Reading Time

Provider vs deployer under the EU AI Act: recruitment assessments

When an employer buys an AI-powered assessment tool and uses it to screen job applicants, two distinct legal roles come into play under Regulation (EU) 2024/1689, the EU AI Act. One party built and placed the system on the market. Another party operates it day-to-day. The Act calls them the "provider" and the "deployer," and it assigns meaningfully different compliance obligations to each. Getting this wrong doesn't produce a minor paperwork gap. It produces situations where no one owns the incident response process, no one has retained the required logs, and no one can produce the technical documentation an auditor requests.

This guide maps those legal roles onto the real-world structure of recruitment technology, so that HR leaders, procurement teams, and their vendors can allocate obligations clearly before contracts are signed.

Provider vs deployer: what the EU AI Act actually says

Article 3 of the EU AI Act (consolidated text available on EUR-Lex under Regulation (EU) 2024/1689) establishes the definitions that govern the entire regulation. The AI Act Service Desk, operated by the European Commission, provides a plain-language summary of these roles.

Provider (Article 3(3)): the natural or legal person, public authority, agency, or other body that develops an AI system or has one developed, and places it on the market or puts it into service under its own name or trademark.

In recruitment terms, this is the assessment vendor. If a company builds and commercially licenses AI-scored assessments, it's the provider. The branding test matters: if a third-party model is embedded and re-released under a different name, the re-releasing entity takes on provider obligations.

Deployer (Article 3(4)): the natural or legal person, public authority, agency, or other body that uses an AI system under its authority in a professional context. Personal, non-professional use is excluded (DLA Piper Intelligence, quoting Article 3(4)).

In recruitment terms, this is the employer or HR team configuring and running the assessment in its hiring funnel. The deployer doesn't need to have built anything. Using the system to score, rank, or recommend candidates is sufficient to trigger deployer status.

One organization can hold both roles simultaneously. An employer that builds a proprietary AI screening tool and then rolls it out internally is both provider and deployer across different parts of the Act.

How roles map to common recruitment tech setups

The table below covers the most frequent configurations.

ScenarioLikely providerLikely deployer
Assessment vendor supplies AI scoring via ATS integrationAssessment vendorEmployer
ATS vendor bundles third-party assessment logic under its brandATS vendor, as re-branded providerEmployer
Employer configures custom scoring thresholds on vendor modelsAssessment vendor, for the base systemEmployer, including for the configuration decisions
Employer builds internal screening tool and deploys it to HR teamsEmployer, as providerEmployer, as deployer

The deciding questions are: who placed or branded the system into service, and who controls operational parameters and uses the outputs to make decisions about candidates? Those answers determine where obligations land.

What providers must do: Article 16 obligations

Under Article 16, providers of high-risk AI systems (which recruitment assessment tools used for employment decisions typically qualify as) carry upstream compliance responsibilities before the system reaches any deployer. The AI Act Service Desk summarizes these as including:

  • Establishing and maintaining a quality management system
  • Drawing up and retaining technical documentation
  • Completing a conformity assessment and registering the system in the EU database
  • Affixing CE marking where applicable
  • Designing the system with appropriate features to support human oversight by deployers
  • Implementing post-market monitoring obligations

For a procurement team evaluating an assessment vendor, this translates into a specific documentation request. Before go-live, the vendor should be able to produce its technical documentation package, a risk management file, its instructions for use, and evidence of its conformity process. If the vendor cannot produce these materials, that is a compliance signal, not just a procurement inconvenience.

What deployers must do: Article 26 obligations

Article 26 governs deployers of high-risk AI systems and covers operational compliance during use. Per the AI Act Service Desk, these obligations include:

  • Taking appropriate technical and organizational measures to use the system according to the provider's instructions
  • Assigning human oversight to natural persons with the necessary competence, training, and authority to intervene
  • Ensuring input data quality where the deployer controls those inputs
  • Monitoring operations and acting on risks
  • Retaining logs and cooperating with incident and risk escalation processes

The recruitment-specific implication: these are not IT department tasks. The obligation to ensure trained, authorized human reviewers can override or stop an automated recommendation belongs to HR and People leadership. A CHRO cannot delegate Article 26 governance entirely to a technical team without retaining process ownership over who reviews outcomes and under what conditions a decision is escalated or reversed.

Where obligations overlap and how contracts should handle them

Several compliance controls don't fall cleanly on one side. Candidate transparency (informing applicants they're subject to an AI-based decision), log retention, incident reporting workflows, and change control when recruitment policies shift all require coordination between vendor and employer.

A practical RACI framework assigns the provider responsibility for drafting instructions for use and supplying compliance documentation; the deployer approves internal governance structures and operates human oversight processes; and both parties share incident escalation paths with defined SLA timelines.

Contract provisions worth including:

  • Require the provider to deliver instructions for use, technical documentation, and audit cooperation support prior to go-live
  • Require the deployer to implement named governance roles, internal training, and monitoring procedures
  • Define the maximum response time for log and data requests (48-72 hours is a reasonable starting benchmark)
  • Specify the triggering conditions under which the deployer must suspend use of the system and notify the provider
  • Align AI Act operational clauses with existing GDPR data processing agreements where personal data is involved. These are separate legal instruments but they must be consistent with each other

One point that often gets missed: threshold configuration is a compliance decision, not just a product setting. If an employer lowers a cut-score or adjusts ranking weights, that changes the system's operational behavior in ways that can affect fairness and defensibility. Contracts should specify that configuration changes require documented validation before being applied in production. On the candidate-facing side, our guide to communicating AI use transparently to candidates covers what the disclosure itself should say.

Compliance checklist for vendors and employers

For vendors (providers):

  • Conformity assessment completed and documented
  • Technical documentation package available on request
  • Instructions for use delivered before deployment
  • Risk management file maintained and versioned
  • Human oversight design features built into the product
  • Post-market monitoring mechanism in place
  • Incident notification process and contact paths documented

For employers (deployers):

  • Named governance owner assigned (typically HR Director or equivalent)
  • Human oversight roles defined with clear authority to override
  • Candidate-facing transparency process in place before first use
  • Input data quality controls documented
  • Log retention process aligned with Article 26 and GDPR retention rules
  • Internal training records maintained for all staff using the system
  • Incident escalation SLA agreed with vendor in writing

Evidence to request before signing a contract:

  • Technical documentation summary or index
  • Instructions for use document
  • Conformity assessment status (self-assessment or third-party)
  • EU database registration confirmation (if applicable)
  • Incident history and response record for existing deployments

A note on go-live timelines and practical readiness

Compliance documentation is not something to gather after a system goes live. For organizations working with an assessment partner on a 2-to-10-week implementation timeline (a realistic window for integrated tools like Selection Lab's AI-driven assessment platform, which connects SmartChat candidate intake, skills assessments, and ATS reporting into a single workflow), the compliance paperwork exchange should happen in parallel with technical integration, not after it. Waiting until users are live to request a provider's technical documentation creates a gap that is difficult to close retroactively.

Further reading and references

  • Consolidated legal text: EUR-Lex, Regulation (EU) 2024/1689, available at eur-lex.europa.eu (last portal update shown as 2026-07-27)
  • Definitions: AI Act Service Desk, Article 3 (Europa.eu / AI Act Single Information Platform)
  • Provider obligations: AI Act Service Desk, Article 16
  • Deployer obligations: AI Act Service Desk, Article 26
  • Role interplay analysis: A&O Shearman, September 16, 2024

Classification of roles under the EU AI Act is fact-specific. Branding arrangements, contractual structures, and the degree of control each party exercises over the system's operation can all shift who holds which responsibilities. Legal counsel should be consulted for any case where the role classification is ambiguous, particularly where ATS vendors, assessment vendors, and employer configuration layers interact.

FAQ

Can game-based assessments promote diversity in the hiring process?

Yes, game-based assessments can support diversity by focusing on skills and behaviors rather than traditional criteria like résumés, which may contain unconscious biases. This gives candidates from diverse backgrounds a fairer chance to demonstrate their potential.

What is a game-based assessment?

A game-based assessment is a method that uses game mechanics to evaluate a candidate’s skills, competencies, and personality traits. While playing these games, candidates are assessed on aspects like problem-solving, cognitive ability, and behavior under pressure in an interactive way.

What are the advantages of game-based assessments?

Game-based assessments offer a more engaging and interactive experience for candidates, which can lead to a more positive perception of the hiring process—especially among certain groups. For employers, they provide deeper insights into both cognitive and behavioral traits, which traditional tests may miss. They also reduce the chance of socially desirable answers, as candidates tend to respond more authentically in a game environment.

How reliable are game-based assessments compared to traditional tests?

When well-designed, game-based assessments can be just as reliable—or even more reliable—than traditional tests. They assess a wide range of behaviors and cognitive abilities in a dynamic setting. However, the quality of these assessments varies greatly, so careful evaluation is essential.

How does a game-based assessment work?

Candidates participate in interactive games designed to measure specific skills and behaviors. Evaluation goes beyond just the final score—it also considers how the candidate makes decisions, handles challenges, and responds to different scenarios. These insights reveal underlying thought processes and behavioral patterns.

Are game-based assessments scientifically validated?

The main drawback is that many game-based assessments are relatively new and have not yet been extensively researched by independent academics. Providers often cite their own research, which is rarely externally validated. Without independent studies, the reliability of these assessments remains uncertain—something to keep in mind when selecting one.

How can game based assessments contribute to a better candidate experience

This can vary significantly by audience. The playful, interactive nature of game-based assessments can lower stress levels for some candidates compared to traditional tests. However, research shows that certain groups, especially those over 35, may find them more stressful. Men also tend to rate the experience more positively than women.

Can you practice game-based assessment?

You can familiarize yourself with the style of games used, but it’s difficult to "practice" for them in a traditional sense. These assessments are designed to measure natural reactions and authentic behavior, so repeated practice typically has less effect on performance than with traditional tests.

Will game-based assessments replace traditional tests in the future?

It’s likely that game-based assessments will become more common in hiring processes, but they probably won’t fully replace traditional tests. Both approaches have value and can complement each other depending on the role and the company’s needs.

How are the results of a game-based assessment analyzed?

Results are analyzed based on predefined criteria such as problem-solving ability, reaction time, and behavior under pressure. Advanced algorithms collect and interpret this data to provide a reliable, objective evaluation of a candidate’s strengths.

What kind of skills do game-based assessments measure?

They assess a wide range of abilities, including problem-solving, adaptability, decision-making under pressure, teamwork, and emotional intelligence. Depending on the design, they may also evaluate cognitive skills like memory, attention, and pattern recognition.

How long does a game-based assessment take?

Typically, these assessments last between 15 and 60 minutes, depending on the game’s complexity and the number of skills being tested. They’re usually shorter and more engaging than traditional assessments, making for a smoother candidate experience.

Are game-based assessments suitable for all roles?

They are especially effective for roles that require flexibility, creativity, problem-solving, and strong interpersonal skills. For highly technical or specialized roles, additional assessments may be needed to measure specific knowledge.

What’s the difference between a game-based and a gamified assessment?

A gamified assessment adds game-like elements (such as points or rewards) to a traditional test to increase engagement. A game-based assessment, on the other hand, is a standalone game designed specifically to evaluate certain competencies. The game itself is the primary evaluation tool, not just an enhancement.

FAQ

How can I improve my company’s retention rate?

The retention rate can be improved by investing in employee development and satisfaction. This includes offering training, career opportunities, and recognition for their contributions. A culture of open communication and attention to work-life balance can also contribute to higher retention. Additionally, offering competitive compensation and involving employees in decision-making can strengthen loyalty.

What are the benefits of growth opportunities for employee retention?

Growth opportunities can promote employee retention by giving staff a sense of direction and motivation. When they have the chance to learn and develop professionally within the company, they feel valued, which increases their loyalty. This can prevent them from leaving to seek better opportunities elsewhere. kunnen het behoud van personeel bevorderen door medewerkers een gevoel van richting en motivatie te geven. Wanneer zij de kans krijgen om te leren en zich professioneel te ontwikkelen binnen het bedrijf, voelen zij zich gewaardeerd, wat hun loyaliteit vergroot. Dit kan voorkomen dat ze vertrekken om elders betere kansen te zoeken.

What are the key factors that influence employee retention?

Key factors that influence employee retention include salary and benefits, opportunities for professional development, work-life balance, company culture, and the relationship with supervisors. Employees tend to stay longer when they feel valued, challenged, and supported in their work environment.

Why is employee retention so important for organizations?

Employee retention is important because it helps reduce recruitment and training costs for new employees, and it contributes to retaining knowledge and experience within the organization. High retention also ensures continuity within teams, leading to a more stable company culture, higher customer satisfaction, and improved business outcomes.

Which recruitment strategies help improve retention?

Recruitment strategies that can improve retention include identifying candidates who align with the company culture, using assessments to evaluate soft skills, and providing transparency about role expectations during the hiring process. Employees who feel connected to the organization and have clarity about their role are more likely to stay longer.

How can a good onboarding process contribute to higher retention?

An effective onboarding process can contribute to higher retention by helping new employees quickly adapt to their role, the company culture, and expectations. By providing support and clear information from the start, their engagement is increased, and the likelihood of them leaving early due to feelings of being overwhelmed or lacking guidance is reduced.

What is the role of company culture in retaining employees?

Company culture plays a crucial role in employee retention. When employees feel heard, valued, and connected to the values and norms of the company, they are more likely to stay. A positive culture that fosters collaboration, respect, and personal growth can significantly enhance employee motivation and satisfaction.

How can leadership and management style influence retention?

Leadership and management style have a significant impact on retention. Leaders who inspire, support, and coach their team can increase employee engagement and satisfaction. Offering autonomy and trust can lead to higher loyalty, while inefficient or negative management styles can contribute to dissatisfaction and increased employee turnover.

What is the importance of recognition and rewards for employee retention?

Recognition and rewards play an important role in employee retention by showing staff that their work is valued. This can increase their motivation and loyalty. In addition to financial rewards, compliments, promotions, and other forms of recognition can also contribute to satisfaction and retaining employees.

What role does work-life balance play in improving retention?

A balanced work-life balance plays an important role in increasing retention. By reducing stress and improving job satisfaction, employees are more likely to stay with the company. Initiatives such as flexible working hours, remote work options, and respect for personal time can contribute to this balance.

What does increasing retention mean within a company?

Increasing retention within a company means implementing strategies to keep employees with the organization for longer. This can be achieved by improving job satisfaction, offering growth opportunities, and fostering a positive and supportive company culture.

How do I measure the success of my retention strategy?

The success of a retention strategy can be measured by tracking retention rates and turnover rates, and by gaining insights from exit interviews. Additionally, employee satisfaction surveys and feedback from performance evaluations can provide valuable information about the effectiveness of the strategies applied.

What are the costs of a low retention rate?

A low retention rate can bring significant costs, such as increased expenses for recruiting and training new employees. Furthermore, the loss of experienced staff can lead to lower productivity, reduced knowledge transfer, and a negative impact on company culture.

How can I increase employee engagement?

To increase employee engagement, involve them in decision-making processes, regularly ask for their feedback, and recognize their contributions. Offering development opportunities and maintaining transparent communication can also contribute to greater engagement.

How can technology help improve employee retention?

Technology can be a tool for improving employee retention by facilitating communication, feedback, and development. By using online platforms for training, recognition, and evaluation, companies can create a more engaged and satisfied workforce.

FAQ

How long does it take to complete the tool?

Less than 10 minutes. You’ll answer 30 guided questions and get a summary of what to look for in your next assessment platform.

Can this checklist help me compare assessment providers?

Yes. By clarifying what matters most to your team, it makes comparing providers' features, pricing, and strengths much easier and more strategic.

How can I use this checklist if I’m not doing a formal RFI?

It’s equally valuable for internal evaluations, exploring new tools, or improving your current hiring process even if you’re not issuing an RFI or RFQ.

What should I look for in a modern assessment tool?

Prioritize platforms with user-friendly design, mobile compatibility, strong analytics, ATS integrations, and inclusive features like neurodiversity support.

What types of assessments should I consider in 2025?

Leading tools combine cognitive testing, situational judgment tests (SJTs), behavior assessments, and predictive AI to evaluate candidates more holistically.

Who should use an assessment checklist?

HR professionals, hiring managers, and procurement teams evaluating pre-selection solutions, especially those comparing AI-powered or compliance-driven assessment platforms.

How does this checklist help with RFIs and RFQs for assessments?

The checklist helps you define your exact requirements so you can confidently draft or respond to Requests for Information (RFI) or Requests for Quotation (RFQ) for assessment tools.

What is an assessment tool in hiring?

An assessment tool evaluates candidates’ skills, behaviors, and fit during the recruitment process. It helps improve hiring decisions and streamline pre-selection.

Game-based assessment packs

← Our Blog

Provider vs deployer under the EU AI Act: recruitment assessments

Learn the difference between provider & deployer roles under the EU AI Act for recruitment assessments.
Joeri Everaers
COO
Read time: Approx

When an employer buys an AI-powered assessment tool and uses it to screen job applicants, two distinct legal roles come into play under Regulation (EU) 2024/1689, the EU AI Act. One party built and placed the system on the market. Another party operates it day-to-day. The Act calls them the "provider" and the "deployer," and it assigns meaningfully different compliance obligations to each. Getting this wrong doesn't produce a minor paperwork gap. It produces situations where no one owns the incident response process, no one has retained the required logs, and no one can produce the technical documentation an auditor requests.

This guide maps those legal roles onto the real-world structure of recruitment technology, so that HR leaders, procurement teams, and their vendors can allocate obligations clearly before contracts are signed.

Provider vs deployer: what the EU AI Act actually says

Article 3 of the EU AI Act (consolidated text available on EUR-Lex under Regulation (EU) 2024/1689) establishes the definitions that govern the entire regulation. The AI Act Service Desk, operated by the European Commission, provides a plain-language summary of these roles.

Provider (Article 3(3)): the natural or legal person, public authority, agency, or other body that develops an AI system or has one developed, and places it on the market or puts it into service under its own name or trademark.

In recruitment terms, this is the assessment vendor. If a company builds and commercially licenses AI-scored assessments, it's the provider. The branding test matters: if a third-party model is embedded and re-released under a different name, the re-releasing entity takes on provider obligations.

Deployer (Article 3(4)): the natural or legal person, public authority, agency, or other body that uses an AI system under its authority in a professional context. Personal, non-professional use is excluded (DLA Piper Intelligence, quoting Article 3(4)).

In recruitment terms, this is the employer or HR team configuring and running the assessment in its hiring funnel. The deployer doesn't need to have built anything. Using the system to score, rank, or recommend candidates is sufficient to trigger deployer status.

One organization can hold both roles simultaneously. An employer that builds a proprietary AI screening tool and then rolls it out internally is both provider and deployer across different parts of the Act.

How roles map to common recruitment tech setups

The table below covers the most frequent configurations.

ScenarioLikely providerLikely deployer
Assessment vendor supplies AI scoring via ATS integrationAssessment vendorEmployer
ATS vendor bundles third-party assessment logic under its brandATS vendor, as re-branded providerEmployer
Employer configures custom scoring thresholds on vendor modelsAssessment vendor, for the base systemEmployer, including for the configuration decisions
Employer builds internal screening tool and deploys it to HR teamsEmployer, as providerEmployer, as deployer

The deciding questions are: who placed or branded the system into service, and who controls operational parameters and uses the outputs to make decisions about candidates? Those answers determine where obligations land.

What providers must do: Article 16 obligations

Under Article 16, providers of high-risk AI systems (which recruitment assessment tools used for employment decisions typically qualify as) carry upstream compliance responsibilities before the system reaches any deployer. The AI Act Service Desk summarizes these as including:

  • Establishing and maintaining a quality management system
  • Drawing up and retaining technical documentation
  • Completing a conformity assessment and registering the system in the EU database
  • Affixing CE marking where applicable
  • Designing the system with appropriate features to support human oversight by deployers
  • Implementing post-market monitoring obligations

For a procurement team evaluating an assessment vendor, this translates into a specific documentation request. Before go-live, the vendor should be able to produce its technical documentation package, a risk management file, its instructions for use, and evidence of its conformity process. If the vendor cannot produce these materials, that is a compliance signal, not just a procurement inconvenience.

What deployers must do: Article 26 obligations

Article 26 governs deployers of high-risk AI systems and covers operational compliance during use. Per the AI Act Service Desk, these obligations include:

  • Taking appropriate technical and organizational measures to use the system according to the provider's instructions
  • Assigning human oversight to natural persons with the necessary competence, training, and authority to intervene
  • Ensuring input data quality where the deployer controls those inputs
  • Monitoring operations and acting on risks
  • Retaining logs and cooperating with incident and risk escalation processes

The recruitment-specific implication: these are not IT department tasks. The obligation to ensure trained, authorized human reviewers can override or stop an automated recommendation belongs to HR and People leadership. A CHRO cannot delegate Article 26 governance entirely to a technical team without retaining process ownership over who reviews outcomes and under what conditions a decision is escalated or reversed.

Where obligations overlap and how contracts should handle them

Several compliance controls don't fall cleanly on one side. Candidate transparency (informing applicants they're subject to an AI-based decision), log retention, incident reporting workflows, and change control when recruitment policies shift all require coordination between vendor and employer.

A practical RACI framework assigns the provider responsibility for drafting instructions for use and supplying compliance documentation; the deployer approves internal governance structures and operates human oversight processes; and both parties share incident escalation paths with defined SLA timelines.

Contract provisions worth including:

  • Require the provider to deliver instructions for use, technical documentation, and audit cooperation support prior to go-live
  • Require the deployer to implement named governance roles, internal training, and monitoring procedures
  • Define the maximum response time for log and data requests (48-72 hours is a reasonable starting benchmark)
  • Specify the triggering conditions under which the deployer must suspend use of the system and notify the provider
  • Align AI Act operational clauses with existing GDPR data processing agreements where personal data is involved. These are separate legal instruments but they must be consistent with each other

One point that often gets missed: threshold configuration is a compliance decision, not just a product setting. If an employer lowers a cut-score or adjusts ranking weights, that changes the system's operational behavior in ways that can affect fairness and defensibility. Contracts should specify that configuration changes require documented validation before being applied in production. On the candidate-facing side, our guide to communicating AI use transparently to candidates covers what the disclosure itself should say.

Compliance checklist for vendors and employers

For vendors (providers):

  • Conformity assessment completed and documented
  • Technical documentation package available on request
  • Instructions for use delivered before deployment
  • Risk management file maintained and versioned
  • Human oversight design features built into the product
  • Post-market monitoring mechanism in place
  • Incident notification process and contact paths documented

For employers (deployers):

  • Named governance owner assigned (typically HR Director or equivalent)
  • Human oversight roles defined with clear authority to override
  • Candidate-facing transparency process in place before first use
  • Input data quality controls documented
  • Log retention process aligned with Article 26 and GDPR retention rules
  • Internal training records maintained for all staff using the system
  • Incident escalation SLA agreed with vendor in writing

Evidence to request before signing a contract:

  • Technical documentation summary or index
  • Instructions for use document
  • Conformity assessment status (self-assessment or third-party)
  • EU database registration confirmation (if applicable)
  • Incident history and response record for existing deployments

A note on go-live timelines and practical readiness

Compliance documentation is not something to gather after a system goes live. For organizations working with an assessment partner on a 2-to-10-week implementation timeline (a realistic window for integrated tools like Selection Lab's AI-driven assessment platform, which connects SmartChat candidate intake, skills assessments, and ATS reporting into a single workflow), the compliance paperwork exchange should happen in parallel with technical integration, not after it. Waiting until users are live to request a provider's technical documentation creates a gap that is difficult to close retroactively.

Further reading and references

  • Consolidated legal text: EUR-Lex, Regulation (EU) 2024/1689, available at eur-lex.europa.eu (last portal update shown as 2026-07-27)
  • Definitions: AI Act Service Desk, Article 3 (Europa.eu / AI Act Single Information Platform)
  • Provider obligations: AI Act Service Desk, Article 16
  • Deployer obligations: AI Act Service Desk, Article 26
  • Role interplay analysis: A&O Shearman, September 16, 2024

Classification of roles under the EU AI Act is fact-specific. Branding arrangements, contractual structures, and the degree of control each party exercises over the system's operation can all shift who holds which responsibilities. Legal counsel should be consulted for any case where the role classification is ambiguous, particularly where ATS vendors, assessment vendors, and employer configuration layers interact.