The EU AI Act and Candidate Evaluation: What Every Program Must Know
Using AI to evaluate people, or their projects, is treated as high-risk under the EU AI Act, which means it comes with obligations rather than being simply allowed: human oversight, transparency, traceability, and non-discrimination are expected, not optional. If you run an accelerator, a grant program, or a fund that scores applicants with software, this affects how you are expected to build and operate that process. This is a plain-language guide to what that means in practice, not legal advice.
The instinct when a regulation lands on your category is to treat it as a compliance chore, something the legal team handles after the product decisions are made. That gets it backwards. The obligations the EU AI Act attaches to evaluating people are, almost line for line, the same properties that make an evaluation good: that a human decides, that the reasoning is visible, that the process leaves a record, that the same standard applies to everyone. Building for the regulation and building for quality turn out to be the same work.
This guide covers why evaluating people is treated as high-risk, the four practical obligations that follow, what they mean concretely for a screening process, and why "the human decides" is the design principle that ties them together. It describes principles, not article numbers, and it is not a substitute for advice from a qualified professional.
Why evaluating people is high-risk
The EU AI Act sorts AI systems by the risk they pose, and puts the heaviest obligations on uses that materially affect people's lives and opportunities. Evaluating individuals, or deciding their access to opportunities, sits high on that scale, for a straightforward reason: a decision about who gets funded, admitted, or advanced shapes a person's prospects, and a system that makes or heavily influences such decisions can do real harm if it is opaque, biased, or unaccountable.
This is not a statement about accelerators and grant programs being singled out. It is that any process which uses software to score people or their ventures falls into a category the regulation treats seriously, because the stakes for the person being evaluated are high. The practical upshot is that "we use a tool to help rank applicants" is not a neutral operational detail. It places your process in a space where certain safeguards are expected.
Whether a given program falls squarely inside the strictest tier depends on specifics that a qualified professional should assess for your situation. But the direction is clear enough to design around now: if software touches how you evaluate people, build as though oversight, transparency, traceability, and fairness are required, because the regulation is moving decisively that way.
The four obligations, in practice
Translate the regulatory expectations into operational terms and four obligations stand out. Each is also, not coincidentally, a mark of a serious evaluation.
1. A human decides
The system may assist, rank, and surface, but a person makes the call, and that person must be positioned to actually exercise judgment, not just rubber-stamp a machine output. In practice this means the tool is a co-pilot: it does the first pass, and a human reads, weighs, and decides on the result. A process where the software's ranking is the decision, with no meaningful human step, is the shape the regulation most wants to prevent.
2. Transparency
The people affected, and the people operating the system, should be able to understand how it works and why it produced a given result. For a screening process, that means a candidate's score should be explainable, this is what was weighed, this is the evidence, rather than an unexplained number from a black box. Transparency is not a marketing nicety here, it is an expected property, and a system that cannot explain its own output is a problem well before it is a compliance risk.
3. Traceability
The process should leave a record: what was decided, on what basis, from what evidence, in a form that can be reconstructed later. This is the same discipline that makes a shortlist defensible a year after the fact, when someone asks why a company was passed over. A decision you cannot reconstruct is neither traceable nor defensible, and the regulation and good practice point at the same requirement.
4. Non-discrimination
The same standard should apply to everyone, and the process should not encode or amplify bias against protected groups. Any scoring system encodes choices, so the mitigations are the ones that make scoring honest generally: a fixed basis applied to all, verification against evidence rather than impression, transparency about how each result was reached, and a human in the decision. Fairness is not achieved by declaring the system neutral. It is worked toward through the same properties the other three obligations require.
What this means for your screening process
Put concretely, a screening process built with these obligations in mind looks like this. Every candidate is scored on one basis, decided in advance and applied identically, so the comparison is real and the standard is the same for all. Each material claim is checked against evidence, so the score reflects what is true rather than what was asserted, which is both better evaluation and a defense against deciding on distorted inputs. Every score is explainable and carries its evidence, so it is transparent and traceable. And a human reads the resulting shortlist and makes the decision, so the system assists rather than decides.
Notice that none of this is extra work bolted on for the regulator. It is what a good evaluation already is. The programs that will find the EU AI Act burdensome are the ones relying on opaque, inconsistent, or fully automated scoring, precisely the processes that were producing indefensible decisions anyway. The programs that already screen on a common basis, with claims checked and a human deciding, are most of the way there.
Why "the human decides" ties it together
If there is one principle to build around, it is this: the human decides, and the system is a co-pilot. It is the throughline of all four obligations. It is what makes oversight real rather than nominal. It keeps the accountable party a person, which is what traceability records and transparency explains. And it is the safeguard against a biased or wrong automated output becoming a decision unchallenged.
It is also simply the right design for evaluation, regulation aside. Software is very good at the first pass, extracting claims, checking them, scoring on a consistent basis, ranking, the mechanical work that does not scale by hand. It is not the right thing to hand the final judgment about a person or a venture, which depends on context, values, and stakes a model does not hold. "Co-pilot, not judge" is where the compliant design and the good design meet, and building there means the regulation is describing what you would want to do anyway.
Frequently asked questions
Does the EU AI Act ban using AI to screen applicants? No. It treats evaluating people as high-risk, which means it comes with obligations, human oversight, transparency, traceability, non-discrimination, rather than a prohibition. The point is not to stop AI-assisted screening but to require that a human decides and that the process is explainable and fair.
What is the single most important requirement? Human oversight: a person makes the decision, positioned to actually exercise judgment rather than rubber-stamp a machine output. It is the principle that makes the other obligations real, and it is also the right design for evaluation regardless of regulation.
Does this apply to a small accelerator or grant program? Whether a specific program falls inside the strictest tier depends on specifics a qualified professional should assess. But the safe and sensible course is to build as though oversight, transparency, traceability, and fairness are required, because that is both the regulatory direction and what a defensible process needs anyway.
Is a fully automated scoring tool compliant? A process where the software's ranking is effectively the decision, with no meaningful human step, is the shape the regulation most wants to prevent. A tool that assists and ranks while a human decides is aligned with the expected design. The distinction is whether a person meaningfully makes the call.
Is this article legal advice? No. It describes principles at a plain-language level to help you design a sound process. For how the regulation applies to your specific program, consult a qualified professional.
The bottom line
The EU AI Act treats evaluating people as high-risk, and the obligations it attaches, a human decides, the process is transparent, traceable, and non-discriminatory, are the same properties that make an evaluation good in the first place. Programs that screen on a common basis, with claims checked and a person deciding, are already building the way the regulation points. "Co-pilot, not judge" is where compliance and quality turn out to be the same thing.
How this shows up in Deckwise
Deckwise is built as a co-pilot, which is the posture the EU AI Act expects for evaluating people. It does the first pass, sourcing, checking each material claim against public evidence, and scoring every candidate on one basis, and then hands a human a ranked, explainable shortlist to decide on. Every score carries its evidence and its reasoning, so results are transparent and the process is traceable, and the weighting is versioned so a past decision can be reconstructed. The human always makes the call. Deckwise assists the judgment, it does not replace it.
Related: Manual vs AI Screening · What Is a Defensible Shortlist? · The Deckwise Method
