Policy
The EU AI Act Reaches US Employers, and the Hiring Deadline Moved to 2027
The EU AI Act, Regulation (EU) 2024/1689, reaches a US employer whenever an AI system's output is used in the European Union: screening EU-based candidates or evaluating EU workers is enough, with or without an EU entity. Annex III point 4 classifies recruitment and selection as high-risk, and the deployer duties attached to that classification now apply from 2 December 2027 rather than August 2026. Two obligations already bind: the prohibited practices and the AI literacy duty.
The takeThe deferral is being read as a reprieve. It is closer to a rescheduling with a bill attached: Annex III point 4 was untouched, the requirements are unchanged, and the same programme still has to exist by December 2027. Meanwhile the parts almost nobody wrote about have been in force since February 2025. Treating the delay as permission to stop is how a company ends up out of step with the live rules while preparing carefully for the deferred ones.
Where Olive fits
Open a role and see what the work shows
The obligations arriving in 2027 ask a deployer to explain the part a system played in a decision, which is hard when the output is a number nobody can trace. Olive returns six findings written by a human reviewer, each carrying the moment in the session it rests on, and every released report exports with its rubric and bank versions attached.
Rank your shortlistWhen does the Act reach a US employer?
When the output of the AI system is used in the European Union. Article 2(1)(c) is the hook, and it asks for no EU entity, no EU office and no EU payroll: screening candidates based in the EU, or evaluating workers there, is enough on its own 1. Annex III point 4 then classifies AI used for the recruitment or selection of people as high-risk, naming targeted job advertising, analysing and filtering job applications, and evaluating candidates 1.
The same Annex entry reaches further into the employment relationship than most readiness notes mention. It covers AI used to decide promotion or termination, to allocate tasks, and to monitor and evaluate performance 1. So a workforce analytics tool pointed at an EU team is inside the same category as a resume screener pointed at EU applicants, and a company that scoped its review to hiring has scoped it too narrowly.
Two limits are worth holding onto. The label attaches to the AI system's intended purpose rather than to anyone's job title, and Article 6(3) takes a system out of high-risk where it performs only a narrow procedural task or improves the result of a previous human activity without posing significant risk 1. A scheduler and a formatter do not do what a filter does. That distinction is the same one US law turns on, which is why which AI hiring laws actually apply now reaches the same conclusion from a completely different statute.
What moved to 2027, and what did not
The compliance date moved, and the classification behind it did not. Regulation (EU) 2026/1744, the Digital Omnibus on AI adopted 8 July 2026 and published in the Official Journal on 24 July 2026, amended Article 113 so the high-risk obligations in Chapter III apply from 2 December 2027 for Annex III systems and 2 August 2028 for those embedded in regulated products 3. The Commission's implementation timeline now carries those dates 2.
The recital gives the reason plainly: standards, common specifications and guidance were late, and national competent authorities were slow to stand up 3. That is a statement about readiness on the regulator's side, not a judgment that the rules were wrong.
What the Omnibus did not do matters more for planning. It did not touch Annex III point 4, so recruitment AI is still classified as high-risk. It left the Chapter III requirements themselves in place, so the programme due in December 2027 is the programme that was due in August 2026. And it did not defer the Article 5 prohibitions, the Article 4 literacy duty or the Article 50 transparency obligations 3. It did rewrite other parts of the Act around them, Article 4 among them 4.
In practice, that leaves a citation problem. Every law-firm note, vendor explainer and internal readiness deck written before mid-2026 says the high-risk hiring rules start 2 August 2026 2. That sentence is now wrong, it is the single most repeated error in this area, and it is probably sitting in a slide somebody is about to present.
Which duties are live right now
Two, both in force since 2 February 2025. Article 5(1)(f) prohibits using AI to infer the emotions of a person in the workplace or in an education institution, outside medical and safety purposes 1. Article 4 asks providers and deployers alike to take measures supporting AI literacy among their staff and anyone operating AI on their behalf, and it is not limited to high-risk systems 14.
Read the emotion ban for what it says. The Act defines an emotion recognition system as one inferring emotions or intentions from biometric data, so the prohibition aims at face, voice and physiological inference rather than at every claim a tool makes about a candidate 1. Whether a pre-hire video interview with an external candidate counts as "the workplace" is contested, and the statute does not settle it. What is settled is the exposure: Article 5 breaches sit in the top fine tier, up to EUR 35 000 000 or 7% of total worldwide annual turnover, whichever is higher 1.
The literacy duty is the opposite shape, easy to satisfy and easy to ignore. Most summaries still quote the original wording, which asked for a "sufficient level" of AI literacy. The Digital Omnibus amendment took effect in mid-July 2026: literacy remains an obligation for providers and deployers, and no specific level is mandated 4. The Commission is equally plain that nobody has to be tested or certified, so any figure for required training hours has been invented somewhere else 4. Note also that Article 4 is absent from the enumerated fine tiers, so the widely repeated claim that AI illiteracy attracts fines up to EUR 15 000 000 or 3% does not follow from the text 1. An employer running an off-the-shelf tool is a deployer, which puts ordinary recruiters inside the duty.
Decide the scope before you build the programme
One question comes before every other: whether EU-based candidates and workers are in scope at all. If the answer is no and you intend to keep it that way, scope the postings and the sourcing so it stays true, and write the decision down with a date. If the answer is yes, the deployer obligations arriving on 2 December 2027 need a programme, and the runway is about fifteen months.
What a deployer owes under Article 26 is worth reading now, because most of it is organisational and slow to build 1:
- Use the system according to the provider's instructions for use, which means somebody has to read them and keep them.
- Assign human oversight to named people who are competent, trained and have the authority to act on what they see. An oversight role with no authority is a title.
- Keep the input data relevant and sufficiently representative for the intended purpose, to the extent the input data is under your control.
- Keep the logs the system generates automatically, for at least six months where they are under your control.
- Inform workers and their representatives before a high-risk system goes into service at the workplace 1.
That last duty names workers. An external applicant's route runs through the Article 86 right to obtain from the deployer a clear explanation of the system's role in a decision that adversely affects them 1. A candidate asking that question is asking the employer, not the vendor, which is the same asymmetry behind a candidate's right to human review of a rejection.
If a mandate arrived from the top and the calendar is already moving, what HR has to build in the first 90 days is the smaller version of this list. Confirm the final Omnibus text and your own scope with counsel before rescheduling any commitment: the deferral was recent, and the reporting on it moved faster than the drafting.
Common questions
Does hiring one contractor in Europe put the whole company in scope?
It puts the systems whose output is used there in scope, not the company as a whole. The test runs system by system: a screening tool applied to that person's application is inside, a US-only performance tool is not. This is why the scoping decision is worth writing down before the programme is designed. Most organisations discover the real exposure sits in one remote-eligible req and one workforce analytics dashboard. Confirm the boundary with counsel before relying on it.
Is an AI screening tool used on EU candidates in 2026 already unlawful?
Not on the strength of Annex III. Classification is not prohibition, and the substantive high-risk requirements do not apply to deployers until 2 December 2027, so using a screening tool this year does not breach that chapter. The live constraints are elsewhere: the Article 5 prohibitions, the Article 4 literacy duty, and national employment and data protection law, which the AI Act leaves entirely in place. Nothing in the deferral touches those.
Can an AI video interview read a candidate's tone or engagement in the EU?
Inferring emotions from biometric data in the workplace is prohibited, and that prohibition has applied since February 2025. The Act's definition points at face, voice and physiological signals rather than at text analysis of a written answer, and whether a pre-hire interview with an external candidate counts as the workplace has not been settled. Given that the breach sits in the top fine tier, a tool advertising engagement or sentiment inference from video is not a good place to test the boundary.
Do the duties fall on the vendor or on the employer?
Both, in different places. The provider building the system carries the high-risk requirements for the system itself. The employer using it is a deployer and carries the Article 26 obligations, including instructions-for-use compliance, human oversight, input data quality where it controls the data, log retention and informing workers. The AI literacy duty under Article 4 names providers and deployers alike. Buying a compliant tool does not transfer the deployer's own duties to the seller.
What does the AI literacy duty actually require of a hiring team?
Measures proportionate to the people involved and the context, and nothing more specific than that. The text asks providers and deployers to take measures supporting AI literacy among staff and anyone operating AI on their behalf, taking account of their technical knowledge, experience, education and training. Since the July 2026 amendment no particular level is mandated, and the Commission says plainly that nobody has to be tested or certified. The duty is not confined to high-risk systems, and a recruiter using an off-the-shelf tool is inside it. A documented briefing on what the tool does and where it fails is a defensible start.
References
- 1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) publications.europa.eu Supports the Article 2(1)(c) scope hook where the output is used in the Union, the Annex III point 4 high-risk classification of recruitment, the Article 6(3) narrow-task carve-out, the Article 5(1)(f) prohibition on workplace emotion inference, the Article 4 literacy duty, the Article 26 deployer obligations, the Article 86 explanation right, and the Article 99 fine tiers of EUR 35 000 000 or 7% and EUR 15 000 000 or 3%.
- 2. Timeline: implementation of the EU AI Act ai-act-service-desk.ec.europa.eu Supports the current application dates for Annex III high-risk systems and the superseded 2 August 2026 date that older readiness material still repeats.
- 3. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) publications.europa.eu Supports the Article 113 amendment deferring Chapter III Sections 1 to 3, the reasons given in the recital, the fact that Annex III point 4 and the high-risk requirements were left in place, and the fact that the prohibitions, literacy and transparency duties were not deferred (though Article 4 was amended).
- 4. AI Literacy - Questions & Answers digital-strategy.ec.europa.eu Supports the post-Omnibus wording of Article 4, that no specific or "sufficient" level of AI literacy is mandated since the mid-July 2026 amendment, and that the duty requires no testing and no certificate.
4 sources, numbered by first appearance. How Olive sources claims
General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.
Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.