IsimioIsimio
Back to the blog
ComplianceAIIndustry

The EU AI Act: what does it mean for you?

Tom Albrighton7 min read

Once it fully takes effect, the EU's AI Act will have major implications for recruiters – even in the UK and US. Here, we break down its most important provisions and what they mean for recruiters who make use of AI tools.

Why should I care about EU rules?

First of all, why are we worrying about European legislation anyway? Britain broke free of the EU years ago, and the US has never been part of it at all.

True and true. But EU law casts a long shadow. If you're recruiting or assessing candidates from any EU member state, or employing EU nationals, this legislation applies to you.

Even if you're based in the USA or Canada, these rules could affect you too – either because you work with European nationals, or because you work in states that have historically legislated EU-adjacent policies, such as California.

So if you're in any doubt at all, compliance is the safest route.

It's a similar situation to the GDPR. Technically, it doesn't apply to the UK. But in practice, UK firms have found that they're effectively obliged to comply with it.

What's the big idea?

Basically, the EU wants to make sure that AI can't make independent decisions that affect people's lives. That includes areas such as work, access to services, or other rights they may have. The goal is to prevent incidents where people's lives are negatively affected, and the person or company involved tries to weasel out of responsibility by saying, 'The AI did it.'

So what does it cover?

The AI Act imposes new duties on organisations that use AI in a professional context. These responsibilities depend on the risks involved, which range from minimal to unacceptable. Minimal-risk applications of AI aren't regulated at all, while unacceptable uses are banned outright. In between are limited-risk and high-risk applications.

When it comes to the workplace, applications like AI monitoring of wellness and attention at work will be branded unacceptable and banned. Workforce and HR systems will be allowed, but since they affect significant outcomes for individuals – a whole new job, a major career move – they're sure to be designated high-risk.

High-risk systems have obligations in terms of quality, transparency, human oversight and safety. In some cases, they'll need a Fundamental Rights Impact Assessment (FRIA) to identify and mitigate potential impacts on fundamental rights before the system is rolled out. Meanwhile, citizens have the right to complain about AI systems and receive explanations of AI decisions that affect their rights – like a job rejection.

Failure to comply can land you a fine of up to €15m or 3% of worldwide annual turnover (not profit), whichever is higher. And if you're using AI for one of the outright banned purposes, that more than doubles – to €35m or 7%. Either way, it applies to both the creator of the application (like a software developer) and the user (like a recruiter).

All in the timing

That all sounds pretty scary – and in a way, it is. After all, if you can shrug off a hit of €15m, your business is doing pretty well.

But crucially, the implementation is phased, with the full law only taking effect in December 2027. So, despite all those wild-eyed LinkedIn posts you may have seen about 'the AI Act becoming law', you've still got well over a year to make any necessary changes. For most of us, the only requirement that really matters so far is that firms must disclose when they're using AI in their recruitment.

What you have to do

When the full law takes effect, both vendors and clients of recruitment software will be responsible for testing and proving the system is free from discrimination, such as bias against specific genders or backgrounds.

So you can't relax in the knowledge that your software provider is on the hook for non-compliance. Whatever third-party AI tools you use for recruitment, you'll have to ensure they're following the rules – and if not, switch to someone else.

Thanks to vibe-coding, some guy in a bedroom can easily whip up a decent-looking AI recruitment platform before breakfast. So this is very much a question of 'buyer beware'. Before you choose a software startup founded in the last couple of years, we suggest you take a long, hard look at their testing regime.

Candidate power

While the new rules are mainly focused on recruiters' responsibilities, they change the picture for candidates too.

Thanks to GDPR, candidates can submit data access requests to see exactly what information companies hold regarding their applications. If they suspect they've been wrongly or unfairly rejected by AI, they'll be able to report the employer to the relevant authority in their specific country – similar to how the ICO handles GDPR complaints in the UK.

However, the authorities won't be overturning any individual hiring decisions, so the best that wronged candidates can hope for is the symbolic victory of a fine. Plus the verdict would most likely take years to arrive anyway.

So much for individual roles. But the greater the volume, the wider the paper trail. In the past, an individual recruiter's biases would be almost impossible to pin down. Now, every decision will have a written rationale associated with it – and big data might reveal broader bias in the way you hire.

Dazzled by AI

The progress in AI recruitment over just a few years has been nothing short of astonishing. AI systems can already screen CVs, assess skills, rank applicants, communicate with candidates and even conduct basic interviews. Obviously, that saves recruiters days of effort and can dramatically shorten the time to make an appointment.

However, we have to keep our feet on the ground. The technology isn't perfect. It can still miss important details, reinforce hiring biases and overlook 'soft' or cultural factors – and, as a result, potentially reject candidates who should have stayed in the mix.

Human in the loop

When it comes to recruitment, the key to oversight, safety and decision quality is to keep a 'human in the loop'. Many AI solutions are 'black boxes', providing an answer without explaining how it was obtained. But AI recruitment systems can't be that way. They must provide a trace or rationale for each decision they make.

What's more, humans need to be involved in their decisions. That doesn't mean blindly rubber-stamping an AI output, but reviewing and verifying every candidate who gets ruled out.

For Isimio, we've gone for a 'mix and match' approach. We use AI to parse CVs for skills and content, but fall back on good old deterministic programming for binary matching criteria, such as a candidate's location or whether they have a DBS check.

Nobody likes filling out forms – especially when they've just uploaded a CV that answers most of the questions on it. That's why our platform uses AI to pre-populate an application, then allows the candidate to review it for accuracy before submitting. That gives them ownership of the info that we will use for decision-making.

We've also released a bias-testing toolkit that checks and records how our AI works against a multitude of personas. This provides hard assurance that our systems do not discriminate against people with a range of protected characteristics.

Taking a step back

In recent years, it has sometimes felt like the jobs market has degenerated into a tech-fuelled 'arms race' between employers and candidates. Recruiters deploy AI bouncers to turn applicants away at the door, while candidates respond with guerilla tactics like prompt injection or bombarding employers with AI-automated applications. And punitive legislation like the AI Act suggests a bad-tempered grudge match in need of a stern referee.

We think it's crucial to keep the aim in mind. At the end of the day, both employers and candidates want the same thing: the right person in the right job. There's little point in saving time and improving efficiency if you end up appointing the wrong person – or, indeed, accepting the wrong post.

When it comes down to it, AI tools are just that: tools. Bringing the right people into an organisation always has been, and always will be, a fundamentally human endeavour. So the new legislation might be a pain in some ways, but if it reminds us of that essential truth, it might be no bad thing.

Want to see Isimio in action?

Book a Demo →