For UK SMEs

Compliance for recruitment and staffing agencies.

Recruitment carries three overlapping duties: high-risk AI screening under the EU AI Act, candidate and client data under UK GDPR, and the Worker Protection Act 2024 preventative duty across your own staff and placed workers.

Why this matters

Recruitment sits at the intersection of AI, data, and worker protection duties.

  • Candidate screening, CV parsing, and ranking tools fall under EU AI Act Annex III high-risk classification.

  • Article 26 deployer obligations apply: human oversight, impact assessment, record-keeping.

  • UK GDPR Article 22 automated decision-making rules tighten the documentation burden further, alongside privacy notices, a ROPA, and a DPIA for candidate data.

  • The Worker Protection Act 2024 preventative duty covers harassment of your own staff and of workers you place, including harassment by clients and site contractors.

Recommended packs

The two tiers most recruitment businesses need.

Clear pricing. 14-day refund.

For UK SMEs

Professional

For recruiters using AI in screening, sourcing, or candidate communications.

Starting at£899one-off
  • AI Acceptable Use Policy
  • AI Literacy Policy
  • Article 50 Transparency Disclosures
  • Human Oversight SOP
  • AI Incident Response Procedure
  • Vendor AI Risk Register
Start your pack
For UK SMEsRecommended

High-Risk Ready

For agencies running AI-driven screening, ranking, or matching: a full Annex III deployer pack.

Starting at£2,499one-off
  • Everything in Professional
  • Fundamental Rights Impact Assessment
  • Risk Management Plan
  • Conformity Self-Assessment Checklist
Start your pack

FAQ

Common questions for recruitment.

Does this apply if we only use AI for CV parsing, not final decisions?

Yes. The EU AI Act classifies any AI system used in recruitment workflows as high-risk, even if a human makes the final call.

What if we use tools like LinkedIn Recruiter or HireVue?

You’re a deployer under the Act. You hold Article 26 obligations regardless of who built the tool.

How does this interact with UK GDPR?

UK GDPR Article 22 covers the data protection side; the EU AI Act covers the AI governance side. You need both.

What did the Digital Omnibus political agreement (May 2026) actually change?

The Digital Omnibus political agreement narrowed and clarified scope in several places, eased some technical compliance burdens for general-purpose AI providers, and pushed the substantive obligations for most Annex III high-risk AI systems to December 2027. What it did not change: the Article 4 AI literacy obligations, the Article 50 transparency obligations, the prohibited-use rules, and the governance and documentation expectations placed on deployers. For UK businesses deploying AI tools, the baseline policy framework you need is essentially unchanged, and only the timetable for high-risk system technical conformity has moved.

Has the high-risk AI deadline really moved to December 2027? What still applies now?

Yes. The agreement pushes the substantive technical and conformity obligations for most Annex III high-risk AI systems to December 2027, giving providers more time to complete conformity assessments and CE marking. Transparency obligations (Article 50), AI literacy obligations (Article 4), prohibited-use rules, governance structures, and the documentation expected of deployers sit outside that extension and already apply. In practice the policy framework, Acceptable Use, AI Literacy, Article 50 disclosures, oversight SOPs and vendor registers, needs to be in place now, even if you are also a high-risk system provider working to a 2027 conformity deadline.

Does the Digital Omnibus mean we can wait until 2027 to act?

No. The Omnibus extended one specific timetable, substantive conformity for most Annex III high-risk systems, to December 2027. It did not defer the transparency, literacy, governance, or deployer documentation obligations. If your business uses AI tools (ChatGPT, Copilot, an internal copilot, an AI chatbot, AI-assisted recruitment or marketing), those obligations already apply to you rather than waiting until 2027. Waiting risks both regulatory exposure and PI questionnaire failure at renewal.

What actually counts as a “high-risk” AI system under Annex III?

Annex III lists categories of AI systems treated as high-risk because of where they are used, not because of the underlying technology. These include AI used in: biometric identification and categorisation; critical infrastructure (water, gas, electricity, transport); education and vocational training (admissions, grading, proctoring); employment (recruitment, CV screening, performance evaluation, task allocation, termination); access to essential private and public services (credit scoring, insurance pricing, benefits eligibility, emergency dispatch); law enforcement, migration and border control; and administration of justice and democratic processes. If your AI sits in any of these workflows, even if it only assists a human decision, you are likely a high-risk deployer.

Does the EU AI Act still apply to UK businesses post-Brexit?

Yes. The Act applies extraterritorially. A UK business is in scope if it places an AI system on the EU market, if the output of its AI system is used in the EU, or if it employs or serves people in the EU or EEA. Brexit did not remove EU regulatory reach over UK businesses whose AI touches EU users, staff, or customers, much as UK GDPR continues to interact with EU data protection law for cross-border processing.

What happens if our business is not compliant?

Enforcement of the EU AI Act is phased and already under way, and there is no grace period once an obligation applies to you. National regulators (in the UK, the ICO and sector regulators acting in cooperation with EU authorities) can investigate, request your documentation, and refer matters for fines. Penalties reach €15 million or 3% of global annual turnover (whichever is higher) for breaches of deployer and transparency obligations, and €35 million or 7% of global turnover for the most serious prohibited-use breaches. PI insurers are already asking for documented AI policies at renewal, so undocumented AI use can affect cover as well as expose you to enforcement.

Reviews

What UK businesses say.

“Clausely is a total lifesaver! I used the Risk Checker and it really opened my eyes to where my business was exposed. It provided exactly the clarity I needed and gave me total peace of mind.”

Rosa Rambla Espejo

Ready to get your recruitment compliance pack?

Tailored to your business. Delivered in minutes. Defensible for years.

Start your pack

Not sure where you stand? Take the free compliance risk check.