Growth + Strategy

The EU Just Classified Every AI Hiring Tool as High-Risk. Fines Can Run Upwards of €35 Million.

July 10, 2026

The EU AI Act now treats every résumé screener, ranking tool, and matching engine in the hiring stack as high-risk. Fines reach €35M or 7% of global turnover—and the rules reach any U.S. employer a European candidate could apply to.

The EU Just Classified Every AI Hiring Tool as High-Risk. Fines Can Run Upwards of €35 Million.
Credit: Talent Observer

Somewhere in Berlin, a candidate who was rejected for a role three months ago is filing a request. They want to know the main factors behind the AI system's decision to take them out of the pipeline. Under the EU AI Act, the company that ran the screening has to answer. Producing an answer that holds up is a taller order.

This is the compliance reality that just landed on every talent team operating in or into the EU.

A €35 million wake-up call

The EU AI Act has classified AI systems used in employment decisions as high-risk, meaning any AI tool used for recruitment, selection, targeted job advertising, candidate evaluation, performance monitoring, or certain decisions about compliance, contract terms, or termination now sits in one of the strictest regulated tiers of the Act. The Act's penalty framework is layered. For deployers who fail to meet their high-risk system obligations, fines can reach up to €15 million or 3% of global annual turnover, whichever is higher.

The top ceiling of €35 million or 7% of turnover is reserved for use of prohibited AI practices, some of which apply directly in the workplace, including biometric categorization and emotion recognition. A separate tier of up to €7.5 million or 1% of turnover applies to providing incorrect or misleading information to regulators.

The penalty structure reframes AI hiring as a board-level compliance question, well beyond anything HR or legal was previously scoped to own.

The classification also applies extraterritorially. A U.S. company deploying an AI hiring tool for a role that could be filled by a candidate located in the EU is inside the scope of the Act, regardless of where the company is headquartered or where the technology is hosted. The perimeter is wider than most compliance teams have mapped.

Where high-risk applies

The scope of the classification is where the surprises are landing. High-risk covers any AI system used to make or materially inform a decision about employment, well beyond the AI video interviewers and personality-scoring bots that draw the headlines.

The classification reaches deeper than the standalone products marketed as AI. Likely in scope: the resumé-screening feature bolted onto every major ATS, the internal mobility recommendation engine sitting inside the HRIS, the skills-matching layer inside the learning platform, the promotion-readiness scoring inside the performance tool, and the AI-assisted job description generator that most talent teams have been using in recent years. The Act carves out a narrow exemption for tools performing purely procedural or preparatory tasks, but that exemption doesn't apply to any system that profiles candidates, which most matching, ranking, and evaluation tools do by design.

This means every talent and legal team is now scrambling to answer a question they haven't had to answer before: where every AI touchpoint sits in the hiring stack. A lot of the answers are going to come back incomplete, because the AI features were bundled into contracts signed with vendors who didn't flag the future classification when the SOW got signed.

The requirements for high-risk systems are extensive. Risk assessments, technical documentation, bias testing, human oversight, transparency to affected individuals, and continuous monitoring. Every deployed tool has to be inventoried, audited, and defended. The vendors carry part of the load. The deploying company carries the rest.

The overlooked exposure

The exposure has been building for years, and now classification put a fine on it.

Companies deploying AI screening tools have been making legally consequential employment decisions through opaque scoring systems for years. The candidate in Berlin filing a documentation request today has leverage that didn't exist before the Act came into force. Across every job req a large employer runs through an AI-touched process in a given year, the litigation surface adds up fast.

The reputational exposure is running on a parallel track. Once compliance disclosures become public record, the market gets to see which companies were using AI to decide who got hired, promoted, or let go. It's information candidates, employees, and journalists will act on. A company that hasn't thought through how it wants that disclosure to read will have its framing chosen by someone else.

The vendors selling these tools have a related problem. Most AI hiring products sold in recent years have operated with limited public transparency about how they work. Model architectures have generally been treated as competitive IP, training data has rarely been disclosed, and accuracy claims have typically gone unaudited. High-risk classification breaks that model. Every vendor is now facing pressure to explain what's inside the box, and a lot of them can't.

Compliance as a brand position

The companies moving fastest on this are running AI hiring compliance as a brand position, with the legal work as one input inside that.

How the disclosure lands is largely a question of timing. Companies that got in front of the requirements early are showing up in the market as credible on AI governance, which is turning into an employer-brand asset at a moment when candidates are watching closely. The delta shows up in candidate trust, employer-brand equity, and the caliber of the people willing to take a first-round call.

The audit itself is generating unexpected findings. Companies inventorying their AI hiring tools are discovering how many decisions they'd unknowingly outsourced to models nobody had reviewed, and how many of those models were making decisions the company wouldn't defend if asked. Some of the tools are getting turned off. Some are getting rebuilt with human review layers that should have been there from the start.

The compliance work is expensive. Skipping it carries a hefty cost per violation, a public disclosure record nobody controls the framing of, and an employer brand that becomes synonymous with algorithmic rejection at the moment the labor market punishes companies for that reputation.

The classification is the forcing function. The compliance work is going to happen on somebody's timeline. Right now, the company still gets to set that timeline, and the window on that closes as soon as the first major fine lands. Every company treating the classification as tomorrow's problem could soon find out that the AI hiring tool bought to save money is the most expensive line item on the ledger.

The best candidate is not in your city.

SiiRA connects US companies with top international talent — end to end, effortless.

Hire Top Talent

The best candidate is not in your city.

SiiRA connects US companies with top international talent — end to end, effortless.

See talent differently.

Get the latest ideas on hiring, leadership, and the future of work.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.