Start free trial of Lex HR →

Are hiring algorithms high-risk under EU AI Act

EU AI Act service desk guidance clarifies whether hiring algorithms are high-risk and spells out obligations for employers and HR vendors.

7 September 2026

The EU AI Act service desk has answered the question are hiring algorithms high-risk under EU AI Act, publishing employment guidance that explains when recruitment, selection and other HR systems fall into the law's high‑risk category and therefore trigger enhanced compliance duties.

Published on Sept. 19, 2024, the guidance says AI systems “used for recruitment, selection and deciding on employment conditions” can be classified as high‑risk when they make decisions or assessments that affect workers’ access to employment or materially change their terms and conditions. The document lists the key obligations that follow: a risk‑management system, technical documentation and record‑keeping, human oversight measures, data‑governance practices and a conformity assessment before the system is placed on the EU market.

The service desk frames the classification around use and impact rather than underlying technology. A simple CV parsing tool used only to format applications is less likely to be high‑risk than an automated screening model that scores candidates and automatically rejects applications or ranks them for hiring decisions. The guidance therefore positions many people‑analytics platforms, screening algorithms and automated decision tools used to route, shortlist or terminate employment as likely to attract the high‑risk label if they materially influence outcomes for jobseekers or employees.

The Commission’s broader guidelines on AI high‑risk systems, published on the European Commission's Digital Strategy site, underpin the service desk note and set out the legal mechanics: high‑risk systems must undergo conformity assessment, implement post‑market monitoring, and meet transparency and human‑oversight standards. Those obligations interact with existing employer duties under data‑protection and labour law, the guidance says, requiring firms to align AI Act compliance with GDPR and national employment rules.

HR vendors and in‑house people‑analytics teams are already scanning the guidance for immediate consequences. Placing a system in the high‑risk bracket will likely force vendors into formal documentation and testing cycles — including bias and accuracy evaluations — and could require independent conformity assessments before software is marketed in the EU. Employers who deploy or rely on such tools will need to show risk‑management processes, preserve detailed logs, and ensure appropriate human oversight in hiring and performance decisions.

The document stops short of a catalogue of specific tools that are automatically high‑risk, instead offering scenarios and decision criteria. It does not quantify thresholds for "significant impact," set precise technical benchmarks for bias testing, or detail the cost and timing of conformity assessments for HR products. The guidance also does not create an EU‑wide register of certified HR systems or explain how national authorities will prioritise enforcement across sectors.

For HR leaders, the immediate work will be practical: inventory AI use across recruitment and workforce‑management processes, update vendor contracts and procurement checklists, and expand impact assessments to cover AI Act obligations as well as GDPR. Vendors can expect increased demand for transparency documentation, third‑party audits and built‑in human‑oversight features.

The service desk guidance signals a tighter regulatory environment for workplace AI: as more hiring and people‑analytics tools are pulled into the high‑risk regime, compliance will shift from optional add‑ons to core product and HR governance requirements. Employers and suppliers that move now to codify risk management, testing and oversight will be better placed to operate under the EU’s rules as conformity assessments and national enforcement follow.

Sources
  1. Employment — AI Act Service Desk
  2. Guidelines on AI high‑risk systems - European Commission Digital Strategy