AI in recruiting: what changes once CV screening becomes a regulated high-risk use
An algorithm that ranks or filters candidates is not a convenience feature under the EU AI Act — it is classified as high-risk, with obligations that follow. What that means in practice, and what the research says about the bias claims recruiting-AI vendors make.
A tool that screens, ranks or filters job applicants sits in a different regulatory category from a chatbot that answers a candidate’s question about the process. Under the EU AI Act, AI systems used in recruitment — screening or filtering applications, evaluating candidates, or making decisions that affect recruitment — are classified as high-risk, which brings a specific set of obligations rather than a general duty of care.
What the classification actually requires
A high-risk system used in recruitment needs documented risk management, a level of human oversight that can genuinely override the system rather than rubber-stamp it, technical documentation the employer can produce on request, and monitoring for the kind of discriminatory pattern that can emerge even from a tool with no explicit bias in its design. Candidates also have a right to know that an automated system is involved in the decision affecting them. None of this bans AI-assisted recruiting; it removes the option of treating it as a black box.
What the research says about vendor bias claims
This is not a hypothetical risk. A 2020 study by Manish Raghavan, Solon Barocas, Jon Kleinberg and Karen Levy, presented at the ACM Conference on Fairness, Accountability, and Transparency, examined 18 vendors of algorithmic pre-employment assessments and what each disclosed about how it tests for and mitigates bias. The finding worth remembering before signing a contract: vendor claims about bias mitigation were frequently vague or unverifiable from the outside, with critical methodological details left undisclosed — precisely the kind of gap the AI Act’s documentation requirement is designed to close.
- →Ask the vendor for the actual bias-testing methodology, not a marketing summary — if it cannot be produced or explained, treat that as a red flag rather than a formality.
- →Keep a human decision-maker who can see and override individual outcomes, not just review aggregate statistics after the fact.
- →Never let the system auto-reject silently — every filtered-out candidate should have a traceable reason a human could re-examine.
- →Log the criteria the system actually used per decision — the documentation obligation is not paperwork for its own sake, it is what lets you answer a regulator or a rejected candidate.
None of this argues against using AI to handle recruiting volume — a high application count is exactly where an assistant helps most. It argues for treating a screening tool the way the regulation already does: as a system that makes consequential decisions about people, not a convenience feature that happens to touch CVs.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
EU AI Act: what became mandatory on August 2, 2026 — and what it means for your SMB
19 August 2026·5 min read
Business & compliance
Claude now watermarks its text: what Anthropic’s move changes — and doesn’t — for your SMB’s AI content
18 August 2026·5 min read
Business & compliance
Computer History: ChatGPT now remembers your activity — except in France (for now)
17 August 2026·5 min read