Back

What Employers Owe Candidates Under the EU AI Act

The EU AI Act treats AI recruitment screening as high-risk. What Articles 12, 13 and 14 require, what falls on the employer rather than the vendor, and why explainable screening is also better hiring.

Ethical AI5 min read
What Employers Owe Candidates Under the EU AI Act

Most companies that use AI to screen candidates couldn't tell a rejected applicant why they were rejected. For years that didn't matter much. Under the EU AI Act it does, because the Act classifies AI used in recruitment and screening as high-risk, the same tier that covers AI in critical infrastructure and in medical devices.

High-risk doesn't mean banned. It means the system has to be able to account for itself, and several articles spell out what that involves. Under Article 13, a high-risk system must be transparent enough for the people using it to understand and interpret what it produces. Article 14 says humans must be able to oversee it effectively. That means being able to step in and change an outcome, a good deal more than glancing at a decision after the fact. And Article 12 requires the system to keep logs automatically, so that what it did can be traced later.

Now picture a screening tool that gives a candidate 72 out of 100, with no breakdown of which factors produced the number. The candidate is rejected and asks why, which the AI Act, and in some cases Article 22 of GDPR, gives people in the EU grounds to do. If your vendor can't produce an explanation, you're the one who has to answer.

That's where a lot of companies are exposed without realizing it. The Act distinguishes providers, who build and sell AI systems, from deployers, who put them to use. Providers carry the heavier load, including conformity assessments and technical documentation. But deployers have duties of their own. They have to use the system according to its instructions, give oversight to people with the training and authority to exercise it, keep the logs the system generates, and tell the people affected that a high-risk AI system is being used in decisions about them.

So a vendor's compliance statement settles less than people assume. Vendors selling in Europe are issuing them, and they tend to be vague, written more to reassure customers than to take anything off their plate. The statement records what you were told. It doesn't discharge what you owe. If your tool screened 400 candidates over a six-month campaign and you can't show how any of those decisions were reached, a FAQ page on the vendor's site won't help you much.

I don't know exactly when enforcement will start to bite, or who will be first. But recruitment looks like a likely early target to me: AI is used widely there, documentation is thin, and liability is fairly easy to establish.

What I find interesting is that the Act's requirements are mostly a description of how a good screening system ought to work anyway. Explanations, human oversight and decision logs sound like compliance overhead. But think about what a hiring manager does with a score that has no reasoning behind it. Either he stops trusting it and overrides it on instinct, or he trusts it completely and stops thinking. Neither gets you better hires than you had before the tool.

A process that leaves a readable record for every candidate, with the reasoning spelled out, is useful well beyond compliance. It's what you'd want the day someone files a discrimination complaint. It's also what you'd want the day you ask whether your screening criteria actually predict who becomes a strong hire. Building for the regulation and building a better product end up being mostly the same work.

That overlap is a large part of why we built Asendia around conversations instead of scores. We make software that phones applicants and interviews them, so the record it leaves is the conversation itself. If a candidate asks why they moved forward or didn't, there's something concrete to point to: what was discussed, which criteria were assessed, and the summary the recruiter received. A decision is much easier to explain when it was built from things a person actually said.

The same design keeps people in charge of the decisions that matter, which is what Article 14 is really asking for. The software handles the first screening call, and recruiters and hiring managers decide who goes further. We've written about where AI in recruiting really helps, and where it only adds a layer of false confidence, in our post on agentic recruiting.

If you hire in Europe, or your screening tool's output is used there, being headquartered somewhere else doesn't take you out of scope. I don't think the answer is to take AI out of recruiting. I'd start with a small exercise: pick a candidate your system rejected last month and try to explain in writing why. If you can't, that's the first thing to fix, and fixing it will probably make your hiring better as well as safer.

Ready to transform your hiring strategy? Schedule a Demo with our founders today!

Badis Zormati

Co-Founder, Asendia AI

Ready to transform your hiring strategy?

Schedule a Demo

Keep reading