
Last updated: 27 July 2026
A lot of EU AI Act guidance still quotes 2 August 2026 as the deadline for high-risk recruitment AI. For systems classified as high-risk under Article 6(2) and Annex III, including recruitment and candidate-selection use cases, that date is now out of date.
Regulation (EU) 2026/1744 was published in the Official Journal of the European Union on 24 July 2026 and enters into force on 27 July 2026. It moves the application date for the main high-risk requirements affecting Annex III systems to 2 December 2027, a 16-month postponement.
The corresponding date for high-risk AI systems embedded in products covered by Annex I moves to 2 August 2028.
Having worked through 360AI’s EU AI Act readiness and conformity documentation as part of our enterprise due-diligence pack, I see this less as regulatory relief and more as an opportunity to build the controls properly.
Risk management, human oversight, data governance, testing, monitoring and technical documentation are product and operating-model work. They cannot be completed credibly as a last-minute policy exercise.
The extra time does not remove the obligations. It removes a credible excuse for doing the work badly.

2 December 2027: The main Chapter III requirements for AI systems classified as high-risk under Article 6(2) and Annex III. This includes many systems intended for recruitment, candidate screening and selection.
2 August 2028: The corresponding requirements for high-risk systems covered by Article 6(1) and Annex I, generally AI used as a safety component of, or as, a regulated product.
2 August 2026: The general Article 50 transparency obligations remain on their original timetable. These include relevant duties to tell people when they are interacting with an AI system and to disclose certain AI-generated or manipulated content.
2 December 2026: A narrow transitional period applies to providers of systems generating synthetic audio, images, video or text that were already on the market before 2 August 2026, allowing them until 2 December 2026 to meet the Article 50(2) machine-readable marking requirement.
Existing prohibited practices: The Article 5 prohibitions already applying from 2 February 2025 were not postponed.
GDPR Article 22: The rules governing decisions based solely on automated processing that produce legal or similarly significant effects remain separate from the AI Act timetable.

The amending regulation points to delays in standards, common specifications, guidance, national governance arrangements and conformity-assessment infrastructure.
In practical terms, organisations were being asked to implement complex high-risk requirements before the support needed for consistent compliance was fully ready.
That did not make compliance impossible. It did make it harder, more expensive and more likely to become a box-ticking exercise.
The postponement creates more time for providers and deployers to build controls that work in the product and operating process, rather than producing documentation that looks compliant but does little to reduce real risk.
Annex III covers AI systems intended for recruitment or selection, including systems used to advertise vacancies, screen or filter applications, or evaluate candidates during interviews or tests.
However, classification still depends on the system’s intended purpose, design and effect on decision-making. A tool used somewhere in a recruitment workflow is not automatically high-risk simply because recruitment is involved.
That makes a documented classification assessment essential. Organisations should be able to explain what the system does, how it influences decisions and why it has been placed inside or outside the high-risk category.
The calendar has changed. The due-diligence questions have not.
Ask the vendor to show:
The most valuable thing this postponement buys is time to build genuinely compliant systems rather than perform compliance on paper.
Bias, transparency, data protection and human oversight have not become less important. By December 2027, the argument that standards and guidance were too immature should carry far less weight.
At 360AI, this is the work our AI Policy and Trust Centre and enterprise due-diligence materials are designed to support.
I will update this article if the legal timetable changes again. I would also be interested to hear where your organisation’s interpretation differs, particularly if you are working through the same issues with legal counsel.
Sam Aria is the Founder and CEO of 360AI, a real-time talent and market intelligence platform for the recruitment industry.
This article is a practical summary and does not constitute legal advice.
Primary legal sources: Regulation (EU) 2026/1744; Regulation (EU) 2024/1689; Regulation (EU) 2016/679, Article 22.