AI Act-audit for recruitment
Ranking job applications is high-risk, including when the software is provided by a third party.
In most sectors, the classification is a borderline case. Not here. Systems that target job advertisements, filter applications, rank candidates or assess their suitability are explicitly listed in Annex III. This also applies to systems that, after recruitment, make decisions about task allocation, promotion or termination.
Almost no organisation develops this software itself. It is part of your ATS, a sourcing tool or a module of your HR software. This does not automatically mean that the obligations lie with the provider.
One category falls outside the high-risk category because it is prohibited: systems that infer emotions or mood in the workplace. This prohibition has been in force since 2 February 2025.
Selection and ranking
We identify which steps in your recruitment process are supported by a model, and which of them effectively exclude a candidate.
A filter that never allows applications to reach a human is different from a ranking order. We also look at whether, in practice, the recruiter has the time and information needed to disregard that ranking.
Your role in the chain
Your ATS and sourcing tools come from external providers. We determine who is the provider and who is the deployer.
Anyone who places a system under their own name or changes its intended purpose becomes the provider, even if the contract suggests otherwise.
Prohibited practices
We assess whether any part of your process involves inferring emotions, mood or personality traits from images, voice or language.
With video interviews and automated interview analysis, this is more often built into the tool than the user realises.
Interaction with existing rules
Anti-discrimination law and the GDPR already impose requirements here, and your social dialogue arrangements may also do so.
We map out where those frameworks already cover what the EU AI Act requires and where they diverge.
What you receive
An inventory of the AI systems within scope, a qualification for each system, and a prioritised list of the gaps identified. The qualification is the work of the affiliated lawyers, acting in their own name and under their own professional indemnity insurance.
We carry out the audit and compile the report. We do not assess conformity and we do not issue certificates.
After the audit,
Automation
The remediation plan is yours. You can carry it out in-house, with your existing supplier, or with us.
If the audit shows that your AI systems run on US infrastructure and you want that to change, that is a separate question.
That is what we are developing Thor for: a self-hosted environment in which your business data does not leave Europe. Development starts on 1 November 2026 and runs for six months, against thresholds set in advance. It is a separate engagement, not a follow-on from the audit.