EU AI Act Transparency & Responsible AI
Last updated: 9 August 2026
Progress Lane Recruitment Agency Ltd ("Progress Lane", "we") operates internationally, including with candidates and clients in the European Union. This statement explains how we use artificial intelligence in our recruitment services and how we meet our obligations under Regulation (EU) 2024/1689 (the "EU AI Act"), alongside the UK GDPR and EU GDPR.
It should be read together with our Privacy Policy, Data Protection Policy and Equal Opportunities & Diversity Policy.
1. Our position under the EU AI Act
Annex III of the EU AI Act classifies AI systems used for the recruitment or selection of people - in particular to place targeted job advertisements, analyse and filter applications, or evaluate candidates - as high-risk. We take the position that any AI used to screen, rank, score or shortlist candidates falls within that category, and we apply the controls in this statement accordingly.
Where we use an AI system supplied by a third party, we act as a deployerunder the Act. We do not develop, train or place our own AI systems on the market, so we do not act as a provider. If that ever changes, this statement will be updated before any such system is used in a live process.
2. Where AI is - and is not - used
AI may be used to assist with:
- Searching and de-duplicating our candidate database and public professional profiles.
- Summarising CVs, notes and job specifications into a consistent internal format.
- Drafting job advertisements, outreach messages and interview questions for human review.
- Suggesting - never deciding - which candidates a consultant should look at first.
AI is not used to:
- Automatically reject, deselect or rank out a candidate without a human decision.
- Infer emotions, personality traits or psychological state from video, voice or images (an prohibited practice in the workplace and recruitment context under Article 5 of the Act).
- Perform biometric categorisation, facial analysis or emotion recognition of any kind.
- Score candidates on protected characteristics or any proxy for them.
- Carry out social scoring or predictive profiling of individuals.
No solely automated decisions. Every shortlist, rejection and client submission is made by a named human consultant. There is no automated decision-making producing legal or similarly significant effects within the meaning of Article 22 UK/EU GDPR.
3. Human oversight (Article 14 / Article 26)
- AI outputs are advisory only and are always reviewed by a competent consultant before use.
- Consultants who use AI tools receive AI-literacy training covering capabilities, limits, automation bias and when to disregard an output (Article 4).
- Any consultant can override, correct or ignore an AI suggestion, and is accountable for the decision made.
- Named senior accountability sits with our Data Protection Officer and the board.
4. Transparency to candidates and clients
- Candidates are informed, before or at the point of engagement, where AI assists in the process.
- Any AI-generated or AI-assisted content sent to candidates or clients is reviewed by a human and is clearly identifiable as such on request.
- Where we deploy a high-risk AI system in relation to workers or candidates, we will inform the affected people (and, where required, their representatives) before it is put into use.
- AI chat or assistant interfaces on our website, if used, disclose that you are interacting with a machine (Article 50).
5. Fairness, bias and testing
- We assess the relevance and representativeness of the input data we feed into AI tools (Article 26(4)).
- Shortlists are reviewed for adverse impact against protected characteristics; anomalies are investigated and documented.
- We prefer suppliers who can evidence CE marking, EU declaration of conformity, technical documentation, bias testing and registration in the EU database for high-risk systems.
- Supplier AI tools are subject to due diligence before use and reviewed at least annually.
6. Data protection and fundamental rights
- A Data Protection Impact Assessment (DPIA) and, where applicable, a Fundamental Rights Impact Assessment (Article 27) are completed before deploying a high-risk AI system.
- Personal data used with AI tools is minimised, purpose-limited and retained per our published retention schedule.
- We do not permit candidate data to be used to train third-party foundation models; supplier contracts must exclude training on our inputs.
- Transfers outside the UK/EEA rely on adequacy decisions or Standard Contractual Clauses with supplementary measures.
7. Logging, records and monitoring
- We keep records of which AI tools are used, for what purpose, and by whom.
- Automatically generated logs from high-risk systems within our control are retained for at least six months, or longer where law requires (Article 26(6)).
- Serious incidents or malfunctions are reported to the provider and, where required, to the relevant market surveillance authority without undue delay.
8. Your rights
If you are a candidate, you have the right to:
- Be told whether AI was used in relation to your application, and how.
- Request a clear explanation of the role an AI output played in a decision that affects you (Article 86).
- Request human review of any outcome you believe was influenced by an AI tool.
- Object to AI-assisted processing, and to have your data corrected or erased, under UK/EU GDPR.
- Lodge a complaint with us, with your national market surveillance authority, or with your data protection regulator (in the UK, the Information Commissioner's Office).
Exercising these rights is free and will never disadvantage your application. Use our Complaints Procedure if you are not satisfied with our response.
9. This website
Our website does not profile visitors with AI, does not use biometric or emotion-recognition technology, and does not make automated decisions about you. Analytics and marketing cookies are optional and controlled through our Cookie Policy and the cookie preference centre.
10. Governance and review
This statement is owned by the board and reviewed at least annually, and whenever we adopt a new AI tool or the regulatory position changes. Phased EU AI Act obligations - including the prohibitions and AI-literacy duties applicable from 2 February 2025, general-purpose AI rules from 2 August 2025, and high-risk obligations phasing in from 2 August 2026 - are tracked in our compliance register.
11. Contact
- AI governance & compliance: legal@progresslane.co
- Data Protection Officer: dpo@progresslane.co
- Privacy requests: privacy@progresslane.co