The EU AI Act for Staffing Firms Placing Into Europe
Recruitment is named as a high-risk use case. If you place candidates into the EU, the obligations follow the candidate rather than your office.
The EU AI Act classifies AI used in recruitment and candidate selection as high-risk, which brings transparency, human oversight and record-keeping obligations. The point most staffing firms miss is jurisdictional: the rules follow where the candidate and the role sit, not where your delivery team does. An agency in Bengaluru placing into Frankfurt is inside the scope of this regulation.
Last reviewed August 2026. Summary of published regulation. Take legal advice before acting.
Key takeaways
- Recruitment AI is explicitly high-risk. Selection, screening and evaluation are named use cases rather than an interpretation.
- The rules follow the candidate, not your office. Placing into the EU from anywhere brings you into scope.
- Human oversight of automated decisions is required. A system that rejects without a person reviewing is not deployable.
- Your obligations depend on your role. Deploying a vendor's system is a different position from building one.

What the Act actually covers in hiring
The EU AI Act sets a risk-tiered framework, and AI used for recruitment, candidate selection and evaluation sits in the high-risk category rather than in a grey area someone has to argue about.
In practice that covers the systems most staffing firms are now using: automated screening, CV ranking, evaluation scoring, and AI-conducted interviews. It does not cover a scheduling tool or a CRM simply because it has automation in it. The trigger is whether the system contributes to a decision about a person's candidacy.
The obligations attach to that contribution. A system that ranks a shortlist is in scope even if a human makes the final call, because the ranking shaped what the human saw.
Why an Indian agency is in scope
The common assumption is that an agency without an EU entity is outside this. That is not how the scope works.
The Act applies where the AI system's output is used within the EU. If you screen candidates for a role based in Germany, or place people into an EU employer, the output is used there regardless of where your recruiters sit.
The practical version: if your client is in the EU or the role is in the EU, plan as though you are in scope. Your client will assume you are, and the contractual obligation will arrive from them before any regulator does.
The four obligations that matter operationally
Transparency to candidates. People should know when AI is being used in the process that assesses them, stated before the assessment rather than in a follow-up.
Human oversight of decisions. A person must be able to review, override and take responsibility. A workflow where a system rejects candidates without human review is the specific thing this prohibits.
Record keeping. Being able to show how a decision was reached. This is why an unexplainable score is a compliance problem as well as a usability one, which we cover in how AI interview scoring should work.
Bias and quality management. Testing that the system does not discriminate, and documenting that testing.
Provider versus deployer, and which you are
The Act distinguishes between the provider who builds an AI system and the deployer who uses it. Most staffing firms are deployers, which is the lighter set of obligations and not an absence of them.
As a deployer you are typically responsible for using the system as intended, ensuring human oversight actually happens, informing candidates, and keeping records of use. The provider carries the heavier burden around conformity, documentation and testing.
Two practical consequences. Ask your vendor for their documentation, because you may need it. And be careful about configuration: a deployer who modifies a system substantially can find themselves treated as a provider.
What to do this quarter
List every system that touches a candidacy decision. Screening, ranking, scoring, interviewing. Most firms have more than they think, including tools bought by individual recruiters.
Check where your human checkpoint is. For each system, name the person who reviews before a rejection. If there is not one, that is the first fix.
Write your candidate disclosure. One sentence, delivered before the assessment, saying that AI is being used and on whose behalf.
Ask your vendors for documentation. Bias auditing, how scores are produced, what data is retained. A vendor who cannot answer is a risk you are carrying.
Document your own process. Not elaborately. A page describing what is automated, who reviews, and what candidates are told.

Frequently asked questions
Does the EU AI Act apply to recruitment?
Yes. AI used for recruitment, candidate selection and evaluation is classified as high-risk, which brings transparency, human oversight, record-keeping and bias management obligations rather than an outright prohibition.
Does the EU AI Act apply to a staffing firm outside the EU?
It applies where the output of the AI system is used within the EU. An agency placing candidates into EU-based roles or for EU employers should plan as though it is in scope, regardless of where its recruiters sit.
Can AI reject candidates automatically under the EU AI Act?
Human oversight of automated decisions is required, which means a person must be able to review, override and take responsibility. A workflow where a system rejects without human review is the specific arrangement the rules target.
What is the difference between a provider and a deployer?
A provider builds the AI system and carries the heavier obligations around conformity, documentation and testing. A deployer uses it and is typically responsible for intended use, human oversight, candidate disclosure and records of use.
Do candidates have to be told AI is being used?
Transparency obligations mean people should know when AI is used in a process assessing them, stated before the assessment rather than afterwards. This is also good practice, since disclosure tends to improve completion rather than reduce it.
What should a staffing firm ask its ATS vendor about the AI Act?
For documentation on bias auditing, how scores are produced and can be explained, what data is retained and for how long, and whether the vendor considers itself a provider under the Act. A vendor who cannot answer is a risk you carry.
The one-page document worth writing
List every system in your process that contributes to a decision about a candidate, name the human who reviews each one before a rejection, and write the sentence candidates are told.
That page is most of what a client's legal team will ask for, and producing it in a meeting rather than promising to follow up is worth more commercially than the compliance itself.
See where the human checkpoint sits
Bring a live role and we will show you exactly which decisions are automated and which stay with your recruiter.
Book a demoFounder of Sortinghat, an AI-native ATS and CRM for staffing, search and RPO firms. Writes about recruiter capacity, sourcing economics and what actually changes when AI reaches a delivery desk. More about the author
Related reading