EU AI Act Annex III hiring and workplace rules:
What employers need to know
The EU AI Act is the first comprehensive law written for artificial intelligence, and it treats the systems used to hire and manage people as one of its highest-risk categories. If you use AI to screen CVs, rank candidates, target job ads, score interviews, monitor productivity, or feed any of this into a promotion or a dismissal, you are running what the Act calls a high-risk AI system. These obligations come into force December 2027. If your hiring or workforce decisions touch anyone in the EU, the EU AI Act applies to you.
What is the EU AI Act, and how does it apply to employment AI?
The EU AI Act (Regulation (EU) 2024/1689) came into force on 1 August 2024 and applies in stages. It sorts AI systems by the risk they pose to people, focusing only on how the system impacts a person, independent of the technology or the size of the company. There are four tiers: a few banned practices, high-risk systems that carry heavy obligations, limited-risk systems that require only transparency, and minimal-risk systems with no obligations. One ban already applies and is worth noting: since February 2025 it has been illegal to use AI to infer workers' emotions in the workplace.
AI systems used for employment decisions sit in the high-risk tier. Annex III lists the high-risk uses, and point 4 is about work, in two halves. The first is recruitment and selection: targeting job ads, parsing and filtering applications, and evaluating candidates. The second, the one most people miss, is managing people once they are hired: promotion and termination decisions, allocating tasks by behaviour or traits, and monitoring or evaluating performance. That covers software nobody intuitively calls a hiring tool, like a productivity monitor that rates staff, an algorithm that assigns shifts by performance, or a model that predicts who will quit. If a system helps decide who gets hired, what they are paid, what work they get, or whether they keep the job, it is high-risk.
Why this matters now
High-risk obligations under Annex III come into effect 2 December 2027. Two things that already apply are the duty to ensure that staff have basic AI literacy, and the ban on workplace emotion recognition.
The Act extends beyond the EU: it applies whenever a system's output is used in the Union, so a US vendor screening candidates for European roles, or a US company hiring in Europe, is covered. Fines run to €35 million or 7% of worldwide turnover for banned practices and €15 million or 3% for most other breaches, but fines rarely arrive first. Regulators can pull a system, candidates and employees can demand to know it was used on them and ask for an explanation, and buyers want audit evidence.
What the EU AI Act requires
The Act treats every Annex III system as high-risk and only excludes assistive systems, meaning those posing no significant risk and that do no more than a narrow procedural or preparatory task. Anything that profiles people, evaluates or predicts personal aspects like performance or behaviour is covered. Most hiring and management tools do exactly that, so the exemption rarely applies. Teams often assume their AI is merely assistive and usually it is not — if it scores, ranks, or predicts, it is profiling, and a human in the loop doesn’t help. Oversight is one of the obligations, not a way around them, and a reviewer who approves the output does not reclassify an automated decision as a human one.
Your obligations depend on your role. A provider builds the system and markets it under its own name; a deployer uses it, and most employers are deployers. The heavy build-time obligations belong to the provider: risk management, data governance, documentation, logging, accuracy testing, and a conformity assessment before sale. But a deployer can become a provider without meaning to, by branding a bought-in tool as its own, changing it substantially, or wrapping a general-purpose model into its own screening pipeline.
Deployers must use the system as intended, give oversight to people with the authority to override it, keep the input data relevant, monitor it and suspend it if it causes harm, and keep its logs for at least six months. Two duties specific to the workplace require workers' representatives and affected employees to be informed before use, as well as anyone subject to a resulting decision where the system was used. One duty is widely misread, the fundamental-rights impact assessment, which falls on public bodies and a few sectors like credit and insurance, and not on an ordinary private employer.
The most stringent and heavy requirements concern bias. A provider must examine its training data for biases likely to cause discrimination and mitigate them, which interacts with another rule: testing whether a model discriminates by race, sex, or age needs data on those characteristics, which data-protection law restricts, especially in employment. The Act defines a narrow path here, allowing special-category data for bias detection only when strictly necessary, only when synthetic or anonymised data will not do, and only with safeguards. On the other side, the people affected must be told a system is in use and, where a decision matters, can ask for a clear explanation of its role.
Complying with Annex III hiring and employment AI requirements
For an organisation starting fresh, the work runs in sequence:
-
Find every AI system that touches an employment decision, from sourcing and screening through performance monitoring, scheduling, and exit, including features buried inside HR software and the informal use of chatbots by staff.
-
Classify each system against Annex III, recording its purpose and whether an exemption is genuinely available. Assume high-risk where the system profiles.
-
Classify your role for each system, provider or deployer, and check whether anything you have rebranded, modified, or built on a general model has made you a provider. Moreover, you must push the matching obligations into your vendor contracts.
-
Give someone clear ownership of AI governance, integrated into your existing risk and compliance structure.
-
Build data and bias controls, including a lawful route for the protected-characteristic data that bias testing needs.
-
Design real human oversight: named people with the training and authority to override the system.
-
Write the transparency notices and run the worker-representative consultation, and where national law requires it, do this before you choose vendors.
-
Test the systems for bias, accuracy, and explainability, and for bought-in tools, obtain and review the provider's documentation.
-
Keep the records: documentation, six-month logs, and the evidence behind every classification and test.
-
Monitor live systems for drift and failure, and act when a threshold is crossed.
This is an initiative that’s typically measured in quarters. The organisations that find 2027 comfortable are the ones doing the bulk of it now.
What ISO 42001 doesn't prove
Most of ISO 42001 is recognizable governance work, and done seriously it delivers something substantial. It forces an organization to answer questions it has usually been avoiding (who owns this, what could it do to people, how would we know if it broke) and it puts an independent party's name behind the answers. None of what follows is an argument against the standard. It is an argument about its extent and limits.
A certificate attests that an organization has built, and operates, a sound system for governing its AI. It does not attest that any particular AI system is accurate, fair, robust, or safe. Three things make that gap fundamental to ISO 42001 rather than incidental:
-
The scope can be narrow. You certify a defined boundary, and a certificate covering one customer-service chatbot says nothing about other AI systems the company runs.
-
The auditor checks the process, not the product. An assessor confirms that you ran your own bias test and kept the logs; the assessor does not independently run the test, evaluate the model, or red-team the system. The audit is of your governance, not of your AI.
-
The standard sets no technical bar. Because it is non-prescriptive, two organizations can both be fully certified while their actual systems differ enormously in how well they behave.
So when someone asks the question that brings most people to this topic — does ISO 42001 mean my AI is safe? — the honest answer is no, and the standard's own defenders say as much. One certified cloud provider notes plainly that the standard does not mandate specific AI controls; another concedes that it does not certify the accuracy of any specific model. What the certificate promises is more narrow: an independent body found that, for the AI in scope, this organization runs a governance system conforming to ISO 42001 at the time it was checked. It does not promise that the AI works.
That scoping is the purpose of the standard, but it leaves an obvious gap, and the gap is the part customers, regulators, and courts ultimately care about: whether the AI, when actually tested, behaves. Closing it takes the different discipline of independent, hands-on technical validation of how the systems themselves perform. That’s the natural complement to a governance certificate, and what the certificate, by design, doesn’t provide.
Where compliance gets most complicated
Most of this is ordinary governance work, but Annex III requires additional AI-bespoke technical efforts.
The first and biggest is testing for bias. Discrimination hides in subgroups an average score conceals, and persists in features that look neutral. Amazon built a recruiting tool that taught itself to downgrade CVs with the word "women's" and graduates of women's colleges, and scrapped the entire system; a 2024 University of Washington study found language models screening CVs favoured names associated with white applicants when nothing else changed. Removing the obvious signals does not fix it, because a name, a postcode, or a career gap can be a proxy for a protected trait.
Three more obligations sit alongside testing for bias: explaining an opaque model's decision, which the Act expects in clear terms; watching for drift, since a tool that passed last year's audit may have discriminated in the years before with no record to show otherwise; and validating a system you cannot see inside. The latter is most employers' position, because they buy tools rather than build them.
Underneath all four sits a feature of the law worth focusing on. For employment systems, the Act requires no independent check at all. Where biometric and certain product systems must be assessed by an accredited outside body, a provider of a hiring or workforce system assesses itself and declares conformity. The legal floor is the provider's own word and, for the deployer, whatever the provider chooses to share. By design, the law leaves the question buyers, regulators, and courts actually ask — whether the system behaves — to whoever decides to answer it.
How it fits with everything else
The Act does not stand alone. Its closest relative is the GDPR, which already restricts decisions made solely by machine where they significantly affect someone, and governs the data that bias testing needs. European equality law applies too, so a hiring tool can satisfy the AI Act and still discriminate unlawfully. National labour law can be much more stringent still: in Germany a works council can block a monitoring-capable tool until it agrees, and complete AI Act paperwork does not change that.
Abroad, the direction is clear as well, with existing US employment law regarding demographic bias also applying to AI system evaluations and decisions. Regional laws exist as well; for example, New York City has required an independent bias audit of hiring tools since 2023. Standards like ISO 42001 and the NIST framework are becoming base requirements, though none discharges the law or proves a system works.
Common questions
Is our recruiting tool really high-risk? Almost certainly, if it filters applications, ranks or scores candidates, or targets job ads. The exemption for assistive systems falls away once a tool profiles people, which ranking and scoring do.
Does this only cover hiring? No. It also covers managing people who already work for you: monitoring and evaluating performance, allocating work by behaviour or traits, and decisions on promotion and termination.
Do we need a fundamental-rights impact assessment? Usually not, if you are an ordinary private employer. That falls on public bodies, providers of public services, and sectors such as credit and insurance. You still owe the deployer or provider duties.
Does the Act apply to us if we are based outside the EU? Yes, if your system's output is used in the EU, such as any screening of candidates located in the EU.
Is a human reviewer enough to stay out of high-risk? No. Human oversight is a requirement of the high-risk regime, not an exemption from it, and a reviewer who simply approves the AI's output does not make the decision a human one.
When do the rules actually apply? The employment obligations apply as of December 2027, and AI literacy and the workplace emotion-recognition ban already apply.
Can we test for bias with data on protected characteristics? Only where it is strictly necessary, after trying synthetic or anonymised data, and with safeguards. The Act creates a narrow allowance for this.
Simplify EU AI Act compliance with Conformance AI
The organisations that will be ready for December 2027 are treating AI in their hiring and workforce decisions as something to test now. That technical work is what Conformance AI does, providing third-party validation and monitoring, and producing audit-ready documentation of unbiased AI system behavior in practice.
We are an independent, third-party check on AI systems: we evaluate hiring and HR models for biased and unfair outcomes, test whether their decisions can be explained, validate the vendor tools most employers depend on but cannot see inside, and monitor live systems for behavioural drift.
This is the part the law leaves to you. A hiring system under the EU AI Act is checked only by the organizations that built it and that run it. Procurement teams, regulators, and candidates increasingly want more, and one body of technical evidence can address several regimes at once: the EU AI Act, data-protection law, New York City's audit rule, and the standards buyers now expect.
If AI touches who you hire or how you manage them, independent validation will be what’s asked for by anybody positioned to inquire.
This article is general information, not legal advice. Confirm specifics against the current text of Regulation (EU) 2024/1689 and with your own advisors.


