EU AI Act · GDPR

AI hiring laws in the EU.

Written for recruiters and hiring managers: which laws govern AI in European hiring, what is legal today, what changes in December 2027 — and, because we build resume screening software ourselves, an honest audit of exactly where our own product complies and where it doesn't yet.

Last reviewed August 8, 2026. Every claim links to the official text below. A summary, not legal advice.

Annex III 4(a)
Hiring AI's classification: high-risk
Dec 2, 2027
High-risk obligations apply to hiring AI
€35M / 7%
Maximum AI Act fine (prohibited practices)

Is it legal to use AI in hiring in the EU?

Yes — AI in recruitment is legal in every EU and EEA country. No European law bans AI resume screening, CV filtering, or candidate ranking. What EU law does is regulate it: the AI Act classifies hiring AI as high-risk and attaches obligations that phase in through December 2, 2027, GDPR already restricts fully automated rejections today, and discrimination law applies to an algorithm exactly as it applies to a person. A short list of practices is banned outright — emotion recognition in the workplace above all.

We publish this guide because we sit on the regulated side of it: we build resume screening software, so we read this law the way an airline reads aviation law — because we have to. Further down you'll find the part most vendor pages omit: an item-by-item audit of our own compliance, including what isn't done.

What the law actually says

The EU AI Act (Regulation (EU) 2024/1689) classifies AI systems used "for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates" as high-risk (Annex III, point 4(a)). That is a literal description of resume screening software, including ours.

High-risk status brings a long list of provider obligations: a risk management system (Art. 9), data and bias governance (Art. 10), technical documentation (Art. 11), automatic logging (Art. 12), transparency and instructions for use (Art. 13), human oversight by design (Art. 14), accuracy and robustness (Art. 15), a quality management system (Art. 17), a conformity assessment with CE marking (Arts. 43–48), and registration in the public EU database (Art. 49). These were due on August 2, 2026, but the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) moved the deadline to December 2, 2027. Deferred — not diluted.

GDPR applies right now, with no grace period. Article 22 restricts decisions based solely on automated processing, and the Court of Justice's SCHUFAjudgment (C-634/21) established that an automated score is itself such a decision when the human relying on it doesn't genuinely deviate from it. Employers screening EU candidates also generally owe a data protection impact assessment (Art. 35). That is why our answer to the EU today is a pause, not a disclaimer.

The legal map

Five bodies of law govern AI in European hiring

The AI Act gets the headlines, but a recruiter using AI in the EU answers to all of these at once.

  • EU AI Act

    Regulation (EU) 2024/1689. Classifies recruitment and selection AI as high-risk (Annex III 4(a)) and phases in duties from February 2025 to December 2027. Also covers workplace AI beyond hiring: promotion, termination, task allocation, and monitoring systems are high-risk too (Annex III 4(b)).

  • GDPR

    Regulation (EU) 2016/679. Applies in full today. Article 22 restricts solely automated decisions, Articles 13–15 give candidates transparency and access rights, and Article 35 requires a DPIA for systematic candidate evaluation.

  • Equality directives

    Directives 2000/78/EC, 2000/43/EC, and 2006/54/EC. EU discrimination law is technology-neutral: an algorithm that disadvantages candidates by age, ethnicity, sex, disability, religion, or sexual orientation creates the same liability as a biased human — and the employer carries it.

  • Platform Work Directive

    Directive (EU) 2024/2831, to be transposed by December 2, 2026. Gives platform workers rights against opaque algorithmic management — human review of significant decisions, transparency about automated monitoring. The clearest signal of where EU law on algorithmic management at work is heading.

  • National law

    Member states add their own layer: in Germany, works councils have co-determination rights when AI is introduced at work; France’s CNIL has issued recruitment-specific guidance; several labour codes require consultation before automated monitoring. Check the countries you hire in.

The timeline

Every EU AI Act date that matters for hiring tools

Many sites still cite August 2, 2026 as the deadline for hiring AI. That date moved.

  1. Aug 1, 2024

    The EU AI Act (Regulation (EU) 2024/1689) enters into force.

  2. Feb 2, 2025

    Prohibited practices banned — including emotion recognition in the workplace (Art. 5(1)(f)) — plus the AI literacy duty (Art. 4).

  3. Aug 2, 2025

    Obligations for general-purpose AI models apply (Arts. 51–56).

  4. Jul 27, 2026

    The Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force, postponing the high-risk deadline for Annex III systems.

  5. Aug 2, 2026

    Art. 50 transparency duties apply — chatbot disclosure and AI-generated content labelling. The high-risk deadline originally set for this date no longer applies.

  6. Dec 2, 2027

    High-risk obligations for hiring AI (Annex III, incl. resume screening) apply — the operative deadline for this product.

  7. Aug 2, 2028

    High-risk rules for AI embedded in Annex I regulated products apply.

For employers

What recruiters and hiring managers must do

The AI Act splits duties between the provider (the software vendor) and the deployer (you, the employer). Some duties bind you today; the rest arrive on December 2, 2027 — and we're designing the product so each one is easy to meet.

Already binding today

  • GDPR Art. 22 · C-634/21

    Don’t let a rejection rest on the score alone. After the SCHUFA judgment, an automated score is itself a “decision” when the human relying on it doesn’t genuinely deviate from it — so keep a person reviewing, and empowered to disagree.

  • GDPR Art. 35

    Run a data protection impact assessment before deploying AI screening. Systematic evaluation of candidates using new technology is a textbook DPIA trigger.

  • GDPR Arts. 13–14

    Tell candidates in your privacy notice that automated processing is part of screening, what logic is involved, and what it means for them.

  • AI Act Art. 4

    Since February 2, 2025: ensure the staff operating AI tools have sufficient AI literacy — recruiters using a screening tool need to understand what it can and cannot do.

  • AI Act Art. 5

    Since February 2, 2025: never use prohibited practices — emotion recognition in interviews or assessments is banned, even when a vendor offers it.

From December 2, 2027

  • Art. 26(1)–(2)

    Use the system according to the provider’s instructions, and assign human oversight to people with the training and authority to overrule it.

  • Art. 26(4)

    Make sure the input data — your job descriptions and the resumes you upload — is relevant and sufficiently representative for the role.

  • Art. 26(6)

    Keep the logs the system generates for at least six months.

  • Art. 26(7) · Art. 86

    Inform workers and their representatives before using high-risk AI at work; candidates can request an explanation of the AI’s role in a decision.

  • Art. 27

    A fundamental rights impact assessment is only required of public bodies and entities providing public services — not of a typical private employer. (A widely repeated myth attributes this duty to all deployers; it’s Art. 27, and it’s narrow.)

The stakes

What non-compliance costs

Fines under the AI Act scale with the violation; GDPR fines stack on top. Figures are the maximum of the fixed sum or the share of worldwide annual turnover.

  • €35M or 7%

    AI Act Art. 99(3) — using a prohibited practice, such as emotion recognition in the workplace. The higher of the fixed sum or the percentage of worldwide annual turnover applies.

  • €15M or 3%

    AI Act Art. 99(4) — breaching the high-risk obligations. This is the tier that covers resume screening providers and the employers deploying them.

  • €7.5M or 1%

    AI Act Art. 99(5) — supplying incorrect, incomplete, or misleading information to notified bodies or authorities.

  • €20M or 4%

    GDPR Art. 83(5) — violations of data subjects’ rights, including Article 22. GDPR fines are separate from, and cumulative with, AI Act fines.

Primary sources

Read the law itself

Everything above traces back to the official texts — worth bookmarking before trusting any summary, ours included.

Our compliance status

Where Resume Screening AI stands, honestly

The audit we'd want from any vendor: what this product already does, what's only partially in place, and what isn't built yet — the reason screening is paused in the EU rather than merely footnoted.

Never in the product

Practices we don't use at all

Techniques the AI Act prohibits outright or restricts heavily — and that this product was never built on.

  • No emotion recognition or facial-expression analysis

    AI Act Art. 5(1)(f) — prohibited

    Inferring emotions in the workplace has been a prohibited AI practice since February 2, 2025. We analyse resume text only — never video, voice, photos, or biometrics.

  • No social scoring or biometric categorisation

    AI Act Arts. 5(1)(c), 5(1)(g) — prohibited

    Candidates are scored against your job description, not against behaviour, social signals, or inferred sensitive traits.

  • No automated candidate contact

    AI Act Art. 50 · GDPR Art. 22

    The product never emails, messages, or chats with a candidate — so nobody ever interacts with an AI believing it to be your recruiter.

In place today

Where we're already aligned

Capabilities that already match what the AI Act and GDPR expect of a hiring tool.

  • A human makes every hiring decision

    AI Act Art. 14 · GDPR Art. 22

    The product only scores and ranks resumes against your job description. It never rejects, advances, or contacts a candidate — every decision is made by a person reviewing the ranked list.

  • A written rationale with every score

    AI Act Art. 13

    Each ranked resume carries a plain-language explanation of why it scored the way it did, so reviewers can interpret — and disagree with — the output rather than rubber-stamp a number.

  • Identical criteria for every applicant

    AI Act Art. 15

    Every resume in a batch is evaluated against the same job description and the same scoring rubric, removing the ordering and fatigue effects of manual screening.

  • Paused in the EU instead of operating out of compliance

    AI Act Annex III 4(a)

    Screening is switched off for EU and EEA visitors while we work through the high-risk obligations, rather than running in the EU before we can meet them. Reopening is announced only to people who explicitly opt in.

Partially in place

Where we're part-way there

The foundation exists, but it doesn't yet meet the full standard the law sets.

  • Record-keeping of screening events

    AI Act Art. 12

    Every score and its rationale is stored with timestamps. A full audit trail — score history across re-ranks, and the model version behind each result — is still being built.

  • Data deletion and retention

    GDPR Arts. 5, 17

    Account deletion is self-serve in Settings, and data export or deletion requests are handled via support. Automatic retention limits and complete, verified erasure of all resume data are in progress.

  • Data minimization in processing

    GDPR Art. 5(1)(c)

    Contact details are stripped from resume text before similarity embeddings are computed. Redacting personal details from everything the ranking model sees is not yet done — see blind screening below.

  • Transparency documentation

    AI Act Art. 13

    Explanations ship inside the product, but the formal instructions for use — documented capabilities, limitations, and accuracy levels — are not yet published.

Not yet

Where we're not compliant yet

Requirements we have not met — being built before we reopen in the EU.

  • Bias testing and fairness audits

    AI Act Art. 10

    We do not yet run adverse-impact or demographic-fairness testing on ranking output. This is the single biggest item on our roadmap.

  • Blind screening mode

    AI Act Art. 10 · GDPR Art. 5

    Names, graduation years, and other identity signals in a resume are currently visible to the ranking model. An anonymized screening mode that redacts them is planned.

  • Risk and quality management system

    AI Act Arts. 9, 17

    The documented, continuously maintained risk-management and quality-management processes the Act requires of high-risk providers do not exist yet.

  • Conformity assessment and CE marking

    AI Act Arts. 43, 47, 48

    The self-assessed conformity procedure, EU declaration of conformity, and CE marking have not been completed.

  • EU database registration and authorized representative

    AI Act Arts. 22, 49

    The system is not yet registered in the EU high-risk AI database, and no EU authorized representative has been appointed.

  • Post-market monitoring and incident reporting

    AI Act Arts. 72, 73

    A formal post-market monitoring plan and serious-incident reporting process are not yet in place.

  • EU data residency

    GDPR Ch. V

    Resume text is processed by US-hosted AI providers today. EU processing options and stricter data-retention agreements with model providers are under evaluation.

  • GDPR paperwork for customers

    GDPR Arts. 28, 35

    A standalone privacy policy, a signable data processing agreement, a subprocessor list, and DPIA support materials for customers are being prepared.

The roadmap

What we're building before reopening in the EU

Roughly in order. Each item moves rows from the red list above into the green one.

01

GDPR foundation

Publish the privacy policy, DPA, and subprocessor list; ship automatic retention limits and complete, verified data erasure.

02

Blind screening & bias audits

Redact names and identity signals before ranking, and run recurring adverse-impact tests on benchmark resume sets.

03

Audit trail

Immutable per-screening logs with score history and the exact model and rubric version behind every result.

04

Risk & quality management

Stand up the Article 9 risk-management process and Article 17 quality-management system, with published instructions for use.

05

Conformity & registration

Complete the conformity self-assessment, CE marking, EU database registration, and appoint an EU authorized representative.

06

EU data residency

EU-region processing options and zero-retention terms with AI model providers for resume content.

Get started free

Hiring outside the EU? Screening is live.

The product is fully available outside the EU and EEA — including the UK, Switzerland, and the US. In the EU, join the notify list on our availability page and we'll email you the day screening reopens.

Try Resume Screening AI free

Questions

Frequently asked questions

Is it legal to use AI in recruitment in the EU?+

Yes. No EU law bans AI in hiring. The EU AI Act regulates it as high-risk rather than prohibiting it: providers and employers must meet specific obligations, most of which apply from December 2, 2027. What is already banned outright is a short list of practices — emotion recognition in the workplace, social scoring, and biometric categorisation of protected traits. GDPR applies to AI screening of EU candidates today, including the Article 22 limits on solely automated decisions.

Do candidates have to be told that AI screened their application?+

Under GDPR, yes — today. Articles 13 and 14 require telling candidates about automated processing, including meaningful information about the logic involved, typically in the privacy notice attached to the application. From December 2, 2027, the AI Act adds more: employers must inform workers and their representatives before using high-risk AI at work (Article 26(7)), and affected candidates can request a clear explanation of the AI system’s role in a decision (Article 86).

Can recruiters use ChatGPT to screen CVs in the EU?+

Legally, feeding CVs to a general-purpose chatbot is still AI-assisted recruitment — the same high-risk classification and GDPR duties apply, and under Article 25 an employer that repurposes a general-purpose system for high-risk hiring use can take on provider obligations itself. Practically, a general chatbot offers none of the controls the law expects: no consistent scoring rubric, no automatic logging, no documented accuracy, and candidate data leaves your controlled environment. A purpose-built system — ours included — has to be engineered around those requirements.

Who is the provider and who is the deployer under the EU AI Act?+

The provider is whoever develops the AI system and places it on the market — for resume screening, the software vendor (us). The deployer is whoever uses it under their own authority — the employer or recruitment agency running candidates through it. Providers carry the heavy obligations (risk management, bias testing, conformity assessment, CE marking); deployers carry usage duties under Article 26. A deployer that rebrands a system or substantially modifies it becomes a provider (Article 25).

Is AI resume screening high-risk under the EU AI Act?+

Yes. Annex III, point 4(a) of the EU AI Act classifies AI systems used for recruitment or selection — including tools that analyse and filter job applications or evaluate candidates — as high-risk. Resume screening and candidate ranking software falls squarely within that definition.

When do the EU AI Act rules for hiring tools apply?+

The high-risk obligations for hiring AI were originally scheduled for August 2, 2026, but the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since July 27, 2026) postponed them to December 2, 2027. The obligations were deferred, not removed — providers of resume screening tools must comply by that date.

Does GDPR already apply to AI resume screening?+

Yes, in full and today. Article 22 GDPR restricts decisions based solely on automated processing, and the CJEU’s SCHUFA judgment (C-634/21) held that automated scoring can itself be such a decision when the recipient relies heavily on it. Employers using screening tools generally also need a data protection impact assessment under Article 35.

Why is Resume Screening AI currently unavailable in the EU?+

We paused screening for EU and EEA visitors rather than operate while key high-risk requirements — bias auditing, full audit trails, conformity assessment — are still being built. The pause is temporary; you can leave your email on the notify list and we will tell you the day it reopens.

Can I use Resume Screening AI outside the EU?+

Yes. The product is fully available outside the EU and EEA, including in the UK, Switzerland, and the US. Note that from December 2, 2027 the AI Act can also reach non-EU companies if the system’s output is used in the EU — for example, screening applicants for an EU-based role.

Isn’t the EU AI Act deadline for hiring tools August 2, 2026?+

Not anymore — that date is widely cited but outdated. The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on July 27, 2026 and postponed the high-risk obligations for Annex III systems, including resume screening, to December 2, 2027. What did start on August 2, 2026 are the Article 50 transparency duties: chatbot disclosure and labelling of AI-generated content.

Can a resume screening tool avoid the high-risk classification?+

Almost certainly not. Article 6(3) exempts systems that only perform narrow preparatory tasks without materially influencing decisions — but the exemption is expressly unavailable to systems that profile natural persons, and scoring or ranking candidates against a job is profiling. We treat our product as high-risk rather than argue for an exemption.

What do employers using an AI screening tool have to do?+

From December 2, 2027, deployers must use the system per the provider’s instructions, assign trained human oversight, ensure input data is relevant, keep logs for at least six months, and inform workers and their representatives before using high-risk AI at work (Article 26). A fundamental rights impact assessment (Article 27) is only required of public bodies and providers of public services — not of typical private employers. GDPR duties, including a DPIA, apply today.

What are the penalties for breaking the EU AI Act?+

Non-compliance with high-risk obligations carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. Prohibited AI practices carry up to €35 million or 7%. GDPR fines of up to €20 million or 4% apply independently.

Keep reading

Explore more