Myths series

The EU AI Act bans AI — true or false?

Myths series · Article 1/10

EU AI Act timeline and obligations for recruiters.
The AI Act governs hiring AI — it does not ban it.

Since the European AI Act took effect, many HR and legal teams have frozen every AI project — including use cases that are already governed and deployed elsewhere in Europe. Headlines about bans and maximum fines created the impression of a total shutdown.

In reality, the AI Act does not prohibit AI in hiring. It classifies certain systems as high-risk under Annex III, category employment, workers management, and access to self-employment. This covers CV filtering, candidate ranking, and some selection tools — but subject to specific obligations, not a project stop.

For hiring leaders, the question is not whether you are allowed to use AI, but whether you are ready to document, inform, and supervise. Companies structuring compliance now turn regulatory pressure into a candidate-trust advantage.

What people say

« The EU AI Act bans AI. »

In practice

The AI Act governs high-risk HR systems through transparency, human oversight, and traceability — it does not ban them when Articles 9–15 and the application timeline are met.

Why this myth spreads

Media often reduce the law to a list of prohibited practices — subliminal manipulation, social scoring, workplace emotion recognition — without distinguishing structured pre-screening from the most sensitive systems. When a vendor says hiring is high-risk, the natural reflex is to pause everything.

Internally, confusion comes from stacking GDPR, the AI Act, and national labor law. Without a clear use-case map, HR, IT, and legal each assess a different risk and the project stalls at executive committee.

Yet lawmakers explicitly targeted high-impact access-to-employment use cases — not innovation itself. The goal is to ensure candidates know AI is involved and a human remains accountable.

Timeline to remember

The calendar is not everything banned tomorrow. Several milestones apply at different dates depending on system type.

For a voice pre-screening project launched in 2025–2026, priority is full high-risk compliance before 2 August 2026, when complete requirements apply to providers and deployers.

  • February 2025: prohibited practices (manipulation, social scoring, certain emotion inference).
  • August 2025: GPAI obligations and value-chain governance.
  • August 2026: full high-risk compliance — documentation, risk management, human oversight, logging.
  • Starting now avoids a rushed 2026 rollout without vendor documentation.
AI Act milestone timeline for recruitment use cases.

Annex III and concrete obligations (Articles 9–15)

A candidate screening or selection tool listed in Annex III must meet ongoing compliance — not a one-off checklist at contract signature.

Articles 9–15 require risk management, representative datasets, technical documentation, logs, transparency toward users and data subjects, effective human oversight, and robustness, cybersecurity, and accuracy where achievable.

  • Art. 9 — Risk management: identify and mitigate bias, errors, and misuse.
  • Art. 10 — Data: quality, relevance, and limits on training and inference data.
  • Art. 13 — Transparency: clear deployer instructions and candidate information.
  • Art. 14 — Human oversight: real ability to intervene, not fake automatic sign-off.
  • Art. 15 — Accuracy and robustness: documented performance on your real use cases.

Automated CV screening vs voice pre-screening

Not all hiring AI carries the same operational risk. Mass CV filtering on proxy criteria (school, zip code, employment gaps) concentrates discrimination risk that is hard to audit afterward.

Structured voice pre-screening — as HiLucy delivers with Lucy — asks the same questions to everyone, records transcribed answers, and produces criteria-based summaries for human review. Candidates know what to expect; recruiters validate before any next step.

This is not an automatic exemption from high-risk status, but a more transparent, auditable use than opaque scoring across thousands of CVs.

Five-step compliance plan

Here is an actionable plan you can launch in half a day with HR, your DPO, and procurement.

Step 1 — Map: list every AI touchpoint (sourcing, CV filter, chatbot, voice interview, scoring). Step 2 — Classify: confirm whether the vendor qualifies the system as Annex III high-risk. Step 3 — Document: require technical documentation, conformity assessment, and instructions for use. Step 4 — Inform: add AI disclosure in job posts, invitation emails, and privacy notice. Step 5 — Supervise: define who reads summaries, within what SLA, and how decisions are logged in your ATS.

  • Name an HR-side AI compliance owner (even part-time).
  • Add a dedicated line in your GDPR processing register.
  • Plan an annual fairness review by application source.
  • Contractually require vendor documentation updates.

What CNIL guidance adds

CNIL reminds that the AI Act and GDPR are cumulative: transparency, minimization, data-subject rights, and DPIA where processing is high-risk.

For recruitment systems, CNIL stresses fair candidate information, banning irrelevant processing (e.g. emotion analysis), and human recourse for significant decisions. A vendor like HiLucy that documents flows (audio → transcript → job criteria → summary) eases DPO review.

When in doubt, involve your DPO before deployment — not after the first pilot hire.

Key takeaway

The AI Act is a trust framework, not a veto: anticipate the 2026 deadline, implement Articles 9–15 with your vendor, and keep humans at the center of decisions.

Frequently asked questions

Does the AI Act ban AI in recruitment?

No. The AI Act classifies some hiring tools as high-risk and requires transparency, documentation, and human oversight — without banning their use.

When does the AI Act fully apply to hiring?

Obligations for high-risk systems, including algorithmic hiring, extend through 2026. Preparing now avoids last-minute compliance scrambles.

Want to move from reading to action? See how Hi Lucy automates your voice AI interviews and your approach to interviews powered by artificial intelligence.