COMPLIPATHDOC complipath.io/guides/eu-ai-act-hr-techRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Industry ·By Yobel Tzegai ·Updated 20 August 2026

Is HR software high-risk under the EU AI Act?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

HR software is mostly high-risk under the EU AI Act. AI for recruitment, selection and targeted job advertising, and AI behind promotion, termination, task allocation or performance monitoring, is high-risk under point 4 of Annex III — obligations that now apply from 2 December 2027, not 2 August 2026. Workplace emotion recognition is not high-risk. It is prohibited, and has been since 2 February 2025.

Quick answer

Which HR tools does point 4 of Annex III actually catch?

Point 4 of Annex III ("Employment, workers' management and access to self-employment") has two letters. In full:

(a) AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates;

(b) AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships.

Under Article 6(2), a system on this list is high-risk. Applied to a typical HR stack:

How to make and defend these calls: how to classify your AI system.

Is emotion analysis in video interviews high-risk or banned?

Banned. Article 5(1), first subparagraph, point (f) prohibits "the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions", except for medical or safety reasons. Scoring a candidate's enthusiasm, stress or confidence from video or voice is neither. The prohibition has applied since 2 February 2025 under Article 113, third paragraph, point (a) — untouched by the 2026 amendment, which delayed the high-risk regime but not this ban.

Three traps:

Article 99(3) attaches the top penalty tier: up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher. The full list of bans: prohibited AI practices.

The deadline has moved — where does that leave you?

The Regulation as a whole has applied since 2 August 2026 (Article 113, second paragraph), but the Chapter III obligations on Annex III systems now apply from 2 December 2027. Article 111(2) was re-anchored by the same amendment: it no longer names a fixed 2 August 2026, but "the date of application of Chapter III referred to in Article 113" — for an HR system, 2 December 2027. Two situations:

One limb of Article 111(2) did not move: its second sentence still requires providers and deployers of high-risk systems intended to be used by public authorities to comply by 2 August 2030 regardless.

The full obligation set is in the high-risk obligations guide; every date, in the EU AI Act timeline.

Who owes what — the vendor or the HR team?

The vendor is the provider. Article 16 requires meeting the Section 2 requirements, a quality management system (Article 17), conformity assessment before placing on the market — for points 2 to 8 of Annex III, internal control with no notified body (Article 43(2)) — the EU declaration of conformity, CE marking, and registration in the EU database (Article 49(1)).

The buying HR team is the deployer, and a CE mark discharges none of Article 26: use the system per its instructions (Article 26(1)), assign human oversight to people with the competence, training and authority to exercise it (Article 26(2)), keep input data relevant and representative where you control it (Article 26(4)), monitor operation and suspend use if a risk emerges (Article 26(5)), and retain the generated logs for at least six months (Article 26(6)).

One trap: white-labelling or substantially modifying a high-risk system makes you the provider under Article 25(1), with the full Article 16 load — see provider vs deployer.

What do you have to tell workers and candidates?

Before the tool goes live, not after. Under Article 26(7), before putting into service or using a high-risk AI system at the workplace, deployers who are employers "shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system". A monitoring or shift-allocation rollout therefore starts with the works council and the affected staff, and national worker-information rules add their own steps where they apply.

Candidates too: under Article 26(11), deployers of Annex III high-risk systems making or assisting decisions about natural persons must inform them — an applicant ranked by your screening tool has to be told.

What this means for you

If you're an HR-tech vendor (provider): any product doing screening, ranking, ad targeting or workforce evaluation needs the Article 16 set — conformity assessment, the declaration of conformity, CE marking, registration — in place by 2 December 2027: sixteen months more than you had, and that stack is not a quarter's work. One piece of it is not on that date. Article 49 sits in Chapter III, Section 5, which point (c) does not defer, so the Article 49(1) registration provision has applied since 2 August 2026 — what moves to 2 December 2027 is the Article 16, point (i) duty to comply with it. Start from a documented classification per system — Complipath's guided risk classification records the category, provisions and reasoning — and audit every emotion-adjacent feature against Article 5(1), first subparagraph, point (f).

If you're an HR team buying tools (deployer): inventory every AI-assisted HR tool, check each against points 4(a) and 4(b) of Annex III, and confirm nothing infers emotions. Map the Article 26 duties to named owners against the 2 December 2027 date, and plan the Article 26(7) information to workers before go-live. Deployer breaches sit in the Article 99(4) tier — up to €15 million or 3% of worldwide turnover, whichever is higher.

Is your HR system one of them?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Is AI recruitment software banned in the EU? No. Recruitment and selection AI is high-risk under point 4(a) of Annex III — lawful, but subject to provider and deployer obligations from 2 December 2027, a date moved back from 2 August 2026 by Regulation (EU) 2026/1744. Only Article 5 practices are banned outright; for HR that mainly means inferring emotions of workers or candidates.

Do the rules apply to HR tools we deployed before the deadline? Only after a change. Article 111(2), as amended, catches operators of high-risk systems placed on the market or put into service before the date Chapter III applies — 2 December 2027 for HR systems — only if those systems undergo significant design changes from that date. Public-authority systems must comply by 2 August 2030 regardless.

Do we have to tell employees before using AI monitoring? Yes. Article 26(7) requires employers, before putting a high-risk AI system into service at the workplace, to inform workers' representatives and the affected workers that they will be subject to it. Article 26(11) separately requires informing individuals — including job applicants — affected by its decisions.

What are the penalties for HR-tech non-compliance? Using or selling a prohibited practice such as workplace emotion recognition: up to €35 million or 7% of total worldwide annual turnover (Article 99(3)). Breaching provider obligations under Article 16 or deployer obligations under Article 26: up to €15 million or 3% (Article 99(4)).


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 5, 6, 16, 25, 26, 43, 49, 99, 111, 113 and Annex III, as amended by Regulation (EU) 2026/1744 (EUR-Lex), Article 1, points (39) and (40). Annex III itself was not amended. "Significant changes" under Article 111(2) is not settled by guidance or case law at the time of writing; edge-of-point-4 classification calls carry the same caveat.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.