The EU AI Act classifies recruitment and employee-evaluation software as high-risk AI. Here’s what that means for HR teams, and how MintHCM fits in.
The EU AI Act classifies recruitment and employee-evaluation software as high-risk AI. Here’s what that means for HR teams, and how MintHCM fits in.
The AI Act (Regulation EU 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. It applies to any organisation using AI to evaluate candidates, rank CVs, monitor employees, or make employment decisions affecting people in the EU, regardless of where the company or the software provider is based. Systems used for recruitment or employee evaluation are classified as high-risk, which triggers a specific set of obligations for the organisation deploying them.
The Digital Omnibus on AI has been formally adopted by the European Parliament (16 June 2026) and the Council of the EU (29 June 2026). Annex III high-risk obligations for recruitment and employee-evaluation systems shift from 2 August 2026 to 2 December 2027. Article 50 transparency obligations, including telling candidates that AI took part in evaluating them, still apply from 2 August 2026.
Does this apply to your HR system?
If your software ranks, filters, or evaluates people for recruitment or employment decisions, yes, regardless of where it was built or where your company is based.
Who’s responsible for compliance?
The organisation deploying the system, not the vendor. A vendor’s compliance claim does not transfer the obligation to you.
Financial penalties reach EUR 15 million or 3% of global annual turnover, whichever is higher. But the more disruptive risk is operational: a supervisory authority can order an AI system to be withdrawn from use in the middle of an active recruitment process.
Deployer obligations include human oversight for every AI-assisted decision, informing candidates that AI was involved, letting candidates request an explanation, keeping action logs for at least six months, and having technical documentation ready for an auditor.
| Date | What applies |
|---|---|
| 2 February 2025 | Ban on unacceptable AI practices, AI literacy obligations |
| 2 August 2025 | Rules for General Purpose AI (GPAI) models |
| 2 August 2026 | Article 50 transparency rules (candidates must be informed) |
| 2 December 2027 | Annex III high-risk obligations for recruitment and HR systems |
| 2 August 2028 | Annex I obligations for AI embedded in separately regulated products |
You can’t audit a system you can’t see.
Closed-source platforms like SAP SuccessFactors, Workday, or Oracle HCM can tell a regulator “trust us.” MintHCM lets you show the code. Every AI action taken through MCP is logged and traceable. Every decision path is inspectable on GitHub. You are not waiting on a vendor’s patch if the rules change, because you can change the system yourself.
| AI Act requirement | How MintHCM meets it |
|---|---|
| Algorithm auditability | Full source code available on GitHub |
| Human oversight | Human-in-the-loop confirmation before any significant AI action |
| Action logging | Every MCP action is logged and traceable |
| Data control | Self-hosting, EU-based hosting option |
| No vendor lock-in | Switch LLM providers (Claude, GPT, Gemini) freely |
Waiting until 2027 is not a strategy.
The extra runway is best spent building the habits that compliance requires anyway: a documented human oversight procedure, a way to inform candidates when AI is part of the process, and log retention that actually works. Start with an inventory of every tool in your HR stack that ranks, filters, or scores a person, and confirm whether it falls under Annex III.
Article
AI Act for HR: What You Need to Do Before 2 August 2026
The original breakdown: who’s affected, what’s required, and why open source HCM is structurally better positioned for algorithm auditability.
Article
AI Act Deadline Extension Confirmed
The update: what the Digital Omnibus changed, what stayed the same, and what it means in practice.