EU AI Act and recruitment: what changes for small hiring teams
If you use AI anywhere in hiring, the EU AI Act applies to you as a deployer, even if you did not build the model. This page explains what that means in practice for a small company, without pretending to be legal advice. The short version: you can use AI, you cannot use it as an unexplained oracle.
Why recruitment is classified as high risk
The AI Act sorts uses of AI by the risk they pose to people's rights. Systems used for recruitment, selection, and the evaluation of candidates sit in the high-risk category, alongside things like access to education and essential services.
The logic is straightforward: a screening error does not just annoy someone, it removes access to work, and the person affected usually never learns it happened.
What is required of you as a deployer
Most of the heavy obligations fall on whoever provides the system. As the company using it, your responsibilities are narrower but real.
- •Human oversight: a person with the authority and the information to overrule the system's output.
- •Transparency: candidates should know an AI system is being used to evaluate their application.
- •Record keeping: keep the logs the system generates, so an evaluation can be reconstructed later.
- •Use it as intended: applying a screening tool to something it was not designed for moves responsibility onto you.
- •Input data quality: if you feed it criteria that are irrelevant or discriminatory, that is your decision, not the model's.
How this overlaps with the GDPR
The two regimes reinforce each other. The GDPR already gives candidates rights over their data and, under Article 22, protection against purely automated decisions with significant effects on them. Recruitment decisions qualify.
In practice, one design choice satisfies both: keep a person responsible for the decision and keep a record of how the evaluation was produced. Everything else is documentation.
Questions to ask any AI recruitment vendor
These five questions separate tools built for the European market from tools that will hand you their compliance problem.
- •Can I see the reasoning behind an individual score, months after the fact?
- •Is there a human confirmation step before a candidate is rejected, and is it enforced?
- •Where is candidate data stored and processed?
- •What exactly is logged, and can I export the log?
- •What happens to candidate data at the end of the retention period?
How Parthumanally is built for this
Every AI evaluation records what was assessed and against which criteria, and stays attached to the application. The shortlist requires human confirmation before it drives any decision, and the reasoning is written in language a candidate could be shown.
This is not an add-on module. It is the reason the product exists in the form it does, because a screening tool for Europe cannot be retrofitted with oversight after the fact.
Frequently asked questions
When does the EU AI Act apply to recruitment?
The Act's obligations phase in over time, with the high-risk requirements arriving after the prohibitions and general provisions. Since hiring records outlive the transition, the practical advice is to run compliant processes now rather than retrofitting logs and oversight later.
Can we reject candidates automatically?
Fully automated rejection with legal or similarly significant effects on a person is what both the GDPR and the AI Act push back against. Keep a person confirming the outcome. In small teams this costs very little, because the volume that reaches the decision point is small by design.
Do we have to tell candidates we use AI?
Yes, transparency towards the people being evaluated is a core requirement, and it is also the low-cost part. A clear line in your privacy notice and on the application page covers it.
Is this legal advice?
No. This page is a practical summary written for hiring teams. For obligations specific to your company, sector and jurisdiction, talk to a lawyer.
See what a compliant screening run looks like
The demo shows the reasoning, the logging and the human review step in place, on fictional candidate data.
See a demo