Two of ScaleHR's four AI tools — the CV screening system and the internal candidate scoring model — sit in the highest risk category under EU law that takes full effect in August 2026. This is not a technicality. These tools make judgments about people's job prospects, which is exactly what regulators wrote this law to govern.
The other two tools (the chatbot and job description generator) carry lighter obligations, but still require action. ScaleHR's most exposed position is the scoring model built in-house: as the creator, not just the user, ScaleHR carries the heaviest compliance burden.
1. Fix the internal scoring model — this is the priority.
As the builder of this system, ScaleHR must produce formal technical documentation of how it works, prove it has been tested for bias against protected groups, and demonstrate that human reviewers can meaningfully understand and challenge its outputs. A black-box score that no one can explain is non-compliant. This work realistically takes six to twelve months. Time is already tight.
2. Add human review gates to both AI recruitment tools.
Neither the CV screening system nor the scoring model can be the last word on a candidate. The law requires that a qualified person reviews AI outputs and can override them before any decision affects an applicant. These review steps must be formalised and documented — informal practices are not sufficient.
3. Tell candidates their applications are assessed by AI.
Anyone whose CV enters these systems must be told, at the point of application, that automated tools are involved and that they can ask questions about how those tools were used. Ready-to-implement notice language is provided in Section 3 of this report.
Fines reach €15 million or 3% of global annual turnover, whichever is higher, for high-risk system violations. Beyond financial penalties, regulators can order suspension of the tools entirely — which would halt core product functionality. There is also meaningful reputational and litigation risk: candidates who believe they were unfairly screened by an undisclosed, untested AI system have grounds to complain to data protection authorities and employment tribunals simultaneously.
Recommended immediate action: Assign an owner to the scoring model compliance workstream this month.
ScaleHR falls within EU AI Act scope. German and Dutch operations mean the Act applies directly. UK operations fall outside EU AI Act jurisdiction, but ScaleHR's EU customer base (30%+) means compliance is non-negotiable for EU-facing systems.
Annex III explicitly lists "AI systems used for recruitment or selection of natural persons, notably for advertising vacancies, screening or filtering applications, evaluating candidates in the course of interviews or tests." CV screening is the canonical example this provision was written to capture. There is no ambiguity here.
Same Annex III basis as System 1, but the compliance profile is significantly more demanding because ScaleHR is the provider of this system, not merely a deployer. They built it. As a 45-person company building and operating a high-risk AI system in the employment sector, ScaleHR faces the same substantive obligations as a large enterprise. There is no SME carve-out that eliminates these requirements.
Note: If the model scores candidates on characteristics that function as proxies for protected characteristics (age inferred from graduation dates, gender from name patterns), ScaleHR faces simultaneous GDPR Article 22, German AGG, and UK Equality Act exposure. This intersection warrants immediate legal review independent of AI Act timelines.
The primary obligation is disclosure: AI-generated content intended for publication must be declared as AI-generated unless substantially human-edited (Article 50(4)). Job descriptions published on ScaleHR's platform or customers' careers pages are public-facing content and trigger this obligation.
Conditional escalation: If GPT-4 is used to determine role requirements that feed into the CV screening or scoring pipeline, the use case edges into Annex III Point 4(a) territory — "advertising vacancies." Confirm and document the human review step between GPT-4 output and publication to maintain the limited-risk classification.
Article 50(1) requires that any AI system interacting with natural persons in real time be designed to inform users they are interacting with an AI, unless this is obvious from context. The chatbot must identify itself as an AI at the start of each interaction, visible on the same screen — not buried in a footer or settings menu.
Escalation trigger: If the chatbot ever makes or substantially influences decisions about individual candidates or employees, reclassify upward to Annex III / high-risk immediately. Confirm chatbot functionality does not include candidate triaging or collection of screening responses.
Ready-to-implement language for each AI transparency obligation that applies to ScaleHR. Bracketed fields must be completed before deployment. These satisfy EU AI Act Article 50 obligations — they run in parallel to, and do not replace, GDPR Articles 13/14 privacy notices.
Must appear at the start of every conversation session, before the user submits any input. Visible on the same screen where the user first encounters the chat interface.
You are interacting with an AI system.
I am ScaleHR's automated assistant, powered by artificial intelligence. I am not a human. I can answer questions about [ScaleHR's platform / your job application / HR policies — select applicable scope], but my responses are generated automatically and may not account for every individual circumstance.
If you would prefer to speak with a person, please [insert human escalation route, e.g., "contact our support team at [email address]"].
For information about how ScaleHR processes your personal data, see our [Privacy Notice — insert hyperlink].
In addition to the opening disclosure, carry a persistent label visible throughout the conversation:
AI Assistant — You are chatting with an automated system, not a human.
Attach the following to each AI-drafted job description, visible to anyone reading the posting:
AI-assisted content: This job description was drafted with the assistance of an artificial intelligence tool. It has been [reviewed / reviewed and edited] by [a ScaleHR team member / the hiring organisation — select as applicable] before publication. The qualification requirements and role details reflect the decisions of the hiring organisation, not the AI system.
For the employer-facing dashboard, proximate to the job description drafting feature:
About AI-generated job descriptions
ScaleHR's job description builder uses artificial intelligence to help draft role descriptions based on the information you provide. You are responsible for reviewing all content before publication to ensure it accurately reflects the role and does not contain criteria that unlawfully discriminate against protected groups.
Send at the point of application submission, before any AI system processes the candidate's materials. Include in the application confirmation email or displayed on the confirmation screen.
Notice: Automated tools are used in our recruitment process
Thank you for applying to [Role Title] at [Employer Name] via ScaleHR.
Your application will be reviewed using AI-assisted tools to help assess whether your experience meets the requirements of the role. A qualified human recruiter will review any automated assessment before it affects your application. No automated tool makes a final decision about your application without human review.
You have the right to request information about how automated tools have been used in evaluating your application. To exercise this right, contact [data subject rights contact, e.g., privacy@scalehr.com].
For full details of how we process your personal data, see our [Privacy Notice — insert hyperlink].
This policy establishes the rules, responsibilities, and safeguards governing ScaleHR's use of artificial intelligence tools and systems. It exists to ensure ScaleHR's AI use is lawful, fair, transparent, and accountable; to satisfy the obligations of the EU AI Act applicable to high-risk AI systems used in employment contexts; and to give all staff clear guidance on what they may and may not do with AI tools.
This policy applies to every person working at or for ScaleHR — including permanent employees, contractors, freelancers, and any third party accessing ScaleHR systems — for all AI tools used in the course of ScaleHR business, on any device, from any location.
| Tool | Provider | Risk Level | Permitted Uses |
|---|---|---|---|
| Anthropic Claude API | Anthropic, PBC | High Risk | CV screening (with human review), CV summarisation, internal drafting (no candidate PII) |
| OpenAI GPT-4 | OpenAI, L.L.C. | Limited Risk | Job description generation (human review required), internal content drafting. Candidate PII must not be submitted. |
| Internal Scoring Model | ScaleHR (built) | High Risk | Candidate scoring with mandatory human review gate. Full technical documentation must be maintained. |
| Customer Chatbot | ScaleHR (deployed) | Limited Risk | Information provision and FAQ responses only. Must not triage candidates or collect screening responses. |
For every high-risk AI system, ScaleHR must maintain a documented human review step that occurs before any AI output affects a candidate. The reviewing person must:
An informal practice of "someone checks it" is not sufficient. The review step must be a mandatory system gate.
Any AI incident — discriminatory output, data exposure, system error, or output used without human review — must be reported to [DPO / Compliance Lead] within 24 hours of discovery. The DPO will assess whether the incident triggers notification obligations under GDPR (72 hours to the ICO / relevant SA) or EU AI Act Article 73 (serious incident reporting for high-risk systems).
Every assessment is specific to your AI systems, your jurisdiction, your role as provider or deployer — with the exact articles that apply to your business, not generic guidance.