EU AI Act compliance for HR tech and recruitment software companies
HR technology is the sector most directly exposed by Annex III. Employment AI is named in point 4, which means a company building screening, ranking, or performance tools is a provider of a high-risk AI system.
Provider duties are heavier than deployer duties, and there is a commercial dimension too. Your customers now ask for AI Act documentation during procurement, so being able to answer quickly has become a sales advantage.
Are you a provider or a deployer?
You are the provider. Your customers are deployers. Both sides have obligations, and your customers increasingly expect you to help them meet theirs.
How this is classified under the Act
Annex III point 4 covers AI for recruitment and selection, evaluation of candidates, decisions on promotion and termination, task allocation, and monitoring of performance and behaviour at work. HR tech products built on those functions are high-risk by design.
What changes the answer: Provider obligations include a risk management system under Article 9, data governance under Article 10, technical documentation under Article 11 and Annex IV, logging, instructions for use, conformity assessment, CE marking, and registration in the EU database.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Usage Policy for Deployers Article 26
Defines permitted and prohibited uses, human oversight arrangements, input data standards, logging, and incident reporting for a high-risk AI system you deploy.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Article 4 Literacy across your own team
This applies to you as a company using AI internally as well, and it has been enforceable since February 2025 regardless of where your product obligations land.
- Article 13 Instructions for use for your customers
High-risk providers must supply instructions enabling deployers to comply, covering intended purpose, accuracy, known limitations, and the human oversight measures the system supports.
- Article 10 Data governance and bias testing
Training, validation, and test data must be examined for bias. In employment AI this is the substance of the classification, not a formality.
- Article 26 Understand your customers’ duties
Your customers need human oversight, worker information, and logging. Products that make those easy get through procurement faster.
Common mistakes
- Marketing AI features while telling customers the AI Act does not apply to the product.
- Leaving customers to work out their deployer obligations alone, which stalls deals in legal review.
- Overlooking the internal Article 4 obligation while focused on product-level compliance.
- Building emotion or personality inference into hiring tools, which runs into Article 5 rather than merely high-risk status.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 4 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.