The Digital Omnibus on AI moved the EU AI Act's compliance deadline for high-risk systems, including AI used in hiring, from 2 August 2026 to 2 December 2027. Sixteen extra months, not sixteen months of permission to wait.
Some obligations are already in force: the AI literacy requirement, the ban on emotion inference in video interviews, and the Article 50 transparency rules covering AI chatbots. The extension covers the harder work, technical documentation, human oversight, vendor contracts, and the full deployer duties under Article 26, but that work can't be compressed into a sprint. This article covers what changed, what didn't, and what TA teams should be doing now.
At the end of July, the Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force. If you work in talent acquisition and you use AI tools for screening, ranking, assessment, or any of the twenty other things AI has worked its way into your hiring stack, this is relevant to you.
What the Digital Omnibus has done is move the deadline for complying with the EU AI Act's most demanding requirements from 2 August 2026 to 2 December 2027. That's sixteen extra months to get your ducks in a row.
Here's what changed, what it means for TA teams right now, and why the extension may look like a blessing but is not a reason to relax.
What the EU AI Act says about AI in hiring
The EU AI Act classifies AI systems used in recruitment and talent decisions as high-risk. That's a legal category under Annex III with specific obligations attached to it, though (as we'll get to) it involves some judgment on the part of the deployer.
Annex III lists AI used for recruitment, candidate selection, targeted job advertising, CV screening, candidate evaluation, and performance monitoring as high-risk systems. These tools materially influence whether someone gets a job, which makes them consequential enough to regulate.
That said, Article 6(3) allows organisations to self-assess whether a specific Annex III system falls outside the high-risk classification. A system is not high-risk if it performs only a narrow procedural task, improves the result of a previously completed human activity, detects deviations from prior decision patterns, or performs a preparatory task (though it is always high-risk if it profiles individuals). An employer branding tool with embedded AI capabilities, for example, falls outside the recruitment category. Traditional, non-AI psychometric assessments aren't covered by the EU AI Act, but other tools that uses those tests' results downstream might be, so you still need to run a proper audit of your tech stack to ensure you know where you stand. That assessment of what is and what isn't in scope must be documented, and systems not deemed high-risk still need to be registered.
Providers of high-risk tools (i.e. the companies building them) have the biggest share of obligations: risk management systems, bias examination of training data, and technical documentation. Deployers (organisations using those tools) have different requirements to meet. They must use the system per the provider's instructions, assign human oversight to people with the necessary competence, training and authority, ensure input data is relevant and sufficiently representative, monitor operation and report serious incidents, keep logs for at least six months, and inform workers and their representatives before deployment.
The fines for non-compliance are hefty and will also come into effect in December 2027: up to €15 million or 3% of global annual turnover for breaching high-risk system obligations, whichever is higher. Some AI practices are banned outright (things like subliminal manipulation, social scoring, or inferring emotions in the workplace). If you're caught using one of those, the fines go up to €35 million or 7% of turnover, and those penalties are already enforceable.
Where your legal entity is located doesn't matter: the Act applies to AI systems placed on the EU market or whose outputs affect people located in the EU. If you're a UK or US-based organisation screening candidates for roles in Germany, France, or any other EU member state, the regulations apply to you.
What the Digital Omnibus changed
The Digital Omnibus entered into force on 27 July 2026, six days before the EU AI Act's original deadline for systems considered high risk, such as AI in hiring. It moves the compliance date from the 2nd August 2026 to the 2nd December 2027, but that's not the only change.
Article 4, the AI literacy requirement, for example, still applies and has been in force since February 2025. But the Omnibus did tweak it slightly: the original standard required providers and deployers to ensure a sufficient level of AI literacy among staff operating AI systems. The amended version has changed this to "taking measures to support the development of AI literacy". Documented, role-relevant training is now sufficient; you don't have to certify individual comprehension. But the obligation to take those measures is live now.
Article 50, the transparency obligations, went live on 2 August 2026. These are narrower and more specific than "tell candidates you use AI." Article 50 covers AI systems that interact directly with people (chatbots, AI interviewers), machine-readable marking of synthetic audio, image, video and text, deepfake disclosure, and notification by deployers of emotion recognition or biometric categorisation systems. For a conventional CV screener or a scored psychometric assessment, Article 50 is largely beside the point. It is relevant, however, if you use an AI chatbot in your candidate journey, or if any AI-generated content is shown to candidates.
The prohibited practices (including the Article 5(1)(f) ban on AI that infers emotions in the workplace from biometric data, which covers video interview tools that use sentiment scoring) have been enforceable since early 2025, the Omnibus doesn't touch them, and your organisation should already be compliant.
So, in short: the compliance deadline for the hardest work (technical documentation, risk management, conformity assessment, human oversight, registration, and the full set of deployer duties under Article 26) has been extended, but the foundational obligations are already enforced.
Why a 16-month extension isn't 16 months of permission to wait
Building the documentation trail, embedding meaningful human oversight into a process, and getting vendor contracts right all take time. These aren't things that can be compressed into a sprint at the end.
And compliance isn't the only thing you should be concerned about.
Draft guidance published by the European Commission in June 2026 indicates that AI tools will generally be classified as high-risk where they materially influence access to employment opportunities, even if a human recruiter makes the final decision. The distinction between "AI made the decision" and "a human made the decision with AI input" doesn't reduce your responsibility. (The guidelines are still in draft, with consultation having closed on 23 July 2026 and final versions expected around the end of 2026, so treat them as directional, not binding.)
Employment litigation involving AI-generated decisions is also on the rise. Tribunal scrutiny and regulatory investigation look at different questions from an AI Act conformity audit, and neither is satisfied by the other.
The extension grants more time to do things properly, but it should not be read as permission to postpone action.
What TA teams are dealing with
Most talent acquisition teams didn't sit down one day and decide to build an AI-powered hiring stack. These things tend to accumulate. A job board with algorithmic ranking here, a CV screening tool there, an ATS with scoring functionality, an assessment platform with AI-driven analysis. Before long, the hiring process contains several AI systems, each doing something consequential, most of them procured through a vendor contract that probably didn't include clauses about EU AI Act compliance documentation.
This is a common state of play, and it creates a specific set of problems.
The first is visibility. Many TA teams don't have a complete inventory of the AI systems operating in their hiring process. The AI is often embedded in tools that aren't described as AI tools: a "smart shortlisting feature," an "intelligent screening engine," a "predictive match score." That language is a vendor choice, but the regulatory classification is determined by what the tool does, not what it's called.
The second is the shared liability question. The EU AI Act distinguishes between providers (the companies building AI systems) and deployers (the organisations using them). Both have obligations. Deployer obligations sit with you: use the system per instructions, put competent and trained people with real authority in charge of overseeing it, control input data quality, monitor and report incidents, keep logs, and inform workers and affected individuals. You don't need to produce risk assessment and bias testing evidence, but you need to be able to obtain and interrogate your providers'.
There's also the Article 25 trap. If you rebrand a tool, substantially modify it, or change its intended purpose, you become the provider in the eyes of the Act and inherit the full set of provider obligations. That reclassification is automatic.
The third is the human oversight requirement. The Act will require (from December 2027) meaningful human oversight over AI-assisted hiring decisions. Article 14(4) requires that oversight enable a person to interpret the output correctly and to disregard, override or reverse it, and Article 26(2) requires deployers to assign oversight to people with the necessary competence, training and authority. A hiring manager who reviews an AI-generated shortlist in three minutes, without having received the training to interrogate how it was produced, will not meet that standard. This is a future obligation, not a current one, but it's the hardest thing to retrofit, which is why it's the first thing to start building.
What talent assessment platforms need to demonstrate
For organisations using a talent assessment platform, and for the vendors providing one, the EU AI Act creates specific obligations that go beyond general privacy or data protection compliance.
Assessment providers need to be able to supply technical documentation for their AI systems: how the system works, what data it was trained on, what the known limitations are, and what bias testing has been conducted. Organisations procuring assessment tools should be asking for this.
It's also worth noting that validation is not the same as bias testing. A well-validated psychometric assessment demonstrates that it measures what it claims to measure and predicts what it claims to predict. Bias testing demonstrates that it doesn't do so differentially across demographic groups in ways that produce discriminatory outcomes. These are related but distinct questions, and you need documented answers to both.
The AI literacy requirement applies particularly to assessment. Recruiters and hiring managers who use AI-assisted assessment outputs need to understand what those outputs represent, what they don't represent, and what it means to exercise independent judgment over them. Since the Omnibus, the legal standard is to take measures that support the development of that literacy, and to be able to show them.
Candidate transparency is also not optional. But it's worth being precise about where that obligation comes from today. The AI Act's candidate-facing duties (Articles 26(11) and 86) are deferred to December 2027. What makes transparency non-optional right now is the GDPR: Articles 13 and 14 on transparency, Article 15 on access, and Article 22 where a decision is solely automated. Candidates are owed plain-language information about how AI is used in the process, and that obligation has been enforceable for years.
Why did employment AI end up in the high-risk category at all?
Most EU AI Act coverage for TA teams focuses on compliance: what you have to do, by when, and what happens if you don't.
The Act's high-risk classification of employment AI exists because these systems affect people's economic opportunities in ways that can be arbitrary, biased, or opaque. The regulatory response is to require documentation, bias testing, oversight, and transparency. Those requirements are a description of what a well-designed talent acquisition process should be doing regardless.
The organisations that will find EU AI Act compliance least painful are the ones that were already asking whether their assessment tools are validated, whether their AI-powered screening is introducing bias, whether candidates are being treated fairly, and whether the humans in the process have the information and authority to exercise judgment. Not because they were worried about regulators, but because those are the right questions for any team that cares about hiring quality.
The Act is turning those questions into requirements: from December 2027, deployers will have to demonstrate their answers.
What to do between now and December 2027
The December 2027 deadline gives most organisations meaningful time to build a compliant programme, not permission to start from zero in November 2027.
The practical starting point is an inventory. Every AI system operating within your hiring process (sourcing, advertising, CV screening, shortlisting, assessment, interview analytics, offer prediction) needs to be identified and classified. Classified means: for each system, record whether it is high-risk under Annex III, whether it falls into one of the Article 6(3) exemptions, and why. That written rationale is the artefact a regulator or tribunal will ask for.
From the inventory, you can identify which systems are likely high-risk, which vendor relationships need to be revisited to ensure access to technical documentation and bias testing results, and where the potential oversight gaps are.
The AI literacy obligation is already in force: you must take measures that support AI literacy among the staff using these tools, and be able to show them. If your TA team hasn't received training on what the AI tools in your hiring stack do, how they produce outputs, and what independent judgment over those outputs looks like, that's what you should be tackling first.
On the vendor side, the most important question is documentation access. Contracts signed before the Act's enforcement dates will typically not include compliance clauses. When those contracts come up for renewal, and when new tools are procured, technical documentation, bias testing results, notification of material model changes, and cooperation with audits should be standard requirements.
The EU AI Act is one piece of a much bigger regulatory shift
The EU AI Act is not the last word on AI in employment. In the US, Illinois HB 3773 amended the Illinois Human Rights Act from 1 January 2026 to require notice whenever AI is used in hiring, promotion, discharge, or discipline. NYC Local Law 144 (a city ordinance, not state law) has required annual independent bias audits of automated employment decision tools since July 2023. Colorado replaced its original comprehensive AI Act with a narrower transparency-focused law in May 2026. The UK's position is still forming.
What's emerging across jurisdictions is a consistent direction: AI tools used to make decisions about people's working lives are going to face scrutiny, transparency requirements, and accountability structures. The specific dates and thresholds will vary, but the underlying logic is going to be the same. Worth noting, though, that the two most significant developments of 2026 both involved timelines shifting or scope narrowing (the EU deferral and the Colorado rewrite). The scope of regulatory scrutiny keeps broadening while the timelines keep shifting. That's exactly why building a compliance strategy on deadline pressure alone is the wrong approach.
The organisations that treat this as a compliance exercise will find themselves constantly trying to catch up. The ones that treat it as a quality question (what do we know about whether our hiring AI is working, who it's working for, and whether the people using it have the judgment to interpret it correctly) are building a more durable strategy.
The EU AI Act gave TA teams 16 more months. Use them to answer two questions: whether you'll be compliant by December 2027 and, perhaps more importantly, whether the tools in your hiring stack are any good.
Sova Assessment is a talent assessment platform built on validated psychometric methodology with documented adverse impact analysis and differential-item-functioning testing across demographic groups. If you're assessing whether your assessment tools meet the documentation, bias testing, and validity standards that the EU AI Act and good practice both require, we're happy to talk. You can book a conversation with our team here.
This article is intended as a general guide for talent acquisition and people leaders. It is not legal advice and should not be treated as a substitute for it. The EU AI Act is a complex and evolving regulation, and how it applies to your organisation will depend on your specific tools, processes, and jurisdictions.
If you're assessing your obligations under the EU AI Act, consult an employment lawyer with expertise in AI regulation and data protection.


.webp)

.webp)
.webp)
.webp)


.webp)