The EU AI Act and HR: What Employers Need to Know in 2026
The EU AI Act is the world's first comprehensive AI law, and employment is one of its main areas of focus. The July 2026 Digital Omnibus changed its timetable, but not its direction.
Short answer
The EU AI Act classifies AI systems used in employment, including recruitment, selection, promotion and termination decisions, task allocation, and monitoring or evaluation of workers, as high-risk. Following the Digital Omnibus (Regulation (EU) 2026/1744), in force since 27 July 2026, high-risk obligations for these systems apply from 2 December 2027. Other rules already apply: the ban on workplace emotion recognition and the AI literacy duty since 2 February 2025, and transparency duties such as disclosing AI chatbots since 2 August 2026. Employers using high-risk AI are 'deployers' with their own obligations, including human oversight, monitoring, logging and informing workers.
Key takeaways
- Most AI used to make or support decisions about candidates and workers is high-risk.
- High-risk obligations for employment AI now apply from 2 December 2027, not August 2026.
- Workplace emotion recognition has been prohibited since February 2025.
- Transparency duties, including telling people they are interacting with AI, apply from August 2026.
- Employers are usually deployers, with duties separate from those of their vendors (providers).
Guides in this topic
- EU AI Act Impact on Recruitment: What Changes for Hiring Teams
Which recruitment tools are high-risk, what changes for hiring teams and candidates, and how to prepare.
- Is AI Hiring Software High-Risk Under the EU AI Act? A Classification Guide
How to classify HR AI under Annex III, the exceptions, and a step-by-step method.
- EU AI Act Compliance Checklist for Employers and HR Teams
A seven-part checklist ordered by what applies now and what applies from December 2027.
- EU AI Act Employer Obligations: Deployer Duties Explained
Each deployer duty for high-risk HR AI explained, with practical actions for HR.
How the AI Act classifies HR uses of AI
| Category | HR examples | Consequence |
|---|---|---|
| Prohibited | AI inferring employees' emotions (except medical or safety reasons); certain biometric categorisation | Banned since 2 February 2025 |
| High-risk (Annex III, point 4) | Targeted job adverts, filtering applications, evaluating candidates; decisions on promotion, termination; task allocation based on behaviour or traits; monitoring and evaluating performance and behaviour | Strict obligations from 2 December 2027 |
| Transparency obligations | HR chatbots and AI assistants interacting with people; certain AI-generated content | Disclosure duties from 2 August 2026 |
| Minimal risk | Drafting job descriptions with AI, internal productivity tools not deciding about people | No specific AI Act duties beyond AI literacy |
The timeline after the Digital Omnibus
| Date | What applies | Relevance to HR |
|---|---|---|
| 1 August 2024 | AI Act enters into force | Start of phased timeline |
| 2 February 2025 | Prohibited practices (Article 5) and AI literacy (Article 4) | Ban on workplace emotion recognition; staff AI literacy measures |
| 2 August 2025 | General-purpose AI model obligations | Mainly affects model providers |
| 27 July 2026 | Digital Omnibus (Regulation (EU) 2026/1744) in force | Deadlines deferred; Article 4 reworded |
| 2 August 2026 | General application, Article 50 transparency duties, national enforcement | Tell people when they interact with AI such as HR chatbots |
| 2 December 2027 | High-risk obligations for Annex III systems | AI in recruitment, promotion, termination, task allocation and worker monitoring |
| 2 August 2028 | High-risk obligations for AI in regulated products (Annex I) | Limited direct HR relevance |
The Omnibus replaced the original August 2026 date for Annex III high-risk systems with a fixed date of 2 December 2027. Transitional rules mean high-risk systems already on the market before that date generally stay outside the new obligations only until they undergo significant design changes. Employers should not treat the deferral as a reason to pause: inventory, classification, human-oversight design and vendor due diligence take time.
Providers and deployers
| Role | Who | Core duties for high-risk systems |
|---|---|---|
| Provider | The HR technology vendor that develops and markets the system | Risk management, data governance, technical documentation, logging capability, transparency to deployers, accuracy and robustness, conformity assessment, registration |
| Deployer | The employer using the system | Use per instructions, competent human oversight, input data relevance, monitoring, keeping logs, informing workers and representatives, informing affected people, cooperation with authorities |
An employer that substantially modifies a high-risk system or puts its own name on it can take on provider duties. See EU AI Act employer obligations.
Penalties
Fines under the AI Act reach up to EUR 35 million or 7 percent of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3 percent for most other breaches, with lower caps for SMEs.
What HR should do now
- Inventory every AI system used in people processes.
- Classify each as prohibited, high-risk, transparency-only or minimal risk.
- Stop any prohibited uses, such as emotion recognition, immediately.
- Label AI chatbots and assistants clearly.
- Document AI literacy measures for staff.
- Prepare high-risk deployer processes ahead of December 2027.
- Update vendor contracts for provider cooperation and information.
Use the EU AI Act compliance checklist.
This is general information, not legal advice. The AI Act is being implemented through guidance, standards and national enforcement that continue to develop. Take qualified advice on your specific systems and jurisdictions.
Related guides
- EU AI Act Compliance Checklist for Employers and HR Teams
A seven-part checklist ordered by what applies now and what applies from December 2027.
- EU AI Act Employer Obligations: Deployer Duties Explained
Each deployer duty for high-risk HR AI explained, with practical actions for HR.
- AI Hiring Bias: Causes, Real Cases, Law and How to Prevent It
Where AI hiring bias comes from, how it is measured, the law, and a prevention framework.
- AI Literacy in the Workplace: What It Is and What the EU AI Act Requires
What AI literacy means, the amended Article 4 obligation, and a proportionate programme design.
Frequently asked questions
Does the EU AI Act apply to HR?
Yes. AI used in recruitment, selection, promotion, termination, task allocation and monitoring or evaluating workers is classified as high-risk, workplace emotion recognition is prohibited, and transparency and AI literacy duties apply to AI used by HR.
When do the EU AI Act high-risk rules apply to recruitment AI?
Following the Digital Omnibus, in force since 27 July 2026, high-risk obligations for Annex III systems, including employment and recruitment AI, apply from 2 December 2027.
Does the EU AI Act apply to companies outside the EU?
It can. It applies to providers placing AI on the EU market and to deployers in the EU, and can reach organisations outside the EU where the output of their AI systems is used in the EU.
What are the penalties under the EU AI Act?
Up to EUR 35 million or 7 percent of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3 percent for most other breaches, with lower caps for SMEs.
