← Blog

EU AI Act for Recruiting: Are AI Interview Notetakers High-Risk?

    Short answer: an AI interview notetaker is not automatically high-risk under the EU AI Act. The Act treats AI used to evaluate, filter, score, or rank candidates as high-risk under Annex III. A tool that only records, transcribes, and summarises an interview, without judging the candidate or making the hiring call, is not doing that. The line that decides your obligations is not whether AI touched the interview; it is whether AI assessed the person.

    That distinction is worth getting right, because the high-risk regime is heavy, and a lot of recruiting teams are quietly assuming either that everything with "AI" in it is now banned, or that nothing applies until 2027. Both are wrong. Here is the accurate version.

    What the EU AI Act actually classifies as high-risk in hiring

    The EU AI Act sorts AI systems by risk. Most tools are minimal or limited risk. A specific list, Annex III, names the use cases the legislator treats as high-risk because they materially affect people's rights and life chances. Point 4 of Annex III is employment: AI intended to be used for recruitment or selection, in particular to place targeted job advertisements, to analyse and filter applications, and to evaluate candidates. It also covers AI used to make or support decisions about promotion, termination, task allocation, and monitoring at work.

    The common thread across point 4 is automated judgement about people. Scoring an applicant, ranking a shortlist, filtering CVs against criteria, predicting "fit," or grading interview answers all sit squarely inside it. These are the functions the Act wants to see governed, documented, and kept under human control, because a biased or opaque model here can decide who gets a livelihood.

    The high-risk test for hiring AI

    Under Annex III, point 4, a recruiting AI is high-risk when it is used to evaluate, filter, score, or rank candidates, or to make or materially support a hiring decision. A tool that only captures and summarises what was said, without assessing the candidate, is performing a different function.

    When do these rules actually apply?

    The high-risk obligations for Annex III recruitment systems apply from 2 December 2027. The original date was 2 August 2026, but the 2026 Digital Omnibus, adopted as Regulation (EU) 2026/1744, moved the application date for Annex III high-risk systems to 2 December 2027 to give providers and deployers more time to prepare.

    Do not read that later date as "nothing applies until then." Several parts of the AI Act are already in force and matter for interviews right now:

    • Prohibited practices (Article 5) have applied since February 2025. Emotion recognition in the workplace, including in interviews, is a prohibited practice, so a tool that claims to read a candidate's emotions is not a compliance project, it is off the table.
    • AI literacy (Article 4) has applied since February 2025. If your team uses AI in hiring, the people operating it need a baseline understanding of what it does and its limits.
    • Transparency obligations (Article 50) apply from 2 August 2026. Where people interact with an AI system or where content is AI-generated, that has to be disclosed. In practice, telling candidates clearly that an AI notetaker is in use is both an AI Act transparency point and a GDPR consent point.

    So the sequence is: the prohibitions and literacy duty are live today, transparency lands in August 2026, and the full high-risk regime for recruitment lands in December 2027. The December 2027 date buys preparation time for high-risk systems; it does not switch off the rules that already apply.

    Does an AI notetaker fall into the high-risk category?

    Usually not, and the reason is functional. An AI notetaker records a conversation, turns speech into text, and produces a summary, action items, or a neutral recap of what was discussed. It documents the interview. It does not, by itself, decide whether the candidate is good, rank them against others, or filter them out.

    Annex III, point 4 is about evaluating candidates. Documenting an interview is not evaluating a candidate any more than a court transcript is a verdict. The notetaker produces a record; a human reads it and makes the call. That is exactly the human-in-the-loop structure the high-risk rules are trying to protect, so a tool that keeps the judgement with people is on the safer side of the line, not the riskier one.

    There is a real boundary to respect, though. The moment a "notetaker" starts scoring the candidate, generating a hire or no-hire recommendation, ranking applicants, or auto-filling a scorecard that feeds an automated shortlist, it stops being a documentation tool and starts performing the Annex III function. At that point the high-risk analysis is back on the table, whatever the product is called.

    The line that matters: recording and summarising versus scoring and ranking

    If you remember one thing, make it this: capturing the conversation is not the same as evaluating the person.

    • Not the high-risk function: recording audio with consent, producing a transcript, generating a factual summary, extracting agreed action items and decisions, sharing that record with the hiring panel.
    • The high-risk function: scoring candidates, ranking or shortlisting them automatically, predicting suitability or "culture fit," grading answers, or producing a recommendation the process then acts on with little human review.

    This is why the choice of tool is a compliance decision, not just a features decision. A notetaker that deliberately stays on the documentation side of that line keeps you out of the high-risk regime. A tool that quietly adds candidate scoring pulls your whole hiring process into it, with all the obligations described below.

    One honest caveat: the Act also has a narrow carve-out in Article 6(3), under which a system listed in Annex III is not high-risk if it performs a purely narrow, procedural, or preparatory task and does not pose a significant risk to people's rights. A plain transcription-and-summary tool has a strong argument here, but relying on 6(3) is a documented provider assessment, not a free pass. The cleaner position is simply not to build candidate evaluation into the tool in the first place.

    What high-risk classification would actually require

    The reason the transcription-versus-evaluation line is worth this much attention is that the high-risk regime is demanding. If a recruiting AI is high-risk, the provider must put in place, among other things:

    • A risk-management system across the model's lifecycle.
    • Data governance, including measures to detect and reduce bias in training and evaluation data.
    • Technical documentation and automatic event logging for traceability.
    • Transparency and instructions so deployers can use the system correctly.
    • Human oversight designed into the system, plus accuracy, robustness, and cybersecurity measures.
    • A conformity assessment and registration in the EU database before the system goes on the market.

    The deployer, meaning the employer using the tool, has duties too: operating it per instructions, ensuring human oversight, monitoring it, and in many cases carrying out a fundamental-rights impact assessment. None of this is impossible, but it is a serious programme. Avoiding it, by not turning your interview documentation into automated candidate assessment, is a legitimate and often sensible design choice.

    What still applies even when notetaking is not high-risk

    Staying out of the high-risk tier is not the same as having no obligations. Interview recording and transcription still sit under GDPR and, once it applies, the AI Act's transparency rule. Regardless of AI Act risk tier, you should:

    • Get genuine consent before recording. In a hiring context consent must be freely given, so offer a real no-recording option. We cover this in detail in is it legal to record job interviews in Germany and the EU.
    • Disclose the AI clearly. Tell candidates an AI notetaker is in use and what it does. This satisfies both the GDPR transparency principle and the Article 50 duty.
    • Watch for special-category data. Interviews can surface health, disability, or ethnicity; minimise what you keep and delete on withdrawal.
    • Keep data in-region with defined retention. Process on EU infrastructure and set a retention window tied to the hiring decision.

    If you want a single-page way to pressure-test a vendor against these points, our AI notetaker AI Act checklist turns them into seven pass or fail questions. For how the wider timeline hits a B2B stack, see the EU AI Act timeline for B2B SaaS.

    How to keep your interview AI out of the high-risk tier

    Practical steps for a recruiting team that wants the benefit of AI notes without inheriting the high-risk regime:

    1. Use AI to document, not to decide. Let the tool transcribe and summarise. Keep scoring, ranking, and the hire or no-hire call with your interviewers.
    2. Avoid candidate-scoring features. Treat "AI fit scores," automated rankings, and hire-recommendation engines as a deliberate line you do not cross without a full high-risk assessment.
    3. Never use emotion recognition. Reading emotions in the workplace is prohibited under Article 5, full stop.
    4. Keep a human reviewing every summary. The record informs the decision; a person makes it.
    5. Document your basis. Note why your tool is documentation rather than evaluation. If you lean on the Article 6(3) narrow-task carve-out, record that assessment.
    6. Pick an EU-hosted, no-scoring tool. The vendor's design choices become your compliance posture, so choose one that stays on the documentation side by design.

    How Numi is built for this lane

    This is the exact boundary we built Numi to respect. Numi records, transcribes, and summarises interviews and pulls out action items and decisions, processed on European infrastructure, and it does not train on customer data. It deliberately does not score, rank, or rate candidates, because that is precisely the automated-evaluation function that would pull a hiring process into the Annex III high-risk regime.

    The design intent is simple: Numi documents the conversation so your panel has an accurate, shared record, and the hiring judgement stays with your people. That keeps the tool on the documentation side of the line the AI Act draws, while consent, transparency, and in-region processing cover the obligations that apply regardless of risk tier.

    The bottom line

    AI interview notetakers are not automatically high-risk under the EU AI Act. Annex III, point 4 targets AI that evaluates, filters, scores, or ranks candidates; a tool that only records, transcribes, and summarises does not do that. The full high-risk regime for recruitment applies from 2 December 2027 after the Digital Omnibus extension, but the prohibition on workplace emotion recognition and the AI-literacy duty are live now, and transparency applies from August 2026. Keep AI on documentation, keep humans on the decision, choose an EU-hosted tool that does not score candidates, and you get the productivity of AI notes without inheriting the heaviest part of the Act.

    This article is general information, not legal advice. For your specific situation, consult a qualified data protection or employment lawyer.

    Frequently asked questions

    Are AI interview notetakers high-risk under the EU AI Act?

    Not automatically. The EU AI Act classifies AI used to evaluate, filter, score, or rank candidates in recruitment as high-risk under Annex III, point 4. An AI notetaker that only records, transcribes, and summarises an interview, without scoring or ranking the candidate or driving the hiring decision, is not performing that high-risk function. The high-risk trigger is automated candidate evaluation, not the act of capturing the conversation.

    When do the EU AI Act high-risk rules for recruitment apply?

    The high-risk obligations for Annex III recruitment systems apply from 2 December 2027. The 2026 Digital Omnibus, Regulation (EU) 2026/1744, moved that date from the original 2 August 2026. This does not mean nothing applies before then: the prohibited-practice rules in Article 5 and the AI-literacy duty in Article 4 have applied since February 2025, and the Article 50 transparency obligations apply from 2 August 2026.

    What makes a recruiting AI tool high-risk under Annex III?

    Annex III, point 4 covers AI intended to be used for recruitment or selection, in particular to place targeted job ads, to analyse and filter applications, and to evaluate candidates. The common thread is automated judgement about people: scoring, ranking, shortlisting, or otherwise assessing candidates. A tool that produces that kind of evaluation is high-risk; a tool that only produces a transcript or a neutral summary of what was said is not.

    Does the EU AI Act ban recording job interviews?

    No. The EU AI Act does not ban interview recording. Whether you may record is a GDPR and employment-law question about consent and lawful basis, not an AI Act question. The AI Act adds obligations on top when the AI evaluates candidates, and it requires transparency when people interact with an AI system. Recording, transcription, and summarisation remain lawful with proper consent, in-region processing, and defined retention.

    What obligations apply if a recruiting AI is classified high-risk?

    A high-risk system must meet a full compliance regime: a risk-management system, data governance, technical documentation, automatic event logging, transparency to deployers, human oversight, and accuracy and robustness measures. Providers must run a conformity assessment and register the system in the EU database, and deployers carry duties too, including human oversight and, in many cases, a fundamental-rights impact assessment. This is why the transcription-versus-evaluation line matters commercially.

    Does an AI notetaker that only transcribes avoid high-risk classification?

    Yes, if it genuinely only records, transcribes, and summarises without evaluating candidates. Such a tool is not the automated candidate-assessment system Annex III targets. It still must meet GDPR consent and retention rules and the Article 50 transparency duty, and if its output is fed into a separate system that scores candidates, that downstream system may be high-risk. Choose a notetaker that deliberately does not score or rank candidates so the boundary stays clear.

    Numi is an EU-hosted AI meeting assistant built for interviews. It records, transcribes, and summarizes every conversation on European infrastructure, never trains on your data, and does not score or rank candidates.

    Get Early Access