Skip to content
Hirify

The AI Act and recruitment: what the law requires in 2026

Opaque scoring banned, explainable decisions, processing records: what changes for recruitment teams and their DPOs.

Author
By Robin Marquet
Published on
6 min read

The AI Act has been phasing in since 2024, and the stage that concerns recruitment is now enforceable. For HR teams and their DPOs, this is no longer something to keep an eye on. It's an audit topic.

We wrote this guide to answer the questions we've been hearing in demos for the past six months: what the law requires day to day, what becomes non-compliant in current practice, and what to ask an HR vendor before you sign.

Why recruitment is classified as "high risk"

The AI Act sorts AI systems by risk level. Recruitment, CV screening, and candidate evaluation fall into the high-risk category (Annex III of the regulation).

For companies, that translates into five cumulative obligations:

  • Document the system (purpose, data used, metrics).
  • Trace AI-assisted decisions.
  • Be able to explain to a candidate, in human terms, why their application was ranked the way it was.
  • Guarantee effective human oversight, with the ability to override the algorithmic decision.
  • Run a fundamental-rights impact assessment before deployment.

It's the combination of these requirements that changes how AI can be used inside a recruitment team, not just the usual GDPR compliance.

Opaque scoring is over

This is the most structural shift. A system that produces a numerical score for a candidate without being able to explain it in human-readable factors lands firmly in the red.

Candidate A gets an 87% match, candidate B gets 64%.

If you can't say in plain language what produces that 87% and that 64%, you don't have a compliant tool. You have a tool that makes a decision no one, not even you, can justify to a candidate or an authority.

Plenty of tools display a score on the grounds that it's "calculated from 12 weighted criteria." If the weighting is neither shown, nor editable, nor justifiable on an individual basis, you're still in opaque-scoring territory. The documentation work behind it isn't enough: what the user sees is a number, and that number isn't explainable in the sense the law intends.

Consumer generative AI becomes a trap

The second change, less visible but just as decisive, concerns consumer generative AI models that originate outside Europe. Not because the technology is bad, but because:

  • The data sent to the model leaves the EU.
  • The conversation history can be used for training, depending on the account and the settings.
  • No serious guarantee exists that the data is actually erased after use.
  • No record is kept on the vendor's side to answer a DPO or CNIL audit.

Recruitment teams work around it, and badly.

Today, CVs are anonymized before they're sent to ChatGPT, and the DPO is tearing their hair out.

TiffanyHead of Recruitment · Hirify target-ICP recruitment agency

It's become common practice. The recruiter copy-pastes a manually anonymized CV, or uses a third-party extension, or asks the AI to generate an interview outline from a job description without really knowing where the data goes. The DPO looks the other way or gets annoyed, and no one is compliant.

The six questions to ask before buying an HR tool

If you're evaluating an HR tool that includes AI, here are the questions to ask, and to get written into the contract, before you sign.

  1. Data location. Where is candidate data stored and processed? Can the vendor guarantee that no data leaves the EU?
  2. Training. Is client data used to train a model? If so, under what conditions, and can you opt out by default?
  3. Model used. Which AI model powers the tool? Is it auditable, or is it a black box supplied by a third party?
  4. Explainability. Does the tool produce scores? If so, can you see the criteria they're built from? If not, how are decisions presented to the recruiter?
  5. Retention. How long is candidate data kept? Does the vendor honor the right to erasure, with proof?
  6. Audit. Can the vendor provide logs on request for a DPO audit or a formal notice?

If even one of these answers stays vague, you're in a gray area.

The DPO becomes a decision-maker

Before the AI Act, the DPO often showed up at the end of the process: an audit after the purchase, a nod at the terms of service, a boilerplate letter. Now it's the DPO who has to sign off on the risk assessment (DPIA) before the system is deployed.

For a recruitment department, that means four things:

  • Bring the DPO in at the evaluation stage of an HR tool, not after the pilot.
  • Give them the vendor's technical documentation (model, data, hosting).
  • Update the records of processing to include the new system.
  • Set up an explicit channel for the candidate to object.

Teams that skip these steps expose themselves to concrete operational risk. A candidate complaint, a CNIL inspection, or a letter from a European authority is enough to trigger a demand for immediate compliance, which can block the tool for weeks.

Sovereignty moves from bonus to filtering criterion

The AI Act doesn't formally require choosing a European vendor. But in practice, a vendor hosted in the EU, with a model that keeps data inside the territory, simplifies the whole compliance file by an order of magnitude.

That's why "hosted in France" has gone, since 2025, from a marketing bonus to a filtering criterion in RFPs from agencies and IT services firms (ESNs). HR vendors whose product pages don't clearly state where candidate data is stored get eliminated on first reading. Still, you have to look past the flag, because what "sovereign" actually means, the vendor's jurisdiction, the Cloud Act, chapter V of the GDPR, decides how solid the file really is.

What makes Hirify easy to clear with a DPO

  • 100% France hosting on Scalingo (Paris datacenter). Candidate data never leaves European soil.
  • No opaque scoring. Hirify doesn't show a match percentage. The Hub surfaces qualified criteria (skill, experience, a constraint the candidate stated) that the recruiter reads like a profile.
  • Explainable decisions. Every enrichment of a candidate profile is traceable back to the interview transcript excerpt that justifies it.
  • No retraining on your data. By default, client data is not used to train any model, and that's written into the contract.
  • Documentation ready. The technical sheet the DPO needs to update the records of processing is provided on request, and the public commitments (host, subprocessors, security measures) are gathered on our Trust & security page.

This is the wedge we've seen on sales cycles since the AI Act took effect: less friction on the DPO side, faster signature, a deployment that actually gets used. Without that layer, you often see the DPO block a tool three months after the purchase, and the value is never delivered.

Key takeaways

  • Recruitment is high-risk under the AI Act: explainability, traceability, and human oversight are mandatory.
  • Opaque scoring is over. Any synthetic number has to be broken down into human-readable criteria.
  • Consumer generative AI isn't fit for processing CVs. Nearly all the uses we see today are non-compliant.
  • The DPO becomes an upstream decision-maker, no longer just a downstream validator. They're the first person to bring on board when choosing a tool.
  • Sovereign hosting simplifies the entire compliance file. It's no longer a bonus; it's become a filtering criterion.
Talent pool diagnostic

Shall we look at your talent pool together?

30 minutes to see, on your real ATS data, what Hirify can already recover and structure.

Estimate my ROI