The AI Act and Recruitment: What Agencies and Staffing Firms Must Do Before 2027

Grégory Hissiger
Grégory Hissiger
July 10, 202611 min read

Summary

The AI Act, the European regulation on artificial intelligence, classifies AI systems used in recruitment (resume screening, scoring, matching, selection support) among high-risk use cases. Consequences for agencies, staffing firms and employers: mandatory human oversight of decisions, candidate information, traceability of the systems used and verification of vendor compliance. The timeline is already running: prohibitions in force since February 2025, high-risk obligations rolling out between August 2026 and August 2027. Penalties reach up to 35 million euros or 7% of global revenue. The good news: for an AI user (not a vendor), compliance comes down to 7 very actionable projects.

Key takeaways

  • 01The AI Act classifies recruitment AI (screening, scoring, matching, selection) as high-risk: obligations apply to vendors AND users.
  • 02Already banned since February 2025: emotion recognition at work and social scoring. Some video interview analysis practices are affected.
  • 03Timeline: most high-risk obligations roll out between August 2026 and August 2027. Compliance time is now.
  • 04Key obligations for an agency or staffing firm: real human oversight of decisions, candidate information, AI system register, compliant vendors.
  • 05Penalties: up to 35M euros or 7% of global revenue for prohibited practices, 15M or 3% for other breaches.
  • 06Compliance is a commercial argument: large accounts will require it in RFPs from 2026.

Why recruitment is on the front line

The AI Act is the world's first regulation governing artificial intelligence. In force since August 1, 2024, it applies progressively until 2027. Its approach: classifying AI uses by risk level, with proportionate obligations.

And recruitment explicitly appears in the high-risk category (Annex III of the regulation): systems used for job ad targeting, application screening and filtering, candidate evaluation, promotion or termination decisions. The legislator's logic: these systems influence access to employment and livelihoods, so an error or bias there has major consequences.

If you are a recruitment agency, a staffing firm or an in-house recruitment team, you are covered as soon as you use AI to screen, score or evaluate candidates. Not covered, however: purely administrative uses (transcription, writing, scheduling, reporting), which do not fall under high-risk.

What has been banned since February 2025

Some practices are prohibited, with no transition period:

  • Emotion recognition at work: analyzing a candidate's facial expressions or voice in a video interview to infer their emotional state. "Behavioral" video analysis tools largely fall under this ban.
  • Social scoring: evaluating a person based on their general social behavior.
  • Exploiting vulnerabilities and certain manipulative practices.

If a tool in your stack offers to "detect motivation" or "engagement" through facial or vocal analysis, that is an immediate red flag.

The timeline that concerns you

DeadlineWhat applies
February 2025Prohibitions (workplace emotion recognition, social scoring) + AI literacy obligation for teams
August 2025Obligations for general-purpose AI models (vendor side)
August 2026General application, including most high-risk obligations
August 2027End of remaining transition periods: every high-risk system must be compliant

Operational translation: 2026 is the compliance year. Companies starting in 2027 will do it under pressure, at the worst time.

Vendor or user: who must do what

The AI Act distinguishes two roles, and that is the key to not panicking:

  • The provider (the AI system's vendor) carries the heaviest load: risk management, training data quality, technical documentation, CE marking, registration in the European database.
  • The deployer (you, using the system) has lighter but real obligations: using the system according to its instructions, ensuring competent human oversight, informing the people concerned, keeping logs, reporting incidents.

Your first reflex should therefore be contractual: require proof of compliance from your vendors. A serious provider makes your compliance easier; an evasive one transfers their risk to you.

Your 7 compliance projects

1. Map your AI systems

List everything that touches candidate evaluation: your ATS's matching, scoring tools, pre-qualification chatbots, automated tests. For each system: vendor, use, data processed, who uses it.

Prepare for the EU directive with Cobalt

Job mapping, gap audits, publishable salary grid. Cobalt natively integrates pay transparency compliance tools.

See Cobalt in demo

2. Classify by risk level

Screening, scoring, matching, evaluation: high-risk. Transcription, job ad writing, scheduling, reporting: outside the high-risk scope. Emotion analysis: banned, to be unplugged.

3. Audit your vendors

Ask in writing for: AI Act compliance documentation, score explainability, bias management, data hosting. Build these requirements into your contract renewals.

4. Organize human oversight

The regulation's central point: no selection decision may be produced by AI alone. Concretely: the AI proposes and argues, a trained recruiter decides and can override. Beware of "rubber-stamp oversight": one-click approving 200 automatic rejections is not real oversight.

5. Inform candidates

Candidates must know an AI system is involved in the process. Update your information notices, career pages and processes: it is also a consistency requirement with GDPR, which already governs automated decisions.

6. Trace and document

Keep the logs of high-risk systems, document who supervised what, keep track of decision reasons. In case of an audit or a dispute with a candidate, this documentation is your protection.

7. Train your teams

The "AI literacy" obligation applies since February 2025: everyone using these systems must understand their capabilities, limits and bias risks. A documented half-day training covers the essentials.

Penalties, and the real risk

The ceilings are dissuasive: up to 35 million euros or 7% of global revenue for prohibited practices, 15 million or 3% for breaches of high-risk obligations.

But for an agency or staffing firm, the most concrete risk lies elsewhere: commercial and litigation. Large accounts are already adding AI Act clauses to their RPO and recruitment RFPs; being unable to answer closes doors. And a rejected candidate can challenge an automated decision: without documented oversight, your defense is weak.

The positive angle: compliance as an advantage

The AI Act's requirements (human oversight, explainability, traceability) match exactly what a well-designed recruitment AI already does. That is Cobalt's approach: always-explained scores, traceable actions, native human approval rules, European hosting aligned with GDPR. For our clients, compliance is not an extra project, it is a property of the platform.

Agencies able to tell their clients "our AI process is compliant, supervised and documented" will turn a regulatory constraint into a differentiation argument. Exactly as GDPR ended up becoming a trust standard.

Conclusion: 12 useful months

The AI Act does not slow AI down in recruitment: it eliminates indefensible practices and imposes the hygiene the best players already practiced. By August 2027, every high-risk system must be compliant; the projects are known, actionable and reasonable if spread over 2026. Start with the mapping and the vendor audit: it is a week of work, and it is what reveals the real issues.

Prepare for the EU directive with Cobalt

Job mapping, gap audits, publishable salary grid. Cobalt natively integrates pay transparency compliance tools.

See Cobalt in demo

Frequently Asked Questions

Yes, as soon as you use an AI system to screen, score, match or evaluate candidates: these uses are classified as high-risk. As a user (deployer), your main obligations are human oversight of decisions, informing candidates, keeping logs and choosing compliant vendors.

Since February 2025: emotion recognition at work (facial or vocal analysis in interviews to infer emotional state), social scoring and manipulative practices. Behavioral video analysis tools for candidates are largely affected: if your stack contains any, unplug them.

Prohibitions and team AI literacy: since February 2025. Most high-risk obligations: August 2026. End of transition periods: August 2027. Compliance work should therefore happen in 2026 to stay comfortable.

Up to 35M euros or 7% of global revenue for prohibited practices, 15M or 3% for high-risk breaches. But the most immediate risk is commercial (AI Act clauses in large accounts' RFPs) and litigation (a rejected candidate can challenge an unsupervised automated decision).

Yes. AI screening and scoring remain legal, provided there is real human oversight (AI proposes, a trained recruiter decides), explainable scores, informed candidates and documented systems. What is proscribed is automating the final decision without a human.

Ask your vendor four questions: are your scores explainable? Is human oversight built into the workflows? Are actions traceable? Where is the data hosted? A compliant vendor answers in writing without difficulty. At Cobalt, these properties are native: explained scores, human approval, traceability and European hosting.

Related Articles