Annex III point 4(a) of the EU AI Act (Regulation (EU) 2024/1689) covers AI intended to be used for recruiting or selecting natural persons, “in particular for placing targeted job advertisements, analysing and filtering applications, and evaluating candidates.” Targeted job advertising is named first, ahead of application filtering and candidate evaluation, in the operative text itself. Most HR compliance programmes classify the applicant tracking system and the interview-scoring tool without ever looking at the ad-targeting stack behind a recruitment campaign — because that stack usually sits with marketing, not HR, and nobody told marketing this Annex applies to them too.
What Annex III point 4 actually lists
Point 4(a) covers recruiting or selecting natural persons, with three named examples: placing targeted job advertisements, analysing and filtering applications, and evaluating candidates. Point 4(b) covers a separate category — decisions affecting the terms of a work-related relationship, promotion or termination of a work-related contract, allocating tasks based on an individual’s behaviour or personal traits, and monitoring or evaluating the performance and behaviour of people already in that relationship.
Why the ad stack is the blind spot
Follow where ownership actually sits inside a typical organisation. The applicant tracking system has an HR owner, and by now usually has an AI Act classification attached to it. The audience-targeting model deciding who sees a given job advertisement — built into or bolted onto a recruitment marketing campaign — has a marketing owner, and in most organisations no classification has ever been attempted. Both sit inside the same legal category. Annex III point 4(a) doesn’t distinguish between the system that decides who to interview and the system that decides who gets shown the ad in the first place; it names the second one first.
Can you exempt out under Article 6(3)?
Article 6(3) lets a provider treat an Annex III system as not high-risk where it poses no significant risk of harm and meets one of four conditions: it performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from them without replacing or influencing a previously completed human assessment without proper human review; or it performs a preparatory task for an assessment relevant to an Annex III use case.
Test an ad-targeting model against these honestly rather than reaching for whichever sounds closest. Deciding which individuals see a job advertisement, based on inferred interests, behaviour, or demographic proxies, is not a narrow procedural task — it’s a substantive targeting decision, arguably the central function of the model. It’s a weak fit for “improving a previously completed human activity” unless a human already decided the exact audience and the model only optimises delivery mechanics within that fixed audience. It doesn’t detect patterns or deviations from prior decisions in the way the third ground contemplates. And it’s a stretch to call the core targeting decision merely “preparatory” to some later assessment, when the targeting decision is often the entire point of the system.
The override that ends the argument
Even where one of the four grounds might plausibly fit, Article 6(3) closes with an override that applies notwithstanding all of them: an Annex III system is always considered high-risk if it carries out profiling of natural persons. No exemption survives that. An audience model built on individual behavioural traits — inferred interests, browsing history, demographic signals used to decide who sees what — is profiling by any ordinary reading of the term. That ends the Article 6(3) argument regardless of how well the model might otherwise have fit one of the four narrow grounds.
The price of claiming the exemption anyway
If you conclude your ad-targeting model genuinely clears Article 6(3) despite this, the exemption doesn’t make the system invisible. You keep the underlying assessment, and you register the system in the EU database with a summary of the grounds you relied on — and that summary sits in the database’s public section, readable by anyone, including a competitor or an advocacy group. The mechanics of that registration duty, and what happens if a market surveillance authority later disagrees with your classification, are covered in full in a companion piece on Article 6(3) registration and Article 80 enforcement rather than repeated here.
When this bites
Annex III obligations now apply from 2 December 2027, following the Digital Omnibus deferral, once the amending regulation is actually published in the Official Journal. Recruitment and employment systems sit in the Annex III categories that go through internal-control self-assessment rather than a notified body, so unlike biometric AI, there’s no third-party capacity bottleneck standing between now and that date. The sixteen-odd months between now and then are for inventory and classification work specifically — finding every system that touches recruitment, including the ones marketing owns — and that work doesn’t depend on any external standard or authority being ready first. Nothing about the extended timeline changes what needs to be found; it only changes how much time there is to find it.
Frequently asked questions
Does using LinkedIn’s ad targeting make us a deployer?
Likely yes. The platform is ordinarily the provider of the underlying targeting system, and the business running a recruitment campaign through it is the deployer — deployer obligations attach to you regardless of who built the model underneath the campaign tool you’re using.
What if the vendor says their tool isn’t high-risk?
Verify it yourself rather than relying on that assurance. The classification decision, and the consequences if a market surveillance authority later disagrees with it, attach to whoever is actually making the call — a vendor’s own marketing claim about its product’s risk tier doesn’t relieve you of that.
Are we the provider or the deployer?
Ordinarily the deployer, using a system someone else built. You become a provider yourself only if you put your own name or branding on the system, substantially modify it, or change a non-high-risk system’s intended purpose in a way that makes it high-risk — the same test that applies to importers and rebranders elsewhere in the Act.
Does a job board’s own matching algorithm count?
To the extent a job board’s algorithm recruits, selects, or filters candidates on an employer’s behalf, that function sits inside Annex III 4(a) in its own right — with the job board as a plausible provider of that specific functionality and the posting employer as its deployer.
Does an internal mobility tool count?
That sits closer to Annex III 4(b) than 4(a) — assessing existing employees for promotion or transfer eligibility is a decision affecting the terms of an employment relationship, not external recruitment. The same profiling override applies equally regardless of which limb of point 4 the tool falls under.
