industries · HR & recruitment

AI in recruitment is high-risk under the AI Act. Here it is auditable.

Recruitment and selection are named high-risk uses under the AI Act, and candidate data is GDPR territory. An auditable open stack on EU infrastructure makes the hard parts structural.

compliance

Compliance, built into the stack.

Every regulatory demand mapped to a platform capability that ships built in, with nothing to configure.

AI Act

Regulation (EU) 2024/1689, Annex III 4 · deadline under revision

RequiresAI for recruitment and selection (ad targeting, filtering applications, evaluating candidates) is high-risk: traceability, data governance and human oversight.

HelmcodeOpen models with published model cards and licenses make the system documentable; the classification of each use is for your legal team.

GDPR

Regulation (EU) 2016/679

RequiresCandidate and employee data demand a lawful basis, minimization and local control.

HelmcodeZero logs and EU-only inference; on-premise for the most sensitive processes.

Human oversight

a person in the loop

RequiresHigh-risk decisions affecting people’s careers need meaningful human oversight.

HelmcodeA traceable, auditable stack that supports a human decision instead of replacing it.

This page is an informational overview, not legal advice. For your obligations and the risk classification of each system, consult qualified legal counsel. AI Act Guide →

what the law names

What the AI Act asks of hiring.

Hiring is not a grey area in the AI Act: Annex III names it, so the high-risk regime is the starting point rather than somebody’s interpretation. The moving part is the deadline, not the demands. Four articles decide how you would build.

01

Screening is on the list

Annex III point 4 names recruitment and selection, and singles out targeted job ads, filtering applications and evaluating candidates. Point 4(b) reaches promotion, termination, allocating tasks by behaviour or traits, and monitoring performance. Little of a modern HR stack falls outside it.

02

The bias data cannot leave

Article 10(5) lets you process protected characteristics to detect and correct bias, under state-of-the-art safeguards, and then says that data must not be transmitted, transferred or accessed by other parties, and must be deleted once the bias is corrected. Measuring bias needs an environment nobody else reaches.

03

The candidate can ask why

Article 86 gives a person affected by such a decision the right to a clear and meaningful explanation of the part the system played in it. Article 26(7) makes the employer inform workers’ representatives and the affected workers beforehand. Both are hard to answer about a model you cannot inspect.

04

AI literacy came first

Article 4 has applied since February 2025, ahead of the high-risk regime: whoever provides or deploys the system must ensure their staff reach a sufficient level of AI literacy for their role and context of use. That is training rather than infrastructure, and nobody can sell it to you.

EU AI Act · Regulation (EU) 2024/1689 Regulation (EU) 2024/1689 of 13 June 2024, in force since 1 August 2024: Annex III point 4, Article 10(5), Article 26(7), Article 86 and Article 4. The calendar is being amended: postponing the Annex III high-risk obligations from 2 August 2026 to 2 December 2027 was agreed by the co-legislators in May 2026 and, as of July 2026, is pending formal adoption. read the report →

use cases

Your most common use cases.

The cases with the most traction in the sector, each with its own page in detail.

Recommended open models.

A starting point per task type. The full guide maps 80 cases to the open model for each one.

Qwen 3.6Apache 2.0 · 256K ctx in Helmcode
Screening that tells evidence from generic claims, and communications in Spanish.
Gemma 4 12BGemma · 128K ctx · 1 GPU
Classification fine-tuned on your criteria, private and low-cost.
Whisper large-v3MIT · STT in Helmcode
Interview transcription on your own infrastructure.

in progressWe are distilling and quantizing these open models into small, tightly specialised versions, trained for one task rather than for all of them. A model like that runs on less hardware, answers faster and fits where the big one does not, your own datacenter included. If you have a process with volume and stable criteria, that is the conversation we want to have with you.

// faq

Questions, answered.

What the sector's technical, compliance and business teams ask.

Is AI in recruitment really high-risk?

Yes. The AI Act (Regulation (EU) 2024/1689, Annex III point 4) lists recruitment and selection, including targeted job ads, filtering applications and evaluating candidates, among high-risk uses. The date those obligations start is the part in motion, and the evidence section below states where it stands. An auditable open stack makes documenting the system easier; classifying each use is for your legal team.

Where is candidate data processed?

Only on EU infrastructure with zero logs, and on-premise for the most sensitive processes, so candidate and employee data stays under your control (GDPR).

Does this keep a human in the loop?

The stack is designed to support a human decision, not replace it: traceable, auditable, with the outputs documented, which is what high-risk human-oversight obligations expect.

Can we fine-tune on our own criteria?

Yes. Gemma 4 can be fine-tuned on your historical data and criteria, run privately, which beats any paid zero-shot for business-specific screening.

// get started

START BURNING TOKENS

Skip the AI infra work. Deploy your first private inference endpoint today.

Flat rate. EU data. OpenAI API compatible.