Introduction

Imagine this: six months ago, you introduced an AI HR tool for your application process. Pre-selection now runs automatically, and your team saves time. Then an email arrives from the data protection authority. A rejected candidate wants to know what logic the AI used to evaluate their application — and whether a human was involved at all. For more and more HR managers at SMEs, this isn't hypothetical.

AI in HR is one of the most legally sensitive application areas there is. Many companies deploy AI HR tools without realizing they're stepping into a minefield of GDPR requirements and EU AI Act obligations. This article shows you where the legal boundaries lie — and how to spot problematic tools before they become a problem.

Why AI in HR Is Especially Tightly Regulated

AI in HR is fundamentally different from other AI applications. It involves decisions that directly affect people's life chances, career paths, and financial livelihoods.

That's exactly why lawmakers have set particularly high hurdles here — higher than for AI in marketing or logistics. Four reasons stand out:

  • Sensitive data: Recruiting often involves processing especially sensitive data — from age and gender to ethnic origin, for example through photos or names on résumés.
  • Reproducing bias: AI HR systems inherit existing biases from historical hiring data. Amazon's internal recruiting tool was proven to disadvantage women — and it's not an isolated case.
  • Structural powerlessness: Candidates can barely challenge AI decisions and lose a job opportunity without ever understanding why.
  • Constitutional protection: The right to work and protection against discrimination are enshrined in constitutional law — setting clear limits on the use of automated systems.

GDPR Art. 22: The Ban on Automated Individual Decisions

The centerpiece of the GDPR requirements for AI in recruiting is Art. 22 GDPR. It generally prohibits automated individual decisions that produce legal effects for a person or significantly affect them.

What this means in practice

A purely automated decision occurs when an AI HR system analyzes applications and independently decides who gets rejected — without a human substantively reviewing the recommendation.

"Important: Not inviting someone to a job interview counts as a significant adverse effect. Candidates lose a job opportunity — that's enough to trigger Art. 22."

The Exceptions Won't Help You Much

Art. 22 GDPR has exceptions — but they typically don't apply in recruiting: consent is barely usable, since candidates are under pressure and the voluntariness of their consent is legally questionable. Contract performance only applies where an employment relationship already exists. And, as things currently stand, there's no statutory permission for recruiting AI.

The consequence: Fully automated application decisions without genuine human review are impermissible in most cases. Simply clicking "OK" on AI suggestions isn't enough.

EU AI Act: When Recruiting AI Becomes a High-Risk Application

The EU AI Act further tightens the requirements for AI in HR. It categorizes AI systems by risk class — and most available tools fall into the high-risk category.

When Does an AI HR Tool Count as High-Risk?

AI systems are considered high-risk when they're used in hiring processes — particularly for pre-selection, evaluation, or hiring decisions — as well as for promotion decisions or performance monitoring. This applies equally to CV-parsing systems with intelligent scoring and interview analysis tools that evaluate facial expressions or speech patterns.

What This Means for You

Strict obligations apply to high-risk AI across six areas:

  • Risk management: Systematic identification and minimization of risks
  • Data quality: Training with representative, error-free datasets
  • Documentation: Comprehensive technical documentation
  • Transparency: Clear information for affected individuals
  • Human oversight: Genuine human oversight mechanisms
  • Accuracy: Demonstrable performance

These obligations are primarily aimed at providers — but as the deployer, you must ensure the tool meets these requirements and that you use it as intended.

When You Should Immediately Question an AI HR Tool

Before you buy or renew a recruiting AI tool, check for these five warning signs:

1. No explanation of the AI logic. The vendor can't describe how recommendations come about. If you don't understand the logic, you can't explain it to candidates either.

2. No bias testing. There's no information about how the system is tested for discrimination. This is a dealbreaker for using AI in HR.

3. No EU data hosting. The vendor is based outside the EU and can't provide sufficient data protection guarantees — no DPA, no standard contractual clauses.

4. Promises of full automation. "Process applicants with zero HR effort" sounds tempting — but under current law, it's a clear warning sign.

5. Compliance is your problem. The vendor shifts all responsibility onto you without providing any evidence of its own.

If you encounter one or more of these red flags, get clarity in writing — or choose a different tool.

Conclusion and Next Step

AI in recruiting is legally complex — but manageable once you know the fundamentals. GDPR Art. 22 and the EU AI Act set the framework. Your job as an employer is to operate within that framework: with genuine human review processes, transparent communication with candidates, and careful selection of your AI HR tools.

The second part of this guide shows you exactly how to put this into practice — with a step-by-step checklist, human-in-the-loop processes, and vendor management tips.