By Rafael Luque Ocaña

Recruitment: when HR is the business, high risk stops hiding

In almost any company, the high-risk system is the one HR uses. In a recruitment agency, HR and the business are the same thing — and the people being evaluated are not its own workers, which changes who has to be informed.

This article closes the sector block, and it does so with the edge case.

The idea that organises all the previous ones is that high risk is usually not in the business activity but in the software used to hire people: it goes unnoticed because it was bought by a department that doesn't take part in the conversation about AI.

In a recruitment agency, that distinction doesn't exist. HR isn't a department: it's the product.

What that solves, and what it doesn't

It solves the visibility problem. Here nobody forgets about the system: it's the tool used every day, the one demonstrated to the client, and the one that appears in the sales proposal. Nothing is hidden.

And it doesn't solve anything else. The obligation is identical, and it arrives through the same route:

“(a) AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates.”

With a difference in scale that isn't minor: where an ordinary company has a point 4 system applying to the applications it receives in a year, a recruitment firm has it applying continuously, at large volumes, and to people who are not going to work for it.

The asymmetry this sector has, and no other

Here something comes up that deserves to be read slowly, because it's specific to this case and the literal text says so.

Article 26(7) imposes an information obligation on the deployer:

“Deployers… who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system.”

Read the subject and the recipient. It talks about employers informing workers.

A recruitment agency uses the system on third-party candidates: people who are not its workers, and with whom it has no employment relationship and will not have one. The obligation in 26(7), as written, doesn't describe that situation.

That doesn't leave those people with nothing. They are data subjects under the GDPR, with their rights of information and access, and with the regime of Article 22 itself when the decision produces legal effects or significantly affects them — a threshold that isn't crossed automatically and that's assessed decision by decision, not system by system. And the client company, which will indeed be their employer if the hiring goes ahead, has its own obligations towards its workforce.

What there is is a split that isn't obvious, and it's worth putting in writing between the agency and its client before anyone asks. Not because any article requires it in those words, but because when the question arrives, the answer “we thought it was the other party's job” won't do.

And a question this sector should ask itself before any other

Are you still just a deployer?

A firm that uses a third party's recruitment tool, under that third party's brand and instructions, is a deployer. One that substantially modifies the system, markets it under its own name, or offers it as its own product to its clients may have changed roles — and with it, obligations, which stop being those of Article 26 and become those of the provider, which are different and considerably heavier.

It isn't a rhetorical question in a sector where the product tends to be built on third-party models and presented under its own brand. And it isn't answered here: it's answered by looking at the contract, the brand under which the service is provided, and what has been modified.

What's worth having sorted out

Three things, and none of them needs to wait until 2027.

What exactly the system does with each application. Filtering by objective criteria, scoring for fit, and ranking a list are not the same operation, and the explanation that will have to be given is different in each case.

Who reviews, with how much latitude, and with what authority. If the ranking the system proposes is always accepted, there is no review: there is an automated decision with a human intermediary.

What is kept from each process. Because the question that arrives months later —“why was this person rejected?”— is answered with what was recorded at the time, not with what is remembered.

The date, which here too is 2027

The Annex III regime starts on 2 December 2027, not before — and the wrong date circulating is August 2026. Today no agency is in breach through this route, and saying otherwise would mean using a deadline that doesn't exist.

What has been in force since 2 February 2025 is Article 4 on literacy —rewritten by the Digital Omnibus without ceasing to apply— and Article 5, which here has a prohibition with a name of its own: inferring emotions is not permitted in the workplace. A system that analyses expressions, tone, or gestures in an interview to deduce a candidate's emotional states isn't a classification problem. It's a practice that stops being used.

Content pursuant to Articles 4, 5, 25 and 26 and Annex III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJ 24 July 2026), and Article 22 of Regulation (EU) 2016/679.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.