The 90-second version
The EU's Digital Omnibus simplification package cleared its last hurdle on 29 June 2026, after the European Parliament endorsed it on 16 June (Council of the EU). The headline change: the AI Act's obligations for high-risk systems, the category that explicitly includes AI used for recruitment, candidate selection, and screening, are deferred from 2 August 2026 to 2 December 2027 for standalone systems, and to 2 August 2028 for AI embedded in already-regulated products (Gibson Dunn). This is settled, not pending: the text was published in the EU's Official Journal on 24 July 2026 (Future of Privacy Forum), so those dates are the law now.
So the paperwork that comes with being classified high-risk (risk management, technical documentation, human-oversight design, conformity assessment) now lands in late 2027 instead of August 2026. That is real relief for anyone building hiring AI. For an agency that uses it, the picture is different, and quieter.
What did not move (this is the part that matters)
Automated rejection of candidates is a GDPR question, not an AI Act one
If a tool in your stack scores applicants and filters some out before a human looks, and you are hiring in the EU, you are already inside Article 22 of the GDPR, which has applied since 2018 and was untouched by the omnibus (GDPR, EUR-Lex). Article 22 gives a candidate the right not to be subject to a decision based solely on automated processing where it significantly affects them. Rejecting someone from a job is exactly that kind of decision.
The AI Act delay changes when you must produce a conformity file. It does nothing to that right. Those are two different laws on two different clocks, and only one of them slipped.
If you are hiring in the UK, the rest of this section does not describe your position. See the UK section below, because it changed in February 2026 and it changed in the opposite direction to what most people assume.
"Human in the loop" has a specific meaning
The get-out clause for Article 22 is genuine human involvement. But a recruiter clicking "confirm" on a ranked list they didn't really review does not count: EU guidance has been consistent that review has to be carried out by someone with the competence and authority to change the outcome. In practice that means three things, and they are worth designing for rather than arguing about later: the person needs the authority to override the decision, access to the data the system used, and enough understanding of how the tool reached its result to disagree with it. A rubber stamp is not human review, and calling it one does not make it compliant.
The transparency duties were not delayed either
Separately from the high-risk regime, the AI Act's transparency obligations still apply from 2 August 2026. If you use an AI chatbot to talk to candidates, you have to tell them it's AI. If you publish AI-generated content, it has to be labelled. None of that was pushed back.
If you hire in the UK, this went the other way
Everything above is the EU position. The UK is not on the same track any more, and the difference is not a technicality.
The Data (Use and Access) Act 2025, section 80, replaced Article 22 of the UK GDPR with new Articles 22A to 22D. It came into force on 5 February 2026 (SI 2026/82, reg 2, which commences "section 80 (automated decision-making)"). Article 22 of the UK GDPR, in the form the rest of this article describes, no longer exists.
What changed: the blanket right not to be subject to a solely automated significant decision now survives only where the decision rests on special category data. For ordinary candidate data, which is what a CV is, there is no longer a standing right to block automated screening. What replaced it is a duty to provide safeguards, which the candidate then has to invoke. The new Article 22C, paragraph 2, reads:
"The safeguards must consist of or include measures which— (a) provide the data subject with information about decisions described in paragraph 1 taken in relation to the data subject; (b) enable the data subject to make representations about such decisions; (c) enable the data subject to obtain human intervention on the part of the controller in relation to such decisions; (d) enable the data subject to contest such decisions."
Read that carefully, because it cuts both ways. It is genuinely lighter than the EU regime: automated screening of ordinary candidate data is not prohibited in the UK the way this article describes for the EU. But every one of those four things is something your system has to be able to do on request, and most systems cannot. Telling a candidate what the decision was based on, six months later, is a records question before it is a legal one.
The practical upshot for a UK agency is the opposite of relief: you have fewer prohibitions and more things you must be able to produce on demand.
The one-line summary: the delay helps the companies that build recruitment AI. It does almost nothing for the agency that runs it. In the EU, because the duty you are most likely to breach, letting a machine quietly reject people, lives in GDPR Article 22, which did not change and is being enforced right now. In the UK, because the equivalent rule changed in February 2026 into a set of things you have to be able to show a candidate on request, and showing them is a records problem.
Why "we'll deal with it in 2027" is the wrong read
The AI Act headline says 2027, so it's easy to file the whole topic under "later." The trap is that the regulator with the nearer deadline is the data-protection one, and it is looking at exactly the thing agencies do casually.
On 19 March 2026 the European Data Protection Board launched its 2026 coordinated enforcement action on transparency, focused on Articles 12 to 14 of the GDPR, the rules about what you tell people when you collect and process their data. Twenty-five national authorities are contacting controllers across sectors through the year (EDPB). Candidate privacy notices, and whether they honestly explain any automated screening, are squarely in scope. That's this year, not 2027.
What a boutique agency should actually check
None of this needs an AI Act compliance project. It's a short, practical review of what your existing tools do to candidates, and what you tell them about it.
A 30-minute self-audit
- List every tool that scores, ranks, or filters applicants. ATS matching, a CV-screening plugin, an AI sourcing tool. If it orders or rejects candidates, it counts.
- For each, ask: does a human see everyone before anyone is rejected? If the tool auto-rejects below a threshold, that's the Article 22 exposure in the EU. In the UK it is not prohibited on ordinary candidate data, but you must still be able to explain the decision and produce a human review on request. Either way, move the cut to a person.
- Check the "human" is real. Can that person actually see why the tool ranked someone low, and override it? If not, it's a rubber stamp.
- Read your candidate privacy notice. Does it say, in plain words, that you use automated tools in screening and what that means for the applicant? If it's silent, that's the CEF 2026 exposure.
- Label your AI touchpoints. If a chatbot or auto-responder talks to candidates, disclose it's AI. Due August 2026, not 2027.
- Write down who decided. Keep a light record that a named person made the shortlist call. If a candidate ever challenges a rejection, that record is your answer.
A note on the numbers. Fines under the AI Act and GDPR run into the millions on paper, but headline maximums are for the worst systemic cases, not a small agency's first misstep. Ignore anyone quoting you a specific penalty figure for your situation; it's scare-selling. The real cost of getting this wrong is more mundane and more likely: a candidate complaint, a regulator's letter during the 2026 enforcement sweep, and the time it eats to answer it.
The honest bottom line
The delay is good news, mostly for vendors. For an agency, the useful takeaway is the opposite of "relax": the rule that can actually bite you didn't move, and the regulator enforcing the related transparency duties is active this year. The fix isn't a compliance binder. It's making sure a person, not a score, does the rejecting, and saying so plainly to candidates.
That's also just how I think AI belongs in recruitment, deadline or no deadline. The tools I build draft the message, read the CV, and fill the fields, so the busywork disappears. They never reject anyone. A person always makes the call, and the system keeps a record that they did. If you'd like to see what that looks like in a working system, the demo on the Sorapis site runs the real product, and you can read more on keeping candidate data in your own tenant or the related pay-transparency changes landing this year.
AI that removes typing, not judgment.
I build recruitment CRMs on the Microsoft 365 you already pay for. AI pulls data from CVs, drafts outreach, and composes client-ready summaries. Every decision stays with a person, and the system logs who made it. In the EU that is what Article 22 asks for. In the UK it is more than the law now demands, and it is also the only way to answer a candidate who asks why, which the new Article 22C entitles them to do. If that's the kind of system you want, send a short note about your agency and I'll come back with a tailored concept.
Get a tailored concept →Sources
- Council of the EU, 29 June 2026: Final green light to simplify and streamline AI rules
- Gibson Dunn: EU AI Act Omnibus agreement, postponed high-risk deadlines
- Future of Privacy Forum: The AI Act implementation timeline, what changes under the AI Omnibus (records publication in the Official Journal on 24 July 2026)
- Ogletree Deakins: EU delays rules for AI use in employment decisions
- White & Case: EU agrees Digital Omnibus deal to simplify AI rules
- GDPR Article 22: Regulation (EU) 2016/679, EUR-Lex full text
- UK, automated decision-making rewritten: Data (Use and Access) Act 2025, section 80
- UK, when it started: SI 2026/82, reg 2 (commencement)
- EDPB, 19 March 2026: CEF 2026 coordinated enforcement on transparency and information obligations