Under the EU AI Act, AI systems used for recruitment and selection — screening applications, filtering candidates, scoring tests, evaluating interviews — are classified as high-risk, which means their providers and the employers who deploy them must meet binding requirements for risk management, data governance, transparency, human oversight, and accuracy monitoring. Those obligations were due to bite on 2 August 2026. In July, sixteen days before the deadline, the EU moved it: the Digital Omnibus regulation, in force since 27 July 2026, pushed compliance for stand-alone high-risk systems (the Annex III list that covers hiring) to 2 December 2027.
If your reaction is relief, look closer. The deferral changed the date, not the destination — and several obligations that touch hiring AI didn't move at all.
What actually changed in July 2026
The original AI Act timeline gave high-risk systems until 2 August 2026. The European Commission proposed a deferral in November 2025, arguing that technical standards weren't ready. After trilogue negotiations that stretched into late April, Parliament endorsed the compromise on 16 June 2026, the Council approved it on 29 June, and the regulation entered into force on 27 July.
The headline changes:
- Annex III high-risk systems — including recruitment, candidate selection, promotion and termination decisions, task allocation, and worker monitoring — now have until 2 December 2027.
- Annex I systems (AI embedded in regulated products such as machinery and medical devices) moved from August 2027 to August 2028.
- The dates are fixed. An earlier proposal to tie the deadline to the availability of harmonised standards was dropped, so there is no further conditional extension to hope for.
- The EU AI Office gained expanded supervisory powers — investigations, inspections, binding commitments, and fines — signalling that enforcement capacity is being built during the deferral, not after it.
Sixteen extra months sounds generous. For organisations that hadn't started, it is roughly the minimum time needed to do the work properly.
What did not move
Three sets of obligations are already live or arriving on schedule, and each one touches hiring:
Prohibited practices have applied since February 2025. Emotion recognition in the workplace, social scoring, and manipulative systems are banned outright, with penalties of up to €35 million or 7% of global annual turnover, whichever is higher. If any tool in your hiring stack claims to infer emotional state from a candidate's face or voice, that is not a 2027 problem. It is a now problem.
AI literacy obligations also date from February 2025. Organisations must support the AI competence of staff who operate AI systems. The Omnibus softened the wording, but the duty stands — and recruiters who cannot explain what their screening tools do remain a liability.
Article 50 transparency duties arrived on 2 August 2026, largely unaffected by the deferral. Users must be told when they are interacting with an AI system, and AI-generated content must be labelled. A candidate talking to a chatbot scheduler or an AI interviewer has a right to know.
The pattern is clear: the EU deferred the paperwork-heavy conformity obligations, but kept the bans, the transparency floor, and the enforcement build-out on schedule.
Why this matters far beyond Europe
The AI Act has extraterritorial reach. A provider or deployer outside the EU is covered when its system's output is used in the Union — which puts Indian GCCs screening candidates for European roles, assessment vendors selling into EU clients, and multinationals running global hiring platforms squarely in scope. If your organisation runs one recruitment stack worldwide, the EU rules effectively become its floor.
And the EU is not regulating alone. Illinois's HB 3773 took effect on 1 January 2026, requiring notice to candidates and prohibiting discriminatory use of AI in employment decisions. New York City's Local Law 144 has mandated bias audits of automated employment decision tools since 2023. Colorado's AI Act, after its own delay, targets algorithmic discrimination in consequential decisions including hiring. The direction of travel is uniform even where the details differ: if AI influences who gets hired, you must be able to show what it measured, how it was validated, and where a human was accountable.
What "high-risk" actually requires of hiring AI
Strip away the legal scaffolding and the Annex III requirements are, at their core, assessment science made mandatory:
- Risk management and data governance — know what your training and scoring data contain, and whether they import historical bias.
- Accuracy, robustness, and bias monitoring — evidence that scores mean what you claim, across demographic groups, not just at launch but continuously.
- Human oversight — a person with the competence and authority to review and overrule the system's output.
- Logging and documentation — records that let an auditor reconstruct why a candidate was scored the way they were.
- Transparency to affected people — candidates told that AI is involved and what it evaluates.
None of this should frighten teams using well-built assessment tools, because it describes what a defensible assessment already does. A structured test with published constructs, documented scoring rubrics, and adverse-impact monitoring is most of the way there. What the law actually threatens is the opaque end of the market: résumé-ranking black boxes, personality inference from video, "culture fit" scores nobody can explain.
This is also why explainable signals beat verdicts. AssessAll's approach reflects that logic: its AI proctoring reports integrity bands — graded, reviewable evidence about test-session integrity — rather than unilateral cheating verdicts, and its AI-graded scenario responses score against defined rubrics a human can inspect and override. That is the shape regulators are converging on: AI that informs an accountable human decision, with the reasoning on the record.
How to spend the sixteen months
Treat December 2027 as a delivery date, not a snooze button.
First, inventory. List every tool in your hiring and talent process that uses AI — sourcing, parsing, screening, testing, interviewing, proctoring. Classify each against Annex III. Most organisations find more in-scope systems than they expected.
Second, interrogate your vendors. Providers carry the heaviest obligations, but deployers must verify. Ask for technical documentation, validation evidence, bias-audit results, and the human-oversight design. A vendor who cannot produce these in 2026 will not conjure them by late 2027 — and switching assessment platforms mid-compliance-cycle is far more painful than switching early. Pay-as-you-go models such as AssessAll's (credits at ₹30/US$0.50, with free credits on signup) make it inexpensive to pilot a compliant alternative before committing.
Third, build the oversight layer. Decide who reviews AI-influenced decisions, on what evidence, with what authority to overrule. Train them — that is your AI-literacy obligation working for you.
Fourth, start the audit trail now. Logging, versioning, and adverse-impact monitoring generate their value over time. A system switched on in November 2027 has no history to show.
The takeaway
The EU moved the high-risk deadline to December 2027, but the bans, transparency duties, and enforcement machinery are already in place — and every serious jurisdiction is converging on the same demand: hiring AI that can show its work. Organisations that use the deferral to build explainable, human-overseen, well-documented assessment will not just be compliant; they will be running better hiring.