10-day free trial
Get Started
Industry Trends

The EU AI Act's High-Risk Rules for HR AI Are Now in Force

HR Advisory Team3 min read
Abstract light-toned illustration of connected geometric checkpoints forming an orderly framework, symbolizing structured AI governance and oversight

The EU AI Act's high-risk obligations for employment-related AI are now active, and they apply to any employer with candidates or employees in the EU — regardless of where the company is headquartered. If your organization uses AI to screen resumes, rank candidates, influence promotion or termination decisions, or monitor employee performance and behavior, that system is now presumptively high-risk under the Act, and the obligations that come with that label are no longer a future compliance project.

What actually counts as "high-risk" HR AI

The Act draws the line around decisions that affect someone's access to work or the terms of their employment, not around the underlying technology. That includes:

  • AI used for recruitment or candidate sourcing, including targeted job ad placement
  • Tools that screen, filter, or rank applications and candidates
  • Systems that inform decisions on promotion, termination, or task allocation
  • AI used to monitor and evaluate employee performance or behavior

A tool doesn't need to be the final decision-maker to qualify — if it materially shapes a hiring or employment decision, it's in scope. That sweeps in a lot of HR tech that wasn't built with this kind of regulatory scrutiny in mind, including chatbots and assistants that surface candidate or performance information without being labeled as "the decision system."

The obligations, in plain terms

Six requirements do most of the work:

  • Risk management — a documented, ongoing process for identifying and mitigating risks the system could create, not a one-time checklist.
  • Data governance — traceable, quality-checked training and input data, with attention to bias in the populations the system was trained or tested on.
  • Technical documentation and logging — the system has to be able to show, after the fact, what it did and why.
  • Transparency to workers — employees and candidates (and, in many jurisdictions, works councils or employee representatives) need to be informed before an in-scope system is used on them, not after.
  • Human oversight — a real, informed override path, not a formality. The regulatory bar for "meaningful" oversight favors systems whose outputs are explainable enough for a reviewer to actually disagree with them.
  • Conformity assessment — a pre-deployment check that the system meets the above before it goes into production use on real candidates or employees.

Deployers carry obligations too — buying a compliant tool isn't the finish line

It's tempting to treat this as a vendor problem: get a compliant tool, move on. But the Act splits duties between the provider (the company that built or substantially modified the system) and the deployer (the employer using it). Deployer obligations don't disappear just because the underlying system is compliant — informing affected workers, keeping human oversight real in day-to-day use, watching for model drift, and pausing use if the system starts producing an unassessed risk are the employer's responsibility, continuously.

Where to start

Most HR teams haven't inventoried which of their tools are actually in scope. A practical first pass:

  1. List every system that touches recruitment, screening, promotion, task allocation, termination, or monitoring decisions.
  2. For each, determine whether your organization is acting as provider or deployer, since the obligations differ.
  3. Check whether each system can currently produce the documentation, audit logging, and worker-facing transparency the Act requires — and whether a human reviewer can see enough to genuinely override its output.

That inventory and gap analysis is exactly what a compliance-focused HR readiness review is built to surface before a regulator, works council, or plaintiff's attorney does. Eva HR Lab's SHRM-aligned evaluation is designed to help HR teams find these gaps, and Eva's broader platform is built around the same trust primitives the Act is asking for — source-grounded answers, role-based access, and audit logs — rather than governance bolted on after the fact. This kind of compliance work is a core part of any HR transformation plan going into 2027.

Frequently asked questions

Which HR AI systems does the EU AI Act classify as high-risk?

The Act classifies AI systems used for recruitment or selection (targeted job ads, screening or filtering applications, evaluating candidates), and AI used to make decisions affecting the terms of a work relationship, promotion, termination, task allocation, or performance and behavior monitoring, as high-risk. It applies to any employer whose employees or candidates are in the EU, not just EU-headquartered companies.

What do employers actually have to do differently now?

The core high-risk obligations are a documented risk-management process, data governance for the training and input data involved, technical documentation and record-keeping (logging), transparency to affected workers and their representatives before the system is used, meaningful human oversight rather than a rubber-stamp review, and a conformity assessment before deployment.

Does this only apply to AI vendors, or to the HR teams using the tools?

Both, with different obligations. Vendors that build or substantially modify the system carry provider-level duties (conformity assessment, technical documentation). Employers deploying it carry deployer-level duties: informing workers, ensuring human oversight in practice, monitoring for drift, and stopping use if the system creates a risk it wasn't assessed for. Buying a compliant tool doesn't discharge the deployer obligations.

What does 'meaningful human oversight' mean in practice for something like resume screening?

It means a person with the authority and information to override the AI's output actually reviews it, not that a human clicks a button after the system has already effectively decided. Regulators and courts have treated oversight as meaningful only when the reviewer can see why a recommendation was made and has a realistic path to disagree with it — which is why source-grounded, explainable outputs matter more under this rule than raw model accuracy.

How is this different from the general 'shadow AI' governance problem?

Shadow AI is about visibility — knowing which unsanctioned tools employees are already using. The EU AI Act is a specific legal obligation attached to sanctioned, in-scope systems your organization deploys on purpose for hiring, promotion, or monitoring decisions. A tool can be fully sanctioned and still be out of compliance if it lacks documentation, worker transparency, or a real human-oversight path.

Where should an HR team start if it hasn't assessed its AI tools yet?

Inventory every system touching recruitment, promotion, task allocation, termination, or monitoring decisions, confirm whether each one is provider- or deployer-classified for your organization, and check whether each can produce the documentation, logging, and worker-facing transparency the Act requires. Readiness and compliance-risk reviews built for this — like Eva HR Lab's SHRM-aligned evaluation — are meant to surface these gaps before a regulator or works council does.

See how Eva's source-grounded answers, access controls, and audit logging map to governed HR AI.

Visit the Trust Center
2026-09-18T23:31:39Z

Cookie preferences

We use necessary cookies to run the site. With your consent, we also use analytics, experience diagnostics, and marketing cookies to improve the site and measure campaigns.