Advertisement
Advertisement
SendPulse

The AI Reading Your CV Is Now High-Risk by Law

By Networks Journal Correspondence Team · 25 August 2026

Sopra Steria built an AI tool to screen CVs and moved it onto European, GPU-backed infrastructure for security and compliance. Under the EU AI Act, CV-screening AI is classified high-risk alongside critical infrastructure, and the UK’s ICO is already auditing recruitment AI tools.

Advertisement
Advertisement

Key Takeaways

  • Sopra Steria, a major European IT consulting group, built an AI system for CV and document analysis and moved the workload onto GPU-equipped dedicated servers from OVHcloud, choosing a European infrastructure provider specifically for compute power, data security and EU regulatory compliance, the criteria the case study itself names.
  • That choice matters more than it would for most AI use cases. Under the EU AI Act, AI systems used to analyse and filter job applications and evaluate candidates are explicitly classified as high-risk, under Annex III, point 4(a), the same category as AI used in critical infrastructure, not because Sopra Steria’s specific tool has been found to fail but because CV screening AI as a category is treated as high-stakes by design.
  • The compliance clock on that classification has just moved. The original 2 August 2026 deadline for Annex III high-risk obligations was postponed to 2 December 2027 by the EU’s Digital Omnibus on AI, which entered into force on 27 July 2026, giving organisations building or buying CV screening AI substantially more runway than they had a few months ago, though a grandfathering rule means systems already on the market before the new deadline can avoid the fuller regime unless substantially modified afterward.
  • The risk this regulation targets is not hypothetical. Amazon’s internal CV screening tool, built from 2014 and scrapped by 2017, before reporting on it became public in 2018, taught itself to downgrade resumes containing the word “women’s” because it was trained on ten years of submissions skewed male by the tech industry’s own hiring history, a documented case of exactly the kind of proxy discrimination the EU AI Act’s high-risk category and the UK’s Equality Act 2010 are both designed to catch.
  • The UK’s Information Commissioner’s Office has already acted in this specific area, not hypothetically: a 2024 audit of AI recruitment tool providers produced close to 300 recommendations, and the ICO published a report and draft guidance on automated decision-making in recruitment on 31 March 2026, opening a public consultation. Sopra Steria’s emphasis on EU-hosted, regulation-compliant infrastructure sits squarely inside the same regulatory conversation UK employers are now being asked to answer.

Sopra Steria’s AI tool for CV and document analysis isn’t the kind of case study built around a headline percentage. There’s no accuracy figure, no time saved, no cost cut. What the case study is actually about is infrastructure, GPU-equipped dedicated servers, a private network, EU data residency, chosen for compute power, security and regulatory compliance, the specific criteria the company itself cites, though the case study doesn’t address cost or speed-to-market tradeoffs. For a UK C-suite, that’s arguably the more useful story to read carefully, because CV screening is one of the small number of AI use cases regulators have already decided deserves the highest level of scrutiny, and Sopra Steria’s infrastructure choices, as described in its own case study, read as a direct response to that reality rather than an afterthought.

What Sopra Steria actually built

Sopra Steria specialises in consulting, digital services and software development, and has developed a solution for CV and document analysis using advanced artificial intelligence algorithms. To ensure adequate computing power and security, the company expanded its infrastructure and migrated its analysis workloads to dedicated cloud servers, gaining the reliability and scalability needed for further development. Sopra Steria’s document analysis solution required exceptionally high computing power to process files quickly, accurately and at quality, while ensuring data security and confidentiality in line with European regulations. The company needed a trusted European technology partner able to guarantee performance, scalability and full regulatory compliance.

Sopra Steria implemented a cloud solution built on dedicated servers with infrastructure optimised for data processing and AI, with GPU-equipped machines central to its success, enabling fast, accurate file processing and AI algorithm execution. An architecture built around a private network ensures all data is processed in a secure environment compliant with European regulations, letting Sopra Steria flexibly scale resources according to current business needs and application load. “Our AI solution requires enormous computing power. Thanks to dedicated OVHcloud machines with efficient GPUs, we can analyse documents faster, more accurately, and on a larger scale, which directly translates into the quality and efficiency of our service. By choosing OVHcloud, we gained the assurance that the data used in the analysis process is protected in accordance with European regulations. Collaboration with a trusted, local infrastructure provider gives us the security and stability on which we can build the long-term development of our AI solutions,” said Miłosz Niczyporuk, Technical Director Application Service at Sopra Steria Poland.

The reason GPUs specifically matter here is straightforward: neural network models, including the kind used for document and CV analysis, run on the same underlying matrix and vector computation that GPUs were originally built to accelerate for graphics rendering, and their thousands of parallel cores handle that workload far faster than a CPU’s much smaller number of sequential cores. That’s general technical grounding for the “enormous computing power” claim in the quote rather than something unique to CV analysis specifically, but it explains why the infrastructure choice, not just the AI model itself, was treated as central to the project’s success.

Why CV screening AI sits in its own regulatory category

Under the EU AI Act, AI systems intended for the recruitment or selection of natural persons, specifically including systems used to analyse and filter job applications and evaluate candidates, are classified as high-risk under Annex III, a category that also includes AI used in critical infrastructure. That classification brings a defined set of obligations: a risk management system, data governance and quality requirements, technical documentation, record-keeping, human oversight, and a conformity assessment before the system can be placed on the market. It’s worth being precise about what that classification does and doesn’t say: it doesn’t mean CV screening AI is presumed unsafe, only that the category is treated, by design, as high-stakes enough to require this level of scrutiny before deployment, regardless of how well any individual tool actually performs.

That compliance timeline recently moved, and it’s worth UK and EU employers knowing the current date rather than the one still circulating in older commentary. The original deadline for Annex III high-risk obligations was 2 August 2026. The EU’s Digital Omnibus on AI, which reached political agreement in May 2026 and entered into force on 27 July 2026, postponed that deadline to 2 December 2027, giving organisations substantially more time to prepare. A grandfathering provision means systems already placed on the market before the new deadline can avoid the fuller high-risk regime unless they’re substantially modified afterward. Other parts of the AI Act weren’t touched by this postponement, including the prohibited-practices rules that have applied since February 2025 and transparency obligations around AI-generated content, so the change is specific to the high-risk compliance clock rather than a general loosening of the Act.

The risk the regulation is actually responding to

The category exists because of a documented, specific problem, not a theoretical one. Amazon built an internal CV screening tool from around 2014, designed to rate candidates on a one-to-five star scale, trained on roughly a decade of CVs submitted to the company. Because the tech industry’s hiring history over that period skewed heavily male, the model taught itself that male-associated resumes were preferable, and it downgraded CVs that included the phrase “women’s,” as in “women’s chess club captain,” along with graduates of two all-women’s colleges. Amazon edited the tool to neutralise those specific terms, but lost confidence that other, less obvious proxies for gender weren’t still influencing its scoring, and scrapped the project by 2017, before reporting on it became public in 2018. The tool was reportedly never used as a sole decision-maker, recruiters had only limited use of its recommendations before it was shut down, but the case remains one of the clearest documented examples of a hiring AI learning discrimination from its own training data rather than from any explicit instruction to discriminate.

The UK has its own active version of this conversation. The Equality Act 2010 applies to automated hiring decisions exactly as it applies to human ones, an employer can’t avoid liability for indirect discrimination simply because a decision was delegated to an algorithm; if a tool’s outputs disproportionately disadvantage people with a protected characteristic without objective justification, that remains unlawful regardless of automation. The Information Commissioner’s Office, whose remit covers data protection rather than equalities law directly, ran a 2024 audit of AI recruitment tool providers that produced close to 300 recommendations, and found that some tools were filtering applications in ways that tracked protected characteristics, while some employers reportedly believed the AI was merely supporting a human decision when in practice it was making the decision outright. The ICO followed that audit with a report and draft guidance on automated decision-making in recruitment, published 31 March 2026, opening a public consultation on the subject.

Why the infrastructure choice reads as the right instinct

Set against that backdrop, Sopra Steria’s emphasis on a European-based, GDPR-aligned infrastructure partner isn’t incidental positioning, it’s a defensible response to a regulatory environment that specifically singles out this use case. OVHcloud, the provider Sopra Steria chose, is a French company that positions itself as a European alternative to the US hyperscalers, built around full ownership of its own data centres and hardware supply chain rather than reselling capacity from elsewhere; by its own disclosed figures it operates 44 owned data centres and serves customers across roughly 140 countries. None of that guarantees Sopra Steria’s specific CV analysis model is free of the kind of bias that undid Amazon’s tool, infrastructure choices address data security and residency, not model training bias, which is a separate and equally important discipline the case study doesn’t describe. But choosing infrastructure that keeps data inside a compliant, auditable European environment is a genuinely sound precondition for meeting the EU AI Act’s human oversight and data governance requirements later, rather than a step that can be retrofitted easily once a system is already built and deployed on infrastructure that wasn’t designed with those requirements in mind.

What a UK C-suite should take from this

The lesson isn’t that CV screening AI is inherently unsafe, Sopra Steria’s case study describes a company solving a real, high-volume document processing problem with real engineering care around security and compliance. The lesson is that this specific category of AI carries regulatory obligations most other AI use cases don’t, and that those obligations, human oversight, data governance, technical documentation, conformity assessment, are easier to build in from the infrastructure layer up than to bolt on afterward. With the EU’s high-risk compliance deadline now pushed to December 2027 and the UK’s ICO actively consulting on automated recruitment decisions in the meantime, any UK organisation building or buying a CV screening tool has a genuine window to get the infrastructure and governance foundations right before the obligations become mandatory, rather than after.

Join the CEOs, CIOs, CTOs and CISOs who rely on our insights.

Stay up to date with emerging threats, network infrastructure strategy, compliance and the latest tools.