Using an AI tool to help sort a pile of job applications feels like an obvious time-saver — and plenty of small charities have quietly started doing it. But under the EU AI Act, AI used to recruit, screen or evaluate people for employment sits in the highest tier the regulation applies to routine business: it's high-risk. That single classification changes what's expected of you.
This article explains what the Act treats as high-risk recruitment AI, why the label matters even for a small organisation, where the timeline currently stands (it moved in 2026), and what a charity should actually do about it. It's written for people who run organisations, not for lawyers.
This article is general information, not legal advice. It does not constitute legal advice, and Vedomia does not provide legal services or certify compliance. For questions about your specific situation, speak to a qualified solicitor or employment-law adviser.
What the Act treats as "high-risk" here
The EU AI Act sorts AI systems into tiers. A small set of uses are banned outright; a large middle band carries lighter transparency duties; and a specific list — set out in Annex III of the Act — is classified as high-risk because of the impact those systems have on people's lives and rights.
Annex III, point 4 covers AI used in employment, workers management and access to self-employment. In plain terms, an AI system is high-risk when it is used to:
- score, rank or shortlist candidates in recruitment — including tools that read CVs or application text and sort them;
- target job advertising so that profiling decides which people see which roles;
- evaluate candidates during a selection process;
- make or materially inform decisions about promotion, task allocation or termination;
- monitor and evaluate the performance or behaviour of people at work.
For a charity, the most common trigger by far is the first one: feeding applications into an AI tool to summarise, score or shortlist them. It doesn't matter that the tool is a general assistant rather than dedicated "HR software" — what matters is the use. If AI output shapes who gets an interview, you're in Annex III territory.
The label isn't about how fancy the tool is. It's about what's at stake for the person on the other side — and a hiring decision is one of the higher-stakes things an organisation does to someone.
One honest caveat on scope: Annex III point 4 is framed around employment and workers. Recruiting paid staff clearly falls inside it. Selecting volunteers is a greyer area legally — but the same fairness, bias and transparency concerns apply to a person either way, so treating volunteer selection to the same standard is simply good practice.
The timeline — and why it moved
This is the part to get right, because it shifted during 2026.
Originally, the obligations for Annex III high-risk systems were due to apply from 2 August 2026. In 2026, however, the EU agreed a package known as the Digital Omnibus, which postpones the application of the stand-alone Annex III high-risk obligations to 2 December 2027 (with a later date again for AI built into regulated products). Public authorities using such systems face their own deadline.
Two important cautions on that relief:
- It is an agreement, not yet the finished law. A postponement like this only takes full legal effect once it is formally adopted and published in the EU's Official Journal. Until then it is the firm direction of travel, not a settled fact — so build your plans on it, but keep an eye on confirmation.
- A later deadline is not a pause on everything. Other duties bite regardless of this date. The AI-literacy duty (Article 4) has applied since February 2025. The Act's outright prohibitions are already live. And crucially, data-protection law already governs this exact scenario — see below.
The trap to avoid: reading "2027" as "nothing to do until then." The extra time is a gift for getting your house in order — not permission to keep sorting applicants through an AI black box with no oversight in the meantime.
The rule that already applies: automated decisions
Even before the AI Act's high-risk obligations land, there's a rule that has governed AI-assisted hiring for years: GDPR Article 22, on automated decisions. If a decision with a significant effect on someone — like rejecting a job application — is based solely on automated processing, the person has rights: to be told, to obtain human involvement, to express their view and to contest it.
The safe posture, and the one that also keeps you clear of the "solely automated" problem, is straightforward: a human being must make the actual shortlisting and hiring decisions, using the AI only as an input they can see, question and overrule. We cover this in more depth in our guide to Article 22 for charities.
What high-risk obligations look like (in plain terms)
You don't need to memorise the legal text, but it helps to know the shape of what's coming for deployers of high-risk recruitment AI. Broadly, you're expected to:
- Use the system as the provider intends. Follow the instructions for use that the tool's provider must supply — not improvise beyond them.
- Keep a human meaningfully in charge. Genuine human oversight of the output, not a rubber-stamp. A person who could, and sometimes does, disagree with the AI.
- Watch how it behaves. Monitor the system in use and be alert to problems — including bias that disadvantages particular groups of applicants.
- Keep records. Retain logs and evidence of how the system was used, so a decision can be reconstructed and explained later.
- Be transparent with the people affected. Applicants should be able to learn that AI was involved and what that meant for them.
Notice how much of that is simply good hiring practice with evidence attached. None of it requires you to be a technologist. It requires you to know what tool you're using, keep a person in charge, and be able to show what happened.
A practical checklist for your charity
If you use — or are tempted to use — AI anywhere in recruitment, work through this:
AI-in-Recruitment — Readiness Checklist
| Check | What good looks like |
|---|---|
| Do you know where AI touches hiring? | Every AI use in recruitment is listed in your AI register — including "informal" use of a general assistant. |
| Is a human making the decision? | A named person shortlists and decides; the AI is an input they can see and overrule. No candidate is rejected by the tool alone. |
| Could bias creep in? | You've thought about whether the tool could disadvantage groups of applicants, and you sanity-check its output rather than trusting the ranking. |
| Can you explain it to a candidate? | You could tell an applicant, plainly, that AI helped process applications and what role a human played. |
| Is it written down? | You keep a simple record of which tool, used how, with what human review — the evidence you'd want if asked. |
If you can't yet tick a row, that row is your next task — not a reason to panic.
How Vedomia can help
Vedomia is an Irish company focused on one thing: helping organisations make their processes and their use of AI visible, explainable and auditable. We work mainly with charities, nonprofits and publicly funded organisations.
Recruitment is a perfect example of why the groundwork matters: the high-risk label is manageable once you know where AI sits in your process, who's in charge of each decision, and what you can show afterwards. That's exactly what our free self-audit surfaces.
- Transparency Self-Audit (free). Around 20 questions across four pillars — Visibility, Sequence, Justification, Auditability — that help you find where AI shapes decisions about people and where your oversight and evidence are thin.
- Mapped with you (€1,450, one-off). A single 90-minute session: you describe how one key process really runs, Sandra maps it live, and you leave with a finished, official document — the process end to end, where AI enters it, the evidence to keep and a prioritised 30–90 day plan. No homework, and it begins with a free Clarity Call.
To be clear about what we do and don't do: Vedomia supports readiness, helps you document your AI use, and identifies transparency gaps. We do not certify compliance, and nothing we provide guarantees legal conformity. This is not legal advice.
You have longer than you thought to meet the full high-risk obligations — but the safe practices behind them are ones a careful charity should be following right now. Keep a person in charge of every hiring decision, know where your AI is, and write down what you do.
This article is general information about the EU AI Act and data-protection rules and does not constitute legal advice. Timelines under the Digital Omnibus were still being finalised at the time of writing.
Prepared with the help of an AI assistant, reviewed by Sandra Fedakova.
Not sure where AI shapes decisions about people in your organisation?
Take the Free Transparency Self-Audit