Your AI hiring tool might be high-risk under the AI Act. Here's what that means.
The AI Act applies fully from August 2, 2026. AI used for job ads, CV screening, and candidate scoring falls under high-risk rules. Practical compliance guide.
The AI Act is not only a topic for model providers and large technology companies. It also affects regular companies using AI in customer communication, HR, internal workflows, marketing, and decision processes.
The practical first step is not an 80-page legal memo. It is an AI register, a plain list of tools, purposes, data, owners, vendors, risks, logging, and human review. Without that list, a company often does not even know what needs to be assessed.
This article is not legal advice. It is a technical and organizational checklist for management, IT, and product owners.
The AI Act entered into force on 1 August 2024, but its obligations apply in stages. Prohibited practices and AI literacy obligations have applied since 2 February 2025. Rules for general-purpose AI models have applied since 2 August 2025. Transparency rules, including requirements relevant to chatbots and selected AI-generated content, apply from 2 August 2026.
Following the political agreement of 7 May 2026, obligations for selected high-risk systems, including employment use cases, are expected to apply from 2 December 2027. High-risk systems embedded in regulated products are expected to follow on 2 August 2028. Those extensions are not a reason to postpone an AI register, staff training, or transparency measures that a company already needs.
Start where AI talks to people, processes personal data, or may influence a decision.
Typical areas:
HR deserves special attention. If you use AI in hiring or employment, read our article on AI Act and high-risk HR AI.
On a smaller screen, scroll the table horizontally.
| Item | What to record |
|---|---|
| Tool name | for example web chatbot, CRM agent, HR screening |
| Owner | business owner and technical owner |
| Purpose | what the tool does and why |
| Data | inputs, personal data, sensitive data, sources |
| Vendor | custom solution, SaaS, API provider, model provider |
| Users | employees, customers, candidates, partners |
| Risk | low, medium, high, and why |
| Human review | where a person checks or approves output |
| Transparency | how the user is informed |
| Logging | what is logged and for how long |
| Status | idea, pilot, production, disabled |
An AI register is useful even outside compliance. Management can see where AI is duplicated, where data may leak, and where technical controls are missing.
Ask these questions for every internal AI workflow:
With custom software, these controls can be designed from the start. With SaaS tools, you need to ask what the vendor can actually provide.
RISE does not act as legal counsel. Our value is in technical implementation: AI registers, logging, approval workflows, role management, secure integrations, audits of existing tools, and lower-risk pilot design.
Compliance without implementation stays a document. Implementation without governance is a risk. A company needs both. If you want to map your AI tools and add technical controls, start with AI automation or contact us.
Yes. Depending on the use case, deployers or users of AI systems may have obligations. The scope depends on purpose and risk category.
According to the AI Act Service Desk, AI agents are not a separate category. The rules depend on what the agent does and which risk category the use case falls into.
Systems that interact with natural persons need transparency. The relevant rules apply from 2 August 2026. The exact wording and format depend on the implementation.
No. This is a technical and organizational checklist. For legal assessment, involve a lawyer or compliance specialist.
The AI Act applies fully from August 2, 2026. AI used for job ads, CV screening, and candidate scoring falls under high-risk rules. Practical compliance guide.

Choose a first automation by scoring the work, data, risk, ownership, and reversibility. Then validate one pilot before you expand it.
EU banks must send and receive instant payments by late 2025. Verification of payee is coming. Here's what it means for reconciliation, fraud prevention, and your ERP.