The EU AI Act and hiring: what every UK and EU employer must do before the deadline
Michael
Founder, KimonRecruit
Published
AI used in recruitment is high-risk under the EU AI Act. The application date is in flux: 2 August 2026 today, with a provisional deferral to 2 December 2027. A practical checklist for UK and EU employers.

If you use AI anywhere in your hiring process, the EU AI Act almost certainly classifies that use as high-risk. The obligations that follow are set in the Regulation to apply from 2 August 2026, although that date is now in flux, as we explain below. This article sets out what that means in practice for UK and EU employers. It is a practical orientation, not legal advice; for decisions about your specific situation, speak to your own advisers. This post is part of our wider guide, the EU AI Act and recruitment, which links to the full set of deeper articles.
The timeline is unsettled. As we publish, the obligation legally applies from 2 August 2026, but a provisional Digital Omnibus agreement would defer stand-alone Annex III recruitment systems to 2 December 2027 and has not yet been adopted. Prepare now regardless: the work below takes longer than the gap to either date.
Why hiring AI is high-risk
The EU AI Act takes a risk-based approach. Annex III lists the use cases the regulation treats as high-risk, and employment is on the list explicitly: AI systems used for recruitment or selection, including placing job adverts, filtering applications and evaluating candidates, sit in the high-risk category.
That is not an edge case reading. Screening tools, ranking tools, assessment scoring, CV parsing that feeds a shortlist: if the output influences who progresses, the system is in scope. The reasoning is straightforward. Hiring decisions shape people's livelihoods, and group-level skew in an automated tool scales across every candidate it touches.
Who carries which obligations
The Act splits responsibility between providers, who build and supply the AI system, and deployers, who use it. An employer running an AI hiring tool is a deployer. That role carries its own duties; you cannot outsource them to your vendor.
As a deployer of a high-risk hiring system you must, among other things:
- Use the system as instructed. Follow the provider's instructions for use, and assign human oversight to people with the competence, training and authority to exercise it properly.
- Keep a human meaningfully in the loop. Oversight is not a checkbox. The person reviewing AI output must be able to understand it, question it and overrule it.
- Mind your input data. Where you control the input data, you are responsible for making sure it is relevant and sufficiently representative for the system's intended purpose.
- Monitor and report. Watch the system's operation, and if you identify a serious risk, inform the provider and the relevant authority. Retain the automatically generated logs that are under your control.
- Tell candidates. People subject to a high-risk AI system in hiring must be informed that it is being used. Quiet deployment is not an option.
- Inform workers and their representatives before putting a high-risk AI system into service in the workplace.
Providers carry the heavier conformity burden: risk management, data governance, technical documentation, accuracy and robustness testing, post-market monitoring. When you evaluate a vendor, you are evaluating whether they can evidence that work, because their gaps become your operational risk.
Does this apply to UK employers?
Often, yes. The Act reaches beyond the EU's borders in two ways that matter for UK companies. If you are hiring into EU member states, or the output of your AI system is used in the EU, you are in scope regardless of where your company sits. And if you operate EU entities, those entities are deployers in their own right.
UK-only hiring still does not mean a compliance holiday. The Equality Act 2010 applies to every stage of your process, automated or not, and discrimination claims do not require proof of intent. An AI tool that produces worse outcomes for a protected group exposes you under UK law today, before any EU enforcement question arises. UK data protection law also restricts solely automated decisions with significant effects, which a hiring outcome plainly is.
The dates that matter, and the one that is moving
The Act entered into force in August 2024 and applies in stages. Prohibited practices, such as emotion recognition in the workplace, have applied since February 2025. General-purpose AI obligations began in August 2025. The high-risk obligations that cover hiring systems under Annex III are, in the Regulation as it currently stands, set to apply from 2 August 2026. Penalties for non-compliance scale to the higher of a fixed sum in the tens of millions of euros or a percentage of global turnover, depending on the breach.
That 2 August 2026 date is no longer settled. On 7 May 2026 the EU reached a provisional political agreement, part of the reported Digital Omnibus simplification package, that would defer the application of obligations for stand-alone Annex III high-risk systems, the category that includes recruitment and selection AI, to 2 December 2027. As we publish, that agreement is provisional and has not yet been formally adopted, so the date that legally stands today is 2 August 2026. A deferral could be confirmed, amended, or fall away. State plainly which date you are relying on and as of when, and do not hang an internal programme or a customer commitment on a single contested date.
The practical conclusion holds under either date: this is not the moment to wait. Vendor due diligence, oversight design and candidate-facing transparency all take longer than a quarter to do honestly, whether the deadline turns out to be 2 August 2026 or 2 December 2027. Prepare now regardless. For the dates set out side by side and the wider picture, see our pillar guide, the EU AI Act and recruitment.
A practical checklist
A reasonable programme for an SME between now and the enforcement date looks like this:
- Inventory your AI. List every tool in your hiring process that scores, ranks, filters or summarises candidates. Include features inside tools you think of as "just an ATS".
- Ask each vendor for evidence. Technical documentation, risk assessment, bias testing results, instructions for use, logging capability. A provider that cannot produce these is asking you to carry their risk.
- Design real human oversight. Name the people, train them, and make sure the tool presents evidence they can interrogate rather than a verdict they can only accept.
- Write the candidate disclosure. Decide where and how applicants are told that AI is involved, what it does, and who makes the final decision.
- Stand up monitoring. Group-level outcome monitoring, such as the four-fifths rule used in adverse-impact analysis, catches skew while it is still a correction rather than a claim.
- Keep records. Logs, decisions, overrides and the reasons for them. If a decision is ever challenged, the contemporaneous record is what carries weight.
How KimonRecruit approaches this
We built KimonRecruit for these obligations ahead of the enforcement date, because retrofitting them is far harder than designing for them. The platform produces decision support, never automated outcomes: there is no code path that takes a candidate out of a pipeline without a human recruiter making that call. Every assessment score is replayable from the prompt, model and version that produced it. An adverse-impact dashboard monitors outcomes across Equality Act 2010 characteristics continuously, and candidates are told how AI is used in their process.
None of that removes the deployer duties described above. It does mean the evidence you need for them, including logs, explanations, oversight records and monitoring, is generated by the platform as you hire, rather than assembled in a panic when someone asks.
The employers who will find the enforcement date uneventful, whichever date it turns out to be, are the ones who treated the Act as a design constraint rather than a deadline. There is still time to be one of them.
Found this useful? Share via email. · Read more →
