AI in recruitment and selection: why HR has become the critical function
Recruitment is high-risk AI under Annex III of the EU AI Act. What HR must arrange now: human oversight, bias control, supplier checks and the 2027 deadline.

Updated 1 July 2026. Recruitment and selection is a high-risk AI application under Annex III of the EU AI Act. Through the Digital Omnibus on AI (adopted by Parliament on 16 June 2026 and the Council on 29 June 2026, still awaiting publication in the Official Journal), the application of the high-risk AI requirements moves from 2 August 2026 to 2 December 2027. The AI literacy obligation of Article 4 has applied unchanged since 2 February 2025. Postponing the high-risk AI requirements is not the same as cancelling them: the preparation HR has to make stays the same and takes time.
Why HR is suddenly the most sensitive function in the organisation
Until recently, HR was mainly a GDPR topic for compliance people. Personal data, processing agreements, retention periods, familiar territory. With the EU AI Act, that changes fundamentally. Recruitment and selection appears literally in Annex III of the regulation, in the list of high-risk AI applications. That means it is the HR department, rather than the IT department or senior management, that is likely to become one of the first places where questions from auditors, candidates and supervisory authorities arise.
That is not an abstract legal move. It is a direct consequence of something HR professionals themselves know best: in two years, AI has become the beating heart of modern recruitment. The legislator has decided that this one function has so much impact on people's lives that the heaviest compliance requirements for permitted AI apply.
What you may not consider "AI", but the law does
In conversations with HR managers, almost the same reaction always comes up: "We do not really use AI." However, a closer look typically reveals that the organisation does, in fact, work with:
Each of these may qualify as an AI system under the EU AI Act, depending on its functionality. If such a system is used for recruitment, selection, promotion, termination or worker evaluation, Annex III can make it high-risk.
What high-risk AI means in practice for your HR department
When the high-risk AI requirements become applicable (with the Digital Omnibus that is 2 December 2027, unless publication in the Official Journal changes that date), your organisation must have demonstrably arranged the following for each high-risk AI system in HR:
Human oversight. There must always be a person who can override the AI outcome, and who is also trained to do so. "The recruiter gets a list, picks the top 5 and schedules interviews" is not enough if that recruiter has no idea how the AI arrived at that list or what to watch out for.
Transparency towards candidates. Applicants must know that AI is used in their assessment. Not in the small print, but clearly and at the right moment in the process. Where an Annex III high-risk AI system contributes to a decision that legally or similarly significantly affects a candidate, the candidate can have a right under Article 86 to a clear and meaningful explanation of the AI system's role and the main elements of the decision. If a high-risk AI system is used in the workplace, the employer must also inform workers' representatives and the affected workers before putting it into service or using it.
Bias control. Demonstrably. How do you know that your screening tool does not systematically score women, older people, non-Western names or people with a disability lower? "Our supplier says the system is unbiased" is not a defence. As deployer, you cannot simply rely on the supplier's reassurance. You must organise competent human oversight, monitor the system in use, keep the necessary logs and document how bias risks are handled in your own recruitment process.
Logging and retention periods. You must be able to reconstruct which candidate was assessed by which AI system, when, and how. In the event of a complaint or audit, that file has to be on the table.
Data quality. The input data you control must be relevant and sufficiently representative for the intended purpose. For training data and system design, you need adequate documentation and assurances from the provider.
The three lines of defence HR needs
One AI literacy training for "everyone in HR" is not enough. As with other high-risk functions, there has to be differentiation:
Anyone who does not cover these three layers separately supports AI literacy insufficiently, as Article 4 requires, and is certainly not ready for the high-risk AI requirements that come on top. How you get to work with Article 4 in practice is something we describe in a separate insight.
The silent time bomb: supplier contracts
An issue that goes largely unnoticed in almost every HR department: most recruitment tools come from external suppliers, and those contracts were signed years ago without any clause about AI Act compliance. As soon as the high-risk AI requirements apply, that becomes a problem. Because even if your supplier calls itself a "provider", the law makes you as the deployer responsible for what happens in your recruitment process. Ignorance does not release you.
This is perhaps the most important action HR must take in the coming period: a supplier check. Which tools do we use, what does the supplier say about AI Act compliance, which documentation can they provide, and, critically, which responsibility can they take on contractually? Suppliers who grow evasive at the first sign of questioning will inevitably become your problem later on. The extra time until 2027 is precisely meant to do this kind of contract work carefully.
What you realistically have to do now
The deadline for the high-risk AI requirements is further away than first thought, but the task remains. Those who use the time rather than wait will be in a strong position later:
In closing
In two years, HR has changed from an administrative function into a function where the heaviest compliance requirements will land. That is not a punishment, it is a recognition of how much impact recruitment and selection has on people. The HR organisations that take this seriously now do more than compliance. They build a recruitment practice that candidates can trust, and that will become the standard other employers are compared against.
At AIAdopt, we developed the HR sector extension (M3-HR) specifically for recruiters, HR business partners and HR management. The training covers recognising bias, human oversight, the high-risk AI requirements under Annex III, and the supplier issue, ending with an assessed certificate that lists the AI Act articles covered.
👉 See our approach for HR or build your own package tailored to your organisation.
Want to know where your organisation stands?
Download our free EU AI Act Compliance Checklist or view our AI literacy training.