Is AI for recruiting and staff scheduling high-risk under the EU AI Act?
Recruitment screening, task allocation and worker monitoring are listed as high-risk in the AI Act. What that means for fashion retailers, and why the 2027 delay is no pause.
KEY TAKEAWAYS Summary by the editors
- Annex III of the EU AI Act lists as high-risk AI systems used to recruit or select people, including analysing and filtering applications and evaluating candidates.
- AI used to make decisions on terms of work, promotion or termination, to allocate tasks based on individual behaviour or personal traits, or to monitor and evaluate workers is also high-risk.
- Under the AI Omnibus, high-risk obligations for these Annex III systems apply from 2 December 2027 rather than 2 August 2026.
- Employers deploying high-risk AI must assign trained human oversight, keep logs for at least six months and inform workers' representatives and affected workers before use in the workplace.
- Emotion recognition in the workplace has been prohibited since 2 February 2025, except for medical or safety reasons.
Yes, in many cases. The EU AI Act classifies AI used to recruit and select staff, to decide on promotion or termination, to allocate tasks based on individual behaviour or personal traits, and to monitor or evaluate workers as high-risk. For fashion retailers that hire seasonal store staff at scale and increasingly use algorithmic rostering, this is the part of the Act most likely to create real obligations. The rules apply to these systems from 2 December 2027.
Which HR tools does the AI Act treat as high-risk?
Point 4 of Annex III covers employment, workers' management and access to self-employment. It names two groups of systems. The first, point 4(a), covers AI intended for recruitment or selection, in particular placing targeted job adverts, analysing and filtering applications and evaluating candidates. The second, point 4(b), covers AI intended to make decisions affecting the terms of work-related relationships, the promotion or termination of contracts, to allocate tasks based on individual behaviour or personal traits or characteristics, and to monitor and evaluate the performance and behaviour of workers.
| Tool | Likely classification | Why |
|---|---|---|
| CV parsing and candidate ranking for store roles | High-risk (Annex III 4a) | Analyses and filters applications, evaluates candidates |
| Targeted job advertising for seasonal hiring | High-risk (Annex III 4a) | Annex III names targeted job adverts |
| Shift scheduling based on footfall forecasts only | Possibly not high-risk | Allocates hours by demand, not by individual behaviour or traits |
| Scheduling that ranks staff by sales conversion or reliability scores | High-risk (Annex III 4b) | Allocates tasks based on individual behaviour |
| Sales associate performance dashboards with AI scoring | High-risk (Annex III 4b) | Monitors and evaluates performance and behaviour |
| Camera analytics inferring staff mood or stress | Prohibited (Article 5) | Emotion recognition in the workplace |
The distinction in the scheduling rows matters. A rostering tool that matches staffing levels to a footfall forecast is a planning tool. Once the same tool decides which employee gets which shift based on their individual metrics, it moves towards Annex III 4(b). Classification depends on the intended purpose described by the provider and on how the retailer actually uses the system.
What is already banned at work?
Article 5 has applied since 2 February 2025. Its point (f) prohibits AI systems that infer the emotions of a natural person in the workplace and in education institutions, unless the system is intended for medical or safety reasons. For stores, that rules out tools that read employees' facial expressions or voices to infer engagement, stress or friendliness towards customers.

What must an employer do when it deploys high-risk HR AI?
Most retailers will be deployers of HR AI bought from software vendors. Article 26 sets their duties, which apply to Annex III systems from 2 December 2027:
- Use the system as instructed by the provider, with appropriate technical and organisational measures.
- Assign human oversight to people with the necessary competence, training and authority, and give them support.
- Control input data where the employer supplies it, so that it is relevant and sufficiently representative for the purpose.
- Monitor operation and, if the system may present a risk, inform the provider and suspend use; report serious incidents.
- Keep automatically generated logs under the employer's control for at least six months, unless other law requires otherwise.
- Inform workers' representatives and affected workers before putting the system into service in the workplace.
- Tell candidates and employees when a high-risk system makes or assists decisions about them.
- Use the provider's information to carry out a GDPR data protection impact assessment where required.
Why does the 2027 delay not mean waiting?
The AI Omnibus moved Annex III obligations from 2 August 2026 to 2 December 2027. Employment lawyers at Cuatrecasas caution that this should not be read as a pause. GDPR Article 22 already restricts decisions about employees based solely on automated processing that have significant effects, and several member states already give workers' representatives rights to information about algorithms. Their example: Spain's Workers' Statute gives employee representatives a right to be informed about algorithms affecting working conditions, and Portugal's Labour Code contains similar information duties.
The AI Act is also a floor. Member states and collective agreements can set stricter rules for AI at work, and Cuatrecasas notes collective agreements increasingly address AI. Multi-country retailers should therefore expect national variation in consultation duties, even once the Act's harmonised rules apply.
How should a fashion retailer prepare?
Three steps put a company in a defensible position well before December 2027:
- Inventory HR AI. Include features embedded in applicant tracking, workforce management and clienteling apps, not only stand-alone tools.
- Ask vendors for classification. Request the provider's view on whether the system is Annex III, its intended purpose and what logs and documentation it will make available.
- Design oversight into store operations. Decide who can override an AI shortlist or roster, how candidates can request human review, and how store managers are trained.
Seasonal peaks deserve particular attention. When a retailer screens thousands of applicants for holiday trading, the temptation to let ranking run unchecked is strongest, and so is the risk of systematically excluding groups because historical hiring data reflected past bias. Representative input data and genuine human review are both legal requirements and the practical safeguards against that outcome.

What about AI that only helps managers?
Assistive tools, such as drafting job descriptions or summarising interview notes, are generally not listed in Annex III because they do not themselves analyse, filter or evaluate candidates. The line is functional, not technical: if a manager relies on the tool's output to rank people, the use may have become high-risk regardless of how the vendor markets it.
Frequently asked questions
Is AI recruitment software high-risk under the EU AI Act?
Yes. Annex III lists AI intended for recruitment or selection, including targeted job adverts, filtering applications and evaluating candidates, as high-risk. The obligations apply from 2 December 2027.
Is AI shift scheduling high-risk?
It depends on how it works. Scheduling based only on demand forecasts is unlikely to be high-risk, but AI that allocates tasks based on individual behaviour or personal traits falls under Annex III point 4(b).
Can retailers use emotion recognition on store staff?
No. Since 2 February 2025 the AI Act has prohibited AI that infers emotions of people in the workplace, except where intended for medical or safety reasons.
Do employers have to inform staff about AI?
Yes. Before putting a high-risk AI system into service at work, deployers must inform workers' representatives and affected workers, and national laws in several member states already require information about algorithms.
One edition every weekday morning. Read in five minutes. Free for industry professionals.
SOURCES
- artificialintelligenceact.eu: Annex III, High-risk AI systems
- artificialintelligenceact.eu: Article 26, Obligations of deployers of high-risk AI systems
- artificialintelligenceact.eu: Article 5, Prohibited AI practices
- Cuatrecasas: The Digital Omnibus on AI, how does it impact employment relations?
- artificialintelligenceact.eu: Article 25, Responsibilities along the AI value chain


