Back

The EU AI Act Just Made Your Hiring AI Stack High-Risk. Most Vendors Haven't Told You.

The EU AI Act's high-risk provisions are now in effect, and AI tools used in recruitment are explicitly in scope. Most hiring teams don't know the compliance burden falls on them — not their vendor. Here's what that means and what to do about it.

Ethical AI6 min read
The EU AI Act Just Made Your Hiring AI Stack High-Risk. Most Vendors Haven't Told You.

The EU AI Act's high-risk provisions are now in full effect for employment systems, and AI tools used in candidate screening are explicitly in scope [1]. If your company uses AI to filter, assess, or rank job applicants, you are — today — a deployer of a high-risk AI system under EU law. Not your vendor. You.

Most hiring teams found out about this from a compliance newsletter, not from the companies selling them software. That's a significant asymmetry to understand before you run your next intake campaign.

What "High-Risk" Means Under the AI Act

Annex III of the EU AI Act explicitly lists AI systems used in recruitment and HR management — including tools that sort and filter job applications, assess candidates, and evaluate performance or promotions — as high-risk AI systems. The classification isn't conditional on how much you use the tool or how much it influences decisions. If you're using it, the classification applies.

High-risk classification creates real obligations. Deploying companies must conduct conformity assessments before using the system and document them. Candidates must receive disclosure that AI is involved in processing their application and must have a right to request human review of AI-based decisions. The system must generate logs of its decisions retained for audit — the Act specifies at least three years [2]. A human oversight mechanism must be in place that's capable of actually overriding AI decisions, not just rubber-stamping them.

The liability structure is the part most companies are underestimating: these obligations fall on the company deploying the AI, not the vendor supplying it. A vendor can sell you a non-compliant system without automatically becoming liable. The due diligence responsibility sits with the buyer. Several of the largest ATS and screening vendors in the market have not published conformity documentation for their AI components. That omission doesn't immunize them from long-term scrutiny, but it does mean their customers are carrying the near-term risk.

The Gap Between What Vendors Market and What Compliance Requires

There's a standard category of AI hiring tool that presents the appearance of ethical design — a bias audit, a "fairness" statement in the documentation, marketing language about "human-centered AI" — without the operational architecture that compliance actually requires.

What's typically missing: no candidate-facing disclosure that AI made or influenced a screening decision, no mechanism for the candidate to trigger human review, no per-decision log that can be exported for regulatory audit, no conformity assessment on file. A bias audit conducted on aggregate historical data is not the same as an ongoing audit trail of individual decisions. The distinction matters enormously when a candidate files a complaint or a regulator requests documentation.

The market reality is that the EU AI Act moved faster than most enterprise software vendors anticipated. Tools that were in development or early adoption when the Act was published are now in compliance debt. The companies that adopted earliest have the most exposure, because they have the longest history of deploying systems that weren't designed to this standard.

What Compliant AI Hiring Architecture Actually Looks Like

Compliance doesn't require removing AI from the hiring process. It requires building with the right design primitives from the start: transparency as a feature, not a disclosure policy; documentation as a byproduct of operation, not an afterthought; human oversight that's structurally real, not cosmetically present.

A compliant system discloses AI involvement at the point of contact — when a candidate is screened, they know they're speaking with AI and that a human can review the outcome. The system logs every interaction with enough fidelity that a compliance team can reconstruct what happened and why for any individual candidate. The escalation path for human review is functional: a recruiter can genuinely override the AI's assessment, and that override is also logged.

Companies that treat this as a retrofit problem will spend 12 to 18 months and significant external counsel fees trying to make non-compliant systems compliant. The practical outcome is usually a system that meets the letter of the regulation in ways that satisfy no one — auditors included. The better position is to run on tools that were designed with these properties natively.

How Asendia AI Is Built for This Moment

Asendia AI is a voice-first AI recruiter that screens candidates 24/7 through live, spoken conversations — and the design is transparent by construction. When Asendia calls a candidate, they're speaking with an AI recruiter. That's not buried in terms of service. It's the first thing they hear. The conversation is recorded and documented, which means the recruiter who inherits the shortlist gets not just a qualification score but verbatim call notes — and which means the audit trail exists from the first interaction.

The system is built to escalate to human recruiters. Asendia's role is first contact and qualification; it produces a ranked shortlist that a human reviews and acts on. That oversight structure isn't a compliance add-on — it's the workflow. Recruiters aren't rubber-stamping AI decisions because they're downstream of an opaque algorithm. They're reviewing documented screening conversations and making the actual placement decisions.

For agencies and enterprise teams operating in the EU or screening candidates across borders, that architecture matters now. The compliance requirement for a system that fits Annex III isn't a future roadmap item. It's a current operational condition. Asendia plugs directly into your existing ATS and handles volume at any hour without adding headcount — and it does so in a way that generates the documentation trail your compliance team will ask for when this comes up in a due diligence review. For more on how AI recruiting tools differ in what they actually do versus what they claim to do, the post on agentic recruiting covers that distinction directly.

Final Word

The EU AI Act didn't create new ethical principles for AI in hiring. It created legal enforceability for principles that thoughtful practitioners already held. If your AI hiring tools aren't transparent to candidates, don't generate audit logs, and don't have a real human-override mechanism, they were already ethically questionable — and they're now legally risky. The vendors who haven't proactively disclosed their compliance status aren't necessarily bad actors. They're operating in a market where disclosure wasn't required until now. That's changing. The question for every hiring team is whether they audit their stack before a complaint arrives or after.

Ready to transform your hiring strategy? Schedule a Demo with our founders today!

Badis Zormati

Co-Founder, Asendia AI

Ready to transform your hiring strategy?

Schedule a Demo

Keep reading