TL;DR
- The delay was narrow: Only high-risk obligations moved from 2 August 2026 to 2 December 2027. Article 50 transparency duties applied from 2 August 2026 regardless.
- Doing nothing is wrong: Teams that paused everything after the headline have already missed a live obligation. Teams that kept sprinting toward August are now spending on a 2027 problem.
- What must already be true: Anyone whose job touches AI used in hiring, performance monitoring, or related employment decisions needs to know whether their tools are caught by Annex III and who counts as a deployer in their setup.
- How the options split: Buy a compliant tool, document a deployer posture around the tool you've, or take a hard look and remove the AI from the workflow.
- The decision rule: If the tool talks to candidates or employees in writing, the August 2026 clock has already run. If it scores, ranks, or screens them, December 2027 is the real one.
- The outcome to expect: A short, honest inventory of where AI is live in your people processes, with a clear list of which obligations already apply and which are on the longer runway.
Friday Afternoon in a People Operations Standup
Marta runs people operations for a 1,200-person SaaS company with offices in Berlin, Amsterdam and Madrid. By June she had a working group, a draft policy, a vendor shortlist and a date on the wall: 2 August 2026. Her CHRO had cleared budget for a compliance sprint. Then on a Tuesday in late July, a colleague in legal Slack-messaged her a one-line summary of the Digital Omnibus, and the date on the wall stopped meaning anything.
Marta called a standup. The room split. Engineering wanted to stand the programme down. Legal wanted to keep going. The CHRO asked the only question that mattered: "What is actually live on 2 August?" Nobody could answer cleanly. Two weeks later Marta is still sorting signal from noise. Her CV-screening tool is still in use. Her hiring managers still use an AI note-taker on first-round calls. Her performance platform still flags flight-risk scores every Monday morning. And her inbox has six vendor newsletters telling her the deadline was extended.
But the real issue isn't the headline. It's that two clocks are now running, and most of the conversation is about the wrong one.
Best tools for AI in the Workplace
When You Genuinely Do Not Need to Act Yet
There's a real version of "nothing to do" and a fake one. Be honest about which is which.
You're genuinely fine if no AI system touches any stage of your hiring, onboarding, performance review, promotion, task allocation or termination workflow, and your HR analytics platform doesn't score or rank employees in any way. Picture a family-owned logistics firm outside Lisbon. Applications arrive by email. The depot manager reads them on a Sunday evening. That firm has no problem to solve. The one thing worth checking is the recruitment agency it uses in busy months. If the agency screens with a tool, the shortlist landing in that inbox has already been shaped by one, and nobody in the depot knows it.
You will feel friction before you feel risk if you use AI on the edges: a writing assistant that drafts recruiter outreach, a meeting summariser that joins calls, a chatbot that answers policy questions. None of these look high risk under Annex III on their face. Each still pulls in other duties, and the line between a tool that helps and a tool that decides is thinner than a vendor demo suggests. Think of a recruiter in Dublin whose summariser writes a tidy paragraph of "candidate strengths" after every call. Nobody decided that paragraph would carry weight. By the fourth hiring loop, managers read it instead of the notes and paste it into the debrief. The tool didn't change. Its job did.
You have real exposure if a system screens CVs, ranks candidates, scores video interviews, suggests who to interview, evaluates assessments, flags employees for performance plans or drives task assignment. That's the Annex III employment bucket, the one that moved to 2 December 2027. A talent lead in Warsaw asks her vendor for the fairness testing and gets a slide covering the model as shipped: not her applicant pool, not her job families, not the two knockout rules her own team added in a configuration screen. The extra runway is real, and it's the only thing the delay bought her. Evidence takes far longer to assemble than the tool took to buy.
You're in the edge case if you use a tool you genuinely don't believe makes or shapes a people decision, while a reasonable observer would disagree. The Act looks at what a system does, not at how a contract describes it. A common shape: an HRIS module that surfaces a "suggested next step" on an internal application, sold as workflow automation, read by managers as a recommendation. The test is what happens when someone ignores it. If overriding the suggestion needs a written reason and a second approval, the tool is doing rather more than suggesting. That gap is where the exposure sits. Take local advice, in the countries where your people actually sit.
Five Questions This Reader Asks at 11pm
Did the delay cover everything? No. Only the high-risk obligations moved, from 2 August 2026 to 2 December 2027. Article 50 transparency duties applied from 2 August 2026 and didn't move at all, and the AI literacy duty has been live since February 2025. The Digital Omnibus entered into force on 27 July 2026, which is why so many programmes were mid-sprint. A team that stands everything down isn't buying time. It's accruing a gap on duties that were already running, with nobody watching the file.
Why does that matter for HR? Because a single tool often sits in both buckets. A careers-site assistant that answers candidate questions carries a transparency duty today. That same assistant, once it starts ordering applicants by fit, lands in the Annex III bucket on the longer runway. Teams that inventory by vendor miss this. Inventory by function instead: what does this thing do to a person, and at which step. Get it wrong and you're defending a tool you classified at purchase against a use that grew sideways after the sales call. Classification follows the deployment, not the product.
What is a deployer, in plain terms? It's the organisation putting an AI system into use. Build the model yourself and you're closer to the provider side. Buy a tool and point it at your candidates or your staff, and you're normally the deployer, which is where most HR teams sit. The consequence is uncomfortable. Duties attach to you for a system you can't see inside, built by someone whose roadmap you don't control. If nobody can say out loud which role you're in for each tool, the follow-on questions have no owner, and the answer gets given by whoever opens the email.
Did the work we did earlier this year get wasted? No. The inventory, the policy draft, the vendor questions, the staff training: all of it's still load-bearing for 2 December 2027. What changed is the order, not the value. The risk now is decay. A tool inventory rots quietly, because procurement keeps buying and product teams keep switching features on, so the document signed off at the start of the programme describes a company that no longer exists. Give it an owner and a refresh rhythm, or you'll rebuild it from nothing nearer the date, with the first pass team long since reassigned.
Are US state laws part of this? Some are, and they aren't coordinated with the EU calendar. A state obligation around automated employment decision tools can be live while your EU high-risk work points at 2 December 2027, so one date on one wall will mislead the whole team. Run them as separate workstreams. The failure mode is a global policy written to the slowest clock, then applied to a New York hiring flow that needed something else months earlier. Ask your counsel, state by state, what already applies to the tools you run.
The Three Honest Categories
Replace the tool with a compliant one. This is right when the vendor plainly isn't going to make the grade and the contract is up for renewal anyway. Low switching cost is the third condition, and it's the one people assume rather than check. The signal is rarely a missing feature. It's the quality of the answers you get when you ask hard questions. A people ops lead in Amsterdam sends her CV-screening vendor three: what the system was tested on, how the ranking is produced, what she must hold as a deployer. Back comes a marketing PDF and an offer of a call with a solutions engineer. A month later, the same PDF. That's your answer, and acting before renewal costs less than acting after. Replacement fails when the tool is wired into scheduling and into the analytics your CHRO reads on Mondays, so the swap turns into an integration project wearing a compliance badge. It fails again when the gap turns out to be documentation you could have written in a fortnight.
Keep the tool and build a deployer posture around it. This is right when the underlying system is sound and your real exposure is process and evidence rather than the model itself. This is where a lot of established HR stacks end up. The work is unglamorous: write down who owns the tool, what it's allowed to decide, what a human has to do before a rejection stands, and how you'd reconstruct that decision half a year later. A talent director in Madrid runs a simple test. She pulls ten recent screening rejections and asks the hiring managers to explain each one with the tool closed. If the explanation is "the system put them near the bottom", the posture doesn't exist yet, whatever the policy says. This one fails when release notes are your only window into changes to the model, so your evidence describes a system that moved underneath it. It also fails when the deployer duties add up to a re-implementation in disguise. At that point you've paid twice: once for the tool, once for the controls it should have carried.
Remove the AI from the workflow. This is right when the AI was bolted on for novelty and a human was making the call anyway. It's also right when the audit overhead would cost more than the tool saves, the honest position for a lot of small deployments nobody has looked at since the pilot. A recruitment manager in Berlin switches off automated ranking on a graduate intake and finds the shortlist barely moves. What changes is time to shortlist, by about a day. That's a trade worth saying out loud. Removal fails when the AI is doing real work at a volume humans can't absorb, and that conversation involves the headcount you'd need instead. It fails harder when a team removes one visible tool, leaves three quiet ones running inside the HRIS, and reports the problem as closed. The register is the check. If you can't produce one, you haven't removed anything, you've just stopped looking.
Five Diagnostics You Can Run This Week
Where is AI actually live in our people processes, and did we add it in the last 18 months? Don't start with the vendors. Ask finance for every people-related subscription, then ask IT for connected apps and browser extensions on the HRIS. Then walk the funnel yourself. Hiring, onboarding, performance, internal mobility, offboarding. Sit with one recruiter for an hour and watch what they actually open. Anything added recently goes to the top, because it's least likely to have reached procurement at all.
For each tool, can we name the lawful basis for using it on EU staff, and can we point to the person who owns it? Test the second half first, because it's faster. Send one email per tool asking how the thing works, and see who replies. A tool with no owner produces either silence or a chain of forwards ending at somebody who left. On the first half, ask your privacy lead where the tool appears in the records you keep, and whether that entry describes what it does now. If it was written at purchase, assume it's out of date.
Are candidates and employees told when they're interacting with an AI system? Check it the way a candidate would, not the way a policy owner would. Open your careers site in a private window on a phone, apply for a live role, and note every point where something automated speaks to you or reads your answers. Then go looking for the notice. If it sits in a privacy policy three clicks from the form, ask honestly whether that counts as telling someone. The Article 50 duty applied from 2 August 2026, so this is arrears rather than preparation.
Can a hiring manager explain, in plain English, how the tool influenced the last rejection they acted on? Pick a manager who isn't in your working group, and a real rejection from the last month. Ask them to walk you through it with the screen closed. Listen for the difference between "she didn't have the certification" and "she came out amber". The first is a decision. The second is a system output repeated back in a confident voice. If most of your managers give you the second, human oversight exists on paper only.
Who in the team has had AI literacy training that maps to the actual tools they use? Put the tool list beside the training records and look for names that appear in one and not the other. A general awareness webinar maps to nothing. The duty has been live since February 2025, so this is the longest-running item on your list and often the least evidenced. Here's a workable test: can the person operating the tool say what it's bad at? Someone who can name a failure mode has been trained. Someone who can only describe the benefits has been sold to.
What Moved and What Did Not, Obligation by Obligation
Article 50 transparency duties
What it is: telling people when they're interacting with an AI system, and labelling AI-generated content in the defined cases. Why it earns a place: the date didn't move. It applied from 2 August 2026 while the high-risk deadline went out to 2 December 2027, so it's the live obligation inside a story everyone read as a delay. For HR it bites at the top of the funnel, where the careers-page chatbot and the assistant answering candidate questions talk to people who have no relationship with you yet. Where it falls short: the generated-content rules were drafted with chatbots and media in mind, and the fit for HR artefacts is uneven. Nobody can say cleanly whether a job advert drafted by a model and edited by a recruiter is generated content or human content with help. That's not a reason to skip the notice. It's a reason to write down the position you took.
Annex III high-risk classification for employment uses
What it is: the list of AI uses in recruitment, selection, promotion, termination, task allocation and performance monitoring that the Act treats as high risk. Why it earns a place: this is the bucket that moved from 2 August 2026 to 2 December 2027, and it covers almost everything HR cares about. Screening, ranking, interview scoring, flight-risk flags, shift allocation: one classification catches the lot. Where it falls short: knowing a system is high risk tells you little about what to do on Monday. The classification is a gate, not a method, and the guidance keeps evolving underneath it. It cuts at the level of use rather than product, so the same analytics suite can be inside the bucket for the module that scores performance and outside it for the one that books annual leave. Teams that classify by vendor end up with a register that looks tidy and is wrong.
Article 26 deployer obligations
What it is: duties on the organisation putting the system into use, including human oversight, monitoring in life, and cooperation with the provider. Why it earns a place: these attach to the employer running a bought-in tool, which describes most HR teams reading this. Providers build the thing. Deployers answer for what it did to a named person on a Tuesday afternoon. Where it falls short: the duties assume access to the system's workings that vendors are often reluctant to provide, and the asymmetry gets worse the smaller you are. A very large customer can put a clause into a renewal and get it. A mid-market buyer gets the standard terms and a support portal. When the person doing oversight can't see what changed in the last release, oversight becomes a signature on a form, which is the thing an inspection is designed to see through.
The fundamental rights impact assessment
What it is: an assessment of how a high-risk AI system affects the people it touches, required before first use. Why it earns a place: of everything on this list, it's the artefact most likely to be asked for by name, and the one that takes longest to produce honestly. It forces questions a procurement form never asks. Who is affected. What happens to them when the system is wrong. Who hears about it, and how fast. Where it falls short: the templates are still maturing, so teams reach for whatever their consultancy hands over and end up with a document written to the shape of the form rather than the shape of the risk. The deeper problem is treating it as a one-off. A tool assessed at launch and retrained twice since has an assessment describing a system that no longer exists.
AI literacy duties for staff
What it is: an obligation to make sure staff using AI systems have sufficient AI literacy for their role. Why it earns a place: it applied from February 2025, giving it the longest live runway of anything here, and it's the cheapest thing on this page to fix. It also does quiet work on the other duties. A recruiter who understands what a ranking model is doing asks better questions and escalates the odd result instead of shrugging at it. Where it falls short: there's no agreed standard for "sufficient", so a compliance function under pressure will buy a webinar, record attendance, and call it done. Training built around the general idea of AI won't help the coordinator deciding whether to override a score at four on a Friday. Literacy that counts is specific to the tool in front of the person, and refreshed when that tool changes.
The prohibited practices list
What it is: a set of AI uses that are banned outright, including certain manipulative or exploitative practices. Why it earns a place: a ban doesn't move with a deadline. It sits underneath every people decision that touches AI, and nothing in the Digital Omnibus makes a prohibited use acceptable in the meantime. Where it falls short: the boundary is genuinely hard to see inside a product feature. A wellbeing app that reads tone in written messages, an engagement tool that infers mood from meeting behaviour: neither arrives labelled, and both get bought by somebody who thought they were buying analytics. Whether either is caught is a question for counsel, not for a blog. Procurement is where this gets spotted or missed, because once a feature is live it has users who like it and a sponsor. Ask what the system infers about a person that the person never told you.
The Decision Table
| Situation | Scale | Setup | Primary Pain | Recommended Starting Point |
|---|---|---|---|---|
| No AI in any people process | Under 250 staff | Single HRIS, no decisioning tools | None real | Document the absence and revisit when something is added |
| AI in candidate comms only | 250 to 1,000 | Chatbot, writing assistant | Transparency duty is already live | Apply Article 50 notice and labelling now |
| CV screening or ranking live | Any | Bought tool, one or two vendors | High-risk deadline moved but deployer duties already bite | Build a deployer posture and prep for FRIA |
| Video interview scoring live | 500+ | Vendor platform | Annex III exposure plus evidentiary burden | Replace or constrain to human-in-the-loop |
| Performance monitoring or scoring live | Any | Workforce analytics suite | Multiple obligations stack | Scope down the model, then document |
| AI note-takers on hiring calls | Any | Consumer-grade tool | Transparency duty live, drift on data retention | Set rules, retain only what you can defend |
| US-headquartered with EU staff | Any | Regional variation | EU and state laws run on different clocks | Run them as two separate workstreams |
| Tool recently added, vendor not engaged | Any | Procurement gap | Nobody owns the compliance question | Name an owner before anything else |
The Cost of Getting This Wrong
The penalties are the part the press covers, and they're not the part that will hurt. The damage that doesn't appear on any invoice is the kind that compounds.
Start with the letter. A rejected candidate writes to ask how the tool that screened her out actually works. The cost isn't the reply. It's the fortnight your team spends discovering that nobody can produce one, while the vendor's support desk treats the question as a feature request. The colleague who configured the knockout rules moved on months ago. You'll answer eventually. You'll answer late, and the lateness is what gets remembered by everyone who watched.
Then the shortlist nobody can reconstruct. A hiring manager is asked why the final five looked the way they did, and finds the honest answer is "the tool ordered them and I worked down the list". That isn't a compliance problem yet. It's a management problem that becomes one the moment somebody writes it down in an email.
Then the works council, or whichever employee representative body you deal with, asking for the impact assessment six months after the tool went live. Being asked for a document you don't have is survivable. Being asked twice is not, because the second ask goes over your head.
The quieter costs are internal, and they last longer. A programme that stood down after the headline and restarted after the correction spends its credibility twice, and the third time HR asks for budget on this subject, the finance director remembers the first two. Legal, burned once, starts refusing every new tool, including the ones that would have helped. Recruiters drift back to spreadsheets they never mention, because the sanctioned route is now slow, and your inventory is wrong again within weeks of being finished.
So the question worth sitting with isn't "what is the fine" but "what is the version of our process we are willing to defend on the page"?
When You Are Ready to Go Further
Most of the noise in this space comes from people who sell something. HROpsLab doesn't. We are an independent review publication that compares HR and people operations software on capability, evidence and fit. Our writers have run HR. Our analysts aren't paid by vendors. When a tool earns a high score here, it's because the work justifies it, not because of a contract.
If you want a structured look at how the HR software market is shaping up against obligations like these, our comparison library is a good place to start. It's free to read, and there's no gated demo waiting at the end of it.
Frequently Asked Questions
Does the delay apply to every obligation in the EU AI Act?
No. The Digital Omnibus entered into force on 27 July 2026 and moved the compliance deadline for high-risk obligations, including the employment uses in Annex III, from 2 August 2026 to 2 December 2027. Article 50 transparency obligations were not moved and applied from 2 August 2026. The AI literacy duty applied from February 2025. So a team reading "the deadline moved" as "nothing applies" has drawn a wrong conclusion from a true headline. Split the task list in two: what is already running, and what now has a longer runway. Which obligations catch your setup is a question for local counsel.
What does an HR team have to do as a deployer?
An employer using a bought-in AI tool on candidates or employees is normally a deployer under the Act. Deployer duties include operating the system in line with the provider's instructions, ensuring human oversight, monitoring the system in use, and keeping records. In practice that tends to mean a named person owns each tool, a human can explain and overturn what it produced, and a decision can be reconstructed months later. The shape of those duties depends on the tool and on how you deployed it, and this article can't tell you what applies in your case. Take local advice.
Does a non-EU company with EU staff fall inside the Act?
The Act applies to providers and deployers that place AI systems on the EU market or put them into use in the EU, and to outputs used there. A US or UK headquartered company with staff or candidates in the EU can be caught, and where the tool was bought doesn't settle it. What usually matters is where the people affected by the system are sitting, not where the contract was signed or where the server lives. Whether your setup is in scope is a legal question, not a reading of the headline, so put it to counsel who knows the countries you employ in.
What should we do with the work we already did?
Keep it. The inventory, the policy draft, the vendor due diligence, the staff training and the gap analysis are all still load-bearing for the 2 December 2027 high-risk deadline and for any transparency obligations that are already live. The mistake to avoid is treating the work as either finished or wasted. It needs maintenance, because tools get added and features get switched on, so an inventory nobody refreshes describes a company you no longer are. Give each artefact an owner and a review rhythm. Sequenced rather than cancelled is the way to put it to a sceptical executive.
Should we keep the AI compliance programme running?
Yes, but reset the scope. A programme aimed only at the August 2026 high-risk deadline is now misaligned with the actual calendar, and a programme aimed at nothing at all leaves the live transparency and literacy duties unowned. Split it in two. One track carries what already applies, and it should close out in weeks rather than quarters. The other carries the high-risk work for 2 December 2027, resourced at a pace you can hold for that long without the working group quietly dissolving. Protect both in the same governance forum, or the urgent track will eat the important one.
How does this interact with US state AI laws?
It doesn't interact cleanly. Several US states have their own rules on automated employment decision tools, and they move on their own schedules rather than in step with the EU. Colorado is the clearest illustration that the direction is not one way: it repealed and replaced its original AI Act with SB 26-189, the Automated Decision-Making Technology Act, signed 14 May 2026 and effective 1 January 2027, narrower than the law it replaced. Treat US state law as a separate workstream with its own deadlines and evidence, because a global policy written to the slowest clock will leave a gap in the fastest jurisdiction. The overlap is real, though. Notice to candidates and records of how a tool was used show up in both places, so the underlying work is often reusable even when the paperwork isn't. Local counsel in each relevant state is the right starting point.
HROpsLab is an independent review publication for HR and people operations software. No vendor pays for placement, and we sell nothing.