Compliance
The law applies to every agency using AI in hiring — from CV screening to chatbots. This page explains the timeline, what applies to recruiters specifically, and how to move from uncertainty to documented compliance.
Recruitment AI exposure
The EU AI Act doesn't only cover futuristic hiring tech. Typical recruitment stacks — ATS plugins, screening tools, chatbots, and assessment platforms — can each trigger different obligations depending on how they are used.
Automated filtering, scoring, and shortlisting of applicants is the highest-risk area for recruiters. Annex III employment AI may apply — requiring classification, documentation, oversight, and conformity workflows.
AI that interacts with candidates — chatbots, automated interview scheduling with generative responses, or similar — triggers transparency obligations under Art. 50. Candidates must know they are interacting with AI.
Video interview analysis, skills testing with AI scoring, and personality tools need classification on a case-by-case basis. Risk tier depends on whether decisions are automated, the data used, and the impact on candidates.
Even when AI is built into your ATS or assessment vendor, your agency is typically the deployer. You remain accountable for knowing what is in use, documenting it internally, and communicating transparency to candidates.
Regulatory timeline
The EU AI Act entered into force in 2024. Obligations phase in over several years — but transparency and governance expectations are already relevant for agencies hiring with AI today.
Agencies should inventory AI in hiring, assign internal ownership, and prepare transparency communications. Waiting until the final high-risk deadline leaves you exposed to client questions and regulatory scrutiny today.
From 2 August 2026, candidates must know when AI is used in recruitment interactions. Agencies deploying chatbots, automated screening, or similar tools need clear notices and internal records of what is deployed.
Documentation, risk management, and vendor oversight become increasingly concrete. Agencies without a living register and classification workflow will struggle to respond to audits and enterprise client security reviews.
From 2 December 2027, Annex III, point 4(a) employment AI may require full conformity workflows — technical documentation, human oversight measures, and ongoing monitoring.
For recruiters
Generic compliance advice misses how recruitment actually works. These are the obligation areas Conformant is built around.
You are responsible for AI you deploy — including vendor tools embedded in your ATS, assessment stack, or sourcing workflow. You need a register, not a one-off spreadsheet.
AI systems intended to interact directly with people — such as candidate-facing chatbots — must make the AI interaction clear under Art. 50. AI used to screen, rank, or evaluate candidates may instead be high-risk under Annex III.
CV screening, ranking, and candidate assessment may fall under high-risk categories. That triggers documentation, risk management, data governance, and oversight requirements.
Enterprise clients and regulators expect evidence: what AI you use, how it is classified, what controls exist, and how you monitor changes over time.