The EU AI Act and HR in 2026: What Applied on August 2, What Moved to 2027, and What Employers Should Do Now
What Changed for HR Under the EU AI Act on August 2, 2026?
Less than most HR teams expected. The Digital Omnibus on AI, published in the Official Journal on July 24, 2026 and in force from July 27, 2026, moved the high-risk obligations for employment and worker-management AI from August 2, 2026 to December 2, 2027. What did apply on August 2, 2026 were the Article 50 transparency duties: chatbot disclosure, labelling AI-generated content, and notice to workers exposed to emotion recognition. Since February 2, 2025, prohibited practices, including emotion recognition in the workplace, have been banned and the AI literacy duty has applied.
Moved is not cancelled. This post sets out the timeline, what counts as high-risk in HR, who the rules bind, and how a 20 to 200 person employer should spend the extra 16 months.
Quick definition: The EU AI Act is the European Union's law on artificial intelligence. It bans a short list of AI practices, applies strict duties to high-risk uses such as recruitment, promotion, termination, task allocation and worker monitoring, and requires transparency for chatbots and AI-generated content. It binds any employer using AI on workers or candidates in the EU.
What Is the EU AI Act Timeline for HR Teams?
The Act took effect on August 1, 2024 with a staggered rollout. The Omnibus (Regulation (EU) 2026/1744) rewrote two dates and left the rest alone, per the European Commission's announcement.
DateWhat appliesHR relevanceStatus February 2, 2025Prohibited practices (Article 5) and the AI literacy duty (Article 4)Emotion recognition at work banned except for medical or safety reasons; staff using AI need appropriate trainingIn force, unchanged August 2, 2025General-purpose AI model rules, governance bodies, penalty regimeMostly a duty on model providers, not employersIn force, unchanged August 2, 2026Article 50 transparency dutiesDisclose HR chatbots, label AI-generated media, inform workers exposed to emotion recognition or biometric categorisationIn force, unchanged by the Omnibus December 2, 2026Grace period ends for marking content from generative systems already on the market before August 2, 2026Check that any AI writing tool you use marks its outputNew date December 2, 2027High-risk obligations for stand-alone Annex III systems, including employmentCV screening, ranking, targeted ads, promotion, termination, task allocation, monitoringMoved from August 2, 2026 August 2, 2028High-risk obligations for AI embedded in regulated products (Annex I)Rarely relevant to HRMoved from August 2, 2027The delay happened because the technical standards vendors need to certify against were not ready, and the Omnibus was fast-tracked to beat the August date, as Ogletree Deakins traced through the spring.
Which HR Uses of AI Are High-Risk, Limited-Risk, or Prohibited?
Annex III, point 4 lists the employment uses that count as high-risk. The table maps common HR tools against the tiers that matter to an employer.
HR use of AICategoryWhat it means for you Screening or filtering CVs and applicationsHigh-riskFull deployer duties from December 2, 2027 Ranking or scoring candidatesHigh-riskSame as above, including human oversight and worker notice Placing targeted job advertisementsHigh-riskApplies even if the AI sits inside the ad platform Decisions on promotion, termination, or contract termsHigh-riskA human must be able to override the output Allocating tasks based on behaviour or personal traitsHigh-riskCommon in gig, logistics, and call-centre scheduling tools Monitoring or evaluating worker performanceHigh-riskProductivity scoring and automated performance flags qualify HR chatbot answering policy or leave questionsLimited-risk (Article 50)Tell users they are talking to AI; in force since August 2, 2026 Emotion recognition of workers or candidates (video interview mood analysis, sentiment monitoring)ProhibitedBanned since February 2, 2025, except for medical or safety reasons Biometric categorisation inferring race, beliefs, union membership, or sexual orientationProhibitedBanned since February 2, 2025One nuance: the Act exempts listed systems that only perform narrow procedural tasks, such as sorting applications by date. A system that scores or ranks people is not narrow, whatever the vendor calls it.
Who Does the EU AI Act Apply To?
The Act separates providers, who build or sell the AI system, from deployers, who use it. An employer running an ATS with AI screening is a deployer. The vendor is the provider and carries the heavier load: risk management, technical documentation, conformity assessment, and registration in the EU database. Your job is to use the system properly.
Location does not save you. The Act covers providers placing systems on the EU market regardless of where they are established, per Jones Walker's analysis, and it covers deployers outside the EU where the system's output is used in the EU. A US company with a Dublin office, or a UK agency screening applicants for a role in Germany, is a deployer for those workers. Retrain a vendor's model on your own data or rebrand it and you can become a provider yourself.
What Do Employers Have to Do as Deployers of High-Risk HR AI?
Article 26 translates into plain duties:
- Use it the way the vendor says. Follow the instructions for use; do not repurpose a screening tool.
- Put a competent human in charge. Name people trained and authorised to question the output and override or stop the system.
- Keep the logs. Automatically generated logs stay under your control for at least six months, longer if other law requires it.
- Tell your workers first. Before putting the system into service, inform affected workers and their representatives that a high-risk AI system will be used on them.
- Tell the individuals. Candidates and employees subject to a decision informed by the system need to know that.
- Run the GDPR side. The vendor's documentation feeds your data protection impact assessment, and Article 22 GDPR limits on solely automated decisions still apply on top.
- Consider a fundamental rights impact assessment. Article 27 requires one for public bodies, operators of public services, and banks and insurers for specific uses. Most private employers are not caught, but a short version is cheap insurance.
The AI literacy duty has applied since February 2025. The Omnibus softened it from guaranteeing a level of literacy to supporting staff development, but a screening tool run by people who do not understand it remains the fastest route to a discrimination claim.
What Are the Penalties for Getting It Wrong?
Article 99 sets three bands, per the official text hosted by the EU AI Act portal: up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for other breaches including deployer and transparency duties, and up to EUR 7.5 million or 1% for supplying incorrect information. For large companies the higher figure applies; for SMEs and start-ups, the lower of the two. The same facts can still support a GDPR fine and a discrimination claim.
How Should a 20 to 200 Person Employer Use the Extra 16 Months?
This is a ten-step list an HR manager can work through in a quarter:
- Inventory every AI feature you use on people. Include the features hiding inside your ATS, HRIS, video interview tool, and productivity software.
- Classify each one against the table above: prohibited, high-risk, or limited-risk.
- Switch off anything prohibited today. Emotion or mood analysis in video interviews is the common one.
- Ask vendors for AI Act documentation. Instructions for use, the intended purpose, conformity plans, and a contact for incidents.
- Design human review for every high-risk use. No candidate is rejected and no employee is flagged on an AI score alone. Name the reviewer in writing.
- Write a one-page worker notice covering which AI tools are used, on whom, for what, and how to ask for human review. Share it with any works council or union.
- Add an AI section to your candidate privacy notice and update your DPIA using the vendor's documentation.
- Train the people who touch the tools. Two hours on what the system does, its limits, and how to override it covers the literacy duty.
- Log decisions. Keep the system logs and a simple record of every AI-informed rejection, promotion, or performance flag and who reviewed it.
- Diary two dates. December 2, 2027 for high-risk go-live, and a vendor review six months earlier. Add both to your HR compliance calendar.
Steps one to five also cover the agent-style tools now arriving in HR platforms, which we examined in our look at agentic AI in HR for small businesses.
What About UK and US Employers?
The UK has no AI Act. UK employers using AI on candidates or staff answer to the Equality Act 2010, UK GDPR (including its rules on solely automated decisions), and ICO guidance on AI and recruitment. A UK company hiring for EU-based roles picks up the EU duties for those roles. UK employers with EU staff should also watch the EU Pay Transparency Directive, which touches the same salary and promotion data AI tools feed on.
The US has no federal equivalent either, but the states have moved. New York City's Local Law 144, Illinois's amended Human Rights Act, and Colorado's AI Act each attach notice, audit, or record-keeping duties to automated hiring tools; our guide to US state AI hiring laws walks through them. Candidates everywhere are learning to game the scoring; see how applicants beat AI resume screening. In every jurisdiction the discipline is the same: inventory, human review, notice, logs.
Where Does TracefyHR Sit Under the EU AI Act?
Outside the high-risk deployer scenario, provided you use it the way it is built. TracefyHR's hiring module posts jobs and tracks a candidate pipeline; it does not score, rank, or reject applicants automatically. Forge AI builds custom forms and approval workflows from a plain-English description, and every approval in those workflows is made by a named person, not by the model. Neither feature makes an automated hiring, promotion, or termination decision, and neither analyses emotion. An employer who built a Forge workflow that auto-rejected candidates on a score would change that analysis, which is why step five above matters.
Key takeaways:
- High-risk duties for HR AI moved from August 2, 2026 to December 2, 2027; they did not disappear.
- Chatbot disclosure and AI-content labelling applied on August 2, 2026, and workplace emotion recognition has been banned since February 2025.
- Fines reach EUR 35 million or 7% of turnover for prohibited practices, with SMEs paying the lower of the two thresholds.
- Inventory, classify, human review, worker notice, training, and logs cover most of what a small employer needs to do in the next 16 months.
The employers who will be comfortable in December 2027 are the ones who spent late 2026 finding out what their software does to people. Start with the inventory, and if you want hiring software where a human signs off on every decision by design, see how the hiring module in TracefyHR handles the pipeline.
Frequently Asked Questions
Did the EU AI Act high-risk rules for HR apply on August 2, 2026?
No. The Digital Omnibus on AI, in force from July 27, 2026, moved the high-risk obligations for employment AI to December 2, 2027.
What EU AI Act duties do apply to HR right now?
The ban on emotion recognition at work and the AI literacy duty (since February 2, 2025), and Article 50 transparency duties such as chatbot disclosure (since August 2, 2026).
Is AI CV screening high-risk under the EU AI Act?
Yes. Screening, filtering, ranking, and evaluating candidates are listed in Annex III, so full deployer duties apply from December 2, 2027.
Does the EU AI Act apply to a US or UK company?
Yes, if the AI system's output is used on candidates or workers in the EU, for example when hiring for an EU-based role or managing EU staff.
What are the fines under the EU AI Act?
Up to EUR 35 million or 7% of turnover for prohibited practices, and up to EUR 15 million or 3% for deployer and transparency breaches; SMEs pay the lower threshold.
Do I need a fundamental rights impact assessment as a private employer?
Usually not. Article 27 requires it for public bodies, operators of public services, and banks and insurers for specific uses. A short voluntary version is still good practice.
Is an HR chatbot high-risk?
No. A chatbot answering policy questions is limited-risk under Article 50: you must make clear it is AI. It becomes high-risk only if it makes or informs employment decisions.