Blog
The EU AI Act: Do HR Need to Take Any Notice?
The EU AI Act has raised the bar for trustworthy AI. If you use HR tools in any way, here’s what the Act means for you, what to be aware of, and what to do next.
Share
Share
Timelines have changed but preparation should not
The EU Artificial Intelligence Act is the world's first artificial intelligence (AI) law, created to make sure that AI is used safely, fairly, and transparently. As the EU AI Act comes into force, the principles that SHL has built our leading assessments on, scientific validity, fairness, transparency, and robust governance, are helping customers meet their compliance obligations with confidence.
In a recent LinkedIn Live event alongside Sara Gutierrez, SHL's Chief Science Officer, and European Head of Strategic Sales, Alex Ratzel, we shared what we’re hearing from our customers and in the market about the EU AI Act, and its impact on organizations that use HR tools.
Don’t get caught out – check out our LinkedIn live replay for answers to some of the most common questions about the EU AI Act and HR tools.
Why "does it contain AI" is the wrong question
Organizations frequently want to know whether a tool "contains AI," either to avoid it entirely, believing this is the best way to mitigate risk and ensure compliance, or to chase it for efficiency's sake as business leaders push for more speed and scale with specific budgets allocated to AI projects. In the session, Sara summed up the issue with both these approaches, “AI is a technology, not a use case. What matters is what the system is actually doing, what decision it informs, and how consequential that decision is for the person on the other end of it.”
That distinction matters because the EU AI Act takes a risk-based approach. Recruitment, promotion, and other employment decisions are explicitly named as high risk under Annex III. But high risk does not mean forbidden. It means the obligations around documentation, fairness testing and oversight need to be taken seriously, whether you built the tool yourself or licensed it from a provider.
What is the difference between a ‘provider’ and a ‘deployer’ of AI?
The Act distinguishes between ‘providers’ (those that developed the AI, for example, SHL) and ‘deployers’ (companies using the system).
Most HR organizations are deployers, using AI tools built by someone else, including Applicant Tracking Systems (ATS), assessment tools, video-interviewing platforms, and any other tools that support workforce and performance management. While providers and deployers share compliance obligations under the Act, the deployer bears primary responsibility for AI risk within its own organization, as the level of risk is determined by the purpose of the intended use.
Within this law, providers are obligated to demonstrate compliance through documented risk management, strong data governance, transparency, human oversight, accuracy, robustness, cybersecurity, and post-market monitoring.
Human oversight is not a rubber stamp
One of the key areas of interest is the need for human oversight. It is tempting to assume that having a recruiter click "approve" on an AI recommendation satisfies the requirement that the Act makes around ‘human oversight.’ It does not. Article 14 of the Act calls for oversight by someone who understands the system's limitations, can interpret its output, and has real authority to disregard or override it. A workflow designed so the human effectively rubber stamps the machine has not created oversight, it has created the appearance of it.
As regulators are asking for more caution, the answer is not to stop using AI. Recruiters have never been able to speak with every applicant, which is exactly why data-driven tools have mattered for decades. The volume challenge is only growing as candidates use their own AI tools to apply faster and at greater scale. Organizations need better information, not less of it, to identify where their people should focus their attention. AI can help with that, but only if used responsibly, transparently, and by ensuring that human oversight is present in every people decision.
Meeting your responsibilities as a deployer of AI
Toward the end of the session, Sara walked through five practical questions every HR and TA leader should be asking about the AI already sitting inside their talent processes, from where it shows up across the employee lifecycle to whether the evidence behind it would hold up to a regulator or a candidate.
The key takeaway was that if you are still treating the EU AI Act as a future problem, high-risk obligations most relevant to employment use cases begin phasing in from December 2027, and the groundwork, documentation and oversight structures needed to meet them take real time to build.
With penalties of up to €35 million or 7% of total worldwide annual turnover for violations, HR teams need to take ownership of their tools and understand what questions they need to ask internally to build confidence in how AI is used across the organization.
Download our guide to what’s required of you under the EU AI Act containing a practical checklist breaking down deployer obligations into actions HR teams can take now.