Employers using AI in recruitment may need to comply with two major EU legal frameworks at the same time: the GDPR and the AI Act.
They overlap, but they do not do the same thing. Complying with one does not automatically mean you comply with the other.
What does the GDPR regulate?
The GDPR focuses on the processing of personal data.
For recruitment AI, that means questions such as:
- What candidate data is processed?
- Why is it processed?
- What is the legal basis?
- Is the data necessary?
- How long is it kept?
- Who receives it?
- Is it transferred internationally?
- Are candidates properly informed?
- Is a Data Protection Impact Assessment required?
- Are automated decision-making rules relevant?
These obligations can apply whether the technology is called “AI” or not.
What does the AI Act regulate?
The AI Act regulates AI systems and imposes different rules depending on the type of system and the role of the organisation using or supplying it.
Certain AI systems intended for recruitment or selection of natural persons are classified as high-risk. This includes certain systems used to analyse and filter job applications and evaluate candidates.
Annex III point 4 is broader than hiring alone. It also reaches AI used for promotion and termination decisions, task allocation, and monitoring or evaluating the performance of workers. An employer that clears its recruitment tools but runs an AI performance or monitoring tool has not finished the exercise.
High-risk systems are subject to detailed requirements.
Is every use of AI in HR high-risk?
No.
The classification depends on the intended purpose and functionality of the system, and the AI Act contains relevant distinctions and exceptions that must be assessed carefully.
Using a general AI tool to improve the grammar of a vacancy is not the same as deploying an AI system intended to rank candidates.
Start with the actual use case rather than the label “AI”.
Provider or deployer?
Your obligations under the AI Act depend partly on your role.
A company that develops and places an AI recruitment system on the market may be a provider.
An employer that uses an AI system under its authority will often be a deployer.
However, organisations can take on different or additional responsibilities in certain circumstances, for example when substantially modifying a system or using it in ways that affect its intended purpose.
Do not assume the vendor carries every compliance obligation. Under the GDPR, the vendor’s role should also be recorded in your Third Party Dossier.
Where do the GDPR and AI Act overlap?
Both frameworks care about responsible processing and meaningful control, but they approach it differently.
Important overlapping areas include:
- Data quality
- Transparency
- Risk assessment
- Human oversight
- Security
- Documentation
- Accountability
- Fairness and potential bias
One assessment can inform another, but do not assume a GDPR DPIA automatically fulfils every AI Act requirement.
Automated decisions under the GDPR
Recruitment AI can also trigger Article 22 GDPR where a decision is based solely on automated processing and produces legal effects or similarly significantly affects the candidate.
This analysis remains necessary even if the AI system is also regulated as high-risk under the AI Act.
Timing matters
The AI Act entered into force in 2024 and applies according to a phased timetable, and that timetable moved in 2026.
The high-risk obligations for the standalone Annex III systems that cover recruitment and employment were originally due to apply from 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, deferred that date to 2 December 2027. Systems embedded in products already covered by EU product safety law move to 2 August 2028.
That deferral does not empty the calendar. The Article 50 transparency obligations were not postponed and have applied since 2 August 2026, so if candidates interact with a recruitment chatbot or receive AI-generated content, those duties are live now. The GDPR applies in full throughout, independently of the AI Act timetable.
The practical reading for employers: you have until December 2027 to meet the high-risk requirements for recruitment AI, and no extra time at all on transparency or on anything the GDPR already required.
Build one governance process
Instead of creating separate silos for privacy and AI, employers can create one intake process for recruitment technology.
Before a new tool is approved, ask:
- What does it do?
- Does it process personal data?
- What GDPR requirements apply?
- Is it an AI system under the AI Act?
- What is its risk classification?
- What role does our organisation have?
- What assessments and documentation are required?
- What human oversight is in place?
GDPRWise helps organisations build the GDPR side of this governance by mapping processing activities, data, legal bases, providers and privacy risks in a structured way.
GDPRWise maps your processing activities, legal bases, providers and privacy risks, giving you the GDPR half of an AI governance check in one place.