TalenIA — EU AI Act and Spanish AI Law

Last updated: July 2026 · Version 1.2

What risk category does TalenIA fall under the EU AI Act?

The EU AI Regulation (Regulation 2024/1689) classifies AI systems into four risk levels. Systems used for recruitment and personnel selection fall under Annex III as high-risk systems.

TalenIA falls into this category. We believe being transparent about it is the right stance, and that the correct response is not to avoid the classification but to design the product to meet its principles from day one.

The Annex III high-risk obligations, initially due on 2 August 2026, have been postponed to 2 December 2027 by the "Digital Omnibus" legislative package, approved by the Council of the EU on 29 June 2026 (pending formal publication in the EU Official Journal). Regardless of this extension, TalenIA already meets the key principles voluntarily and has started the registration process in the European Commission's AI Office public database, under Article 71 of the Regulation.

Built for high-risk from day one

1

Human oversight guaranteed by design

TalenIA never hires or rejects anyone. Its role is to organise and synthesise the information in the CVs so the recruiter has a clearer picture before starting the human process. The recruiter sees the reasoning behind every score, can disregard it and makes the final decision. No automated action affecting a candidate takes place without human intervention. This mechanism is documented internally under Article 14 of the AI Act.

2

Transparency towards candidates

When a recruiter closes a hiring process, TalenIA offers the option to send an email to candidates who were not selected. The default template states that an AI-based support system was used during the evaluation. The recruiter can customise or skip the email, transparency is the default.

3

No protected data in the scoring

TalenIA's scoring system relies exclusively on declared professional experience, education and fit for the role. We do not use, infer or process data from the protected categories under Article 9 GDPR: ethnic or racial origin, gender, age, health status, religion, sexual orientation or other special categories.

4

Explainability of every evaluation

Every candidate receives a text justification generated by the AI model, not an opaque number. The recruiter can read the analysis, challenge it and combine it with their own judgment. This explainable AI (XAI) architecture supports internal audits and fulfils the EU AI Act's transparency principle.

The Spanish AI Law (26 May 2026)

On 26 May 2026, the Council of Ministers approved the Draft Organic Law on the Good Use and Governance of Artificial Intelligence, currently going through parliamentary procedure, with final approval expected before December 2027. This law implements the EU AI Act's sanctioning regime into Spanish law and adds national specifics.

National supervisory authority: AESIA

The Spanish Agency for the Supervision of Artificial Intelligence (AESIA), based in A Coruña, is the competent body for supervising compliance with the EU AI Act and the Spanish law nationally, investigating incidents and, where applicable, imposing sanctions.

As a high-risk system (Annex III), TalenIA is subject to fines of up to €15 million or 3% of worldwide turnover for serious breaches, and up to €35 million or 7% for prohibited practices. TalenIA takes a proactive compliance stance, it does not wait for the national law to enter into force to apply its principles.

The Spanish law's specifics include an explicit ban on non-consensual sexual deepfakes and reinforced protection for minors and vulnerable groups against AI systems that exploit their vulnerabilities. TalenIA does not operate in either of these areas.

What does this mean for candidates?

  • You'll know if AI was used: the recruiter can send you a closing email that states this. If you don't receive one, you can request it directly from the employer.
  • Your CV is not stored in an identifiable form: TalenIA pseudonymises names before processing them. The recruiter sees an initials code, not your real name, during the evaluation phase.
  • No automated decisions are made about you: every action that affects you (advancing, rejecting, inviting to interview) is decided by a person.
  • Right to an explanation (Art. 86 AI Act): if you were evaluated with TalenIA, you have the right to request an explanation of the results generated by the system and to ask for the decision to be reviewed by a person. To exercise this right, contact the company that ran the hiring process directly, or write to us at [email protected] stating the company name and the role.
  • Your data is deleted: the CV text and identifying data are irreversibly purged once the archive period elapses (maximum 60 days after the process is closed or expires). Only numeric scores without direct identifiers are kept.

If you're a TalenIA client: your obligations as a deployer

By using TalenIA to run hiring processes, your company acts as a deployer of a high-risk AI system within the meaning of the EU AI Act. This carries obligations of your own that TalenIA cannot fulfil on your behalf:

  • AI literacy training (Art. 4, already in force since August 2025): you must ensure that staff using TalenIA have an adequate level of understanding of how AI systems work, their risks and their limitations. This obligation is enforceable now and must be documented.
  • Effective human oversight: you must ensure that the people making hiring decisions understand TalenIA's scores as guidance, not a definitive criterion, and are trained to disregard or challenge them.
  • Transparency towards candidates: you must inform candidates that an AI system was used in their evaluation. TalenIA makes this easier through the closing email templates. Using them is recommended.
  • Legal basis for data processing: you are responsible for processing your candidates' data (Art. 28 GDPR). See our Data Processing Agreement (DPA) for details.
  • AI system inventory: TalenIA must appear in your internal inventory of high-risk AI systems, classified under Annex III, personnel selection.

TalenIA makes the system's technical documentation available to clients and can assist with the Fundamental Rights Impact Assessment (FRIA) required for high-risk systems. Write to us at [email protected].

GDPR and data protection

TalenIA processes candidates' personal data solely for the stated purpose: assessing suitability for a specific role. The legal basis is the employer's legitimate interest in the context of an active hiring process.

For more information on data processing, see our Privacy Policy.

Public system card

For companies running due diligence, DPOs assessing TalenIA's use, or anyone who wants to understand the system's technical workings in detail:

Questions about regulatory compliance

If you're an organisation assessing TalenIA for internal use and need additional compliance information (FRIA, technical system documentation, signed DPA, coordination with your DPO), write to us at [email protected]. You can also raise queries with the AESIA (aesia.gob.es) as the national supervisory authority.