AI Act · Employment
AI in hiring under the EU AI Act: who supervises you, by country
The Regulation is identical in every member state. The regulator changes at every border — and it is rarely the one people prepare for.
Recruitment screening is the most common high-risk AI deployment that organisations do not recognise as one. It arrives as a feature of an applicant tracking system, procured by HR, and nobody files it anywhere.
The Act is unambiguous that it is in scope. What is not obvious — and what no tracker sets out — is who turns up.
What Annex III actually covers
Point 4 has two limbs, and the second is the one that catches people.
4(a) — AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates.
4(b) — AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships.
Read 4(b) again with your own systems in mind. Task allocation based on individual behaviour. Monitoring and evaluating performance. That is workforce management, shift scheduling, productivity analytics and performance scoring — none of which anyone calls "AI hiring". An organisation that never uses AI to recruit can be squarely in scope through 4(b) alone.
One category sits outside this entirely and arrived earlier. Emotion inference in the workplace is a prohibited practice, not a high-risk one, and prohibitions have applied since 2 February 2025. High-risk obligations arrive on 2 December 2027 for stand-alone systems and 2 August 2028 for embedded ones.
Six countries, six kinds of regulator
Same Regulation. Same Annex III category. Six different institutions, each with a different professional instinct.
| Country | Who supervises workplace AI | Kind of body |
|---|---|---|
| France | CNIL — holds employment within its broad scope, with exclusive competence over workplace emotion inference | Privacy regulator |
| Netherlands | AP — recruitment sits in its share of high-risk systems, alongside education and lending | Privacy regulator |
| Ireland | Workplace Relations Commission — but only for certain prohibited workplace practices, emotion inference named expressly | Employment body |
| Spain | AESIA — employment was deliberately not carved out to the AEPD, which got borders and biometrics | Purpose-built AI agency |
| Italy | ACN, plus a national duty for workers to be told AI is in use | Cybersecurity agency |
| Germany | Bundesnetzagentur, by elimination — BaFin takes financial AI and an independent chamber takes law enforcement and justice | Engineering regulator |
Two of those come with a caveat worth stating plainly. Ireland's WRC publishes a narrower scope than its designation suggests — prohibited practices in the workplace, not the whole of high-risk recruitment, and the Data Protection Commission remains designated for fundamental rights in personal data. Germany's allocation is inferred: no source consulted assigns employment to the Bundesnetzagentur expressly; it is where the category lands once the other three German authorities' scopes are excluded.
Why the kind of regulator matters more than its name
A supervisor's first question comes from its professional history, and it decides what your documentation has to be built to survive.
- A privacy regulator asks about the individual. What was decided, on what basis, what the person was told, what recourse they had. It will read the AI Act alongside its existing doctrine on automated decision-making rather than as a separate regime. A technically impeccable system that cannot explain one rejection in plain language is in a weak position.
- An engineering regulator asks whether the system meets spec. Conformity, technical documentation, the declared intended purpose, whether behaviour matches it.
- A cybersecurity agency asks who could reach it. Access paths, permissions, authentication, and what the logs show. An inspection looks more like a security audit than a paper review.
- An employment body asks about the worker. Dignity, consultation, whether the practice is one the law permits at all.
- A purpose-built AI agency asks all of it, and in Spain's case has already published guidance derived from twelve real high-risk systems that went through its sandbox.
The multinational problem in one line. One applicant-screening system, deployed across France, Ireland and Italy, answers to a privacy lawyer, an employment adjudicator and a cyber inspector. A group policy written from any one of those misroutes in the other two — not because the obligations differ, but because the evidence each body finds persuasive does.
What you owe regardless of country
Article 26 binds the deployer — the organisation using the system — not only the vendor that built it. Your supplier's conformity does not discharge it and no contract reassigns it. Three duties matter most in an employment context.
Tell the workforce, before you switch it on
Article 26(7) requires deployers who are employers to inform workers' representatives and the affected workers, before putting a high-risk system into service at the workplace, that they will be subject to it, following applicable information procedures.
This is the obligation most often missed, because it is owed to people rather than to a regulator, so nothing prompts it. It is also the cheapest to satisfy and the most conspicuous to have skipped.
Keep six months of logs
Article 26(6) requires the logs the system generates automatically to be kept for a period appropriate to the purpose, and at least six months. Logs not kept cannot be reconstructed, so a system needs to be running and logging correctly by roughly mid-2027 to have a compliant record on the first day.
Know which systems you actually have
Every obligation above presumes you can name the systems. Screening tools arrive inside HR platforms, scheduling tools inside workforce software, scoring inside analytics dashboards. None of them announce themselves as high-risk AI.
Spain noticed this from an unusual angle: its draft AI law tells its own public administration to inventory every AI system, not only the high-risk ones, and classify afterwards. That inverts the order almost everyone else is working in, and it is the right way round — you cannot triage an estate you have not enumerated, and a system nobody listed is never classified as anything.
What to do now
- Inventory first, classify second. Start with every system that touches hiring, scheduling, task allocation, monitoring or performance — including features inside tools you bought for another purpose.
- Check 4(b) before you conclude you are out of scope. "We do not use AI to hire" is not an answer to task allocation and performance monitoring.
- Stop any workplace emotion inference now. It is prohibited, not high-risk, and it has been since February 2025. There is no 2027 runway on it.
- Write the Article 26(7) notice. One document, owed to your workforce, needed before the system goes live.
- Find out which regulator you face in each country you operate in, and write your documentation for the one whose questions are hardest for you — usually the cyber agency if your evidence is thin on access and logs, usually the privacy regulator if it is thin on explaining a decision.
- Turn logging on now, so the six-month record exists when it is first required.
Questions
Is AI used in recruitment high-risk under the EU AI Act?
Yes. Annex III point 4(a) covers AI intended for the recruitment or selection of natural persons, and names targeted job advertisements, analysing and filtering applications, and evaluating candidates. Point 4(b) goes further, covering decisions on terms of work, promotion and termination, task allocation based on individual behaviour or traits, and monitoring and evaluating performance and behaviour. An organisation that never uses AI to hire can still be in scope through 4(b).
Which regulator supervises AI hiring in my country?
It depends where you are, and the answer is not intuitive. France and the Netherlands give it to the data protection authority. Spain gives it to AESIA, a purpose-built AI agency, having deliberately left employment out of the privacy regulator's slice. Ireland's Workplace Relations Commission covers prohibited workplace practices such as emotion inference, not the whole of high-risk recruitment. Italy supervises through the national cybersecurity agency. In Germany it falls to the Bundesnetzagentur by elimination rather than express allocation.
Do I have to tell staff that an AI system is being used?
Yes. Article 26(7) requires deployers who are employers to inform workers' representatives and the affected workers, before putting a high-risk AI system into service at the workplace, that they will be subject to it. This is a duty owed to the workforce rather than a filing owed to a regulator, and Italy's Law 132/2025 adds a national right for workers to know when AI is in use.
When do the obligations start?
2 December 2027 for stand-alone high-risk systems and 2 August 2028 for those embedded in regulated products, under Regulation (EU) 2026/1744. The earlier date of 2 August 2026 that still circulates never took effect. Prohibitions have applied since 2 February 2025, which matters here because workplace emotion inference is a prohibited practice, not a high-risk one.
What does the six-month log requirement mean in practice?
Article 26(6) requires deployers to keep the logs the system generates automatically for a period appropriate to its purpose and at least six months. Logs not kept cannot be reconstructed afterwards, so a system needs to be running and logging correctly by roughly mid-2027 to have a compliant record on the first day the obligations bind.
Related
Agent Trust Cloud
We publish this because the deployer side of the AI Act is widely misread, and employment is where the gap between "we are not really an AI company" and Annex III is widest. Agent Trust Cloud is building a control plane for AI agents — identity, policy, evidence. You can start with a free Discover workspace or a subscription plan today, or begin with a fixed-scope assessment of the agents and machine identities you already have: what each can reach, which permission combinations are dangerous together, delivered as a written report and a scored register you keep.