An organisation can use AI to shortlist applicants, but a CV-screening tool that scores or ranks candidates is a high-risk AI system under the EU AI Act, and there is no realistic argument to classify it as anything else. The interesting question is not whether the rules apply — it is who carries which obligation, and what "meaningful human oversight" has to look like in practice to keep the tool both lawful and defensible.
One timing point that changed recently and is widely misread: the high-risk obligations were deferred, not removed. Reading "deferred" as "we can wait" is the mistake this analysis is designed to prevent.
Start with the business, not the legislation
Good governance analysis begins with discovery, not statute. Before opening the Act, you establish what the system actually does, who it affects, and who built it — because the answers decide which obligations attach and to whom.
The scenario for this teaching case: a mid-sized company buys a CV-screening tool from an external vendor. HR uploads applications; the tool parses each CV, scores candidates against the role, and returns a ranked shortlist. It will be used across the company's EU entities. That last detail matters — jurisdiction and scale are not footnotes, they determine exposure.
| Purpose | Parse, score and rank job applicants against a role profile |
|---|---|
| Users | HR and recruitment staff |
| Affected persons | Job applicants — who do not choose to be assessed this way |
| Inputs | CVs, cover letters, work history, qualifications |
| Outputs | Candidate score, ranking, suggested shortlist |
| Origin | Purchased from a third-party vendor (not built in-house) |
Because the tool is bought, not built, the company is a deployer, and the vendor is the provider. These two roles carry different legal duties under the Act. The single most common mistake in this scenario is assuming the vendor's compliance discharges the employer's — it does not. A compliant vendor does not make you a compliant deployer.
Map where the AI acts — and where humans can intervene
Drawing the workflow is not decoration. It locates the exact points where the system influences a person's opportunities, and the exact points where a human being can still change the outcome. Those intervention points are where oversight either exists or is a fiction.
Note the asymmetry: the AI acts twice, early, and shapes the field before any human looks. By the time a recruiter reviews, the ranking has already framed the decision. That framing effect — not the final click — is where governance has to bite.
Show the reasoning, not just the conclusion
The Act lists employment and recruitment AI as high-risk Annex III(4). But being listed in Annex III does not automatically make a system high-risk — the Act provides exceptions Art 6(3) for systems that perform only narrow procedural tasks or otherwise don't materially influence the outcome. A careful analyst checks whether any exception applies rather than asserting the conclusion.
Ranking candidates by predicted suitability is profiling of natural persons. The Act says a system that profiles is always high-risk, regardless of the Art 6(3) exceptions. So you don't spend time arguing the exceptions for a CV-ranker — the profiling override closes that door before you reach it. Even setting profiling aside, a tool that shapes who gets hired doesn't meet the "doesn't influence the outcome" bar. The classification is doubly locked.
Who carries what — provider vs deployer
Because the tool is bought in, obligations split. The provider (vendor) must build the quality management system, technical documentation, conformity assessment and CE marking, and register the system Art 16 · Art 49. The deployer (the employer) carries its own, separate duties Art 26 — chief among them assigning competent human oversight, keeping logs, monitoring outputs, and, as an employer, informing workers' representatives and affected staff before use Art 26(7).
Recruitment AI follows the internal self-assessment route Annex VI — no independent notified body is required (those are reserved mainly for biometric identification). That means the vendor's conformity is self-declared. It is a starting document to interrogate, not a guarantee to rely on. Ask to see the technical documentation behind the mark.
Timing: deferred is not cancelled
The Digital Omnibus Reg (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the application date for stand-alone Annex III high-risk obligations from 2 August 2026 to 2 December 2027. That is real runway — but the obligations themselves are unchanged, the readiness timeline is tied to a registration mechanism that is being stood up now, and systems materially modified after the date lose any grandfathering. The disciplined reading is: use the runway to get oversight and documentation right, not to defer the work.
What could go wrong — and who owns the fix
Move from legal categories to practical failure modes. A governance professional asks not "is this compliant?" but "what harm is plausible, how likely, and who is accountable for reducing it?"
| Risk | What it looks like | Sev. | Primary owner |
|---|---|---|---|
| Bias & discrimination | Historic hiring data teaches the model to favour some groups; proxies (postcode, career gaps, language) stand in for protected traits. | High | Deployer + Provider |
| Accuracy | Misparses non-standard CVs; penalises unconventional but valid careers; rejects qualified candidates. | High | Provider |
| Transparency | Applicants aren't told AI is used; recruiters can't explain why a score is low. | Med | Deployer |
| Privacy / GDPR | CVs reveal or imply special-category data; automated rejection engages Art 22; unclear retention. | High | Deployer (controller) |
| Contestability | A rejected applicant has no route to challenge or seek a human review. | Med | Deployer |
| Automation bias | Recruiters defer to the ranking rather than exercising judgement — oversight becomes a rubber stamp. | High | Deployer |
Automated rejection with no meaningful human involvement engages the right not to be subject to solely automated decisions GDPR Art 22. CVs frequently expose special-category data GDPR Art 9, and profiling on this scale almost always triggers a Data Protection Impact Assessment GDPR Art 35. The AI Act and GDPR are not alternatives — they stack.
Compliance lives in organisational process
The obligations only become real when someone owns them. This is where analysis moves from citing articles to designing accountability.
| Control | The question to answer |
|---|---|
| AI policy | Does an internal policy govern how AI hiring tools are selected, approved and reviewed? |
| Internal inventory | Is the system logged in an AI register with owner, purpose, risk tier and vendor? |
| RACI | Who is accountable — HR, IT, Legal, or a governance lead? Ambiguity here is the failure mode. |
| Approval gate | Has anyone formally signed off deployment against a documented assessment? |
| Worker information | Have workers' representatives and affected staff been informed before use? Art 26(7) |
| Monitoring cadence | How often are outcomes reviewed for drift and disparate impact — and by whom? |
"A human reviews it" is not oversight
The Act requires that high-risk systems be overseen by natural persons with the competence, authority and support to act Art 14 · Art 26(2). The bar is not the presence of a human — it is a human who can meaningfully change the outcome. Design oversight to defeat automation bias, or it fails on contact.
| Weak (rubber stamp) | Meaningful (defensible) |
|---|---|
| Recruiter sees the ranked list and proceeds. | Scores are advisory; the recruiter records a reason when following or departing from them. |
| Rejected candidates disappear. | A sample of AI-rejected candidates is human-reviewed for false negatives. |
| Staff trust the tool because it's "the system." | Staff are trained on the tool's limitations and empowered to override without penalty. |
Meaningful human involvement is also what keeps the process outside "solely automated" decision-making GDPR Art 22. Get oversight right and you satisfy two regimes with one well-designed control. Get it wrong and a single weak checkpoint breaches both.
Prepare as if an audit is coming
The deployer's defence is its evidence trail. Some artefacts you obtain from the provider; others you must generate yourself. Knowing which is which is half the discipline.
- System description and intended purposeObtain from provider · verify against your use
- Vendor conformity documentation & instructions for useObtain from provider · interrogate the self-declaration
- Deployer risk assessment for your contextGenerate — your responsibility
- Data protection impact assessmentGenerate · GDPR Art 35
- Bias / disparate-impact testing resultsRequest from provider · re-test on your data
- Human oversight procedure & override policyGenerate — your responsibility
- Retained system logsGenerate · keep at least 6 months · Art 26(6)
- Worker information recordGenerate · Art 26(7)
- Monitoring plan & review cadenceGenerate — your responsibility
- Staff training records on the tool's limitsGenerate — your responsibility
Governance and security are the same problem, viewed twice
Security is not a separate checklist bolted on at the end — the integrity of a hiring decision depends on the integrity of the data and model behind it. Three lenses are useful here.
Data confidentiality
Applicant data is personal and often sensitive. Is it encrypted at rest and in transit? Who can access scores and raw CVs, and is that access logged? How long is data retained, and does retention align with what the DPIA justifies? Over-retention is both a security surface and a GDPR exposure.
Model integrity
Can inputs be manipulated to game the ranking — keyword-stuffed CVs, adversarial formatting? Is there version control, so you know which model version produced which decision? A model that silently updates behind a vendor API can change hiring behaviour with no audit trail.
Operational auditability
Are decisions logged in a way that lets you reconstruct why a given candidate was ranked where they were? Can anomalous behaviour — a sudden shift in pass rates for a demographic — be detected and investigated? Auditability is what turns "we oversee the system" from a claim into evidence.
The standards you'd measure "compliance" against don't fully exist yet
Here is the detail that separates primary-source reading from law-firm summary. The Act relies on harmonised European standards to give its requirements operational meaning — but the standards work is unfinished. The quality-management standard prEN 18286 reached a formal vote in 2026; the standard covering bias and data governance prEN 18283 hasn't yet completed a first draft. Where harmonised standards are missing, the Commission can fall back on Common Specifications Art 41.
When a vendor says the tool is "bias-tested and compliant," ask against what. There is no finished harmonised bias standard to certify against yet. That doesn't excuse anyone from managing bias — the obligation stands — but it means "certified compliant" claims should be read as vendor methodology, not third-party conformity to a settled benchmark. Separately, the Digital Omnibus widened the GDPR legal basis for processing special-category data specifically to detect and correct bias, under a strict-necessity standard — a signal that regulators expect active bias management, not a paperwork exercise.
What an HR director should actually do
Questions HR teams actually ask
The vendor says their tool is fully compliant. Are we covered?
No. The vendor's compliance covers the provider's obligations. As a deployer you have separate duties — human oversight, monitoring, logging, worker information and your own risk assessment Art 26 — that no vendor certificate discharges.
Does the Digital Omnibus mean we can stop worrying until 2027?
No. The application date moved to 2 December 2027, but the obligations are unchanged and the timeline is tied to a registration-and-readiness mechanism. Systems modified after the date can lose grandfathering. It's runway to prepare, not a reason to defer preparation.
Do we need to carry out a fundamental rights impact assessment (FRIA)?
Not automatically. The FRIA duty Art 27 binds public bodies, providers of public services, and credit/insurance deployers. A private-sector employer using recruitment AI isn't automatically in scope — though you'll still almost certainly owe a DPIA under GDPR, which covers much of the same ground.
Is a human glancing at the ranking enough to satisfy human oversight?
No — and this is where many programmes fail. Oversight must be meaningful: the reviewer needs the competence, authority and information to override, and must be positioned to do so Art 14. A glance that ratifies the ranking is exactly the automation bias the requirement exists to prevent.
Does GDPR apply on top of the AI Act here?
Yes — they stack. Automated rejection engages GDPR Art 22, CVs raise special-category data questions Art 9, and the profiling almost certainly requires a DPIA Art 35. Designing one strong oversight control can help satisfy both regimes at once.
What this analysis assumes — and where it would change
Assumptions made. That the tool scores and ranks (not merely deduplicates records), that the employer is private-sector, and that CVs are processed in the EU. Change any of these and the analysis shifts: a pure administrative de-duplication tool might reach for an Art 6(3) exception; a public-sector employer would owe a FRIA.
Where the law is clear. That recruitment ranking is high-risk, that profiling overrides the exceptions, and that provider and deployer duties are distinct. These are not close calls.
Where interpretation is required. What counts as "meaningful" oversight in a high-volume pipeline; how far a deployer must go to test a vendor's model on its own data; and how the unfinished standards landscape should shape what "reasonable" bias management looks like today.
How it travels. Swap recruitment for credit scoring and the FRIA becomes mandatory and the GDPR Art 22 stakes rise. Swap it for a healthcare triage tool and product-safety law layers on top. The method holds; the specific obligations move with the sector.