AI recruiting compliance in the EU means following the AI Act, GDPR, and national employment law whenever a tool screens, scores, or ranks candidates. The Digital Omnibus just delayed recruitment AI obligations to December 2027, but everything else still applies today.
Core Legal Rules
- EU AI Act: Classifies recruitment AI as high-risk under Annex III, requiring risk management, bias testing, and human oversight.
- GDPR (Article 22): Restricts fully automated hiring decisions unless candidates get transparency and a real human review.
- Equal Treatment Directives: Ban discrimination by algorithm, though each of the 27 member states enforces this differently.
- Works Councils: Germany's Betriebsrat can block an AI rollout outright, a right unrelated to the AI Act itself.
Skima AI supports these laws with human-reviewed scoring, documented rejection reasons, and EU-hosted data processing. It's built to help recruiters meet these compliance requirements, overlapping national and EU-wide standards.
On July 27, 2026, the EU's Digital Omnibus on AI entered into force. It pushed the high-risk AI deadline from August 2026 to December 2027, and that sounds like relief. It isn't, because GDPR and anti-discrimination law still apply today.
Germany's works councils can also still block your AI rollout, regardless of that deadline. The delay changed one date and left everything else exactly where it was. 4 laws actually govern AI recruitment in the EU, and only 2 apply the same way everywhere.
4 Key Recruitment Compliance Laws in the EU
2 of these are regulations, binding everywhere unchanged, while two are directives, applied differently by country.
EU AI Act and the Digital Omnibus Delay
The EU AI Act, Regulation 2024/1689, classifies recruitment AI as high-risk under Annex III. That includes CV screening, candidate ranking, and even targeted job advertising to prospective candidates. The Digital Omnibus didn't remove these obligations; it simply delayed them by sixteen months.
That pushes the compliance date from August 2026 to December 2027 for standalone high-risk systems. Providers and deployers still need risk management, bias testing, and human oversight once that deadline arrives.
GDPR and Automated Decision-Making
GDPR is a regulation rather than a directive, so it applies the same way in every member state. Article 22 restricts fully automated decisions that produce legal or similarly significant effects on a person.
Most AI hiring tools trigger this article, since a rejection or shortlist decision clearly qualifies. Employers need a lawful basis for the decision, plus a way for candidates to contest it. A genuine human review step has to sit behind that process as well.
EU Equal Treatment Directives in Employment
Directives work differently than regulations, since each member state writes its own national law to implement them. The Employment Equality Directive, 2000/78/EC, bans bias based on religion, disability, age, and sexual orientation.
Moreover, the Gender Equality Directive, 2006/54/EC, covers sex discrimination throughout the hiring and recruitment process. An algorithm that scores candidates unevenly across these groups violates national law, even without any discriminatory intent.
Provider and Deployer Liability Under the AI Act
The AI Act splits responsibility into two distinct roles, providers and deployers, with different duties for each. A provider builds the AI system, while a deployer (meaning you) uses it to screen or rank candidates. Article 16 sets provider obligations, such as technical documentation and risk management systems.
In contrast, Article 26 sets deployer obligations instead, covering human oversight, monitoring, and ongoing risk assessment. Buying a compliant tool from a vendor doesn't make your own use of it compliant automatically.
Why Compliance Still Differs by Member State
The AI Act and GDPR apply the same way everywhere in the EU, but employment law doesn't. Worker consultation rights vary enormously by country, and that gap often matters more than the Act.
Germany is the strictest example, since its works councils hold real co-determination rights under national law. These works councils, called Betriebsrat, operate under the Works Constitution Act, known as the BetrVG.
Section 87 covers technical systems that monitor employee behavior, while Section 95 covers AI-driven hiring selection criteria. A German works council can effectively block an AI rollout it hasn't formally approved in advance. This right exists independently of the AI Act and predates it by several decades.
Furthermore, France works differently, since its employee representative body, the CSE, holds weaker rights than Germany's. The CSE must be consulted before major workplace technology changes, but it cannot veto them outright. Most other member states sit somewhere between Germany's strong veto and France's lighter consultation duty.
None of this appears in the AI Act's text, but it surfaces the moment you try to deploy.
What Counts as High-Risk AI in Recruiting in the EU?
Annex III lists recruitment and candidate selection as high-risk by default, covering CV screening and application filtering. Candidate ranking tools fall into this category too, regardless of how simple the ranking logic looks.
The European Commission published draft guidance on this classification on May 19, 2026, opening it for public comment. It clarifies that a tool can be high-risk even when a human makes the final hiring call. What actually matters is whether the AI materially influences that decision, not who technically approves it. A tool that only organizes resumes for a recruiter to read may fall outside this test entirely.
However, a tool that actively ranks or scores candidates almost always falls inside it instead. Final guidance is expected by the end of 2026, so nothing here is fully settled yet. Until then, treat the draft as a strong signal rather than a finished legal standard.
5 Best Practices for Recruiters to Be Compliant
The expert-backed 5 practices turn these obligations into a repeatable process, regardless of where in the EU you hire:
1. Register the System and Document Everything
Once your recruitment AI gets classified as high-risk, it needs formal registration in the EU database. You also need technical documentation explaining exactly how the scoring system actually works.
Keep records of training data, testing results, and any changes made to the model. Auditors and national authorities will ask for this documentation directly, not a verbal explanation.
2. Consult Works Councils Early
If a works council or similar body exists, involve it before deployment, not after. In Germany specifically, this consultation step is not optional under the BetrVG at all.
Starting the conversation early avoids the stalled rollouts that come from retroactive consultation attempts. Even where consultation isn't legally required, informing employee representatives early builds trust and avoids resistance.
3. Test for Bias on Your Own Candidate Data
A vendor's test set almost never reflects your own actual applicant pool accurately. Run adverse-impact analysis on your own candidate data, on a regular schedule.
Additionally, test across protected categories under both the Employment and Gender Equality Directives. Log every test and its results, since evidence matters more than intent under EU discrimination law.
4. Give Candidates Transparency and Human Review
Candidates need to know AI is involved in screening or ranking them. They also need a way to request human review of a significant decision.
A rubber-stamp reviewer, who never actually overrides the AI, doesn't satisfy this requirement. The reviewer needs real authority, adequate training, and enough time to actually use it.
5. Vet Vendors for Provider-Side Compliance
Ask every vendor for their provider-side documentation before you sign a contract. That includes technical documentation, bias testing results, and clear instructions for actual use.
Confirm the vendor has registered the system in the EU database, where required. Remember that your deployer obligations exist regardless of what the vendor already did.
EU AI Act Enforcement and Penalties in 2026
The penalty regime under Article 99 has already been applied since August 2, 2025. This is separate from the Annex III deadline that just moved to December 2027.
Confusing these two separate timelines is a common and costly mistake among employers right now. Fines are calculated as a fixed amount or a percentage of global turnover, whichever is higher.
SMEs and startups automatically get the lower of these two possible figures. Large employers face the full calculation instead, based on their worldwide turnover. National authorities enforce these penalties, even though the underlying law is uniform.
One Compliance Program Across EU Member States
Building a separate program for each of 27 member states wastes time. Build to the strictest standard instead, and treat lighter requirements as a subset. That means treating Germany's works council process as your baseline, even elsewhere. It also means documenting bias testing everywhere, not just where enforcement feels active.
Centralize ownership of your entire AI hiring tool inventory inside one dedicated team. That team should span legal, HR, and whoever manages your applicant tracking system. The goal is one process that satisfies the strictest member state, not 27 different playbooks.
How Skima AI Helps as an EU Recruiting Compliance Ready Tool?
Skima AI has a core design choice that involves a human authorizing every hiring decision, aligns with Article 26 deployer obligations. Every candidate's score, shortlist, and rejection are reviewed by a human with real override power.
Candidate resumes and personal data are managed entirely within Skima AI's own models. Those models are hosted in an EU data center in Dublin, Ireland, specifically. Nothing related to candidates is sent to a public LLM API outside the EU.
The scoring model itself directly supports your obligations under the Equal Treatment Directives. By contractual DPA obligation, protected attributes like race, religion, disability, and age are never used as scoring inputs. Skima AI also checks job descriptions for biased or exclusionary language before a role goes live. This addresses discrimination risk at the posting stage, not only at screening.
Every disqualified candidate is tagged with the specific requirement they failed to meet. That documentation supports transparency and human review obligations under GDPR Article 22. It also supports the AI Act, once its recruitment provisions apply in December 2027.
None of this transfers your own deployer obligations over to Skima AI. You remain responsible under the AI Act, GDPR, and national employment law.
What a documented, human-reviewed architecture actually provides is usable evidence, not just reassurance. You can show it to works councils, national authorities, or candidates who ask how a decision was made.
EU Recruitment Compliance Checklist
Use this checklist to turn everything above into a concrete action plan.
Final Note
The EU AI Act didn't get lighter this week; it got later. GDPR, national discrimination law, and works council rights never moved at all. Germany's Betriebsrat can still stop a rollout today, regardless of any AI Act deadline.
Build your compliance program around the strictest requirement you face, not the newest deadline extension. Document human review, consult employee representatives early, and treat vendor promises as a starting point, not proof.
Frequently Asked Questions
1. How to be compliant with the EU AI Act?
Classify your recruitment AI under Annex III, since most hiring tools qualify as high-risk. Register the system, maintain technical documentation, run bias testing, and keep a human reviewing every final decision.
2. How would you ensure legal compliance in a hiring process?
Map which laws apply to each hiring stage, document every AI-assisted decision, test for bias regularly, and keep a human reviewer with real authority to override any automated outcome.
3. How to use automated AI software to source or screen resumes in the EU?
An automated AI software like Skima AI is classified as high-risk under the AI Act. It is required to disclose its AI use to candidates. Additionally, every score is routed through a human before deciding to advance or reject anyone.
4. How do local recruitment laws differ between Germany and France?
Germany's works councils hold real co-determination rights over AI hiring tools under the Works Constitution Act. France's CSE only requires consultation, without Germany's stronger veto-like power.