Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page

The Deadline Has Already Passed β€” Now Comes the Enforcement

On August 2, 2026, the core high-risk obligations of the European Union’s AI Act became legally binding. For most industries this was a distant compliance milestone. For HR departments, it was something closer to a reckoning: recruitment platforms, CV screening tools, candidate ranking algorithms, performance evaluation systems, and even AI used in termination decisions were pulled directly into the EU’s strictest AI regulatory category. That deadline is now a few weeks behind us, and the shift from “get ready” to “prove you’re compliant” has already begun.

The timing collides with a workplace AI boom that shows no sign of slowing. Just over a third of organizations now use AI somewhere in their HR function, and more than half of talent leaders say they plan to add autonomous AI agents to their teams before the end of 2026. The result is a widening gap between how fast HR is adopting AI and how ready HR is to govern it.

⚑ TL;DR
Since August 2, 2026, HR systems used for recruitment, CV filtering, candidate ranking, and performance evaluation are classified as “high-risk” under the EU AI Act, requiring bias testing, human oversight, and detailed logging. The rules apply to any company hiring for EU-based roles, regardless of where the employer is headquartered. Yet fewer than half of organizations have a formal AI policy, and most HR functions aren’t even part of their own company’s AI strategy conversations.

What Actually Changed on August 2

The EU AI Act classifies AI systems into risk tiers, and Annex III, Section 4 of the Act explicitly names employment-related AI as high-risk. That covers a wider net than most HR leaders initially assumed:

  • Recruitment and candidate sourcing tools
  • CV and resume screening or filtering software
  • Candidate ranking and scoring algorithms
  • Performance evaluation and monitoring systems
  • Tools that inform promotion, termination, or contract-related decisions

From August 2, 2026, providers of these systems face obligations under Articles 9 through 17 β€” covering risk management systems, data governance, technical documentation, and record-keeping. Employers deploying them face parallel obligations under Article 26, including human oversight, monitoring for malfunction, and informing affected workers before an AI system is used in a decision that affects them.

A European Commission proposal floated in late 2025 to delay parts of this timeline β€” sometimes referred to as the “Digital Omnibus” β€” has created some confusion, but the prevailing guidance among compliance advisors is unambiguous: treat August 2026 as the operative deadline. Proposed deferrals are not law until adopted, and enforcement bodies have given no indication they intend to pause.

Yes, This Applies to You Even Outside the EU

The AI Act’s territorial reach is broader than many non-European employers realize. The regulation applies wherever an AI system is placed on the EU market, used within the EU, or produces outputs that affect people located in the EU. In practice, that means a recruiting team in London, New York, or Singapore screening candidates for an EU-based role β€” or using an AI tool built by an EU vendor β€” falls squarely within scope, regardless of where the parent company is headquartered.

πŸ’‘ Pro Tip: Don’t audit your AI Act exposure by asking “do we operate in the EU?” Ask instead: “does any role we’re hiring for sit in the EU, and does any tool in our hiring or performance-review stack use automated scoring, ranking, or filtering?” Multinational employers are routinely surprised to find EU exposure through a single regional hire, a shared global ATS, or a vendor’s default configuration.

The Governance Gap Regulators Will Find First

The uncomfortable reality is that HR’s AI governance maturity has not kept pace with its AI adoption. Recent industry research paints a clear picture of where the gaps sit:

  • Just under half of organizations using workplace AI have a formal AI policy in place at all.
  • 57% of HR professionals working in jurisdictions that already have AI-related legislation say they were unaware of the specific rules that applied to them.
  • Recruiting is the single largest AI use case in HR β€” the exact function the EU AI Act treats as highest-risk β€” with roughly 27% of organizations already applying AI there.
  • In most companies, IT β€” not HR β€” drives AI strategy, with HR functions playing a supporting or even excluded role in decisions about tools HR itself will be legally accountable for using.

That last point matters most for compliance purposes. Under Article 26, the deployer β€” typically the employer, not the software vendor β€” carries direct obligations for human oversight and worker notification. An HR team that adopted a recruiting tool it didn’t select and doesn’t fully control is still the party regulators will hold accountable if that tool makes an unlogged, unreviewed hiring decision affecting an EU candidate.

A Practical Compliance Checklist for the Weeks Ahead

For HR and legal teams working through post-deadline remediation, four workstreams are worth prioritizing immediately:

  • Inventory every AI touchpoint in the employee lifecycle. Recruiting, screening, interview scheduling and scoring, performance management, and workforce analytics tools should all be catalogued with their vendor, purpose, and decision authority documented.
  • Run bias testing on high-risk systems, not just a fairness statement from the vendor. Article 9’s risk-management requirements expect ongoing testing, not a one-time certification obtained at purchase.
  • Establish real human oversight, not a rubber stamp. Regulators are specifically looking for evidence that a human reviewer can meaningfully override an AI-driven hiring or performance decision β€” not merely click “approve.”
  • Notify affected workers and candidates. Article 26 requires informing people when a high-risk AI system is used in a decision affecting them. Standard job postings and offer letters in many companies still don’t include this disclosure.
⚠️ Warning: Waiting for final clarity on the proposed “Digital Omnibus” delay before acting is a risky bet. The proposal has not been adopted, enforcement authorities have signaled no pause, and remediation β€” inventorying tools, testing for bias, documenting oversight β€” takes months, not weeks. Treat any further delay as a bonus, not a plan.

Where This Leaves Employers Heading Into 2027 Planning

The EU AI Act’s August 2026 deadline is arriving at the same moment HR departments are racing to deploy agentic AI β€” autonomous systems that don’t just screen a resume but actively manage parts of the hiring or performance process end to end. That combination raises the stakes considerably: the more autonomous the system, the harder “meaningful human oversight” becomes to demonstrate, and the more scrutiny it will attract from regulators looking for the first enforcement cases under the new regime.

For HR leaders, the strategic takeaway isn’t to slow AI adoption β€” the productivity gains are real, with the large majority of adopters reporting efficiency and quality improvements. It’s to make sure HR has a seat at the table where AI tools are selected and governed, rather than inheriting compliance obligations for systems it didn’t choose. Companies that close that gap now will spend 2027 scaling AI in HR with confidence. Those that don’t may spend it explaining themselves to a regulator instead.


Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading