# EU AI Act Annex III and Recruitment: What Is Actually High-Risk

What is high-risk under Annex III of the EU AI Act in recruitment, what is not, and why the deadline moved to 2 December 2027 while Article 50 went live.

Canonical: https://recruitmentads.com/resources/guides/eu-ai-act-recruitment

[← Back to home](https://recruitmentads.com/)

Two things changed in the eight days before this page was written, and they moved in opposite directions.

Regulation (EU) 2026/1744 entered into force on 27 July 2026 and pushed the Annex III high-risk regime (the part that covers recruitment) from 2 August 2026 to 2 December 2027. It did not touch Article 50. Transparency obligations for AI-generated content applied on schedule on 2 August 2026.

So the obligation the recruitment market has been bracing for is sixteen months away, and the obligation almost nobody is discussing is already binding. Most published guidance on AI and hiring still states the old date.

## The dates, as they stand today

| Date            | What applies                                                                                                          | Status   |
| --------------- | --------------------------------------------------------------------------------------------------------------------- | -------- |
| 2 February 2025 | Article 5 prohibitions and Article 4 AI literacy                                                                      | In force |
| 2 August 2025   | General-purpose AI, governance, and the Article 99 penalty regime                                                     | In force |
| 2 August 2026   | Article 50 transparency for AI-generated and manipulated content                                                      | In force |
| 2 December 2026 | End of the transitional period for Art. 50(2) marking of generative systems placed on the market before 2 August 2026 | Pending  |
| 2 December 2027 | Annex III high-risk, including employment and recruitment (moved from 2 August 2026)                                  | Pending  |
| 2 August 2028   | Annex I embedded-product high-risk (moved from 2 August 2027)                                                         | Pending  |

Source: Regulation (EU) 2024/1689 Art. 113, as amended by Regulation (EU) 2026/1744.

Operative law

## What Annex III actually covers in recruitment

Start with the text, because a lot of the confusion comes from paraphrase. Annex III point 4(a) covers _“AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements”_, and goes on to name analysing and filtering job applications and evaluating candidates. Point 4(b) covers AI used to make decisions on terms of the working relationship, promotion and termination, to allocate tasks, and to monitor and evaluate performance and behaviour.

Systems inside Annex III are high-risk by default under Article 6(2). So the honest list of what is high-risk in recruitment is not short, and this page is not going to pretend otherwise:

- **CV screening and application filtering** where the system applies evaluative weight.
- **Candidate scoring, matching and ranking**, including suitability scores and shortlisting.
- **Candidate evaluation**: assessments, structured scoring, automated interview grading.
- **Targeted placement of job advertisements**, where an algorithm decides which people see the vacancy.
- **Promotion, pay and termination decisions**, and anything that materially feeds them.
- **Task allocation** based on individual behaviour or personal traits.
- **Monitoring and evaluation of performance and behaviour** of people at work.

If your tooling does any of those, the rest of this page will not help you avoid the high-risk regime, and you should be planning for December 2027 rather than looking for an exit. What follows is about the one category that is routinely swept in and does not belong there.

Draft guidance

## Why “targeted job advertisements” is not “AI-made job ads”

The phrase “place targeted job advertisements” in point 4(a) is doing a specific job, and on 19 May 2026 the Commission published draft guidelines on the classification of high-risk AI systems that explain which one. The Annex III volume runs to 148 pages of worked examples. Targeted consultation closed on 23 July 2026 and the final text is expected around the end of 2026.

The relevant passage explains the point in terms of advertisements _“algorithmically tailored to reach certain groups of individuals”_, because that determines who becomes aware of a vacancy and who is encouraged to apply. The mischief is **audience determination**. Not asset creation. Generating a picture, a script or a headline does not decide who sees the job.

The guidelines then say it directly. Employer branding and generic company advertising _“which do not in practice relate to a vacancy, fall outside the use case listed in point 4(a)”_. Contextual placement (choosing a website or a location rather than identified people or groups) is treated as outside the point too.

**The counter-argument, stated properly.** Para. (245) says the activity must relate to or impact the substance of the recruitment process, and lists preparatory steps including “special advertising”. A footnote in the same document warns that job advertisements can strongly influence who succeeds, especially where they set out required qualifications, and that drafting them from biased data can increase discrimination risk. That is a real argument, and it lands on vacancy-specific creative whose imagery or wording is derived from historical hiring data. A generic employer-brand film is comfortably out. The middle of that spectrum is not settled by anything published.

Draft guidance

## The line the Commission drew through AI-written job descriptions

The clearest thing in the draft guidelines for anyone building or buying job-ad tooling is a worked example on AI-generated job descriptions, and it turns on one fact: **who supplies the criteria**.

A system that generates job descriptions from a list of tasks and a set of qualifications and skills _previously defined by a human recruiter_ is treated as performing a narrow procedural task under Article 6(3)(a), and is exempt. A system where _“the AI system itself generates the necessary qualifications and skills based on a high-level description”_, or which additionally evaluates CVs against the description it created, cannot rely on the filter and should be classified as high-risk.

That is a crisp, product-shaped test. “Here are the requirements, write me the ad” is on one side. “Here's a job title, work out what the role should require” is on the other. The framing test the guidelines use is whether the system impacts in substance career prospects or workers' rights.

Question 1

### What does the system actually do?

Pick the strongest thing it does. If more than one applies, take the highest on the list.

- Infers emotions of candidates or employeesScores enthusiasm, confidence, engagement or mood from face, voice or text during interviews, assessments or work.
- Infers protected attributes from biometric dataCategorises an individual from their face or voice to deduce race, beliefs, union membership, sex life or sexual orientation.
- Screens, scores, ranks, filters or shortlists peopleCV parsing with evaluative weight, matching scores, ranked candidate lists, knock-out questions.
- Decides who sees a job advertisementAudience selection, lookalike modelling, delivery optimisation for an employment ad.
- Feeds decisions about people already employedPromotion, pay, termination, task allocation, or monitoring of behaviour and performance.
- Produces the advertisement itselfWrites the copy, generates the images, cuts the video. It makes the asset; it does not choose who sees it.

Operative law

## The Article 6(3) derogation is not a zero-obligation state

Article 6(3) lets a provider conclude that an Annex III system is not high-risk where it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing human assessment, or performs a preparatory task; and where it does not pose a significant risk of harm.

Two things are widely missed about it.

**First, profiling closes it.** Article 6(3)'s final subparagraph provides that an Annex III system _“shall always be considered to be high-risk where the AI system performs profiling of natural persons”_. There is no balancing exercise and no assessment to write. If the system evaluates personal aspects of identified people, the filter is gone.

**Second, claiming it costs you paperwork.** Article 6(4) requires the provider to _“document its assessment before that system is placed on the market or put into service”_, and Article 49(2) requires registration in the EU database even where the provider concluded the system is _not_ high-risk. The derogation converts a heavy regime into a lighter documentation-and-registration regime. It does not produce nothing.

**One open point.** Whether Article 49(2) registration survived the Digital Omnibus unchanged is something we have not been able to confirm from the amending regulation itself. Secondary commentary says the proposal to remove it did not succeed. If the answer matters to you, verify it against the consolidated text rather than against this page.

All of this bites from 2 December 2027, not 2 August 2026. That includes the Article 6(4) documentation and the Article 49(2) registration.

Operative law

## Who carries the high-risk duty in a job-ad chain

Roles matter more than product categories here. A provider develops a system and places it on the market or puts it into service under its own name or trademark (Art. 3(3)). A deployer uses a system under its own authority (Art. 3(4)). The same campaign can involve four different companies in three different roles.

| Party                                   | Function                                 | Role                                                                                    | From             |
| --------------------------------------- | ---------------------------------------- | --------------------------------------------------------------------------------------- | ---------------- |
| Ad platform                             | Targeting and delivery of employment ads | **Provider** of an Annex III 4(a) system                                                | 2 Dec 2027       |
| Employer or agency running the campaign | Buys and directs the targeting           | **Deployer** of that high-risk system                                                   | 2 Dec 2027       |
| Creative generation tool                | Produces the asset from a human brief    | Not the Annex III 4(a) actor on the analysis above; **provider** for Art. 50(2) marking | Art. 50 live now |
| Employer publishing the creative        | Puts the asset in front of people        | **Deployer** for Art. 50(4) labelling                                                   | Live now         |

The practical consequence: the high-risk actor in the job-advertising chain is almost always the platform whose model decides who sees what. Content that tells employers they are carrying Annex III provider obligations because they used a generative tool to make a video has the roles wrong.

Operative law

## Article 50: the obligation that is already live

Article 50 sits outside the risk tiers entirely. It attaches to a function (conversational, generative, emotion-detecting or deepfake-producing) rather than to a risk classification, which is why the Digital Omnibus deferral missed it. It applied on 2 August 2026.

Two duties matter for recruitment marketing.

**Article 50(2), on providers.** Outputs of a generative system must be _“marked in a machine-readable format and detectable as artificially generated or manipulated”_. Systems placed on the market before 2 August 2026 have a transitional period to 2 December 2026. That grace is provider-side, marking-only, and legacy-only.

**Article 50(4), on deployers.** Whoever publishes a deep fake must disclose that the content is artificially generated or manipulated. There is **no transitional period** for this one. If you are an employer or an agency publishing AI-generated creative in the EU, the duty is on you today.

Two findings from the Commission's Article 50 guidelines of 20 July 2026 tend to surprise people. First, the deep-fake definition is read broadly enough to cover realistic AI-generated avatars and personas: a photorealistic presenter who is nobody in particular still counts. Second, and more operationally, _“deployers cannot rely on the machine-readable marking embedded in the content by the provider under Article 50(2)”_, because it is not clear and distinguishable to a person. Machine marking is the provider's duty. A visible label is the deployer's, and it is a separate one.

Operative law

## Article 4 AI literacy: in force since February 2025, and it binds deployers

Article 4 has applied to providers _and deployers_ since 2 February 2025. It is the oldest live obligation in this whole area and it is the one most recruitment teams have never been told about, because it does not carry a headline penalty tier.

The Digital Omnibus softened it rather than removing it. As amended, providers and deployers must _“take measures to support the development of AI literacy”_ of their staff and others operating AI systems on their behalf, with an express statement that this _“does not require providers or deployers to guarantee any specific level of AI literacy of any individual”_. The Commission is also tasked with publishing practical compliance examples.

That shifts it from an outcome duty to an effort duty, which has a practical implication: the evidence of the measure _is_ the compliance. A dated, role-appropriate briefing for whoever operates the tool (what it does, what it does not do, what has to be labelled, when to escalate) is the deliverable. Note that the AI Act text still displayed on some popular reference sites is the pre-amendment wording; check EUR-Lex for the consolidated position.

Regulator guidance

## The prohibitions that already touch hiring

Article 5's bans have applied since 2 February 2025 and carry the top penalty tier: up to €35m or 7% of worldwide annual turnover, whichever is higher. Two are directly relevant to recruitment, and one is widely misread.

**Emotion recognition in the workplace (Art. 5(1)(f)).** Inferring emotions of a natural person in the workplace is prohibited outside medical and safety purposes. The Commission's guidelines on prohibited practices read “workplace” to extend to _“candidates during the selection and hiring process”_, and give emotion recognition during recruitment as a prohibited example, along with inferring emotions from voice and imagery on video calls. Inferring customers' emotions in a call centre is not caught. If a video-interview or assessment vendor scores enthusiasm, confidence or engagement from face or voice, that is not a high-risk system to be documented; it is a prohibited one.

**Biometric categorisation to infer protected attributes (Art. 5(1)(g)).** Categorising individuals from their biometric data to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation is prohibited. There is a carve-out for labelling or filtering lawfully acquired biometric datasets, but it is drafted around datasets, not around inference about an identified person.

**The one that is misread: untargeted scraping of facial images (Art. 5(1)(e)).** This prohibits creating or expanding _facial recognition databases_ through untargeted scraping. The prohibited-practices guidelines describe such a database as one capable of matching a face against a database of faces, and limit the prohibition to tools placed on the market for that specific purpose. A generative image model trained on scraped web images is not, without more, that thing. The real exposure for scraped training data is data-protection law, not Article 5. That is a distinction a lot of vendor content gets wrong in the alarming direction.

Contested / open

## Whether it reaches you at all

Article 2(1) catches providers placing systems on the Union market wherever they are established, deployers established or located in the Union, and providers and deployers in a third country _“where the output produced by the AI system is used in the Union”_. That third limb is the one that matters for UK and US employers.

The Commission's Article 50 guidelines read the deployer limb broadly, extending it to entities outside the Union that themselves foresee dissemination and use of the outputs in the Union, including by posting deep fakes on the globally accessible internet, with a limit where content reaches EU audiences through channels that are unforeseeable and outside the deployer's control.

Applied to recruitment: a US or UK employer running an AI-generated job ad aimed at EU-based candidates is caught. A geo-fenced domestic campaign that a VPN user happens to see is not. Whether a single EU viewer of a globally accessible careers page is enough is **genuinely unresolved**: Article 2(1)(c) says “is used”, Recital 22 says “intended to be used”, no guidance interprets the article directly and no court has construed it. Geo-fencing is a meaningful mitigation. Labelling by default is usually the cheaper answer than the argument.

The UK has no equivalent statute. It has not adopted the AI Act, has no cross-sector AI legislation in force, and continues to run the 2023 pro-innovation approach through existing regulators. The ICO is the one that has actually done work here: its _AI tools in recruitment_ audit outcomes report of 6 November 2024 audited developers of AI sourcing and screening tools, and its recommendations put weight on employers having oversight of their provider's compliance rather than only their own.

Regulator guidance

## Who enforces this, and the gap in the machinery

Penalties under Article 99: Article 5 breaches up to €35m or 7% of worldwide annual turnover, whichever is _higher_; most other obligations including Article 50 up to €15m or 3%, whichever is higher. For SMEs and start-ups, Article 99(6) inverts it: each cap is whichever of the euro figure and the percentage is _lower_. Adherence to an adequate code of practice is a mitigating factor in setting a fine.

The gap is national. Article 70 required Member States to designate notifying and market surveillance authorities by 2 August 2025, and the Digital Omnibus extended nothing about that deadline. The European Parliament's research service reported eight single points of contact out of twenty-seven as of March 2026. The Commission's own register of national market surveillance authorities was last updated on 26 September 2025, which makes the authoritative EU-level list of who enforces this nationally close to a year stale.

Germany moved: the KI-MIG implementing law has been in force since 29 July 2026, with the Bundesnetzagentur as central market surveillance authority and single point of contact on a residual basis, and specialised authorities retaining competence in their own fields. The Netherlands has not: the Uitvoeringswet AI-verordening went through internet consultation in spring 2026 and the Raad van State in July 2026, and had not been submitted to the Tweede Kamer at the time of writing.

The obligations bind everywhere. The apparatus to fine does not yet exist everywhere. For anyone operating across several Member States, that asymmetry is more operationally relevant than the headline penalty figures.

Contested / open

## What is genuinely unsettled

A page that tells you only the parts with clean answers is not useful for planning. Five things in this area are open, and the honest position on each is that nobody knows yet.

- **The guidelines are draft.** The classification guidelines of 19 May 2026 are the best available signal on Annex III point 4(a) and practitioners are relying on them, but consultation closed on 23 July 2026 and the final text could move.
- **Where employer branding stops.** Para. (251) puts branding outside the point where it does not in practice relate to a vacancy. Real campaigns run from always-on brand films that link to a vacancies page, through role-family campaigns, to single-vacancy ads. No guidance addresses the middle.
- **How far the deep-fake definition reaches.** The Commission reads it to cover wholly invented photorealistic people. That is an expansive reading of “existing persons” and no court has tested it. Until one does, the safe course is to label.
- **Whether Article 49(2) registration survived the Digital Omnibus.** It decides whether claiming the Article 6(3) filter still costs you an EU database entry.
- **Whether passive EU viewing triggers Article 2(1)(c).** The article says “is used”; the recital says “intended to be used”. Practitioner advice converges on assuming you are caught if your escape depends on a fine reading.

## How to classify a recruitment AI system, in six steps

1. ### Write down what the system does, function by function

   Not the product category, the functions. Classification under Annex III follows intended use. A tool sold as a creative suite that also ranks candidates is two systems for these purposes.

2. ### Check the prohibitions first

   Emotion inference in the workplace, including on candidates during selection, and biometric categorisation to infer protected attributes are prohibited under Article 5 and have been since 2 February 2025. Nothing later in the process fixes a system that fails here.

3. ### Test each function against Annex III points 4(a) and 4(b)

   Screening, ranking, evaluation, targeted advertisement placement, promotion and termination decisions, task allocation and worker monitoring are inside. Creative generation from human-supplied criteria is, on the Commission's draft guidelines, outside.

4. ### If you think a function is outside, check whether it profiles anyone

   Article 6(3)'s final subparagraph makes an Annex III system always high-risk where it profiles natural persons. That closes the filter with no balancing exercise available.

5. ### Document the Article 6(3) assessment before you rely on it

   Article 6(4) requires the assessment to be documented before the system is placed on the market or put into service, and Article 49(2) requires EU database registration even for a system self-assessed as not high-risk. Verify the current status of Article 49(2) against the consolidated text.

6. ### Deal with the obligations that are already live

   Article 4 AI literacy has applied since 2 February 2025 and binds deployers. Article 50 transparency applied on 2 August 2026, with the deployer labelling duty carrying no transitional period. Annex III high-risk is 2 December 2027.

## Questions people actually ask

### Is AI recruitment high-risk under the EU AI Act?

Some of it, and the boundary is precise. Annex III point 4(a) makes AI used for recruitment or selection high-risk, including CV screening, application filtering, candidate evaluation and the targeted placement of job advertisements. Point 4(b) covers promotion, termination, task allocation and worker monitoring. AI that generates advertising creative from criteria a human has supplied is, on the Commission's draft classification guidelines of 19 May 2026, outside point 4(a). These obligations apply from 2 December 2027, deferred from 2 August 2026 by Regulation (EU) 2026/1744.

### Are AI-generated job ads high-risk under Annex III?

Generating the creative asset is very probably not. The Commission's draft guidelines explain that point 4(a) covers targeted job advertisements because algorithmic tailoring determines who becomes aware of a vacancy. The mischief is audience determination, not asset creation. Para. (251) puts employer branding and generic company advertising that does not in practice relate to a vacancy outside the point expressly. The high-risk actor in a job-ad chain is normally the ad platform whose model selects the audience. The guidelines are draft, so document your Article 6(3) assessment rather than treating the question as closed.

### When do the EU AI Act's high-risk rules for recruitment apply?

2 December 2027. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and deferred the Annex III high-risk regime from 2 August 2026 to 2 December 2027 as an unconditional calendar date. Annex I embedded-product high-risk moved to 2 August 2028. Article 50 transparency was not deferred and applied on 2 August 2026.

### How does the EU AI Act affect recruitment practices?

Through three separate mechanisms with three separate dates. Article 5 prohibitions have applied since 2 February 2025 and ban emotion inference in the workplace (which the Commission reads to include candidates during selection) and biometric categorisation to infer protected attributes. Article 4 AI literacy has applied since the same date and binds deployers, not just vendors. Article 50 transparency applied on 2 August 2026 and requires visible disclosure of deep fakes by whoever publishes them. The high-risk regime covering screening, ranking and targeted job advertising follows on 2 December 2027.

### Does the EU AI Act cover CV screening?

Yes. Annex III point 4(a) names analysing and filtering job applications and evaluating candidates. The Commission's draft classification guidelines put systems producing suitability scores or assessing the compatibility of a candidate's profile inside the point. Purely descriptive handling (converting formats or standardising degree classifications without applying evaluative weight) can be a preparatory task under Article 6(3)(d). The dividing line is whether the system applies evaluative weight. Where it profiles individuals, Article 6(3) is unavailable outright.

### Is employer branding content covered by the AI Act's high-risk rules?

Not under Annex III point 4(a), on the Commission's draft guidelines: employer branding and generic company advertising that does not in practice relate to a vacancy falls outside the use case. Contextual placement based on site or location rather than identified people is also outside. Article 50 transparency and Article 4 AI literacy still apply, and both are already in force. The unsettled part is the middle of the spectrum: an always-on brand film linking to a live vacancies page is not the clean case the guidelines describe.

### Does claiming the Article 6(3) exemption mean I have no obligations?

No. Article 6(4) requires the provider to document its assessment before the system is placed on the market or put into service, and Article 49(2) requires registration in the EU database even where the provider concluded the system is not high-risk. The derogation converts a heavy regime into a lighter documentation-and-registration one. Whether Article 49(2) survived the Digital Omnibus unchanged should be verified against the consolidated text before you rely on either answer.

### Is AI emotion analysis allowed in video interviews?

No. Article 5(1)(f) prohibits using AI to infer emotions of a natural person in the workplace outside medical and safety purposes, and the Commission's guidelines on prohibited AI practices read workplace to apply to candidates during the selection and hiring process. Emotion recognition during recruitment is given as a prohibited example, as is inferring emotions from voice and imagery on video calls. This is the top penalty tier (up to €35m or 7% of worldwide annual turnover), and it has been in force since 2 February 2025.

### Who does the EU AI Act apply to?

Providers placing AI systems on the Union market wherever they are established; deployers established or located in the Union; and providers and deployers in a third country where the output produced by the system is used in the Union. In recruitment that means the vendor, the employer and the agency can each hold a different role in the same campaign: provider duties follow whoever places the system on the market under their own name, deployer duties follow whoever uses it under their own authority.

### Will the EU AI Act apply to the UK?

Not as domestic law. The UK has not adopted the AI Act and has no cross-sector AI statute in force; it continues to run the 2023 pro-innovation approach through existing regulators, principally the ICO and the ASA. But the AI Act's hook is output-based rather than establishment-based: a UK employer or agency is caught by Article 2(1)(c) where the output of its AI system is used in the Union, which includes running AI-generated job advertising aimed at EU-based candidates.

### What is the legal risk of using AI in recruitment?

It stacks by layer rather than arriving all at once. Prohibited practices under Article 5 (emotion inference on candidates, biometric categorisation) carry the top fine tier and bind now. Transparency duties under Article 50 bind now, with no transitional period for the deployer labelling duty. High-risk classification under Annex III arrives on 2 December 2027 for screening, ranking, evaluation and targeted job advertising. Underneath all of it sit data-protection law and non-discrimination law, which are not deferred and which regulate ad delivery and candidate processing today.

## Primary sources

- [Regulation (EU) 2024/1689 (AI Act), consolidated to 27 July 2026](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02024R1689-20260727)
- [Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 27 July 2026](https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng)
- [Draft Commission guidelines on the classification of high-risk AI systems, 19 May 2026](https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems). Annex III volume. Consultation closed 23 July 2026; final text expected end-2026.
- [Commission guidelines on Article 50 transparency obligations, C(2026) 5054, 20 July 2026](https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content)
- [Commission guidelines on prohibited AI practices, 4 February 2025](https://ec.europa.eu/newsroom/dae/redirection/document/112367)
- [Code of Practice on Transparency of AI-generated Content, final 10 June 2026](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content)
- [ICO, AI tools in recruitment: audit outcomes report, 6 November 2024](https://ico.org.uk/action-weve-taken/audits-and-overview-reports/2024/11/ai-tools-used-in-recruitment/)
- [Commission register of national market surveillance authorities](https://digital-strategy.ec.europa.eu/en/policies/market-surveillance-authorities-under-ai-act). Last updated 26 September 2025.

## Related

[Do you have to label an AI-generated job ad? (Article 50)](https://recruitmentads.com/resources/guides/ai-generated-recruitment-ads-disclosure)[Free tool: employee photo release form](https://recruitmentads.com/resources/employee-photo-release-form)[Recruitment ad tools, compared](https://recruitmentads.com/alternatives)
