A recruiter opens a laptop and finds that software has screened 500 CVs overnight, scored every candidate, and produced a shortlist of 10. Ropes & Gray uses that example to ask the question most HR dashboards prefer to hide: did the system decide, or did it merely assist a human? That is not a philosophical exercise with better snacks. It is where the EU AI Act, GDPR automated decision making rules, and UK rules start pulling employers into different paperwork piles.
The timing is not theoretical. The European Commission says a Joint Research Centre survey drew on more than 70,000 workers across all 27 Member States, finding that 90% of workers in the EU use digital devices and 30% now use AI tools such as chatbots powered by large language models. Workplace AI has become ordinary enough to be procured by routine. That is exactly when a compliance issue stops being a memo and starts becoming deployment plumbing.
The compliance question starts before the demo
Ogletree Deakins frames the issue in its guide by Simon J. McMenemy and Nicola McCrudden as employer obligations under both the GDPR and the EU AI Act. The useful word is employer. The company buying the recruitment tool is not just choosing a feature set, it is deciding how candidates will be assessed, routed, and possibly excluded.
The European Commission describes the AI Act as setting risk based rules for AI developers and deployers. That deployer label matters because a vendor badge is not a legal force field. Before rollout, the employer needs a written account of what the tool does, which hiring step it affects, what candidate data it uses, and what a human reviewer is expected to check. If that sounds like procurement has become governance, yes, that is the point.
Assistance is not a magic word
Ropes & Gray points to Annex III(4) of the EU AI Act, which classifies AI systems as high risk where they are “intended to be used” for recruitment, selection, or evaluation decisions in the employment context. That captures more than the scary version of automation where a machine rejects candidates with no human in sight. A system that scores CVs, ranks applicants, or produces a shortlist can still shape the decision so strongly that the human review becomes theatre.
From 2 August 2026, Ropes & Gray says the classification question sits at the intersection of three frameworks: the EU AI Act, the GDPR automated decision making regime, and the UK Data (Use and Access) Act 2025. It also notes that the UK regime is lighter touch, which is lawyer for please stop reusing the same compliance slide in every country. The practical test for employers is whether the manager can genuinely depart from the system output, understands the basis for that output, and has time to review more than the top 10 names.
GDPR is the older trap in the room
IAPP reports that AI used in employment and the workplace is considered high risk under the AI Act if it can affect a person’s health and safety or employment, and that workplace emotion recognition systems are prohibited. IAPP also cites Cian O'Brien of Ireland's Data Protection Commission for the point that not all HR focused AI deployments are high risk. That distinction is not a loophole. It is a scoping exercise that must happen before someone signs the vendor order form.
GDPR remains the older trap because Ropes & Gray places recruitment AI inside the automated decision making analysis as well as the AI Act analysis. Employers should therefore treat data protection impact, candidate notice, lawful basis, and meaningful human involvement as design requirements, not post launch annotations. Transparency here is not a banner saying the company uses AI. It is enough operational detail for candidates, HR staff, and auditors to understand what role the system played.
What builders and buyers should change now
The European Commission survey found that 37% of workers say employers use AI and other tools for monitoring working hours, while 24% report algorithmic management involving automatic allocation or evaluation of work. Recruitment is part of that same workplace automation pattern. Once a tool touches access to work, it stops being only an efficiency project and becomes an accountability project.
For builders, that means separating scoring, ranking, and decision recommendations in the product design so customers can configure real human review. For buyers, it means vendor review should ask for training data summaries, performance documentation, bias testing information, audit support, and deletion or retention controls, then map those answers to the actual hiring workflow. Ogletree Deakins’ guide is useful because it moves the conversation away from whether AI recruiting is clever. The better question is whether the employer can explain the deployment without making its lawyers stare silently at the ceiling.
The next thing to watch is not another announcement about responsible AI in hiring. Watch the boring artifacts: procurement questionnaires, data processing records, manager instructions, candidate notices, and audit logs. That is where EU AI recruitment compliance will either become routine governance or an expensive reconstruction exercise.
Sources
- Deployment of AI Recruitment Tools in the EU: Employer Obligations Under GDPR and EU AI Act
- Helping Hand Or Complete Control? AI In Recruitment In The EU And UK
- AI Act | Shaping Europe's digital future - European Union
- Transparency, good data and documentation: How HR can navigate the EU AI Act
- Survey results show that one in three EU workers use AI tools at work - Employment, Social Affairs and Inclusion