Sam Aria
Founder of 360AI

Published: 27 July 2026

EU AI Act Recruitment Deadline Postponed to December 2027

Last updated: 27 July 2026

What recruitment teams, AI vendors and technology buyers need to know about the move from 2 August 2026 to 2 December 2027.

A lot of EU AI Act guidance still quotes 2 August 2026 as the deadline for high-risk recruitment AI. For systems classified as high-risk under Article 6(2) and Annex III, including recruitment and candidate-selection use cases, that date is now out of date.

Regulation (EU) 2026/1744 was published in the Official Journal of the European Union on 24 July 2026 and enters into force on 27 July 2026. It moves the application date for the main high-risk requirements affecting Annex III systems to 2 December 2027, a 16-month postponement.

The corresponding date for high-risk AI systems embedded in products covered by Annex I moves to 2 August 2028.

Having worked through 360AI’s EU AI Act readiness and conformity documentation as part of our enterprise due-diligence pack, I see this less as regulatory relief and more as an opportunity to build the controls properly.

Risk management, human oversight, data governance, testing, monitoring and technical documentation are product and operating-model work. They cannot be completed credibly as a last-minute policy exercise.

The extra time does not remove the obligations. It removes a credible excuse for doing the work badly.


What changed at a glance?

2 December 2027: The main Chapter III requirements for AI systems classified as high-risk under Article 6(2) and Annex III. This includes many systems intended for recruitment, candidate screening and selection.

2 August 2028: The corresponding requirements for high-risk systems covered by Article 6(1) and Annex I, generally AI used as a safety component of, or as, a regulated product.

2 August 2026: The general Article 50 transparency obligations remain on their original timetable. These include relevant duties to tell people when they are interacting with an AI system and to disclose certain AI-generated or manipulated content.

2 December 2026: A narrow transitional period applies to providers of systems generating synthetic audio, images, video or text that were already on the market before 2 August 2026, allowing them until 2 December 2026 to meet the Article 50(2) machine-readable marking requirement.

Existing prohibited practices: The Article 5 prohibitions already applying from 2 February 2025 were not postponed.

GDPR Article 22: The rules governing decisions based solely on automated processing that produce legal or similarly significant effects remain separate from the AI Act timetable.


Why was the deadline postponed?

The amending regulation points to delays in standards, common specifications, guidance, national governance arrangements and conformity-assessment infrastructure.

In practical terms, organisations were being asked to implement complex high-risk requirements before the support needed for consistent compliance was fully ready.

That did not make compliance impossible. It did make it harder, more expensive and more likely to become a box-ticking exercise.

The postponement creates more time for providers and deployers to build controls that work in the product and operating process, rather than producing documentation that looks compliant but does little to reduce real risk.


Not every recruitment tool is automatically high-risk

Annex III covers AI systems intended for recruitment or selection, including systems used to advertise vacancies, screen or filter applications, or evaluate candidates during interviews or tests.

However, classification still depends on the system’s intended purpose, design and effect on decision-making. A tool used somewhere in a recruitment workflow is not automatically high-risk simply because recruitment is involved.

That makes a documented classification assessment essential. Organisations should be able to explain what the system does, how it influences decisions and why it has been placed inside or outside the high-risk category.


What should buyers ask an AI recruitment vendor?

The calendar has changed. The due-diligence questions have not.

Ask the vendor to show:

  • how the system has been classified under the AI Act;
  • its intended purpose and known limitations;
  • evidence of risk management, data governance and testing;
  • how human oversight works inside the product and operating process;
  • how candidate data, profiling and automated decisions are handled under the GDPR;
  • technical documentation and monitoring evidence that exist now, rather than promises to create them shortly before December 2027.

Where this leaves the compliance conversation

The most valuable thing this postponement buys is time to build genuinely compliant systems rather than perform compliance on paper.

Bias, transparency, data protection and human oversight have not become less important. By December 2027, the argument that standards and guidance were too immature should carry far less weight.

At 360AI, this is the work our AI Policy and Trust Centre and enterprise due-diligence materials are designed to support.

I will update this article if the legal timetable changes again. I would also be interested to hear where your organisation’s interpretation differs, particularly if you are working through the same issues with legal counsel.


Sam Aria is the Founder and CEO of 360AI, a real-time talent and market intelligence platform for the recruitment industry.

This article is a practical summary and does not constitute legal advice.

Primary legal sources: Regulation (EU) 2026/1744; Regulation (EU) 2024/1689; Regulation (EU) 2016/679, Article 22.

Get started with 360AI

Place great candidates. Find new clients. Unlock your data value.