NO AI ACT.

AI Act · Employment · High risk

AI in recruitment and employment

An algorithm that rejects your CV, software that scores your productivity, a camera that "reads" your mood in an interview: the AI Act treats these three scenarios very differently. This page explains where the line runs between banned, high-risk and permitted — and who answers for each.

01In brief

At work, the AI Act draws two lines. Prohibited: inferring the emotions of workers and students from their biometric data, except for medical or safety reasons (Art. 5). High-risk: systems that screen candidates, allocate tasks, evaluate performance or decide promotions and terminations (Annex III, point 4) — permitted, but under strict duties of human oversight, transparency and data governance.

02What is banned in the workplace

Emotion recognition in the workplace is a prohibited practice: software that claims to measure "enthusiasm" or "reliability" from facial movements in a video interview is not a high-risk system needing better paperwork — it is outside what is lawful. The logic: the employment relationship is asymmetric, and someone who depends on a judgement cannot opt out of being observed. More in prohibited practices.

03What is high-risk (and why it is not banned)

  • Recruitment and hiring: CV screening, application filtering, candidate-ranking systems.
  • Managing the relationship: task allocation, monitoring and evaluating performance, decisions on promotion and termination.

"High-risk" does not mean "forbidden": it means the system may operate only with requirements on data quality, documentation, worker information and effective human oversight — a person who can understand the system and overturn its output, not a rubber stamp on decisions already taken. The full picture is in high-risk AI systems.

The GDPR does not stop here: automated decisions and informing workers remain its territory. See the AI Act and the GDPR.

04Who is responsible

The provider (who builds and sells the system) answers for design, data and documentation; the deployer — here the employer — answers for concrete use: operating the system as instructed, ensuring oversight, informing workers. "The algorithm decided" does not move responsibility anywhere: it just assigns it badly.

05In the game: "The interview that never happened"

In the case The interview that never happened you inspect an automated hiring system: you must separate what is prohibited (the emotion analysis) from what is "merely" badly governed high risk, and assign responsibility between the builder and the user of the system. The contrast with The observed classroom (monitoring minors at school) shows how the same tool changes weight as the context changes.

06Official sources and transparency