Estonian SME Regulatory Preparedness for AI-driven Recruitment Under the EU AI Act Estonian
Baloch, Ali Bilal (2026)
Baloch, Ali Bilal
2026
Master's Programme in Sustainable Societies and Digitalisation
Informaatioteknologian ja viestinnän tiedekunta - Faculty of Information Technology and Communication Sciences
Hyväksymispäivämäärä
2026-06-29
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:tuni-202606267974
https://urn.fi/URN:NBN:fi:tuni-202606267974
Tiivistelmä
Estonian SMEs face a major challenge in complying with the EU AI Act, particularly with automated recruitment systems. The legislation classifies these tools as high-risk and imposes significant responsibilities on the organizations that operate them, known as "Deployers." This study explores how Estonian SMEs are preparing for these requirements, with particular attention to Article 14 on human oversight and Article 26 on the deployer's duties.
The investigation centers on the rift between legal mandates and the practical constraints of small businesses. Most SMEs do not develop their own software; instead, they depend on third-party platforms. This reliance creates information asymmetry, where vendors treat their algorithms as trade secrets, leaving HR practitioners unable to verify whether the tools they use are fair or biased. The empirical data suggests that without internal technical teams, these firms may face a practical risk of falling into 'symbolic compliance, satisfying the law through surface-level policy changes without understanding or controlling the technology.
To explore these dynamics, the study used a qualitative approach, including semi-structured interviews with HR professionals and a documentary analysis of vendor terms and legal texts. The findings highlight a "capability gap," where the administrative and technical burden of compliance exceeds the resources available to Estonian SMEs. Many participants reported a heavy reliance on external consultants and vendors to interpret the law, further deepening their dependency.
The thesis contributes a practical preparedness framework tailored to the needs of SMEs. This framework offers strategies for managing vendor relationships and implementing realistic human oversight, helping organizations move from surface-level adherence toward accountability. By addressing the specific vulnerabilities of small firms, the research provides a roadmap for navigating the transitional period of the EU AI Act.
The investigation centers on the rift between legal mandates and the practical constraints of small businesses. Most SMEs do not develop their own software; instead, they depend on third-party platforms. This reliance creates information asymmetry, where vendors treat their algorithms as trade secrets, leaving HR practitioners unable to verify whether the tools they use are fair or biased. The empirical data suggests that without internal technical teams, these firms may face a practical risk of falling into 'symbolic compliance, satisfying the law through surface-level policy changes without understanding or controlling the technology.
To explore these dynamics, the study used a qualitative approach, including semi-structured interviews with HR professionals and a documentary analysis of vendor terms and legal texts. The findings highlight a "capability gap," where the administrative and technical burden of compliance exceeds the resources available to Estonian SMEs. Many participants reported a heavy reliance on external consultants and vendors to interpret the law, further deepening their dependency.
The thesis contributes a practical preparedness framework tailored to the needs of SMEs. This framework offers strategies for managing vendor relationships and implementing realistic human oversight, helping organizations move from surface-level adherence toward accountability. By addressing the specific vulnerabilities of small firms, the research provides a roadmap for navigating the transitional period of the EU AI Act.