Tools and Frameworks Compliance

What does the EU AI Act require for engineering hiring?

In short

Since 2 August 2026, the EU AI Act has treated AI systems used in employment decisions as high risk, with obligations for providers and deployers and fines up to 3 percent of global turnover. Engineering hiring teams need documentation, human oversight, adverse impact monitoring, and clear vendor evidence in place now.

This article offers general guidance and does not constitute legal advice.

  • Regulation 2024/1689, Annex III Section 4 covers employment uses: recruitment, application screening, and candidate evaluation.
  • Obligations reach deployers as well as providers, and the reach is extraterritorial.
  • The decisive question is where AI or machine learning sits in the scoring path, and whether it makes or materially informs the decision.
  • Codility scores deterministically, with no AI or machine learning making automated hiring decisions, and AI Follow-Up Questions are intentionally not scored.
  • Human oversight and reviewable evidence trails sit at the center of the obligations, and they are sound hiring practice regardless.

Does the EU AI Act apply to your hiring process?

Most likely yes, if you use an AI system to recruit, screen, or evaluate candidates. Regulation 2024/1689 names employment as a high-risk domain, and Annex III Section 4 covers systems used for recruitment, application screening, and candidate evaluation.

The obligations reach deployers, the organizations that use these systems in their hiring, alongside providers, the organizations that build and supply them. Many employers are deployers even when a vendor built the tool.

Provider and deployer under the EU AI Act. The provider builds and supplies the AI system. The deployer uses it in its own processes, such as an employer screening candidates. Both carry obligations, and one organization can be both.

The reach is extraterritorial. A company based outside the EU can fall in scope when its system assesses candidates for roles in the EU, or when the outputs are used inside the EU. Article 111 sets transition provisions for systems already on the market, so timing can vary. Confirm how it applies with legal counsel.

What must be in place now?

High-risk obligations have applied since 2 August 2026, and deployers need a defined set of controls in place. In plain language, that means human oversight of decisions, documentation and record-keeping, adverse impact monitoring, and evidence you can produce on request.

A human should review and own every hiring decision, with no automated rejection. Records should show how a decision was reached and what evidence supported it.

The checklist further down mirrors these obligations so a talent or engineering team can work through them line by line. Because the obligation set is detailed and guidance is still arriving, treat the checklist as a working aid and confirm the full list with legal counsel.

Where does a coding assessment sit under the Act?

A coding assessment sits under the Act wherever AI or machine learning makes or materially informs the hiring decision. That single question does more to place your assessment than any product label.

A decision diagram. Where does AI or machine learning sit in the scoring path, and does it make or materially inform the decision? If it does, Annex III Section 4 places the assessment in the high-risk category. If scoring is deterministic with no AI making or informing the decision, the analysis changes. Final classification depends on configuration and use.

Both carry obligations, so both sides of the relationship matter: the vendor is often the provider of the system, and the employer is usually the deployer.

Codility’s posture is deterministic scoring, with no AI or machine learning making automated hiring decisions on the platform. AI Follow-Up Questions are intentionally not scored, so they inform a human reviewer rather than drive an outcome. Final compliance depends on customer configuration, so confirm how your own deployment is set up.

What evidence should you demand from any assessment vendor?

Demand evidence that the assessment is fair, documented, and reviewable by a human. Four items carry most of the weight: adverse impact data at every cut score, linguistic fairness auditing, a technical manual, and reviewable evidence trails.

Codility monitors adverse impact to the EEOC four-fifths threshold at every measured cut score. A cApStAn linguistic audit found 65 percent of tasks at or below B1 CEFR, which helps fairness for non-native English speakers. The Technical Manual is structured to APA Standards, and every result carries a reviewable evidence trail.

Accessibility belongs in the same request. Ask for conformance to WCAG 2.2 AA, so candidates are not disadvantaged by the tool itself.

What does this have to do with cheating and integrity controls?

Candidate monitoring is itself in scope, so integrity controls need the same defensibility as your scoring. Behavioral monitoring and risk scoring process candidate data, which brings them squarely into the compliance conversation.

Codility’s integrity risk level is deterministic, with four bands from None to High, and a human confirms every flag. A signal informs a decision, and it never triggers an automated rejection.

Our companion article on preventing cheating in coding assessments covers the layered controls in full, and it shares the same evidence-first posture this piece describes.

What happens now that enforcement has begun?

Enforcement is under way and further guidance will keep arriving, so treat compliance as a maintained practice rather than a one-time project.

This page carries visible published and last-updated dates, and it will be updated as guidance lands and as enforcement patterns emerge.

The through-line is simple: defensible hiring is designed, not bolted on. Teams that built oversight, documentation, and reviewable evidence into the process before the date are now confirming what they already do rather than rebuilding it. Teams that have not can still close the gap, and the checklist below is where to start.

The EU AI Act hiring readiness checklist

The checklist below mirrors the obligations in this article. It doubles as a working document for talent, engineering, legal, and procurement. Confirm the complete obligation set with legal counsel before you rely on it.

Scope

  • Confirm whether your recruitment, screening, or candidate-evaluation tools use an AI system covered by Annex III Section 4.
  • Identify your role for each system: provider, deployer, or both.
  • Confirm whether the Act reaches you through extraterritorial scope, for example assessing candidates for roles based in the EU.
  • Check whether Article 111 transition provisions affect the timing for any system already in use, and confirm with legal.

Obligations that now apply

  • Confirm a human reviews and owns every hiring decision, with no automated rejection.
  • Keep documentation and reviewable evidence trails for each assessment and decision.
  • Monitor adverse impact at every cut score you use.
  • Record where AI or machine learning sits in your scoring path, and whether it makes or materially informs any decision.

Vendor evidence to request

  • Adverse impact data at every cut score.
  • Linguistic fairness auditing evidence.
  • A technical manual you can hand to legal and procurement.
  • Reviewable evidence trails on every result.
  • Accessibility conformance to WCAG 2.2 AA.

Integrity and monitoring

  • Confirm candidate monitoring is proportionate and its data handling is documented.
  • Confirm integrity signals inform a human decision and never trigger an automated rejection.
  • Confirm any risk scoring is explainable, for example deterministic bands rather than an opaque model.

Frequently asked questions

Is a coding assessment a high-risk AI system under the EU AI Act?

It can be. If the assessment uses an AI system to recruit, screen, or evaluate candidates, Annex III Section 4 places it in the high-risk category. A deterministic assessment with no AI or machine learning making or materially informing the decision changes that analysis. Confirm the scoring path with your vendor, because final classification depends on how the system is configured and used.