AI Act Sorted Sample Report
Get your company's assessment Book a call
Sample
AI Act Sorted · aiactsorted.uk
EU AI Act Compliance Assessment
ScaleHR Limited
Prepared for Head of Legal, ScaleHR
Assessment date 27 June 2026
Regulatory basis Regulation (EU) 2024/1689
Systems assessed 4 AI systems
This assessment is a compliance guidance document, not legal advice. Consult a qualified solicitor for formal legal representation. Reviewed by Taha Haroon Janjua, LLB, University of Law — UK.
Claude API — CV Screening
Anthropic · Deployer
Deployer High Risk
Internal Candidate Scoring
ScaleHR-built ML model
Provider High Risk
GPT-4 — Job Descriptions
OpenAI · Deployer
Deployer Limited Risk
Customer-Facing Chatbot
External-facing
Deployer Limited Risk

1 Executive Summary

The Bottom Line

Two of ScaleHR's four AI tools — the CV screening system and the internal candidate scoring model — sit in the highest risk category under EU law that takes full effect in August 2026. This is not a technicality. These tools make judgments about people's job prospects, which is exactly what regulators wrote this law to govern.

The other two tools (the chatbot and job description generator) carry lighter obligations, but still require action. ScaleHR's most exposed position is the scoring model built in-house: as the creator, not just the user, ScaleHR carries the heaviest compliance burden.

Three Things That Must Happen Before August 2026

1. Fix the internal scoring model — this is the priority.
As the builder of this system, ScaleHR must produce formal technical documentation of how it works, prove it has been tested for bias against protected groups, and demonstrate that human reviewers can meaningfully understand and challenge its outputs. A black-box score that no one can explain is non-compliant. This work realistically takes six to twelve months. Time is already tight.

2. Add human review gates to both AI recruitment tools.
Neither the CV screening system nor the scoring model can be the last word on a candidate. The law requires that a qualified person reviews AI outputs and can override them before any decision affects an applicant. These review steps must be formalised and documented — informal practices are not sufficient.

3. Tell candidates their applications are assessed by AI.
Anyone whose CV enters these systems must be told, at the point of application, that automated tools are involved and that they can ask questions about how those tools were used. Ready-to-implement notice language is provided in Section 3 of this report.

What Happens If ScaleHR Does Not Act

Fines reach €15 million or 3% of global annual turnover, whichever is higher, for high-risk system violations. Beyond financial penalties, regulators can order suspension of the tools entirely — which would halt core product functionality. There is also meaningful reputational and litigation risk: candidates who believe they were unfairly screened by an undisclosed, untested AI system have grounds to complain to data protection authorities and employment tribunals simultaneously.

Recommended immediate action: Assign an owner to the scoring model compliance workstream this month.

2 Risk Classification

ScaleHR falls within EU AI Act scope. German and Dutch operations mean the Act applies directly. UK operations fall outside EU AI Act jurisdiction, but ScaleHR's EU customer base (30%+) means compliance is non-negotiable for EU-facing systems.

Claude API — CV Screening
Provider: Anthropic · ScaleHR Role: Deployer
High Risk

Regulatory basis: Annex III, Point 4(a)

Annex III explicitly lists "AI systems used for recruitment or selection of natural persons, notably for advertising vacancies, screening or filtering applications, evaluating candidates in the course of interviews or tests." CV screening is the canonical example this provision was written to capture. There is no ambiguity here.

Deployer obligations triggered
  • Conduct a fundamental rights impact assessment before deployment (Article 26(9))
  • Implement a human oversight mechanism — a human must review, override, or halt CV screening outputs before they affect candidates (Article 26(1))
  • Ensure input data governance: CVs fed into Claude must be relevant, representative, and not introduce discriminatory proxies (Article 26(5))
  • Maintain logs of system use sufficient to enable post-hoc auditing (Article 26(6))
  • Inform candidates that AI was used in assessing their application
  • Register the use case in the EU database for high-risk AI systems (Article 49(2))
  • Verify Anthropic has completed conformity assessment and CE marking for this use case. If not, ScaleHR cannot lawfully deploy after August 2026.
Confidence: High
Internal ML Candidate Scoring Model
ScaleHR-built · ScaleHR Role: Provider — elevated obligations
High Risk

Regulatory basis: Annex III, Point 4(a) — Provider obligations

Same Annex III basis as System 1, but the compliance profile is significantly more demanding because ScaleHR is the provider of this system, not merely a deployer. They built it. As a 45-person company building and operating a high-risk AI system in the employment sector, ScaleHR faces the same substantive obligations as a large enterprise. There is no SME carve-out that eliminates these requirements.

Provider obligations triggered (Article 9–17 burden)
  • Establish and maintain a quality management system covering design, development, testing, and monitoring (Article 17)
  • Compile full technical documentation per Annex IV: architecture, training data, performance metrics, known limitations (Article 11)
  • Implement data governance: training/validation/testing datasets examined for biases, demographic balance assessed (Article 10)
  • Conduct conformity assessment — self-assessment under Annex VI likely sufficient; must be formally confirmed and documented
  • Register in the EU AI Act database (Article 49(1)) and apply CE marking (Article 48)
  • Maintain post-market monitoring: track real-world performance and update documentation when the system is modified (Article 72)
  • Ensure human oversight by design: technically designed so humans can interpret outputs and intervene (Article 14)

Note: If the model scores candidates on characteristics that function as proxies for protected characteristics (age inferred from graduation dates, gender from name patterns), ScaleHR faces simultaneous GDPR Article 22, German AGG, and UK Equality Act exposure. This intersection warrants immediate legal review independent of AI Act timelines.

Confidence: High
GPT-4 — Job Description Generation
Provider: OpenAI · ScaleHR Role: Deployer
Limited Risk

Regulatory basis: Article 50(4) — with conditional Annex III risk

The primary obligation is disclosure: AI-generated content intended for publication must be declared as AI-generated unless substantially human-edited (Article 50(4)). Job descriptions published on ScaleHR's platform or customers' careers pages are public-facing content and trigger this obligation.

Conditional escalation: If GPT-4 is used to determine role requirements that feed into the CV screening or scoring pipeline, the use case edges into Annex III Point 4(a) territory — "advertising vacancies." Confirm and document the human review step between GPT-4 output and publication to maintain the limited-risk classification.

Confidence: Medium — depends on workflow
Customer-Facing Chatbot
External-facing · ScaleHR Role: Deployer
Limited Risk

Regulatory basis: Article 50(1)

Article 50(1) requires that any AI system interacting with natural persons in real time be designed to inform users they are interacting with an AI, unless this is obvious from context. The chatbot must identify itself as an AI at the start of each interaction, visible on the same screen — not buried in a footer or settings menu.

Escalation trigger: If the chatbot ever makes or substantially influences decisions about individual candidates or employees, reclassify upward to Annex III / high-risk immediately. Confirm chatbot functionality does not include candidate triaging or collection of screening responses.

Confidence: High

3 Article 50 Disclosure Language

Ready-to-implement language for each AI transparency obligation that applies to ScaleHR. Bracketed fields must be completed before deployment. These satisfy EU AI Act Article 50 obligations — they run in parallel to, and do not replace, GDPR Articles 13/14 privacy notices.

💬

Chatbot Interface Disclosure

Article 50(1)
✓ Ready to implement

Primary Disclosure — Display on First Interaction

Must appear at the start of every conversation session, before the user submits any input. Visible on the same screen where the user first encounters the chat interface.

You are interacting with an AI system.

I am ScaleHR's automated assistant, powered by artificial intelligence. I am not a human. I can answer questions about [ScaleHR's platform / your job application / HR policies — select applicable scope], but my responses are generated automatically and may not account for every individual circumstance.

If you would prefer to speak with a person, please [insert human escalation route, e.g., "contact our support team at [email address]"].

For information about how ScaleHR processes your personal data, see our [Privacy Notice — insert hyperlink].

Persistent Session Label

In addition to the opening disclosure, carry a persistent label visible throughout the conversation:

AI Assistant — You are chatting with an automated system, not a human.

📄

AI-Generated Content Disclosure

Article 50(4)
✓ Ready to implement

Option A — Inline Label for Job Descriptions

Attach the following to each AI-drafted job description, visible to anyone reading the posting:

AI-assisted content: This job description was drafted with the assistance of an artificial intelligence tool. It has been [reviewed / reviewed and edited] by [a ScaleHR team member / the hiring organisation — select as applicable] before publication. The qualification requirements and role details reflect the decisions of the hiring organisation, not the AI system.

Option B — Platform-Level Disclosure

For the employer-facing dashboard, proximate to the job description drafting feature:

About AI-generated job descriptions

ScaleHR's job description builder uses artificial intelligence to help draft role descriptions based on the information you provide. You are responsible for reviewing all content before publication to ensure it accurately reflects the role and does not contain criteria that unlawfully discriminate against protected groups.

👤

Candidate AI Processing Notice

Articles 26(1) + 13 + GDPR Article 22
✓ Ready to implement

Notice A — Application Receipt (Screening Stage)

Send at the point of application submission, before any AI system processes the candidate's materials. Include in the application confirmation email or displayed on the confirmation screen.

Notice: Automated tools are used in our recruitment process

Thank you for applying to [Role Title] at [Employer Name] via ScaleHR.

Your application will be reviewed using AI-assisted tools to help assess whether your experience meets the requirements of the role. A qualified human recruiter will review any automated assessment before it affects your application. No automated tool makes a final decision about your application without human review.

You have the right to request information about how automated tools have been used in evaluating your application. To exercise this right, contact [data subject rights contact, e.g., privacy@scalehr.com].

For full details of how we process your personal data, see our [Privacy Notice — insert hyperlink].

4 AI Usage Policy

Document Ref
SHR-POL-AI-001
Version
1.0
Effective Date
[INSERT DATE]
Classification
Internal — All Staff

Contents

  1. Purpose and Scope
  2. Definitions
  3. Approved AI Tools and Permitted Use Cases
  4. Prohibited Uses
  5. Data Handling Rules for AI Tools
  6. Human Oversight Requirements
  7. Transparency and Candidate Rights
  8. Incident Reporting
  9. Training and Accountability
  10. Policy Review and Governance
EU AI Act Compliance Notice: ScaleHR operates AI systems that fall within the scope of Regulation (EU) 2024/1689. CV screening, candidate scoring, and employment-related AI decision-making are classified as high-risk AI applications under Annex III of the EU AI Act. This policy reflects the obligations arising from that classification alongside ScaleHR's existing GDPR commitments.

1. Purpose and Scope

This policy establishes the rules, responsibilities, and safeguards governing ScaleHR's use of artificial intelligence tools and systems. It exists to ensure ScaleHR's AI use is lawful, fair, transparent, and accountable; to satisfy the obligations of the EU AI Act applicable to high-risk AI systems used in employment contexts; and to give all staff clear guidance on what they may and may not do with AI tools.

This policy applies to every person working at or for ScaleHR — including permanent employees, contractors, freelancers, and any third party accessing ScaleHR systems — for all AI tools used in the course of ScaleHR business, on any device, from any location.

3. Approved AI Tools and Permitted Use Cases

ToolProviderRisk LevelPermitted Uses
Anthropic Claude API Anthropic, PBC High Risk CV screening (with human review), CV summarisation, internal drafting (no candidate PII)
OpenAI GPT-4 OpenAI, L.L.C. Limited Risk Job description generation (human review required), internal content drafting. Candidate PII must not be submitted.
Internal Scoring Model ScaleHR (built) High Risk Candidate scoring with mandatory human review gate. Full technical documentation must be maintained.
Customer Chatbot ScaleHR (deployed) Limited Risk Information provision and FAQ responses only. Must not triage candidates or collect screening responses.

4. Prohibited Uses

  • Submitting candidate personal data to any AI tool not listed in Section 3
  • Using AI outputs as the final decision on any candidate, employee, or contractor without human review
  • Training any AI model on candidate data without a formal impact assessment and DPO sign-off
  • Using AI to infer or record special category data (health, religion, ethnicity, etc.) from candidates
  • Using consumer AI interfaces (e.g., claude.ai, ChatGPT) to process candidate CVs or personal data

6. Human Oversight Requirements

For every high-risk AI system, ScaleHR must maintain a documented human review step that occurs before any AI output affects a candidate. The reviewing person must:

  • Be qualified to assess the role and candidate in question
  • Have access to the original CV or application, not only the AI output
  • Have the ability and authority to override or reject the AI output
  • Record their review decision in the ATS or relevant system

An informal practice of "someone checks it" is not sufficient. The review step must be a mandatory system gate.

8. Incident Reporting

Any AI incident — discriminatory output, data exposure, system error, or output used without human review — must be reported to [DPO / Compliance Lead] within 24 hours of discovery. The DPO will assess whether the incident triggers notification obligations under GDPR (72 hours to the ICO / relevant SA) or EU AI Act Article 73 (serious incident reporting for high-risk systems).

This was written for ScaleHR. Yours will be written for you.

Every assessment is specific to your AI systems, your jurisdiction, your role as provider or deployer — with the exact articles that apply to your business, not generic guidance.