[{"data":1,"prerenderedAt":30},["ShallowReactive",2],{"nr-en-eu-ki-verordnung-protokollpflicht-2027-speicherfrist":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":22,"trackerLabel":23,"headlineStat":24,"image":25,"ogImage":26,"imageAlt":5,"csv":10,"minutes":27,"words":28,"html":29},"eu-ki-verordnung-protokollpflicht-2027-speicherfrist","EU AI Act: Logging Obligations from 2027, Six-Month Retention Period","The EU AI Regulation classifies recruitment analysis systems as high-risk applications. From December 2027, companies must retain automatically generated logs for at least six months and prepare for new compliance requirements.","2026-09-24","10:45","2026-09-24T10:45:00+02:00","","September 24, 2026","news","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"AI regulation","EU AI Act","Compliance","Recruiting","Data protection","\u002Feu-ai-act-fahrplan","EU AI Act Timeline","Logging obligation from December 2, 2027; six-month retention period","\u002Fnewsroom\u002Fimg\u002Feu-ki-verordnung-protokollpflicht-2027-speicherfrist.webp","\u002Fog-nr\u002Feu-ki-verordnung-protokollpflicht-2027-speicherfrist.en.png",2,473,"\u003Cp>Starting December 2, 2027, the first binding obligations of the EU AI Regulation take effect for high-risk applications. Operators of AI systems for resume analysis or candidate evaluation must then ensure that intended use is controlled and automatically generated logs are retained for at least six months. A second wave of obligations follows on August 2, 2028. For German HR departments, the message is clear: time to prepare is running out.\u003C\u002Fp>\n\u003Ch2>The essentials\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>High-risk classification\u003C\u002Fstrong>: AI systems for resume analysis and candidate evaluation fall under the high-risk category of the AI Regulation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Logging requirement\u003C\u002Fstrong>: Automatically generated logs must be retained for \u003Cstrong>at least six months\u003C\u002Fstrong> (from December 2, 2027)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manipulation risks\u003C\u002Fstrong>: A Duke University study from May 2026 identified \u003Cstrong>prompt injection attempts in approximately 1% of nearly 200,000 reviewed resumes\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widespread adoption\u003C\u002Fstrong>: \u003Cstrong>33% of AI-using firms\u003C\u002Fstrong> use the technology for document analysis, \u003Cstrong>31%\u003C\u002Fstrong> for initial screening (Randstad survey)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Manipulation threats in recruitment\u003C\u002Fh2>\n\u003Cp>Growing automation in hiring brings new security risks. General chatbots invent qualifications in resumes if not controlled by specialized workflows. More insidious is so-called \u003Cstrong>prompt injection\u003C\u002Fstrong>: applicants hide minimal or white text in their documents to manipulate the recruiting AI into positive evaluations. Google responded with the \u003Cstrong>Model Guard\u003C\u002Fstrong> tool, designed to detect such interference.\u003C\u002Fp>\n\u003Cp>The numbers illustrate the scale: analyzing nearly 200,000 resumes, Duke University found such manipulation attempts in roughly \u003Cstrong>1%\u003C\u002Fstrong> of cases in May 2026. While that sounds low, across millions of applications worldwide it represents a significant problem.\u003C\u002Fp>\n\u003Ch2>Candidate trust is eroding\u003C\u002Fh2>\n\u003Cp>Skepticism toward AI in selection processes is justified. According to a Gartner survey from July 2025, only \u003Cstrong>roughly one-quarter of candidates\u003C\u002Fstrong> trust that AI systems judge fairly. This is a trust deficit companies should take seriously—not just for ethical reasons, but also for employer branding.\u003C\u002Fp>\n\u003Ch2>Data protection and labor law tighten\u003C\u002Fh2>\n\u003Cp>Regulatory requirements extend beyond the AI Regulation. Under \u003Cstrong>Article 22 of the GDPR\u003C\u002Fstrong>, purely automated decisions with significant impact are fundamentally restricted and require human safeguards. This means: no pure AI decisions in hiring without human oversight.\u003C\u002Fp>\n\u003Cp>Labor law remains complex. While employers may specify tools under § 106 GewO, confidential or personal data cannot simply be entered into external systems. Additionally, technical systems for performance or behavior monitoring are subject to co-determination by works councils or employee representatives.\u003C\u002Fp>\n\u003Ch2>What this means for you\u003C\u002Fh2>\n\u003Cp>German companies should now adjust their compliance strategies. The deadlines are approaching: binding obligations kick in within about a year. This means concretely: audit deployed AI systems, verify logging functions, clarify data storage, and coordinate with works councils or employee representatives. Missing this preparation window risks not only fines—but also reputational damage if candidates learn about lack of transparency.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.ad-hoc-news.de\u002Fwirtschaft\u002Fki-verordnung-protokolle-sechs-monate-speichern-pflichten-ab-2027-und\u002F70171791\">AD HOC NEWS\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1790247137075]