Article 6 of 6
The US cases show how discrimination law reaches automated hiring. In Europe, two further regimes matter for organisations that provide or use AI recruitment systems: the EU AI Act, which regulates many of these tools as high-risk systems, and the revised Product Liability Directive, which treats software and AI as products and applies strict liability when a defect causes covered harm.
These frameworks do not replace equality law. They sit alongside it. A recruitment system can create discrimination exposure, regulatory duties under the AI Act, and product liability exposure under the Directive at the same time.
The GDPR is a fourth layer, not a substitute for any of the three. CVs, scores, rankings and video assessments are personal data. A candidate can use an access request, a complaint to a supervisory authority, or a claim for compensation under the GDPR without first proving discrimination, an AI Act breach, or product defect.
Why recruitment AI is high-risk under the EU AI Act
Annex III of the EU AI Act treats AI systems used in employment and recruitment as high-risk in defined cases. That includes systems used to place targeted job advertisements, analyse and filter applications, and evaluate candidates.
The reason is the impact on people's access to work. Automated ranking and rejection at scale can cause significant harm if the system is biased, opaque or poorly controlled. High-risk classification brings duties for providers (who place the system on the market) and deployers (who use it), including risk management, data governance, transparency, human oversight, logging, documentation and, for providers, a quality management system under Article 17.
Employers using third-party screening tools are usually deployers. Vendors placing those tools on the EU market are usually providers. An employer that builds its own ranking model may be a provider in respect of that system. Both roles need clarity in contracts and in day-to-day control.
Fundamental rights and Article 27
Annex III classification exists because recruitment AI can affect Charter rights: non-discrimination, protection of personal data, and the right to engage in work. Deployers of high-risk systems still have Article 26 duties: follow the instructions for use, assign competent human oversight, monitor operation, and keep logs under their control.
Article 27 requires a fundamental rights impact assessment before first use for specified deployers of Annex III systems: bodies governed by public law, private entities providing public services, and deployers of the credit and insurance systems in Annex III, points 5(b) and 5(c). A private employer is not automatically inside Article 27. Public employers, and private bodies delivering public services, often are.
Where a FRIA is required, it must describe the real hiring process, who is filtered out, residual risk after oversight, and what happens if those risks materialise. A previous assessment, or the provider's documentation alone, is not enough if the process or the people affected are different. Where Article 27 does not apply, equality law, the GDPR and Article 26 still require the organisation to know what the system does to people.
GDPR and access requests
The employer is normally the controller. The vendor that hosts the scoring engine is normally a processor and may only process candidate data on documented instructions under Article 28. If the vendor trains models on customer candidate data, or sets rejection logic the employer cannot see, it may be a joint controller, or a controller in its own right, for that part of the processing.
Article 22 can apply where a score auto-rejects a candidate, or where a human only rubber-stamps the ranked list. The person then has a right to human intervention, to express their view, and to contest the outcome. Video analysis of faces, voice profiling, or inference of health or disability can engage Article 9.
Under Article 15 a candidate can ask for their file, their score or rank, and, where Article 22 is engaged, meaningful information about the logic involved. The employer must answer. The vendor must assist. A contract that leaves the employer unable to retrieve a score or an explanation is not an adequate processing arrangement. A DPIA under Article 35 will often be required where people are evaluated systematically at scale and access to work is at stake. The DPIA examines privacy risk. It does not replace a FRIA, an equality assessment, or product-liability evidence.
Where the Product Liability Directive comes in
Directive (EU) 2024/2853 modernises EU product liability law. From 9 December 2026, it applies to products placed on the market or put into service on or after that date. Software and AI systems are expressly included as products. Providers of AI systems are treated as manufacturers for these purposes.
That matters for recruitment AI. If a defective AI system causes damage covered by the Directive - for example personal injury or other recognised heads of damage in a qualifying case - the injured person can claim under strict liability. They do not have to prove negligence. In complex AI cases, courts can order disclosure of technical information and may presume defect or causation where the claimant shows these are likely, especially given the technical complexity of AI.
Defectiveness is assessed against the safety a person is entitled to expect. For AI, that assessment can take account of learning behaviour, updates under the manufacturer's control, cybersecurity, and interaction with other systems. Failure to meet mandatory safety requirements intended to protect against the relevant risk can support a presumption of defect.
So for vendors and others who place recruitment AI on the EU market, the Product Liability Directive creates a compensation route that turns on defect, damage and causation - not on the claimant proving fault.
Two clocks, not one
The timelines are different, and that is important for planning.
- Product Liability Directive: applies to AI products placed on the market or put into service from 9 December 2026.
- AI Act high-risk obligations (after the Omnibus adjustments): for many Annex III systems, including typical recruitment use cases, apply from 2 December 2027.
Liability exposure under the Product Liability Directive can therefore begin before the full high-risk AI Act machinery is mandatory for those systems. Organisations should not read the later AI Act date as a quiet period. Discrimination law already applies. Product liability for AI products applies from December 2026. High-risk AI Act duties follow for in-scope systems on the 2027 timeline.
The GDPR is already in force. Access requests, Article 22 and DPIA duties do not wait for 2026 or 2027.
How the regimes reinforce each other
In practice, the controls that reduce discrimination risk and support AI Act compliance also strengthen a product liability position:
- clear intended purpose and instructions for use
- data governance and testing for harmful bias
- human oversight of screening outcomes
- logging and technical documentation
- controlled updates and monitoring after deployment
- evidence that mandatory safety-related requirements were considered
The same file answers a GDPR access request, supports an Article 26 oversight record, and is the starting point for disclosure if a product-liability claim is brought. Under the Product Liability Directive, weak documentation and inability to explain how a system operated make claims harder to defend, especially where disclosure orders and presumptions apply. Under the AI Act, the same weaknesses undermine high-risk compliance. Under equality law, they make it harder to show that a selection practice was fair and job-related. Under the GDPR, they make an access request or an Article 22 challenge harder to meet.
iTutorGroup illustrates a blunt failure: automated rejection tied to age. That is a discrimination case, but it also shows the kind of system behaviour that robust design, testing and oversight are meant to prevent. Mobley v. Workday raises the accountability question when a platform screens candidates at scale. In the EU, provider and deployer duties under the AI Act, together with manufacturer liability under the Product Liability Directive for defective AI products, push vendors and employers toward clearer role allocation and stronger evidence - even though the US case is still ongoing and rests on different legal theories.
What organisations should do
For recruitment AI used in or supplied to the EU:
- Classify tools against the AI Act's high-risk criteria.
- Assign roles - provider, deployer, or both - and reflect them in contracts.
- Test for discriminatory outcomes and keep records of methodology and results.
- Ensure meaningful human oversight of ranking and rejection.
- Maintain technical documentation, logs and update history sufficient for regulatory scrutiny and, from December 2026, liability defence.
- Treat AI hiring tools as products for liability readiness when they are placed on the EU market, not only as HR software.
- Align privacy, equality, AI Act and product safety/liability work so evidence is not scattered across teams.
To that list add three GDPR and rights steps that use the same records:
- Name a lawful basis for each purpose, complete a DPIA where Article 35 applies, and keep processor terms that stop the vendor training on candidate data unless that is agreed.
- Be able to answer an Article 15 request with the file, the score and a usable explanation of the logic, within the statutory time.
- Complete an Article 27 FRIA before first use if the organisation is one of the deployers the Act names. If it is not, still document who the ranking system filters out, because equality law and Article 26 remain in force.
Closing the series
AI in recruitment can improve efficiency. It can also deny qualified people a fair chance of being considered. US enforcement and litigation show how discrimination law applies to automated screening. The EU AI Act adds high-risk regulatory duties for many recruitment systems. The Product Liability Directive adds strict liability for defective AI products from 9 December 2026.
The durable response is the same across these regimes: know the tools, control what they optimise for, keep humans able to intervene, document how the system works, and be able to show evidence if a candidate, regulator or court asks. That is good hiring governance. In Europe, it is also increasingly a legal necessity.