EU AI Act Compliance in HR: What It Means and What HR Teams Must Do Now
The EU AI Act classifies AI recruitment tools as high-risk systems — the same category as medical devices and critical infrastructure. For HR teams using AI resume screening, candidate scoring, or automated hiring decisions, this creates mandatory obligations: transparency documentation, human oversight requirements, bias testing, and candidate rights to explanation. Non-compliance carries fines up to 3% of global annual revenue. Here’s what the law requires and what HR teams need to implement now.
The EU AI Act entered into force in August 2024, with phased implementation timelines running through 2026. HR teams using AI in recruiting need to understand which obligations apply now versus which come into force on later dates — and start building compliance infrastructure before enforcement deadlines arrive.
The automation architecture that supports compliance is built on the same CRM and workflow tools that support recruiting efficiency. If you’re starting from scratch on HR automation, Keap for HR: 8 Strategic Ways to Automate Recruiting — Complete 2026 Guide provides the foundation. This post covers the specific compliance layer that needs to sit on top of it.
Why Recruitment AI Is Classified as High-Risk
The EU AI Act’s high-risk classification for recruitment AI reflects the stakes involved: AI systems that influence hiring decisions have a direct impact on employment access — a fundamental right. High-risk classification means these systems can be used, but only with specific safeguards in place. The classification applies to any AI system used to shortlist candidates, score resumes, predict interview performance, or inform hiring decisions.
Mandatory Requirement 1: Risk Assessment and Documentation
High-risk AI systems require a documented risk assessment before deployment. For recruitment AI, this means documenting:
- What data the system uses to score candidates
- What outcomes the scoring is designed to predict
- What populations the system has been tested on
- What disparate impact testing has been conducted
- What human oversight mechanisms exist
This documentation doesn’t require a legal team to create — it requires honest answers to these questions. If your scoring model uses criteria you can’t explain, that’s the compliance problem to fix, not just the documentation to complete.
Mandatory Requirement 2: Human Oversight in the Decision Loop
The EU AI Act prohibits using high-risk AI to make final hiring decisions without human review. AI can score, rank, and shortlist — but a human must make the hiring decision, and that human must have the ability to override the AI’s recommendation. Documentation of the human override mechanism is required.
In practice: your scoring model produces a ranked candidate list. A human recruiter reviews that list and makes the advancement decision. The AI informs the process; it doesn’t replace the decision-maker. Build this explicitly into your workflow documentation.
Mandatory Requirement 3: Transparency to Candidates
Candidates subject to AI-assisted screening must be informed that AI is being used. The notification must occur before or at the time of application. This is typically included in the application process disclosure or privacy notice. It doesn’t need to reveal the scoring criteria — just disclose that AI tools are used in the screening process.
Mandatory Requirement 4: Bias Testing and Audit
High-risk AI systems require ongoing bias monitoring. For recruitment AI, this means: quarterly analysis of scoring outcomes across demographic groups, documentation of any systematic disparate impact, and evidence of corrective action when disparate impact is identified.
The practical implementation: export your scored candidate pool quarterly, segment by available demographic indicators, and compare pass-through rates by group. If any group has a statistically different pass-through rate that isn’t explained by relevant skill differences, that’s a flag requiring model review.
Mandatory Requirement 5: Candidate Rights to Explanation
Candidates have the right to request an explanation of decisions made about them. For AI-assisted screening, this means: if a candidate requests to know why they weren’t advanced, you must be able to provide a meaningful explanation of the criteria applied. “The AI scored you below threshold” is not a compliant explanation. “Your application scored below our threshold for [specific criteria] based on the criteria documented in our hiring process” begins to meet the standard.
Implementation Timeline
Already required (as of August 2024): Disclosure to candidates that AI is used in screening.
Required by August 2026: Full risk assessment documentation, bias testing logs, human oversight documentation, candidate explanation procedures.
Ongoing: Quarterly bias audits, documentation updates when scoring models change, incident logging when AI errors affect candidate outcomes.
Building the Compliance Layer in Make.com and Keap
The compliance infrastructure doesn’t require separate systems — it layers onto the automation infrastructure you’re already building:
- Make.com audit logging: configure every AI scoring scenario to log inputs and outputs to a compliance record in Airtable or a dedicated Keap field
- Keap candidate records: add a compliance note field that captures which scoring model version was applied and when
- Bias audit automation: Make.com runs quarterly exports of scored candidates with outcome data for bias review
- Disclosure automation: the application intake form includes AI use disclosure before resume submission
Expert Take
HR teams that treat EU AI Act compliance as a separate compliance project are making this harder than it needs to be. The documentation requirements are really just good practice documentation for any AI system: what criteria are you using, how are you testing for bias, and who makes the final decision? If you can answer those questions clearly, you’re 80% of the way to compliance. The remaining 20% is making sure the answers are in writing and regularly updated.
FAQ
Does the EU AI Act apply to US companies recruiting EU candidates?
Yes. The Act applies based on where the candidate is located, not where the employer is headquartered. US companies using AI to screen candidates based in the EU are subject to the Act’s requirements for those candidates.
Are all AI-powered ATS features considered high-risk under the EU AI Act?
AI features that directly influence hiring decisions — scoring, ranking, shortlisting — are high-risk. ATS workflow features that track stage progression without AI scoring are not. Check your ATS vendor’s documentation for their EU AI Act compliance status for specific features.
What’s the penalty for non-compliance?
Fines for using prohibited AI practices: up to 7% of global annual revenue. Fines for non-compliance with high-risk AI obligations: up to 3% of global annual revenue. These are maximum figures — actual penalties scale with violation severity.
How often does the bias audit need to happen?
The EU AI Act requires “regular” monitoring. Current guidance interprets this as quarterly for actively used high-risk systems. If your recruitment AI processes more than 1,000 candidates per quarter, consider monthly reviews to catch disparate impact issues earlier.
]]>
