Skip to main content

UK firms hiring in the EU now face €35m AI Act fines: what HR must do

Ilustrační obrázek
A recruiter at a Manchester startup posts a remote job ad. Within a week, applications arrive from Dublin, Berlin and Prague. An AI tool scores the CVs overnight. As of 2 August 2026, that everyday scene is regulated by the EU AI Act — even though the startup is British. The maximum fine for getting it wrong: €35 million, or 7% of global annual turnover.
For years, British HR teams could treat Brussels as someone else's problem. Brexit gave the UK its own employment law, and a hiring manager in Leeds rarely had to think about what the European Parliament decided. That is no longer true. The EU AI Act reaches across the Channel, and it reaches further than many UK employers realise. The rule of thumb is simple: the law follows the person, not the company. If an AI system makes or supports decisions about someone in the EU, the law applies — regardless of where the employer is registered. HR Grapevine's new briefing for UK employers walks through the practical details, and the picture is clearer than most HR teams expect.

When does EU law reach a British company?

There are three situations in which a UK employer falls under the Act's HR provisions right now: - The company recruits EU-based candidates — including for fully remote roles. - The company employs staff in the EU — including a single employee working from home in another member state. - The company buys recruitment or HR software from a vendor whose AI outputs affect people in the EU. In legal terms, the employer becomes a "deployer" — the entity using the AI system, not the one building it. And deployers carry their own obligations, even if they bought the software from a US or UK supplier. You cannot outsource the responsibility by signing a contract with a vendor.

Which HR tools are now "high-risk"?

Annex III of the Act contains an explicit list of employment-related systems classified as high-risk. It covers more than recruiters might expect: - CV screening and candidate ranking - Performance evaluation - Task allocation - Automated monitoring of workers Three points matter here. First, a simple spreadsheet or a chatbot that helps you rewrite a job ad is not high-risk — the classification applies to systems that score, rank or evaluate people. Second, the rules apply even when the tool is a small, inexpensive SaaS product, not an enterprise platform. Third, the obligations start with the deployer, not with the vendor. The Act sits alongside the GDPR: because CV screening involves personal data, the two laws overlap in hiring. The official text of the regulation is available on EUR-Lex, but the practical obligations for HR teams can be summarised in a short list:
Deployer obligationWhat it means in practice
Human oversightA named person can review, correct or override the AI's decision before it becomes final.
TransparencyApplicants and staff are told that AI is used in decisions about them.
Activity logsAutomated logs must be kept for at least six months.
Risk evaluationThe system is assessed for bias and risk, and the assessment is documented.

What changed in the last few weeks

The legal framework is not hypothetical. The obligations for high-risk systems, including the Annex III HR tools, kicked in on 2 August 2026. Late July brought additional clarity in the form of Regulation (EU) 2026/1744 — the Digital Omnibus on AI — which updated compliance timelines and enforcement guidelines for deployers of standalone high-risk systems. The practical consequence: if you use AI in hiring now, compliance is not a future project. It is an active obligation with a regulator's attention.

The view from the applicant's side

For job seekers across Europe, this is genuinely new protection. Whether you are reading this in Prague, Manchester or Lyon: if an algorithm screens your CV, the employer must tell you, and you can ask a human to review the decision. That right exists regardless of whether the employer is German, French — or British. The gap between law and practice remains wide. Compliance research published in late July 2026 found that fewer than one in four deployers disclose a human rights impact assessment, and only a third conduct ethical impact assessments. So the protections exist on paper; making them real is exactly what the next enforcement wave is trying to change. And here is where the Brussels Effect comes in. The EU guards access to 450 million consumers, and global vendors would rather adapt once than build separate products for each region. 47% of companies that now cite the EU AI Act in their compliance disclosures are headquartered outside the EU. That shows up in recruitment platforms too: the EU-compliant version is increasingly the only version on sale.

Where should a small HR team start?

If this sounds like a lot for a ten-person company, it is manageable — but it requires a first step this month, not next year. - Map the tools. List every system that scores, ranks, evaluates or monitors people. - Ask the vendor. "Does your product meet the EU AI Act's deployer requirements?" In 2026, the answer should be documented, not improvised. - Name a human. Designate who reviews and overrides AI decisions. - Log it. Make sure automated activity is saved for at least six months. - Write it down. A short, honest risk note is enough to start — bias risks, who reviews, how a candidate can appeal. None of this is about stopping the use of AI in hiring. It is about making sure the person at the other end of the algorithm is still treated like a person. For UK employers, the debate about whether Brussels rules apply is over. The only question left is how well they are applied.

Does the EU AI Act apply to my UK company if I only use ChatGPT to rewrite job adverts?

Probably not on its own. Drafting text with a general-purpose chatbot is different from using an AI system that screens, ranks, evaluates or monitors people. The high-risk rules start where automated decisions about individuals begin.

I applied for a remote job with a British company. Can I ask whether AI was involved?

Yes. Deployers must tell you when AI is used in decisions that affect you, and you can request a human review of the decision. If the company refuses, it is worth contacting the data protection authority in the EU country where you live.

Can we avoid all this by buying HR software from a non-EU vendor?

No. The deployer obligations belong to the company using the system, not the vendor. In practice, though, many global vendors already ship EU-compliant versions to all customers — the Brussels Effect at work.

Discussion

No comments yet — be the first to share your thoughts.
X

Don't miss out!

Subscribe for the latest news and updates.