Who Is Responsible Under the EU AI Act, You or Your Vendor?
The EU AI Act treats AI used to screen and rank job applicants as high-risk, and the companies using those tools have obligations of their own. What that means in plain terms, and what to look for in your tools.

Suppose your company uses an AI tool to sort and rank job applicants, and one day a regulator asks how it reached a decision about a particular candidate. Who answers? Most hiring teams would assume the vendor does. Under the EU AI Act, a good part of the answer has to come from you.
I'm not a lawyer, and anyone screening candidates in the EU should go through the details with one. But the basic shape of the law is simple enough to explain, and I think many teams have the wrong picture of where they stand.
The Act sorts AI systems by risk. Annex III lists the uses it treats as high-risk, and employment is on that list: systems used to recruit and select people, including tools that filter applications and evaluate candidates, as well as systems used for decisions about promotion and performance. There are narrow exceptions for tools that only do small procedural tasks, but a tool that assesses or ranks applicants is squarely what the list describes.
The high-risk label brings obligations, and they're split between two parties. The provider, meaning the vendor who builds the system, carries many of them, such as having the system assessed for conformity before it's sold. But the deployer, meaning the company that uses it, has obligations of its own. You have to use the system as intended, put real human oversight in place, keep the logs it produces, and tell the people it's being used on. The vendor can't do those things for you, because they're about how you run your own hiring.
This is the part I suspect most teams underestimate. It's natural to assume that buying from a reputable vendor transfers the risk. Here it doesn't, at least not all of it. If the tool you bought wasn't designed to support these obligations, you're the one who will struggle to meet them.
Plenty of tools weren't designed that way. There's a familiar kind of AI hiring product that looks responsible from the outside. It has a bias audit, a fairness statement in its documentation, and marketing about human-centered AI. What it often lacks are the things a deployer needs day to day. Candidates aren't told that AI was involved in screening them. A human has no practical way to review or override a particular decision. Nothing records individual decisions in a form you could hand over if asked.
The bias audit deserves a closer look, because it's what vendors point to most. An audit of aggregate historical data tells you how the system behaved on average. It tells you nothing about what happened to one candidate last Tuesday. And when a candidate complains or a regulator asks for documentation, the question is almost always about one candidate.
Oddly, the companies most exposed may be the early adopters. They have the longest history of running systems that were never built with any of this in mind.
None of this means taking AI out of hiring. What it means is using tools where the things the law cares about are part of how the system normally works, instead of policies added afterward. Candidates should know they're dealing with an AI at the moment it happens, and not from a clause in the terms of service. Every interaction should leave a record detailed enough that someone could later work out what happened with a given candidate and why. And a recruiter should be able to override the AI's assessment, with that override recorded as well.
You can try to retrofit all this onto a system that lacks it, and some companies will. The result, I'd expect, will often meet the letter of the rules while satisfying nobody, auditors included. Starting with tools that already work this way is much easier.
We had this kind of scrutiny in mind when we built Asendia. It phones applicants and runs a structured screening conversation with each one, and the first thing a candidate hears is that they're talking to an AI recruiter. Every conversation is recorded and documented, so there's a record of each candidate's screening from the first interaction.
What lands on the recruiter's desk is a ranked shortlist, and next to each name are verbatim notes from the call rather than a bare score. Asendia's job ends at first contact and qualification. People review the shortlist and make the real decisions, and because they're reading documented conversations, they have something concrete to agree or disagree with. Since that's simply how the workflow runs, human oversight doesn't have to be bolted on for compliance. The shortlist and notes are saved to the ATS. If you want more on the gap between what AI recruiting tools claim and what they do, there's a post on agentic recruiting that goes into it.
The Act didn't invent new ethics for hiring. Telling candidates when AI is involved, keeping records, and letting a person overrule the machine are things careful practitioners already thought were right. What's new is that they now have the force of law. Vendors who haven't said anything about their compliance status aren't necessarily acting in bad faith, since until recently nobody asked them. But someone is going to ask now, and it's better if that's you, reviewing your own tools, than a regulator responding to a complaint.
Ready to transform your hiring strategy? Schedule a Demo with our founders today!
Badis Zormati
Co-Founder, Asendia AI

