← Back to white papers

The EU AI Act and Hiring: Why Recruitment AI Is High-Risk and What Article 10 Requires

Summary: The EU AI Act classifies AI used in recruitment, selection, and employment decisions as high-risk. That classification triggers a substantial set of obligations covering risk management, data governance, transparency, human oversight, and record-keeping. Article 10, the data governance provision, is one of the most demanding: it requires that the datasets behind a hiring tool be relevant, representative, and examined for bias. Companies deploying hiring AI in the EU need to prepare well before the high-risk obligations take effect.

Key takeaways

  • Recruitment and selection AI falls under Annex III of the EU AI Act, making it high-risk by default.
  • High-risk classification brings a broad compliance program, not a single audit.
  • Article 10 governs the data behind the tool and requires bias examination and mitigation at the dataset level.
  • Both the provider that builds the tool and the deployer that uses it carry obligations.
  • The compliance work is significant, so the operative deadline should be treated as a planning horizon, not a starting gun.

Why hiring AI is high-risk under the EU AI Act

The EU AI Act sorts AI systems by risk. A small set of practices are prohibited outright. A large middle category is designated high-risk and heavily regulated. Everything else faces lighter or minimal obligations.

Employment sits squarely in the high-risk category. Annex III of the Act lists AI systems used for the recruitment or selection of people, for decisions about promotion or termination, for task allocation, and for monitoring or evaluating performance. That covers tools that target job advertisements, filter applications, and evaluate candidates during interviews or assessments. If your tool decides who gets seen, shortlisted, scored, or advanced, it is high-risk.

The reasoning is that employment decisions materially affect people's livelihoods and fundamental rights, and that automated systems can entrench discrimination at scale if left unchecked. The Act responds with obligations rather than a ban.

What high-risk classification requires

High-risk status is not satisfied by a single test. It brings a program of obligations that, depending on your role, includes a risk management system, strong data governance, technical documentation, automatic record-keeping and logging, transparency and clear instructions for use, meaningful human oversight, and appropriate accuracy, robustness, and cybersecurity. Providers must also operate a quality management system and complete a conformity assessment before placing the system on the market.

For a company that simply buys and uses a hiring tool, the full provider burden may not apply, but the deployer obligations still do. And any company that meaningfully customizes or rebrands a tool can find itself treated as a provider, with the heavier set of duties that follow.

Article 10: the data governance provision

Article 10 is where many hiring tools are most exposed, because bias in hiring AI usually originates in the data. The provision requires that the training, validation, and testing datasets behind a high-risk system meet quality criteria.

In practical terms, Article 10 asks that datasets be relevant and sufficiently representative, that data collection and preparation follow sound governance, and, critically, that the data be examined for biases that could affect health, safety, or fundamental rights, or lead to prohibited discrimination. Where such biases are found, appropriate measures to detect, prevent, and mitigate them are required. The provision also expects attention to data gaps and shortcomings.

This is a higher bar than a one-time outcome audit. It asks about the provenance and composition of the data, not only the results the model produces. A tool trained on historical hiring decisions that already favored one group will tend to reproduce that pattern, and Article 10 puts the obligation to catch and correct that squarely on the table.

Provider versus deployer

The Act distinguishes between the provider, who develops the system or has it developed and places it on the market, and the deployer, who uses it. Most employers are deployers. Deployers must use the system according to the provider's instructions, ensure human oversight is actually exercised, monitor operation, keep logs, and inform affected workers and their representatives that a high-risk system is in use.

The distinction is not always clean. If you fine-tune a tool on your own data, integrate it deeply, or put your brand on it, you may cross into provider territory and inherit the fuller obligations. Understanding which role you occupy for each tool is an early and important part of scoping the work.

How this connects to NYC Local Law 144

If you hire in both New York City and the EU, you face two regimes with different mechanics but overlapping spirit. Local Law 144 centers on an annual outcome audit and candidate notice. The EU AI Act centers on a broader governance program with strong data requirements. A well-designed compliance program can serve both, because the evidence you gather for one, clean data, documented bias testing, transparent candidate communication, is largely the same evidence the other rewards. Building once for both is far more efficient than running two disconnected projects.

How to prepare

Begin by inventorying every hiring tool and identifying which are high-risk and whether you are a provider or deployer for each. Then assess your data governance against Article 10, paying particular attention to representativeness and documented bias examination. Stand up the surrounding obligations: human oversight that is real rather than nominal, logging, transparency to candidates and workers, and technical documentation. Finally, put a monitoring cadence in place, because high-risk compliance is an ongoing state, not a certificate you earn once.

Frequently asked questions

Is all hiring AI high-risk under the EU AI Act? AI used for recruitment, selection, promotion, termination, task allocation, and performance evaluation is listed as high-risk in Annex III. Tools that decide who advances generally qualify.

What does Article 10 require? That the datasets behind a high-risk system are relevant, representative, well-governed, and examined for bias, with mitigation measures where bias is found.

Are we a provider or a deployer? Most employers are deployers who use a tool. Building, heavily customizing, or rebranding a tool can make you a provider with fuller obligations.

When do the high-risk obligations apply? The high-risk employment obligations take effect on a set EU deadline in 2026. Confirm the current applicable date, since timing has been subject to adjustment, and plan against it as a horizon rather than a start line.

Can one program satisfy both the EU AI Act and NYC Local Law 144? Largely yes. The underlying evidence overlaps, so a single well-structured program can serve both markets efficiently.


Preparing for the EU AI Act is a governance project, not a quick fix, and starting early is the difference between a calm rollout and a deadline scramble. If you want a clear scope of what high-risk compliance requires for your specific stack, that is where a focused assessment starts.