EU AI Act Aug 2 Deadline: 876 EU TA Leaders, 8 Governance Owners
The Aug 2, 2026 EU AI Act deadline reclassified most AI sourcing tools as high-risk. Here's what changed, who's liable, and what to audit first.
On August 2, 2026, the EU AI Act's high-risk obligations for hiring and employee selection went live under Regulation (EU) 2024/1689. Every AI sourcing engine, CV ranker, outreach personalizer, and interview scorer touching an EU candidate is now in scope, and the deployer obligations sit on you, not just your vendor.
Most buyers have not mapped which tools got reclassified, and the political noise around a possible delay is making the problem worse.
What actually changed on August 2, 2026
The bulk of substantive obligations for high-risk AI systems became binding, and Annex III, point 4 explicitly captures recruitment and selection. That includes AI used to place targeted job ads, analyze and filter job applications, and evaluate candidates. In practice, the tools your team uses every day (autonomous sourcing agents, ranked shortlists, "fit" scoring, interview transcript scorers) are now the regulated category.
Two things to pin down immediately:
- Penalties are real. Non-compliance with high-risk obligations can reach €15M or 3% of global annual turnover. Prohibited practices (workplace emotion recognition, biometric categorization of protected traits) reach €35M or 7%. Supplying incorrect information to authorities is its own €7.5M or 1% tier.
- The "delay" is not law yet. The Commission proposed a Digital Omnibus on 19 November 2025 that would push Annex III obligations to 2 December 2027. A provisional agreement was reached on 7 May 2026. Until it is formally adopted, the August 2, 2026 date remains binding. Acting as if the delay already passed is a bet, not a compliance strategy.
Which tools got reclassified as "high-risk"
Any AI system that ranks, scores, filters, or targets candidates for an EU-facing role is now presumptively high-risk under Annex III 4(a). The bar is lower than most buyers assume: "sourcing" tools got quietly folded into "selection" tools because filtering a prospect list is a decision that shapes who gets considered.
The exposure map, in order of severity:
- Autonomous "AI recruiter" agents that source, score, and message without a human in the middle. Highest exposure. If you white-labeled one or fine-tuned it on your ATS data, you likely became a provider, not just a deployer, which triggers CE marking, EU database registration, and post-market monitoring.
- CV rankers and screeners (HireVue, Eightfold, Paradox for screening flows). Classic 4(a) territory.
- Sourcing engines that rank or score prospects (HireEZ, HeroHunt.ai, LinkedIn Recruiter's AI features). The ranking itself is the regulated act.
- Interview scoring and assessment tools. Anything producing a numeric "fit" score is inside the tent.
- Outreach personalizers that score prospect quality. Lower risk if they only draft copy, higher risk if they gate who gets contacted.
Already banned since 2 February 2025, regardless of the August deadline:
- Workplace emotion recognition ("read tone/facial cues")
- Biometric categorization of protected traits
- Social scoring
- Harmful manipulation via AI
If a vendor pitch still leads with facial-cue reading or trait inference, that is a €35M-tier problem, not a procurement conversation.
The EU deployer population nobody has counted
Roughly 876 senior Talent Acquisition and People leaders across eight major EU economies are now, functionally, Article 26 deployers the moment their teams use AI sourcing on an EU candidate. In Refolk's index of professional profiles, that is the population most of the enforcement risk actually sits on, and it is not a group most compliance programs have identified as regulated actors.
Here is the shape of the market against the compliance layer that is supposed to guard it:
| Segment (EU footprint) | Count in Refolk's index | What it means |
|---|---|---|
| Senior TA/People leaders (Director/VP/Manager), DE FR NL IE ES SE IT PL | 876 | Deployers now on the hook for Article 26 duties |
| Technical Recruiters and Sourcers, DE FR NL IE ES | 701 | Front-line users of newly high-risk tooling |
| "AI Governance / Ethics / Compliance" titled pros, same DE-FR-NL-IE-ES footprint | 8 | Entire dedicated governance layer in those countries |
| Ratio: sourcers per dedicated AI-governance pro (EU-5) | ~88:1 | The audit-capacity gap |
| Max deployer fine, high-risk breach | €15M or 3% global turnover | Regulation (EU) 2024/1689 |
| Max fine, prohibited practices | €35M or 7% global turnover | Same regime |
Named employers on the tiny governance side include Rabobank, NXP Semiconductors, Fraunhofer IAIS, and Johnson Controls. Those are useful anchors for what "good" looks like: dedicated governance headcount attached to the AI, not bolted onto a data protection officer's already-full plate.
Why the ratio matters more than the fine
GDPR followed exactly this pattern. The first wave of enforcement did not hit companies without any DPO. It hit companies who assumed that buying SaaS from a "GDPR-compliant" vendor discharged their own controller duties. The AI Act is set up to repeat that story with deployers who assume a vendor's conformity assessment covers them. It does not.
Deployer obligations you cannot offload to your vendor
Article 26 imposes independent deployer duties that cannot be contracted away, and most sourcing teams have not read it. Vendor marketing tends to absorb all the compliance attention, which is convenient for the vendor and dangerous for the buyer.
The non-transferable obligations you inherit as a deployer of a high-risk hiring system:
- Use the system according to instructions. Sounds trivial. It is the hook regulators will use when a sourcer uses a screening tool for a use case the vendor never certified.
- Assign human oversight to competent, trained people. Not "someone from ops who has 15 minutes."
- Monitor operation and log incidents. Keep the logs the system generates.
- Inform affected individuals. Candidates must be told when a high-risk system makes or helps make a decision about them. Employees must be informed before high-risk AI is used at their workplace, as a separate duty.
- Do a fundamental rights impact assessment where applicable (public bodies and certain private deployers).
- Cooperate with authorities on request.
The trap most founders will hit: fine-tuning a vendor model on your own ATS data, or slapping your brand on a sourcing agent, can silently upgrade you from deployer to provider. Provider obligations are a much heavier set: conformity assessment, CE marking, EU database registration, post-market monitoring, technical documentation to Annex IV standard. If your engineers are wrapping an open-source model with a custom scorer, you are almost certainly a provider.
Deployer duties do not travel with the invoice. The vendor's compliance page is not your compliance program.
The GDPR Article 22 ceiling nobody talks about
Even a perfectly conformity-assessed high-risk system is still bounded by GDPR Article 22, which limits fully automated rejections without meaningful human review. The AI Act sits on top of GDPR, it does not replace it, and this is where most sourcing pipelines quietly break.
A reviewer clicking through 200 auto-rejections a day is not "human in the loop." It is a rubber stamp, and it is likely non-compliant under both regimes at once. Practical implications:
- Auto-rejection rules based on AI scoring need genuine human judgment attached to each negative decision, not batch approval.
- The candidate notice you send under the AI Act should be paired with a GDPR Article 22 route to contest and to request human review.
- "Assist, don't decide" is the design pattern. A tool that produces a ranked list a human then works through is far cleaner than a tool that eliminates candidates before a human sees them.
This is one of the reasons Refolk was built as an ask-in-plain-English shortlist rather than an autonomous decision engine: you describe the person you're trying to find, get a ranked list across GitHub, LinkedIn, and the open web, and a human decides who to contact. The scoring is transparent, the decision stays with the recruiter, and the Article 22 conversation is much simpler.
Extraterritorial reach: London and New York, this means you
The AI Act applies wherever AI is placed on the EU market, used in the EU, or produces outputs affecting people located in the EU. A recruiter sitting in London or New York screening candidates for an EU-based role is in scope, full stop.
Concrete cases:
- A San Francisco startup running an AI screener on applicants for a Berlin engineer role: in scope.
- A London agency scoring prospects for a Dublin client: in scope.
- A New York VP of Talent using Eightfold on a Paris opening: in scope.
- A remote-first company hiring anywhere including Madrid: in scope for those candidates.
The GetYourGuide, Deliveroo, Meta EU, and Huawei Ireland Research Center recruiting stacks are all sitting inside this perimeter right now, and so is every non-EU firm sourcing into them.
What to actually do this quarter
Stop waiting for the Digital Omnibus vote. Build a defensible position under the current binding text, and if the delay lands in December 2027, you keep the good hygiene for free. AI sourcing compliance in 2026 is a design problem, not a paperwork problem.
A focused 90-day plan:
- Inventory every AI in your hiring path. Sourcing, screening, outreach scoring, assessments, interview tooling. Note vendor, use case, whether it ranks or filters, and whether outputs touch EU candidates.
- Classify each tool against Annex III 4(a) and 4(b). If it ranks or scores humans for hiring, promotion, or termination, assume high-risk until you can defend otherwise.
- Run an automated employment decision tool audit. For each high-risk tool: instructions for use, human-oversight design, logging, incident procedure, candidate notice text, Article 22 route.
- Check the provider trap. If any engineer has fine-tuned a model on ATS data, or you white-label a vendor's agent under your brand, escalate. You may be a provider.
- Kill the banned features. Any emotion recognition or trait inference goes off today. Not next quarter.
- Write the candidate notice and the worker notice. Plain language, in the local language of the role. Deploy candidate notice in the ATS; deliver worker notice before deployment.
- Assign named owners. Given the 88:1 ratio, expect to draft TA leaders into de facto governance roles. Give them the training budget to match.
FAQ
Does the Digital Omnibus delay mean I can ignore the August 2, 2026 deadline?
No. The Commission proposed the Digital Omnibus on 19 November 2025, and a provisional agreement was reached on 7 May 2026 that would defer Annex III obligations to 2 December 2027. Until that legislation is formally adopted, Regulation (EU) 2024/1689 remains binding as written. Acting on an unadopted delay exposes you to enforcement risk, civil claims, and reputational damage that will not wait for the vote.
Is a sourcing tool "high-risk" or only a formal screener?
Annex III 4(a) explicitly covers AI used to place targeted job ads, analyze and filter job applications, and evaluate candidates. Any tool that ranks or scores a prospect list falls inside that scope in most reasonable readings, even if you call it "sourcing" rather than "screening." Autonomous AI recruiter agents are the highest-exposure category. A tool that returns a ranked list for a human to work through is lower risk than one that auto-rejects, but both are still high-risk AI hiring tools under the Act.
If my vendor is compliant, am I compliant?
No. Article 26 imposes deployer obligations (human oversight, logging, candidate notice, worker notice, fundamental rights impact assessment where applicable) that cannot be contracted away. Vendor conformity covers the vendor's provider duties. It does nothing for your deployer duties. If you fine-tune the model on your data or white-label the agent, you can become a provider yourself, which is a heavier obligation set.
We're a US company hiring one engineer in Amsterdam. Does this apply to us?
Yes. The Act reaches non-EU companies where the AI is placed on the EU market, used in the EU, or produces outputs affecting people located in the EU. A single Amsterdam candidate in your pipeline pulls that hiring flow into scope. In practice, most global recruiting stacks are now partly regulated by the AI Act, and treating the EU segment as a carve-out with its own controls (notice text, human review, banned features off) is the cleanest path.
Try it on your own search
Stop building boolean strings. Just describe the person.
Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.
- One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
- Read live at search time, not from a database that went stale last quarter.
- Watch every step as it runs, and see why each name made the list.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
500 free credits on sign-up. No card, no demo call. See real searches.