High-risk AI · 8 min read

CV screening tools are high-risk AI: the employment trap catching Irish SMEs

Published 13 May 2026 · last updated 12 June 2026

Any AI tool that ranks, filters or scores job applicants is classified as high-risk under Annex III of the EU AI Act — and having a human make the final hiring decision does not change that. The classification attaches to what the system does, not to who signs off at the end. For Irish SMEs, recruitment is the single most common way an ordinary business walks into the Act’s high-risk regime without noticing.

Why recruitment AI is high-risk

Annex III of the AI Act lists the areas the EU legislator decided carry serious risk to people’s rights and livelihoods, and employment and worker management is one of them. It covers AI used for recruitment and selection — placing job ads, analysing and filtering applications, evaluating candidates — and AI used on existing staff for task allocation, monitoring, evaluation, promotion or termination decisions. The logic is straightforward: a system that decides who gets shortlisted decides who gets a livelihood, and errors or bias at that point are hard for the affected person to even see, let alone challenge.

The human-in-the-loop myth

The most common misunderstanding in Irish boardrooms is that a human reviewer takes the tool out of scope. It does not. If the AI ranks 400 applications and a recruiter interviews the top 20, the AI decided the fate of the other 380 — the human never saw them. The Act treats human oversight as one of the obligations that applies to a high-risk system (Article 26(2)), not as an exemption from the classification. Oversight is part of the answer; it is never the escape hatch.

Where the tools hide

Few SMEs buy something labelled “AI recruitment system”. The screening function usually arrives inside something else:

  • An applicant tracking system with “candidate matching” or “fit scores” switched on.
  • A job-board or LinkedIn feature that pre-ranks applicants before you see them.
  • A recruitment agency using AI screening on your behalf — your candidates, their tool, questions you still need answered.
  • HR software that scores performance, flags attrition risk or allocates shifts — the same Annex III category covers existing workers, not just applicants.

What being a high-risk deployer requires

If you use the tool as supplied by the vendor, you are a deployer — the lighter role, but not a light one. (If you are unsure which side of the line you sit on, start with deployer or provider.) Article 26 requires deployers of high-risk systems to:

  1. Use the system in line with the provider’s instructions.
  2. Assign human oversight to a named person with the training and authority to override or stop the system.
  3. Check input data is relevant and representative, to the extent you control it.
  4. Retain the system’s logs, where under your control.
  5. Inform workers and their representatives before use, and monitor operation, suspending use and reporting serious incidents.

The timeline — and why waiting is a mistake

Under the 7 May 2026 Omnibus political agreement, the main Annex III obligations apply from 2 December 2027 — but that date is subject to formal adoption, and if the Omnibus stalls, the fallback is 2 August 2026. Either way, the work is the same: identifying the tools, getting the provider’s instructions, naming an overseer and setting up logging takes months, not days. And the duties that already apply — Article 4 literacy for the recruiters using the tool — are in force now.

Find the trap before it finds you

AI Register Ireland’s guided classification flags the employment trap explicitly: record the tool, answer plain-English questions, and get the Annex III classification with the Article 26 duties and their deadlines attached. See how it works.

Put your AI register in place

Inventory, classification, obligations and an evidence trail. Join the waitlist for early access.

Join the waitlist