EU AI rules in hiring: what applies now and what moves to 2027

Insights  /  AI & regulation

EU AI rules in hiring: what applies now and what moves to 2027

The EU has moved its strictest AI rules for hiring tools to December 2027. But the delay is only half the story. Some duties already apply, and one practice is already banned.

Anonymous candidate cards pass through a network of AI connection lines to a single selected profile, while a human hand rests on a control button beneath a circle of EU stars.

The three dates that matter

  • 2 February 2025: Ban on AI that reads emotions at work and in recruitment takes effect. So does the duty to support AI know-how among staff.
  • 2 August 2026: Transparency rules apply. Mostly a matter for AI providers; employers have a shorter list.
  • 2 December 2027: Strict high-risk rules apply to genuinely new hiring-AI types and models first placed on the EU market or put into service from this date. Earlier types and models are generally grandfathered unless their design is significantly changed later.

In July 2026, the EU changed the timetable of its AI law. Regulation (EU) 2026/1744, the “Digital Omnibus on AI”, was published on 24 July 2026 and has been in force since 27 July 2026. It amends the EU AI Act and moves the strictest obligations for high-risk AI, including many hiring tools, from August 2026 to December 2027.

The headlines called it a delay. That reading skips two things. Some rules were never postponed, and the most important rule for hiring took effect back in February 2025.

Already banned: software that reads emotions

Some video-interview and assessment tools claim to read enthusiasm, stress, or honesty from a candidate’s face or voice. Since 2 February 2025, AI that infers emotions or intentions from facial expressions, voice characteristics, or other biometric data is banned in the workplace and in recruitment. Only narrow medical and safety uses are allowed. The ban is about inferring emotion from the body: analyzing the tone of written text is a different matter and not automatically prohibited. And telling candidates about it does not make it lawful. A ban is a ban.

This sits in Article 5 of the AI Act, and the European Commission has published practical guidelines on these prohibited practices. If a tool in your selection process claims to read emotions from facial expressions, voice characteristics, or other biometric data, that is the first thing to check.

A second duty from the same date also remains in place. Organizations using AI must take measures supporting the development of AI literacy among their staff (training, internal guidelines) without having to guarantee that each individual reaches a set level (see the Commission’s AI-literacy Q&A).

What changed in July 2026, and what did not

What moved is the high-risk regime. “High-risk” refers to a list in the law (Annex III) of sensitive uses. That list includes AI used to recruit and select people, and AI used for decisions on promotion, termination, task allocation, and monitoring. The strict duties tied to that list now apply from 2 December 2027 instead of 2 August 2026.

Two qualifications keep this realistic. First, the December 2027 rules apply to genuinely new types and models first placed on the EU market or put into service from that date. A type and model already on the market before then is generally grandfathered unless its design is significantly changed later, so buying another unit of the same unchanged model does not automatically trigger the full regime (Article 111, as amended). Genuinely new types and models and significantly redesigned systems do fall under it. Systems used by public authorities have a separate 2030 deadline.

Second, the delay concerns the AI Act only. The GDPR, equality law, employment law, and worker-consultation rights apply today. The GDPR already restricts decisions based solely on automated processing where they have legal or similarly significant effects for candidates, subject to limited exceptions, and can require a data protection impact assessment for candidate screening.

What did not move: the transparency rules of Article 50. Those have applied since 2 August 2026, as planned.

Transparency since August 2026: mostly the provider’s job

The AI Act divides duties between two roles. The provider develops the system or places it on the market under its own name. The deployer uses it. When you buy an off-the-shelf tool, the vendor is usually the provider and you, the employer, are usually the deployer. That distinction decides who must do what.

Most transparency duties sit with providers. A chatbot must tell people that they are interacting with AI unless this is obvious, but building that notice into the system is the provider’s job. Providers of AI systems that generate synthetic audio, images, video or text must generally ensure that the output is marked in a machine-readable format and can be detected as artificially generated or manipulated. Limited exceptions apply, including for standard editing and when the output does not substantially alter the input or its meaning. Providers of systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with this specific marking duty.

The employer’s own list is shorter. Disclose deepfakes: AI-made or AI-altered images, audio, or video that resemble real people, places, or events and could falsely appear authentic. Label AI-written text you publish to inform the public on matters of public interest, unless it has had substantive human review (a knowledgeable person genuinely examining the content, not a spell-check) and someone assumes editorial responsibility. And inform people where lawfully permitted emotion recognition or biometric categorization is used. That is rare at work, given the ban above. The Commission’s Article 50 guidance spells out these tests.

In practice: a vacancy page will rarely count as public-interest information in the first place. A better example is a piece like this one: an AI-assisted article on the legal rules for recruitment and selection can be published without an AI label if a knowledgeable person substantively reviews it and the publisher takes editorial responsibility. A lifelike AI-generated “employee” telling their story in a recruitment video, by contrast, may be a deepfake and require disclosure if it could falsely appear authentic.

Which hiring tools count as high-risk

Not every tool in recruitment is high-risk. A chatbot answering questions about parking is not. Neither is an interview scheduler or the document storage in your applicant tracking system. A tool that ranks CVs, scores candidates, or recommends who advances may well be.

The classification test in the law (Article 6) is stricter than it sounds. A system listed in Annex III falls outside the high-risk category only if it poses no significant risk of harm to health, safety or fundamental rights, including by not materially influencing the decision, and meets at least one of Article 6(3)’s limited conditions. An Annex III system that profiles natural persons is always considered high-risk. The provider must document any assessment that the system is not high-risk before placing it on the market or putting it into service. That provider is not always your commercial vendor, so ask each vendor in writing how the product is classified and why.

What December 2027 will ask of you

For tools that qualify as high-risk, providers carry the heavier load: conformity assessment, technical documentation, accuracy requirements, and measures to address bias and discrimination. The employer’s duties as deployer under Article 26 are more operational and include:

  • assign trained, authorized people to oversee the system;
  • use it according to the instructions and monitor its operation; if you have reason to consider that use in accordance with the instructions may present a risk under the Act, suspend use and inform the provider or distributor and the relevant market-surveillance authority without undue delay; if you identify a serious incident, immediately inform first the provider and then the importer or distributor and the relevant market-surveillance authorities;
  • keep the system’s automatically generated logs that are in your control, generally for at least six months, unless other law sets a different period;
  • inform employees and their representatives before putting it into use;
  • inform candidates and employees affected by AI-assisted decisions;
  • make sure input data is relevant and sufficiently representative, to the extent you control that data.

Some public-sector and public-service deployers must also complete a fundamental-rights impact assessment before use.

Two contract points are worth settling early. Agreements with vendors can allocate support, remedies and indemnities, but they cannot change the roles assigned by law.

In three situations an employer becomes the provider, with the full provider obligations: putting its own name or trademark on an existing high-risk system; making a substantial modification to a high-risk system that remains high-risk; or changing the intended purpose of a system that was not classified as high-risk so that it becomes high-risk (Article 25). Not every adjustment or new use changes your legal role, but an assessment portal offered under your own brand deserves a second look.

Fines and national supervision

The law sets maximums, not standard penalties. For banned practices: up to €35 million or, for companies, 7% of worldwide annual turnover, whichever is higher. For breaches of specified provider, deployer, and transparency duties: up to €15 million or 3% on the same basis. For small and medium-sized companies, the lower of the two amounts applies (Article 99). What a penalty becomes in practice depends on the case, but the ceilings signal how significant the consequences of non-compliance can be.

National supervision is taking shape at different speeds. In Germany, a national implementation act brought the AI Act framework into force on 29 July 2026, with the Federal Network Agency (Bundesnetzagentur) as central coordinator. In the Netherlands, the government put its implementation bill out for consultation in April 2026: existing regulators supervise AI within their own domains, with the Dutch Data Protection Authority and the Digital Infrastructure Inspectorate (RDI) in coordinating roles.

As at 20 August 2026, Belgium had identified several authorities responsible for protecting fundamental rights under Article 77, but had not yet completed the wider designation of market-surveillance authorities and its single point of contact under Article 70.

The practical conclusion is the same everywhere: do not wait for a regulator’s checklist. The obligations apply regardless, and an organization that keeps a dated record of its AI tools, its role for each, and the checks it ran will be in a far better position than one that waited.

Three moves to start now

  1. List your hiring tools. Everything that touches candidates or employees: what it does, who the provider is, whether it infers emotions from facial expressions, voice characteristics, or other biometric data, and whether you are deployer, or have quietly become provider.
  2. Fix what applies now. Stop using functions that infer emotions or intentions from candidates or employees on the basis of biometric data, unless qualified counsel confirms that a narrow medical or safety exception applies. Ask the provider to confirm in writing which signals the function processes and disable it wherever the prohibition applies. Check that chatbots and deepfakes meet the applicable transparency duties. Document your AI-literacy measures.
  3. Plan the 2027 build with providers and counsel. Ask each provider for its classification and its compliance plan. Assign the deployer duties above to named owners and set deadlines, and route questions of legal interpretation to your counsel. Where role design or structured assessment needs rethinking alongside this, our Talent Advisory work covers that ground.

Hiring decisions increasingly involve software. The useful governance question (today, not in 2027) is whether you can explain and document how a decision was made.

Where Article 86 applies, an affected person has the right to obtain a clear and meaningful explanation from the deployer. The decision must be based on the output of a qualifying Annex III high-risk AI system, other than one listed in Annex III point 2, and must have legal or similarly significant effects that the person considers adverse to their health, safety or fundamental rights. The explanation must cover the system’s role in the decision-making procedure and the main elements of the decision. This right applies to the extent that Union law does not already provide it, and transition rules may affect its practical operation.

In regulated environments, documenting that reasoning is already a prudent governance practice. The period until December 2027 is preparation time.

This article is general information for employers, not legal advice. Have specific questions of interpretation reviewed by qualified EU employment and privacy counsel.

The Smarter Search view

Selecting senior people with software in the loop? Smarter Search helps clients set the assessment criteria, the human decision points and the documentation that make an appointment explainable, today and under the 2027 regime.