Playbook6 min readTenPerZent

    EU AI Act forinternational companies hiring in Europe.

    EU AI Act explained for US, UK, and international companies hiring in Europe. Article 26 requirements, penalties, what to ask your ATS vendor. Updated for August 2026 enforcement.

    Does it apply to your company?

    The EU AI Act applies if either of these is true:

    • You have an EU-based legal entity
    • You don't have an EU entity, but the AI system you use processes data of EU residents or affects them

    For recruiting specifically: if a US-based company uses an AI-powered ATS to screen candidates who live in France, Germany, Italy, or any other EU country, the EU AI Act applies. Even if no AI is run on EU soil. Even if the candidate is being hired for a US role.

    This is the same extraterritorial principle as GDPR. If you assume "we're a US company so it doesn't apply," you're wrong and exposed.

    What it actually requires for hiring AI

    The AI Act classifies AI systems used for hiring, performance evaluation, and promotion decisions as "high-risk AI systems." Specifically (Annex III, point 4):

    • AI used to filter or rank candidates
    • AI used to evaluate candidate performance during the process
    • AI used to make or substantially influence hiring decisions
    • AI used to evaluate work performance for promotion/demotion/termination

    If your ATS does any of this — including the auto-ranking of resumes that virtually every modern ATS does — Article 26 applies to you.

    Article 26 — what "transparency" means in practice

    Article 26 of the EU AI Act sets specific obligations for organizations deploying high-risk AI systems (this is you, the company using the ATS, not just the vendor):

    1. Use the system as intended. If the AI is built for a purpose, don't use it for another (e.g., don't use a resume-parser to make hiring decisions if it wasn't built for that).
    2. Human oversight. Meaningful, not symbolic. A human must be able to ignore the AI's suggestion with documented reasoning.
    3. Transparency to affected persons. Candidates must be informed they're being evaluated by an AI system, what its purpose is, what consequences may follow.
    4. Logging. Keep automatic logs of system operation for at least 6 months — longer per other legislation.
    5. Cooperate with authorities. Provide documentation and access when requested by EU authorities.
    6. Inform workers and their representatives before deployment (Article 26(7)).
    7. Conduct a Fundamental Rights Impact Assessment (FRIA) for public sector deployers and some private deployers offering services of public nature (Article 27).

    What to ask your ATS vendor

    If your ATS uses AI, ask the vendor these questions before August 2, 2026:

    1. Is your AI system classified as high-risk under the EU AI Act?
    2. Do you have a CE marking for the system, or are you in the process of obtaining one?
    3. Can you provide the technical documentation required by Annex IV (model architecture, training data, performance per demographic group, known limitations)?
    4. Do you publish model cards for each AI feature?
    5. How do you support our Article 26 obligations (transparency to candidates, human oversight, logging)?
    6. What is your incident reporting process if the AI behaves unexpectedly?
    7. Do you sign a Data Processing Agreement and have GDPR Article 28 documentation?
    8. Can you produce an export of all AI-assisted decisions made by our instance, in a regulator-readable format?

    If your vendor cannot answer these questions clearly by spring 2026, you have a compliance risk you're carrying — not them.

    Penalties — what's at stake

    The AI Act tiers penalties based on the violation:

    Violation typeMaximum fine
    Prohibited AI practices (Article 5)€35M or 7% of global annual turnover
    Non-compliance with key high-risk requirements€15M or 3% of global annual turnover
    Supplying incorrect information to authorities€7.5M or 1.5% of global annual turnover

    Whichever is higher applies. For an SME, capped at smaller of the absolute or percentage figure.

    Beyond fines: reputational damage, potential class actions from affected candidates, and prohibition orders that can shut down your hiring process.

    Key dates for international companies

    • February 2, 2025 — General provisions and prohibitions on certain AI practices entered into force
    • August 2, 2025 — Rules for general-purpose AI providers became applicable
    • February 2, 2026 — National competent authorities established by Member States
    • August 2, 2026 — Most high-risk AI system rules become enforceable (this includes AI for hiring)
    • August 2, 2027 — Full application of high-risk requirements for AI systems integrated in products

    Action plan for international companies — 6 steps

    1. Inventory your AI in hiring. List every AI feature in your ATS, sourcing tool, assessment platform, scheduling tool.
    2. Classify each system. Is it high-risk under Annex III? If yes, Article 26 applies.
    3. Audit your vendors. Send them the 8 questions in the section above. Get written answers.
    4. Set up transparency notice for candidates. Add language to your application form, careers page, and offer process. Inform candidates about AI use, purpose, consequences.
    5. Establish human oversight workflows. Document who has authority to override AI decisions, with what reasoning, in what timeframe.
    6. Inform workers and their representatives. If you have a works council in EU operations, brief them. If not, document the disclosure process.

    Most US companies hiring in the EU are 6-12 months behind on this. The August 2, 2026 deadline is firm. Starting now means you finish on time.

    Frequently asked questions

    Does the EU AI Act apply to my US-based company?

    Yes, if you use AI-powered hiring tools to screen, rank, or evaluate candidates who live in the EU — even if you don't have an EU office. The extraterritorial scope mirrors GDPR.

    When does enforcement start?

    August 2, 2026 for most high-risk AI hiring systems. Prohibitions on certain practices were already in force from February 2, 2025.

    What's the difference between an AI provider and a deployer?

    The provider is the company that develops and sells the AI system (e.g., your ATS vendor). The deployer is the company that uses it (e.g., your company). Different obligations apply to each. As the deployer, your obligations come from Article 26 and related provisions.

    Does this apply to LinkedIn Recruiter's AI suggestions?

    If LinkedIn's AI features rank or filter candidates in a way that influences hiring decisions, yes — they qualify as high-risk. LinkedIn, as the provider, has primary obligations. As the deployer using LinkedIn Recruiter, you still have Article 26 obligations (transparency, oversight, logging).

    What if my ATS vendor refuses to provide AI Act documentation?

    That's a major red flag. As the deployer, you can't comply without their cooperation. Either escalate to executive level (this isn't optional for them either if they sell to EU customers), or plan a migration to a compliant vendor before August 2, 2026.

    Stop fighting your ATS. Start hiring.

    Focus on people, not paperwork. Screen your first 100 CVs free. No credit card, no setup call.

    100 free screenings · No credit card · Live in 60 seconds

    Stop reading CVs. Start hiring better.

    Drop your next job description in. TenPerZent ranks every applicant with evidence and surfaces your top 5 — usually before your morning coffee.

    • EU AI Act ready
    • 60-second setup
    • Cancel anytime