Summary: A worked sector example of the high-risk regime. Annex III(4) makes most HR AI high-risk, obligations fall on both providers and deployers, and the Act reaches non-EU deployers.
Sources: raw/Laws/What the EU AI Act Means for Staffing Businesses...md; raw/AI-regulations/Regulation - EU - 2024_1689.md (Annex III(4))
Last updated: 2026-07-28
Useful here not because employment is a security domain, but because it is the clearest end-to-end illustration in the corpus of what the high-risk regime actually demands of an ordinary organisation.
What is covered
Annex III(4) covers AI systems for “the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates,” and for “decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons” (source: Regulation - EU - 2024_1689.md).
The sector reading: “recruitment, selection, targeted job advertising, candidate evaluation, performance monitoring, and certain decisions about compliance, contract terms or termination” (source: What the EU AI Act Means for Staffing Businesses…md).
What it requires
From 2 August 2026, each such tool needs “mandatory risk assessments, technical documentation, bias testing, human oversight, transparency disclosures, and continuous monitoring.”
Both providers and deployers are in scope. A staffing firm that merely uses a vendor’s screening tool has its own Article 26 obligations, and can become a provider if it modifies the system — see provider vs deployer.
The five points the source emphasises
Extraterritorial reach — the Act “may apply to deployers even if they are not based in the European Union.”
Human oversight is not optional — the section heading is verbatim. This is Art 14, and it is the requirement most often satisfied nominally and not substantively.
Candidates and workers must be told — the transparency layer, stacking Art 13 (to deployers), Art 26(7) (deployer duty to inform workers) and Art 50 where applicable.
Data quality and bias monitoring need real attention — Art 10.
“Logs and documentation are an infrastructure requirement” — the framing is right. Art 12 record-keeping is not a policy you write; it is a system you build. See below.
Article 5 sits underneath all of this
Two prohibitions apply directly to the employment context and are already in force since 2 February 2025:
- Art 5(1)(f) — inferring emotions “in the areas of workplace and education institutions,” except for medical or safety reasons. Emotion-analysis features in interview or monitoring tools are banned outright, not high-risk.
- Art 5(1)(b) — exploiting vulnerabilities due to “age, disability or a specific social or economic situation.”
Exemptions exist but are narrow
The source’s section heading: “Some of your tools might be exempt. Most of them probably aren’t.”
The Art 6(3) derogation is the route — narrow procedural task, improving completed human activity, pattern detection not replacing human assessment, or preparatory task. But profiling defeats the derogation unconditionally, and candidate scoring and ranking is profiling. See high-risk classification.
The security-relevant reading
Two things generalise from this sector example:
-
Logging is infrastructure, and it is the forensic precondition for everything else. Art 12 requires automatic event recording over the system’s lifetime. Without it there is no incident investigation, no root-cause analysis for an Art 73 report, and no evidence for the Art 6(4) derogation documentation. Teams that treat it as a compliance checkbox discover the gap during an incident.
-
Deployers inherit obligations they cannot discharge alone. A deployer must monitor for bias and provide human oversight over a model whose training data and internals belong to the provider. The Act’s answer is Art 53(1)(b) documentation flowing downstream; whether that is sufficient in practice is the open question in provider vs deployer.
Penalties
The source notes “national authorities’ fining powers, as well as other enforcement powers, such as the power to withdraw or recall AI systems from the market.” Art 16 provider and Art 26 deployer breaches sit in the €15M / 3% tier. See enforcement and penalties.