Back to Blog
Industry Trends

EU AI Act Hiring Deadlines After the Digital Omnibus: The Real Timetable

CVSense® InsightsCircle
2 views
0 comments
Share:
EU AI Act Hiring Deadlines After the Digital Omnibus: The Real Timetable

Recruitment AI is high-risk under Annex III of the EU AI Act, but the obligations moved from 2 August 2026 to 2 December 2027 under the Digital Omnibus. The corrected timetable, whether it reaches a UK recruiter, and why UK law already requires most of it.

AI used for recruitment and selection is high-risk under Annex III of the EU AI Act. The obligations that attach to that classification were originally due to apply from 2 August 2026. They now apply from 2 December 2027, following the Digital Omnibus amendment. A great deal of published guidance still quotes the old date, so if your compliance plan was built around August 2026 it is working from a superseded timetable.

The extension is not permission to stop. It is roughly sixteen additional months to do work that most organisations had not started.


The Corrected Timetable

The Act entered into force on 1 August 2024 with staggered application. Prohibited practices and general provisions have applied since 2 February 2025. Rules on general-purpose AI models, governance and penalties have applied since 2 August 2025. Those dates are unchanged.

What moved is Chapter III, the substantive obligations for standalone high-risk systems listed in Annex III, which includes AI used in employment, recruitment and worker management. Those now apply from 2 December 2027. High-risk AI embedded in regulated products under Annex I, such as medical devices and machinery, moves to 2 August 2028. Transparency and synthetic content marking obligations were also adjusted, with compliance due on 2 December 2026.

Note the shape of that: the transparency requirements land a full year before the high-risk requirements. An organisation that plans only for December 2027 will miss an earlier obligation.


Does This Reach a UK Employer at All?

Frequently, yes, and the reason is territorial scope rather than establishment. The Act applies to providers placing systems on the EU market and to deployers established in the EU, and it can reach organisations outside the EU where the output of the system is used in the EU.

Concrete situations where a UK recruiter should assume engagement.

  • You screen candidates for roles located in an EU member state.
  • You supply shortlists to EU-based clients who rely on them for selection.
  • You operate a group with EU entities using your screening process.
  • You build screening technology and make it available to EU customers, which puts you in the provider role rather than the deployer role.

A UK agency placing only UK roles for UK clients is a different analysis. The distinction is worth establishing in writing rather than assuming, because provider obligations are materially heavier than deployer obligations.


What the High-Risk Obligations Involve

Providers of high-risk systems carry the bulk of the burden: a risk management system, data governance covering training and testing data, technical documentation, logging, accuracy and robustness requirements, human oversight design, a quality management system, conformity assessment and registration.

Deployers carry a lighter but real set. Use the system in accordance with instructions. Assign human oversight to people with the competence and authority to exercise it. Monitor operation and report serious incidents. Keep logs. Inform workers and their representatives before putting a high-risk system into use in the workplace. And where the system makes decisions about people, inform those people.

The Obligation Most Often Overlooked

Informing workers and their representatives before deployment is a discrete duty, separate from anything in data protection law, and it is easy to miss because it sits outside the usual privacy workflow.


The UK Position Is Not a Gap

The United Kingdom has no equivalent AI statute, which sometimes gets read as an absence of regulation. It is not. UK GDPR and the Data Protection Act 2018 already constrain automated decision-making, including rights relating to decisions taken solely by automated means, the requirement for a lawful basis, and data protection impact assessments for high-risk processing.

The Equality Act 2010 already prohibits discriminatory selection however it is produced, and a screening process that disadvantages a protected group is unlawful whether a human or a model created the disadvantage. Public bodies carry the public sector equality duty under section 149 on top.

The result is that a UK recruiter with no EU exposure still needs documented lawful basis, a completed impact assessment, meaningful human review, explainable outputs and an equality analysis. That is most of what an EU deployer needs. Building it once serves both.


Using the Extra Time Sensibly

  1. Establish your role. Provider, deployer, or out of scope, in writing, per system. Everything downstream depends on this and it is the step most often skipped.
  2. Inventory your systems. Including the ones nobody registered as AI, such as a scoring feature inside an ATS or a sifting tool a single team adopted.
  3. Fix the December 2026 transparency obligations first. They arrive a year earlier than the rest.
  4. Make human oversight real. A reviewer who cannot in practice overturn a score is not oversight. Name the people, define their authority, and record interventions.
  5. Get explainability from your vendor now. A system that cannot explain why a candidate scored as they did will not satisfy the Act, UK GDPR or a tribunal. Ask for a per-candidate rationale you can export.
  6. Document the equality analysis. Under the Equality Act this is already required and does not wait for 2027.
  7. Get contractual commitments. Suppliers should commit to conformity by the applicable date and to providing the documentation and logs you need as a deployer.


Frequently Asked Questions

Has the EU Weakened the AI Act?

The Digital Omnibus changed application dates and made some adjustments. The high-risk classification of recruitment AI under Annex III remains. Treat this as a timing change rather than a change of direction.

Which Date Applies to Us?

For standalone Annex III high-risk systems including recruitment, 2 December 2027. For transparency and synthetic content marking, 2 December 2026. For prohibited practices, already in force. For general-purpose AI model rules, already in force.

Is CV Screening Definitely High-Risk?

Annex III covers AI intended to be used for recruitment or selection, including for filtering applications and evaluating candidates. Screening sits within that description. The narrow exemptions are just that, narrow, and should be assessed rather than assumed.

Does a Human Reviewing the Output Remove the Classification?

No. Human involvement affects the analysis of solely automated decision-making under data protection law, and it is a required safeguard under the Act. It does not remove the high-risk classification.

Where Should a UK Recruiter With No EU Exposure Start?

With UK GDPR and the Equality Act, because those obligations already apply. A documented lawful basis, a completed impact assessment, explainable per-candidate scoring and an equality analysis are required now, and they also form the foundation of EU readiness if your footprint changes.


What to Take From This

Correct the date in your plan, then note that the earlier transparency deadline still lands in December 2026. Beyond that, the useful insight is how much of the EU framework the UK already requires through data protection and equality law.

The organisations that will find December 2027 straightforward are not the ones that waited for it. They are the ones that built documented lawful basis, genuine human oversight and explainable scoring because UK law already expected it.

This article is general information about a fast-moving regulatory position, not legal advice. Dates have already changed once. Take specialist advice on your own systems and territorial exposure.


Sources

Publications Office of the European Union. Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence.
https://eur-lex.europa.eu/eli/reg/2024/1689/oj

EU Artificial Intelligence Act. Annex III: High-Risk AI Systems Referred to in Article 6(2).
https://artificialintelligenceact.eu/annex/3/

Information Commissioner's Office. Rights Related to Automated Decision Making Including Profiling.
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/rights-related-to-automated-decision-making-including-profiling/

Information Commissioner's Office. Guidance on AI and Data Protection.
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/

Information Commissioner's Office. Data Protection Impact Assessments.
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/

The Stationery Office. Data Protection Act 2018.
https://www.legislation.gov.uk/ukpga/2018/12/contents

The Stationery Office. Equality Act 2010.
https://www.legislation.gov.uk/ukpga/2010/15/contents

The Stationery Office. Equality Act 2010 Section 149: Public Sector Equality Duty.
https://www.legislation.gov.uk/ukpga/2010/15/section/149


InsightCircle

Comments

Start the discussion

Be the first to comment on this article.

Loading comments…
Powered by CVSense InsightsCircle

Follow @CVSense on LinkedIn

Get recruitment best practices, career guides, and insights that can help you succeed.

Tags
#EUAIAct#AIcompliance#automateddecisionmaking#UKGDPR#recruitmenttechnology

Supercharge Your Job Search with CVSense

Apply to jobs faster and smarter with CVSense. Tailor your CV to any job description, get AI-powered recommendations, and land more interviews.

Start Landing Job Interviews

More Articles You Might Like