What is the EU AI Act?

The EU Artificial Intelligence Act is the world's first artificial intelligence (AI) law, created to make sure that AI is used safely, fairly and transparently.

It introduces a risk-based framework that places obligations on AI providers and deployers according to the level of risk their systems pose.

And regardless of whether your organization is based in the EU or not, the Act applies if your AI system touches people – candidates or employees – located within the EU, or if the output is used within the EU.

"The significance of the EU AI Act is not that it slows innovation, but that it helps make innovation sustainable; clear rules create the foundation for responsible growth and long-term human-AI synergy."

Kuldeep Yadav
Senior Vice President AI, SHL

The EU AI Act Risk Classification

The Act classifies AI risk into four tiers from "unacceptable risk" to "minimal risk."

Unacceptable Risk

AI that is considered too harmful and an unacceptable risk, therefore banned.

Example: Social scoring of employees or candidates that uses unrelated personal data such as social media activity or credit history.

High Risk

HR SITS HERE

AI used in high-risk areas, so usage is permitted within regulatory guidelines.

Example: Tools using AI for recruiting, screening, selection, performance evaluation, or other employment-related decision-making.

Limited Risk

AI that requires transparency labels, so people know AI is being used.

Example: Using generative AI to draft a job posting, but not to target or filter candidates.

Minimal Risk

Everyday AI with low potential for harm.

Example: AI grammar tools used to draft offer letters.

Regulation (EU) 2024/1689 · Risk classification

High risk classification isn’t just a warning label, it is a requirement for an AI system to be compliant with specific criteria. These criteria cover safety, transparency, human oversight, data quality, accuracy and ongoing monitoring.

As the level of risk associated with an AI system is determined by the purpose of its intended use, HR organizations deploying the tools (deployers) bear the primary responsibility for ensuring compliance, regardless of whether the AI was developed in-house or by third-party vendors (providers).

To fulfil that responsibility, organizations must identify, understand, document and maintain every instance where AI is used across the employee lifecycle and assess the associated level of the risk.

Compliance with the Act isn’t just a regulatory exercise. It builds trust in employers’ responsible and transparent use of AI, giving employees and candidates confidence in its practices. And in a world increasingly shaped by AI, trust can become a strong competitive advantage.

Why You Should Act Now

Preparing for the EU AI Act is today’s priority

The full obligations for high-risk AI systems, including AI used in employment, were originally scheduled for 2 August 2026.  These have now been formally postponed to 2 December 2027; however, organizations should be preparing for compliance now.

Our focus is on helping our customers navigate the EU AI Act with confidence. That is why we have sequenced its compliance program on the original timetable and will incorporate any formally adopted amendments as regulations evolve.

Regulation entered into force

Regulation (EU) 2024/1689 adopted

Article 5 prohibitions and Article 4 AI literacy

Banned practices illegal. Providers and deployers must ensure staff have appropriate AI literacy

GPAI obligations and governance regime

Obligations on general-purpose AI providers and penalties / governance regime apply

Transparency obligations and broader AI Act enforcement

Original high-risk AI deadline, subsequently deferred to 2 Dec 2027

High-risk system rules apply in full

Full obligations for high-risk AI systems, including AI used in employment, apply

SHL’s Approach to AI Compliance

Helping HR and their organizations navigate complex regulation isn’t new to SHL. For nearly five decades, we’ve developed leading assessment solutions, AI and data insights around scientific validity, fairness, transparency, and robust governance.

As the EU AI Act raises the bar for trustworthy AI, those same principles will continue to underpin how we evolve our solutions and practices to help customers meet their compliance obligations with confidence, while maintaining the trust of their employees and candidates.

Compliant today, confident tomorrow.

Talk to our team

With SHL, You Benefit from AI You Can Trust

The eight fundamental principles of responsible AI provide the foundation for how SHL develops AI in alignment with the EU AI Act. 

Explainability

Every score traces to a defined competency under SHL’s Universal Competency Framework

Explainable scoring for every assessment, every time

Transparency

AI use clearly disclosed to candidates, where appropriate

Technical documentation and deployment guidance provided to all customers

Human oversight

AI assists; humans decide. No automated candidate rejection

Built-in workflow controls help ensure appropriate human oversight

Risk management

AI risk management process documented across the AI lifecycle

Risks assessed, mitigations tested, documented, and regularly reviewed

 

Data governance

Validation datasets assessed for bias and representativeness

Data lineage and governance controls documented and audited

Accuracy, robustness and cybersecurity

Models continuously monitored for performance and reliability

Cybersecurity independently audited through ISO/IEC 27001

Ongoing monitoring

Assessment score drift and emerging risks monitored continuously

Incidents  monitored, with robust processes supporting reporting and improvement 

 

Fairness and non-discrimination

Aligned with SIOP (Society for Industrial and Organizational Psychology) best-practice standards

Accessible, inclusive assessments continuously monitored for adverse impact.

"Organizations shouldn’t have to choose between innovation and confidence – and they shouldn’t have to navigate regulation alone.  Our role is to provide powerful assessment solutions with configurable AI that are not only innovative, but also grounded in robust governance, transparent practices and decades of reliable people science – so organizations can adopt AI with confidence."

Sheilendra Tomar
Head of Compliance and Data Protection Officer, SHL

FAQs

Your Questions on the EU AI Act, Answered

About the EU AI Act

When does the EU AI Act come into effect?

The full obligations for high-risk AI systems, including AI used in employment, were originally scheduled for 2 August 2026 but have been deferred to 2 December 2027.

What is the difference between a ‘provider’ and a ‘deployer’ of AI?

The Act distinguishes between ‘providers’ (those that developed the AI, for example, SHL) and ‘deployers’ (companies using the system). Most HR organizations are deployers, using AI tools built by someone else, including Applicant Tracking Systems (ATS), assessment tools, video-interviewing platforms, and any other tools that support workforce and performance management.

Within this law, the providers are obligated to demonstrate compliance documented risk management, strong data governance, transparency, human oversight, accuracy, robustness, cybersecurity and post-market monitoring.

The deployer bears the primary responsibility for AI risk within their organization as the level of risk is determined by the purpose of its intended use. To effectively manage AI risk, deployers must proactively catalog, assess, and categorize AI usage into risk tiers, including those embedded within SaaS solutions (“embedded AI”) and those leveraging pretrained models with enterprise data (“hybrid AI”).

What questions should I be asking my vendor?

To help ensure you have relevant compliance documentation and avoid leaving yourself open to unnecessary legal risk, it is important to understand how AI is used and works in your vendor’s offering. Here’s some basic questions that you may want to ask:

  • In language a hiring manager, regulator, or candidate can understand, can you explain how your AI model works?
  • How do you align with the EU AI Act?
  • Can you provide technical compliance documentation on how AI is used in your offering?
  • Who is responsible if this tool is found non-compliant?

Does using AI in hiring create legal risk for my organization?

The use of AI in hiring is lawful in the EU, UK and US, provided organizations comply with applicable AI and anti-discrimination laws. Legal risk should be a concern if AI is used without human oversight, documentation, fairness testing and candidate notification, not from the using AI itself.

How SHL Supports Compliance

Is SHL compliant with the EU AI Act?

SHL’s has designed its AI-enabled assessments to align with the requirements the EU AI Act places on providers of high-risk AI systems used in employment. Our approach incorporates robust risk management, data governance, transparency, human oversight, accuracy, robustness, cybersecurity and ongoing monitoring.

Beyond meeting our own obligations as a provider, SHL also equips customers with the documentation, transparency and guidance they need to support their responsibilities as deployers. 

Are you EU AI Act certified?

A vendor cannot obtain an “EU AI Act certificate” or be certified for a hiring tool. Any claims should be treated with caution.

A notified-body certification route exists under Annex VII, but it applies to other categories, such as certain biometric systems and AI embedded in regulated products, not to employment AI.

However, SHL follows the appropriate conformity assessment process required for its solutions. It is able to produce the technical documentation, bias testing, human-oversight design and post-market monitoring plan that fulfils the provider requirements.

Does SHL’s AI make hiring decisions on its own?

No. SHL’s AI assists scoring and surfaces insight; it does not auto-reject candidates. Final decisions are made by humans, consistent with Article 14 of the EU AI Act. 

How does SHL demonstrate that its AI is fair?

SHL uses three key mechanisms to ensure fairness:

Design: Industrial-organizational psychologists define the construct and predictive rationale.

Testing: Adverse impact analysis is performed across protected groups prior to launch and documented in technical manuals. 

Monitoring: Live dashboards track scoring patterns across demographics in production. Where drift or disparity is identified, models are recalibrated or retired. 

Beyond the Legislation

The EU AI Act is just one part of the evolving AI landscape. Discover more insights, guidance, and resources on AI in talent assessment.

Explore the resources