AI in hiring and HR: the rules are stricter here
Why employment uses of AI are treated as high-risk, what that means for a small business, and where AI can still help in recruitment safely.
The short answer
Employment is one of the areas the AI Act treats as high-risk. Systems intended for recruitment or selection, in particular for targeting job advertisements, analysing and filtering applications and evaluating candidates, and systems used for decisions on promotion and termination, task allocation based on behaviour or personal traits, and monitoring and evaluating performance, all fall within the high-risk category. For a deployer that brings obligations: use the system according to its instructions, assign human oversight to people with the competence, training and authority to exercise it, monitor operation and suspend use if a risk appears, keep the logs the system generates, and inform workers and their representatives before putting such a system into use. Data protection adds a second layer, including a basis, an impact assessment in most cases, transparency to candidates, and the restrictions on solely automated decisions producing significant effects. Emotion recognition in the workplace is prohibited with narrow exceptions. For a small business the sensible line is to keep AI out of selection and use it for the administration around hiring instead.
What is high-risk and what is not
| Use | Classification | Position for a small business |
|---|---|---|
| Filtering, ranking or scoring applicants | High-risk | Avoid; or treat as a full compliance project |
| Targeting job advertisements | High-risk | Care with platform tools that do this automatically |
| Automated assessment or testing of candidates | High-risk | Avoid unless properly governed |
| Promotion, termination and task allocation decisions | High-risk | Human decisions with documented criteria |
| Performance monitoring and evaluation | High-risk | Legal advice and consultation first |
| Emotion recognition in the workplace | Prohibited, with narrow exceptions | Do not |
| Drafting job descriptions and adverts | Minimal | Useful; review for biased language |
| Scheduling interviews and communication | Minimal | Useful; saves real time |
| Transcription and structured interview notes | Minimal, with data protection care | Useful; interviewers assess |
| Summarising a candidate’s own submitted material for the panel | Borderline; keep supportive | Panel reads the source |
| Onboarding administration | Minimal | Useful |
Where AI helps safely in hiring
- Drafting job descriptions and adverts, reviewed for language that deters groups unnecessarily.
- Answering candidate questions about the process, with disclosure that it is automated.
- Scheduling interviews across calendars, with reminders.
- Transcribing interviews and producing structured notes against the criteria, for the panel to review.
- Drafting candidate communication, including rejections, for a person to review and send.
- Summarising the process for record keeping and reporting.
- Checking your own criteria for consistency across applicants, as an audit rather than a decision.
Our position
We advise clients to keep AI out of candidate selection. The obligations are substantial, the bias risk is real and difficult to test at small volumes, the consequences of getting it wrong reach individuals’ livelihoods, and the efficiency gain over structured human screening is modest for the number of applications a small business receives. The administration around hiring, on the other hand, consumes real hours and carries almost no risk, which is where we help clients apply it.
What this means for you
Employment uses of AI, screening, selection, promotion, termination, task allocation and monitoring, are high-risk, with deployer obligations including instructions, real human oversight, monitoring, logs and informing workers, alongside data protection requirements. Emotion recognition at work is prohibited with narrow exceptions. Keep AI out of selection, use it for the administration around hiring, and check what your HR software’s AI features are already doing. This is general information rather than legal advice; employment AI warrants qualified input.
Frequently asked questions
Can we use AI to screen CVs?
Using AI to filter, rank or score applicants is a high-risk use with substantial obligations for the deployer, and it raises discrimination and data protection risks that are difficult for a small business to manage well. Our position is to avoid it: use structured criteria applied by people, and let AI help with the administration around the process. If you do proceed, treat it as a compliance project with legal input, human oversight that is real, logging, monitoring and information to applicants.
What about AI note-taking in interviews?
Transcription and structured notes for the interviewers to review are administrative support rather than selection, provided the interviewers make the assessment and the notes are treated as candidate personal data with a basis, transparency, security and retention. Inform candidates before recording, get any consent required in your jurisdiction for recording, and do not let a generated summary become the decision.
Is monitoring employees with AI allowed?
Worker monitoring uses are high-risk under the Act, and separately face strict data protection limits, works council involvement in many European countries, and employment law constraints. Emotion recognition in the workplace is among the prohibited practices with narrow exceptions. A small business should treat any monitoring proposal as requiring legal advice and employee representative consultation before it is built, not after.
Sources
- EUR-Lex: Regulation (EU) 2024/1689, Annex III (accessed 2026-09-14)
- European Commission: AI Act (accessed 2026-09-12)