Why recruitment is on the front line
The AI Act is the world's first regulation governing artificial intelligence. In force since August 1, 2024, it applies progressively until 2027. Its approach: classifying AI uses by risk level, with proportionate obligations.
And recruitment explicitly appears in the high-risk category (Annex III of the regulation): systems used for job ad targeting, application screening and filtering, candidate evaluation, promotion or termination decisions. The legislator's logic: these systems influence access to employment and livelihoods, so an error or bias there has major consequences.
If you are a recruitment agency, a staffing firm or an in-house recruitment team, you are covered as soon as you use AI to screen, score or evaluate candidates. Not covered, however: purely administrative uses (transcription, writing, scheduling, reporting), which do not fall under high-risk.
What has been banned since February 2025
Some practices are prohibited, with no transition period:
- Emotion recognition at work: analyzing a candidate's facial expressions or voice in a video interview to infer their emotional state. "Behavioral" video analysis tools largely fall under this ban.
- Social scoring: evaluating a person based on their general social behavior.
- Exploiting vulnerabilities and certain manipulative practices.
If a tool in your stack offers to "detect motivation" or "engagement" through facial or vocal analysis, that is an immediate red flag.
The timeline that concerns you
| Deadline | What applies |
|---|---|
| February 2025 | Prohibitions (workplace emotion recognition, social scoring) + AI literacy obligation for teams |
| August 2025 | Obligations for general-purpose AI models (vendor side) |
| August 2026 | General application, including most high-risk obligations |
| August 2027 | End of remaining transition periods: every high-risk system must be compliant |
Operational translation: 2026 is the compliance year. Companies starting in 2027 will do it under pressure, at the worst time.
Vendor or user: who must do what
The AI Act distinguishes two roles, and that is the key to not panicking:
- The provider (the AI system's vendor) carries the heaviest load: risk management, training data quality, technical documentation, CE marking, registration in the European database.
- The deployer (you, using the system) has lighter but real obligations: using the system according to its instructions, ensuring competent human oversight, informing the people concerned, keeping logs, reporting incidents.
Your first reflex should therefore be contractual: require proof of compliance from your vendors. A serious provider makes your compliance easier; an evasive one transfers their risk to you.
Your 7 compliance projects
1. Map your AI systems
List everything that touches candidate evaluation: your ATS's matching, scoring tools, pre-qualification chatbots, automated tests. For each system: vendor, use, data processed, who uses it.
Prepare for the EU directive with Cobalt
Job mapping, gap audits, publishable salary grid. Cobalt natively integrates pay transparency compliance tools.
2. Classify by risk level
Screening, scoring, matching, evaluation: high-risk. Transcription, job ad writing, scheduling, reporting: outside the high-risk scope. Emotion analysis: banned, to be unplugged.
3. Audit your vendors
Ask in writing for: AI Act compliance documentation, score explainability, bias management, data hosting. Build these requirements into your contract renewals.
4. Organize human oversight
The regulation's central point: no selection decision may be produced by AI alone. Concretely: the AI proposes and argues, a trained recruiter decides and can override. Beware of "rubber-stamp oversight": one-click approving 200 automatic rejections is not real oversight.
5. Inform candidates
Candidates must know an AI system is involved in the process. Update your information notices, career pages and processes: it is also a consistency requirement with GDPR, which already governs automated decisions.
6. Trace and document
Keep the logs of high-risk systems, document who supervised what, keep track of decision reasons. In case of an audit or a dispute with a candidate, this documentation is your protection.
7. Train your teams
The "AI literacy" obligation applies since February 2025: everyone using these systems must understand their capabilities, limits and bias risks. A documented half-day training covers the essentials.
Penalties, and the real risk
The ceilings are dissuasive: up to 35 million euros or 7% of global revenue for prohibited practices, 15 million or 3% for breaches of high-risk obligations.
But for an agency or staffing firm, the most concrete risk lies elsewhere: commercial and litigation. Large accounts are already adding AI Act clauses to their RPO and recruitment RFPs; being unable to answer closes doors. And a rejected candidate can challenge an automated decision: without documented oversight, your defense is weak.
The positive angle: compliance as an advantage
The AI Act's requirements (human oversight, explainability, traceability) match exactly what a well-designed recruitment AI already does. That is Cobalt's approach: always-explained scores, traceable actions, native human approval rules, European hosting aligned with GDPR. For our clients, compliance is not an extra project, it is a property of the platform.
Agencies able to tell their clients "our AI process is compliant, supervised and documented" will turn a regulatory constraint into a differentiation argument. Exactly as GDPR ended up becoming a trust standard.
Conclusion: 12 useful months
The AI Act does not slow AI down in recruitment: it eliminates indefensible practices and imposes the hygiene the best players already practiced. By August 2027, every high-risk system must be compliant; the projects are known, actionable and reasonable if spread over 2026. Start with the mapping and the vendor audit: it is a week of work, and it is what reveals the real issues.

