Back to all articles
19 min read

What the EU AI Act Means for Recruitment in 2026, and the 7 Actions You Need

What does the EU AI Act mean for recruitment? Read what applies in 2026, what shifts to 2027, and which 7 actions recruiters need to take now.

Recruiter reviewing an EU AI Act recruitment compliance checklist with tool owners and review dates
Key points

Prepare now by building AI literacy and human oversight, since the strictest rules for high-risk systems only take effect at the end of 2027. Focus first on transparency and understanding the tools you currently use.

2 August 2026Key date for the first transparency rules within recruitment processes
2 December 2027Compliance deadline for high-risk systems that filter or rank candidates
AI literacyMandatory basic knowledge for recruiters about how AI works and its limits
7 actionsDirectly applicable steps to start with a workable approach today

The core point is simple: for the EU AI Act in recruitment, you don't need to wait until every rule kicks in at once. Prohibited applications and AI literacy already apply earlier. Certain transparency rules start to matter from 2 August 2026. Many rules for standalone high-risk AI systems in recruitment mainly become relevant from 2 December 2027. So right now, what you most need to know is which AI you use, what that AI does, and where your responsibility begins and ends.

This article gives a practical answer for recruiters and agency owners. You'll read what already counts now, what kicks in later, and which seven actions you can put in place today. This explanation is informational and does not replace individual legal advice.

  • Many recruiters think all the heavy rules already start in August 2026, but that's not accurate.
  • AI that drafts text often calls for a different approach than AI that assesses or ranks candidates.
  • As a user, you stay responsible for oversight, clear explanation and checking the outcomes.
  • A workable approach starts with ownership, evidence and a review date per tool.

Why this update on the EU AI Act in recruitment is needed now

A lot of explanation about the AI Act stays general. As a result, it can sometimes look as though every rule for AI in hiring starts on exactly the same date. That's unhelpful, because it quickly leads you to pick the wrong priorities. For AI legislation in recruitment, you need to draw a clear line between prohibited applications, staff knowledge, transparency, and specific rules for higher-impact applications. That distinction is exactly what helps recruitment teams work in a targeted way on recruitment AI compliance, without immediately labelling every tool a heavy risk.

For agencies and employers without their own in-house lawyer, that nuance matters even more. You want to know, after all, what needs to change in your process tomorrow. That's why we explain the timeline in plain language, translate the roles of supplier and user into everyday tasks, and make human oversight concrete using examples from recruitment work.

2 / 12

What the EU AI Act timeline for recruitment actually says

What already applies now

Part of the rules already apply much earlier than many recruiters think. This covers, in any case, prohibited applications and the employer's AI literacy. In plain terms, this means staff need to understand enough about the AI they use. They need to know what a tool does, where the limits are, and when to step in. For the AI Act in HR, that's an absolute baseline requirement, because as a recruiter you must not blindly trust a score, suggestion or summary when it has consequences for the candidate.

What becomes relevant from 2 August 2026

From 2 August 2026, certain transparency rules become increasingly important in practice. Not every AI tool falls under exactly the same requirements here; the purpose and the actual use make the difference. A tool for drafting text or intake summaries works fundamentally differently from a system that assesses candidates or affects their chances of moving to the next step. That's why the AI Act in recruitment calls for a targeted assessment per application, not general assumptions based on a tool's name.

What kicks in later for many high-risk applications

For many standalone high-risk AI systems in recruitment, 2 December 2027 is the key moment. This point often gets missed. This date is relevant for applications involving work, access to work, and the actual assessment of candidates. Think of systems that independently filter applications, evaluate candidates, target advertising in a way that affects people's chances, or rank people for a next application step. This doesn't mean, though, that you can sit back until 2027. It does mean you need to get the basics in order now, so you have less to fix at a later stage.

For the exact timeline and the official legal texts, it's always wise to check the public information from EUR-Lex, the Council of the EU (Consilium) and the EU's Digital Strategy website. Those sources are authoritative when it comes to dates, definitions and the structure of the law.

3 / 12

When the EU AI Act in recruitment is about high risk

High risk in plain language

Within the EU AI Act for recruitment, high risk usually concerns AI that has a direct influence on access to work or on the assessment of a candidate. That's the absolute core of it. As soon as AI has a say in who becomes visible, who gets through to the next round, or who drops out, you move faster into a much stricter framework. Within the AI Act for hiring, it's about the real impact on people's chances, not just a technical label.

Examples in recruitment

Examples that may fall under high risk include filtering applications, evaluating answers or CVs, ranking candidates by suitability, and forms of targeted advertising that directly affect access to vacancies. Systems that give a recruiter a score, order or priority for who should be approached first can fall under this too. The assessment always depends entirely on the actual use. So look critically, per tool, at the purpose, the influence and its exact place in the process.

What doesn't decide it

A supplier can happily call a tool an assistant or a copilot, but that says very little about its legal meaning. A light-sounding name doesn't automatically make a system light in use. For the user's role under the law, what mainly counts is how you actually deploy the tool in practice. Does the system only help with preparation, or does it actively steer a decision about candidates? That's the key question you need to keep answering if you want to assess the risk properly.

Tip: Elvatix gets more out of every InMail credit. Higher response rates, lower cost per contact.

See how
4 / 12

The difference between supplier and user within the EU AI Act for recruitment

What the supplier needs to arrange

The supplier has specific tasks around design, testing, documentation, logging, explanation and enabling oversight. In plain terms, this comes down to transparency and evidence. The maker of the tool needs to clearly explain what the system is for, how it was tested, and what checks are needed. This should also include important information about the data used, known limitations, and how incidents or errors can be reported.

What the user needs to arrange

The user has their own responsibilities and can't simply hand these entirely over to the supplier. Always use the tool according to the instructions. Watch the input. Check the outcomes. Flag errors and unusual patterns. Organise human oversight of AI in a way that's genuinely workable on a busy working day too. This connects directly to the AI Act obligations for the employer, because the quality of your process ultimately always becomes visible within your own team.

A practical translation for recruitment agencies

In a small team, simplicity usually works best. Set out who owns a tool, who checks the output, who handles candidates' questions, and who keeps in touch with the supplier. Split those tasks per process step, such as sourcing, first selection, outreach and reporting. This way, AI use at recruitment agencies becomes a concrete working agreement with clear responsibility and a fixed review date.

5 / 12

What human oversight looks like in practice under the EU AI Act for recruitment

What human oversight of AI really means

Human oversight means a recruiter properly understands what the system is doing and can knowingly disregard its outcome. The recruiter must also be able to stop the process at any moment if something isn't right. That calls for far more than a quick check. Someone needs to be able to see why a candidate scores exactly high or low, and must also have the authority to deviate from that score. Without that room, there's no genuine oversight, even if the process looks neatly described on paper.

Which conditions are needed

Good oversight consistently calls for time, knowledge and authority. Time is needed because careful checking simply takes work. Knowledge is essential because someone needs to understand where errors or skewed outcomes might arise. Authority is essential because a recruiter must genuinely be allowed and able to intervene. These three conditions make the real difference between a paper agreement and a workable process for the AI Act in recruitment in everyday practice.

Practical example

Say a recruiter works with fixed search criteria, a scorecard and a short note per candidate. Then that recruiter needs to be able to adjust the criteria, properly assess the score, and decide entirely on their own whether or not to approach someone. In our workflow, we build in checkpoints like this very deliberately, so the review always stays visible. Anyone who wants to see how steps like this come back in a process can look at the page how the review works in Elvatix to see how this is set up in practice. That helps enormously with process control, but it obviously doesn't replace a full legal assessment.

6 / 12

The difference between writing support and decision-making with AI

AI that drafts text

AI can be enormously useful for draft messages, summaries, first versions of job adverts, or notes after an intake call. In cases like this, the tool mainly supports the preparatory work. The recruiter then checks the text thoroughly and decides for themselves what actually gets used. The risk here is often much lower, as long as the AI doesn't determine who becomes visible or who disappears from view instead. That difference matters a great deal within the AI Act for HR, because the impact on candidates here is far more limited than with systems that steer substantive choices.

AI that ranks or rejects candidates

The situation changes completely once AI ranks, scores, selects or even rejects candidates. Then the system directly affects people's chances. That's where the AI Act for hiring calls for tighter controls, a clear division of roles, and far better documented review moments. For many teams, this is the single most important distinction, because it marks exactly the point where handy support turns into decision support with heavier consequences.

Why this difference matters so much

Many teams say the AI is only supporting them, while in practice the output is quietly already steering the selection. So always take an honest look at the system's real role. If the AI actively plays a part in the choice to approach someone or not, to put them forward or not, or to reject them or not, you simply need to assess that more heavily than a tool that only generates text. That's why such a simple two-way split often works better than complicated technical jargon: preparation really is something different from assessment.

7 / 12

Informing candidates about AI under the EU AI Act in recruitment

When informing is needed

If AI plays a relevant role in your process, you need to think carefully about when you inform candidates about this. Especially with applications that affect assessment or access to work, a clear explanation matters a great deal. Informing candidates about AI means that someone understands a system is being used, exactly what for, and that a human stays involved at all times. This information also needs to arrive at a logical moment, for example in the job advert, directly in the application confirmation, or just before an important assessment step.

What to explain in plain language

Calmly explain that you use AI, for which specific purpose, what role the recruiter keeps in this, and how someone can ask questions about this process. Preferably avoid loaded words like "smart", "fair" or "objective" if you can't then back these up firmly. Simple, clear language works far better, because candidates then understand much faster what happens with their personal data and with the final assessment of their application.

Example text for candidates

A very usable text, for example, is: "In this hiring process, we use AI to support parts of sourcing, summarising or assessment. A recruiter always checks the outcomes and can deviate from them at any moment. Do you have questions about the use of AI in your specific process? Please feel free to let us know." This explanation is short, strong, clear and fits perfectly at B1 level.

8 / 12

AI Act checklist for recruiters: 7 actions for recruitment AI compliance

1. Build a complete overview

Carefully note down every AI tool you currently use. For each tool, write down where it sits in the process, what its precise purpose is, who the internal owner is, and what evidence you keep. Think of supplier documentation, internal work instructions and handy screenshots of your settings. This forms the basis of every AI Act checklist for the recruiter, because without a good overview you simply can't make a good assessment.

2. Assess the tool's role

Decide critically, per tool, whether it's mainly about writing support or actually about supporting a decision. Then look carefully at whether the application might fall under high risk. The key question always remains whether the tool has an influence on access to work or on the substantive assessment of candidates.

3. Ask the supplier targeted questions

Ask how the supplier classifies the tool, what specific data was used, how it was tested for errors and skewed outcomes, what logging is available, and how explanations are given. Also ask very concretely what you, as the user, still need to arrange yourself. A recruitment team working with AI sourcing with human control still needs to assess for itself whether the outcome is correct and whether the review is properly set up.

4. Run a privacy check

Check carefully which personal data the tool processes, how long the data is kept, and exactly who it's shared with. The AI Act, of course, doesn't exist separately from the existing privacy rules. So also always look closely at the legal basis, the retention periods and the agreements with suppliers about data processing. For recruitment AI compliance, this is genuinely a standard part, and certainly not a side issue.

5. Document human oversight

Write down clearly who checks, at what moment, and with what authority. Also record who is allowed to disregard an outcome, who can stop the process immediately, and when escalation is needed. This makes human oversight of AI concrete and testable, even when several recruiters work with exactly the same tool.

6. Arrange communication to candidates

Decide in advance which text you use, exactly when you show it, and through which channel that happens. Always assign an owner and a review date to it. This way, you turn informing candidates about AI into a fixed and logical part of your process, rather than a quick, loose remark added afterwards.

7. Track incidents and deviations

Log all errors, complaints, unexpected outcomes and later adjustments. Think of strange or unexplainable scores, technical problems, or possible signs of unequal treatment. By keeping good records of this, you can later show far more clearly what you observed and which steps you then took. This also helps enormously with holding suppliers to account on recurring problems in a targeted way.

A particularly handy approach is to use three fixed fields for each of these seven points: owner, evidence and review date. This keeps the checklist highly workable and clear, even for a relatively small team.

  • Overview: note the tool, process step, purpose, owner, evidence and review date.
  • Assessment: record whether it's purely writing support or has an influence on selection and assessment.
  • Supplier check: keep all answers about data, testing, logging, explanation and incidents.
  • Oversight and communication: assign a clear person responsible for the review and the candidate notice.
  • Monitoring: keep all complaints, errors and any adjustments in one fixed log.
9 / 12

Questions recruiters should ask suppliers about the EU AI Act in recruitment

About purpose and classification

Ask exactly what the tool in question is meant for. Does the system only support preparation, or does it also indirectly or directly influence selection, scoring or ranking? Also push to understand why the supplier believes a system does or doesn't come close to high risk. This helps considerably with your own assessment as the end user of the tool.

About training and test data

Ask explicitly what types of data were used for training and testing. Also ask how well suited that data is to your everyday practice, and which limitations are already known. If a supplier can't give you a clear, straightforward answer to that, it's a strong signal to keep probing before you build a tool like that more deeply into your own process.

About testing for errors and skewed outcomes

Ask what concrete checks have been done on errors, skewed results, and performance across strongly different situations. Also ask how often those checks are repeated and how any improvements are recorded. General claims simply aren't enough without a concrete explanation, because otherwise you can't properly judge whether a tool really fits your way of hiring.

About logging and explainability

Ask exactly what data is recorded, which choices made can still be traced later, and how a recruiter can properly understand the final outcome. This matters especially for teams without their own in-house specialist, because otherwise it's hard to show afterwards exactly how a decision came about and where an outcome may have gone wrong.

About security, incidents and implementation

Ask how your data is secured, how incidents are reported, and what the supplier needs directly from you if something does go wrong. Also ask who your fixed point of contact is, what a reasonable response time looks like, and what support is offered with implementation and setting up the review. If you'd like to discuss a product or process further, you can get in touch very easily via ask your question about AI in recruitment. We're happy to help with more explanation about how it works and how to implement it, but we explicitly do not give individual legal advice.

10 / 12

What this means for your team, process and tool choice

The AI Act really doesn't only touch your software. Your entire process around it matters at least as much. So look closely, step by step, at who decides, what the AI actually does, and what evidence you keep of that. This is how you make the AI Act obligations for employers genuinely practical and workable. It also stops important policy from existing only on paper while everyday practice lags far behind it.

Teams that get this right straight away look much wider than just buying a new tool. They carefully document review moments, train their recruiters on how AI works and where its limits are, and they regularly check whether practice still matches the original intention. Anyone who wants a bit more context on setting up a good process can take a look at our Elvatix case studies. Those specific examples show beautifully how checkpoints can be made visible, but of course they don't constitute legal proof on their own.

11 / 12

A practical example of control in sourcing and outreach

Take, for example, a sourcing process where a recruiter enters specific search criteria, lets a smart system suggest candidates, and then reviews the reason for the match per candidate. This recruiter then checks the draft message, manually adjusts the tone, and ultimately decides for themselves whether the message actually gets sent. In a clear process like this, you can clearly see where the human oversight sits: at the criteria, at the assessment, and at the sending. Also record clearly who checks these steps and how often you reassess this way of working. This makes the AI Act for hiring very concrete and directly workable for an agency or an in-house team.

This kind of setup also helps enormously with staff AI literacy. Recruiters then learn not just which button to press, but also, directly, why a suggestion from a system is never automatically the right decision on its own. This way, oversight genuinely becomes a core part of the work, not a separate check that only gets added on afterwards.

12 / 12

Frequently asked questions about the EU AI Act in recruitment

Does the EU AI Act still apply if I only use AI for text?

Yes, the law can still be relevant even then. The risk here is often different, though, from systems that directly assess or rank candidates. So always look carefully at the actual purpose of the tool and at the influence it has on decisions in the recruitment process.

When is AI in recruitment high risk?

AI in recruitment mainly comes into view prominently as high risk when the system has an influence on access to work or on the assessment of candidates. Think of filtering, evaluating, scoring or ranking. The tool's name is absolutely not decisive here; the actual use is what counts.

Do I always need to inform candidates about AI?

You always need to assess very carefully at which moment information is needed. Especially with a relevant use of AI in assessment or selection, a clear explanation is always wise. Informing candidates about AI helps make expectations clear on both sides and directly shows that human oversight is in place.

Am I responsible if my supplier builds the tool?

Yes. The supplier has its own tasks, but as the user you stay responsible for how you deploy, check and keep monitoring the system within your own process. That's a very important part of responsible use and of good recruitment AI compliance.

What should a small recruitment agency arrange first?

Start by building a good overview of your tools. Note down exactly what they do, who owns them, and exactly where human oversight takes place. Then ask your suppliers targeted questions and clearly document communication to candidates. This quickly gives you a good overview and lets you make better, well-founded choices.

Anyone who wants to start today is particularly well advised to first map out AI use properly, then document oversight, and then bundle the supplier questions together. This is how you make the EU AI Act in recruitment genuinely manageable for your team. Do keep the timeline sharply in view, though. Some duties already apply now, some specifically only come into play from 2026, and many rules for standalone high-risk AI systems in recruitment need extra attention especially as 2 December 2027 approaches. Serious breaches can ultimately lead to heavy fines, though the nature, context and proportionality always play a role here too. This article is purely meant as a practical explanation and does not serve as individual legal advice.

Try it now

Write a personal message right here

Enter a name or LinkedIn URL and get a personalised message within 30 seconds. No account needed.

1Candidate
2Your profile

Is your recruitment ready for the AI Act?

Elvatix offers a recruitment platform that facilitates human oversight and transparent decision-making in line with EU guidelines. Use our audit logs and configurable workflows to stay demonstrably in control.