AI Act, Annex III point 4(a) — recruitment and selection as high-risk (Chapter III)
Providers and deployers of AI systems intended for the recruitment or selection of natural persons — placing targeted job advertisements, analysing and filtering applications, and evaluating candidates. Also promotion and termination decisions, task allocation, and performance monitoring under point 4(b).
- 01Nothing yet. The obligations below do not bite until 2 December 2027.
- 02From that date, as deployer: assign human oversight to a competent person, use the system per its instructions, monitor operation, keep logs, inform workers' representatives and affected workers before putting it into service, and give an affected person an explanation of the role the system played in a decision.
- 01Nothing yet.
- 02From 2 December 2027, as provider: operate a risk-management system, meet data-governance standards, produce technical documentation, enable logging, ensure accuracy, robustness and cybersecurity, undergo conformity assessment, register in the EU database, and affix CE marking.
- 01Nothing at all today. Any vendor selling on the basis that EU high-risk hiring rules are already live is wrong, and any buyer being hurried on that basis is being hurried on a false premise.
- 02The deferral is not a repeal. The requirements were postponed because national authorities and harmonised standards were not ready — not because they were abandoned.
- 03It does not defer Article 50. Those transparency duties took effect on 2 August 2026 and are unaffected (see EU-01).
From the application date, Article 99 fines up to EUR 15 000 000 or 3% of worldwide annual turnover for breach of provider or deployer high-risk obligations.
A 60-second scored role rehearsal used to evaluate candidates falls squarely inside Annex III point 4(a). We have roughly sixteen months. We would rather say that plainly than let the deferral read as a reprieve — the honest position is that we are not yet built to the Chapter III standard and the clock is running.
“2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III”
Reg. (EU) 2026/1744, Art. 1(40)(b)
European Commission, 'AI Omnibus enters into force' (Digital Strategy newsroom).