Is Your Screening Tool High-Risk Under the EU AI Act?
From August 2026, the EU AI Act treats AI used to screen, assess, or rank job candidates as high risk. Here is what that asks of talent teams, and why tools that can't explain their decisions are where the exposure is.

Suppose a candidate in Lyon applies for a job at your company, gets filtered out by the scoring feature in your ATS, and asks why. Could you tell her? I mean for her application specifically: what the system looked at, how it weighed it, and why someone else ranked higher.
I suspect most talent teams couldn't, and until recently that didn't matter much. From August 2026 it does, because that's when the EU AI Act's high-risk provisions for employment become enforceable. Most TA leaders haven't heard much about it, because the discussion has been happening in legal and IT and hasn't reached the people who choose and run the hiring tools.
The Act puts any AI system used to screen, assess, or rank job candidates in its high-risk category. That's broader than it sounds. It covers the resume scoring built into your ATS, AI-assisted interview tools, and voice screening systems. Where your company is based doesn't matter either. If a tool makes or informs hiring decisions about candidates in the EU, the obligation is yours.
The obligations are not light. For each high-risk system you need a documented risk assessment and evidence that it was tested for bias before deployment. You need human oversight that means something, as opposed to a person who approves whatever the system produced. Candidates have to be told that AI is involved in decisions about them. You also need audit trails good enough to reconstruct any individual screening decision after the fact. Fines for violations can reach 3% of global annual turnover, and national supervisory authorities have the power to investigate. My guess is that enforcement will start with whoever makes it easy.
Why would a company be easy? Mostly because of how these tools got bought. Someone chose the tool because it shortened time-to-shortlist. At procurement, nobody asked whether its ranking logic could be explained, whether a bias assessment existed, or whether it could produce an audit trail for a regulator. That was a sensible way to buy software when the only question was whether it worked. Now the same tool has to answer a second question, whether you could defend it to a regulator, and most buyers have never checked.
The companies in the worst position are probably the ones that stacked several tools: an ATS with built-in scoring, a separate resume screener, maybe an async video interview product on top. Each vendor may well have its own compliance documents. But a candidate who went through all of them was judged by a chain of systems, each opaque in its own way, and there may be no single record connecting what happened to a decision someone is accountable for. That gap is what a regulator reviewing a complaint would look for first.
The requirement TA teams seem to underestimate most is disclosure. Candidates have to be meaningfully informed when AI is making decisions about them, and a sentence buried in the privacy policy doesn't meet that. The disclosure has to be part of the process the candidate actually goes through, at the moment it applies. "We may use AI in our hiring process" tells a candidate almost nothing. Something like "this screening conversation is conducted by AI, and the results inform whether you advance" tells them what is happening.
Disclosure leads to a harder problem, though. Say your screener takes in a lot of inputs, combines them into a score, and shows you the score without showing its work. You can tell the candidate that AI was involved. You can't tell her why she ranked where she did, because you don't know either. No disclosure wording fixes that, since you can't disclose what you can't explain. If the system can't say in plain terms why candidate A ranked above candidate B, you have nothing to pass on to the candidate, and under the Act you'll need to.
So the question worth asking of any hiring tool is whether it can show its work. We make software that phones applicants and interviews them, and that question shaped most of how we built it. Each conversation is logged word for word as a structured exchange instead of being boiled down to a score, so when a candidate asks why they didn't advance, there's a record of what was discussed and which criteria were applied. The AI says it's an AI at the start of every conversation, so candidates know before they say a word. And the employer sets the screening criteria explicitly for each role before a campaign starts; we don't infer what matters from past hiring data that may carry old biases. That last choice matters more than it looks. When the criteria are written down and chosen by you, you can review them and explain why each one is relevant to the job, which is the first thing a regulator looking at a challenged decision will ask.
For recruiting agencies hiring for EU clients, each screened candidate arrives in their ATS with the conversation record and a structured qualification summary, and there's no ranking that nobody can explain. We didn't add any of this for compliance. It's how the system works by default, and it happens to be the kind of documentation the Act now asks for.
Compliance also isn't the first pressure on AI screening in hiring. Text-based screening was already breaking down before the regulators showed up, which is the subject of this post on AI-generated applications flooding your ATS.
The EU AI Act is the first employment AI law with real enforcement behind it. I don't think the companies that handle it well will be the ones with the biggest legal teams. They'll be the ones whose tools can say why a candidate was ranked where she was, in words both the candidate and a regulator could follow. There's a simple way to find out where you stand. Pick one candidate your AI tools screened out last month and try to explain the decision yourself.
Ready to transform your hiring strategy? Schedule a Demo with our founders today!
Badis Zormati
Co-Founder, Asendia AI

