Is AI CV screening high-risk under the EU AI Act?
Annex III classifies AI used to screen and filter job applications as high risk, with obligations applying from 2 December 2027.
Yes. Annex III of the EU AI Act lists AI systems used in employment for recruitment and selection as high-risk, and this expressly covers systems that screen or filter job applications and evaluate candidates. The classification itself is not in question and was not changed by the Digital Omnibus. What moved is the deadline: the obligations for these stand-alone high-risk systems, once due on 2 August 2026, now apply from 2 December 2027.
The question matters in 2026 because employers are procuring screening systems now, and those systems will still be in service when the obligations bite. UK employers also carry separate duties under UK GDPR and the Equality Act that apply today, on no timetable at all.
What does Annex III actually say about CV screening?
Annex III covers employment, workers management and access to self-employment. It captures AI systems intended for the recruitment or selection of natural persons, in particular for placing targeted job advertisements, analysing and filtering applications, and evaluating candidates. A system that ranks CVs, rejects applications below a threshold or shortlists candidates for interview sits squarely inside that wording.
The Act splits duties between the provider, who builds the system and places it on the market, and the deployer, who uses it. An employer buying screening software is almost always a deployer. Deployer duties are lighter than provider duties, but they are real, and they cannot be transferred to the vendor by contract.
When do the high-risk obligations actually apply?
The Act's prohibitions have applied since 2 February 2025, and the obligations on general-purpose AI models since August 2025. The high-risk obligations for Annex III systems, including recruitment AI, were originally due on 2 August 2026. The Digital Omnibus deferred them to 2 December 2027, with high-risk systems embedded in regulated products under Annex I moving to 2 August 2028. The Article 50 transparency duties are largely unchanged.
We read the deferral as a build window, not a reprieve. Oversight, logging and record-keeping cannot be retrofitted onto a screening pipeline in the final quarter before a deadline.
What must a deployer of screening AI build toward?
Four capabilities recur across the deployer obligations, and each is checkable.
- Human oversight: a named person with the competence and the authority to overrule a ranking, not a rubber stamp at the end of the pipeline.
- Logging: automatically generated logs of the system's operation, retained under the deployer's control.
- Candidate transparency: applicants told that AI is used in the process, in language they can act on.
- Records: the ability to show, for any individual rejection, what the system considered and what a human then did.
The last item is the hardest, and it is the one a tribunal or regulator will actually test.
What duties apply to UK employers today?
UK GDPR Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects, and rejecting a job application is widely treated as significant. Relying on screening AI without meaningful human involvement, a lawful route and an explanation the candidate can understand creates regulatory risk now, not in 2027.
The Equality Act adds discrimination risk. If a screening model filters applications in a way that disadvantages a protected group, that creates indirect discrimination risk today, and it is the employer, not the vendor, who answers for the hiring decision at a tribunal. A contractual promise that a model is unbiased is not a technical guarantee, and it is not evidence.
What evidence would a tribunal or regulator expect to see?
The practical standard is reconstruction. For a contested rejection, the employer should be able to produce the model version in use on the day, the inputs the system considered, the score or ranking it returned, the identity of the human who reviewed it, and what that human changed. We call this the reconstruction test: take one rejection from six months ago and rebuild the decision from records alone. If the logs live in a vendor's cloud, can be silently amended, or expire on a short vendor timetable, the test fails before it starts.
How does sovereign infrastructure change the picture?
The obligations point toward screening that runs on infrastructure the employer controls. Mickai is a Sovereign Intelligence Operating System, a SIOS that runs offline on operator-owned hardware. Every ranking decision is sealed to a post-quantum signed audit ledger, operator actions are bound to that record through hardware-attested identity, and a zero-egress perimeter means candidate data never leaves the building. Offline verifiability matters most: the sealed record can be checked by a third party without trusting the employer, the vendor or the network in between.
“A rejection an employer cannot reconstruct is a liability, and a rejection sealed to a verifiable audit record is a defence.”
How the whole architecture fits together is set out at /sovereign-ai, and the film at /film shows the interface in operation.
Frequently asked questions
Is my company a provider or a deployer if we buy AI CV screening from a vendor?
Almost always a deployer. The vendor who built the system and placed it on the market is the provider and carries the heavier obligations. An employer can become a provider by substantially modifying the system or marketing it under its own name, so heavy customisation deserves legal review before it happens.
Do I have to tell candidates that AI screened their CV?
Yes, in practice. Deployer transparency duties under the Act point that way on the deferred timeline, and UK GDPR requires fair processing information about automated decision-making today. Silent screening followed by an unexplained rejection is the fact pattern regulators and tribunals find easiest to act on.
Can I keep using AI CV screening before December 2027?
Yes. The Annex III classification does not ban recruitment AI, it conditions it, and those conditions bite from 2 December 2027. UK GDPR Article 22 and the Equality Act apply now, so human involvement, candidate information and decision records are already the prudent baseline rather than a future requirement.
What should I do if a rejected candidate challenges an AI screening decision?
Reconstruct it. Produce the record of what the system considered, the output it returned and the human review that followed. Employers who can do this from sealed logs resolve most challenges early. Employers who cannot are negotiating from weakness, whatever the underlying merits of the decision.
Does the deferral to 2027 mean I can pause compliance work?
We advise the opposite. The classification is settled, the duties are known, and the deferral is the time needed to put oversight, logging and sealed records in place before they are tested. Employers who build now choose their architecture. Employers who wait will take whatever is left.