If you have been tracking the EU AI Act, you will have a date in your diary: 2 August 2026, the point at which obligations for high-risk AI systems were due to apply. AI used in recruitment sits squarely in that category. That date has now moved, and the way it moved matters — because a deferral is not a cancellation, and several parts of the Act that already bind you were never deferred at all.
This is an explainer for agency operators rather than lawyers, and it is not legal advice. If you deploy AI in hiring decisions affecting people in the EU, take advice on your specific setup. What follows is the shape of the thing, so you know which questions to ask.
Why recruitment is classified as high-risk
The Act sorts AI systems by risk rather than by technology. A small number of practices are banned outright; a defined set are high-risk and carry substantial obligations; most everyday systems carry only light transparency duties.
Employment is on the high-risk list — Annex III — and the scope is broad. It covers AI used for recruitment and selection, for filtering applications and evaluating candidates, and beyond hiring, for task allocation, performance evaluation, monitoring, promotion, and termination. In practice, if software helps decide who gets shortlisted, interviewed, or hired, assume it is in scope until someone qualified tells you otherwise.
The reasoning is not that recruitment AI is uniquely dangerous. It is that hiring decisions materially affect people's livelihoods, the person affected usually has no visibility into how the decision was made, and errors compound quietly across thousands of applicants.
What changed in May 2026
On 6 May 2026 the Council and the European Parliament reached provisional political agreement on the package known as the Digital Omnibus, confirmed by Member State representatives on 13 May. Under the agreed text, standalone Annex III systems — the category that covers recruitment — move from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moves to 2 August 2028.
At the time of writing the agreement is provisional; formal adoption and publication in the Official Journal are expected ahead of the original August 2026 date. The stated reason for the delay is practical rather than political: national competent authorities have not all been designated, and the harmonised standards that providers need in order to demonstrate conformity are not finished. Regulators concluded that a deadline nobody could comply with was worse than a later one that people could.
Two things follow. First, you have roughly eighteen months more than you thought on the high-risk chapter. Second — and this is the part that gets missed — the deferral applies to that chapter specifically. Other obligations either are already in force or arrive this August as originally planned.
What is already binding, and what still lands in August
Three sets of duties are unaffected by the deferral. Two are live now; one arrives on the date everyone had in their diary for a different reason.
- The prohibited-practices ban — in force since February 2025. The provision most relevant to hiring is the prohibition on AI that infers emotions in the workplace or in education. This is an outright ban, not a risk-managed permission — it covers emotion-recognition or sentiment-inference features applied to candidates and employees, including in video interviews.
- The AI literacy duty — in force since February 2025. Organisations must ensure staff who use AI systems, or whose work is affected by them, have adequate training. It is a light-touch obligation, but it is a real one, and it expects you to be able to show what training was given and to whom.
- Article 50 transparency — applies from 2 August 2026, not deferred. Where a person interacts with an AI system, or is shown AI-generated content, that has to be disclosed. For agencies this is the near-term item: chatbots and AI-assisted candidate messaging are in scope, and the date did not move with everything else.
That third point is the one most likely to be missed, precisely because the headline story was a delay. The August 2026 date is still live for transparency; it is only the high-risk obligations that moved to December 2027.
The emotion-recognition ban also deserves a specific check. Several video-interview and assessment vendors have shipped features that score candidate tone, facial expression, or engagement. If any tool in your stack does that for EU-based candidates, that is a live exposure now, not a 2027 planning item.
Provider or deployer?
The Act splits duties between the provider who develops and places a system on the market and the deployer who uses it. Most agencies are deployers, which is the lighter of the two roles — but it is not a null role.
Deployer obligations under the high-risk chapter include using the system in line with the provider's instructions, assigning human oversight to people with the competence and authority to exercise it, keeping logs, monitoring operation, and informing affected people that a high-risk system is being used in decisions about them.
There is a trap worth knowing about. A deployer can be reclassified as a provider — inheriting the much heavier provider obligations — by putting their own name on the system, substantially modifying it, or repurposing it for a high-risk use the original provider did not intend. Heavy customisation of a general-purpose tool into a candidate-scoring system is the pattern to watch.
The extraterritorial reach
Non-EU agencies frequently assume this does not apply to them. The Act reaches providers and deployers outside the EU where the output of the system is used in the EU. A UK or US agency screening candidates for a role based in Ireland, Germany, or the Netherlands is within scope on the plain reading.
Penalties are tiered. Breaching the prohibited-practices rules attracts the highest band — up to €35 million or 7% of global annual turnover, whichever is greater. Most other breaches sit at up to €15 million or 3%.
What to do with the extra eighteen months
The temptation is to shelve this until 2027. The better use of the deferral is to do the work slowly rather than in a panic, because most of it is worth doing on its own merits.
- Inventory the AI in your stack. Every tool that scores, ranks, filters, or recommends candidates. Include features inside your ATS, your sourcing tools, and anything a recruiter has adopted independently. Most agencies find more than they expected.
- Kill anything doing emotion inference. This is already prohibited and it is the one item that cannot wait.
- Establish where the human decision sits. For each system, write down who decides, what they see, and what would make them overrule the tool. If the honest answer is that nobody overrules it, you do not have human oversight — you have a rubber stamp.
- Check your vendors can produce documentation. Providers of high-risk systems will need technical documentation, conformity assessment, and instructions for use. Ask now what they will supply and when. A vendor with no answer in mid-2026 is a risk.
- Write down what you tell candidates. You will need to inform people when a high-risk system is used in decisions about them. Drafting that disclosure now is a candidate-experience improvement long before it is a compliance artefact.
- Run and document AI literacy training. Already required, cheap to do, and the easiest gap to close.
- Handle Article 50 before August. Disclose AI interaction and AI-generated content wherever candidates encounter it. This deadline did not move.
Why the compliance shape is also the product shape
The obligations converge on a small number of properties: know what the system does, be able to explain a decision, keep a human meaningfully in the loop, and tell the affected person what happened. Those are not regulatory overhead bolted onto a good tool. They are the description of a good tool.
A score without explanation is worse than no score at all — for a recruiter, and now for a regulator.
This is why explainability stopped being a nice-to-have. A system that returns a ranked list with no reasoning cannot support human oversight, because the human has nothing to oversee; and it cannot support candidate disclosure, because there is nothing to disclose beyond the existence of a number. Placr's matching engine returns a dimension-by-dimension breakdown for exactly this reason — which requirements were met, which were not, and what evidence sits behind each. We wrote up the engineering behind that in how we built AI matching that explains itself.
There is a commercial angle too. Enterprise clients are already putting AI questions into procurement, and clients hiring into the EU will be asking their suppliers what they use and how it is governed well before December 2027. Agencies that can answer clearly will find it a differentiator. Agencies that cannot will find it a disqualifier.
The short version
The high-risk deadline for recruitment AI has moved from August 2026 to December 2027, subject to formal adoption. The ban on workplace emotion inference, the AI literacy duty, and Article 50 transparency are in force now. The Act reaches you if your output is used in the EU, wherever you are based. And nearly everything the high-risk chapter will eventually require — an inventory, a real human decision point, an explainable system, and a clear message to candidates — is worth building before anyone makes you.
Frequently asked questions
- Is AI used in recruitment high-risk under the EU AI Act?
- Yes. Employment is listed in Annex III, covering AI used for recruitment and selection, filtering applications, evaluating candidates, and also task allocation, performance evaluation, monitoring, promotion, and termination decisions.
- Has the August 2026 AI Act deadline been delayed?
- Partly. Under the Digital Omnibus, provisionally agreed on 6 May 2026 and confirmed by Member State representatives on 13 May, standalone Annex III high-risk obligations move from 2 August 2026 to 2 December 2027. Article 50 transparency obligations still apply from 2 August 2026, and the prohibited-practices and AI literacy duties have been in force since February 2025.
- What parts of the EU AI Act already apply to hiring?
- The prohibited-practices ban and the AI literacy duty have applied since February 2025 — including an outright prohibition on AI that infers emotions in the workplace. Article 50 transparency applies from 2 August 2026 and was not deferred, so AI chatbots and AI-generated candidate content must be disclosed from that date.
- Does the EU AI Act apply to UK or US recruitment agencies?
- It can. The Act reaches providers and deployers outside the EU where the output of the AI system is used in the EU, so an agency screening candidates for an EU-based role is within scope on the plain reading, regardless of where it is established.
- Is an agency a provider or a deployer under the AI Act?
- Most agencies are deployers, which carries lighter obligations — following the provider's instructions, assigning competent human oversight, keeping logs, and informing affected people. A deployer can become a provider by rebranding a system, substantially modifying it, or repurposing it for a high-risk use it was not intended for.


