EU AI Act Slipped 16 Months. Article 50 Didn't. Diligence Can't.
The Digital Omnibus deferred Annex III hiring-AI rules to Dec 2, 2027, but Article 50 transparency hits Aug 2, 2026. Here is the vendor diligence to run now.
On July 24, 2026, Regulation (EU) 2026/1744 (the Digital Omnibus on AI) landed in the Official Journal and, three days later, quietly rewrote every hiring-AI compliance calendar in Europe. High-risk obligations for Annex III employment systems just slid from August 2, 2026 to December 2, 2027. Article 50 transparency duties did not move.
That asymmetry is the whole story. If you procure sourcing software for an EU workforce, it is now the diligence question.
What actually changed on July 24, 2026
The Digital Omnibus deferred the substantive obligations for Annex III high-risk hiring AI by 16 months, from August 2, 2026 to December 2, 2027, while leaving Article 50 transparency duties on the original August 2, 2026 date. Everything else about the AI Act - prohibitions, scope, penalties framework - still stands.
The mechanics, in order:
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted July 8, 2026, published in the Official Journal on July 24, 2026, and entered into force July 27, 2026.
- Annex III high-risk systems (which explicitly cover AI used to place targeted job ads, filter applications, and evaluate candidates) now apply from December 2, 2027.
- High-risk AI embedded in Annex I products (regulated safety goods) slides further, to August 2, 2028.
- Article 5 prohibited practices land in between, on December 2, 2026.
- Article 50 transparency (labeling AI-generated content, disclosing chatbots and synthetic media to the person interacting) still applies from August 2, 2026.
- The Strasbourg vote was 569 in favor, 45 against.
The stated reason was not lobbying. It was capacity. By March 2026, only 8 of 27 Member States had designated the national competent authorities the Act requires. Brussels punted because Brussels had to.
Why the 16-month "pause" is actually a permanent loophole
Article 111 of the AI Act is not retroactive, which means any hiring-AI product placed on the EU market before December 2, 2027 can sit permanently outside the high-risk regime unless the vendor "substantially modifies" it later. The delay is not a pause. For a subset of vendors, it is a legal off-ramp.
Laura Caroli, one of the AI Act's co-negotiators, put it plainly to Tech Policy Press: a covered system "may remain outside the AI Act indefinitely, unless it is substantially altered after that date." Bram Vranken at Corporate Europe Observatory said the quiet part louder: "a large part of high-risk AI systems that have been placed on the market before December 2027 will never have to comply with the rules."
The rational vendor response writes itself:
- Freeze the EU SKU. Ship the same model, same UI, same scoring logic through December 1, 2027.
- Route EU customers to that frozen SKU on the "placed on the market before" grandfather.
- Push interesting features into a separate US or global SKU that is never "placed on the market" in the EU as a new product.
- Redefine model updates as "operational" rather than "substantial" so grandfathering survives.
If your ATS vendor, your candidate-scoring layer, or your outbound sourcing tool executes that playbook, the December 2027 deadline never actually reaches you. You inherit a permanently un-conformant tool, and the enforcement conversation, when it comes, lands on you as the deployer.
The delay is not a pause. For some vendors, it is a legal off-ramp with your logo on it.
The one diligence question that flushes this out: "Will your EU product be re-placed on the market as a new system on or after December 2, 2027, and will you commit to that in the DPA?" A vendor that says yes is planning to comply. A vendor that dodges is planning to grandfather.
Article 50 is the only live obligation between Aug 2, 2026 and Dec 2, 2027
From August 2, 2026 through December 1, 2027, the only AI Act duty biting sourcing tools is Article 50 transparency: candidates must know when they are talking to a bot, receiving AI-generated messages, or hearing a synthetic voice. That is exactly the surface area of a modern sourcing stack.
Most sourcing tools ship AI-drafted outreach by default. Many now ship AI voice agents for screening. A few ship candidate-facing chatbots on the careers site. Under Article 50, each of those needs a clear, machine-readable disclosure to the recipient, and, for synthetic media, a detectable marker. This is the diligence question during the gap, not the model card, not the bias metric.
Concretely, ask every hiring-AI vendor:
- Does every AI-drafted outbound message carry a disclosure the candidate can see before they reply?
- Are AI voice screens announced as AI at the start of the call, in the candidate's language?
- Do you watermark or label AI-generated candidate summaries shared with hiring managers?
- Where is the audit log that proves disclosure happened, per message, per call?
This is also where a plain-English sourcing layer earns its keep. Refolk drafts nothing you did not ask for and never impersonates a human on the candidate side. When you use Refolk to ask "senior Rust engineers in Berlin who ship on-prem" and get a ranked shortlist, the AI work happens in the query, not in a synthetic voicemail to the candidate. That keeps the Article 50 surface narrow and auditable.
The EU has ~16 people to review this. The US has ~1,415.
In Refolk's index of professional profiles, only about 16 professionals across Germany, France, the Netherlands, Ireland, Spain, Belgium, Italy, and Sweden publicly headline "AI Act" or "responsible AI compliance" work. The comparable US pool for "responsible AI governance" is roughly 1,415. That is an 88x gap, and it is why "we'll hire an AI Act compliance officer" is not a plan.
The full picture from Refolk's index, alongside the public regulatory numbers:
| Metric | Value | Source |
|---|---|---|
| EU-8 professionals headlining "AI Act / responsible AI compliance" | 16 | Refolk's index |
| US professionals headlining "responsible AI governance" | 1,415 | Refolk's index |
| US-to-EU-8 ratio of surfaced governance talent | ~88x | Derived |
| Top EU employer of AI-Act compliance profiles | European Commission (3) | Refolk's index |
| EU-8 TA / Head-of-Talent profiles that mention "AI" | 25 | Refolk's index |
| Top employer among AI-mentioning EU TA leaders | Mistral (3) | Refolk's index |
| Strasbourg vote on the Digital Omnibus | 569 to 45 | actuia.com |
| Member States with a designated AI authority by March 2026 | 8 of 27 | actuia.com |
Two things fall out of that table. First, the European Commission itself is the single largest employer of AI-Act compliance profiles Refolk can surface in the EU-8, with three. Three. Second, among EU TA leaders whose profile even mentions AI, Mistral surfaces most often, also with three. The market you would hire from to run your AI-Act diligence is that shallow.
The practical implication: diligence has to be codified into procurement templates and re-run yearly, not delegated to a hire that does not exist. The advisory layer TA teams will actually lean on in the 16-month gap is the usual suspects (Accenture, Deloitte, Orange Cyberdefense, Fraunhofer IAIS, Rabobank's in-house team) plus the works council.
The AI literacy downgrade shifts liability to you
The Digital Omnibus softened Article 4's AI literacy duty from "ensure a sufficient level of AI proficiency" to "support the improvement of AI proficiency," which sounds cosmetic and is not. When the statutory floor gets vaguer, DPAs, works councils, and labor courts fill the gap, and they fill it against the employer, not the vendor.
ETUC and industriAll Europe flagged this in July: "The few workplace references in the AI Act now risk being weakened by the Digital Omnibus." Translation: German Betriebsrat and French CSE will treat AI-in-hiring as a co-determination topic regardless of what the Omnibus says. The de facto compliance layer is your internal training program plus the works-council agreement, not the recital.
What to put in the 2026 to 2027 procurement template:
- A one-page model card the recruiter can actually read, in the local language.
- A named internal owner (not "TA ops," a person) for each AI feature in the stack.
- A quarterly log of AI-assisted decisions per requisition, exportable to the works council.
- A clause that any vendor "substantial modification" triggers re-review before the update ships to EU users.
What survived the Omnibus, and what to ask vendors now
Two obligations survived and matter for hiring: the EU high-risk database registration for providers, and the strict-necessity standard for processing special-category personal data when doing bias detection. Both make the vendor's answer to "how do you test for bias" a legal question, not a marketing one.
The Digital Omnibus reinstated the requirement that providers register high-risk systems in the EU database, and preserved the strict-necessity standard for processing special categories of personal data specifically for bias detection and correction. That means a vendor cannot say "we test for bias on your candidate data" without a lawful basis and a documented necessity test. It also means, come December 2, 2027, you should be able to look your vendor up in the public database. If they will not be there, ask why.
The diligence questions worth writing into the MSA today:
- Confirm in writing whether the EU product will be "placed on the market" as a new system on or after December 2, 2027.
- Name the intended lead supervisory authority and confirm that Member State has staffed it.
- Provide an Article 50 disclosure spec for every AI touchpoint that reaches a candidate.
- Commit to the strict-necessity standard for any bias testing that touches special-category data (Art. 9 GDPR).
- Trigger clause: any "substantial modification" (Art. 43(4) / Art. 3(23)) requires 60-day notice and customer sign-off.
- On request, provide the EU high-risk database registration ID once available.
If a vendor cannot answer 1, 3, and 5 in writing, they are not ready to sell to an EU-facing TA team, whatever the delay says. Sourcing tools that keep their AI surface on the query side rather than the candidate side make this shorter. Refolk sits on that side of the line: you ask in plain English, you get people, and the candidate-facing surface stays yours.
FAQ
Did Article 50 transparency really stay at August 2, 2026?
Yes. The Digital Omnibus moved the Annex III high-risk application date to December 2, 2027 and the Annex I embedded-product date to August 2, 2028, but Article 50 transparency duties still apply from August 2, 2026. Any candidate-facing chatbot, AI-drafted outreach, or synthetic voice screen your stack ships in the EU needs a disclosure now, not later. Confirm this with your vendor in writing before your next EU sourcing campaign goes out.
What is the "Article 111 loophole" in one sentence?
Article 111 makes the AI Act non-retroactive, so hiring-AI systems placed on the EU market before December 2, 2027 can remain outside the high-risk regime indefinitely unless the vendor substantially modifies them. Former co-negotiator Laura Caroli warned that a covered system "may remain outside the AI Act indefinitely, unless it is substantially altered after that date." The diligence question: will your vendor re-place the product as a new system after the deadline, or grandfather the old one?
Should we still buy hiring AI during the 16-month gap?
Yes, but procure as if December 2, 2027 were tomorrow. Put Annex III-grade diligence into the MSA now (disclosure spec, substantial-modification trigger, lead supervisor, database registration, strict-necessity clause for bias testing), because you cannot rely on a European hire to backfill the work. Refolk's index shows roughly 16 people across the EU-8 who publicly do this compliance work, versus about 1,415 in the US.
Who actually enforces this between now and December 2027?
Mostly no one at the AI-Act level, because only 8 of 27 Member States had designated a competent national authority by March 2026, and even after the deadline enforcement will be uneven for 12 to 18 months. In the interim, expect data protection authorities (under GDPR), works councils (under national labor law), and the Article 50 transparency regime to carry the load. Plan diligence around those three, not around a hypothetical AI Office knock on the door.
Try it on your own search
Stop building boolean strings. Just describe the person.
Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.
- One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
- Read live at search time, not from a database that went stale last quarter.
- Watch every step as it runs, and see why each name made the list.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
500 free credits on sign-up. No card, no demo call. See real searches.