By Rafael Luque Ocaña

AI in recruitment: the high-risk zone arriving in December 2027

Filtering candidates with AI is one of [the uses the AI Act classifies as high-risk](/en/blog/high-risk-classification-guidelines-consultation). The Omnibus grants leeway until the end of 2027, but the documentation is worth starting sooner.

Update, 13 August 2026: the Annex III date of application cited in this article — 2 December 2027 — is the one set by Regulation (EU) 2026/1744, published in the Official Journal of the EU on 24 July 2026 and in force since 27 July 2026. At the time this article was published, the Omnibus was still a proposal, so the date was given then as anticipated and is now confirmed. The rest of the content is unchanged. A distributor handling hundreds of applications a month has an obvious incentive to automate filtering. A system that scores CVs, ranks candidates or discards profiles saves an enormous amount of work. It also places the company in one of the AI Act's most sensitive categories: employment. It's worth understanding why, on what timeline, and what can — and should — be documented starting now.

Why recruitment is high-risk

Annex III of the AI Act identifies a series of uses it considers high-risk because of their impact on people. Among them, expressly, systems intended for the selection or filtering of job applications, the evaluation of people in recruitment processes, and decisions on promotion or termination. The logic is direct: these are systems that decide on access to employment, an area where a bias in the model translates into real discrimination against specific people.

A distinction that decides the classification is key here. A system that informs is not the same as one that decides or pre-selects:

  • A chatbot that answers questions about a job offer or schedules an interview informs: it operates in the realm of transparency (Article 50).
  • A system that scores, ranks, screens, discards, pre-selects or recommends candidates falls under Annex III as high-risk.

What determines the classification is the system's intended purpose within the process, not the product's commercial name. The same module marketed as a "recruitment assistant" can fall on one side or the other depending on what it actually does with applications.

The calendar, after the Omnibus

With the Digital Omnibus, Annex III's high-risk obligations move from 2 August 2026 to 2 December 2027. In other words: a company using AI in recruitment has a window — until 2 December 2027 — before the full high-risk obligations apply, including the Article 27 FRIA, which follows the same timeline.

That window is real and worth using. But there are two reasons not to wait until the last quarter of 2027.

Reason 1: the GDPR already applies

A candidate-scoring system processes personal data, often with profiling. That triggers GDPR obligations that are in force today, regardless of the AI Act's timeline:

  • DPIA (Article 35), very likely when there is systematic evaluation of people with significant effects.
  • Automated decisions (Article 22): if the system rejects candidates without meaningful human intervention, this enters the territory of automated individual decision-making, with the reinforced safeguards that requires.
  • Legal bases and transparency towards candidates about the processing of their data.

None of this is postponed. It is enforceable now.

Reason 2: labour transparency

Beyond the AI Act, Spain has its own labour framework. Article 64.4.d) of the Workers' Statute — introduced by Law 12/2021, known as the "Rider Law" — grants workers' legal representatives the right to be informed of the parameters, rules and instructions underlying the algorithms or artificial intelligence systems that affect decisions capable of influencing working conditions, access to and retention of employment, including profiling. This is a general right to information — not limited to delivery platforms — in force since 2021 and with its own logic, independent of the AI Act's timeline. What matters for a company: this labour transparency does not wait for 2 December 2027.

The AI Act's Article 26(7) obligation — informing workers affected by a high-risk system at work — does follow the high-risk timeline and does not apply "yet". Article 26 applies from 2 December 2027 for the high-risk systems of Annex III and from 2 August 2028 for those of Annex I; it does not reach the products of Annex I, Section B (Article 113, third paragraph, point (c), and Article 2(2), as worded by Regulation (EU) 2026/1744). Article 27 does not bifurcate: it only reaches the high-risk systems referred to in Article 6(2) — those of Annex III — so its only date of application is 2 December 2027. The two should not be conflated, nor should the AI Act's obligation be presented as already in force ahead of time.

The risk no date on the calendar captures: bias

There's a reason no regulatory date captures, and it is, in practice, the most important one: a biased recruitment system discriminates against people today, not in 2027. There are well-known public precedents of recruitment tools withdrawn for systematically penalising certain profiles. Reputational damage and the risk of employment litigation over discrimination don't wait for the high-risk obligations to enter into force.

That's why, even though the full Annex III obligations arrive in 2027, evaluating bias and maintaining human oversight of the system are sound diligence from the very first day of use.

What to document now, even with time to go until December 2027

Without front-loading the full high-risk burden, there's work worth closing out now:

  1. Classify honestly each HR system according to what it actually does: does it inform, or does it pre-select? That's what determines the label.
  2. DPIA for scoring or filtering systems. A present-day GDPR obligation.
  3. Human oversight: ensure no application is rejected solely on the system's output, and keep a record of that control.
  4. Transparency towards candidates and, where applicable, towards workers' representatives — with the Spanish labour reference verified.
  5. Inventory and training (Article 4) for the team operating the tool.

The Omnibus postponement gives breathing room for the heaviest part of the high-risk file. It gives no breathing room for the GDPR, for bias, or for labour transparency. The company that keeps those three clocks properly separated uses the window in its favour. The one that assumes "everything got pushed to 2027" is exposed to what does apply today.

Mentions of products and cases are descriptive. This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.