Back to blog

EU AI Act and AI Hiring: What Applies Now

The August 2026 high-risk deadline moved to December 2027. But three obligations already bind anyone screening candidates with AI in the EU. Here is which.

Person in a dark suit holding a tablet and touching a glowing holographic dashboard of charts and gauges

If you screen candidates with AI and you hire in the EU, you probably saw a wave of posts about a 2 August 2026 compliance deadline.

That deadline moved. The obligations that actually bind you today are not the ones most of those posts were about.

Here is the corrected picture, and what an SMB hiring team should do about it.

What changed in June 2026

On 29 June 2026, the Council of the EU gave final approval to the Digital Omnibus on AI. It deferred the high-risk obligations under Annex III by roughly 16 months.

New date for standalone high-risk systems, including recruitment tools: 2 December 2027. AI embedded in regulated products under Annex I moves to 2 August 2028.

The reason was readiness, not a change of heart. The harmonised technical standards from CEN-CENELEC were behind schedule, Commission guidelines were still in draft, and several member states had not resourced their market surveillance authorities. The deadline assumed an ecosystem that did not exist yet.

Sources worth reading in full: Gibson Dunn on the omnibus agreement, Freshfields on the final text, and Travers Smith on the agreed delay.

What still applies today

Three things are live right now. None of them were deferred.

1. The Article 5 prohibitions, since February 2025

Some uses are banned outright, not regulated. The one that matters most in hiring: AI that infers emotions in the workplace.

That covers video interview tools that claim to read confidence, enthusiasm, or honesty from a face or a voice. This has been prohibited since 2 February 2025.

If a vendor pitches you sentiment scoring on interview recordings, the correct response is to end the demo.

2. Article 50 transparency, since August 2026

The transparency obligations did take effect on 2 August 2026. In hiring terms, people should know when they are interacting with an AI system rather than a person.

Practically: if a chatbot screens applicants, say so. If AI drafts your rejection emails, do not present them as personally written.

3. GDPR, the whole time

The AI Act sits on top of GDPR. It does not replace it. Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects, and a rejected job application can qualify.

This is the obligation most SMB teams already breach without noticing, and it has nothing to do with the new deadline.

What this means for how you screen

The deferral buys time on documentation and conformity assessment. It changes nothing about the design principle that keeps you safe under both regimes.

AI ranks and flags. A person decides and can explain why.

That is not a legal opinion, it is an operating rule. Three habits make it real:

  • Publish your criteria before you screen. Decide what disqualifies someone, in writing, before applications arrive. Applying the same standard to every applicant is also what EEOC guidance asks of US employers, so this travels well across jurisdictions.
  • Keep the reason, not just the outcome. “Rejected” is a data point. “Rejected: no EU work authorisation, which was a published requirement” is a defensible record.
  • Never let a score be the only input. A percentage with no human review is exactly the shape Article 22 is aimed at.

More on the practical side of this in responsible AI in recruiting and AI candidate scoring without bias.

How Canvider is built around this

We designed for the human-in-the-loop rule because it is good practice, not because a deadline forced it.

  • CriteriaMatch evaluates up to five criteria you define per job, returning a pass or fail with a confidence level. You set the criteria. You see why each candidate passed or failed.
  • AI Score produces a ranking with written strengths and gaps, not a black box number. Nothing is auto-rejected.
  • DecisionHelper compares 2 to 4 finalists and gives a structured recommendation your team can accept, override, and record.

We do not do emotion recognition. We do not auto-reject. Every score has a written rationale attached to the candidate record, which is what turns a decision into something you can explain eighteen months later. That is the point of keeping a decision history.

The honest summary

You have until December 2027 on the heavy documentation. You have zero runway on the prohibitions, on transparency, and on GDPR.

If your process already logs published criteria and a written reason for every rejection, the 2027 deadline will be paperwork. If it does not, the deadline is not your problem. Your process is.

This is a summary for hiring teams, not legal advice. Regulatory dates have already moved once. Confirm current requirements with counsel before you rely on them.

Get started free

Frequently asked questions

Is AI resume screening high-risk under the EU AI Act?

Yes. Annex III classifies AI used for recruitment and selection as high-risk, including systems that filter applications and evaluate candidates. The classification did not change. What changed is when the high-risk obligations start applying, which is now 2 December 2027 for standalone systems.

Did the August 2026 AI Act deadline actually happen?

Not for high-risk recruitment tools. The Council of the EU approved the Digital Omnibus on AI on 29 June 2026, deferring standalone Annex III obligations by roughly 16 months to 2 December 2027. Article 50 transparency obligations did begin on 2 August 2026, and the Article 5 prohibitions have applied since 2 February 2025.

Can I use AI to score candidates in the EU right now?

Yes, provided you stay clear of the practices banned under Article 5 and meet your GDPR obligations. GDPR applies independently of the AI Act, including Article 22 on automated decision-making. The practical rule is that AI can rank and flag, but a person makes the decision and can explain it.

Is emotion recognition in video interviews allowed?

No. Article 5 prohibits AI systems that infer emotions in the workplace, and that ban has been in force since 2 February 2025. It is not deferred. If a vendor is selling you sentiment or facial expression analysis of interview recordings, that is a red flag, not a feature.