An HR lead and a colleague review a printed checklist, with an AI Act checklist: candidates informed and human oversight done, logs kept in progress
Playbook
→
Compliance

The EU AI Act and Your Recruiting Stack: A Deployer Checklist for 2026 and 2027

Recruitment sits in Annex III, so the duties land on you as deployer rather than on the vendor. The deadline moved in July 2026, which bought time and changed nothing about what has to be written down.

Julia Komkowski
Co-Founder & CTO
11
min read
Last updated:
August 24, 2026

Introduction

Your applicant tracking system gained a matching score last year. A sourcing tool ranks profiles. A job-board campaign targets an audience. None of that felt like deploying a high-risk AI system at the time, and all of it is named in the EU AI Act, in the text of Annex III rather than by implication.

This checklist is for the employer, because that is where the duties land. The vendor that built the model has obligations of its own, but the ones in this article follow the organisation that puts the system to use, and they do not transfer with a procurement contract. It covers what the Act names, what the July 2026 deferral did and did not change, the eight items worth having on file, and the two duties that were never deferred at all.

TL;DR

  • Recruitment is named explicitly. Annex III point 4(a) covers AI "intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates" (EU Artificial Intelligence Act, Annex III, Aug 2026).
  • The deadline moved. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and deferred the main obligations for standalone Annex III systems to 2 December 2027 (Hunton, Aug 2026).
  • Transparency did not move. Article 50 duties applied from 2 August 2026, and they cover telling people they are interacting with an AI system.
  • Deployer duties are specific: human oversight by people with "the necessary competence, training and authority", monitoring in operation, representative input data, and logs kept for at least six months (EU Artificial Intelligence Act, Art. 26, Aug 2026).
  • One duty commonly listed does not apply to you. The fundamental rights impact assessment under Article 27 falls on public bodies and private entities providing public services, not on an ordinary employer hiring for itself.
  • GDPR did not wait for any of this. Article 22 already restricts decisions based solely on automated processing, and it has applied since 2018 (EU GDPR, Art. 22, Aug 2026).

What does the Act actually name?

Recruitment, in the operative text rather than in a recital. Annex III point 4(a) reads:

"AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates"

EU Artificial Intelligence Act, Annex III, August 2026

Three activities, and most stacks do all three without anyone calling it AI. Targeted job advertising is a campaign setting. Filtering applications is a knock-out question or a ranking. Evaluating candidates is a matching score or an assessment result.

This is why the useful first step is an inventory rather than a policy. Go through what is already connected and ask, per tool, whether it places, filters or evaluates. LinkedIn's Apply Connect, for instance, returns real-time applications together with skills-match data (LinkedIn Talent Solutions, Feb 2026). SmartRecruiters documents an assessment ordering flow where a partner returns a result and score against an order identifier (SmartRecruiters Developers, Aug 2026). Neither is marketed as high-risk AI. Both produce an output that ranks a person.

What in a normal recruiting stack is actually in scope?

More than the tools with AI in the name, and you can identify them from vendor documentation rather than from guesswork. Take the three Annex III verbs one at a time.

Placing targeted job advertisements. Any campaign that selects an audience rather than publishing to everyone. This is the one most often missed, because it sits with whoever runs paid channels rather than with recruiting operations.

Analysing and filtering job applications. Screening questions with automatic knock-outs are the common case, and the structures involved are richer than teams assume. Indeed supports eleven screener question types including conditional and hierarchical logic (Indeed Partner Docs, Aug 2026), and StepStone supports branching questions (StepStone API knowledge base, Aug 2026). A branching question that ends in an automatic rejection is a filter, whatever the vendor calls it.

Evaluating candidates. Matching scores, assessment results, ranking. LinkedIn's Apply Connect returns skills-match data alongside the application (LinkedIn Talent Solutions, Feb 2026), and SmartRecruiters documents assessment results returned against an order identifier (SmartRecruiters Developers, Aug 2026).

Where those outputs land matters for the documentation as much as for the workflow. Personio accepts applications through a Recruiting API whose token is predefined per account (Personio Developer Hub, Aug 2026); a score that arrives as an attachment rather than a field cannot be reviewed, compared or audited later, which makes both the oversight duty and the monitoring duty harder to discharge than they need to be.

What did the July 2026 deferral change?

The date, and not much else. It is worth being precise, because the change is easy to over-read in both directions.

Regulation (EU) 2026/1744, the Digital Omnibus, entered into force on 27 July 2026. It deferred the main obligations for standalone Annex III high-risk systems, the category employment sits in, to 2 December 2027. Embedded Annex I systems move to 2 August 2028. Transparency obligations were not deferred and applied from 2 August 2026 (Hunton, Aug 2026).

ObligationApplies fromDeferred in July 2026?
Prohibited practices2 February 2025No
Governance and general-purpose AI2 August 2025No
Article 50 transparency2 August 2026No
Annex III high-risk, standalone, including employment2 December 2027Yes, from 2 August 2026
Annex I high-risk, embedded in regulated products2 August 2028Yes

One practical warning, because it cost us a day. Several widely cited summaries of the Act still show the pre-amendment dates. One heavily referenced site is stamped "last updated 1 August 2024" on its implementation-timeline page and still shows the superseded date on its Article 26 page, while a third page on the same domain carries the current one. Check the currency of any source you rely on for a date here, not only its authority.

What does the Act ask of you as deployer?

Named, specific things, and the wording matters because it decides who in your organisation has to be involved. Article 26 requires:

"Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support."

EU Artificial Intelligence Act, Article 26, August 2026

The same article requires monitoring the system in operation against its instructions for use and informing the provider where relevant, ensuring input data is relevant and sufficiently representative for the intended purpose, keeping system-generated logs for at least six months, and reporting serious incidents. There is also a workplace-specific step that has to happen before anything goes live:

"Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system."

EU Artificial Intelligence Act, Article 26, August 2026

Read that against a German works council and it stops looking like a communications task appended to a launch. It is a precondition.

Curious how it workswith your stack?

Book a demo
Book a demo
→ Magic-link setup
→ Field mapping included
→ Fast go-live

Which duty on most checklists does not apply to you?

The fundamental rights impact assessment. It appears on nearly every AI Act checklist aimed at employers, and for an ordinary private employer hiring for itself, Article 27 does not require one.

Article 27 places the obligation on deployers that are bodies governed by public law, or private entities providing public services, and on deployers of the systems in Annex III points 5(b) and 5(c), meaning creditworthiness and life or health insurance pricing. Employment is point 4. The assessment itself covers the deployer's processes, the period and frequency of use, the categories of people affected, the specific risks of harm, human oversight measures, and what happens if a risk materialises (EU Artificial Intelligence Act, Art. 27, Aug 2026).

Two qualifications before anyone deletes the work item. If you are a public-sector employer or provide public services, it does apply. And the content of a fundamental rights impact assessment is a reasonable structure for the risk documentation Article 26 does require, so the work is rarely wasted. What differs is the legal obligation, not the usefulness.

What was never deferred, and never depended on the Act?

Two things, and both apply to recruiting today.

Article 50 transparency. Where a system interacts with people, they have to be told, "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect", and the information has to arrive "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure" (EU Artificial Intelligence Act, Art. 50, Aug 2026). A conversational apply flow or a screening chatbot is squarely in scope, and this date did not move.

GDPR Article 22, which has applied since 2018 and is stricter than most recruiting teams assume:

"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."

EU GDPR, Article 22, August 2026

An automatic rejection on a knock-out question is a decision based solely on automated processing. The exceptions are narrow: contractual necessity, authorisation in law, or explicit consent. Where one of them applies, the controller must still provide a route to human intervention, a chance for the candidate to express a view, and the ability to contest the decision. Erasure duties run alongside: Article 17 requires the controller to erase without undue delay on any of six grounds (EU GDPR, Art. 17, Aug 2026).

Where does the documentation actually come from?

Mostly from the integration. Doing it while a connection is being built costs a fraction of reconstructing it later.

Three of the eight items below are produced as a by-product of connecting a system properly. The inventory falls out of listing what is connected. The log retention is a property of whatever moves the data. A connection that does not record what was sent and what came back cannot produce six months of logs after the fact. The representative-input-data statement describes what actually crosses the boundary, and a field mapping already requires that document.

The remaining five are organisational: naming the oversight person, writing down their authority, informing workers' representatives, drafting candidate-facing disclosure, and defining the human-review route. None of those needs a vendor, and none of them gets easier by waiting. The deferral to December 2027 is time to do this deliberately rather than time to postpone starting.

The checklist

Eight items. Most are documentation you can produce this quarter, and every one of them is easier to write while a system is being connected than to reconstruct afterwards.

#ItemWhere it comes from
1An inventory of every tool that places, filters or evaluates, including features inside your ATSAnnex III 4(a)
2A named person exercising oversight, with their competence and authority written downArticle 26
3A monitoring routine, and a record of what you did with what it showedArticle 26
4A statement that input data is relevant and representative for how you use the systemArticle 26
5Logs retained for at least six monthsArticle 26
6Evidence that workers' representatives were informed before useArticle 26
7Candidate-facing disclosure wherever a system interacts with themArticle 50
8A human-review route wherever a decision is effectively automaticGDPR Article 22

Start with item 1, which is also the item people skip because it feels administrative. Every other item is impossible to complete without it, and it is the one most likely to surprise you. The AI in a recruiting stack usually sits inside tools bought for other reasons.

Where a connection moves candidate data between systems, the documentation and the integration are the same project. A connection you can describe is a compliance artefact as much as a technical one: what crosses, on what trigger, held for how long. A candidate record that stays current is the same document from the other side, and what comes back afterwards is what makes monitoring possible rather than theoretical.

What to do next

Three steps, in order:

  1. Inventory before policy. List every tool touching candidates and mark each one places, filters, evaluates, or none. An hour with the list of what is connected gets you further than a week of drafting.
  2. Name the oversight person now. Not a team, a person, with the authority to override an output. Article 26 asks for competence and authority together, and the second is the one that is usually missing.
  3. Check your dates against a current source. Several widely cited AI Act summaries still show the pre-July-2026 timeline. Confirm the date before you plan around it.

If you would like a second pair of eyes on which of your connected tools fall inside Annex III, a conversation with our team is a reasonable place to start. For the legal position itself, ask counsel rather than a vendor.

FAQ

Frequently asked questions

Common questions from teams running plays like this one. If your situation is different, our full FAQ covers the edge cases, or just reach out.

Does the EU AI Act apply to ordinary recruiting tools?
It applies where a system places targeted job advertisements, analyses and filters applications, or evaluates candidates. Annex III names those three activities directly. Most stacks do all three through features bought for other reasons, so an inventory usually surprises the team running it.
Did the deadline really move to December 2027?
For standalone Annex III high-risk systems, yes. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and moved those obligations to 2 December 2027. Most transparency duties under Article 50 still applied from 2 August 2026, with a short grace period only for marking AI-generated content, so nothing was postponed wholesale.
Do we need a fundamental rights impact assessment?
Not as a private employer hiring for yourself. Article 27 applies to public bodies, private entities providing public services, and deployers of creditworthiness and insurance-pricing systems. Employment is a different Annex III point. Public-sector employers are in scope, and the structure remains useful documentation regardless.
Whose obligation is this, ours or the vendor's?
Both, in different roles. Providers have duties for what they build; deployers have duties for how they use it. The deployer duties follow the employer and do not transfer through a procurement contract, so vendor documentation supports your compliance without replacing it.
Does GDPR already cover automated rejections?
Yes, since 2018. Article 22 gives a right not to be subject to decisions based solely on automated processing with significant effects. An automatic knock-out rejection qualifies. Where an exception applies, the candidate must still get human intervention, a chance to respond, and a route to contest.
When do we have to tell the works council?
Before the system is put into service. Article 26 requires employers to inform workers' representatives and affected workers before use at the workplace. Treat it as a launch precondition rather than a communications task, particularly in Germany where existing co-determination rights already apply.
How long do we have to keep logs?
At least six months, where the logs are under your control, unless other law requires longer. This is a design requirement rather than a paperwork one: a connection that does not record what was sent and what came back cannot produce those logs after the fact.

Can't find your answer? Explore more on our detailed FAQ Page.

Your integrations.Managed by us.Live in minutes.

Syncs
Jobs
Cleaner
Out
→
Flows
Applications
Faster
In

No engineering backlog. No manual data handling. Just a working connection between your tools.

Team memberTeam member
Book a demo
Book a demo
Personio Logo
SAP SuccessFactors Logo
Workday Logo
Greenhouse Logo
softgarden Logo
d.vinci Logo
StepStone Logo
Indeed Logo
LinkedIn Logo
XING Logo
Bundesagentur für Arbeit Logo
Jobware Logo
1
Select ATS
2
Enter ATS credentials
3
Go live
Fast go-live