All case studies

Project 03

EU AI Act Classification

A worked classification exercise for a hypothetical AI-enabled workforce screening system.

Scenario

This independent exercise assesses a hypothetical AI system used to rank applicants for recruitment shortlisting within an EU-based organisation. It illustrates a classification method and is not legal advice.

Step 1 — prohibited-practice screen

The first review asks whether the design involves a prohibited practice—for example certain manipulative techniques, impermissible sensitive-trait inference or other uses specifically restricted by law. The facts in this scenario do not establish a prohibited practice, but the screen must be evidenced rather than assumed.

Step 2 — high-risk classification

Because the system influences access to employment, it is likely to sit within a high-risk use category, subject to the Act’s detailed scope, exemptions and the organisation’s role in the value chain. Classification should be confirmed with qualified legal advice against the actual design and deployment context.

Step 3 — role mapping

The organisation must determine whether it is acting as deployer, provider, importer, distributor or in more than one role. Obligations and evidence differ. Contract language cannot substitute for examining who develops, modifies, brands, supplies and operates the system.

Step 4 — control and evidence expectations

| Domain | Example evidence | |---|---| | Risk management | Versioned risk file, foreseeable misuse, control rationale | | Data governance | Provenance, representativeness, quality checks, limitations | | Technical documentation | System purpose, architecture, performance and known limits | | Record keeping | Logs supporting traceability and incident investigation | | Transparency | Instructions, limitations and meaningful user information | | Human oversight | Reviewer authority, competence, override and escalation design | | Accuracy and robustness | Defined metrics, thresholds, resilience and security testing | | Post-market monitoring | Performance, incidents, complaints and change triggers |

Transparency and affected people

Applicants should receive clear information where required, and the organisation should ensure that explanations, review routes and contestability are operational—not merely present in a privacy notice. Human reviewers need evidence that helps them identify inappropriate ranking rather than simply ratify it.

GPAI considerations

If the recruitment system incorporates a general-purpose AI model, the organisation should map which evidence comes from the upstream provider and which responsibilities remain with the downstream system owner or deployer. Provider documentation supports, but does not complete, the use-case assessment.

Decision

The appropriate route is high-risk governance pending legal confirmation, with implementation conditional on documented role mapping, conformity responsibilities, data and bias evaluation, human oversight, monitoring and applicant redress. If the organisation cannot obtain sufficient evidence from the vendor, that is a decision-relevant risk—not an administrative inconvenience.

Assumptions and limits

This case study deliberately avoids claiming a definitive legal determination. Actual classification depends on current law, guidance, system facts, jurisdiction, contractual roles and material modifications.