ViDA is here. What changes for your invoices, ERP and accounting
The EU adopted the VAT in the Digital Age package. From April 2025, member states can mandate e-invoicing. Here's what it means for your systems.
An ATS that stores CVs, schedules interviews or drafts a neutral job description is not automatically a high-risk AI system. Classification turns on the system's intended purpose and the way it is used. Under Annex III, employment uses such as targeted job advertising, analysing or filtering applications, evaluating candidates, making decisions affecting terms of work, promotion, termination, task allocation or worker monitoring need close assessment. The high-risk rules for Annex III systems apply from 2 December 2027. The AI Omnibus entered into force on 27 July 2026. The later 2 August 2028 date concerns high-risk AI that is a regulated product or safety component under Annex I, not ordinary recruitment software.
Article 6(3) matters. An Annex III use can be outside the high-risk class only when it presents no significant risk to health, safety or fundamental rights and does not materially influence a decision. The listed cases are a narrow procedural task, improving an already completed human activity, detecting patterns without replacing or influencing the reviewed human assessment, or a preparatory task. An Annex III system that profiles natural persons remains high-risk regardless of these exceptions. Record the intended purpose, inputs, output, who can override it and the reasoning for any exception. Do not relabel ranking as administrative support.
Ask: What exactly is the model intended to do? Does it rank, filter or recommend candidates? Which data and proxies are used? Is profiling involved? Can a recruiter see the reasons, correct data and override the result before a consequential decision? What evaluation, bias testing, change control and incident process exist? A supplier may be the provider, while an employer using the tool is usually the deployer. The roles have different duties.
For a high-risk system, the provider handles the required system controls, documentation, risk management and logs under its control. Article 19 requires those logs to be kept for an appropriate period of at least six months, unless other applicable law says otherwise. A deployer must follow instructions, monitor use, assign effective human oversight and inform affected workers or persons where the Act requires it. Human oversight is a real control, not a rubber stamp. GDPR Article 22 has its own test for solely automated decisions with legal or similarly significant effects. It does not create a blanket rule for every AI-assisted HR decision.
Article 27 does not require every private employer using HR AI to perform a fundamental-rights impact assessment. It targets public bodies, private entities providing public services and specified credit or life and health insurance uses. A DPIA may still be needed under GDPR, and existing work can be cross-referenced where the law allows. If AI affects pay, also review current national rules and our pay-transparency article.
Start with a technical audit. Map tools and purposes, classify each use, obtain supplier evidence, test representative workflows and document the human decision path. Contact us if you need help assessing an ATS or HR system.
The EU adopted the VAT in the Digital Age package. From April 2025, member states can mandate e-invoicing. Here's what it means for your systems.

Choose a first automation by scoring the work, data, risk, ownership, and reversibility. Then validate one pilot before you expand it.

Build a software or automation business case from measured current-process cost, TCO, scenarios, sensitivity analysis, and explicit stop criteria.