← Back to Blog
Compliance 2 August 2026 · 6 min read

The EU delayed the AI hiring rules to 2027. Here's what still applies to your agency now.

On 29 June 2026 the Council of the EU gave final approval to push the AI Act's high-risk obligations, the ones that cover recruitment and hiring AI, from 2 August 2026 out to 2 December 2027. If you read that as "we can stop worrying about AI compliance," you've misread it. The rule most likely to catch a boutique agency was never on that clock. It's GDPR Article 22, it has applied since 2018, and it did not move.

The 90-second version

The EU's Digital Omnibus simplification package cleared its last hurdle on 29 June 2026, after the European Parliament endorsed it on 16 June (Council of the EU). The headline change: the AI Act's obligations for high-risk systems, the category that explicitly includes AI used for recruitment, candidate selection, and screening, are deferred from 2 August 2026 to 2 December 2027 for standalone systems, and to 2 August 2028 for AI embedded in already-regulated products (Gibson Dunn). This is settled, not pending: the text was published in the EU's Official Journal on 24 July 2026 (Future of Privacy Forum), so those dates are the law now.

So the paperwork that comes with being classified high-risk (risk management, technical documentation, human-oversight design, conformity assessment) now lands in late 2027 instead of August 2026. That is real relief for anyone building hiring AI. For an agency that uses it, the picture is different, and quieter.

What did not move (this is the part that matters)

Automated rejection of candidates is a GDPR question, not an AI Act one

If a tool in your stack scores applicants and filters some out before a human looks, you are already inside Article 22 of the GDPR, which has applied since 2018 and was untouched by the omnibus (GDPR, EUR-Lex). Article 22 gives a candidate the right not to be subject to a decision based solely on automated processing where it significantly affects them. Rejecting someone from a job is exactly that kind of decision.

The AI Act delay changes when you must produce a conformity file. It does nothing to the candidate's existing right to a human in the loop. Those are two different laws on two different clocks, and only one of them slipped.

"Human in the loop" has a specific meaning

The get-out clause for Article 22 is genuine human involvement. But a recruiter clicking "confirm" on a ranked list they didn't really review does not count. The established regulatory standard is that the person must have the authority to override the decision, access to the data the system used, and enough understanding of how the tool reached its result to disagree with it. A rubber stamp is not human review, and calling it one does not make it compliant.

The transparency duties were not delayed either

Separately from the high-risk regime, the AI Act's transparency obligations still apply from 2 August 2026. If you use an AI chatbot to talk to candidates, you have to tell them it's AI. If you publish AI-generated content, it has to be labelled. None of that was pushed back.

The one-line summary: the delay helps the companies that build recruitment AI. It does almost nothing for the agency that runs it, because the duty you're most likely to breach, letting a machine quietly reject people, lives in GDPR, which didn't change, and is being actively enforced right now.

Why "we'll deal with it in 2027" is the wrong read

The AI Act headline says 2027, so it's easy to file the whole topic under "later." The trap is that the regulator with the nearer deadline is the data-protection one, and it is looking at exactly the thing agencies do casually.

On 19 March 2026 the European Data Protection Board launched its 2026 coordinated enforcement action on transparency, focused on Articles 12 to 14 of the GDPR, the rules about what you tell people when you collect and process their data. Twenty-five national authorities are contacting controllers across sectors through the year (EDPB). Candidate privacy notices, and whether they honestly explain any automated screening, are squarely in scope. That's this year, not 2027.

What a boutique agency should actually check

None of this needs an AI Act compliance project. It's a short, practical review of what your existing tools do to candidates, and what you tell them about it.

A 30-minute self-audit

  1. List every tool that scores, ranks, or filters applicants. ATS matching, a CV-screening plugin, an AI sourcing tool. If it orders or rejects candidates, it counts.
  2. For each, ask: does a human see everyone before anyone is rejected? If the tool auto-rejects below a threshold, that's the Article 22 exposure. Move the cut to a person.
  3. Check the "human" is real. Can that person actually see why the tool ranked someone low, and override it? If not, it's a rubber stamp.
  4. Read your candidate privacy notice. Does it say, in plain words, that you use automated tools in screening and what that means for the applicant? If it's silent, that's the CEF 2026 exposure.
  5. Label your AI touchpoints. If a chatbot or auto-responder talks to candidates, disclose it's AI. Due August 2026, not 2027.
  6. Write down who decided. Keep a light record that a named person made the shortlist call. If a candidate ever challenges a rejection, that record is your answer.

A note on the numbers. Fines under the AI Act and GDPR run into the millions on paper, but headline maximums are for the worst systemic cases, not a small agency's first misstep. Ignore anyone quoting you a specific penalty figure for your situation; it's scare-selling. The real cost of getting this wrong is more mundane and more likely: a candidate complaint, a regulator's letter during the 2026 enforcement sweep, and the time it eats to answer it.

The honest bottom line

The delay is good news, mostly for vendors. For an agency, the useful takeaway is the opposite of "relax": the rule that can actually bite you didn't move, and the regulator enforcing the related transparency duties is active this year. The fix isn't a compliance binder. It's making sure a person, not a score, does the rejecting, and saying so plainly to candidates.

That's also just how I think AI belongs in recruitment, deadline or no deadline. The tools I build draft the message, read the CV, and fill the fields, so the busywork disappears. They never reject anyone. A person always makes the call, and the system keeps a record that they did. If you'd like to see what that looks like in a working system, the demo on the Sorapis site runs the real product, and you can read more on keeping candidate data in your own tenant or the related pay-transparency changes landing this year.

Sorapis · AI, kept honest

AI that removes typing, not judgment.

I build recruitment CRMs on the Microsoft 365 you already pay for. AI pulls data from CVs, drafts outreach, and composes client-ready summaries. Every decision stays with a person, and the system logs who made it, which is exactly what Article 22 asks for. If that's the kind of system you want, send a short note about your agency and I'll come back with a tailored concept.

Get a tailored concept →
Anto Andrijanic · Sorapis · Custom CRM and compliance-aware systems for boutique recruitment firms on Microsoft 365.