The EU AI Act entered into force on 1 August 2024 and became fully applicable on 2 August 2026. For organizations using AI-powered recruitment assessments, this creates a concrete compliance structure with obligations distributed across two distinct roles. The provider (the company that develops and places the AI system on the market) and the deployer (the organization that uses the AI system in its own context, such as a hiring process). For the wider picture, see the EU AI Act explained for recruitment.
This page exists to clarify precisely how that responsibility split works when you use Selection Lab as your recruitment assessment platform. It maps what Selection Lab supplies as the provider of AI-enabled assessment tools against what your organization, as the deployer, is responsible for managing and demonstrating under applicable EU AI Act obligations.
One important note before proceeding. This page is not legal advice. The compliance scope that applies to any specific deployment depends on your organization's use case, jurisdiction, and the risk classification you assign to your recruitment assessment workflow. Your legal, DPO, and compliance teams should confirm the applicable obligations for your configuration.
As the provider of the assessment platform, Selection Lab's obligations cluster around system design, transparency documentation, and the contractual and technical controls that enable deployers to operate the system appropriately. Below is a summary of what Selection Lab delivers.
All personal data processed within the platform is stored in Frankfurt, in accordance with GDPR requirements. Selection Lab is fully GDPR compliant and maintains clear data processing agreements with all sub-processors. For each processing purpose, consent is requested from candidates, and defined retention periods are in place. Candidates see their results before being asked again for consent before those results are shared with the hiring organization.
Selection Lab also applies privacy-by-design at the conversation layer. Local large language models are used to remove all personal information from SmartChat conversations before any processing occurs, reducing the risk of unintended personal data exposure.
Article 13 of the EU AI Act requires providers of high-risk AI systems to supply deployers with sufficient information to operate the system in compliance with applicable obligations. This includes clear instructions for use, information about the system's purpose and limitations, and guidance on human oversight.
Selection Lab provides documentation covering how the platform works, its intended use in selection workflows, the boundaries of the system's outputs, and how results should be interpreted by hiring teams. This documentation forms the basis of your organization's own transparency flows toward candidates and HR stakeholders.
A Data Processing Agreement (DPA) is established with every customer as part of onboarding. This agreement documents the categories of personal data processed, the purposes of processing, sub-processor arrangements, data retention and deletion commitments, and security obligations. For organizations subject to EU AI Act obligations, this DPA also supports your ability to demonstrate processor-level accountability.
Selection Lab's platform covers the full selection funnel. Pre-screening, role match, interview preparation, and evaluation. The SmartChat module responds within 10 seconds and is accessible via WhatsApp or webchat, with results feeding directly into your ATS workflow. Native ATS integrations are supported, and implementation typically takes 2 to 10 weeks from contract signature to go-live.
After go-live, Selection Lab runs adoption checks every two weeks during the initial phase, followed by quarterly strategic reviews and ongoing support and training. This cadence is designed to help your teams use the system correctly and within the bounds documented in the instructions for use.
The following documentation categories are available to customers and should be requested during your onboarding process.
If you have a DPO, legal team, or external compliance advisor involved in your procurement, request this evidence pack at the start of your implementation engagement.
Selection Lab provides the vendor-side building blocks, but deployers carry a defined set of obligations that cannot be delegated to the platform provider. The following sections identify those obligations and their EU AI Act article anchors.
Before deploying any AI system in a recruitment context, your organization must determine the applicable EU AI Act risk category for your specific use case. Recruitment and selection AI systems that make or meaningfully inform decisions about access to employment may qualify as high-risk systems under Annex III of the Act. If high-risk classification applies, a full set of obligations under Chapter III applies to both provider and deployer.
Documenting your risk classification decision, the use-case scope, and the governance structure under which the system operates is your organization's responsibility. Selection Lab can provide supporting documentation to inform this assessment, but the classification itself must be owned and signed off by your team.
Article 14 requires that high-risk AI systems be designed so that natural persons can effectively oversee operation and intervene when necessary. Selection Lab designs its platform with this in mind, but the deployer must implement the human oversight structures in practice.
This means three things.
This is an organizational process obligation. It cannot be satisfied by platform features alone.
While Selection Lab provides the instructions for use and the consent flow at the platform level, your organization must operationalize transparency in your own recruitment communications. Candidates must be informed that AI systems are being used in the selection process, what data is collected, how it is used, and what their rights are.
Your HR communications, candidate-facing materials, career site disclosures, and internal HR policy documents all need to reflect the system's use in a way that satisfies the transparency expectations under Article 13 and any relevant national implementation measures.
Article 19 of the EU AI Act establishes logging requirements for high-risk AI systems. Article 26 requires deployers to keep automatically generated logs to the extent those logs are under their control, and to retain them for a minimum of six months.
Selection Lab provides logging and record-keeping capabilities within the platform. The specifics of log access, export format, and retention configuration are confirmed during implementation. However, your organization must establish the operational procedures to do the following.
Do not assume that logs held within the platform automatically satisfy this requirement. Your compliance team should confirm that your log retention procedures meet the Article 26 obligations for your specific deployment configuration.
The hiring decision remains entirely with your organization. Selection Lab's platform produces assessment outputs and recommendations that inform your recruitment process, but the system does not make hiring decisions autonomously. Your organization must document the following.
This documentation is essential for audit readiness and for demonstrating that human judgment remains accountable in the final selection outcome.
The compliance obligations described above require organizational action, but Selection Lab structures its implementation and support model to help you get there efficiently.
Use the following checklist as a starting point when operationalizing your EU AI Act obligations for recruitment assessments.
During implementation, the following documentation categories can be provided to support your internal compliance file.
Where Selection Lab's documentation does not cover a specific technical detail you need for your compliance file, such as log export format or tamper-evidence controls, raise those questions during your implementation kickoff. The technical and customer success teams can confirm specifics or escalate to the appropriate internal owner.
If you need a structured walkthrough of vendor and deployer responsibilities for your specific recruitment assessment configuration, Selection Lab offers a dedicated compliance engagement. This is particularly relevant for organizations with a DPO, legal team, or external compliance advisor involved in their EU AI Act readiness program.
To prepare for a compliance walkthrough, it helps to have the following information available.
Based on this information, Selection Lab can deliver a responsibility matrix tailored to your configuration and a compliance evidence pack covering the vendor-side documentation described above.
Contact the Selection Lab team to schedule your compliance walkthrough or to request the documentation package for your onboarding.
Selection Lab is the provider, the party that develops the assessment platform and places it on the market. Your organization is the deployer, the party that uses the system in its own hiring process. Each role carries its own obligations and neither can take over the other's.
They can be. AI systems that make or meaningfully inform decisions about access to employment fall under Annex III. Whether your specific use case qualifies depends on how the outputs are used, and that classification is the deployer's responsibility to make, document and sign off, with input from legal and the DPO.
Use the system according to the provider's instructions for use, assign competent human oversight, inform candidates that AI is used, and keep the automatically generated logs that are under your control for at least six months. Selection Lab supplies the documentation and logging capabilities; the procedures around them are yours.
No. The platform produces assessment outputs and recommendations. The decision stays with your organization, and you need a documented decision policy that states how outputs are used, when a recommendation can be overridden and how outputs are reviewed over time.
The data processing agreement, a data residency and security overview, the consent and retention statement per processing purpose, the instructions for use package, ATS integration documentation, and logging and record-access details. Request them at the start of implementation, especially if a DPO or legal team is involved.

The EU AI Act entered into force on 1 August 2024 and became fully applicable on 2 August 2026. For organizations using AI-powered recruitment assessments, this creates a concrete compliance structure with obligations distributed across two distinct roles. The provider (the company that develops and places the AI system on the market) and the deployer (the organization that uses the AI system in its own context, such as a hiring process). For the wider picture, see the EU AI Act explained for recruitment.
This page exists to clarify precisely how that responsibility split works when you use Selection Lab as your recruitment assessment platform. It maps what Selection Lab supplies as the provider of AI-enabled assessment tools against what your organization, as the deployer, is responsible for managing and demonstrating under applicable EU AI Act obligations.
One important note before proceeding. This page is not legal advice. The compliance scope that applies to any specific deployment depends on your organization's use case, jurisdiction, and the risk classification you assign to your recruitment assessment workflow. Your legal, DPO, and compliance teams should confirm the applicable obligations for your configuration.
As the provider of the assessment platform, Selection Lab's obligations cluster around system design, transparency documentation, and the contractual and technical controls that enable deployers to operate the system appropriately. Below is a summary of what Selection Lab delivers.
All personal data processed within the platform is stored in Frankfurt, in accordance with GDPR requirements. Selection Lab is fully GDPR compliant and maintains clear data processing agreements with all sub-processors. For each processing purpose, consent is requested from candidates, and defined retention periods are in place. Candidates see their results before being asked again for consent before those results are shared with the hiring organization.
Selection Lab also applies privacy-by-design at the conversation layer. Local large language models are used to remove all personal information from SmartChat conversations before any processing occurs, reducing the risk of unintended personal data exposure.
Article 13 of the EU AI Act requires providers of high-risk AI systems to supply deployers with sufficient information to operate the system in compliance with applicable obligations. This includes clear instructions for use, information about the system's purpose and limitations, and guidance on human oversight.
Selection Lab provides documentation covering how the platform works, its intended use in selection workflows, the boundaries of the system's outputs, and how results should be interpreted by hiring teams. This documentation forms the basis of your organization's own transparency flows toward candidates and HR stakeholders.
A Data Processing Agreement (DPA) is established with every customer as part of onboarding. This agreement documents the categories of personal data processed, the purposes of processing, sub-processor arrangements, data retention and deletion commitments, and security obligations. For organizations subject to EU AI Act obligations, this DPA also supports your ability to demonstrate processor-level accountability.
Selection Lab's platform covers the full selection funnel. Pre-screening, role match, interview preparation, and evaluation. The SmartChat module responds within 10 seconds and is accessible via WhatsApp or webchat, with results feeding directly into your ATS workflow. Native ATS integrations are supported, and implementation typically takes 2 to 10 weeks from contract signature to go-live.
After go-live, Selection Lab runs adoption checks every two weeks during the initial phase, followed by quarterly strategic reviews and ongoing support and training. This cadence is designed to help your teams use the system correctly and within the bounds documented in the instructions for use.
The following documentation categories are available to customers and should be requested during your onboarding process.
If you have a DPO, legal team, or external compliance advisor involved in your procurement, request this evidence pack at the start of your implementation engagement.
Selection Lab provides the vendor-side building blocks, but deployers carry a defined set of obligations that cannot be delegated to the platform provider. The following sections identify those obligations and their EU AI Act article anchors.
Before deploying any AI system in a recruitment context, your organization must determine the applicable EU AI Act risk category for your specific use case. Recruitment and selection AI systems that make or meaningfully inform decisions about access to employment may qualify as high-risk systems under Annex III of the Act. If high-risk classification applies, a full set of obligations under Chapter III applies to both provider and deployer.
Documenting your risk classification decision, the use-case scope, and the governance structure under which the system operates is your organization's responsibility. Selection Lab can provide supporting documentation to inform this assessment, but the classification itself must be owned and signed off by your team.
Article 14 requires that high-risk AI systems be designed so that natural persons can effectively oversee operation and intervene when necessary. Selection Lab designs its platform with this in mind, but the deployer must implement the human oversight structures in practice.
This means three things.
This is an organizational process obligation. It cannot be satisfied by platform features alone.
While Selection Lab provides the instructions for use and the consent flow at the platform level, your organization must operationalize transparency in your own recruitment communications. Candidates must be informed that AI systems are being used in the selection process, what data is collected, how it is used, and what their rights are.
Your HR communications, candidate-facing materials, career site disclosures, and internal HR policy documents all need to reflect the system's use in a way that satisfies the transparency expectations under Article 13 and any relevant national implementation measures.
Article 19 of the EU AI Act establishes logging requirements for high-risk AI systems. Article 26 requires deployers to keep automatically generated logs to the extent those logs are under their control, and to retain them for a minimum of six months.
Selection Lab provides logging and record-keeping capabilities within the platform. The specifics of log access, export format, and retention configuration are confirmed during implementation. However, your organization must establish the operational procedures to do the following.
Do not assume that logs held within the platform automatically satisfy this requirement. Your compliance team should confirm that your log retention procedures meet the Article 26 obligations for your specific deployment configuration.
The hiring decision remains entirely with your organization. Selection Lab's platform produces assessment outputs and recommendations that inform your recruitment process, but the system does not make hiring decisions autonomously. Your organization must document the following.
This documentation is essential for audit readiness and for demonstrating that human judgment remains accountable in the final selection outcome.
The compliance obligations described above require organizational action, but Selection Lab structures its implementation and support model to help you get there efficiently.
Use the following checklist as a starting point when operationalizing your EU AI Act obligations for recruitment assessments.
During implementation, the following documentation categories can be provided to support your internal compliance file.
Where Selection Lab's documentation does not cover a specific technical detail you need for your compliance file, such as log export format or tamper-evidence controls, raise those questions during your implementation kickoff. The technical and customer success teams can confirm specifics or escalate to the appropriate internal owner.
If you need a structured walkthrough of vendor and deployer responsibilities for your specific recruitment assessment configuration, Selection Lab offers a dedicated compliance engagement. This is particularly relevant for organizations with a DPO, legal team, or external compliance advisor involved in their EU AI Act readiness program.
To prepare for a compliance walkthrough, it helps to have the following information available.
Based on this information, Selection Lab can deliver a responsibility matrix tailored to your configuration and a compliance evidence pack covering the vendor-side documentation described above.
Contact the Selection Lab team to schedule your compliance walkthrough or to request the documentation package for your onboarding.
Selection Lab is the provider, the party that develops the assessment platform and places it on the market. Your organization is the deployer, the party that uses the system in its own hiring process. Each role carries its own obligations and neither can take over the other's.
They can be. AI systems that make or meaningfully inform decisions about access to employment fall under Annex III. Whether your specific use case qualifies depends on how the outputs are used, and that classification is the deployer's responsibility to make, document and sign off, with input from legal and the DPO.
Use the system according to the provider's instructions for use, assign competent human oversight, inform candidates that AI is used, and keep the automatically generated logs that are under your control for at least six months. Selection Lab supplies the documentation and logging capabilities; the procedures around them are yours.
No. The platform produces assessment outputs and recommendations. The decision stays with your organization, and you need a documented decision policy that states how outputs are used, when a recommendation can be overridden and how outputs are reviewed over time.
The data processing agreement, a data residency and security overview, the consent and retention statement per processing purpose, the instructions for use package, ATS integration documentation, and logging and record-access details. Request them at the start of implementation, especially if a DPO or legal team is involved.