The €18M HR-Tech Fine: Why AI Sourcing Survived Aug 2 and Screening Didn't
The EU AI Office's first €47M enforcement wave hit HR tech hardest. Here is why AI sourcing stays low-risk while AI screening now carries 7%-of-turnover fines.
Within days of the August 2, 2026 enforcement start, the EU AI Office issued €47M in fines across three cases. The biggest single hit, €18M, went to a pan-European HR technology company for deploying hiring AI without conformity assessment documentation or human oversight controls. If you are a US founder or recruiter with any EU candidate exposure, the interesting question is not "was this fair," it is "which side of the sourcing-vs-screening line was I on."
What actually happened on August 2
The EU AI Office launched enforcement with a pre-built docket, and HR tech was the first vertical fined. Three cases landed almost simultaneously:
- €18M against a pan-European HR technology company for deploying hiring AI without conformity assessment documentation or human oversight controls
- €14M against a credit scoring provider
- €15M against a retail chain for real-time emotion recognition
Total: €47M across three cases, all touching Annex III high-risk categories. The HR-tech investigation was triggered by complaints about opaque and apparently discriminatory hiring decisions. Investigators found incomplete technical documentation that could not demonstrate how candidate recommendations were made. The company had positioned itself publicly as a "modern AI-driven talent platform," but could not explain individual decisions to regulators or to rejected candidates.
The speed matters. EU AI Office officials signaled through mid-2026 that pre-built cases would be ready at launch. This is investigation-led enforcement, not audit-led. Candidate complaints, not routine inspections, are what pull the trigger. Opaque rejection emails are the ignition source.
The Annex III line: sourcing is low-risk, screening is high-risk
The EU AI Act's high-risk category for employment (Annex III Category 4(a)) captures specific activities, not the general idea of "AI in hiring." Read the text carefully and a clean architectural line appears.
Annex III names AI systems intended for the recruitment or selection of natural persons, "in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates." That last clause is the load-bearing one.
Here is the practical split most compliance guidance now uses:
| Activity | Risk tier under Annex III | Why |
|---|---|---|
| Identifying passive candidates from public data | Low-risk | Not analysing or filtering an application |
| Drafting personalised outreach | Low-risk | Content generation, not selection |
| Matching people to open roles pre-application | Low-risk | No candidate has applied yet |
| Ranking or scoring applicants in an ATS | High-risk | Directly "filters job applications" |
| Video interview scoring, personality inference | High-risk | "Evaluates candidates" |
| Automated reject/advance decisions | High-risk | Selection decision, needs human oversight |
The distinction is not marketing spin. It is the difference between a product that sits upstream of your application inbox and one that sits inside it. Anything that touches an applicant record and produces a score, rank, or filter falls squarely inside Category 4(a). Anything that helps you find and reach people who have not applied yet does not.
This is why the sourcing-first architecture matters right now. Refolk is deliberately upstream: you describe the person in plain English, and Refolk returns a ranked shortlist from GitHub, LinkedIn, and the open web. No one has applied. No application is being filtered. No candidate is being evaluated against other applicants for a specific job decision. That keeps the workflow out of Annex III Category 4(a) by construction, not by policy.
Why the "December 2027 delay" is a trap
The €18M fine landed even though many compliance blogs still say high-risk employment AI obligations only bite on December 2, 2027. Both statements are true, and the reconciliation is what will catch US teams.
Following the Digital Omnibus package, obligations for stand-alone Annex III high-risk systems (including employment AI) now apply from 2 December 2027, not the earlier August 2026 date. But three things activated on schedule:
- Article 5 prohibitions on unacceptable-risk practices
- Article 50 transparency duties, including the duty to disclose AI-generated content and automated decisions
- Market-surveillance powers, including the ability to investigate on complaint
The €18M HR-tech case fits inside those live obligations. The company could not explain decisions to rejected candidates (transparency), and could not produce technical documentation on request (market-surveillance). You do not need the full Annex III regime to be in force to lose €18M for those failures.
Deadline delay is not enforcement pause. The AI Office queued cases before August 2 and started billing on August 3.
US founders are already in scope
If you recruit EU candidates or deploy AI tools that touch EU residents, you are in scope of the EU AI Act, even without a European office. The extraterritorial reach mirrors GDPR.
Two facts sharpen this for US teams:
- 51% of organizations already use AI specifically for recruiting (SHRM, 2025)
- ~70% of businesses say they have difficulty understanding their obligations under the Act (IAPP 2025 AI Governance Report)
The second number is the interesting one. Most companies using AI in hiring do not know what they are on the hook for. That is the exact pool the AI Office is fishing in.
Deployer liability is the specific trap
Buying or licensing a third-party recruitment tool makes you a deployer, not a provider, but deployer obligations still apply. That includes registration duties for high-risk systems, human oversight requirements, and the duty to explain automated decisions to affected candidates.
Translated: a US Series A that uses a US-built screening vendor to rank Berlin engineers owns the compliance risk itself. Not the vendor. The vendor may be untouchable in California; the deployer is very much reachable in Berlin.
The talent bench that has to fix this does not exist yet
The EU-5 has roughly one named AI-governance owner for every 875 recruiters. That is not a policy gap, it is a headcount gap, and it is why the AI Office chose HR tech first: nobody is ready.
Refolk's index of professional profiles gives a concrete read on the buying and compliance population on both sides of the Atlantic:
| Metric | Figure |
|---|---|
| US recruiting-function profiles (Recruiter, Technical Recruiter, TA, Head of Talent) | 112,951 |
| EU-5 recruiting-function profiles (DE, FR, NL, IE, ES combined) | 11,383 |
| US : EU-5 ratio, recruiting function | 9.92x |
| EU-5 profiles with AI Governance / Responsible AI / AI Ethics titles | 13 |
| EU-5 recruiters per named AI-governance owner | ~876 : 1 |
| First-wave fine total | €47M |
| Largest single fine (HR tech) | €18M |
| Statutory ceiling for high-risk violations | €35M or 7% of global turnover |
Thirteen. Across Germany, France, the Netherlands, Ireland, and Spain. Top employers of those thirteen include BMW Group, Zurich Insurance, Rabobank, Fraunhofer IAIS, and Apple. Everyone else is running AI in hiring without an internal owner who has "AI governance" in their title.
If you are trying to hire one of those thirteen people, or find the next thirteen, that is a plain-English sourcing problem across GitHub, LinkedIn, and the open web. It is the exact gap Refolk closes: describe "Responsible AI lead at a European bank or industrial, published on model documentation," and get a ranked shortlist back.
What to change this quarter if you sell into or hire from the EU
Push AI into sourcing and out of screening. That is the single architectural move that converts a high-risk system into a low-risk one under Annex III, without waiting for December 2027 guidance.
Concretely:
- Audit your stack by Annex III activity, not by vendor. For each tool, ask: does it analyse or filter job applications, or evaluate candidates against each other? If yes, it is high-risk when used on EU candidates.
- Move ranking and scoring out of the applicant funnel. If a tool ranks people who have not applied yet (passive sourcing), it is not filtering applications. Once someone applies, downgrade the AI to a decision-support role with a documented human reviewer.
- Confirm your deployer registration posture. If you are using HireVue, Eightfold, Paradox, Fonzi AI, Carv, HireVox.ai, or any similar screening/assessment vendor on EU candidates, you are a deployer of a high-risk system. The vendor's compliance is not yours.
- Write the rejection email a regulator can read. The €18M case turned on the inability to explain decisions to rejected candidates. If your rejection template says "we've decided to move forward with other candidates," and an AI system produced the ranking, you have a transparency exposure.
- Assign one internal owner. With 13 named AI-governance people across the EU-5, you will not hire one this quarter. Name someone internal, give them the title, and put them on the org chart before you need them in a filing.
Sourcing tools that stay upstream of the application inbox are the cheapest compliance win available right now. Refolk is built for that upstream slice: plain-English queries, ranked shortlists across GitHub, LinkedIn, and the open web, no applicant records touched, no scoring inside an ATS. Screening decisions and the human oversight around them stay with your team, where the Act expects them.
Why HR tech got picked first
The AI Office picked HR tech first because it is where opaque decisions meet motivated complainants. Rejected candidates file complaints. Rejected loan applicants file complaints. Shoppers scanned by emotion-recognition cameras usually do not know they were scanned.
That is why the first three cases were HR tech, credit scoring, and retail emotion recognition, in that order of visibility. The €18M number is small relative to the statutory ceiling of €35M or 7% of global turnover. Future enforcement against larger platforms could reach hundreds of millions. The first wave was a signal, not a settlement.
The rational response is not to abandon AI in hiring. It is to move the AI to the part of the workflow that is not covered: finding people who have not yet applied. Everything downstream of "apply now" is where the regulator is standing.
FAQ
Does the EU AI Act apply to a US-only startup with no European entity?
Yes, if you recruit EU-resident candidates or deploy AI tools that produce effects on people in the EU. The Act's territorial scope follows the affected person, not your incorporation. A US Series A screening Berlin engineers with a US-built vendor is a deployer of a high-risk system under Annex III Category 4(a) and carries deployer obligations, including registration and transparency duties.
Is sourcing really out of scope, or is that a marketing claim?
Annex III Category 4(a) explicitly names "targeted job advertisements," "analyse and filter job applications," and "evaluate candidates." Sourcing activities that identify passive candidates from public data, draft outreach, or match people to jobs before any application exists do not fit those verbs. That is why sourcing-first tools sit outside the high-risk tier, and why moving AI upstream of the application inbox is the cheapest compliance move available today.
The high-risk deadline is December 2, 2027. Why did the €18M fine land in August 2026?
Because Article 5 prohibitions, Article 50 transparency duties, and market-surveillance powers activated on schedule in August 2026 regardless of the Digital Omnibus extension for stand-alone Annex III systems. The HR-tech company was fined for failures inside those already-live obligations: opaque decisions to rejected candidates, and incomplete technical documentation on request. The 2027 date delays some obligations, not enforcement itself.
What is the fastest way to reduce exposure this quarter?
Audit each tool in your hiring stack against Annex III verbs (filter applications, evaluate candidates), move any AI ranking or scoring out of the post-application funnel, assign one internal owner for AI governance even without the exact title, and rewrite rejection communications so a regulator could read them. Push sourcing and outreach AI upstream, keep human oversight on every selection decision, and confirm your deployer registration posture with vendors like HireVue, Eightfold, and Paradox before renewal.
Try it on the search you came here for
Stop building boolean strings. Just describe the person.
Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.
01Describe them
One plain sentence. Role, city, stack, stage, whatever matters to you.
02I read the web live
GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.
03You read the shortlist
Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
- No boolean, no filters, no seat to buy. One box.
- Read at search time, so a profile updated yesterday counts today.
- Every step visible as it runs, every name with its reason.
500 free credits on sign-up. No card, no demo call. See real searches.