← Blog

EU AI Act for HR: Annex III Point 4 and the December 2027 Deadline

Parminder Singh
Parminder Singh··9 min read
Summarize with AI

The current EU AI Act places recruitment, promotion, termination, task allocation, and worker-monitoring systems in Annex III point 4, subject to the Article 6(3) exception. Regulation (EU) 2026/1744 moved the main Chapter III high-risk duties for these systems to 2 December 2027. This guide separates the duties already in force, the later high-risk controls, deployer notices, logging and retention, impact assessments, and explanation rights.

Compliance & Regulationeu-ai-acthrrecruitmenthigh-risk-aicompliancearticle-12
EU AI Act for HR: Annex III Point 4 and the High-Risk Recruitment Stack

TL;DR

  • HR AI is not classified by software labels alone, but by intended use, influence on employment decisions, and profiling.
  • Article 6(3) can exclude a listed system only when it poses no significant risk and does not materially influence the outcome; profiling removes that exception.
  • Employers should document the workflow, human review, inputs, overrides, and evidence for any exception before deployment.
  • A defensible plan separates current duties, delayed high-risk controls, and records needed to explain an AI-assisted employment decision.

The deadline for the main EU AI Act high-risk duties covering Annex III recruitment and worker-management systems is now 2 December 2027. Regulation (EU) 2026/1744 changed the timetable in July 2026. Any HR compliance plan still built around 2 August 2026 is reading an obsolete calendar.

The scope also needs more care than a list of HR software. Annex III point 4 identifies particular intended uses in recruitment, employment decisions, task allocation, monitoring, and performance evaluation. Article 6(3) can take an Annex III system outside the high-risk classification when it poses no significant risk to health, safety, or fundamental rights and does not materially influence decision-making. Profiling of natural persons removes that route.

I would put a red pen through any HR AI inventory that labels every summarizer high-risk and every human-reviewed ranking tool low-risk. Both shortcuts miss the statutory test. The intended purpose, the actual influence on the employment decision, and profiling determine the classification.

Annex III point 4 covers defined HR decisions

Annex III point 4 divides employment and worker-management uses into two groups.

Point 4(a) covers AI intended for recruitment or selection, particularly targeted job advertising, analysis and filtering of applications, and candidate evaluation. A model that scores applications for a shortlist sits squarely in that language. An LLM that rewrites a recruiter-authored job description may be performing a preparatory task instead, depending on its intended purpose and effect.

Point 4(b) covers AI intended to make decisions affecting terms of work-related relationships, promotion, termination, task allocation based on individual behaviour or personal traits, and monitoring or evaluation of performance and behaviour. That reaches beyond the applicant tracking system. A warehouse dashboard assigning shifts from individual productivity data and a performance model recommending a promotion can enter the same Annex III category.

The classification follows the intended use of the system. Buying a general-purpose model leaves that question open. The employer must document the intended HR function, the decision it feeds, the personal data or behaviour it evaluates, and the authority retained by the human reviewer. Our Annex III high-risk guide covers the broader classification structure.

Article 6(3) creates a material-influence test

Article 6(3) prevents Annex III from becoming a label attached to every minor AI feature near an employment workflow. A listed system can fall outside high-risk status when it poses no significant risk of harm to health, safety, or fundamental rights, including by failing to materially influence the outcome of decision-making.

The article gives four relevant patterns: a narrow procedural task, improvement of the result of a previously completed human activity, detection of decision-making patterns or deviations without replacing or influencing the completed human assessment without proper review, and a preparatory task for an Annex III assessment. These are conditional routes, rather than product categories.

Profiling creates the hard edge in this test. An Annex III system that performs profiling of natural persons is always high-risk under Article 6(3). An employer relying on the exception must document its assessment before placing the system on the market or putting it into service and provide the documentation to a competent authority on request.

For HR, “a manager checks the output” is weak classification evidence. A screen showing 200 applications sorted by model score can materially shape who receives attention even when the manager clicks the final button. I would test influence with the workflow on the screen: Can the reviewer see candidates outside the ranked list, alter the criteria, record a disagreement, and complete the decision without the model score?

The 2026 amendment moved the main high-risk deadline

Regulation (EU) 2026/1744 amended Article 113. For high-risk systems covered by Article 6(2), which includes Annex III point 4 HR systems, Chapter III Sections 1, 2, and 3 apply from 2 December 2027, apart from the separately treated Article 6(5). The delay covers the core high-risk classification, provider, and deployer framework in those sections. It did not shift every AI Act provision to that date.

This distinction matters in a 2026 HR plan. The prohibited-practice rules and Article 4 AI-literacy duty follow their own timetable. The organization needs a provision-by-provision calendar rather than a single “AI Act date.” Our December 2027 amendment analysis tracks the revised high-risk schedule.

Article 4 has applied since 2 February 2025. Its current wording requires providers and deployers to take measures supporting a sufficient level of AI literacy among staff and other people dealing with AI systems on their behalf, taking account of their knowledge, experience, education, training, context, and affected persons. The amended text clarifies that this creates no obligation to ensure a specific level for each individual. For HR, a recruiter approving a shortlist needs training tied to that system and decision, rather than a generic 30-minute slide deck with a stock robot on page one.

Articles 12 and 19 require scope-correct logging

Article 12 requires high-risk systems to be technically capable of automatically recording events, known as logs, over the system lifetime. The capability must support traceability appropriate to the system's intended purpose and enable monitoring, post-market monitoring, and investigation of operational risks and substantial modifications.

The detailed fields in Article 12(3), including reference databases and identification of people who verified matches, apply to Annex III point 1(a) remote biometric identification. They are not a statutory field list for HR systems under point 4. Copying those biometric fields into a recruitment checklist creates impressive-looking paperwork with the wrong legal basis.

Article 19 addresses provider retention. Providers of high-risk systems must keep automatically generated logs under their control for an appropriate period, generally at least six months unless other Union or national law says otherwise. Article 26 separately requires deployers to keep logs automatically generated by the system under their control for an appropriate period of at least six months, subject again to other applicable law. Our AI audit-log retention guide examines that split.

A useful HR evidence record can go beyond the statute's generic language. Candidate or worker reference, authenticated operator, model route, input and output, policy version, timestamp, reviewer action, and override reason can help reconstruct an AI-assisted decision. Those are recommended operating fields, not an Article 12 minimum list for HR.

Article 26 gives employers notice and operating duties

Once the delayed Chapter III duties apply to an Annex III point 4 system, the employer acting as deployer must use it according to the provider's instructions, assign competent human oversight, monitor its operation, and act when use may create a risk. The deployer also controls input-data relevance and representativeness where it controls that input.

Article 26 contains two HR notices that teams often merge. Before putting a high-risk AI system into service or using it in the workplace, an employer must inform workers' representatives and affected workers that they will be subject to the system. A deployer using an Annex III high-risk system to make or assist decisions about natural persons must also inform those people that they are subject to its use.

A works-council communication, candidate notice, and runtime log serve different purposes. The first records workplace procedure. The second tells the affected person about the system. The runtime record helps establish what occurred during a particular routed interaction. The Article 26 deployer guide provides a wider operating checklist.

Article 27 is narrower than a universal HR assessment

Article 27 does not impose a fundamental-rights impact assessment on every private employer using high-risk recruitment AI. Its deployer scope covers bodies governed by public law, private entities providing public services, and deployers of the specified Annex III point 5(b) and 5(c) creditworthiness and life or health insurance systems.

A public authority using recruitment AI may enter Article 27 because of who the deployer is. An ordinary private employer does not enter the duty merely because its system appears in Annex III point 4. GDPR data protection impact assessment duties, equality law, labour law, or national requirements can still demand separate analysis. The legal basis should appear at the top of the assessment template.

Article 86 explanation rights have several gates

Article 86 has applied since 2 August 2026, but it is narrower than a general right to inspect any model output. It concerns a decision taken by a deployer on the basis of output from an Annex III high-risk system, except systems listed under point 2, where that decision produces legal effects or similarly significantly affects a person in a way they consider adverse to health, safety, or fundamental rights.

The person can request clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken. The right is subject to the article's exceptions and does not apply where Union law already provides an equivalent right. An explanation process therefore needs intake criteria, a link to the relevant decision, and a record of the human procedure. A pile of raw prompts is a poor explanation.

For recruitment teams, the practical test is concrete: retrieve the candidate's affected decision, identify which Annex III output informed it, show the role that output played, and describe the main elements of the final decision in clear language. GDPR Article 22 remains a separate analysis with its own conditions and safeguards.

An HR compliance plan for 2026 and 2027

A defensible program can start with six records:

  • Use-case register: intended purpose, Annex III point, owner, provider, deployment geography, and decision affected.
  • Article 6 assessment: material influence, profiling, significant-risk analysis, and the evidence supporting any exception.
  • Application calendar: Article 4 measures now, Article 86 handling now, and delayed Chapter III controls scheduled for 2 December 2027 where applicable.
  • Notice register: workers, representatives, candidates or employees notified, with date, version, channel, and responsible owner.
  • Oversight design: reviewer competence, displayed inputs, override path, escalation trigger, and periodic sampling.
  • Evidence map: provider documentation, system logs, deployer logs, HR decision records, retention periods, access controls, and deletion authority.

Keep the Article 6 assessment attached to the deployed configuration. A change that turns a drafting assistant into a candidate-ranking feature can alter classification. Procurement names rarely reveal that transition; the changed screen and workflow do.

DeepInspect

DeepInspect covers a specific part of this control model: authenticated HTTP requests routed by an HR application or agent to an LLM endpoint. At that boundary, DeepInspect can evaluate identity-aware policy and produce a per-decision audit trail for the model interaction. Complete records depend on the HR application supplying stable candidate or worker context when the subject differs from the authenticated caller.

That evidence can support request reconstruction, deployer monitoring, retention design, and an Article 86 investigation. DeepInspect leaves several responsibilities with the employer and provider, including Article 6 classification, AI-literacy measures, worker and representative procedure, bias testing, impact assessments, final employment decisions, and AI calls that bypass the routed authenticated HTTP path.

For an HR team, the clean architecture is a routed model call tied to an authenticated recruiter, a stable subject reference, the policy decision, and the resulting model interaction. That gives compliance and security teams a precise record instead of a screenshot pasted into a ticket three months later. Book a demo today.