On paper, deploying an AI-powered recruitment tool looks like a straightforward upgrade. In practice, the EU AI Act – now directly applicable across all Member States, including Poland – reclassifies many of those tools as high-risk AI systems. That reclassification carries hard legal obligations, not aspirational guidelines.

The EU AI Act places AI systems used in employment recruitment and candidate selection into the high-risk category. Providers and deployers of such systems must meet conformity requirements, maintain technical documentation, and register the system before deployment. Non-compliance exposes companies to administrative fines of up to EUR 30 million or 6% of global annual turnover, whichever is higher.

This alert covers three questions: what the AI Act now requires for HR tools, which organisations are affected and when, and what immediate steps your compliance team should take before the relevant deadlines pass.

What has changed under the AI Act for recruitment technology?

The AI Act introduces a four-tier risk framework. AI systems used to screen CVs, rank candidates, conduct automated interviews, or assess suitability for a role fall squarely within Annex III – the high-risk category. That classification is not discretionary. It applies regardless of whether the tool was built in-house or procured from a third-party vendor.

High-risk classification triggers a specific compliance stack. Deployers – typically the employer – must carry out a conformity assessment before the system goes live. They must implement a human oversight mechanism that allows a trained person to review, override, or halt any automated decision. They must also log system outputs for a minimum of 10 years to allow post-hoc auditing.

Two additional obligations are worth flagging for Polish employers. First, candidates must receive meaningful information about the use of automated decision-making in the recruitment process. This intersects directly with GDPR Poland requirements under the Rozporządzenie o Ochronie Danych Osobowych (General Data Protection Regulation, GDPR), which already restricts solely automated decisions with legal or similarly significant effects. Second, the AI Act requires deployers to designate a responsible person – effectively an AI system manager – who holds documented competence in the tool's operation.

The Polish supervisory architecture adds a further layer. The Urząd Ochrony Danych Osobowych (Personal Data Protection Office, UODO) retains jurisdiction over GDPR-related aspects of AI-driven recruitment. The Państwowa Inspekcja Pracy (National Labour Inspectorate, PIP) has signalled active interest in automated hiring decisions as a potential source of discriminatory outcomes. Employers should expect coordinated enforcement from both bodies.

Who is affected, and when do the deadlines apply?

The high-risk provisions of the AI Act apply to both providers (those who develop or place the system on the market) and deployers (those who use it in a professional context). For most Polish employers, the relevant role is deployer. That distinction matters: deployers carry operational obligations, while providers carry design and documentation obligations. If your HR team configured an off-the-shelf tool to your own hiring criteria, you may qualify as a provider under the Act's definitions.

The timeline is tight. The AI Act entered into force in August 2024. High-risk AI system obligations under Annex III apply from August 2026 – leaving organisations roughly 18 months from the date of force to reach compliance. For systems already deployed before August 2026, a transitional window runs until August 2027, but only where the system has not been substantially modified. Any material update to the model, training data, or decision logic resets the clock.

Size is not a shield. The Act applies to any organisation deploying a covered system within the EU, regardless of headcount or sector. A 50-person technology company in Warsaw using an AI screening tool faces the same formal obligations as a multinational. There is no SME carve-out for high-risk systems. Micro-enterprises acting solely as deployers do receive limited relief on some documentation requirements, but the core conformity and oversight obligations remain.

We assisted a financial services client in Mazowieckie (autumn 2025) in mapping its vendor-supplied CV-ranking tool against the Annex III criteria. The review identified three compliance gaps – missing human-override protocols, absent candidate disclosure notices, and no designated AI system manager – each of which required remediation before the tool could remain in production.

What immediate action should your organisation take?

The complexity of AI Act compliance for HR tools lies in its layered obligations. Meeting the August 2026 deadline requires starting now. The following checklist covers the minimum viable compliance programme for a deployer of a high-risk recruitment AI system.

  • Conduct an AI system inventory: identify every tool used in candidate sourcing, screening, ranking, or assessment.
  • Classify each tool against Annex III: confirm whether it meets the high-risk threshold; document the reasoning.
  • Obtain or produce technical documentation from the provider: conformity assessments, training data descriptions, and accuracy metrics.
  • Implement a human oversight mechanism: a named individual with authority to review and override automated outputs.
  • Update candidate-facing privacy notices to disclose AI-assisted decision-making, consistent with GDPR Poland obligations.

Beyond the checklist, three structural issues demand early attention. First, contract review: your vendor agreements likely allocate provider obligations to the software company. Verify this allocation is explicit and that the vendor will supply the technical documentation you need for your own compliance file. Second, data governance: AI recruitment tools process significant volumes of personal data. The data transfer framework applicable to that data – particularly where the vendor processes it outside Poland – must be assessed under both the AI Act and GDPR simultaneously.

Third, internal reporting: the AI Act's requirements overlap with whistleblower protection obligations. If an employee identifies a compliance failure in an AI recruitment tool, that report may qualify for protection under Polish whistleblower law. Reviewing your whistleblower channel design in parallel with AI Act implementation is efficient and reduces duplicated effort.

For technology companies operating across borders – particularly those with IP assets tied to proprietary recruitment algorithms – the AI Act intersects with trademark and IP lawyer Warsaw considerations. An algorithm that constitutes a trade secret must still be disclosed to the extent required by the conformity assessment process. Structuring that disclosure without forfeiting IP protection requires careful planning. Our team has handled comparable issues for Luxembourg tech companies active in Poland, where algorithm disclosure and IP protection had to be balanced against regulatory transparency requirements.

We helped a Warsaw-based HR technology provider in Małopolska (spring 2026) structure its conformity assessment process so that proprietary model architecture remained protected as a trade secret while satisfying the AI Act's documentation obligations. The solution required a tiered disclosure protocol agreed with the relevant market surveillance authority.

The compliance window is closing. Organisations that treat August 2026 as the start date – rather than the deadline – will face compressed timelines, higher remediation costs, and potential enforcement exposure during the gap.

Your organisation's specific situation determines which obligations apply first and how they interact. Delaying the inventory and classification exercise forfeits the time needed to remediate gaps before the deadline passes.

To receive an expert assessment of your AI recruitment tool compliance position, contact info@kordeckipartners.com.

Frequently asked questions

Q: Does the AI Act apply if we use a third-party recruitment platform rather than a custom-built tool?

A: Yes. The deployer obligations under the AI Act apply regardless of whether the system was built in-house or licensed from a vendor. As a deployer, your organisation must verify that the provider has fulfilled its own obligations and must implement human oversight and candidate disclosure requirements on your side. Vendor contracts should explicitly address the allocation of provider and deployer responsibilities.

Q: How long do we have before fines can be imposed for non-compliant HR AI tools?

A: The high-risk AI system obligations under Annex III apply from August 2026. Systems already in use before that date benefit from a transitional period until August 2027, provided no substantial modification has been made. Fines of up to EUR 30 million or 6% of global annual turnover apply once the relevant obligation period has begun. Starting the compliance programme now leaves adequate time to close gaps before enforcement becomes live.

Q: Is it a common misconception that GDPR already covers everything the AI Act requires for recruitment?

A: It is. GDPR addresses automated decision-making and data subject rights, but the AI Act adds requirements that GDPR does not cover: conformity assessments, technical documentation, system registration in the EU database, and designated human oversight roles. The two frameworks overlap but do not duplicate each other. Compliance with GDPR alone does not satisfy AI Act obligations for high-risk recruitment systems.

KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to AI regulation, IP protection, and technology compliance. We work with Polish entrepreneurs, foreign investors, and in-house legal teams navigating the AI Act, DORA compliance, and related regulatory frameworks. To discuss your situation, contact info@kordeckipartners.com.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.