Confession: the Digital Services Act was my big love. The one I couldn’t stop talking about at dinner, the one I filed a complaint over, the one whose Article 40(12) I still think about more than is strictly healthy. The AI Act, by comparison, has always felt like the girl next door — I’d seen her around, I knew she was going places, but I hadn’t really looked. Then I actually sat down and read Article 27, and, well. Here we are. I have eyes on her now.

And the thing that got me is so familiar it’s almost funny. I want to tell you about a rule that doesn’t exist.

Picture two AI systems. The first decides whether you get a loan. The second decides whether you get a job interview. Under EU law, before the bank ever switches on the first system, it must sit down and formally ask itself: who could this hurt, and how? It has to write that assessment down and hand it to a regulator. The second system — the one deciding your job, your income, your ability to feed your family — faces no such requirement. Not from the company that built it. Not from the company that uses it. Nobody has to ask the question at all.

That’s not a loophole I’m speculating about. It’s the plain text of the EU’s Artificial Intelligence Act — the law the world is watching as the template for how democracies should govern AI.

The right that almost reaches you

The AI Act does something genuinely new: it creates a legal category called “high-risk” AI, and it says that before you deploy a high-risk system, you need a Fundamental Rights Impact Assessment. Think of it as a pre-flight checklist for algorithms — who will this affect, what could go wrong, how are we watching for it.

Hiring tools are squarely high-risk under the law. CV-screening software, candidate-ranking algorithms, automated interview scoring — all of it. The Act says so explicitly, and it applies whether you’re a five-person startup or a multinational.

But here’s the catch buried in the Act’s own architecture: the obligation to actually run that fundamental-rights check only falls on public authorities, on private companies delivering public services, and — by name — on credit-scoring and insurance-pricing systems. Recruitment isn’t on that list. A private employer’s hiring algorithm gets the “high-risk” label and every paperwork burden that comes with it, except the one safeguard actually designed to stop discrimination before it happens.

I checked this against independent compliance analysts and a recent academic paper on AI governance, and they say the same thing in almost the same words: this isn’t ambiguous, and it isn’t an accident of drafting. Employment management systems are explicitly named among the high-risk uses that simply don’t trigger the fundamental-rights check.

So: your bank has to ask whether its algorithm might unfairly deny you credit. The company that might employ you does not have to ask whether its algorithm might unfairly deny you a livelihood.

Who actually pays for this

This wouldn’t matter much if hiring bias against religious minorities were a fringe worry. It isn’t.

Researchers have run the same experiment, with small variations, across five European countries — Germany, the Netherlands, Norway, Spain, and the UK — sending out identical fictitious CVs that differ only in the details signaling religion. Applicants flagged as Muslim, through a name, a volunteer role at a faith organization, or a photo with a headscarf, get called back at consistently lower rates than identical candidates without those signals. This isn’t one country’s quirk. It’s a pattern that survives translation across borders, labor markets, and hiring cultures.

Now here’s the part that should stop every AI-ethics conference in its tracks: a 2025 study of actual deployed hiring algorithms — not lab experiments, real software used by real employers — found that AI screening tools reproduce this exact bias. Candidates who wear headscarves and candidates with names read as belonging to minority groups get systematically downgraded. The researchers point to the well-known case of a major tech company’s recruiting AI that taught itself, without anyone telling it to, to penalize applications that looked like they came from women. Machines don’t invent bias from nothing. They learn it from us, encode it into a number, and then apply it at a scale no single biased recruiter ever could.

That’s the discrimination the EU’s flagship AI law has decided, by omission, not to check for in advance.

The law hasn’t caught up to the machine

There’s a deeper problem here, and it’s not just a missing checkbox. Europe’s courts already have a body of law on religious discrimination at work — cases about whether a company can ban headscarves as part of a “neutral” dress code. That case law was built around a very human scenario: a manager, a policy, a conversation, a decision you can point to and argue about.

An algorithm doesn’t give you any of that. It doesn’t announce a policy. It doesn’t sit across the table and explain itself. It just quietly assigns a lower score to CVs that correlate with a name, a neighborhood, or a gap in employment that reads as a headscarf photo removed. There is no decision to put in front of a judge, because there was never a decision anyone can see. The only moment where that hidden pattern could be caught is before the system goes live — which is exactly the moment the AI Act has decided not to regulate for private employers.

And if you do get rejected and suspect the algorithm was the reason? The law gives you a right to ask for an explanation, and a right to file a complaint with a regulator. It does not give you a right to compensation. Compare that to Europe’s own data protection law, which lets you sue for damages — including purely emotional harm — if a company mishandles your data. Losing a job opportunity to a discriminatory algorithm is treated, legally, as less serious than a data breach.

A very familiar shape. Again.

If you’ve read anything I’ve written before, you already know where this is going, because it’s always the same shape. The DSA gave platforms a duty to assess systemic risk — and then left the enforcement teeth so blunt that a formal complaint against a platform the size of X still has to fight for basic data access, years later. The child-protection provisions read beautifully on paper, right up until you ask which agency actually checks whether they’re being followed for the kids who need it most. And now here’s the AI Act, doing it again: writing a real safeguard into real law, and then quietly forgetting to point it at the one group of people — job applicants, disproportionately from religious minorities — who needed it pointed at them most.

I don’t think this is a coincidence anymore. I think it’s a pattern of how EU law gets made: the principle survives the drafting process, and the enforcement mechanism doesn’t. Every one of these gaps has the same fingerprint — a right that sounds airtight in the recitals, and a scope clause, buried three paragraphs later, that quietly excuses the actor most likely to cause harm. The DSA forgot to give researchers real access. The child-safety rules forgot to give anyone real teeth. And the AI Act forgot, again, that the people most exposed to discrimination are usually the ones standing outside the room where “high-risk” got defined.

Why this is fixable, and why now

Here’s the good news buried in the bad news: this is a small, precise fix, not a rewrite of European law. Add one category — employment — to the list of systems that require a fundamental-rights check. Add a right to compensation alongside the existing right to an explanation. That’s it.

And there’s a real window to make this happen. The EU just finished amending the AI Act to push back the deadline for high-risk obligations, including employment AI, to December 2027. That delay was meant to give regulators time to get their technical standards ready. It also, as a side effect, gives advocates time to fix the scope of the law before the current gap becomes the accepted status quo. Once companies build their compliance programs around “employment AI doesn’t need a fundamental-rights check,” undoing that expectation gets much harder.

I’ve spent years trying to close the distance between the rights Europe writes into law and the rights people can actually use. The pattern is always the same: a beautiful piece of legislation, a right that sounds airtight on paper, and a carve-out — usually technical, usually boring-sounding — that quietly excuses the actor most likely to cause harm. The AI Act is no different. It just happens to be the law that will decide, for the next decade, whether the people screening you for a job have to ask whether their machine is fair before they let it decide your future.

Right now, in Europe, the answer is: only if they feel like it.

Companion piece to the formal policy briefing The Employment Blind Spot and the formal submission Closing the FRIA gap in recruitment AI (Ref. EFE/AI-ACT/2026-01), both available in full in Publications.