EU AI Act compliance for AI-enabled applicant tracking systems
Most applicant tracking systems now advertise AI features. Some of those features put you into the high-risk tier of the EU AI Act and some do not, so the useful first step is working out which parts of your ATS actually do what.
Keyword search and duplicate detection are not the concern. Matching scores, candidate ranking, and automated rejection are.
Are you a provider or a deployer?
You are the deployer of the ATS. The vendor is the provider and carries conformity assessment, technical documentation, and registration duties for any high-risk functionality.
How this is classified under the Act
Classification follows function rather than product category. An ATS that stores applications and lets recruiters search them stays outside Annex III. The moment it analyses and filters applications or evaluates candidates, Annex III point 4 applies and the high-risk tier follows.
What changes the answer: Features that push an ATS into high risk include match or fit scoring, automated ranking of a shortlist, automated rejection thresholds, video interview analysis, and inferred personality or competency assessment.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Usage Policy for Deployers Article 26
Defines permitted and prohibited uses, human oversight arrangements, input data standards, logging, and incident reporting for a high-risk AI system you deploy.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Articles 6 and 9 Feature-level assessment
Document which specific AI features are enabled in your configuration, because the classification depends on your setup and not on the vendor’s full feature list.
- Article 26(2) Human oversight where scoring is used
Where the system scores or ranks, a competent person must be able to see and reconsider candidates the tool deprioritised.
- Article 26(7) Worker and representative information
Inform employees and their representatives before deploying high-risk AI in the workplace.
- Article 4 Recruiter literacy
Recruiters need to understand what the score means, what data produced it, and where it goes wrong. This is due now, independent of the high-risk timeline.
Common mistakes
- Accepting the vendor’s assurance that the product is not high-risk without checking which features you have switched on.
- Documenting the product name instead of the configuration, which leaves the assessment unverifiable.
- Enabling a new AI feature after the assessment and never revisiting the classification.
- Treating video interview analysis as ordinary screening when it raises emotion-inference questions under Article 5 as well.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 4 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.