EU AI Act

Built for high-risk hiring AI — with oversight designed in

The EU AI Act treats candidate-evaluation tools as high-risk. Rather than retrofit compliance, we built hire.center around its principles: human oversight, transparency, data governance and auditability.

Why hiring tools are high-risk

Under Annex III of the EU AI Act, AI systems intended to be used for the recruitment or selection of people — screening applications and evaluating candidates — are classified as high-risk. The reasoning is simple: these systems affect people's access to work, so the law demands they be safe, transparent, well-governed and subject to human control.

For a provider like hire.center, high-risk classification means a concrete set of obligations. Here is how each maps to how the product actually works.

Obligation → design

How the requirements map to the product

Human oversight

A person always decides

Output is advisory. No automated advancement, rejection or ranking. The scorecard is structured to be read and overridden by a human — the essence of meaningful oversight.

Transparency

Candidates are told

Candidates consent before the simulation and are informed they are interacting with an AI-assisted assessment whose result is advisory to a human decision.

Data governance

Relevant data only

Scoring is based on the transcript of the simulation against role-relevant constructs — not résumés, names, photos or demographic signals. See fairness.

Record-keeping

Logged and auditable

Assessments, blueprints and evidence are retained so a decision can be reconstructed and reviewed — supporting the Act's logging expectations.

Accuracy & robustness

Evidence-first scoring

Quote verification and an explicit 'insufficient evidence' outcome reduce fabricated confidence and make scores checkable against the transcript.

Technical docs

A maintained risk file

We keep provider-side technical documentation and a risk-management file describing the system, its intended purpose, and its limitations.

Provider vs. deployer — who does what

The Act splits duties between the provider (us) and the deployer (the employer). Clarity here protects both sides.

ResponsibilityProvider — hire.centerDeployer — the employer
Risk management & technical documentationMaintains the risk file and system documentation.Reviews suitability for their use case.
Human oversightBuilds oversight controls into the product (advisory-only, override).Ensures a competent person actually reviews and decides.
Transparency to candidatesProvides consent flow and candidate-facing information.Communicates use to candidates as an employer.
Logging & retentionRetains assessment records and evidence.Sets retention aligned to local employment law.
Bias monitoringDesigns for construct-focused, demographic-blind scoring.Monitors real-world outcomes for adverse impact.
FAQ

Common questions

Is hiring AI really 'high-risk' under the EU AI Act?

Yes. Annex III of the EU AI Act classifies AI systems used for recruitment and selection — including tools that evaluate candidates — as high-risk. That triggers obligations around risk management, data governance, transparency, human oversight, logging and technical documentation.

Does hire.center make automated hiring decisions?

No — and that is deliberate. hire.center produces an advisory assessment only. A human always makes the hiring decision. We never auto-advance, auto-reject or auto-rank candidates. Meaningful human oversight is a core requirement of the Act, and it is designed into the product, not bolted on.

What is the deadline for the high-risk rules?

The AI Act entered into force in 2024 and applies in phases. Obligations for high-risk systems under Annex III phase in over 2026–2027. We treat the earliest applicable dates as our planning horizon rather than waiting for enforcement.

Are you the 'provider' or the 'deployer'?

We are the provider of the AI system; the employer using it is the deployer. Each role has distinct duties. We give deployers what they need to meet theirs — transparency information for candidates, human-oversight controls, and documentation — while we maintain the provider-side risk file and technical documentation.

Compliance-conscious hiring, self-serve

See the human-in-the-loop scorecard and the evidence behind every score.