You bought an AI recruiting tool. What does the EU AI Act make you do?
The system being classified
You are an employer in the EU using a third-party AI tool to screen or rank job applicants. You did not build it and you do not sell it.
High-risk system
Your system falls under Annex III or is a regulated product safety component. The full high-risk obligation set applies from 2 December 2027 (Annex III) or 2 August 2028 (Annex I) — postponed by the 2026 Omnibus. Any Article 50 transparency duties apply already, and the runway is what makes conformity achievable in-house.
This is the classification of the configuration described above, not of your system. One different answer can move it — which is exactly what the comparison further down shows, and what the free assessment settles in about ten minutes.
What produced this verdict
These are the entire inputs. The engine is deterministic, so these answers always produce the verdict above.
Annex III categories
- · Employment and worker management
Scope and role
- · Deployer — you use it under your own authority
- · Placed on the EU market, or output used in the EU
- · Used in a workplace toward workers
What applies, and from when (9)
Every entry cites the article it comes from and the date it binds. That second column is the part most summaries of the Omnibus get wrong.
| Article | Obligation | Binding from |
|---|---|---|
| Art. 4 | AI literacy Ensure staff dealing with AI systems have a sufficient level of AI literacy (training records recommended). | 2 February 2025 |
| Best practice | AI system inventory Maintain a central register of all AI systems in use, their purpose, risk tier and owner. | Good practice |
| Art. 26(1) | Operate per provider instructions Assign technical and organisational measures to use the system strictly according to its instructions for use. | 2 December 2027 |
| Art. 26(2) | Assign trained human oversight Name specific, competent, trained people with authority to oversee the system and overrule or halt it. | 2 December 2027 |
| Art. 26(4) | Input data control Ensure input data under your control is relevant and sufficiently representative for the intended purpose. | 2 December 2027 |
| Art. 26(5) | Monitor and suspend on risk Monitor operation, inform the provider of risks, and suspend use when the system presents a serious risk. | 2 December 2027 |
| Art. 26(6) | Retain logs (minimum 6 months) Keep automatically generated logs under your control for at least six months. | 2 December 2027 |
| Art. 26(7) | Inform affected workers Before using workplace AI, inform workers' representatives and affected workers that they are subject to it. | 2 December 2027 |
| Art. 26(11) + 86 | Inform affected persons; explain on request Tell natural persons subject to decisions made or materially informed by an Annex III system that it is in use, and be ready to give the Article 86 explanation of the role the system played in a decision. | 2 December 2027 |
What would change this verdict
Each row below is the same scenario with one answer changed, re-run through the same engine. These are not predictions about your system; they are what our classifier returns when that single fact differs. Where one change to the scenario necessarily moves a second answer with it, the row says which, and why.
You also put your own name or trademark on it
Same risk tierArticle 25 can turn a deployer into a provider of the same system, which swaps a short duty list for the full high-risk stack.
- Obligations: 9 → 21 (+12)
- +1 flagged for counsel review
You claim the Article 6(3) derogation
Becomes minimal riskAvailable where the system performs a narrow procedural task, improves the result of prior human work, or does no more than preparatory profiling — and never where it profiles natural persons. Claiming it is a documented decision, not a checkbox.
- Obligations: 9 → 2 (-7)
- +1 flagged for counsel review
- Key date changes to No dated obligations pending — AI literacy (Art. 4) applies since 2 February 2025; keep the inventory current
Your system is not this system
The assessment asks the same questions this page answered for a generic configuration, and produces the verdict, the gap list and the 30-day plan for yours. Ten minutes, free, no sign-up, and it runs entirely in your browser — your answers never reach us.
Classify your own system →Other configurations
Creditworthiness evaluation is named in Annex III point 5(b). The AnnexWise engine's verdict for a credit-scoring system: tier, obligations, binding dates and counsel flags.
Risk assessment and pricing in life and health insurance sits in Annex III point 5(c). What the deploying insurer owes, including the fundamental rights impact assessment.
Monitoring and detecting prohibited behaviour during tests is named in Annex III point 3. The engine's verdict for a proctoring system, with every obligation and its date.
Remote biometric identification sits in Annex III point 1, and one-to-one verification is expressly carved out of it. Which side of that line an access system falls on, and what it owes if it lands on the wrong one.
Produced by rule set 1.6.1, legal state 2026-08-05. The engine is deterministic and contains no language model in the verdict path, and every rule is published at /methodology for you to audit.
AnnexWise is preparation software, not legal advice. This page classifies a described configuration; it is not an opinion on any particular organisation or system.