HR tools built by a senior HR executive · United States

Published standard  ·  Assessments  ·  Contact

The EU AI Act in employment

Most AI used to hire, manage, and monitor people is high-risk under the EU AI Act. That brings a stack of duties, and the deadline for them has just moved. Here is what counts as high-risk, and what is already banned or required today. It also covers the date that keeps shifting and why, and when these rules reach an employer based outside the EU.

How this note is governed

Jurisdiction note. EU.

Applies to Employers deploying automated systems in hiring or people management inside the EU. The high-risk duties are deferred to 2 December 2027. The prohibitions have applied since 2 February 2025.

Short answer

2 December 2027. Most employment AI is high-risk under Annex III. Those duties now apply from 2 December 2027, moved back from 2 August 2026. The bans, including workplace emotion recognition, have applied since 2 February 2025.

Published Last verified

The Digital Omnibus, adopted in June 2026 and signed 8 July 2026, moved the high-risk employment duties from 2 August 2026 to 2 December 2027.

2 Feb 2025
Already in force, whatever happens to the deferral: the ban on certain AI practices, including emotion recognition in the workplace, and the duty to give the people who deal with these systems a basic level of AI literacy. Part of the Act binds employers in the EU today.
2 Dec 2027
The date for the high-risk employment-AI duties. The Digital Omnibus, agreed 7 May 2026 and formally adopted in June 2026 (Parliament 16 June, Council 29 June, signed 8 July 2026), moved them back from 2 August 2026.

Employment AI is high-risk and the deadline just moved

The AI Act puts every system into one of four risk tiers. The first is a short list of banned practices. The second is a larger high-risk category that is allowed but heavily regulated. Then comes a transparency tier for things like chatbots, and everything else, which is left alone. AI used to make or support employment decisions sits, with one exception, in the high-risk tier. Annex III names the employment uses directly. Read this list as the scope of the work, then read the timeline as the part that keeps changing.

  1. Recruitment and selection. Tools that place targeted job ads, source or filter applications, screen resumes, or score and rank candidates. The ordinary hiring-funnel software most teams already run.
  2. Performance and task allocation. Systems that evaluate performance or work behaviour, or that assign tasks and work based on a person’s traits, behaviour, or output.
  3. Worker monitoring. AI that tracks and analyses how people work. Note one carve-out: emotion-recognition monitoring at work is not high-risk, it is banned outright, covered below.
  4. Promotion and termination. Anything that drives a decision to promote someone, change their terms of work, or end the employment relationship.

Two things follow. First, this reaches ordinary HR software, not just exotic systems. A resume screener or an interview-scoring tool is squarely in scope. Second, the duties land on whoever builds the system and, separately, on the employer that uses it. The question most people then get wrong is when.

The EU-focused tool. It inventories your HR and recruiting AI, then classifies each system against the Annex III high-risk list and the banned-practice list. It also tracks readiness against the deployer duties.

EU HR AI Risk Checklist, $99

The dates and why one of them keeps moving

The Act took effect in stages, and the stages matter. Part of it binds you now, while the part most HR teams worry about has been pushed back. Here is the sequence as it stands today.

Milestonewhat the rule coversApplies Banned practices and AI literacyArticle 5 and Article 4, in force now2 Feb 2025 General-purpose AI models, governance, penaltiesthe supervisory machinery, in force now2 Aug 2025 Transparency and content markingArticle 50, moved from 2 Aug 20262 Dec 2026 High-risk employment AI dutiesAnnex III, was 2 Aug 20262 Dec 2027 High-risk AI built into regulated productsAnnex I2 Aug 2028 The Act entered into force on 1 August 2024. The high-risk employment duties were originally set for 2 August 2026. The Digital Omnibus, agreed in political terms on 7 May 2026 and formally adopted in June 2026 (Parliament 16 June, Council 29 June, signed 8 July 2026), moves them to 2 December 2027 and pushes the transparency duty to 2 December 2026. Treat 2 December 2027 as the compliance baseline for the high-risk employment duties, and remember what already applies: the emotion-recognition ban and the AI-literacy duty have been in force since February 2025.

Part of the Act is already in force

The deferral does not buy a clean pause, because two duties already apply and one of them lands directly on the HR stack. Since 2 February 2025 the Act’s list of banned AI practices has been in effect. For employers the one that bites is the ban on emotion-recognition AI in the workplace. It covers systems that infer a worker’s emotions from their face, voice, or body. It also covers sentiment scoring of staff and video-interview tools that read a candidate’s emotional state. These are banned outright, not merely regulated, with narrow exceptions for medical or safety reasons. Check whether that capability sits anywhere in your HR or recruiting software. If it does and you have people in the EU, it is a problem today, not in 2027.

The second live duty is AI literacy. Providers and deployers have to take steps on the people who deal with these systems. Those people must understand, at a basic level, how the systems work and where they can go wrong. It is a light obligation next to the high-risk stack, but it applies now, and it is the cheapest first move toward everything else.

What high-risk status requires and who owes it

When the high-risk duties apply, they form a substantial stack. It starts with a risk management system, plus data governance and quality checks on the data the system learns from and runs on. Next come technical documentation and automatic logging of what the system does. Then transparency and clear instructions for use. Human oversight has to be built in, so a person can understand and override the system. Last is a level of accuracy and robustness fit for the job. The Act splits these between two roles, and an employer needs to know which one it is.

Provider Usually the vendor
The party that develops the system, or puts it on the market under its own name, builds the heavy package. That is the risk management system, the technical file, the conformity assessment, the CE marking, the quality system, and registration in the EU database. For most employers this is the software vendor, not them.
Deployer This is the employer
The employer that uses a high-risk system carries its own duties. Use it according to the instructions. Assign human oversight to people who are competent and have the authority to act on it. Keep the logs and watch how it performs. Before putting it to use at work, inform the affected workers and their representatives. Some deployers must also run a fundamental-rights impact assessment first.
Workers and candidates The people affected
A person subject to a decision made or supported by a high-risk system has a right to a clear explanation. It must cover the role the AI played and the main factors behind the decision. The transparency runs to the individual, not only to the regulator.
AI literacy Both roles, now
The duty to ensure a working level of AI literacy falls on providers and deployers alike, and unlike the high-risk stack it already applies. It is the one obligation that does not wait for 2027.

Here is the short version for an HR team. Even if you only buy a tool off the shelf, you are the deployer, and the deployer duties are yours. You cannot hand them to the vendor in a contract.

When this reaches an employer outside the EU

The Act does not stop at the EU border, but it does not reach every company on earth either. It applies to an employer outside the EU in two situations. The first is operating in the EU. If you have staff, a subsidiary, a branch, or remote employees in a member state, the rules cover the AI you use on them. The second is the output test. If the result your AI system produces is used on people in the EU, you are in scope even without an EU office. That is what catches a company based elsewhere screening or scoring candidates located in the EU. A purely domestic employer hiring only people based at home, with a tool used only on people based at home, is outside the Act. The line is not where your headquarters sits. It is where your people, and the people your AI judges, are.

Four ways employers read this wrong

  • Treating the new deadline as a reason to wait.Two duties already apply, including the ban on emotion-recognition AI at work and the literacy obligation, and they reach the HR stack now. Building governance for high-risk systems takes far longer than the runway you gain, and December 2027 arrives faster than a procurement, audit, and oversight build.
  • Assuming a vendor tool is the vendor’s problem alone.The Act gives the deployer its own duties. Those are human oversight by competent people, monitoring, logging, informing affected workers, and in some cases a fundamental-rights impact assessment. Buying off the shelf does not move those to the vendor.
  • Counting only EU-headquartered companies.The Act reaches you if you have staff in the EU or your AI output is used on people in the EU. A recruiter based elsewhere who scores EU-based candidates is in scope, headquarters notwithstanding.
  • Reading high-risk as forbidden.High-risk means allowed but regulated, not banned. The only employment AI banned outright is emotion recognition in the workplace under the prohibited-practices list. Everything else on the Annex III list is permitted once the duties are met.

Six red flags to check before you fire someone

Free, and written to the same standard

A five minute screen to run before you act, sent to your inbox as a print-ready PDF. Every figure in it traces to a reference note like this one.

Where these figures come from

4 citations checked, newest check 21 July 2026
  1. Regulation (EU) 2024/1689, the AI Act, the text in the Official Journal. The source for the framework. It carries the risk tiers and the prohibited practices in Article 5, including emotion recognition in the workplace. It also carries the employment uses listed as high-risk in Annex III and the provider duties. The deployer duties sit in Article 26 and the transparency duty in Article 50. Adopted 13 June 2024, in force 1 August 2024. eur-lex.europa.eu, Regulation (EU) 2024/1689 eur-lex.europa.eu Checked 21 July 2026
  2. European Commission, AI Act, "Shaping Europe’s digital future". The official application timeline. Prohibited-practice and AI literacy duties run from 2 February 2025. The general-purpose AI and governance rules run from 2 August 2025. It also covers the high-risk regime and confirms that a political agreement on the AI Omnibus simplification package was reached on 7 May 2026. digital-strategy.ec.europa.eu, regulatory framework for AI digital-strategy.ec.europa.eu Checked 21 July 2026
  3. European Commission, AI Act Service Desk, frequently asked questions. Sets out the original staggered dates. Prohibitions and AI literacy landed on 2 February 2025. Governance and general-purpose AI model rules landed on 2 August 2025. The Annex III high-risk obligations, the Article 50 transparency requirements, and the start of enforcement all fell on 2 August 2026. ai-act-service-desk.ec.europa.eu, FAQ ai-act-service-desk.ec.europa.eu Checked 21 July 2026
  4. The Digital Omnibus deferral, Gibson Dunn analysis, May 2026. The deferral layer. The package postpones the standalone Annex III high-risk obligations to 2 December 2027, and the Annex I embedded duties to 2 August 2028. Formally adopted in June 2026, with Parliament on 16 June and Council final approval on 29 June. It was signed 8 July 2026, with publication in the Official Journal and entry into force following. gibsondunn.com, EU AI Act Omnibus agreement gibsondunn.com Checked 21 July 2026

Common questions

Does the AI Act apply to a company based outside the EU?

It can. Two situations bring a non-EU employer into scope. One is operating in the EU, meaning staff, a subsidiary, a branch, or remote employees based in a member state. The other is the output test. If the result your AI system produces is used on people in the EU, you are covered even without an EU office. A recruiter scoring candidates located in the EU is the common example. An employer hiring only people based outside the EU, with a tool used only on them, is outside the Act.

The high-risk deadline moved to 2027, so can we wait?

No. The ban on emotion-recognition AI at work and the AI literacy duty have applied since February 2025, and they reach the HR stack now. The Digital Omnibus moves the high-risk duties to 2 December 2027. It was formally adopted in June 2026, with Parliament on 16 June and Council on 29 June. It was signed on 8 July 2026, so that is the operative planning date. And the work of governing high-risk systems takes far longer than the time you gain. The safe move is to scope and start now.

We only use a vendor’s hiring tool. Are we still covered?

Yes, as the deployer. The vendor that builds and sells the system carries the provider duties. The employer that uses it carries its own. Use it according to the instructions. Assign human oversight to competent people who can act on it. Keep the logs, monitor it, and inform affected workers before putting it to use. Some deployers must run a fundamental-rights impact assessment as well. Those duties cannot be signed away to the vendor.

Does high-risk mean the tool is banned?

No. High-risk means allowed but regulated. The system is permitted once the duties are met. The only employment AI banned outright is emotion recognition in the workplace, which sits on the separate prohibited-practices list, not the high-risk list. A resume screener or a performance-scoring tool is high-risk, not forbidden. This is general information.

Put it to work

  • The EU-focused tool. It inventories your HR and recruiting AI, then classifies each system against the Annex III high-risk list and the banned-practice list. It also tracks readiness against the deployer duties.

    $99
  • The broader policy version. It is a ready-to-adapt AI-use policy plus a per-tool risk assessment, a vendor due-diligence questionnaire, and a decision record. It covers the US federal and state layer alongside the EU.

    $89

This note is general information about employment practice rather than legal advice for your situation. Check the review date and the jurisdictions above, follow the source link, and confirm the rule before you act on it.

From evidence to action

Use the note to make the next decision.

A reference note establishes scope and authority. The useful next move is to test the facts, install the operating method, or review the live situation.

01 · Test

Run a related calculator

Put your own facts into the method instead of relying on a general example.

Open the analysis →
02 · Implement

EU HR AI Risk Checklist

Move from the rule or method into an editable operating document.

See the operating path →
03 · Apply

Use the matched tool

The kit or calculator built for this issue carries the evidence into a file you can run.

Browse the tools →