EU AI Act Compliance
HR Tech Vendor EU AI Act Compliance: What ATS and Scoring Tools Must Do Now
If you sell AI-powered recruitment or performance management tools to EU customers, you already have obligations under the EU AI Act — and your buyers are starting to ask. Here is exactly what you need to know.
Your ATS Is a High-Risk AI System. Full Stop.
HR tech vendor EU AI Act compliance is not a future consideration. The clock started on 2 August 2024, when the EU AI Act entered into force. For vendors selling AI-powered applicant tracking systems (ATS), candidate scoring engines, or performance management tools into the EU market, the obligations are real, they are tiered, and your enterprise customers are already asking about them in procurement questionnaires.
The reason HR tech sits in the highest-scrutiny category is simple: Annex III of the EU AI Act explicitly lists AI systems used for recruitment and selection of natural persons, evaluation of candidates, and assessment of persons in employment relationships as high-risk AI systems. That classification does not depend on company size, revenue, or whether you are headquartered in Amsterdam or Atlanta. If your product makes, or materially contributes to, decisions about who gets interviewed, hired, promoted, or managed out, it is Annex III.
Provider Obligations: What Vendors Must Do
As a vendor, the EU AI Act classifies you as a provider under Article 3(3). Provider status comes with the heavier burden. Here is the concrete list:
Conformity assessment. Before placing your high-risk AI system on the EU market, you must complete a conformity assessment. For most HR tech providers, this is a self-assessment documented in a technical file, not a third-party audit, but that file must be comprehensive. It covers training data governance, algorithmic transparency, human oversight mechanisms, and accuracy metrics.
CE marking and EU Declaration of Conformity. Once conformity is assessed, your product requires a CE mark and a signed Declaration of Conformity as required by Article 48. No CE mark, no lawful sale into the EU after the high-risk provisions become fully applicable.
Registration in the EU database. High-risk AI systems must be registered in the EU-wide database maintained by the Commission before deployment. This is a public-facing step that your buyers will be able to verify.
Post-market monitoring. Article 72 requires providers to actively monitor system performance after deployment. You need a structured process to collect data on how your tool performs in real conditions, flag unexpected risks, and feed that back into the model.
Serious incident reporting. If your system contributes to a serious incident — a discriminatory hiring outcome, for example — you must report it to market surveillance authorities under Article 73. This is not optional, and it is not the deployer's problem to solve alone.
Instructions for use. You must supply your deployers with clear instructions covering intended use, known limitations, required human oversight steps, and prohibited applications. Vague documentation is a liability, not a safe harbour.
Deployer Obligations: What Your Customers Must Do
Your EU customers — the HR teams and People Ops departments actually running your software — are deployers under Article 26. Their obligations do not disappear just because they bought a compliant tool. They include:
- Implementing your instructions for use faithfully
- Ensuring meaningful human oversight of AI-assisted decisions (Article 14)
- Conducting a Fundamental Rights Impact Assessment (FRIA) before using the system for consequential HR decisions
- Providing AI literacy training to staff who interact with the system (Article 4)
- Keeping logs and making them available to regulators on request
Here is the commercial reality: a deployer who cannot demonstrate compliance will not renew your contract. Procurement teams at companies with more than 50 employees are already building AI governance checklists. Showing up to a sales conversation without answers to these questions means losing deals to vendors who have prepared.
The Dual-Obligation Overlap
Some vendors also deploy their own tools — for example, if you run an AI recruiting platform as a service and you are actively matching candidates to employer job posts. In that scenario, you wear both hats simultaneously. Recital 80 clarifies that a provider who also deploys their own high-risk system must fulfil both sets of obligations in parallel. That means your internal compliance and your customer-facing compliance documentation are distinct deliverables.
The boundary gets blurry when you offer white-label or API-based products. If a customer builds a candidate-scoring workflow on top of your API, they likely become the provider for that specific deployment. Your contract language needs to specify this clearly. Ambiguity here creates legal exposure for both parties.
Key Dates to Build Your Roadmap Around
The EU AI Act applies in phases. High-risk AI provisions under Annex III — the ones that directly affect HR tech — become fully applicable on 2 August 2026. That sounds like breathing room. It is not. The conformity assessment, technical file preparation, and registration process are not weekend projects. Vendors selling to large enterprise customers will face procurement requirements 12 to 18 months before the legal deadline. The first wave of informed buyers is already sending compliance questionnaires now.
The prohibited AI practices under Article 5 are already in force as of 2 February 2025. If your product uses social scoring or real-time emotion recognition in hiring contexts, that prohibition is live today.
What to Tell Prospects Asking About Compliance
When an HR Director or Compliance Officer asks whether your tool is EU AI Act compliant, here is the framework for a credible answer:
Confirm the classification. Tell them clearly that your system is classified as a high-risk AI system under Annex III, and that you are treating it accordingly. Downplaying the classification is a red flag to sophisticated buyers.
Describe your conformity assessment status. If you have a completed technical file, say so. If you are in progress, give a completion date. Vagueness signals unpreparedness.
Hand over the instructions for use. Proactively share the document that tells deployers how to implement human oversight. Buyers who receive this document without asking for it trust the vendor more.
Clarify what they must do. Walk the prospect through their Article 26 deployer obligations. Help them understand the FRIA requirement. This positions you as a compliance partner, not just a software seller.
Confirm your post-market monitoring process. Buyers want to know that if your model starts producing biased outputs in their environment, you will detect it and they will hear from you. Describe your monitoring cadence and escalation path.
This conversation, done well, shortens procurement cycles. Done poorly, it kills deals.
The Discrimination Risk You Cannot Ignore
HR AI sits at the intersection of the AI Act and the GDPR. Candidate scoring and performance assessment systems process special categories of data by inference, even if they are not explicitly ingesting protected attributes. The Dutch Autoriteit Persoonsgegevens has indicated active interest in algorithmic discrimination in recruitment contexts. Belgian and German data protection authorities are similarly engaged.
For vendors, this means bias testing must be documented, not assumed. Your technical file must include accuracy and fairness metrics broken down by demographic group to the extent your data allows. If you do not have that documentation, build it before your next enterprise sales cycle.
One Action to Take This Week
Pull your product's current documentation and ask one question: could a deployer's Compliance Officer read this and know exactly how to implement human oversight and conduct a FRIA? If the answer is no, that document is your first priority. Rewrite it to meet the standard required by Article 13 (transparency) and Article 26 (deployer instructions). That single deliverable will differentiate you in more sales conversations than any feature release this year.
Run your vendor compliance posture through the free 2-minute check at comply.khairos.ai to see exactly where your documentation gaps are before your next enterprise prospect asks.
# Need help getting compliant?
The free 2-minute compliance check shows you exactly where your gaps are. No email gate to see your score.
Start the free check →