An employer using an AI agent to screen or interview candidates is the deployer under Regulation (EU) 2024/1689, not the provider. Article 26 puts the duties on you: assigned human oversight, input-data control, logs kept at least six months, worker notice before use. For Annex III employment systems they apply from 2 December 2027.
Every Article below was read in the consolidated text of the Regulation on EUR-Lex on 8 September 2026. This is general information about what a published text says, not legal advice. Employment law and AI regulation are jurisdiction-specific and the dates below have already moved once. Put your own deployment to your own counsel.
Provider or deployer? The definitions decide, not the contract
Article 3 of the AI Act settles the question before anyone opens a procurement document. A provider is a person or body that “develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark” (Article 3(3)). A deployer is “a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity” (Article 3(4)).
Buy a screening agent from a vendor, point it at your applicant pool, and you are using it under your authority. That is the whole test. It does not depend on how the licence agreement allocates risk, on whether you configured the model, or on whether you employ a single engineer. Both roles fall inside the definition of “operator” in Article 3(8), which is why the penalty article addresses them separately.
Scope reaches beyond the EU. Article 2(1)(b) catches deployers established or located in the Union; Article 2(1)(c) catches “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union”. An Australian employer screening applicants for a Dublin or Berlin role is reading the same text as a German one.
Is my screening agent high-risk? Annex III point 4(a), and the filter that removes almost nothing
Annex III point 4 covers “Employment, workers’ management and access to self-employment”. Point 4(a) is the recruitment limb, and the wording is broad: “AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates”. Point 4(b) picks up promotion, termination, task allocation and performance monitoring — so the same regime follows the person after they are hired. If you are still working out what the tool itself does before you work out who owes what, start with how AI recruitment screening agents handle sourcing, qualification and interview scheduling.
Article 6(3) offers a derogation: an Annex III system is not high-risk where it “does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making”, and only where it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing human assessment, or performs a preparatory task. Then the sentence that closes the door on most screening agents: “Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.”
Note who makes that call. Under Article 6(4) it is the provider who documents an assessment that its Annex III system is not high-risk, and who must then register under Article 49(2). A deployer relying on a vendor’s “not high-risk” position is relying on a document it should ask to see. Our jurisdiction-by-jurisdiction view of AI candidate-screening compliance across the EU, New York City, Illinois, Colorado and Australia covers what binds outside the AI Act; this page is the employer-side duty list inside it.
Provider vs deployer: who owes what, with the Article for each row
This is the table to take into a vendor call. Every row carries its provision. “Provider” means the obligation cannot be transferred to you by contract; “deployer” means buying a compliant tool does not discharge it.
| Obligation | Article | Falls on | What it means for an employer running a screening agent |
|---|---|---|---|
| Conformity assessment before the system is placed on the market or put into service | Art 16(f), Art 43 | Provider | You cannot perform it. Ask which assessment route was used and for the system version it covers. |
| EU declaration of conformity and CE marking | Art 16(g)–(h), Arts 47–48 | Provider | Ask to see the declaration and check it names the version you are licensing. |
| Quality management system and technical documentation | Art 16(c)–(d), Arts 17–18 | Provider | You do not get the technical file. You get the instructions for use, and everything you do hangs off them. |
| Instructions for use supplied to the deployer | Art 13 | Provider | The single most important artefact you receive. Without it, Article 26(1) is unauditable. |
| Human oversight designed into the system | Art 14(1), 14(3)(a) | Provider | The interface must let a person actually intervene, not just watch. |
| Automatic logging capability built into the system | Art 12 | Provider | Ask what is logged and whether the logs are exportable to you. |
| Registration of the high-risk system in the EU database | Art 49(1) | Provider | Deployer registration under Art 26(8) reaches deployers that are public authorities or Union institutions, bodies, offices or agencies — not private employers. |
| Use the system in accordance with the instructions for use | Art 26(1) | Deployer | Appropriate technical and organisational measures. Your configuration must match the documented intended purpose. |
| Assign human oversight to competent, trained, authorised people | Art 26(2) | Deployer | Name them. A hiring manager who glances at the shortlist is not an assignment. |
| Ensure input data is relevant and sufficiently representative | Art 26(4) | Deployer | Applies “to the extent the deployer exercises control over the input data” — your job-ad text, CV corpus, knock-out questions and score thresholds. |
| Keep automatically generated logs | Art 26(6) | Deployer | “for a period appropriate to the intended purpose of the high-risk AI system, of at least six months” — to the extent the logs are under your control. |
| Inform workers’ representatives and affected workers before putting into service at the workplace | Art 26(7) | Deployer (employers specifically) | Before, not after. Follows national information and consultation practice. |
| Tell the individual they are subject to the system | Art 26(11) | Deployer | Applies where the Annex III system makes or assists decisions about natural persons. |
| Monitor operation, inform the provider, suspend on risk, report serious incidents | Art 26(5), Arts 72–73 | Deployer (post-market monitoring plan sits with provider under Art 72) | Needs a runbook and a named owner, not goodwill. |
| Data protection impact assessment using the provider’s Article 13 information | Art 26(9), GDPR Art 35 | Deployer | The AI Act does not replace the DPIA; it feeds it. |
| Fundamental rights impact assessment | Art 27(1) | Deployer — but only public-law bodies, private entities providing public services, and Annex III 5(b)/(c) deployers | A private employer running a screening agent is generally outside this. Check whether you provide public services. |
| Explain an individual decision to the affected person | Art 86(1) | Deployer | Owed where the decision “produces legal effects or similarly significantly affects” the person adversely: “clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken”. Art 86(3) applies it only so far as the right is not already given by other Union law. |
| Cooperate with competent authorities | Art 26(12) | Deployer | Assume a market surveillance authority can ask for the artefacts below. |
| AI literacy of staff operating the system | Art 4(1) | Both | Already in force — Chapter I applied from 2 February 2025. |
| Disclosure that a person is interacting with an AI system | Art 50(1); Art 50(3) for emotion recognition and biometric categorisation | Provider (50(1)); Deployer (50(3)) | Chapter IV applies from 2 August 2026, independently of the high-risk timetable. |
| Rebranding or substantially modifying the system | Art 25(1) | Deployer becomes the Provider | Put your trademark on it, or substantially modify it, and Article 16 becomes yours. |
What applies today, and what waits until 2 December 2027
This is the part most published summaries have wrong, and it is worth showing the working. The consolidated text on EUR-Lex, read on 8 September 2026, is version 02024R1689 — EN — 27.07.2026 — 001.001. It carries one amendment: Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026 and titled, in part, “the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)”. EUR-Lex labels the consolidated text a documentation tool with “no legal effect”; the authentic version is the Official Journal.
Article 113 still says “It shall apply from 2 August 2026.” The exceptions are where the employment question is decided. Point (c), as replaced by the 2026 amendment, now reads: “Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I”.
Article 26 sits in Chapter III, Section 3. So do Article 16, Article 25 and Article 27. That is the deferral: the deployer obligation set for an Annex III employment system applies from 2 December 2027. The amending regulation’s own reasoning is the delay in standards and national authorities — “the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities”.
| Provision | Where it sits | Applies from | Set by |
|---|---|---|---|
| Article 4 — AI literacy for providers and deployers | Chapter I | 2 February 2025 | Art 113, third para, point (a) |
| Article 5 — prohibited practices, incl. 5(1)(f) emotion inference in the workplace | Chapter II | 2 February 2025 for 5(1)(f); the points inserted by the 2026 amendment — Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) — apply from 2 December 2026 | Art 113, third para, point (a), as replaced by Reg (EU) 2026/1744 |
| Article 99 — penalties framework | Chapter XII | 2 August 2025 | Art 113, third para, point (b) |
| Article 50 — transparency for certain AI systems | Chapter IV | 2 August 2026 | Art 113, second para (general date) |
| Articles 85–86 — complaints and right to explanation | Chapter IX, Section 4 | 2 August 2026 | Art 113, second para (general date) |
| Articles 16, 25, 26, 27 — provider and deployer obligations for Annex III high-risk | Chapter III, Section 3 | 2 December 2027 | Art 113, third para, point (c)(i), as amended by Reg (EU) 2026/1744 |
| Annex I high-risk (product safety components) | Chapter III, Sections 1–3 | 2 August 2028 | Art 113, third para, point (c)(ii), as amended |
Two honest caveats, because this is where a confident summary would mislead you. First, Article 86 gives an affected person a right to explanation of a decision based on “the output from a high-risk AI system listed in Annex III”, and Chapter IX carries no deferral — yet the classification rule that makes an employment system high-risk (Article 6(2), Chapter III Section 1) is itself deferred to December 2027. How those two interact between now and then is a question for counsel, not something the text resolves on its face. Second, the timetable has already been amended once; Article 112 requires the Commission to keep assessing Annex III annually, so re-read Article 113 before you rely on any date, including these.
Nothing about the deferral touches Article 5. Inferring emotions from a candidate is a prohibited practice, not a high-risk one: Article 5(1)(f) bans “the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons”, and it has applied since 2 February 2025. Whether a recruitment interview is “the workplace” for this purpose is exactly the scoping question to put to a lawyer before you buy a tool that scores tone, sentiment or enthusiasm.
Zian AI has been running outbound acquisition since 2017, and our AI agents run live phone, SMS, email and WhatsApp outreach, with private model deployment on customer infrastructure available where data control matters. If you want agents built by a team that reads the regulation text rather than the press release, Apply For Partnership to our current partnership-application beta.
The Article 26 evidence pack: nine artefacts an employer must be able to produce
Article 26 does not ask for a policy. It asks for things that exist. This is the readiness checklist we use when mapping a deployment, with each artefact traced to the provision that demands it. If you cannot produce the item, you do not hold the obligation — you hold an intention.
- Oversight roster — Article 26(2). Named natural persons with recorded competence, training and, critically, documented authority: the text requires “the necessary competence, training and authority, as well as the necessary support”. A reviewer who cannot overturn a rejection is not oversight. Our note on where human-in-the-loop review actually belongs in an agent workflow covers the design side of this.
- Instructions-for-use conformance note — Article 26(1) with Article 13. A written mapping of the vendor’s instructions to your live configuration, listing every setting you changed and why the change stays inside the documented intended purpose.
- Input-data statement — Article 26(4). What you feed the system: job-ad text, CV fields, screening questions, score thresholds, any historical hiring data. Plus your reasoning that the data is “relevant and sufficiently representative in view of the intended purpose”. This obligation bites only “to the extent the deployer exercises control over the input data” — so record what you control and what you do not.
- Log retention proof — Article 26(6) with Article 12. Evidence that logs under your control are retained for at least six months, with the chosen period justified against the intended purpose and against data-protection law, which the provision expressly preserves.
- Workforce notice, dated before go-live — Article 26(7). Evidence that workers’ representatives and affected workers were informed before the system was put into service or used, in line with national information and consultation practice. A retrospective email fails on its face.
- Candidate notice — Article 26(11), read with Article 50. The statement given to every natural person subject to a decision the system makes or assists. Article 26(11) is a deployer duty; Article 50(1) is a provider design duty — you need both to be true.
- Monitoring and escalation runbook — Article 26(5) with Articles 72 and 73. Who watches the system, what metric triggers suspension, and the contact path to the provider and the relevant market surveillance authority. The article requires you to suspend use and inform, “without undue delay”, where you have reason to consider the system presents a risk.
- DPIA cross-reference — Article 26(9). Your GDPR Article 35 assessment, showing it used the information the provider supplied under Article 13.
- Explanation procedure — Article 86(1). A repeatable way to give a rejected candidate an explanation of the role of the AI system in the decision and the main elements of the decision taken, where the decision produces legal effects or similarly significantly affects them and Union law does not already provide that right (Article 86(3)).
Nine artefacts, seven of which are documents you write rather than software you buy. That ratio is the point of this page.
Buying a compliant tool discharges nothing — and rebranding one makes you the provider
The commercially expensive misreading of the AI Act is that a CE-marked, conformity-assessed screening tool transfers the employer’s exposure to the vendor. It does not. Article 26 is addressed to deployers in its own terms, and Article 99(4)(e) makes “obligations of deployers pursuant to Article 26” a distinct head of liability from the provider obligations at Article 99(4)(a). The vendor’s conformity assessment says the tool can be used lawfully. It says nothing about whether you did.
The reverse trap is sharper. Article 25(1) converts a deployer into a provider in three situations: where “they put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated”; where “they make a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6”; or where they modify the intended purpose of a system so that it becomes high-risk.
White-labelling a screening agent into your careers portal under your own brand is squarely the first limb — and the article says contractual allocation does not save you. Article 25(2), as replaced by Regulation (EU) 2026/1744, then makes the handover explicit: “the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation”, though it must cooperate, hand over sufficient technical documentation, disclose known limitations and failure modes, and give targeted technical access. That cooperation duty falls away where the initial provider clearly specified that its system is not to be changed into a high-risk system — a clause worth reading in any licence before you rebrand anything.
On penalties, quote only the ceiling and treat it as a ceiling. Article 99(4) provides for administrative fines “up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher” for the listed heads, including deployer obligations under Article 26. Article 99(6) inverts that for SMEs and start-ups: the fine is capped at “the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower”. Article 99(1) leaves the actual penalty regime to Member States, requiring only that it be “effective, proportionate and dissuasive”. A maximum in a regulation is not a forecast of what any employer will pay.
What to ask your counsel, and what to ask the vendor
Four questions for counsel: whether your screening flow performs “profiling of natural persons” and so loses the Article 6(3) derogation; whether your recruitment interview sits inside “the workplace” for Article 5(1)(f); whether any national information-and-consultation rule adds process to Article 26(7); and whether Article 111(2) grandfathering helps you — it now applies the Regulation to systems placed on the market before Chapter III applies “only if, as from that date, those systems are subject to significant changes in their designs”.
Five for the vendor, all answerable in writing: the conformity assessment route and the version it covers; a copy of the instructions for use before contract, not after; whether logs are exportable to you and in what format, since Article 26(6) only reaches logs under your control; whether the vendor’s Article 6(4) documentation claims the system is not high-risk; and whether anything in the licence purports to reallocate Article 26 duties, which it cannot do. In every case the vendor’s marketing claim and the vendor’s documentation are different objects, and only one of them is evidence.
Frequently asked questions
Am I the provider or the deployer if I buy an AI screening tool?
The deployer. Article 3(4) defines a deployer as a body “using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity”. Running a bought tool against your applicant pool is use under your authority. You become a provider only in the Article 25(1) situations — putting your name or trademark on it, substantially modifying it, or modifying its intended purpose so that it becomes high-risk.
Does the EU AI Act apply to my company if we are based outside the EU?
It can. Article 2(1)(c) of Regulation (EU) 2024/1689 as consolidated on EUR-Lex extends the Regulation to “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union”. An Australian or US employer screening candidates for an EU-based role should assume it is in scope and take advice on the point.
When do the high-risk deployer duties for hiring actually start?
2 December 2027, on the text as it stands today. Article 113, third paragraph, point (c)(i) — as replaced by Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force from 27 July 2026 — applies Chapter III Sections 1, 2 and 3 from “2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III”. Article 26 is in Section 3. The general application date of the Regulation remains 2 August 2026, and this timetable has been amended once already.
Do I have to tell candidates that an AI is screening them?
Two separate provisions. Article 26(11) requires deployers of Annex III high-risk systems that make or assist decisions about natural persons to inform those persons that they are subject to the system — deferred with the rest of Chapter III Section 3. Article 50(1) requires providers to design systems intended to interact directly with natural persons so that people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person, and Chapter IV applies from 2 August 2026. Our Article 50 disclosure checklist works through the transparency limb.
Can an AI interview agent assess a candidate’s emotions or enthusiasm?
Article 5(1)(f) prohibits “the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions”, subject to a medical or safety exception, and that prohibition has applied since 2 February 2025 — it is not deferred. Emotion recognition is separately listed as high-risk at Annex III point 1(c). Whether a pre-employment interview falls inside “the workplace” is a question for counsel; the conservative reading is that tone, sentiment and enthusiasm scoring is the highest-risk feature you can switch on.
Does a private employer have to do a fundamental rights impact assessment?
Generally no. Article 27(1) directs the fundamental rights impact assessment at “deployers that are bodies governed by public law, or are private entities providing public services”, plus deployers of the Annex III point 5(b) and 5(c) systems — creditworthiness, and life and health insurance pricing. A private employer running a recruitment screening agent normally sits outside it, but still owes the Article 26(9) data protection impact assessment under Article 35 GDPR.
The provider ships a compliant tool; the employer still owes the evidence pack. If you want AI phone, SMS, email and WhatsApp agents — SmartReach AI™ for message, channel and timing, PrecisionPitch AI™ for continuous script testing, with private model deployment on customer infrastructure — Apply For Partnership to our current partnership-application beta.