Regulation

The EU AI Act's HR deadline is days away — and Brussels just blinked

High-risk obligations for hiring and workforce AI apply from August 2. A proposed deferral is muddying the water. Here's what actually applies, to whom, and what to do either way.

On August 2, 2026, the EU AI Act's obligations for high-risk AI systems become applicable — and employment is squarely in the high-risk category. AI used for recruitment and candidate selection, performance evaluation, task allocation, worker monitoring, and promotion or termination decisions falls under the regime.

For HR, this is the AI Act's center of gravity. And ten days out, two things are true at once: the deadline is real, and Brussels is wobbling.

What actually applies from August 2

If your organization deploys high-risk AI in employment — you don't have to build it; using a vendor's tool counts — the core duties are:

Penalties for deployers who fail high-risk obligations reach €15 million or 3% of global annual turnover, whichever is higher.

The reach is wider than many US leaders assume: no EU entity is required. If AI outputs are used in the EU — recruiting EU candidates, evaluating EU-based workers or contractors, or running a global HR tool your EU teams use — a US employer can be covered.

The wobble: the Digital Omnibus

The European Commission's proposed Digital Omnibus package would defer some high-risk obligations. That has led some vendors — and some advisors — to counsel waiting.

Here is the practitioner's read: a proposal is not a law. As of this writing, the deferral has not been adopted, August 2 stands, and a narrow subset of obligations was already scheduled for 2027 anyway. Betting your compliance posture on pending legislation is a decision you'd have to defend later — to a regulator, a works council, or a plaintiff's lawyer.

The deadline may move. The direction will not. Every deferred obligation is still coming.

The CHRO playbook — worth doing even if the deadline slips

  1. Inventory. Every AI touching EU candidates or workers, including features quietly switched on inside your ATS, HRIS, and monitoring tools. Ask vendors directly: which of your features are high-risk under the Act, and where is your conformity documentation?
  2. Classify and assign. For each system: high-risk or not, provider or deployer role, and a named accountable owner. (HR owns this — don't let it default to IT.)
  3. Stand up worker notice. The duty to inform workers and their representatives before deployment is the obligation most organizations have simply not built. It's also the cheapest to fix.
  4. Design real oversight. Document who can override the system, how often they actually do, and what happens when they disagree with it. An override rate of zero is not oversight; it's decoration.
  5. Get vendor attestations in writing. Consolidating vendors (see this week's market analysis) are renegotiating anyway — fold AI Act warranties into every renewal.

None of this is wasted work under any deferral scenario. All of it is table stakes under the law as it stands. That asymmetry is the whole decision.

Walk into Monday already knowing.

The weekly signal: what changed in HR tech, what it means, what to do. Free forever — founding readers lock the founding rate when Pro launches.

No spam. Unsubscribe anytime.