AI-driven recruitment – three questions management should be able to answer
September 24, 2026
AI-driven recruitment – three questions management should be able to answerSeptember 24, 2026 Why this matters nowAI tools that screen applications and rank candidates are rapidly gaining traction among employers. These tools directly determine which applicants advance in the recruitment process, and which do not. The EU AI Act classifies such tools as high-risk AI systems. The specific requirements for high-risk systems will apply from 2 December 2027, but the General Data Protection Regulation (GDPR) and the Swedish Discrimination Act already apply in full. The period leading up to 2027 should therefore not be seen as a breathing space, but as a window for preparation for what is already here as well as what will come. The regulatory landscapeThe AI Act. Annex III to the AI Act classifies AI systems intended for recruitment or selection as high-risk systems, including systems used for posting targeted job advertisements, screening applications and evaluating candidates. Systems that profile natural persons are always treated as high-risk. The requirements cover risk management, data quality, transparency, human oversight and accuracy and robustness. Deployers of such systems must, among other things, inform affected workers and trade union representatives. GDPR. GDPR gives individuals the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect them. GDPR also requires that data subjects are informed of the existence of automated decision-making and the underlying logic. AI-based candidate screening will typically involve systematic profiling with significant effects, triggering the requirement for a data protection impact assessment. The Discrimination Act. The prohibition against discrimination applies to job applicants and covers all seven grounds of discrimination, including ethnicity, gender, age and disability. The concept of indirect discrimination, where an apparently neutral criterion or practice places a protected group at a particular disadvantage, is directly relevant to algorithm-based selection. Employers are also required to take proactive measures to prevent discrimination in the recruitment process. The Swedish Authority for Privacy Protection (IMY) has emphasized that the GDPR’s accuracy principle requires that personal data processing, as well as the results of such processing, are not discriminatory. Practical implications and recommendationsThose responsible for recruitment should be able to answer three core questions:
Key takeawaysUse the time until 2 December 2027 to carry out a data protection impact assessment of existing recruitment tools, review vendor agreements for transparency and data quality provisions, and establish procedures for ongoing monitoring. In our view, the AI Act’s requirements for high-risk systems should however not set the timeline for action. Legal responsibility under the GDPR and the Discrimination Act applies already today. Employers who review their tools now, ensure meaningful human oversight and hold their vendors to the right standards are building a stronger foundation, both for regulatory compliance and for discrimination-free recruitment. Latest Events |