Skip to main content
Bibha home

HR and recruitment,

EU AI Act recruitment rules: the deadline moved, the duties did not

The Digital Omnibus on AI moved the start of the EU AI Act recruitment rules for high-risk systems to 2 December 2027. It did not take hiring off the high-risk list or soften the high-risk duties of employers that use these tools. Here is what changed, what already applies and what to build now.

By Praveen Hebbale, Chief Business Officer, Bibha AI Labs

Two recruiters seen from behind at a light oak table, reviewing stacks of paper application folders beside a window with plants.
AI-generated illustration: recruiters reviewing applications by hand in a sunlit meeting room.

What changed for EU AI Act recruitment rules?

The date changed; the substance did not. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It moves the start of the high-risk rules for AI systems listed in Annex III of the AI Act, which include tools used to recruit and select people, from 2 August 2026 to 2 December 2027. The hiring uses in Annex III and the deployer duties in Article 26 were not amended.

The Commission proposed the package on 19 November 2025 and wanted to link the start date to the availability of harmonised standards. The Parliament and the Council chose fixed dates instead: 2 December 2027 for Annex III systems and 2 August 2028 for high-risk AI built into products covered by Annex I. The recitals explain why: standards and national supervisory structures arrived later than planned.

For HR, talent acquisition and procurement leaders, that means a longer runway, not a lighter load. This article is general information, not legal advice; decide on specific systems with your legal and data protection advisers.

Which hiring tools does the AI Act treat as high-risk?

Annex III point 4(a) covers AI systems intended to be used to recruit or select people, naming three examples: placing targeted job advertisements, analysing and filtering applications, and evaluating candidates. Point 4(b) adds decisions within employment, such as promotion, termination, task allocation and performance monitoring. Classification turns on the intended purpose the provider states and on what the system does in your process.

Article 6(3) offers a narrow exit. An Annex III system is not high-risk if it poses no significant risk of harm to health, safety or fundamental rights, for example because it performs a narrow procedural task, improves work a person has already completed, detects deviations from earlier decision patterns without replacing human assessment, or only prepares an assessment. One override matters most in hiring: a system that profiles people is always high-risk.

On 19 May 2026 the Commission published draft classification guidelines with recruitment examples. They are not legally binding and may change, but they show how the Commission reads the text. The table summarises the draft.

How the Commission's draft classification guidelines of 19 May 2026 treat common hiring uses
Use in the hiring processDraft positionReason given
Matching or ranking tools that score applicants and build shortlistsHigh-riskScores and rankings are a primary input to who advances, even when recruiters can override them
Scoring written or recorded answers in an online assessmentHigh-riskThe system evaluates applicants and decides who is invited to interview
Sourcing tools that search job boards and CV databases for matching profilesHigh-riskFiltering and identifying candidates materially affects selection
Background checks that output risk scores or flagsHigh-riskThe system profiles applicants, so the Article 6(3) exemptions cannot apply
Targeted job advertisements that rely on profilingHigh-riskTargeting decides who learns about a vacancy, and profiling rules out the exemptions
Interview scheduling and remindersExempt: narrow procedural taskPurely logistical, with no part in selecting candidates
Extracting CV information into a searchable databaseExempt under Article 6(3)A limited function without material impact on selection
Emails acknowledging receipt of an applicationExempt: narrow procedural taskIt does not change anyone's chance of being selected
Flagging non-inclusive wording in job advertisementsOutside point 4(a)It is not used to recruit or select people
Inferring candidates' emotions from video or voiceProhibitedArticle 5(1)(f) applies, and a prohibition prevails over the high-risk regime

What already applies to AI in hiring?

Several rules apply long before December 2027. The prohibited practices in Article 5 and the AI literacy duty in Article 4 have applied since 2 February 2025, with Article 4 rewritten by the omnibus from 27 July 2026. The transparency duties in Article 50 have applied since 2 August 2026. The GDPR has applied to candidate data throughout.

Penalties are in force too. Under national rules, breaching an Article 5 prohibition can bring fines of up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Breaching the transparency duties in Article 50, and from December 2027 the deployer duties in Article 26, can bring up to EUR 15 million or 3%.

  • Emotion recognition and sensitive categorisation are banned. Article 5(1)(f) bans AI that infers people's emotions in the workplace, except for medical or safety reasons. The Commission's guidelines on prohibited practices read this as inferences from biometric data, such as facial expressions or voice, and apply it to candidates during hiring. Article 5(1)(g) separately bans using biometric data to infer traits such as race, religious beliefs or sexual orientation.
  • AI literacy is still a duty. The omnibus replaced the duty to ensure “to their best extent, a sufficient level of AI literacy” with a duty to take measures that support staff in developing it, without guaranteeing any level. Recruiters using AI still need training that fits the tools.
  • Chatbots must say they are AI. Article 50 requires providers to design systems that talk directly to people so that those people know they are dealing with AI, unless that is obvious. A candidate assistant on a careers site or messaging channel should make this clear.
  • GDPR already governs candidate data. Article 22 GDPR gives people a right not to face significant decisions made solely by automated processing, with limited exceptions that need safeguards such as human intervention. Article 35 GDPR requires a data protection impact assessment where processing is likely to result in a high risk.
Key EU AI Act dates for AI used in hiring
DateWhat appliesWhat it means for hiring
1 August 2024The AI Act enters into forceThe timetable starts; no hiring obligations yet
2 February 2025Chapters I and II: definitions, AI literacy and prohibited practicesEmotion recognition of candidates and staff is banned, and people using AI need AI literacy measures
2 August 2025Penalties, rules for general-purpose AI models and governanceNational penalty regimes for infringements apply
27 July 2026Regulation (EU) 2026/1744 enters into forceNew high-risk dates and the amended AI literacy duty take effect
2 August 2026General date of application, including Article 50 transparencyCandidate chatbots must make clear that they are AI
2 December 2027High-risk rules for Annex III systems (Chapter III, Sections 1 to 3)Recruitment and selection tools in scope must meet provider and deployer obligations
2 August 2028High-risk rules for AI in products covered by Annex IMainly a product safety matter, not a hiring one
2 August 2030Compliance deadline for existing high-risk systems intended for use by public authoritiesPublic sector employers cannot rely on legacy status after this date

Which deployer duties should hiring teams build before December 2027?

An organisation using a high-risk recruitment system under its own authority is a deployer, and Article 26 sets its duties. The omnibus cut none of them. Most depend on people, process and records more than software, so they take time to build.

The fundamental rights impact assessment in Article 27 applies to public bodies, private entities providing public services and certain credit and insurance uses, so most private employers do not need one for hiring tools. And an organisation that builds its own screening system, or turns a general-purpose model into a candidate-ranking tool, can become the provider, with far heavier obligations (Articles 3 and 25).

  • Use it as instructed. Take technical and organisational measures so the system is used in line with the provider's instructions for use (Article 26(1)).
  • Assign competent oversight. Give oversight to named people with the competence, training and authority to question, override or stop the system (Article 26(2)). A reviewer who never changes an outcome adds little protection.
  • Check the input data you control. Job criteria, historical hiring data and assessment questions you supply must be relevant and sufficiently representative for the purpose (Article 26(4)).
  • Monitor and act. Monitor operation, tell the provider about problems, suspend use if the system presents a risk, and report serious incidents (Article 26(5)).
  • Keep the logs. Retain the automatically generated logs you control for at least six months, unless other law, notably data protection law, provides otherwise (Article 26(6)).
  • Inform people. Tell candidates when a high-risk system makes or supports decisions about them (Article 26(11)). Before using one on employees, inform workers' representatives and the affected workers (Article 26(7)).
  • Prepare for explanation requests. Under Article 86, a person significantly affected by a decision based on a high-risk system's output can ask the deployer to explain the system's role and the main elements of the decision.
Illustration of blank cards travelling along a winding path through three arches, with a hand lifting one card beside a glowing lantern.
AI-generated illustration: one application is paused for a closer look, a picture of human oversight in a hiring workflow.

What should procurement ask recruitment AI vendors?

A deployer depends on the provider for instructions for use, oversight design, logs and evidence of conformity. Secure them in contracts and renewals now, not late in 2027. These questions follow the provider requirements in Articles 10 to 16 and 43 to 49.

  • Purpose and classification. Do you classify the system as high-risk under Annex III point 4? If you rely on Article 6(3), have you documented the assessment and registered the system as Articles 6(4) and 49(2) require?
  • Instructions and oversight. Will the instructions explain capabilities, limitations and the oversight measures we must apply (Articles 13 and 14)?
  • Logs and data. Which events are logged, can we export the logs we must keep, and how do you detect and correct bias in training and test data (Articles 10 and 12)?
  • Conformity and registration. When will the internal-control conformity assessment, EU declaration of conformity and registration be complete, and what will you show us before 2 December 2027 (Article 43(2))?
  • Changes and prohibited features. How will you notify significant design changes (Article 111(2)), and will you confirm in writing that no feature infers candidates' emotions?

Worked example: one hiring workflow, six AI features

Consider an illustrative retail group recruiting store and warehouse staff in several EU countries. It is a composite, not a real company. Its hiring stack has six AI features, and each lands in a different place.

The result: one feature to stop now, two to bring up to the high-risk standard, and three to document and review before December 2027.

  • Programmatic job advertising. Audiences are targeted on browsing patterns and personal traits. That is profiling, so the draft treats it as high-risk. Action: test whether contextual placement would meet the need.
  • CV parsing. CV text is extracted into a searchable database, which the draft treats as exempt. Action: document why and confirm it does not score applicants.
  • Matching scores. The applicant tracking system ranks applicants for each role: high-risk. Action: name trained reviewers who can override, set log retention and draft the candidate notice.
  • Video interview analytics. An optional module reports enthusiasm from facial expressions. That is emotion recognition, banned since 2 February 2025. Action: switch it off now and get the vendor's written confirmation.
  • Interview scheduling. An assistant proposes slots and sends reminders: a narrow procedural task. Action: record the reasoning and revisit it if features grow.
  • Candidate chatbot. A chatbot answers questions about roles. Article 50 already requires candidates to know it is AI. Action: check the disclosure on every channel.

Common misconceptions about the delay

Most mistakes come from reading the new date as a pause for everything.

  • Nothing applies until December 2027. Prohibitions, AI literacy, Article 50 transparency, penalties and the GDPR already apply.
  • Compliance is the vendor's problem. Providers carry design and conformity duties, but Article 26 places separate duties on the employer. A compliant product used without oversight, logs or candidate notices still exposes the deployer.
  • A human click takes a tool out of scope. The draft guidelines treat a system as evaluating candidates when it appreciably influences the decision, for example by building shortlists, even if a recruiter makes the final choice.
  • Every HR tool is now high-risk. Scheduling, acknowledgement emails and CV extraction sit outside the high-risk regime in the draft. Over-classifying diverts effort from tools that rank and score people.
  • Tools bought before December 2027 are exempt for good. Under Article 111(2), high-risk systems already on the market or in service before 2 December 2027 come under the rules only after significant design changes, and those used by public authorities must comply by 2 August 2030. Software changes often, so agree with vendors and counsel how such changes will be identified.

A readiness checklist for HR, talent and procurement

Most items belong to HR, talent and procurement owners, not the legal team.

  • Now: inventory. List every AI feature from job advertising to offer, including modules inside HR suites, with its purpose, vendor, data and the decisions it touches.
  • Now: stop and disclose. Disable emotion inference in hiring tools, and check that candidate chatbots disclose that they are AI on every channel.
  • Now: AI literacy. Train recruiters and hiring managers on what each tool does, where it fails and when to override it.
  • Next: classify. Assess each use against Annex III point 4 and Article 6(3), using the Commission's draft examples, and document the reasoning.
  • Next: oversight, records and notices. Name reviewers with authority to change outcomes, set log retention of at least six months within data protection limits, and draft candidate notices.
  • Before 2 December 2027: contracts and staff. Write the vendor questions into renewals, collect conformity evidence, and plan the information Article 26(7) requires before high-risk systems are used on employees.

Where TalentFlow and the Bibha platform fit

TalentFlow, a recruitment solution built on Bibha, keeps recruiters in charge: they set the criteria and make the hiring decisions. It supports candidate engagement, structured information capture, interview scheduling and drafts for review, and it does not score, rank or recommend candidates or analyse emotion, personality or culture fit.

For wider workflows, Bibha's governance capabilities include identity and access, roles and permissions, policy enforcement, audit history, retention and deletion, change and release authority, and emergency stop and revocation. They help implement agreed controls; a capability list does not establish compliance, which depends on your actual system, data, configuration and operating practice.

Questions and answers

Does the Digital Omnibus remove recruitment from the AI Act's high-risk list?

No. Annex III point 4, which covers AI used to recruit and select people and to manage employment, was not amended. Only the date changed: the high-risk rules for Annex III systems apply from 2 December 2027 instead of 2 August 2026. The deployer duties in Article 26 are unchanged.

Can we use AI to analyse candidates' emotions in video interviews?

No. Article 5(1)(f) prohibits AI that infers emotions in the workplace except for medical or safety reasons, and the Commission's guidelines on prohibited practices apply this to candidates. The ban has applied since 2 February 2025, so disable any such feature now.

Is an AI interview scheduling tool high-risk?

Probably not, if scheduling is all it does. The Commission's draft guidelines treat a scheduling assistant that proposes slots and sends reminders as a narrow procedural task, exempt under Article 6(3). That changes if the tool starts filtering or prioritising candidates.

How long should we keep logs from a high-risk recruitment system?

Article 26(6) requires deployers to keep the automatically generated logs they control for a period suited to the system's purpose and at least six months, unless other law, notably data protection law, provides otherwise. Agree the period with your data protection officer.

Do private employers need a fundamental rights impact assessment for hiring AI?

Usually not. Article 27 applies to bodies governed by public law, private entities providing public services and certain credit and insurance uses. Public sector employers using high-risk recruitment tools must carry one out, and any employer needs a GDPR impact assessment where processing is likely to result in a high risk.

References

  1. European Parliament & Council of the European Union. (2026). Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). Official Journal of the European Union, L series, 24 July 2026. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202601744 (external site)
  2. European Parliament & Council of the European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), consolidated text of 27 July 2026. EUR-Lex. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (external site)
  3. European Commission. (2026, July 27). AI Omnibus enters into force. Shaping Europe's digital future. https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force (external site)
  4. Niestadt, M. (2026). Digital Omnibus on AI (EU Legislation in Progress briefing, PE 782.651). European Parliamentary Research Service. https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/782651/EPRS_BRI(2026)782651_EN.pdf (external site)
  5. European Commission. (2025). Commission guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act) (C(2025) 5052 final). https://ai-act-service-desk.ec.europa.eu/sites/default/files/2025-08/guidelines_on_prohibited_artificial_intelligence_practices_established_by_regulation_eu_20241689_ai_act_english_ied3r5nwo50xggpcfmwckm3nuc_112367-1.PDF (external site)
  6. European Commission. (2026, May 19). Draft Commission guidelines on the classification of high-risk AI systems under Article 6 of Regulation (EU) 2024/1689 (AI Act) [Draft for stakeholder consultation]. https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems (external site)
  7. European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). Official Journal of the European Union, L 119, 4 May 2016. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (external site)
Explore TalentFlow for recruitment workflowsReview governance and customer controlDiscuss a recruitment workflowAll news and research