Relief With Reservations: The EU AI Act Hits Recruiting AI Only in 2027 – What TA Teams Should Do Anyway



There's a particular moment when a deadline in the calendar suddenly turns grey. For many TA teams, 2 August 2026 was one of those dates. Marked in red, planned well in advance, with a half-finished action plan sitting next to it. And then came the Digital Omnibus – and pushed the date back by sixteen months.
The relief is understandable. Unfortunately, it is only partly unwarranted. Because what was postponed is not "the AI Act", but a clearly defined part of it. Anyone who confuses the two creates a compliance gap in precisely the year the supervisory authorities are finishing setting up their structures.
A quick note on context: there has already been a foundational piece on the EU AI Act here – "When the Algorithm Becomes a Compliance Risk", written back when August 2026 was the vanishing point. This text is deliberately not a second primer but an update: what the Omnibus changed, what has actually applied since, and where the relief is misleading. Anyone who wants the basics will find them there.
What Was Actually Postponed
On 24 July 2026, the Digital Omnibus Regulation (EU) 2026/1744 was published in the Official Journal; three days later it entered into force. Its core for recruiting: the obligations for standalone high-risk AI under Annex III – and that covers just about everything that sorts, scores or ranks candidates – only apply from 2 December 2027. Where the AI is embedded in a regulated product (Annex I), the date moves out to 2 August 2028.
This concerns the heavy artillery: risk management system, technical documentation, data quality requirements, logging, conformity assessment, registration. In other words, exactly the points where most projects stalled in early 2026, because the harmonized standards for them simply weren't finished.
It matters just as much what the Omnibus did not do: recruiting remains high-risk. There is no reclassification, no all-clear on the substance. And the much-quoted line that a human looks at it in the end does not lift a system out of the high-risk category. Human oversight is a requirement, not an escape route.

What Was Switched On Anyway on 2 August 2026
This is where it gets uncomfortable for everyone who deleted the calendar entry. The transparency obligations under Article 50 were not postponed. Since 2 August 2026, the rule has been: anyone interacting with an AI system must be able to recognize it. Synthetically generated or manipulated content must be labeled. For systems already in use before that cut-off date, the transitional period expires on 2 December 2026.
Translated into everyday recruiting terms: the chatbot on the careers page, the pre-selection dialogue in the application form, the AI-generated interview feedback, the synthetic voice on the screening call – all of it needs a disclosure. Not in 2027. Now. Breaches of the transparency obligations can be penalized with up to 15 million euros or three percent of global annual turnover.
The prohibitions in Article 5 have been live even longer. They have applied since 2 February 2025, backed by penalties since August 2025, and with the highest fine bracket in the entire regulation: up to 35 million euros or seven percent of group turnover. Three of them matter most for recruiting:
Emotion recognition in the workplace – and that includes the application process. Any tool that infers motivation, stress or honesty from facial expressions, tone of voice or speaking pace is prohibited, not merely regulated.
Biometric categorization that allows sensitive characteristics to be derived – origin, political views or beliefs, for example.
Social scoring, where it results in detrimental treatment.
And: anyone who merely operates such systems, rather than building them, is liable too. Pointing at the vendor doesn't help.

That leaves Article 4, AI literacy. The Omnibus watered it down – an obligation to deliver became an obligation to make an effort, measures to promote competence instead of guaranteed competence. Training obligations do remain in place for operators of high-risk systems, though. Anyone reading that as a free pass should take a look at Gallup's HR Report 2026: 81 percent of HR staff use AI in their day-to-day work, but only 4 percent of specialists consider employees adequately prepared for it. That is no longer a legal question; it is an operational risk.
The Part That Never Hung on the AI Act
The biggest misunderstanding around the postponement is different: a substantial share of what constrains TA teams in their use of AI doesn't come from the AI Act at all.
Article 22 GDPR prohibits decisions based solely on automated processing that have significant effects. A rejection is one of them. AI may structure and prioritize CVs, but a human must make an independent assessment, and rubber-stamping the ranking is not enough. That was true in 2018, it is true in 2026, and it remains true unchanged until 2027.
On top of that, Germany adds Section 26 BDSG – the Federal Data Protection Act – as the legal basis for applicant data, the AGG, Germany's General Equal Treatment Act with its reversal of the burden of proof once there is an indication of discrimination (and an algorithmically produced pattern is an excellent indication), plus Section 87(1) No. 6 of the Works Constitution Act (Betriebsverfassungsgesetz, BetrVG). The latter is the real time sink: anyone introducing an AI-supported selection system needs a formal works agreement with the works council, Germany's elected employee representation body. That doesn't get negotiated in four weeks.
Switzerland looks different, but no more relaxed. There is no dedicated AI law; the Federal Council is relying on existing law, targeted adjustments, and ratification of the Council of Europe convention, with a consultation draft announced for the end of 2026. The revised Data Protection Act applies to AI-supported processing of personal data anyway. And any Swiss company that recruits in the EU, or uses systems whose output is used in the EU, falls within the scope of the EU rules under the market-location principle.
By the Way: Supervision Is Only Now Going Live
One detail that gets lost in the postponement debate: while the obligations slide backward, supervision is being built up. Germany's implementing act for the AI Act cleared cabinet in February 2026 and sets out which authorities are responsible – including the structures for supervising precisely those transparency obligations that were not postponed. At EU level, the Omnibus concentrates responsibility more heavily with the AI Office, which reduces the number of contact points but not the number of questions you have to be able to answer.
At the same time, the Omnibus brings real relief that's worth taking advantage of: binding definitions for SMEs and small mid-caps, simplified technical documentation for those groups, and an EU-wide sandbox. So anyone running a mid-sized company has not only more time but a slightly easier path – provided someone takes care of using it in good time.
Why "Let's Wait and See" Is the Most Expensive Option
Sixteen months sounds like a lot. Work the chain through once: system inventory, classification of every tool, requesting vendor documentation, renegotiating contracts, involving the works council, concluding a works agreement, defining processes and roles, training staff. Realistically, that's twelve to eighteen months – if nothing gets in the way. So the postponement doesn't create a buffer; it creates just about enough time.
Then there's the procurement effect. Every contract with a recruiting tech vendor signed in 2026 that runs beyond 2027 needs to contain the compliance commitments already. Anyone who renegotiates only in 2027 is negotiating from the weakest position imaginable: mid-term, with a deadline at their back.
And a third point that's easy to miss: the law firm Gleiss Lutz classifies the Omnibus as a practice-oriented adjustment, not as deregulation – the core obligations remain unchanged. Anyone reading the postponement as a change of direction is reading it wrong.
And one more aspect that rarely gets factored in: candidates don't care when the rules start to apply. The question "is a human or a model deciding on my application?" is already being asked – in conversations, on review platforms, in networks. A clean, comprehensible answer to it in 2026 is an employer branding argument, not a compliance form. Anyone who only formulates one in 2027, because that's when the legislator asks, has missed the more useful part of the topic.
The Homework That's Due Regardless
Five things that tolerate no delay:
Inventory.
Capture every AI element in the process – including whatever the vendor sells as "smart matching" and doesn't call AI. What has been postponed is the start of application of certain high-risk rules, not the obligation to know today what is in use.
Article 5 check.
Check whether emotion or personality analysis from video, voice, or speech behavior is happening anywhere. If so: switch it off. That's not a project, it's an emergency.
Catch up on transparency.
Label chatbots, automated replies and AI-generated texts in candidate communication. The deadline was August 2026; for legacy systems, it expires in December 2026.
Document the human decision.
Don't claim it; make it demonstrable: who decided on what basis, and what did the AI contribute?
Start contracts and co-determination in parallel.
Both have long lead times and can't be compressed.

The Real Takeaway
The Digital Omnibus is good news for everyone who was honestly prepared and got stuck on missing standards. For everyone else, it's an invitation to defer a problem that can't be deferred – because half of it never hung on that date.
The most honest summary: the hard part comes later. The uncomfortable part has been here for a while.
Sources
Regulation (EU) 2026/1744 (Digital Omnibus Regulation on Artificial Intelligence), EUR-Lex
ITMR Legal: "Digital Omnibus zur KI: Was am AI Act wirklich verändert wird"
Gleiss Lutz: "Vereinfachung der KI-Verordnung (Digital-Omnibus)"
Börse Express: "EU AI Act: Recruiting-KI muss erst bis Dezember 2027 konform sein"
SRD Rechtsanwälte: "AI Act Fristverlängerung – was gilt wirklich ab 2. August 2026?"
Haufe: "Digital Omnibus: Was ändert sich an der KI-Verordnung?"
EU AI Verordnung: "Art. 5 EU AI Act – Verbotene KI-Praktiken im Überblick"
Personalwirtschaft: "EU AI Act – Diese HR-relevanten Regeln gelten bereits ab jetzt"
Compound Law: "KI im Recruiting in Deutschland: DSGVO, AI Act und Betriebsrat 2026"
ad-hoc-news: "HR-Report 2026: 81 Prozent nutzen KI, aber nur 4 Prozent sind vorbereitet"
Swiss Federal Council: "KI-Regulierung – Bundesrat will Konvention des Europarats ratifizieren"
Swiss-Press: "KI-Regulierung in der Schweiz 2026: Was Unternehmen jetzt wissen sollten"
AI Transparency Notice
AI-based tools were used in a supporting capacity in the creation of this article. They serve in particular for researching and structuring information, for linguistic and grammatical revision, for translation, and in part for creating or editing illustrations and image material.
The concept, the substantive statements, the assessments and the conclusions come from the author and reflect his personal thoughts, professional experience and convictions. All content is editorially reviewed before publication, and the author takes responsibility for it.
Articles on this website are not created or published automatically by AI. AI is used as a supporting tool; responsibility for content and editorial decisions remains entirely with the author.




Comments