Human in the Loop Hiring: The Five Article 14 Duties (2026)
EU AI Act Article 14 applied to hiring tools from 2 August 2026. Here is what it actually asks of your team.
Human in the loop hiring became law on 2 August 2026. The five duties Article 14 creates, and the two-person rule that does not apply to recruitment.

TL;DR
Human in the loop hiring stopped being a best practice and became a legal requirement on 2 August 2026, the date Article 14 of the EU AI Act began to apply to high-risk systems. Recruitment and candidate selection sit squarely in that category, so if your screening or ranking tool touches EU candidates, someone must be able to understand its output, override it, and stop it. The rule people most often quote at you, that two humans must sign off on every decision, is not in the employment part of the law at all. If you want the wider regulatory picture first, start with our AI hiring compliance guide.
What is actually happening
Three regimes now point at the same operational question, and they arrived in a cluster. The EU AI Act's high-risk obligations, including Article 14, applied from 2 August 2026. New York City's Local Law 144 has been live since 2023 and requires an independent annual bias audit, a public summary of it, and at least ten business days of notice to candidates.
The enforcement mood changed in December 2025. The New York State Comptroller published an audit of how the city's Department of Consumer and Worker Protection was policing Local Law 144 and concluded that enforcement was ineffective, citing weak complaint handling and inaccurate compliance reviews. Regulators who get told their enforcement is ineffective tend to enforce more.
Meanwhile the thing the law is worried about has been measured. Article 14(4)(b) singles out "automation bias", the tendency of a human reviewer to lean on whatever the machine suggested, and it does so in the operative text rather than a recital.
That is not a theoretical worry. In a University of Washington study presented in October 2025, 528 people screened candidates for 16 different jobs alongside a simulated AI. Working with a severely biased recommendation, participants followed the AI's picks around 90% of the time, and even people who could recognise the bias did not fully resist it.
The gap this opens is uncomfortable for most TA functions. Lead author Kyra Wilson noted that in one survey, 80% of organisations using AI hiring tools said they do not reject applicants without human review. Human review is therefore the dominant control, and the evidence says it is a weaker control than almost everyone assumes.
The numbers
The cost of getting this wrong is easier to quantify in New York than in Brussels, because Local Law 144 attaches a daily civil penalty. The Department of Consumer and Worker Protection can impose between $500 and $1,500 per violation per day, and failing to run the bias audit and failing to give candidate notice count as separate violations.
Two structural details make that compound faster than teams expect. The penalty accrues per day rather than per incident, so a tool quietly running out of compliance for a quarter is not one fine. And because audit and notice are separate obligations, a single non-compliant tool can be generating two clocks at once.
The EU side does not publish a neat daily figure, but the exposure is larger rather than smaller, and the reputational surface is wider because Article 14 failures show up as a design problem rather than a paperwork gap.
How to read this chart:
- The bars show the statutory floor and ceiling for a single Local Law 144 violation, extended across common durations. The low end assumes the minimum $500 daily penalty and the high end the maximum $1,500.
- These are per violation. Running an unaudited tool without candidate notice can put two of these bars on the board simultaneously.
- This is New York City only. It is a useful proxy for the cost of neglect, not a global estimate, and the EU AI Act operates on a different and generally larger scale.
How it actually works, and where it breaks
Article 14 is short, and reading it directly is worth the ten minutes. It requires that high-risk systems be designed so they can be effectively overseen by a natural person while in use, and it lists what that person must be able to do.
They must understand the system's capacities and limitations well enough to spot anomalies. They must stay aware of automation bias. They must interpret the output correctly, decide in any particular situation not to use the system or to disregard, override or reverse its output, and be able to intervene or halt it.
The first failure mode is oversight that has no off switch. Article 14(4)(e) expects a stop, and 14(4)(d) expects the reviewer to be able to reverse an output. Plenty of screening deployments give a recruiter a ranked list and no mechanism to reinstate a rejected candidate, which means the human is present but not actually in the loop.
The second is the reviewer who reads from the top. If the interface shows the top twenty candidates and the reviewer works down, the model's ranking has been ratified rather than checked. This is the same structural problem that produces AI screening false negatives, and it is why oversight has to include looking at what the system ranked low.
The third is the two-person myth. Article 14(5) does require that a decision be separately verified by at least two competent people, but only for the systems in Annex III point 1(a), which is remote biometric identification. Recruitment sits elsewhere in Annex III, so that specific duty does not attach to your screening tool, and teams that build a two-signoff workflow for hiring are usually solving a requirement they do not have while leaving the override and stop duties unbuilt.
"A ranked list with no way back is not oversight, it is a recommendation the reviewer has been asked to rubber stamp."
What this means for your team
Oversight is a design problem before it is a policy problem. Writing "a human reviews all AI recommendations" into a policy document satisfies nobody if the interface makes review impossible, so the work runs in this order.
The sequence below is deliberately unglamorous, and most of it is configuration and documentation rather than procurement.
- Inventory the tools that actually decide. List every system that scores, ranks, filters or rejects, including the knockout rules inside your ATS. Anything that narrows a pool is in scope even if the vendor does not call it AI.
- Name an accountable overseer per tool. Article 14 assumes a natural person with the competence, training and authority to act. A committee is not an overseer.
- Build the override and the stop. The reviewer needs a way to reinstate a rejected candidate and a way to switch the tool off without filing a ticket. If neither exists, oversight is decorative.
- Design against automation bias. Show reviewers unranked or low-ranked candidates as a matter of routine, and record when a human disagreed with the system. A review process that never disagrees is not producing evidence of oversight.
- Document and re-test on a cycle. Keep the bias audit current where Local Law 144 applies, keep the Article 14 records current, and re-run the checks when the model or the requisition template changes.
If you are still selecting tooling, the override and stop requirements belong in the evaluation criteria rather than the security review, and our note on AI candidate screening tools covers what else to ask for.
Human in the loop vs a bias audit
These two get treated as the same compliance task and they are not. A bias audit is retrospective and statistical: it samples outcomes and asks whether selection rates differ across groups. Human oversight is live and individual: it asks whether a person can understand, override and stop the system while it is running.
You can pass a bias audit with a system nobody can override, and you can have excellent override controls on a system with a measurable disparate impact. Local Law 144 is largely the first kind of duty and Article 14 is entirely the second, which is why one programme cannot discharge both. Our guide to bias free hiring covers the distributional side properly.
Run them as two workstreams with two owners. The audit protects you from treating groups differently, and the oversight design protects you from a system that cannot be questioned.
How to actually do this (and the four traps)
Trap one: buying the two-person rule. Vendors and blog posts will tell you Article 14 requires dual signoff on hiring decisions. It does not, for employment tools. Read 14(5) and note that it points at Annex III point 1(a), then spend the effort on override and stop instead.
Trap two: treating human review as automatically sufficient. The Washington result is the direct rebuttal, and Article 14(4)(b) names the problem by its proper name. Oversight that never disagrees with the model is a rubber stamp with a job title.
Trap three: overseers who cannot explain the tool. Article 14(4)(a) requires the person to understand the system's capacities and limitations. If your recruiters cannot say what the score means or what data produced it, you have not met that clause, and the fix is vendor documentation and training rather than a policy line.
Trap four: scoping only the obvious AI. The hard knockout rules in your ATS narrow pools just as effectively as a model does, and reviewers rarely see the candidates those rules removed. Our note on resume screening with AI covers where those filters usually sit.
"If your review process has never once disagreed with the model, you do not have a control, you have a witness."
The one thing every hiring leader should take from this
Open your screening tool and try to reverse a rejection. Not in theory, not in the policy document: pick a candidate the system screened out this week and try to put them back into the process, then try to turn the tool off. If either takes longer than a few minutes or needs someone outside the recruiting team, you do not currently have human in the loop hiring, whatever your documentation says, and that is the gap Article 14 is written to close. At TheHireHub we think that two-minute test tells you more than any compliance questionnaire, and we look at this stuff all day if you want a second opinion.
Frequently Asked Questions
It means a named person can meaningfully supervise an automated hiring tool while it runs: understanding what it does, interpreting its output correctly, overriding or reversing a result, and stopping the system. Under EU AI Act Article 14 it is a design requirement placed on the system, not just a process promise made by the employer.
Article 14 sits in the high-risk requirements of Chapter III and applies from 2 August 2026, under Article 113. Recruitment and candidate selection are classified as high-risk uses, so screening, ranking and selection tools used on EU candidates fall within scope from that date.
No. The two-person verification duty in Article 14(5) applies to the systems listed in Annex III point 1(a), which covers remote biometric identification. Employment and worker management tools sit in a different part of Annex III, so the dual-verification rule does not attach to standard recruitment screening tools.
Automation bias is the tendency of a human reviewer to over-rely on a machine's output rather than judge independently. Article 14(4)(b) requires that overseers be enabled to stay aware of it, which makes it one of the few cognitive phenomena named directly in the operative text of an EU regulation.
No. Research presented at the AAAI/ACM conference in October 2025 found that reviewers working with a severely biased AI recommendation followed its picks around 90% of the time. Review counts as oversight only when the reviewer can and sometimes does disagree, which requires seeing candidates the system ranked low.
Local Law 144 requires an independent annual bias audit, a public summary of the results, and at least ten business days of notice to candidates before an automated employment decision tool is used. It is retrospective and statistical. Article 14 is about live human control of the system and imposes no audit or notice duty of its own.
The Department of Consumer and Worker Protection can impose civil penalties between $500 and $1,500 per violation per day. Obtaining a bias audit and providing candidate notice are separate requirements, so a single non-compliant tool can generate two concurrent violations.
Functionally yes, because they narrow the candidate pool without human judgement, and reviewers usually never see who was removed. Whether a specific rule meets a given statutory definition depends on the regime and the configuration, so the practical approach is to inventory every rule that filters or ranks and treat it as in scope.
Article 14 assumes a natural person with the competence, training and authority to act on what they see. In practice that is usually a senior recruiter or TA operations lead who can override a result and escalate to switch the system off, rather than a committee or a legal owner with no access to the tool.
Keep records of overrides and reversals, of low-ranked candidates that were reviewed anyway, and of occasions when the tool was paused or disregarded. A log showing that humans regularly agreed with every recommendation is weak evidence of oversight, while a log showing considered disagreement is strong evidence.



