AI Act classification memorandum
CandidateRank (version 2.4) — Northwind Talent GmbH, HRB 998877, Berlin
Prepared for internal record and for production to national competent authorities on request. Supporting record for the classification reached.
1. Purpose and status of this document
Art. 6(4); Art. 49(2)
This memorandum records the risk classification of the AI system identified below under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force 27 July 2026, the reasoning behind it, and the obligations that follow. It is written to be handed to a national competent authority without further preparation.
Where a provider concludes that an Annex III system is not high-risk, Article 6(4) makes documenting that assessment a legal duty. Where the conclusion is different — prohibited, high-risk, transparency-only or minimal — no provision compels a memorandum, but the same record is what every later obligation is built on, and it is the first thing an authority or an acquirer asks for.
2. Identification
- Organisation
- Northwind Talent GmbH, HRB 998877, Berlin
- Country of establishment
- Germany
- AI system
- CandidateRank (version 2.4)
- Built by
- In-house, built on a third-party general-purpose model via API
- Assessment date
- 2026-09-11
- Assessment owner
- Jana Novak — Head of People Operations, acting AI compliance owner
- Reviewed by
- Not yet reviewed — see the review section
3. The system being assessed
Art. 3(1); Art. 3(12)
Intended purpose, as declared by the provider:
Intended purpose
Ranks inbound job applications by fit against the role description in order to produce a shortlist, which a recruiter reviews before any interview or rejection decision is taken.
Classification under the AI Act turns on the intended purpose, not on the technology used. A change to the intended purpose is therefore a change to the classification — see the obligations section.
- People affected by its output
- External job applicants in the EU; internal candidates applying for promotion.
- Processes personal data
- Yes
- Placed on the market before 2 August 2026
- Yes
4. Our role in relation to this system
Art. 3(3), 3(4); Art. 25
- Role assessed
- Both — we build it and use it ourselves
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority. The roles carry different obligations and the same organisation is frequently both.
5. Step one — prohibited practices
Art. 5
The Article 5 prohibitions were screened first, because a prohibited practice cannot be cured by documentation or a later deadline. The prohibitions in Article 5(1)(a) to (h) have applied since 2 February 2025. Two further prohibitions, inserted by Regulation (EU) 2026/1744 — Article 5(1)(ba) on non-consensual intimate imagery and Article 5(1)(bb) on child sexual abuse material — apply from 2 December 2026.
Conclusion: none of the Article 5 prohibitions applies to this system, on the basis of the intended purpose recorded above.
- Practices identified
- None
6. Step two — regulated products (Annex I)
Art. 6(1); Art. 2(2); Annex I
Article 6(1) has two cumulative conditions: the AI system is a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I; and that product must undergo a third-party conformity assessment under that legislation. Both must be true.
- Finding
- No — it is not part of a regulated product, or the product self-certifies without a notified body
Conclusion: the Annex I route does not apply. The assessment therefore proceeds to Annex III.
7. Step three — use-case areas (Annex III)
Art. 6(2); Annex III
Annex III lists eight areas in which a stand-alone AI system is high-risk. Annex III itself was not amended by Regulation (EU) 2026/1744 and no delegated act under Article 7 has added to it.
- Areas identified
- Employment and workers management — recruitment, screening or ranking candidates, decisions on promotion, termination or task allocation, monitoring and evaluating workers
The system operates in an Annex III area, so the Article 6(3) filter below must be applied before any conclusion is drawn.
8. Step four — the Article 6(3) filter
Art. 6(3); Art. 3(52)
An Annex III system is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights. Article 6(3) is satisfied where ANY ONE of four conditions is met: the system performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from prior patterns and is not meant to replace or influence the previously completed human assessment without proper human review; or it performs a preparatory task to an assessment relevant to the Annex III use case.
- Condition relied on
- None of these — it materially influences the decision or outcome
Conclusion: the filter does not apply, either because the system materially influences the outcome or because it profiles natural persons. The system is high-risk under Article 6(2) and Annex III.
9. Steps five and six — transparency and general-purpose models
Art. 50; Chapter V
Transparency duties under Article 50 sit in Chapter IV and are independent of risk tier: a minimal-risk system can owe them, and a high-risk system owes them in addition to Chapter III. They have applied since 2 August 2026 and were not deferred.
- Article 50 triggers identified
- Interacts directly with people — chatbots, voice assistants, conversational agents; Generates synthetic audio, image, video or text content
- General-purpose AI model placed on the market by us
- No
The disclosure wordings and the marking policy that satisfy these triggers are set out in the companion Article 50 disclosure kit.
10. Conclusion and applicable dates
Art. 113 as amended
- Classification
- High-risk — Annex III use case + Transparency obligations — live now
| Date | What applies | Basis | Status |
|---|---|---|---|
| 2 December 2027 | Chapter III, Sections 1–3 apply to Annex III high-risk systems (deferred from 2 August 2026 by Regulation (EU) 2026/1744; the deferral is unconditional — the proposed standards-readiness trigger was dropped). | Art. 113(c)(i) | Upcoming |
| 2 August 2026 | Registration in the EU database (Article 49) is not deferred — it applies from the general application date. | Art. 49; Art. 113 | Applies now |
| 2 August 2026 | Article 50 transparency obligations apply. | Art. 113 | Applies now |
| 2 December 2026 | Generative systems placed on the market before 2 August 2026 have until this date to meet the Article 50(2) machine-readable marking duty. | Art. 111(4) as inserted by Reg. (EU) 2026/1744 | Upcoming |
Penalty exposure for the obligations identified: Most operator obligations, including Article 50: up to EUR 15 000 000 or 3% of worldwide annual turnover, whichever is higher (SMEs: whichever is lower, Art. 99(6)). Supplying incorrect information to authorities: up to EUR 7 500 000 or 1%.
11. Obligations that follow from this classification
- Register the system in the EU database under Article 49 before placing it on the market or putting it into service.
- Build the Articles 9 to 15 programme — risk management, data governance, technical documentation to Annex IV, automatic logging, instructions for deployers, human-oversight design, accuracy, robustness and cybersecurity.
- Establish a quality management system (Article 17), complete the conformity assessment (Article 43), draw up the EU declaration of conformity (Article 47) and affix the CE marking (Article 48).
- Operate post-market monitoring (Article 72) and serious-incident reporting (Article 73).
- Use the system in accordance with the instructions for use, assign human oversight to people with the necessary competence, training, authority and support (Article 26(2)), ensure input data under our control is relevant and sufficiently representative (Article 26(4)), and keep the automatically generated logs we control for at least six months (Article 26(6)).
- Inform workers' representatives and affected workers before putting the system into use in the workplace (Article 26(7)), and inform natural persons that they are subject to the system where it is used to make or assist decisions about them (Article 26(11)).
- Implement the Article 50 disclosures — these apply now, not in 2027.
- If the system generates synthetic content and was on the market before 2 August 2026, the Article 50(2) machine-readable marking duty must be met by 2 December 2026 under the new Article 111(4).
- Maintain a proportionate level of AI literacy among staff who deal with the system (Article 4, as rewritten by Regulation (EU) 2026/1744).
12. Review triggers and outstanding items
Art. 3(23); Art. 25; Art. 6(3)
This classification is valid for the intended purpose recorded above. It must be redone when any of the following happens:
- The intended purpose changes, or the system is used for something it was not assessed for. Under Article 25 a change of intended purpose that makes a non-high-risk system high-risk moves the provider's obligations onto whoever made the change.
- A substantial modification is made — a change after placing on the market or putting into service that was not foreseen or planned in the initial conformity assessment (Article 3(23)).
- The system starts to profile natural persons, which defeats any reliance on Article 6(3).
- We put our own name or trademark on a third-party high-risk system (Article 25).
- The Commission adopts the final Article 6(5) classification guidelines, or amends Annex III by delegated act under Article 7.
- Next scheduled review
- [to be completed]
- Review owner
- Jana Novak
Assessment owner
Reviewer
Date
What a lawyer should check
Hand this list to counsel with the document. It is short on purpose — these are the points where a generated record most often diverges from the facts of a real organisation.
- Whether the intended purpose is the purpose actually marketed and actually used — misalignment here invalidates everything downstream.
- The role determination, particularly whether anything we do engages Article 25 and makes us a provider of a system we bought.
- Whether any Article 6(3) condition could in fact be relied on, which would change the classification and the deadline.
- Whether Article 27 applies to us on the facts, and whether the fundamental rights impact assessment can be combined with an existing DPIA under Article 27(4).
- The GDPR position in parallel: lawful basis, Article 22 automated decision-making, and whether a DPIA is required.
- Whether the conclusion reached should be disclosed to customers, insurers or investors, and whether any contract already warrants a different position.
- This document is a structured record of an assessment you made, drafted for your review. It is not legal advice and it does not bind any authority.
- It reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force 27 July 2026. The Commission's guidelines on high-risk classification under Article 6(5) were due on 2 February 2026 and remain in draft (version of 19 May 2026), so classification positions that depend on them may change.
- No harmonised standard has yet been cited in the Official Journal, so the presumption of conformity in Article 40 is not available to anyone.