If you read a guide on AI and hiring written before the summer of 2026, it almost certainly tells you that the high-risk obligations apply on 2 August 2026. That date is no longer correct.
Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the application date for standalone high-risk AI systems under Annex III to 2 December 2027.
That matters for recruitment, because recruitment is one of the Annex III categories.
Why recruitment AI is high-risk in the first place
Annex III, point 4 of the AI Act names employment explicitly. It covers two things.
First: "AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates."
Second: "AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships."
Read that carefully. Targeted job advertising is in scope. CV screening is in scope. So is performance monitoring. If your ATS ranks candidates, or your job ads are algorithmically targeted, you are inside Annex III.
What exactly moved, and what did not
The deferral is narrower than the headlines suggest.
- Standalone Annex III high-risk systems, which includes recruitment and employment: moved from 2 August 2026 to 2 December 2027.
- AI embedded in products already covered by EU product-safety law (Annex I): moved to 2 August 2028.
- The prohibited practices and the AI literacy obligation, which have applied since 2 February 2025: unchanged.
That last line is the one people miss. Emotion recognition in the workplace is a prohibited practice, not a high-risk one. It has been banned since February 2025 and nothing in the Digital Omnibus changes that. A vendor selling you interview software that infers a candidate's emotional state is not offering you something you can deploy in 2027 either.
Why the Commission moved the date
Not because the risk went away.
The stated reason is readiness: the harmonised standards being developed by CEN and CENELEC were not going to be finished in time, and the conformity assessment infrastructure the Act assumes would exist had not matured. In other words, companies were about to be asked to demonstrate conformity against standards that did not yet exist.
That is a procedural reprieve, not a policy reversal. The obligations are the same obligations, arriving sixteen months later.
You are almost certainly a deployer, not a provider
This distinction decides how much work you actually have.
If you build the screening model, you are a provider and you carry the heavy obligations: risk management, data governance, technical documentation, conformity assessment. Very few Belgian employers are in this position.
If you buy an ATS or an assessment tool and switch the AI features on, you are a deployer. Your duties are lighter but they are real, and the one that matters most in hiring is transparency: you have to inform candidates and employees that a high-risk AI system is being used and explain how it operates.
The practical risk for most companies is therefore not engineering. It is that nobody can say which tools in the HR stack have AI in them.
What to do with the extra sixteen months
Three things, in this order.
Inventory first. List every tool touching sourcing, screening, assessment, scheduling and performance, and ask each vendor in writing whether the product falls under Annex III and what their compliance roadmap is. A vendor who cannot answer that in 2026 is a risk in 2027.
Then fix the transparency layer, because it is cheap now and it is also good practice under GDPR, which already applies. Candidates should know when a machine is involved in the decision.
Then keep the human in the loop and make it documented rather than assumed. "A recruiter always reviews the shortlist" is worth very little if nobody can evidence it.
The Belgian layer on top
The AI Act is a regulation, so it applies directly in Belgium without transposition. But it lands on top of rules that already bite.
GDPR governs automated decision-making and profiling regardless of what the AI Act says, and the Belgian Data Protection Authority has already published guidance on candidate recruitment. Collective labour agreements and works council information duties apply to monitoring tools. None of that was deferred.
We covered the broader Belgian compliance picture here: the EU AI Act in Belgium and what HR, finance and compliance teams must prepare for.
In short
Recruitment AI is high-risk under Annex III of the EU AI Act. The obligations now apply from 2 December 2027, not August 2026, following Regulation (EU) 2026/1744.
The prohibitions from February 2025 did not move, and emotion recognition in the workplace remains banned outright.
Most employers are deployers, which means the work is inventory, transparency and documented human oversight rather than conformity engineering. Sixteen extra months is enough time to do that properly, and not much more than enough. Given how fast the dates have shifted, verify the current position against the Official Journal text before you build a compliance plan on any article, including this one.