Starting December 2, 2027, the first binding obligations of the EU AI Regulation take effect for high-risk applications. Operators of AI systems for resume analysis or candidate evaluation must then ensure that intended use is controlled and automatically generated logs are retained for at least six months. A second wave of obligations follows on August 2, 2028. For German HR departments, the message is clear: time to prepare is running out.
The essentials
- High-risk classification: AI systems for resume analysis and candidate evaluation fall under the high-risk category of the AI Regulation
- Logging requirement: Automatically generated logs must be retained for at least six months (from December 2, 2027)
- Manipulation risks: A Duke University study from May 2026 identified prompt injection attempts in approximately 1% of nearly 200,000 reviewed resumes
- Widespread adoption: 33% of AI-using firms use the technology for document analysis, 31% for initial screening (Randstad survey)
Manipulation threats in recruitment
Growing automation in hiring brings new security risks. General chatbots invent qualifications in resumes if not controlled by specialized workflows. More insidious is so-called prompt injection: applicants hide minimal or white text in their documents to manipulate the recruiting AI into positive evaluations. Google responded with the Model Guard tool, designed to detect such interference.
The numbers illustrate the scale: analyzing nearly 200,000 resumes, Duke University found such manipulation attempts in roughly 1% of cases in May 2026. While that sounds low, across millions of applications worldwide it represents a significant problem.
Candidate trust is eroding
Skepticism toward AI in selection processes is justified. According to a Gartner survey from July 2025, only roughly one-quarter of candidates trust that AI systems judge fairly. This is a trust deficit companies should take seriously—not just for ethical reasons, but also for employer branding.
Data protection and labor law tighten
Regulatory requirements extend beyond the AI Regulation. Under Article 22 of the GDPR, purely automated decisions with significant impact are fundamentally restricted and require human safeguards. This means: no pure AI decisions in hiring without human oversight.
Labor law remains complex. While employers may specify tools under § 106 GewO, confidential or personal data cannot simply be entered into external systems. Additionally, technical systems for performance or behavior monitoring are subject to co-determination by works councils or employee representatives.
What this means for you
German companies should now adjust their compliance strategies. The deadlines are approaching: binding obligations kick in within about a year. This means concretely: audit deployed AI systems, verify logging functions, clarify data storage, and coordinate with works councils or employee representatives. Missing this preparation window risks not only fines—but also reputational damage if candidates learn about lack of transparency.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




