing the product so each one is easy to meet.
Don’t let a rejection rest on the score alone. After the SCHUFA judgment, an automated score is itself a “decision” when the human relying on it doesn’t genuinely deviate from it — so keep a person reviewing, and empowered to disagree.
Run a data protection impact assessment before deploying AI screening. Systematic evaluation of candidates using new technology is a textbook DPIA trigger.
Tell candidates in your privacy notice that automated processing is part of screening, what logic is involved, and what it means for them.
Since February 2, 2025: ensure the staff operating AI tools have sufficient AI literacy — recruiters using a screening tool need to understand what it can and cannot do.
Since February 2, 2025: never use prohibited practices — emotion recognition in interviews or assessments is banned, even when a vendor offers it.
Use the system according to the provider’s instructions, and assign human oversight to people with the training and authority to overrule it.
Make sure the input data — your job descriptions and the resumes you upload — is relevant and sufficiently representative for the role.
Keep the logs the system generates for at least six months.
Inform workers and their representatives before using high-risk AI at work; candidates can request an explanation of the AI’s role in a decision.
A fundamental rights impact assessment is only required of public bodies and entities providing public services — not of a typical private employer. (A widely repeated myth attributes this duty to all deployers; it’s Art. 27, and it’s narrow.)
The stakes
Fines under the AI Act scale with the violation; GDPR fines stack on top. Figures are the maximum of the fixed sum or the share of worldwide annual turnover.
AI Act Art. 99(3) — using a prohibited practice, such as emotion recognition in the workplace. The higher of the fixed sum or the percentage of worldwide annual turnover applies.
AI Act Art. 99(4) — breaching the high-risk obligations. This is the tier that covers resume screening providers and the employers deploying them.
AI Act Art. 99(5) — supplying incorrect, incomplete, or misleading information to notified bodies or authorities.
GDPR Art. 83(5) — violations of data subjects’ rights, including Article 22. GDPR fines are separate from, and cumulative with, AI Act fines.
Primary sources
Everything above traces back to the official texts — worth bookmarking before trusting any summary, ours included.
The EU AI Act — full official text on EUR-Lex.
The Digital Omnibus on AI — the regulation that moved the high-risk deadline to December 2, 2027.
The GDPR — Articles 13–15, 22, and 35 are the ones that matter for screening.
The SCHUFA judgment — automated scoring as a “decision” under Article 22 GDPR.
The Employment Equality Directive — the anti-discrimination baseline for hiring.
The Platform Work Directive — algorithmic management rules for platform work.
Our compliance status
The audit we'd want from any vendor: what this product already does, what's only partially in place, and what isn't built yet — the reason screening is paused in the EU rather than merely footnoted.
Never in the product
Techniques the AI Act prohibits outright or restricts heavily — and that this product was never built on.
AI Act Art. 5(1)(f) — prohibited
Inferring emotions in the workplace has been a prohibited AI practice since February 2, 2025. We analyse resume text only — never video, voice, photos, or biometrics.
AI Act Arts. 5(1)(c), 5(1)(g) — prohibited
Candidates are scored against your job description, not against behaviour, social signals, or inferred sensitive traits.
AI Act Art. 50 · GDPR Art. 22
The product never emails, messages, or chats with a candidate — so nobody ever interacts with an AI believing it to be your recruiter.
In place today
Capabilities that already match what the AI Act and GDPR expect of a hiring tool.
AI Act Art. 14 · GDPR Art. 22
The product only scores and ranks resumes against your job description. It never rejects, advances, or contacts a candidate — every decision is made by a person reviewing the ranked list.
AI Act Art. 13
Each ranked resume carries a plain-language explanation of why it scored the way it did, so reviewers can interpret — and disagree with — the output rather than rubber-stamp a number.
AI Act Art. 15
Every resume in a batch is evaluated against the same job description and the same scoring rubric, removing the ordering and fatigue effects of manual screening.
AI Act Annex III 4(a)
Screening is switched off for EU and EEA visitors while we work through the high-risk obligations, rather than running in the EU before we can meet them. Reopening is announced only to people who explicitly opt in.
Partially in place
The foundation exists, but it doesn't yet meet the full standard the law sets.
AI Act Art. 12
Every score and its rationale is stored with timestamps. A full audit trail — score history across re-ranks, and the model version behind each result — is still being built.
GDPR Arts. 5, 17
Account deletion is self-serve in Settings, and data export or deletion requests are handled via support. Automatic retention limits and complete, verified erasure of all resume data are in progress.
GDPR Art. 5(1)(c)
Contact details are stripped from resume text before similarity embeddings are computed. Redacting personal details from everything the ranking model sees is not yet done — see blind screening below.
AI Act Art. 13
Explanations ship inside the product, but the formal instructions for use — documented capabilities, limitations, and accuracy levels — are not yet published.
Not yet
Requirements we have not met — being built before we reopen in the EU.
AI Act Art. 10
We do not yet run adverse-impact or demographic-fairness testing on ranking output. This is the single biggest item on our roadmap.
AI Act Art. 10 · GDPR Art. 5
Names, graduation years, and other identity signals in a resume are currently visible to the ranking model. An anonymized screening mode that redacts them is planned.
AI Act Arts. 9, 17
The documented, continuously maintained risk-management and quality-management processes the Act requires of high-risk providers do not exist yet.
AI Act Arts. 43, 47, 48
The self-assessed conformity procedure, EU declaration of conformity, and CE marking have not been completed.
AI Act Arts. 22, 49
The system is not yet registered in the EU high-risk AI database, and no EU authorized representative has been appointed.
AI Act Arts. 72, 73
A formal post-market monitoring plan and serious-incident reporting process are not yet in place.
GDPR Ch. V
Resume text is processed by US-hosted AI providers today. EU processing options and stricter data-retention agreements with model providers are under evaluation.
GDPR Arts. 28, 35
A standalone privacy policy, a signable data processing agreement, a subprocessor list, and DPIA support materials for customers are being prepared.
The roadmap
Roughly in order. Each item moves rows from the red list above into the green one.
Publish the privacy policy, DPA, and subprocessor list; ship automatic retention limits and complete, verified data erasure.
Redact names and identity signals before ranking, and run recurring adverse-impact tests on benchmark resume sets.
Immutable per-screening logs with score history and the exact model and rubric version behind every result.
Stand up the Article 9 risk-management process and Article 17 quality-management system, with published instructions for use.
Complete the conformity self-assessment, CE marking, EU database registration, and appoint an EU authorized representative.
EU-region processing options and zero-retention terms with AI model providers for resume content.
Get started free
The product is fully available outside the EU and EEA — including the UK, Switzerland, and the US. In the EU, join the notify list on our availability page and we'll email you the day screening reopens.
Try Resume Screening AI freeQuestions
Yes. No EU law bans AI in hiring. The EU AI Act regulates it as high-risk rather than prohibiting it: providers and employers must meet specific obligations, most of which apply from December 2, 2027. What is already banned outright is a short list of practices — emotion recognition in the workplace, social scoring, and biometric categorisation of protected traits. GDPR applies to AI screening of EU candidates today, including the Article 22 limits on solely automated decisions.
Under GDPR, yes — today. Articles 13 and 14 require telling candidates about automated processing, including meaningful information about the logic involved, typically in the privacy notice attached to the application. From December 2, 2027, the AI Act adds more: employers must inform workers and their representatives before using high-risk AI at work (Article 26(7)), and affected candidates can request a clear explanation of the AI system’s role in a decision (Article 86).
Legally, feeding CVs to a general-purpose chatbot is still AI-assisted recruitment — the same high-risk classification and GDPR duties apply, and under Article 25 an employer that repurposes a general-purpose system for high-risk hiring use can take on provider obligations itself. Practically, a general chatbot offers none of the controls the law expects: no consistent scoring rubric, no automatic logging, no documented accuracy, and candidate data leaves your controlled environment. A purpose-built system — ours included — has to be engineered around those requirements.
The provider is whoever develops the AI system and places it on the market — for resume screening, the software vendor (us). The deployer is whoever uses it under their own authority — the employer or recruitment agency running candidates through it. Providers carry the heavy obligations (risk management, bias testing, conformity assessment, CE marking); deployers carry usage duties under Article 26. A deployer that rebrands a system or substantially modifies it becomes a provider (Article 25).
Yes. Annex III, point 4(a) of the EU AI Act classifies AI systems used for recruitment or selection — including tools that analyse and filter job applications or evaluate candidates — as high-risk. Resume screening and candidate ranking software falls squarely within that definition.
The high-risk obligations for hiring AI were originally scheduled for August 2, 2026, but the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since July 27, 2026) postponed them to December 2, 2027. The obligations were deferred, not removed — providers of resume screening tools must comply by that date.
Yes, in full and today. Article 22 GDPR restricts decisions based solely on automated processing, and the CJEU’s SCHUFA judgment (C-634/21) held that automated scoring can itself be such a decision when the recipient relies heavily on it. Employers using screening tools generally also need a data protection impact assessment under Article 35.
We paused screening for EU and EEA visitors rather than operate while key high-risk requirements — bias auditing, full audit trails, conformity assessment — are still being built. The pause is temporary; you can leave your email on the notify list and we will tell you the day it reopens.
Yes. The product is fully available outside the EU and EEA, including in the UK, Switzerland, and the US. Note that from December 2, 2027 the AI Act can also reach non-EU companies if the system’s output is used in the EU — for example, screening applicants for an EU-based role.
Not anymore — that date is widely cited but outdated. The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on July 27, 2026 and postponed the high-risk obligations for Annex III systems, including resume screening, to December 2, 2027. What did start on August 2, 2026 are the Article 50 transparency duties: chatbot disclosure and labelling of AI-generated content.
Almost certainly not. Article 6(3) exempts systems that only perform narrow preparatory tasks without materially influencing decisions — but the exemption is expressly unavailable to systems that profile natural persons, and scoring or ranking candidates against a job is profiling. We treat our product as high-risk rather than argue for an exemption.
From December 2, 2027, deployers must use the system per the provider’s instructions, assign trained human oversight, ensure input data is relevant, keep logs for at least six months, and inform workers and their representatives before using high-risk AI at work (Article 26). A fundamental rights impact assessment (Article 27) is only required of public bodies and providers of public services — not of typical private employers. GDPR duties, including a DPIA, apply today.
Non-compliance with high-risk obligations carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. Prohibited AI practices carry up to €35 million or 7%. GDPR fines of up to €20 million or 4% apply independently.
Keep reading