EU AI Act compliance for AI CV screening and candidate ranking
AI that filters applications, scores candidates, or ranks a shortlist falls under Annex III point 4 of Regulation (EU) 2024/1689. This is high-risk classification, and it brings the fullest set of deployer obligations in the Act for an ordinary company.
The Omnibus, published in the Official Journal on 24 July 2026, pushed the standalone high-risk compliance date to 2 December 2027. That is real breathing room, and the Article 4 literacy obligation covering your recruiters still applies today.
Are you a provider or a deployer?
If you use a recruitment platform built by someone else, you are the deployer and Article 26 governs your duties. The platform vendor carries the provider obligations including conformity assessment.
How this is classified under the Act
Annex III point 4 covers AI used in recruitment or selection, in particular to place targeted job advertisements, analyse and filter applications, and evaluate candidates. Screening CVs sits squarely inside that description, so the high-risk tier applies regardless of company size.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Usage Policy for Deployers Article 26
Defines permitted and prohibited uses, human oversight arrangements, input data standards, logging, and incident reporting for a high-risk AI system you deploy.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Article 26(2) Meaningful human oversight
A qualified person has to review outcomes with real authority to override them, and with enough information to judge whether a ranking is reasonable. Rubber-stamping a machine shortlist does not meet this.
- Article 26(7) Inform affected workers
Before putting a high-risk system into use in the workplace, employers must inform workers and their representatives that they will be subject to it.
- Article 26(6) Keep logs
Retain system logs for at least six months, and longer where other law requires it. In practice a three-year retention keeps you aligned with employment record norms.
- Article 86 Right to an explanation
A candidate affected by a decision made with a high-risk system can ask for a clear explanation of the role the AI played. You need to be able to answer that.
- Article 26(1) Use it as the provider intended
Follow the vendor’s instructions for use. Repurposing a screening tool for something it was not validated for shifts liability toward you and can even make you a provider.
Common mistakes
- Assuming the ATS vendor’s compliance covers you. Provider and deployer obligations are separate and both have to be met.
- Calling a human reviewer the oversight mechanism when that person sees only the tool’s shortlist and never the rejected applications.
- Never telling candidates or works councils that AI is used in the process.
- Reading the Omnibus delay to December 2027 as a reason to do nothing, when literacy is already due and vendor contracts take months to renegotiate.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 4 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.