Skip to content

High-Risk AI in Employment and Recruitment: the Annex III Category

10 min read · updated August 11, 2026

Annex III point 4 is the category most employers will actually meet, because it covers not only hiring tools but the systems that allocate work, monitor performance and end contracts. It is also the category where an employer operating on both sides of the Atlantic collects three overlapping regimes at once.

The two sub-points, and how wide they are

Point 4 of Annex III to Regulation (EU) 2024/1689 covers employment, workers’ management and access to self-employment, and lists AI systems intended to be used:

  • (a) for recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates;
  • (b) to make decisions affecting the terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics, or to monitor and evaluate the performance and behaviour of persons in such relationships.

Point (a) is wider than a CV screener. “Targeted job advertisements” puts the audience-selection model that decides who sees a vacancy inside the category — a system typically operated by a platform rather than by the employer, and the origin of some of the most consequential hiring discrimination findings anywhere.

Point (b) is wider still. “Work-related contractual relationships” is not limited to employees: it reaches contractors and platform workers, which is the point of the “access to self-employment” heading. Task allocation based on individual behaviour or traits is the algorithmic-management case in plain words, and performance and behaviour monitoring covers productivity scoring whether or not any decision follows automatically.

Not legal advice. Whether a specific workforce tool is “intended to be used” for one of these purposes, and who is its provider once you have configured it, are fact-specific questions. Take advice on your own deployment before concluding either way.

Why the Article 6(3) exemption rarely helps here

Article 6(3) lets a provider conclude that an Annex III system is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights — including by not materially influencing the outcome of decision-making — and one of four conditions is met: narrow procedural task, improving a previously completed human activity, detecting decision patterns without replacing the human assessment, or performing a preparatory task.

The final subparagraph closes the route for most employment tools: an Annex III system is always considered high-risk where it performs profiling of natural persons, meaning profiling as defined in Article 4(4) of the GDPR — any form of automated processing of personal data to evaluate personal aspects relating to a natural person, in particular to analyse or predict performance at work, reliability or behaviour. Candidate scoring, fit prediction and performance analytics are profiling on that definition, and the exemption is unavailable to them regardless of how much human review sits downstream.

A tool that parses a CV into structured fields without evaluating the person, or that de-duplicates applications, is a narrow procedural task and plausibly outside. The line is between processing about the application and evaluation of the applicant. A provider relying on Article 6(3) must document the assessment before placing the system on the market and register it under Article 49(2) anyway — the exemption removes the obligations, not the paper trail.

The duties owed to workers and their representatives

Three provisions matter to a deployer here and only one of them appears in most summaries.

Article 26(7) requires deployers who are employers, before putting into service or using a high-risk AI system at the workplace, to inform workers’ representatives and the affected workers that they will be subject to its use. This is a prior information duty, it runs to representatives as well as individuals, and it is independent of anything national labour law requires. Where a works council has co-determination rights over monitoring technology — as in Germany under the Works Constitution Act, or through the Dutch works council’s consent right on personnel-monitoring arrangements — those rights sit on top. See works councils and AI monitoring.

Article 26(11) requires deployers of Annex III high-risk systems that make or assist in making decisions related to natural persons to inform those persons that they are subject to the use of the system. For a candidate, that is a notice at application time rather than a line in a privacy policy nobody opens.

Article 86 gives an affected person subject to a decision based on the output of an Annex III system — where it produces legal effects or similarly significantly affects them adversely — the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision procedure and of the main elements of the decision taken. Employment is not carved out of that right; only Annex III point 2 is.

One duty that generally does not apply to a private employer is Article 27. The fundamental rights impact assessment is required of deployers that are bodies governed by public law or private entities providing public services, and of deployers of the creditworthiness and life-and-health-insurance systems in Annex III points 5(b) and 5(c). A private-sector employer deploying a hiring tool is outside that list, which surprises people who assume the FRIA follows the risk tier. Article 2(11) separately preserves Member States’ freedom to keep or introduce law more favourable to workers, so national requirements can and will go further.

Where the US obligations stack on top

An employer hiring in New York City, Illinois and the EU is subject to three regimes that regulate the same tool at different points, and none of them satisfies another.

New York City Local Law 144 of 2021 requires an independent bias audit of an automated employment decision tool within one year before its use, publication of a summary of the audit results, and notice to candidates and employees who reside in the city at least ten business days before use. It is enforced by the Department of Consumer and Worker Protection, which began enforcement on 5 July 2023; the official guidance and rules are published by NYC DCWP. It is an audit-and-disclosure regime: it does not prohibit a discriminatory outcome, it requires the numbers to be published. See what the bias audit involves.

Illinois House Bill 3773, enacted in August 2024 as Public Act 103-0804, amends the Illinois Human Rights Act with effect from 1 January 2026. It makes it a civil rights violation for an employer to use AI with respect to recruitment, hiring, promotion, discipline, discharge and related decisions in a way that has the effect of discriminating on the basis of a protected class, and to use zip code as a proxy for a protected class; it also requires notice to employees and applicants. The bill status and text are published by the Illinois General Assembly. This is a liability regime, not a disclosure one — it attaches to the outcome. See the Illinois provisions.

Annex III(4) is a product-safety regime. It regulates how the system is built, documented, tested, logged and overseen, largely before anybody is hired at all. Colorado adds a fourth model again — a duty of reasonable care against algorithmic discrimination — whose commencement date has been moved once already; see the Colorado effective date rather than relying on a date quoted anywhere else. Existing federal anti-discrimination law under Title VII applies to all of it regardless; see AI hiring law.

Building the evidence once

The three regimes ask different questions and share most of their underlying facts. A single dataset — selection rates by protected category across the tool’s decisions, with the tool version, the date range and the population recorded — feeds the NYC bias audit, supports an Illinois disparate-impact position, and is a large part of what Article 10 data governance and Article 15 accuracy declarations need.

What does not transfer is the direction of the duty. The NYC audit must be conducted by an independent auditor and published; the Illinois analysis is privileged work product until it is not; the EU documentation goes to a notified body or a market surveillance authority and to the deployer, and under Article 11 must exist before the system is placed on the market. An organisation that treats one as covering the others will have the numbers and the wrong artefact. See what compliance evidence looks like and the consolidated Regulation on EUR-Lex.

The sequencing changed in 2026 and it matters for a multi-jurisdiction employer. Annex III high-risk obligations were to apply from 2 August 2026; the digital omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, moves stand-alone Annex III obligations to 2 December 2027 and Annex I embedded high-risk to 2 August 2028. New York City’s bias audit duty has been enforced since 2023 and the Illinois amendments took effect on 1 January 2026, so for a US-EU employer the American obligations now bite well before the European ones rather than alongside them. Nothing else on this page is attributed to that amending Regulation.