Lumo360  /  EU AI Act for recruiters

EU compliance guide

The EU AI Act and AI in recruitment, in plain English.

AI used to screen or evaluate job candidates is classed as high-risk under the EU AI Act. The main obligations now apply from 2 December 2027, after the Digital Omnibus moved the original August 2026 date. Some rules already apply today. Here is what each one means for an employer using an AI hiring tool.

Which rules apply, and from when

The Digital Omnibus delayed the high-risk rules. It did not remove them.

01

2 February 2025: banned practices and AI literacy

Prohibited AI practices apply, including emotion recognition in the workplace1. Employers and vendors must also support AI literacy among staff who use AI; the Digital Omnibus softened this to a duty to support literacy rather than guarantee a set level2.

02

2 August 2026: telling people they're talking to an AI

Transparency rules in Article 50 apply. An AI system that interacts directly with people must make sure they are "informed that they are interacting with an AI system"3. The Omnibus did not change these obligations4.

03

2 December 2027: high-risk obligations for recruitment AI

Obligations for high-risk systems listed in Annex III, which includes employment, now apply from this date. It was originally 2 August 2026, and was moved by Regulation (EU) 2026/1744, in force since 27 July 202625.

04

Until then: prepare, don't wait

The extra time is for standards and guidance to catch up, not a reason to pause. Contracts you sign now will very likely still be running in December 2027.

Is your recruitment tool high-risk?

Almost certainly, if it screens or evaluates candidates. Annex III of the Act lists "AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates"6.

There is a narrow exception for systems that don't pose a significant risk, such as tools that only do a narrow procedural task or preparatory work7. But it doesn't apply to profiling: an Annex III system that profiles people "shall always be considered to be high-risk"7. A tool that scores candidates on competencies is hard to fit into the exception.

The Act also reaches beyond the EU. It covers providers and deployers based outside the EU "where the output produced by the AI system is used in the Union"8, so a UK employer hiring for EU roles, or a UK vendor selling to EU employers, can be in scope.

No emotion recognition in interviews

Since 2 February 2025, it has been prohibited to use AI "to infer emotions of a natural person in the areas of workplace and education institutions", except for medical or safety reasons1. Commission guidelines read "workplace" broadly, covering the relationship from recruitment to dismissal1.

In practice, an interview tool that reads facial expressions or tone of voice to judge whether a candidate is nervous, enthusiastic or honest is a serious risk. Breaches of the prohibitions carry the Act's highest fines: up to €35 million or 7% of worldwide annual turnover, whichever is higher; for SMEs, whichever is lower9.

What employers using AI hiring tools must do

These are the deployer obligations in Article 26, plus the right to explanation in Article 86. Breaches can lead to fines of up to €15 million or 3% of worldwide turnover9.

01

Use it as the vendor intends

Take appropriate technical and organisational measures to use the system in line with the provider's instructions for use10.

02

Put a qualified person in charge

Assign human oversight to people with "the necessary competence, training and authority"10.

03

Monitor it, and keep the logs

Monitor the system, report risks to the provider and authorities, and keep the logs it generates for at least six months10.

04

Tell candidates and workers

Inform people that they are subject to a high-risk system used to make or assist decisions about them, and inform workers' representatives before using one in the workplace10.

05

Run a data protection impact assessment

Use the information the provider must supply to carry out your DPIA under data protection law10.

06

Be ready to explain a decision

People affected by a decision based on a high-risk system's output can ask for "clear and meaningful explanations of the role of the AI system" and the main elements of the decision11.

Questions to ask your AI hiring vendor now

Our own answers are included where we can give them today. For the rest, ask us for our current position.

Classification

Do you treat your product as a high-risk AI system?

If a tool screens or evaluates candidates and the vendor says it isn't high-risk, ask them to explain why in writing.

Emotion inference

Does the tool infer emotions, from video, voice or text?

Ask directly, and get the answer in the contract. This has been prohibited at work since February 2025.

Explanations

Can a recruiter see why a candidate got a particular score?

You will need this to meet the right to explanation, and to answer a rejected candidate's question fairly.

Lumo360: Every score links to the transcript moments that support it, so a recruiter can show the evidence behind it.

Human oversight

Does a person review every result before a candidate is rejected?

Oversight has to be real: a named, trained person with the authority to overrule the system.

Lumo360: A recruiter reviews every result before anyone moves forward or is rejected.

Disclosure

How are candidates told they are speaking to an AI?

From August 2026 this is required by Article 50, and candidates react badly when they find out later.

Records

What logs and documents will you give us, and for how long?

You need logs for at least six months, and enough information from the vendor to complete your DPIA.

If you only hire in the UK

The EU AI Act doesn't apply to UK-only hiring. UK GDPR and the Information Commissioner's Office set the rules instead, and the ICO has published its own six questions for buyers of AI recruitment tools.

Read our guide to the ICO's six questions. If you hire into EU roles as well, plan for both.

From job description to shortlist

Step 01

Start with the role

Upload the job description. Lumo360 identifies the competencies that matter and turns them into a structured interview framework. You review and adjust it before going live.

Step 02

Candidates have a real conversation

Candidates join when it suits them. The interviewer follows the framework, asks relevant questions and follows up based on each answer.

Step 03

You review the evidence

See how each candidate performed against every competency, with each score linked to the conversation. Your team decides who moves forward.

What this guide is, and isn't

This guide summarises Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, checked in October 2026. It is general information, not legal advice. Guidance and standards are still being published, so take advice on your own situation.

Common questions

Is AI recruitment software high-risk under the EU AI Act?

Yes, in most cases. Annex III lists AI used for recruitment or selection, including analysing and filtering applications and evaluating candidates, as high-risk. A narrow exception exists, but it never applies to systems that profile people.

When do the EU AI Act rules for recruitment apply?

The high-risk obligations apply from 2 December 2027, moved from 2 August 2026 by the Digital Omnibus (Regulation (EU) 2026/1744). The ban on emotion recognition at work has applied since 2 February 2025, and the duty to tell people they are interacting with an AI applies from 2 August 2026.

Can AI interviews analyse candidates' emotions?

No. Since 2 February 2025 the EU AI Act prohibits using AI to infer emotions in the workplace, which Commission guidance says includes recruitment, except for medical or safety reasons.

Does the EU AI Act apply to UK companies?

It can. The Act covers providers and deployers outside the EU where the AI system's output is used in the EU, for example a UK company hiring for roles in the EU. UK-only hiring is covered by UK GDPR and ICO guidance instead.

Do candidates have to be told an AI is involved?

Yes. From 2 August 2026 people must be told when they are interacting directly with an AI system, and from December 2027 employers must inform candidates that a high-risk AI system is being used in decisions about them.

Give candidates a conversation.
Give your team the evidence.

See a Lumo360 interview and the report it produces, using one of your own job descriptions.

Book a demo