← Back to Insights

The EU AI act hiring rules were delayed. That's not a reason to wait.

The deadline moved to December 2027. The obligations didn't. What the Digital Omnibus changed for AI in hiring, and what to decide this quarter.

The deadline moved to December 2027. The obligations did not, and some rules for AI in hiring already apply.

‍

In March, the plan was clear. The AI tools used in recruiting would be inventoried by summer, vendors questioned, oversight rules written, all in time for August 2, 2026. Then the deadline moved, and in many companies the project quietly slid down the list. That is an understandable reaction. It is also the wrong one.

‍

The EU AI Act hiring rules have not gone away. They have been rescheduled. Under the Digital Omnibus, Regulation (EU) 2026/1744, which entered into force on July 27, 2026, the obligations for high-risk AI systems listed in Annex III now apply from December 2, 2027 instead of August 2, 2026. That category includes recruitment, candidate selection, promotion, termination, task allocation, and performance monitoring. What those obligations require has not changed. And several rules that touch hiring already apply today.

‍

For a CEO or CHRO, the practical question is not whether to comply. It is what to decide now, while there is still time to decide it well. The tools, vendor contracts, and workflows chosen this fall will still be running when the deadline arrives.

‍

What Did the Digital Omnibus Actually Change for AI in Hiring?

‍

The Omnibus changed dates, not duties. The European Commission proposed the deferral in November 2025, citing a practical problem. The harmonized technical standards that companies need to demonstrate compliance were not ready, and neither were the notified bodies and national authorities meant to enforce them. The European Parliament approved the agreement on June 16, 2026, the Council followed on June 29, and the regulation entered into force days before the original deadline.

‍

The result is two new dates. Stand-alone high-risk systems under Annex III, where employment sits, must comply by December 2, 2027. High-risk AI embedded in products regulated under Annex I follows on August 2, 2028. For hiring, the first date is the one that matters.

‍

What did not move is just as important. The core requirements for high-risk systems remain intact: risk management, data governance, technical documentation, human oversight, logging, and post-market monitoring for providers. There is also a parallel set of duties for the companies that use these systems.

‍

In the language of the Act, an employer that uses an AI tool to screen candidates is a "deployer," and deployers carry real obligations. They must use the system as instructed, assign human oversight to people with the competence and authority to exercise it, monitor performance, and keep logs. They must also inform workers and their representatives before a high-risk system is put to use in the workplace.

‍

Law firms that advise on the Act have been consistent on one point since July: the extension is a planning reprieve, not a reason to stand down. Some operators argue that if the date slipped once, it could slip again. That is a bet, not a strategy, and it is a poor one to build hiring processes on.

‍

What Already Applies Today

‍

The delay covers high-risk obligations. It does not cover everything, and two sets of rules are already live for any company hiring in the European Union.

‍

Prohibited practices, since February 2, 2025. Article 5 of the Act bans a short list of AI uses outright. The one most relevant to employers is the prohibition on systems that infer emotions in the workplace, with narrow exceptions for medical or safety reasons. The European Commission's guidelines on prohibited practices make clear that "workplace" is read broadly. It extends to candidates in a recruitment process and to employees on probation.

‍

An interview tool that scores a candidate's enthusiasm or stress from facial expressions or voice patterns is not a future compliance issue. It is already unlawful in the EU. Fines for prohibited practices can reach EUR 35 million or 7% of global annual turnover, whichever is higher.

‍

Transparency obligations, since August 2, 2026. The Omnibus left Article 50 untouched. In an HR context, that covers recruitment chatbots, virtual assistants that answer candidates' questions, and generative tools used in recruitment or employee communications. People interacting with these systems need to know they are dealing with AI.

‍

Neither of these waits for 2027. A company that paused its AI inventory in July may already be running a tool that falls under one of them, without knowing it.

‍

Which Hiring Tools Fall Under the EU AI Act Hiring Rules?

‍

The answer is broader than most leadership teams assume. Annex III, point 4, covers AI systems intended for the recruitment or selection of people, including placing targeted job advertisements, analyzing and filtering applications, and evaluating candidates. It also covers systems used to:

  • make decisions affecting the terms of employment, promotion, and termination
  • allocate tasks based on individual behavior or traits
  • monitor and evaluate performance

‍

In practice, that reaches well beyond a dedicated screening platform. It can include the ranking feature inside an applicant tracking system, or an assessment tool licensed by a business unit without HR's involvement. It can include a video interview product with automated scoring, or a performance analytics module switched on by default in a wider HR suite.

‍

The scale of use is significant. SHRM's State of AI in HR 2026 report, based on a survey of 1,908 HR professionals, found that recruiting is the most common use of AI in HR, at 27% of organizations. Seven of the ten most frequent AI use cases in HR sit in recruiting. Adoption is also accelerating at the frontier: Gartner found in late 2025 that 82% of HR leaders planned to deploy agentic AI within 12 months.

‍

Agents deserve particular attention. Legal analyses of the Omnibus point out that if an AI agent is used for a high-risk purpose, high-risk obligations apply. A company that uses a system in a way its provider did not intend can end up carrying the obligations of a provider itself. A general-purpose assistant configured internally to shortlist candidates is a very different compliance object from the same assistant drafting job descriptions.

‍

This is why AI in recruitment compliance starts with an inventory, not a policy. Our playbook on AI governance for mid-market companies sets out how to assign ownership for that inventory when there is no dedicated AI function.

‍

Why Decisions Made This Fall Will Still Be Running in 2027

‍

Fourteen months sounds like a long time. In procurement terms, it is not.

‍

Consider the sequence a typical company faces:

  • Most HR technology contracts run for multiple years, and renewal and RFP cycles for 2027 are being negotiated now.
  • Integrating a new assessment or screening tool into an existing HR stack, training recruiters, and rewriting processes takes months.
  • The harmonized standards that define what "compliant" looks like in technical terms are still being finalized through late 2026 and into 2027.

‍

A company that waits for the deadline to approach will be making vendor decisions under time pressure, with less negotiating leverage and fewer alternatives.

‍

The contract is where most of the risk can be managed cheaply today. Before signing, a buyer can ask the vendor:

  • whether it considers its product high-risk under Annex III
  • what documentation and instructions for use it will provide
  • how human oversight is designed into the workflow
  • what logs the deployer will be able to access
  • who carries responsibility if the system is configured beyond its intended purpose

‍

Those questions cost nothing in October 2026. They are expensive to raise in a renewal negotiation in late 2027.

‍

There is also a quality argument that has nothing to do with regulation. SHRM data shows that 19% of organizations using automation or AI in hiring report that their tools have overlooked or screened out qualified applicants. For high-volume roles, that is an efficiency loss. For senior roles, where the right candidate is often one person in a small market, it can mean the hire never happens.

‍

The Most Common Mistake: Treating the Delay as a Pause

‍

The most common mistake is reading "deferred" as "paused" and stopping the work entirely.

‍

It happens for understandable reasons. The original deadline created urgency and budget. When it moved, the urgency disappeared and the budget was reallocated. The AI inventory in HR, often half complete, was parked.

‍

The cost of that decision shows up in three places:

  • Rules that never moved. The company may already be exposed under the workplace emotion-recognition ban and the transparency duties, without having checked.
  • Unreviewed tools. Every month without an inventory is a month in which new tools enter the organization unreviewed, often through business units rather than HR.
  • Work that does not shrink. Classification, governance, documentation, and evidence collection take as long in 2027 as they would have taken in 2026, and they compete with whatever else is urgent that year.

‍

The better approach is to reset the plan, not abandon it. Keep the inventory going. Move the heavier work, such as documentation and oversight procedures, onto a realistic timeline that ends well before December 2027. And make sure the team that owns it is still named.

‍

What Boards and CHROs Should Decide in the Next 90 Days

‍

A short list of decisions covers most of what matters this quarter.

‍

Name one owner. AI in hiring sits between HR, legal, IT, and procurement. Without a single accountable executive, it belongs to no one. Whether that owner should be a dedicated AI leader is a separate question, explored in our piece on whether you need a Chief AI Officer.

‍

Finish the inventory. List every AI system that touches candidates or employees, including features embedded in larger platforms. For each, record what it does, who uses it, and which countries it operates in.

‍

Check what already applies. Confirm that no tool infers emotions from candidates or employees, and that every candidate-facing chatbot or assistant is clearly identified as AI.

‍

Write vendor questions into every renewal. Classification, documentation, oversight, logs, and responsibility for configuration should be in the contract, not in a sales conversation.

‍

Decide where human judgment is non-negotiable. The Act requires human oversight for high-risk systems. Leadership teams should go further and decide, explicitly, which hiring decisions AI may inform and which it may never make.

‍

That last decision matters most at the top of the organization. For senior roles, AI can usefully speed up market mapping and research. It cannot assess how a candidate will lead through a restructuring, read the culture of a new market, or build the trust that persuades a performing executive to move. Future Manager World's view, built on senior searches in Europe and the United States, is that the EU AI Act hiring rules simply formalize what good executive hiring already required: technology in support, people accountable for the decision.

‍

Key Takeaways

‍

  • The Digital Omnibus moved the EU AI Act hiring rules for high-risk systems to December 2, 2027. The obligations themselves did not change.
  • The ban on workplace emotion recognition, including in recruitment, has applied since February 2025, and transparency duties for candidate-facing AI since August 2026.
  • Annex III covers far more than screening platforms, including embedded features, assessment tools, performance analytics, and AI agents used for hiring decisions.
  • Vendor contracts and HR technology choices made this fall will still be running when the deadline arrives, which makes now the cheapest time to set requirements.
  • The work does not get shorter with time. Keep the inventory going, name an owner, and decide where human judgment is non-negotiable.

‍

Future Manager World works with CEOs and CHROs building senior hiring processes across Europe and the United States. Talk to our team.

‍

Frequently Asked Questions

When do the EU AI Act hiring rules apply?

High-risk obligations for AI used in recruitment, selection, promotion, termination, and performance monitoring apply from December 2, 2027, following the Digital Omnibus (Regulation (EU) 2026/1744). Some rules already apply: the ban on workplace emotion recognition since February 2025, and transparency duties for candidate-facing AI since August 2026.

Is AI used in recruitment considered high-risk under the AI Act?

Yes. Annex III lists AI systems used to recruit or select candidates as high-risk, including targeted job advertising, filtering applications, and evaluating candidates. Systems used for promotion, termination, task allocation, and performance monitoring are also covered.

Does the AI Act apply to US companies hiring in Europe?

It can. The Act covers AI systems used in the EU and, in some cases, systems whose output is used in the EU, regardless of where the provider or employer is based. US companies hiring for European roles should assume their tools may be in scope and confirm with counsel.

What should employers do before December 2027?

Name one accountable owner, complete an inventory of every AI tool that touches candidates or employees, and confirm that nothing already prohibited is in use. Then build AI Act requirements into vendor contracts at renewal and define which hiring decisions must always remain with people.

ShareLinkedInX (Twitter)Copy link

More from Insights

View all →