Ukrainian IT companies face fines of up to €35 million over AI: who will be affected by the new EU law?

A typical scenario: AI sorts through CVs, screens out candidates and suggests who to hire. For businesses, this is, of course, a form of optimisation. But for EU regulators, it amounts to influencing access to employment. And that is already a risk area.

So if a system filters candidates, assesses them and influences hiring decisions, it falls under strict requirements.

Who will be affected:

SaaS products with EU clients

Outsourced teams working with European data

Products with AI features (recruitment, scoring, recommendations)

Companies whose clients use their product in the EU

Start-ups planning to enter the EU market

Where are the main risks:

Use of AI in candidate recruitment

Uncontrolled use of third-party AI (such as ChatGPT)

Lack of a description of how the AI works

Processing EU user data without verification

Automated decisions without human involvement

One of the biggest risks right now really lies with HR teams.

Here is an example of ‘poor’ AI compliance: HR cannot explain why a candidate has been rejected. There is no description of how the AI works, and the decision appears to be automatic. The responsibility still lies with the company.

What exactly does the law change:

Risk categories for AI are being introduced

Some systems may be banned

Some require an audit and oversight

Heavy fines are being introduced

It is not where the company is based that matters, but where the product is used

What to do right now

Check where you have AI

Find out if you have customers or users from the EU

Assess whether AI influences decisions regarding people

Describe how your AI functions work

 

https://dev.ua/blogs/posts/do-diiasity-pryiednavsia-shche-odyn-defense-tech-iedynorih-ievropeiskyi-vyrobnyk-bpla-tekever