1. Purpose and Scope
This document is intended as a working operational reference for recruitment agencies, staffing firms, and HR-technology companies operating in Ireland and across the European Union that use, or are considering using, AI systems as part of their hiring workflows.
It is written for operations directors, compliance managers, data protection officers, and employment law practitioners who need a precise and practically useful interpretation of the EU AI Act as it applies to their organisations.
What this document covers
- Relevant provisions of Regulation (EU) 2024/1689 applying to organisations deploying AI in employment decision-making
- Operational interpretation of those provisions for recruitment contexts
- Documentation and implementation guidance consistent with the regulatory framework
- The Irish regulatory environment as it currently stands
What this document does not cover
- GDPR compliance in relation to AI systems (a separate and overlapping body of obligations)
- General AI ethics frameworks
- AI systems used in contexts other than hiring and candidate assessment
- Provider obligations — obligations on the companies that build and sell AI systems rather than those that deploy them
- Obligations relating to general-purpose AI models under Title V of the Regulation
2. Source Methodology
This document draws exclusively on official primary sources. All article references are to the final published text of Regulation (EU) 2024/1689 as published in the Official Journal of the European Union on 12 July 2024 (OJ L 2024/1689).
Sources used
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024, published in OJ L, 12 July 2024
- EUR-Lex consolidated text of Regulation (EU) 2024/1689
- Recitals of Regulation (EU) 2024/1689
- Official EU AI Act timeline and implementation guidance from the European Commission
- Data Protection Commission (Ireland) published guidance on AI
This document does not rely on secondary commentary, legal blogs, consultancy white papers, or AI-generated summaries of the Regulation as authoritative sources. All article references correspond to the final published Regulation (EU) 2024/1689. Earlier draft proposals used different article numbering.
3. Regulatory Background and Timeline
Regulation (EU) 2024/1689 — commonly referred to as the EU AI Act — is a directly applicable EU regulation establishing harmonised rules governing the development, placing on the market, and use of artificial intelligence systems within the European Union. It was adopted on 13 March 2024, published in the Official Journal on 12 July 2024, and entered into force on 1 August 2024. As an EU Regulation, it is directly binding in all member states, including Ireland, without requiring transposition into national law.
Application timeline
| Milestone | Date | Scope |
|---|---|---|
| Entry into force | 1 August 2024 | Regulation enters EU legal order |
| Prohibited practices | 2 February 2025 | Chapter II prohibitions apply |
| General-purpose AI model rules | 2 August 2025 | Title V obligations apply |
| Article 50 transparency (chatbots, AI-generated content) | 2 August 2026 | Proactive disclosure obligations for AI-facing interfaces apply |
| Standalone high-risk AI systems (Annex III) — original deadline | 2 August 2026 | Extended — see note below |
| Standalone high-risk AI systems (Annex III) — revised deadline | 2 December 2027 | Title III applies in full, including employment AI under Annex III Point 4. Extended 16 months under the AI Digital Omnibus agreement, May 2026. |
| Annex I high-risk AI (limited) | 2 August 2028 | Systems covered by sectoral Union harmonisation legislation (extended 12 months under AI Digital Omnibus) |
Providers versus deployers
The EU AI Act distinguishes between two primary roles in the AI supply chain. Providers are organisations that develop, place on the market, or put into service an AI system under their own name or trademark (Article 3(3)). Deployers are natural or legal persons, public authorities, agencies or other bodies that use an AI system under their own authority, except where the AI system is used in the course of a personal non-professional activity (Article 3(4)).
For recruitment agencies, this distinction is critical. The organisations that build and sell AI screening tools, ATS platforms with AI features, or automated assessment products are generally providers. The recruitment agencies that integrate and use those tools in their hiring workflows are generally deployers. This document focuses exclusively on deployer obligations.
4. Who Is a Deployer? The Definitional Framework
Relevant legal text
"…any natural or legal person, public authority, agency or other body using an AI system under its own authority except where the AI system is used in the course of a personal non-professional activity."
— Article 3(4), Regulation (EU) 2024/1689
Operational interpretation
A recruitment agency that uses an AI-assisted applicant tracking system, an automated CV screening tool, a psychometric assessment platform, or an AI interview scoring product as part of its hiring process is, in most operational configurations, using that AI system "under its own authority." The agency determines which roles to apply the tool to, what data to input, and what decisions follow from the tool's outputs.
The "personal non-professional activity" carve-out is not relevant to organisations operating recruitment services commercially.
Practical checklist
- ☐Identify all AI tools currently used in your agency's recruitment workflow
- ☐For each tool, assess: does it evaluate, score, rank, or filter individual candidates?
- ☐For each such tool, assess: is your agency the entity that decides how and to whom the tool is applied?
- ☐If yes to both: your agency is likely a deployer, and the obligations described below may apply
5. Annex III, Point 4: High-Risk Classification in Employment
Relevant legal text
"4. Employment, workers management and access to self-employment: (a) AI systems intended to be used for recruitment or selection of natural persons, notably for advertising vacancies, screening or filtering applications, evaluating candidates in the course of interviews or tests; (b) AI systems intended to be used for making decisions on promotion and termination of work-related contractual relationships, for task allocation and for monitoring and evaluating performance and behaviour of persons in such relationships."
— Annex III, Point 4, Regulation (EU) 2024/1689
Operational interpretation
The phrase "intended to be used for recruitment or selection" is significant. The classification turns on the system's intended purpose, not solely on its technical sophistication. A basic automated filter that rejects applications not meeting stated criteria may qualify as readily as a more sophisticated machine learning-based scoring system, if the system is intended for use in applicant selection.
The inclusion of "screening or filtering applications" and "evaluating candidates in the course of interviews or tests" covers a broad range of tools currently common in recruitment workflows, including:
- Automated CV parsing tools that rank or filter applications before human review
- AI-assisted video interview platforms that score candidates on speaking patterns, content, or other inferred characteristics
- Psychometric testing platforms that generate automated rankings or suitability scores
- ATS systems with built-in match-scoring functionality
Suggested documentation
- ☐A written assessment of each AI tool used in recruitment workflows against Annex III, Point 4
- ☐Documentation of the reasoning behind any conclusion that a tool does or does not fall within the high-risk category
- ☐Date of assessment and identity of the person conducting it
6. Article 6: Classification Rules for High-Risk AI Systems
Relevant legal text
"AI systems referred to in Annex III shall be considered to be high-risk… Notwithstanding [the exception], an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons."
— Article 6(2) and 6(4), Regulation (EU) 2024/1689
Operational interpretation
Article 6 establishes a rebuttable presumption for Annex III systems: they are high-risk by default. A narrow exception exists where the system does not materially influence decision-making and does not pose significant risk to fundamental rights — but Article 6(4) closes this exception where the AI system performs profiling of natural persons.
For most recruitment tools that generate candidate scores, rankings, or suitability assessments, the Article 6(4) profiling provision means the high-risk classification is likely to apply regardless of the exception. Agencies should not assume the exception removes their tools from scope without specific, documented legal analysis.
7. Article 26: Core Obligations of Deployers
Article 26 of Regulation (EU) 2024/1689 sets out the principal obligations of deployers of high-risk AI systems. It is the central operative provision for any recruitment agency that concludes its AI tools meet the Annex III, Point 4 threshold.
7.1 Use in accordance with instructions (Article 26(1))
Deployers shall take appropriate technical and organisational measures to ensure they use high-risk AI systems in accordance with the instructions for use accompanying those systems. This requires operating the AI system within the parameters and for the purposes for which the system was developed and documented by the provider.
- ☐Obtain and retain the current instructions for use for each AI tool
- ☐Review each tool's documented intended use cases
- ☐Confirm that your agency's deployment of the tool aligns with those intended use cases
- ☐Document any deviations and the rationale for them
7.2 Human oversight assignment (Article 26(2))
Deployers shall assign the task of human oversight to natural persons who have the necessary competence, training, and authority, as well as the necessary support. Human oversight is not satisfied by the mere existence of a human at some stage of the recruitment process. The provision appears to require that the oversight function be formally assigned to an identified person with the ability to meaningfully evaluate the AI system's outputs and, where appropriate, disregard or override them.
- ☐Identify the person(s) who review AI outputs before hiring decisions are made
- ☐Formally document their designation as oversight officers
- ☐Confirm they have been provided with vendor documentation on the AI system's limitations
- ☐Confirm they have the authority to disregard or override AI outputs
- ☐Document the oversight process
7.3 Notification to workers and worker representatives (Article 26(3))
Where deployers are employers, they shall inform workers' representatives and the workers themselves, prior to deploying high-risk AI systems at work. For recruitment agencies, this provision clearly applies to the agency's use of AI in managing its own internal workforce.
7.4 Input data relevance
Deployers shall ensure that input data is relevant in view of the intended purpose of the high-risk AI system, to the extent they exercise control over such data. Where a recruitment agency controls the data fed into an AI screening tool — application form content, CV format, interview question structure — it should consider whether that data is appropriate and relevant for the tool's intended assessment function.
7.5 Record-keeping and log retention
Deployers shall keep the logs automatically generated by a high-risk AI system, to the extent such logs are under their control, for the applicable minimum retention period specified in the Regulation. Agencies should confirm with each AI vendor whether the system generates operational logs, whether those logs are accessible to the agency, and in what format.
- ☐Confirm whether each AI tool generates operational logs
- ☐Confirm whether those logs are accessible to your agency and in what format
- ☐Establish a retention process for any logs that are provided or accessible
- ☐Confirm whether the vendor's own data retention practices are aligned with this obligation
8. Article 13: What Your AI Vendor Must Provide
Relevant legal text
High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system's output and use it appropriately.
— Article 13(1), Regulation (EU) 2024/1689
Operational interpretation
Article 13 is a provider obligation — it imposes requirements on the companies that build and sell AI systems. However, it is directly operationally relevant to deployers for two reasons. First, the information that providers must supply under Article 13 is the same information that deployers need to fulfil their own obligations under Article 26. Second, deployers who do not receive Article 13-compliant documentation from their AI vendors are in a weaker position with respect to their own compliance obligations.
What to look for in vendor documentation
Under Article 13, a provider of a high-risk AI recruitment tool should, at minimum, provide documentation covering:
- The intended purpose of the AI system
- The system's technical capabilities and known limitations
- Performance metrics, including any data on accuracy or performance across different candidate demographics
- The type and nature of the training data used, in general terms
- Any known biases or performance disparities
- Instructions for the human oversight of the system's outputs
- Circumstances under which the system's outputs should not be relied upon
- ☐Request the full instructions for use and technical documentation from each AI vendor
- ☐Assess whether the documentation covers the Article 13 areas listed above
- ☐If documentation is incomplete, make a written request to the vendor for the missing information
- ☐Retain all vendor documentation and any correspondence regarding documentation requests
9. Article 14: Human Oversight Requirements
Relevant legal text
High-risk AI systems shall be designed and developed, including with appropriate human-machine interface tools, in such a way that they can be effectively overseen by natural persons during the period in which they are in use.
— Article 14(1), Regulation (EU) 2024/1689
Operational interpretation
Article 14 is partly a provider obligation (systems must be designed for human oversight) and partly a deployer obligation (oversight measures must be implemented in practice). The provision creates a shared responsibility: system design should enable meaningful oversight, and the deployer must actually exercise it.
Meaningful human oversight in a recruitment AI context means more than a human glancing at the AI output and approving it. It implies that the human reviewer:
- Can identify when the AI system may have produced an unreliable or anomalous result
- Has sufficient information about the system's limitations to identify such situations
- Has authority to override the AI system's recommendation
- Does not operate under process pressure that structurally undermines their ability to review independently
A process in which AI shortlisting results are presented to a recruiter with limited time for review, under volume pressure, may not constitute effective human oversight even if a human is nominally involved in the process.
- ☐Document the oversight process for each AI tool, including who reviews outputs and at what stage
- ☐Confirm that reviewers have access to vendor documentation on the AI system's limitations
- ☐Assess whether workflow conditions allow for meaningful review (time, information, authority)
- ☐Establish a process for recording instances where human reviewers override or adjust AI outputs
- ☐Include human oversight procedures in recruiter training materials
10. Article 86: Candidate Right to Explanation
Relevant legal text
"Any affected person subject to a decision taken by the deployer that is based on the output of a high-risk AI system listed in Annex III… and that produces legal effects or similarly significantly affects that person in a significant way, shall have the right to obtain from the deployer clear and meaningful explanations of the role that the AI system played in the decision-making procedure and the main elements of the decision taken."
— Article 86(1), Regulation (EU) 2024/1689
Operational interpretation
Article 86 creates an individual right exercisable by affected persons against the deployer — not against the AI vendor. The right is triggered where: (1) a deployer has made a decision; (2) that decision was based on the output of a high-risk AI system listed in Annex III; and (3) the decision produces legal effects or similarly significant effects on the affected person.
In a recruitment context, the "affected person" is a job applicant or candidate. A decision to reject, shortlist, or advance a candidate based in material part on the output of an Annex III high-risk AI system may trigger Article 86 rights, depending on the nature and effect of the decision on the candidate.
What an explanation under Article 86 should contain
The provision requires that explanations be "clear and meaningful" and cover the role the AI system played and the main elements of the decision. Operationally, this suggests agencies should be able to explain:
- What AI system was used and at what stage of the process
- What information was provided to the AI system
- What output the AI system produced (e.g., a score, a ranking, a recommendation)
- How that output was used in the decision
A response that merely states "we used AI in our hiring process" is unlikely to satisfy the "clear and meaningful" standard if a candidate requests explanation of a specific decision.
Article 86, Article 50, and the proactive versus reactive distinction
Article 86 creates a right to explanation upon request — it does not on its face require proactive notification to all candidates. However, this distinction is important to understand correctly, because a separate and earlier-applying provision does impose proactive obligations in certain recruitment contexts.
Article 50(1) — proactive obligation, applicable from 2 August 2026. Article 50 of the Regulation requires that natural persons who interact with AI systems must be informed that they are doing so, in a timely and clear manner. This obligation applies to the operator of the system. Where a recruitment agency deploys an AI chatbot to conduct initial candidate screening, or an AI-powered automated interview platform that candidates engage with directly, Article 50(1) requires that candidates be informed of the AI interaction proactively and in real time — not only upon subsequent request. This obligation applies from 2 August 2026 and was not extended by the AI Digital Omnibus agreement.
Article 86, by contrast, applies to decisions — the right to understand why an AI-assisted outcome was reached — and will apply from December 2027 alongside the full Annex III high-risk obligations. GDPR obligations, including transparency under Article 13 GDPR and rights relating to automated decision-making under Article 22 GDPR, may impose further disclosure requirements. The two frameworks should be assessed together with appropriate legal support.
- ☐Identify all AI systems used in your recruitment workflow that may trigger Article 86 obligations
- ☐Establish an internal process for receiving and responding to candidate explanation requests
- ☐Develop a template response covering the required elements (role of AI, main decision elements)
- ☐Confirm who in your organisation is responsible for handling Article 86 requests
- ☐Assess whether proactive candidate notification is appropriate given your workflow and GDPR obligations
11. Documentation Framework
The EU AI Act does not prescribe a single mandatory format for deployer documentation. However, the combined effect of the obligations described above points toward a set of records that deployers of high-risk AI systems in recruitment contexts are likely to need to maintain. The following is an operational framework — not a legal compliance certification.
11.1 AI Tools Register
- ☐System name and provider
- ☐Provider contact information
- ☐Intended purpose as documented by the vendor
- ☐Annex III classification assessment (including date and responsible person)
- ☐Risk level classification
- ☐Date of first deployment
- ☐Status (active / suspended / decommissioned)
11.2 Vendor Documentation File
- ☐Vendor instructions for use
- ☐Technical documentation provided by the vendor under Article 13
- ☐Any updates or amendments to that documentation
- ☐Written requests made to the vendor for documentation and vendor responses
- ☐Vendor terms of service and contractual provisions relevant to EU AI Act obligations
11.3 Human Oversight Designation Records
- ☐Written designation of the human oversight officer(s) for each AI tool
- ☐Record of training provided to oversight officers
- ☐Documentation of the oversight process
- ☐Records of instances where oversight officers overrode or adjusted AI outputs
11.4 Operational Log Records
- ☐Retained logs generated by AI systems, to the extent accessible
- ☐Maintained for the applicable retention period under Article 26
11.5 Article 86 Request Log
- ☐Log of any Article 86 explanation requests received from candidates
- ☐Agency responses and dates of response
12. Irish Regulatory Context
12.1 Ireland's AI regulatory structure — confirmed February 2026
In February 2026, the Irish Government published the General Scheme of the Regulation of Artificial Intelligence Bill 2026, which established Ireland's national framework for implementing the EU AI Act. Ireland has adopted a distributed model of AI oversight, rather than designating a single existing authority as the sole national competent authority.
The central coordinating body is a newly established independent office: Oifig Intleachta Shaorga na hÉireann (the AI Office of Ireland). This office acts as the single point of contact for EU-level coordination and oversees the implementation of the AI Act across Irish sectors. Alongside it, Ireland has designated fifteen sector-specific authorities as competent authorities for their respective domains.
12.2 The relevant authority for recruitment agencies
For recruitment agencies and HR technology operators, the designated sector-specific competent authority under the Irish AI regulatory framework is the Workplace Relations Commission (WRC). The WRC has been identified as the market surveillance authority responsible for supervising compliance with the EU AI Act in employment and labour market contexts. Recruitment agencies operating in Ireland should expect the WRC — in coordination with the AI Office of Ireland — to be the primary point of regulatory contact for AI Act enforcement in their sector.
12.3 Data Protection Commission
The DPC's primary statutory mandate is the GDPR and related data protection legislation. AI systems that process personal data of candidates are likely to engage both GDPR and EU AI Act frameworks simultaneously. The DPC has published guidance on the use of AI in the context of GDPR obligations, and has stated that the use of AI in hiring processes involving personal data of candidates requires careful attention to lawful basis, transparency, and automated decision-making provisions under GDPR.
Agencies should not treat EU AI Act compliance as a substitute for GDPR compliance. The two frameworks have overlapping but distinct requirements. Where a recruitment agency uses AI tools that process candidate personal data, it is likely to have obligations under both the WRC (as the AI Act competent authority for employment) and the DPC (as the data protection supervisory authority).
12.4 Intersection with Irish employment law
The Employment Equality Acts 1998–2015 prohibit discrimination in recruitment on grounds including gender, age, race, disability, and sexual orientation. Where AI recruitment tools produce outputs that have disparate impact on protected groups — even unintentionally — this may create exposure under Irish employment equality law independent of EU AI Act obligations. Agencies using AI tools should include assessment of potential discriminatory impact as part of their governance processes. The WRC, as the designated AI Act competent authority for employment, would be a natural forum for complaints at the intersection of AI use and employment equality.
13. Practical Guidance by Agency Profile
The following is operational guidance for agencies at different scales as they begin to assess their position. It is not a compliance certification framework.
Smaller agencies (under 20 staff)
Agencies of this size typically have fewer AI tools in active deployment. The most common configurations involve an ATS with AI-assisted matching features, or a standalone CV screening or psychometric tool.
- ☐Conduct an AI inventory: identify every AI tool used in any candidate-facing workflow
- ☐For each tool, request vendor documentation and instructions for use
- ☐Make an initial assessment of whether the tool falls within Annex III, Point 4
- ☐Identify who currently reviews AI outputs — that person is your de facto human oversight officer
- ☐Assess whether that person has access to vendor documentation on the tool's limitations
Mid-size agencies (20–100 staff)
Agencies in this range often have more diverse tool stacks and may have a designated operations or compliance lead.
- ☐Build a formal AI tools register as described in Section 11
- ☐Formalise human oversight designations in writing
- ☐Assess whether vendor documentation is adequate for each tool
- ☐Establish a candidate notice process for roles where AI tools are used in candidate evaluation
- ☐Establish an internal process for handling Article 86 candidate requests
Larger agencies (100+ staff)
Larger agencies may have dedicated compliance, legal, or HR operations functions and may operate across multiple EU jurisdictions.
- ☐Commission a formal AI system audit against Annex III criteria
- ☐Engage DPO (or equivalent) in the assessment of each AI system's data processing implications
- ☐Review vendor contracts for adequate Article 13 disclosures
- ☐Establish a data protection impact assessment (DPIA) process for any AI system determined to be high-risk
- ☐Consider board-level reporting on AI compliance status
14. Frequently Asked Questions
The deadline was August 2026. Has that changed?
Yes. On 7 May 2026, the European Parliament and the Council reached agreement on the AI Digital Omnibus regulation, which extended the deadline for standalone high-risk AI systems listed in Annex III — including AI systems used in employment and recruitment — from 2 August 2026 to 2 December 2027, a deferral of 16 months. The extension was driven by delays in completing required technical standards. Importantly, this extension does not apply to Article 50 transparency obligations, which still take effect on 2 August 2026 and require proactive disclosure to candidates interacting directly with AI systems (chatbots, automated screening interviews). Organisations should not interpret the Annex III extension as a reason to pause compliance preparation.
My agency uses an ATS with AI features. Does that automatically make us a deployer of a high-risk AI system?
Not automatically. The key question is whether the AI features are used to screen, filter, or evaluate candidates in a way that falls within Annex III, Point 4(a). If your ATS uses AI only for administrative functions — scheduling, email drafting — and not to evaluate or rank candidates, the high-risk classification may not apply. However, many modern ATS platforms include AI-assisted candidate matching or scoring features that are likely to require assessment. You should review the specific AI features you have enabled and how they function in your workflow.
Our AI vendor tells us they are 'EU AI Act compliant.' Does that mean we have no obligations as a deployer?
No. Vendor compliance as a provider relates to a different set of obligations under the Regulation. Deployer obligations under Article 26 are distinct and rest with the deployer — your agency — regardless of the provider's own compliance status. Your AI vendor's compliance does not satisfy your deployer obligations.
Do we need to notify every candidate that we use AI in recruitment?
The EU AI Act does not on its face require proactive notification to all candidates in all circumstances. Article 86 creates a right to explanation upon request rather than a blanket proactive disclosure requirement. However, GDPR obligations — including transparency under Article 13 GDPR and rights relating to automated decision-making under Article 22 GDPR — may impose disclosure requirements separately. The two frameworks should be assessed together. This is an area where independent legal advice is recommended.
We only use AI for sourcing (identifying candidates), not for screening applications. Are we in scope?
Annex III, Point 4(a) refers to AI systems used 'for recruitment or selection… notably for advertising vacancies.' The reference to advertising vacancies suggests that AI tools used to target job advertisements at specific candidate profiles may also be within scope. Agencies using AI-powered job ad targeting should assess the position carefully. This is an area of interpretive uncertainty as of the assessment date.
Does this apply to agencies using tools built by non-EU companies?
Yes. The EU AI Act applies to AI systems placed on the market in the EU or put into service in the EU, regardless of where the provider is established. Agencies established in Ireland using AI tools from US, UK, or other non-EU providers remain within scope as deployers.
What happens if we are not compliant by 2 August 2026?
The EU AI Act's penalty provisions apply from the date the obligations come into force. Enforcement is carried out by national market surveillance authorities and, for some matters, by the EU AI Office. The penalty framework under Article 99 includes significant potential fines. Enforcement approaches will depend on national authority capacity and priorities. Agencies should not assume the absence of immediate enforcement action means no risk — but should also not rely on non-specialist sources for predictions about enforcement likelihood.
15. Sources
- [1]Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L Series, 12 July 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202401689
- [2]EUR-Lex consolidated text of Regulation (EU) 2024/1689. https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32024R1689
- [3]Recitals to Regulation (EU) 2024/1689 (within full text at [1] above). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202401689
- [4]European Commission. EU AI Act — implementation and timeline. https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence
- [5]Data Protection Commission (Ireland). Published guidance on AI and data protection. https://www.dataprotection.ie
This document is published by Kadya for informational purposes only. Kadya is a compliance software company, not a law firm. Nothing in this document constitutes legal advice. Readers with specific compliance questions should seek independent legal counsel. © Kadya 2026. This document may be reproduced for non-commercial purposes with attribution.
