Fair, auditable AI hiring
The EU AI Act deadline moved. The one that binds you didn't.
August 18, 2026

If you built a compliance plan around 2 August 2026, that date is gone. High-risk obligations for AI used in employment and recruitment now apply from 2 December 2027 — a sixteen-month deferral, granted by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which was signed on 8 July 2026 and entered into force on 27 July. The Commission's own timeline page now states that rules for employment-related systems "will apply from 2 December 2027."
That is the part most coverage has caught up with. Two other things are true at the same time, and they are the ones that actually govern what you can run next Monday.
The transparency rules went live on schedule. And the single most common feature in AI interview tooling has been outright prohibited in hiring since February 2025.
What moved, precisely
The deferral applies to Chapter III — the obligations attaching to high-risk systems. Annex III covers stand-alone high-risk uses, and employment sits inside it: AI used for recruitment, for filtering applications, and for evaluating candidates. Those obligations move to 2 December 2027. Annex I, covering AI as a safety component in already-regulated products, moves to 2 August 2028.
Both replace the original 2 August 2026 date.
What the deferral does not touch is everything outside Chapter III. White & Case put it plainly: the extension "is limited to Chapter III and does not apply to other obligations relevant to high-risk AI systems." A system can be high-risk, have its conformity assessment deferred by sixteen months, and still be squarely bound by rules that are in force today.
That is the distinction worth internalising. "The AI Act was delayed" is not a true sentence. One chapter of it was.
What went live on 2 August
Article 50, the transparency obligations, applied from 2 August 2026 as originally scheduled.
For anything that conducts an interview, Article 50(1) is the operative provision. The Commission's own guidance states that providers of systems which directly interact with people must ensure those people are informed they are interacting with an AI system — unless it is obvious — and that this happens "from the start of the first interaction in a clear and distinguishable manner."
Three parts of that sentence do work.
From the start. Not in a policy the candidate accepted at application. Not disclosed when they ask. At the beginning of the first interaction.
Clear and distinguishable. A line in paragraph nine of a terms page is not distinguishable.
Unless obvious. This is narrower than it reads. If a reasonable candidate could plausibly believe a person is on the other side, it is not obvious, and the exemption does not apply. The more natural the system sounds, the less available that argument becomes.
Article 50 splits its duties. Paragraph 1 sits on the provider — the company that builds the system. Paragraphs 3 and 4 sit on the deployer — you, the employer. That split matters commercially: a provider's compliance does not discharge your obligations, and your policies do not discharge theirs. When you buy, you are buying into a division of duties, and it is worth knowing which side of the line each requirement falls on before you sign.
The rule that has been in force for eighteen months
Article 5 lists the practices the Act prohibits outright. Those prohibitions became applicable on 2 February 2025 — they are the oldest operative part of the Act, and they were not touched by the omnibus.
Article 5(1)(f) prohibits AI systems that infer the emotions of a person from biometric data, in the workplace and in education. Not "high-risk." Not "requires a conformity assessment." Prohibited.
The question that decides whether this reaches hiring is whether "workplace" includes candidates who do not work for you yet. It does. The Commission's guidelines on prohibited practices state that hiring processes fall within the workplace context — a point the Future of Privacy Forum sets out in its analysis of the prohibition. Emotion inference during candidate interviews and selection is covered.
Two exceptions exist and both are narrow: medical purposes, limited to CE-marked devices used therapeutically, and safety, limited to protecting life and health. Neither is available to a hiring process. Fraud prevention is explicitly not a safety justification, which forecloses the argument a vendor is most likely to reach for — that reading a candidate's face is a way of catching cheating.
So: any tool that scores a candidate's confidence from their voice, reads engagement from their facial expression, or flags nervousness as a signal, is doing a prohibited thing when it does it to a job applicant in the EU. It has been prohibited since February 2025. It is not scheduled to become prohibited. It is not deferred to December 2027.
And disclosure does not cure it. This is where the two rules interact in a way that is easy to get wrong. Article 50(3) requires a deployer to inform people exposed to an emotion recognition system that it is operating. Read alone, that looks like a compliance route: tell the candidate, and proceed. It is not. You cannot consent your way out of a prohibition, and Article 5 does not have a notice exemption. In a hiring context, the transparency obligation for emotion recognition describes a disclosure for a system you were never permitted to run.
If a vendor's answer to the emotion-analysis question is "we disclose it," that answer is addressing the wrong article.
What this actually changes this quarter
Less than the deferral headline suggests, and more than most compliance plans account for.
The sixteen months buy time on documentation: the risk management system, the technical file, the conformity assessment, registration, the logging architecture that a high-risk classification requires. That work is real, it is expensive, and it now has until December 2027. Deprioritising it for two quarters is defensible.
What has not moved is anything about what a candidate experiences. Disclosure is live. The prohibition is eighteen months old. Both are enforceable now, and both are visible from the outside — a candidate can tell you whether they were informed at the start of an interview, and a regulator can tell whether a product infers emotion from a face. Neither requires anyone to audit a model.
That asymmetry is the practical point. The deferred obligations are the ones only an auditor can see. The live obligations are the ones a candidate can see. Guess which produce complaints first.
There is also a strategic reading. A sixteen-month deferral on documentation while transparency and prohibition stay in force is, in effect, a regulator saying the paperwork can wait but the candidate-facing conduct cannot. Building for the December 2027 file while running something today that Article 5 forbids is precisely the wrong order.
What to ask before you buy
Six questions. All answerable in a sentence, and a vendor who cannot answer them in a sentence has told you something.
Does the system infer emotion, affect, sentiment or engagement from face, voice, or any other biometric signal — at any point, including in a confidence or authenticity score? Not "do you show it to us." Does it compute it. A derived signal buried in a composite score is still inference.
Where in the flow is the AI disclosure, and what exactly does it say? Ask for the actual string and a screenshot of where it appears. "From the start of the first interaction" is testable.
Which Article 50 duties do you carry as provider, and which land on us as deployer? A vendor who has not separated these has not read the article.
What is recorded for each scored decision, and can we export it? The high-risk logging obligations are deferred, not repealed. A system that cannot produce its evidence today will not learn to by December 2027, and you will be the one asked for it. The useful test is whether each score traces to a specific moment rather than arriving as a free-floating number — which is a good property of a first-round scorecard regardless of what any regulator asks.
Who makes the rejection decision, and where is that enforced in the product? If the answer is that the system can decline a candidate without a person, the deferral has bought you nothing — you have an automated decision in an Annex III use case, and December 2027 arrives eventually.
What changed in your product on 2 August 2026? The honest answers are a specific change or a considered "nothing, because we already did this." A vendor who does not know the date went by has not been watching.
Recio's approach to this is that the evidence behind every score is exportable and a person makes the call, which is a design position rather than a compliance claim — the obligations above sit on any vendor, and the right posture is to make them easy to verify rather than to assert. The same logic runs through what candidates actually object to in AI interviews, which turns out to be much less about the AI than about not being told.
The short version
The deadline that moved was the documentation deadline. The disclosure rule is live. The emotion-recognition prohibition has been live for a year and a half and covers your candidates, not just your employees.
Most of the pages currently ranking for this question are working from the old timeline, and a fair number are still describing emotion analysis as a compliance question rather than a prohibited practice. If you are choosing a vendor this quarter, that is the gap to check them against — not the one in December 2027.
Every date and article number above is linked to its source, including the Commission's own pages, so it is checkable rather than something you have to take on trust. None of it is legal advice, and counsel will have views on the edges — particularly on what counts as "obvious" under Article 50(1). The centre of it is not close to the edges, though: if a product infers emotion from a candidate's face, no reading of the Act makes that fine in the EU.