When does EU law reach a British company?
There are three situations in which a UK employer falls under the Act's HR provisions right now: - The company recruits EU-based candidates — including for fully remote roles. - The company employs staff in the EU — including a single employee working from home in another member state. - The company buys recruitment or HR software from a vendor whose AI outputs affect people in the EU. In legal terms, the employer becomes a "deployer" — the entity using the AI system, not the one building it. And deployers carry their own obligations, even if they bought the software from a US or UK supplier. You cannot outsource the responsibility by signing a contract with a vendor.Which HR tools are now "high-risk"?
Annex III of the Act contains an explicit list of employment-related systems classified as high-risk. It covers more than recruiters might expect: - CV screening and candidate ranking - Performance evaluation - Task allocation - Automated monitoring of workers Three points matter here. First, a simple spreadsheet or a chatbot that helps you rewrite a job ad is not high-risk — the classification applies to systems that score, rank or evaluate people. Second, the rules apply even when the tool is a small, inexpensive SaaS product, not an enterprise platform. Third, the obligations start with the deployer, not with the vendor. The Act sits alongside the GDPR: because CV screening involves personal data, the two laws overlap in hiring. The official text of the regulation is available on EUR-Lex, but the practical obligations for HR teams can be summarised in a short list:| Deployer obligation | What it means in practice |
|---|---|
| Human oversight | A named person can review, correct or override the AI's decision before it becomes final. |
| Transparency | Applicants and staff are told that AI is used in decisions about them. |
| Activity logs | Automated logs must be kept for at least six months. |
| Risk evaluation | The system is assessed for bias and risk, and the assessment is documented. |
What changed in the last few weeks
The legal framework is not hypothetical. The obligations for high-risk systems, including the Annex III HR tools, kicked in on 2 August 2026. Late July brought additional clarity in the form of Regulation (EU) 2026/1744 — the Digital Omnibus on AI — which updated compliance timelines and enforcement guidelines for deployers of standalone high-risk systems. The practical consequence: if you use AI in hiring now, compliance is not a future project. It is an active obligation with a regulator's attention.The view from the applicant's side
For job seekers across Europe, this is genuinely new protection. Whether you are reading this in Prague, Manchester or Lyon: if an algorithm screens your CV, the employer must tell you, and you can ask a human to review the decision. That right exists regardless of whether the employer is German, French — or British. The gap between law and practice remains wide. Compliance research published in late July 2026 found that fewer than one in four deployers disclose a human rights impact assessment, and only a third conduct ethical impact assessments. So the protections exist on paper; making them real is exactly what the next enforcement wave is trying to change. And here is where the Brussels Effect comes in. The EU guards access to 450 million consumers, and global vendors would rather adapt once than build separate products for each region. 47% of companies that now cite the EU AI Act in their compliance disclosures are headquartered outside the EU. That shows up in recruitment platforms too: the EU-compliant version is increasingly the only version on sale.Where should a small HR team start?
If this sounds like a lot for a ten-person company, it is manageable — but it requires a first step this month, not next year. - Map the tools. List every system that scores, ranks, evaluates or monitors people. - Ask the vendor. "Does your product meet the EU AI Act's deployer requirements?" In 2026, the answer should be documented, not improvised. - Name a human. Designate who reviews and overrides AI decisions. - Log it. Make sure automated activity is saved for at least six months. - Write it down. A short, honest risk note is enough to start — bias risks, who reviews, how a candidate can appeal. None of this is about stopping the use of AI in hiring. It is about making sure the person at the other end of the algorithm is still treated like a person. For UK employers, the debate about whether Brussels rules apply is over. The only question left is how well they are applied.Does the EU AI Act apply to my UK company if I only use ChatGPT to rewrite job adverts?
Probably not on its own. Drafting text with a general-purpose chatbot is different from using an AI system that screens, ranks, evaluates or monitors people. The high-risk rules start where automated decisions about individuals begin.
I applied for a remote job with a British company. Can I ask whether AI was involved?
Yes. Deployers must tell you when AI is used in decisions that affect you, and you can request a human review of the decision. If the company refuses, it is worth contacting the data protection authority in the EU country where you live.
Can we avoid all this by buying HR software from a non-EU vendor?
No. The deployer obligations belong to the company using the system, not the vendor. In practice, though, many global vendors already ship EU-compliant versions to all customers — the Brussels Effect at work.