AI in HR Guide
Governance, ethics and compliance

The EU AI Act and HR: What Employers Need to Know in 2026

The EU AI Act is the world's first comprehensive AI law, and employment is one of its main areas of focus. The July 2026 Digital Omnibus changed its timetable, but not its direction.

By the HRight Talks editorial teamUpdated 4 minute read

Short answer

The EU AI Act classifies AI systems used in employment, including recruitment, selection, promotion and termination decisions, task allocation, and monitoring or evaluation of workers, as high-risk. Following the Digital Omnibus (Regulation (EU) 2026/1744), in force since 27 July 2026, high-risk obligations for these systems apply from 2 December 2027. Other rules already apply: the ban on workplace emotion recognition and the AI literacy duty since 2 February 2025, and transparency duties such as disclosing AI chatbots since 2 August 2026. Employers using high-risk AI are 'deployers' with their own obligations, including human oversight, monitoring, logging and informing workers.

Key takeaways

  • Most AI used to make or support decisions about candidates and workers is high-risk.
  • High-risk obligations for employment AI now apply from 2 December 2027, not August 2026.
  • Workplace emotion recognition has been prohibited since February 2025.
  • Transparency duties, including telling people they are interacting with AI, apply from August 2026.
  • Employers are usually deployers, with duties separate from those of their vendors (providers).

Guides in this topic

How the AI Act classifies HR uses of AI

CategoryHR examplesConsequence
ProhibitedAI inferring employees' emotions (except medical or safety reasons); certain biometric categorisationBanned since 2 February 2025
High-risk (Annex III, point 4)Targeted job adverts, filtering applications, evaluating candidates; decisions on promotion, termination; task allocation based on behaviour or traits; monitoring and evaluating performance and behaviourStrict obligations from 2 December 2027
Transparency obligationsHR chatbots and AI assistants interacting with people; certain AI-generated contentDisclosure duties from 2 August 2026
Minimal riskDrafting job descriptions with AI, internal productivity tools not deciding about peopleNo specific AI Act duties beyond AI literacy

See high-risk hiring systems.

The timeline after the Digital Omnibus

DateWhat appliesRelevance to HR
1 August 2024AI Act enters into forceStart of phased timeline
2 February 2025Prohibited practices (Article 5) and AI literacy (Article 4)Ban on workplace emotion recognition; staff AI literacy measures
2 August 2025General-purpose AI model obligationsMainly affects model providers
27 July 2026Digital Omnibus (Regulation (EU) 2026/1744) in forceDeadlines deferred; Article 4 reworded
2 August 2026General application, Article 50 transparency duties, national enforcementTell people when they interact with AI such as HR chatbots
2 December 2027High-risk obligations for Annex III systemsAI in recruitment, promotion, termination, task allocation and worker monitoring
2 August 2028High-risk obligations for AI in regulated products (Annex I)Limited direct HR relevance

The Omnibus replaced the original August 2026 date for Annex III high-risk systems with a fixed date of 2 December 2027. Transitional rules mean high-risk systems already on the market before that date generally stay outside the new obligations only until they undergo significant design changes. Employers should not treat the deferral as a reason to pause: inventory, classification, human-oversight design and vendor due diligence take time.

Providers and deployers

RoleWhoCore duties for high-risk systems
ProviderThe HR technology vendor that develops and markets the systemRisk management, data governance, technical documentation, logging capability, transparency to deployers, accuracy and robustness, conformity assessment, registration
DeployerThe employer using the systemUse per instructions, competent human oversight, input data relevance, monitoring, keeping logs, informing workers and representatives, informing affected people, cooperation with authorities

An employer that substantially modifies a high-risk system or puts its own name on it can take on provider duties. See EU AI Act employer obligations.

Penalties

Fines under the AI Act reach up to EUR 35 million or 7 percent of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3 percent for most other breaches, with lower caps for SMEs.

What HR should do now

  1. Inventory every AI system used in people processes.
  2. Classify each as prohibited, high-risk, transparency-only or minimal risk.
  3. Stop any prohibited uses, such as emotion recognition, immediately.
  4. Label AI chatbots and assistants clearly.
  5. Document AI literacy measures for staff.
  6. Prepare high-risk deployer processes ahead of December 2027.
  7. Update vendor contracts for provider cooperation and information.

Use the EU AI Act compliance checklist.

This is general information, not legal advice. The AI Act is being implemented through guidance, standards and national enforcement that continue to develop. Take qualified advice on your specific systems and jurisdictions.

Frequently asked questions

Does the EU AI Act apply to HR?

Yes. AI used in recruitment, selection, promotion, termination, task allocation and monitoring or evaluating workers is classified as high-risk, workplace emotion recognition is prohibited, and transparency and AI literacy duties apply to AI used by HR.

When do the EU AI Act high-risk rules apply to recruitment AI?

Following the Digital Omnibus, in force since 27 July 2026, high-risk obligations for Annex III systems, including employment and recruitment AI, apply from 2 December 2027.

Does the EU AI Act apply to companies outside the EU?

It can. It applies to providers placing AI on the EU market and to deployers in the EU, and can reach organisations outside the EU where the output of their AI systems is used in the EU.

What are the penalties under the EU AI Act?

Up to EUR 35 million or 7 percent of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3 percent for most other breaches, with lower caps for SMEs.

Sources and further reading

  1. Regulation (EU) 2024/1689 (EU AI Act), EUR-Lex
  2. Hunton Andrews Kurth (July 2026): EU Digital Omnibus on AI enters into force
  3. Modulos (July 2026): EU AI Act Omnibus published, new deadlines
  4. Cooley (August 2026): Digital AI Omnibus delays key deadlines, introduces new rules