Skip to main content

Regulation

Annex III Employment Systems: From CV Screening to Promotions

A practical guide to Annex III point 4 of the EU AI Act — which HR and workforce tools are caught, whether you are a provider or a deployer, and what evidence satisfies the duties.

Annex III Employment Systems: From CV Screening to Promotions

A mid-size employer runs a hiring process that touches AI in four places it has never thought about as one estate. The advert goes out through a programmatic platform that optimises who sees it. The applicant tracking system ranks CVs. A video interview tool scores answers. And someone in talent has built a sifting script on a commercial general-purpose model. Procurement asks one question — is any of this high-risk? — and the honest answer is that at least three almost certainly are, and the fourth may have turned the employer into a provider rather than a deployer.

Annex III point 4 is where employment AI lands, and it is the category most likely to be live already inside an ordinary organisation. The hard part is rarely the controls; it is establishing in writing which systems are caught and in which role.

What Annex III point 4 covers

The category splits in two. The first limb covers AI used for recruitment or selection of natural persons — in particular to place targeted job advertisements, to analyse and filter applications, and to evaluate candidates. The second covers AI used to make decisions affecting the terms of work-related relationships, promotion or termination, to allocate tasks based on individual behaviour or personal traits, and to monitor or evaluate performance and behaviour.

Three points get missed. Targeted job advertising is named expressly, so the media-buying tool marketing owns is in scope. The second limb reaches past hiring into task allocation, shift assignment and performance monitoring, putting workforce management tools in the same bracket as the ATS. And it is not confined to employees: work-related contractual relationships and access to self-employment bring contractor and platform arrangements inside the perimeter.

Already in force, Article 5 separately prohibits AI that infers emotions of a natural person in the workplace other than for medical or safety reasons, and biometric categorisation deducing characteristics such as race, political opinion or trade union membership. An interview tool sold on "engagement" or "candidate sentiment" scoring is not a high-risk problem to manage; it is a prohibited practice carrying exposure of up to 7% of global annual turnover.

Who the duty falls on

Most obligations — risk management, data governance, technical documentation, conformity assessment, CE marking, registration — fall on the provider: the party that develops the system and places it on the market under its own name or trademark. An employer buying a commercial ATS is normally the deployer, and deployer duties are a far shorter list.

The trap is that a deployer can become a provider. Under Article 25, a deployer takes on the full provider set if it puts its own name or trademark on a high-risk system already on the market; if it makes a substantial modification to such a system while it remains high-risk; or if it changes the intended purpose of a system — expressly including a general-purpose AI system — so that the system becomes high-risk. The homegrown sifting script is the textbook third case. The original provider then drops out, and the employer inherits a quality management system, technical documentation, conformity assessment, an EU declaration of conformity, database registration and post-market monitoring — which is why "who is the provider here?" is the first question in an assessment, not a footnote.

Typical useLimbUsual roleWatch for
Programmatic job advertising4(a)DeployerOwned outside HR; optimisation can discriminate in effect
ATS CV ranking4(a)DeployerThresholds and knock-out rules are your decisions
In-house model wired into sifting4(a)Likely providerArticle 25 change of intended purpose
Promotion or attrition scoring4(b)DeployerOften internally built; same Article 25 exposure
Shift and task allocation4(b)DeployerRarely recognised as in scope
Emotion scoring in interviewsArticle 5EitherProhibited, already applicable

The Article 6(3) exemption is narrower than it looks

Article 6(3) lets an Annex III system escape high-risk classification where it poses no significant risk of harm and meets one of four conditions: a narrow procedural task; improving the result of a previously completed human activity; detecting decision-making patterns or deviations without replacing or influencing the prior human assessment absent proper review; or a preparatory task to a relevant assessment.

Two limits bite in employment. A system that performs profiling of natural persons is always high-risk regardless of those conditions — and evaluating candidates on personal characteristics generally is profiling, which closes the exemption for most scoring tools. The exemption is also the provider's documented determination, made before market placement and registered accordingly. A deployer that reaches its own conclusion becomes the party asserting the classification, and should expect to defend it.

What a deployer must actually do

Article 26 and its neighbours are practical, and the evidence asked for is documentary.

  • Use the system in accordance with the provider's instructions for use, with measures that make deviation visible.
  • Assign human oversight to named natural persons with the competence, training, authority and support to exercise it — and record that the reviewer can and does override, not merely countersign.
  • Where you control input data, ensure it is relevant and sufficiently representative for the intended purpose. Role profiles, keyword weightings and historical hire data are input data.
  • Monitor operation, notify the provider and the market surveillance authority where a risk is identified, and suspend use where appropriate.
  • Retain automatically generated logs under your control for a period appropriate to the purpose and at least six months, unless other law provides otherwise.
  • Before workplace go-live, inform workers' representatives and the affected workers that they will be subject to the system — a specific employer duty, not a general transparency gesture.
  • Inform individuals subject to decisions made or assisted by the system, and be ready to explain its role and the main elements of the decision.
  • Meet the Article 4 AI literacy duty for staff operating these systems — already applicable, and cheap to evidence through training records.

Two duties are commonly over-scoped. The Article 27 fundamental rights impact assessment applies to public bodies, private providers of public services and deployers of certain creditworthiness and insurance systems — not to private employers on the basis of point 4 alone. Deployer registration in the EU database likewise falls on public authorities. Neither removes the likely need for a GDPR Article 35 data protection impact assessment.

Where this guidance stops

This is a map, not advice on your systems. Classification is fact-specific, and the Article 25 provider question turns on configuration, branding and contract detail that cannot be resolved from a description. UK organisations have no domestic equivalent statute: exposure runs through the Equality Act 2010, UK GDPR — where the automated decision-making rules have been reformed by recent legislation whose commencement should be checked — and, where output is used in the EU, the AI Act's extraterritorial reach. Penalties reach up to 3% of global annual turnover for most AI Act obligations, 7% for prohibited practices and 4% for data protection breaches; but discrimination claims are the more probable practical risk.

Take specialist advice where a system is internally built or reconfigured, where automated output influences dismissal or promotion, where representative bodies or collective agreements are engaged, or where a vendor declines to supply instructions for use and conformity documentation. That refusal is itself a finding: a deployer cannot build compliant use on a provider that cannot evidence its own compliance.

  • EU AI Act
  • Annex III
  • high-risk AI
  • recruitment
  • deployer obligations
  • HR technology

More guides

Start Free AI Compliance Review