Bunny Honey ClubBunny Honey/blog
Work with us
← back to indexblog / ai / ai-candidate-screening-eu-high-risk-ai
AI

AI Candidate Screening Just Became High-Risk AI in the EU

Fireflies launched AI voice screening for job candidates on Sept 2, 2026. In the EU that's high-risk AI, and it still can't verify who's calling.

AH
Arthur HofFounder, Bunny Honey Club AI
publishedSep 08, 2026
read6 min
AI Candidate Screening Just Became High-Risk AI in the EU

Fireflies made its name summarizing Zoom calls. On September 2, 2026, it turned that into something that runs the call for you. Voice Agents dials the candidate, asks your screening questions, scores the answers against a rubric you set, an

Fireflies made its name summarizing Zoom calls. On September 2, 2026, it turned that into something that runs the call for you.

Voice Agents dials the candidate, asks your screening questions, scores the answers against a rubric you set, and syncs a transcript straight into your ATS before a recruiter ever picks up the phone. More than 2,100 organizations switched it on inside a few weeks, and Fireflies' own hiring team says it saved over 800 hours screening candidates this way. A third of new hires at marketing agency WebFX started with a Voice Agent call, according to Fireflies' own launch announcement.

That's a genuinely useful product. It's also, if you're hiring for a role based in the EU, a high-risk AI system under a law that just started actively enforcing pieces of itself. And nothing about a voice-only screening call checks whether the person answering it is the person on the resume.

Fireflies just automated the first call in your hiring pipeline

Setup takes three steps: pick or build an agent, define the questions and guardrails, connect a knowledge base of docs and FAQs it can answer from. No scheduling, no dialer software. You share a link, the candidate calls in, and the agent runs the conversation start to finish, then hands your team a scorecard.

40,000+conversations run across Fireflies Voice Agents since its Sept 2, 2026 launch
1 in 4candidate profiles Gartner expects to be fake globally by 2028
Dec 2, 2027when the EU's high-risk AI rules for recruitment tools actually apply
6%of 3,000 surveyed candidates who admitted to interview fraud in a 2025 Gartner poll

It's the recruiting use case that's doing the heaviest lifting in Fireflies' own numbers, and the mechanism matters: the agent only knows what you fed it in a static knowledge base. No live lookup against your open roles, no cross-reference against a background check, no camera. It's a phone screen with better notes, not a hiring decision-maker, and Fireflies is careful to frame it that way. CEO Krish Ramineni put it plainly.

Voice Agents is the next step. Fireflies can now have the conversation for you, then hand your team back exactly what mattered.

Krish Ramineni, CEO, Fireflies.ai

That framing (a pre-qualifying tool that generates a scorecard for a human to review, not a system that rejects anyone on its own) is the right instinct. It also happens to be the exact posture the EU AI Act wants you to already have, whether or not you've read the regulation.

Recruitment AI just landed on the EU's high-risk list

Annex III of the AI Act names the categories of AI the EU treats as high-risk, and employment is one of them by name. The text is specific: systems "intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates" are high-risk, full stop, per the official Annex III text. A second clause covers AI used to manage people once they're hired: task allocation, performance monitoring, promotion and termination decisions.

Screening calls that "evaluate candidates" is not a stretch of that language. It's the plain use case. If your business screens candidates for a role in the EU, or you're an EU business screening anyone at all, a tool that scores and ranks applicants by phone sits inside a regulated category, not a gray area.

That doesn't mean you can't use one. It means a specific set of obligations kicks in before you're supposed to lean on it for real hiring decisions: a documented risk-management process, technical documentation of how the system works, a human genuinely positioned to catch and override a bad call, and a conformity assessment before deployment. We've walked through what that looks like for small businesses more broadly in our EU AI Act guide, and the short version holds here too: most of this was never designed for a five-person shop hiring a part-time driver, but it applies in full to anyone using AI to filter people into or out of a job.

The compliance deadline moved. The disclosure rule didn't

Here's where it gets confusing if you only read the headline. The EU's Digital Omnibus pushed the deadline for standalone high-risk systems, recruitment tools included, from August 2, 2026, to December 2, 2027. That political agreement landed May 7, 2026, and the deferral itself entered into force July 27, 2026, according to the European Commission's own regulatory framework page. Systems in this category get sixteen extra months to get their paperwork in order.

So the honest read for a small business: you have until December 2027 to build the documentation and oversight infrastructure a regulator would ask for. You have zero runway on telling the candidate upfront that a machine is running the interview. Two different clocks, and most coverage of the Omnibus collapses them into one.

None of this is EU-only, either. New York City has required annual, independent bias audits of "automated employment decision tools" (AEDTs) since Local Law 144 took effect in January 2023, defined broadly enough to cover any tool that issues a score or classification used to screen a candidate, exactly what a Voice Agent scorecard is. Employers also have to post a notice in the job listing at least ten business days before using one and give candidates a way to opt out, per the city's own AEDT guidance. If your hiring runs through New York, the EU AI Act's December 2027 deadline was never the deadline that mattered. This one has been enforced since July 2023.

A voice-only screen can't see who's actually calling

Set the EU aside for a second, because the identity problem is bigger than one jurisdiction. A voice agent that scores answers from a phone call has no way to confirm the voice belongs to the applicant it's evaluating. That's not a Fireflies-specific gap; it's true of every voice-based screening tool on the market right now, and it's colliding with a fraud trend that's already real.

We wrote in August about the joint government alert warning that state-backed operatives now use real-time AI deepfakes to pass live video interviews for remote developer roles. A voice-only screen is an easier target than a video call, not a harder one: there's no face to fake, only a voice, and voice cloning from a few seconds of public audio is a solved problem. Gartner's own research puts a number on the broader trend: by 2028, one in four job candidate profiles will be fake worldwide, and in a mid-2025 Gartner survey of 3,000 candidates, 6% admitted outright to interview fraud, posing as someone else or having someone else pose for them.

Automating the first call in your pipeline without adding an identity check doesn't just create a hiring-quality risk. It removes the one moment (a human recruiter's gut check on a live call) that used to catch some of this by accident. Speeding up the funnel and skipping verification is exactly how you end up screening 300 candidates fast and confidently hiring the wrong one.

A compliant screening pipeline is a build, not a toggle

None of this is an argument against automating candidate screening. It's an argument against believing a link-and-template setup is the whole job. A screening pipeline that actually holds up, for a regulator or for your own hiring quality, needs four things a five-minute Fireflies setup doesn't give you out of the box: a document or ID check tied to the interview itself, not a separate step candidates can skip; disclosure language at the start of the call that satisfies Article 50 and any state-level rule that applies to where the candidate sits; a logged audit trail that ties every scored call back to a human who reviewed it before a rejection went out; and routing logic that flags anything unusual (mismatched details, a refusal to verify, an ID that doesn't match the name on file) to a person instead of letting the scorecard speak for itself.

That's genuinely fiddly integration work: your ATS, your identity-verification vendor, your disclosure script, and your review workflow all need to talk to each other correctly, not just exist as four separate tools. It's exactly the kind of pipeline we build for clients who want the speed of AI screening without inheriting the two risks that come free with a bare-bones setup: a compliance gap and a fraud gap, stacked on top of each other.

— share
— keep reading

Three more from the log.