The use of artificial intelligence systems and algorithmic tools in the recruitment and management of personnel is already giving rise to specific legal obligations for companies in Spain. In 2026, this regulatory framework has become particularly significant due to the convergence of three developments: the application of the European Artificial Intelligence Regulation (the AI Act), a recent action by the Spanish Data Protection Agency (AEPD) specifically addressing the use of AI in recruitment processes, and the adoption of Royal Decree 723/2026, which introduces new requirements regarding the use of algorithmic systems in employment relationships.
The latter development partially implements Directive (EU) 2019/1152 on transparent and predictable working conditions. However, the Spanish legislator has introduced a specific obligation requiring employers to inform employees of the existence of algorithmic or automated decision-making systems. The Royal Decree itself expressly links this innovation to the AI Act, thereby creating a direct point of connection between Spanish employment law and the new European regulatory framework for artificial intelligence.
From candidate to worker: a new obligation of algorithmic transparency
The Royal Decree 723/2026, of 9 September, which entered into force on 5 October 2026, introduces a novel obligation to inform employees, in writing, of the existence of algorithmic or automated decision-making systems and, where such systems are used to make certain employment-related decisions, to provide information regarding the guidelines, criteria and operating rules governing those systems.
This requirement has an immediate practical impact on businesses, namely the need to review their employment contracts and the information documents provided to employees upon joining the organisation. The Royal Decree does not require all of this information to be included in the employment contract itself and expressly allows it to be provided through one or more separate written documents where it is not incorporated into the contract. However, it does require that employees receive the information prescribed in Article 3 (prior to the commencement of the employment relationship) in paper or electronic form that is accessible, storable and printable, and material changes must be notified as soon as possible and, at the latest, on the day it takes effect. Furthermore, the AEPD Note of 7 October 2026 on Algorithmic Systems in the Workplace: Transparency and Data Protection Safeguards and algorithmic transparency obligations, following Royal Decree 723/2026, reiterates that, for employment relationships already in force, employees may request the information from the entry into force of the Royal Decree, and the employer has 30 working days to provide it. The algorithmic information under Article 3.2(k) cannot be satisfied by referencing the law or the collective agreement; it must be provided in specific terms.
Accordingly, organisations using algorithmic systems within the scope of the Royal Decree must update their contractual and onboarding documentation and maintain evidence that the information has been duly provided. This is distinct from the information owed to job applicants, whose transparency rights stem primarily from data protection legislation, in particular the GDPR rules on profiling and automated decision-making.
The Royal Decree thus strengthens the individual dimension of algorithmic transparency: beyond the information rights of employee representatives under the Spanish Workers’ Statute, employees themselves are entitled to know of the existence and essential operating features of algorithmic systems that may affect significant aspects of their employment relationship.
The selection of personnel in the age of AI: the AEPD sets criteria
The AEPD's Warning AI-00009-2026, (2026) addresses the screening and assessment of job candidates. The AEPD does not consider the use of AI in recruitment unlawful, but places data protection by design and by default at the centre of its analysis: safeguards must be assessed from the earliest stages of the tool's lifecycle (design, evaluation, selection, configuration and deployment), not added once the system is operational.
Companies must therefore ensure: (i) meaningful human oversight; (ii) a prior risk assessment before deployment and, where a high risk to rights and freedoms is likely, a Data Protection Impact Assessment (DPIA); (iii) clear, accessible and understandable information to candidates on the processing, its purposes and the role of the AI tool; and (iv) recognition that corporate responsibility is assumed before the algorithm is put into operation.
The warning is preventative in nature (Article 58.2(a) GDPR); it neither declares an infringement nor imposes a sanction, but shifts to the controller the burden of assessing, adapting and demonstrating compliance. The formal presence of a reviewer does not exclude Article 22 GDPR; the reviewer must be able to assess the score critically and depart from it, and the CJEU has held that an automated score may itself constitute an automated decision where the decision-maker relies heavily on it. Scores, profiles and inferences may also be personal data, and a claim that a tool does not use sensitive attributes is insufficient unless it is verified that other variables do not act as proxies for them.
Prior screening of third-party systems & providers
Outsourcing an AI tool does not transfer the responsibilities of the company deploying it, which must document its role (controller, joint controller or user of a processor’s service), the contractual safeguards, data location and any international transfers. Before deployment, the company should screen the system and the provider to determine whether the tool falls within the scope of the AI Act, its classification and each party’s regulatory role, obtaining sufficient information on the system’s purpose, operation, data, capabilities and limitations, human involvement and safeguards. This screening also informs the obligations under employment and data protection laws, even where the AI Act does not apply. Moreover, the AEPD Note highlights that references to periodic audits do not themselves prove compliance; audits should record their scope, the system version tested, error rates, differential impacts and corrective measures.
The contract with the provider should then be reviewed to include obligations on information sharing, documentation, cooperation, oversight and any other safeguards the company needs to meet its legal obligations.
Regulations that complement each other
The most interesting question arises when we put this new employment obligation in relation to the GDPR and the AI Act. They are not three alternative regimes; in fact, they are rules that operate from perspectives that, although different, are cumulative.
- The GDPR regulates the processing of personal data; therefore, it is applicable in the event that an AI system uses information about workers or candidates, regardless of whether the technology is considered high risk under the AI Act. From this derive, among others, the obligations relating to lawfulness, transparency, minimisation, data protection by design, impact assessments and automated decisions.
- Labour law, on the other hand, introduces guarantees specifically linked to the relationship between the company and the worker. As mentioned above, Royal Decree 723/2026 has made it mandatory to report individually on certain algorithmic systems involved in labour decisions. In addition, there is the collective right to information provided in the Workers' Statute.
- The AI Act establishes specific obligations for certain AI systems in view of the risk they generate. Annex III.4 includes those systems intended for hiring or selecting personnel and certain systems used to adopt decisions that affect working conditions, among the systems potentially considered to be high-risk.
It is important, however, to distinguish between the respective scopes of application, as not every algorithmic system subject to the new labour-related obligations will necessarily fall within the category of high-risk AI systems under the AI Act. Royal Decree 723/2026 adopts a broad concept of “algorithmic or automated decision-making systems” and requires employers to provide information regarding a number of specified matters. However, for the specific high-risk regime under the AI Act to apply, the relevant tool must first qualify as an “AI system” within the meaning of the Regulation and must fall within one of the exhaustively listed use cases set out in Annex III.4. Certain exceptions may apply where the system does not materially influence the outcome of a decision, although such exceptions do not apply when the system performs profiling of natural persons.
Accordingly, there may be situations in which labour-law transparency obligations, GDPR requirements and obligations imposed by the AI Act apply concurrently. However, there may also be cases where an automated system is subject to the labour transparency requirements introduced by RD 723/2026 and, where personal data is processed, to the applicable data protection framework, without being subject to the high-risk regime under the AI Act.
There is a relevant temporal particularity here. Although the general date of application of the AI Act was 2 August 2026, certain obligations relating to high-risk systems will be applicable from 2 December 2027. This postponement does not create any legal loophole; rather, a company that currently uses AI in Human Resources is already subject to the GDPR and Spanish labour law. Precisely, the AEPD's recent warning stresses that the authorities can, and do, intervene even before the effective implementation of a tool when the planned processing may be in breach of data protection regulations.
Towards an integrated governance of AI in human resources
The convergence of the GDPR, employment law and the AI Act requires organisations to move from a fragmented analysis of each framework to comprehensive governance of algorithmic systems used in Human Resources. In practical terms, organisations should begin by:
- Identifying and maintaining an inventory of algorithmic systems used in the employment context, including tools deployed during recruitment processes and those used in the management of the employment relationship, determining the decisions they influence, and the degree of automation involved. In doing so, each tool should be assessed and classified from a legal perspective, avoiding the assumption that every algorithm necessarily constitutes a high-risk AI system. Instead, a separate analysis should be undertaken to determine whether Royal Decree 723/2026 applies, whether the processing of personal data triggers obligations under the GDPR, and whether the system falls within the scope of the AI Act.
- Prior screening of technology providers and third-party systems, as described above, to determine the applicable framework, classification and roles of the parties, and reflecting the findings in the provider contract through the necessary information, safeguards and commitments.
- Updating employment contracts and employment-related documentation to comply with the new information obligations introduced by RD 723/2026. Employers should determine which algorithmic systems fall within the scope of the norm and ensure that employees receive the required information regarding their existence and, if applicable, operating parameters, criteria and decision-making rules.
- Reviewing the information provided to candidates. Where AI is used in recruitment processes, organisations should assess privacy notices and related documentation, verify compliance with the GDPR transparency requirements, and implement any additional safeguards required in cases involving automated decision-making.
- Reviewing recruitment processes that incorporate AI, particularly in light of the AEPD's Warning AI-00009-2026. This includes examining, from the pre-deployment stage onwards, the legal basis for processing, the data used, any profiling or automated decision-making activities, potential discrimination risks, and the need to conduct a Data Protection Impact Assessment (DPIA).
- Ensuring meaningful and effective human oversight where required. The mere formal involvement of an individual tasked with validating the output of an algorithm should not amount to automatic endorsement. Such individual should have sufficient information, expertise and genuine authority to challenge, review or modify the outcome generated by the system; and discrepancies with the automated recommendation should be recorded, since a systematic absence of discrepancies may indicate de facto reliance on the score (AEPD Note).
- Coordinating individual and collective transparency obligations in accordance with RD 723/2026 and the Spanish Workers' Statute.
- Preparing for the obligations applicable to high-risk AI systems under the AI Act, notwithstanding that certain requirements applicable to such systems have been deferred until 2027.
The result is a significant shift in the compliance paradigm. It is no longer sufficient to ask whether an organisation uses AI; rather, it is necessary to determine the purposes for which it is used, the decisions it influences, and the legal framework applicable in each specific case. Not all systems will simultaneously trigger obligations under employment law, the GDPR and the high-risk AI regime established by the AI Act; and precisely for that reason, the first step towards effective governance is to identify and accurately classify each tool. As the AEPD notes, informing employees does not in itself legitimise the processing; the processing must also be lawful, necessary, proportionate and subject to oversight.