Refolk
September 14, 2026·10 min read

EU AI Act Deferred to Dec 2027. Outbound Is Still the Loophole.

The EU AI Act's high-risk hiring deadline slipped to Dec 2027. Here is what actually landed on Aug 2, 2026, and why outbound sourcing is safer.

EU AI Act recruitmenthigh-risk AI hiring complianceAI resume screening EUAugust 2026 AI Act deadlineoutbound sourcing compliance
EU AI Act Deferred to Dec 2027. Outbound Is Still the Loophole.

Five days before the EU AI Act was supposed to make hiring AI a "high-risk" system, Brussels blinked. The Digital Omnibus entered into force on 27 July 2026 and pushed the Annex III hiring obligations to 2 December 2027, with product-embedded Annex I systems slipping to 2 August 2028. If you are a TA leader who spent Q2 rewriting DPIAs for an August cutover, you now have a 16-month runway and a very different tactical question: which parts of your stack actually got a reprieve, and which parts never did.

What actually happened on August 2, 2026

The high-risk regime for hiring AI was deferred, but the transparency and AI-literacy duties landed on schedule. Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026, moved Annex III high-risk obligations from 2 August 2026 to 2 December 2027 and Annex I embedded systems to 2 August 2028. What did not move: Article 50 transparency duties and the Article 4 AI literacy obligation both took effect on 2 August 2026 as originally scheduled.

So the AI screener you were going to conformity-assess this summer is not off the hook. It is on a longer, harder hook. Meanwhile, the two things that did land quietly change how you introduce any AI to candidates:

  • Article 50 transparency: candidates must be told, in clear language, when they are interacting with an AI system (an AI interviewer, a chatbot recruiter, a scoring model). Live now.
  • Article 4 AI literacy: providers and deployers of AI systems must ensure staff using those systems have "a sufficient level of AI literacy." Live now, and enforceable against every recruiter using a covered tool.
  • Everything else in Annex III (hiring): deferred to 2 December 2027. The substance did not change. The clock did.

The framing most trade press ran with in July ("Aug 2 is the hard deadline for AI screeners") was factually behind by the time it published. If your CFO is asking whether the €35M number applies to your ATS vendor, it does not: the €35M or 7% of global turnover ceiling is for prohibited practices such as workplace emotion recognition. High-risk non-compliance tops out at €15M or 3% of global turnover, which is still a real number and still exceeds GDPR's ceiling.

Why the deferral is a trap, not a reprieve

Treating the extra 16 months as free time is the single most common planning mistake teams are making right now. The delay happened because harmonized standards and notified body capacity were not ready, which means the documentation burden actually grows as standards drop between now and late 2027 and the assessment queue compresses against the exact bottleneck that caused the delay.

Three mechanics make this worse than it looks:

  1. Harmonized standards will publish in tranches. Every tranche resets what "state of the art" means for your conformity assessment. Pausing until Q3 2027 means you inherit whichever standard version is current when you finally start, with no time to influence it.
  2. Notified body capacity is the binding constraint. The bodies that were supposed to certify high-risk AI systems by August 2026 are not suddenly going to triple in count by December 2027. If you queue in Q4 2027, you queue behind everyone who also treated the deferral as a holiday.
  3. The backstop is absolute. 2 December 2027 for Annex III and 2 August 2028 for Annex I apply "even if standards have not been published by then." You do not get a further extension because your notified body was slow.

Bitkom president Ralf Wintergerst already called the Omnibus package insufficient to clear "Europe's regulatory jungle," while more than 60 civil society organizations warned it weakens fundamental-rights safeguards. Neither camp is going to make enforcement easier when it lands.

The two-tier stack the deferral just exposed

August 2, 2026 quietly split the recruiting stack into two regulatory tiers: inbound AI that ranks or scores candidates, and outbound sourcing that finds them. They are governed by different laws, on different clocks, with different documentation burdens. Treat them as one program and you will over-spend on outbound and under-spend on inbound.

Here is how the split actually looks:

ActivityRegulatory regimeLive deadlineCeiling
AI resume screening, candidate rankingEU AI Act, Annex III high-risk2 Dec 2027€15M or 3% turnover
AI interview scoring, video assessmentEU AI Act, Annex III high-risk2 Dec 2027€15M or 3% turnover
Workplace emotion recognitionEU AI Act, prohibited practiceIn force€35M or 7% turnover
Article 50 transparency (candidate-facing AI)EU AI Act, horizontalIn force (2 Aug 2026)€15M or 3% turnover
Article 4 AI literacy (staff training)EU AI Act, horizontalIn force (2 Aug 2026)€15M or 3% turnover
Outbound sourcing on public profilesGDPR, Art. 6(1)(f) legitimate interestIn force (since 2018)€20M or 4% turnover

The scope of "high-risk" hiring AI is broader than most vendors admit: resume screening, candidate ranking, AI-powered interview agents, performance evaluation, promotion decisions, task allocation, and termination processes. If your tool touches any of those, it is Annex III, and the 16-month runway is yours to squander or use.

Why outbound sourcing is the loophole (and its limits)

Outbound sourcing sits under GDPR, not under Annex III of the AI Act, because finding a candidate is data collection rather than an automated decision about them. A sourcer asking a natural-language tool to surface people who match a brief is processing personal data under GDPR Article 6(1)(f), the legitimate-interest basis, not deploying a high-risk hiring AI that ranks applicants who applied to you.

The distinction is mechanical and worth memorizing:

  • Inbound: a candidate applies. Your system scores, ranks, or filters them. That output influences a hiring decision about that specific person. Annex III.
  • Outbound: you describe the person you want. Your tool returns a shortlist from the open web. The candidate has not applied, and the output is a discovery, not a decision. GDPR.

Same underlying models. Different regulatory surface. This is the exact gap Refolk closes for teams whose inbound stack just entered a 16-month conformity-assessment slog: you describe the person in plain English and get a ranked shortlist across GitHub, LinkedIn, and the open web, without invoking the Annex III machinery your ATS scorer now triggers.

The loophole has hard edges, though. Public LinkedIn data extraction is lawful under Article 6(1)(f) only if you can defend the proportionality of the processing and respect data subject rights when exercised. The ICO's November 2024 audit of AI recruitment tools already flagged scraping candidate profiles without a lawful basis as an enforcement priority, and CNIL litigated the same question in the Nestor case in France. A documented Legitimate Interest Assessment (LIA) is the difference between a defensible outbound program and a €20M / 4% exposure under GDPR Article 83.

The extraterritorial wedge non-EU recruiters keep missing

If you are a US or UK recruiter and you think you are outside the EU AI Act, check who reads your shortlist. The Act applies where AI systems are placed on the EU market, used in the EU, or where their outputs affect people located in the EU. A London or New York recruiter screening candidates for an EU-based role is in scope, full stop.

This is where the inbound/outbound wedge does real work. An outbound "find me this person" output going to an EU hiring manager is a discovery, not a candidate ranking, and does not trigger Annex III. An inbound "score these 400 applicants" output going to the same hiring manager does trigger it, even if the tool sits on servers in Virginia and the recruiter is in Austin. Same vendor, same account, different regulatory surface depending on where in the funnel it fires.

Practically, this means US-based agencies working EU reqs should be doing two things right now:

  1. Documenting which tools produce outputs that reach EU hiring managers, and classifying each output as ranking (Annex III) or discovery (GDPR).
  2. Making sure the Article 50 transparency notice fires whenever a candidate in the EU interacts with an AI, regardless of where the recruiter sits.
15
AI governance titles in the seven largest EU economies
Across DE, FR, NL, IE, ES, IT and BE combined, Refolk's index finds roughly 15 people carrying "AI Governance," "Responsible AI," or "AI Compliance" titles today.

The labor supply cannot staff the December 2027 deadline

There are not enough compliance humans in Europe to conformity-assess the hiring stack by December 2027, and the ratios in Refolk's index make that obvious. Roughly 744 technical recruiters and sourcers work across Germany, France, the Netherlands, Ireland and Spain combined. Roughly 15 people across the seven largest EU economies carry an AI governance title. That is about 50 sourcers per governance owner before you count the rest of the hiring org.

For comparison, the US alone has around 22,093 technical recruiters and sourcers in the same index, a 30x gap versus the EU5. Berlin is the single largest EU concentration in the sample, with Meta and GetYourGuide among the named employers staffing sourcers there today.

SegmentPopulation in Refolk's index
Technical recruiters + sourcers, US22,093
Technical recruiters + sourcers, EU5 (DE/FR/NL/IE/ES)744
US-to-EU5 sourcer ratio~29.7x
AI Governance / Responsible AI titles, EU715
EU sourcers per EU AI-governance owner~50:1
Berlin share of EU5 technical-sourcer sample16% (4 of 25)
The deferral did not buy Europe a compliance holiday. It bought Europe a queue.

Two consequences follow from the ratio, and both should shape how you spend the next four quarters:

  • Vendor-supplied conformity packages become the default. With no in-house governance capacity, most deployers will accept whatever conformity documentation their HireVue, Eightfold, Paradox or HeyMilo account manager hands them. Vendor lock-in becomes the compliance strategy by attrition.
  • Outbound stays in-house. GDPR compliance for sourcing is well-understood, the LIA template is a known artifact, and the tools that do it well (natural-language sourcing across public data) do not carry the Annex III surface.

What to actually do this quarter

Assume the December 2027 deadline is real, assume the deferral is a queue rather than a holiday, and split the work by regulatory tier. Concretely:

  1. Ship Article 50 and Article 4 now. Both landed on 2 August 2026. Candidate-facing AI needs a transparency notice, and every recruiter using an AI tool needs documented AI-literacy training. This is the only piece that is already enforceable.
  2. Inventory your inbound stack against Annex III. For every scoring, ranking, filtering, interview, performance, promotion, task-allocation or termination tool, identify whether it is Annex III high-risk. Get the vendor's conformity roadmap in writing.
  3. Move discovery work outbound. For roles you can source rather than screen, shift volume out of the Annex III surface and into GDPR-governed outbound. Refolk is one way to run this in plain English across GitHub, LinkedIn, and the open web without adding a new Annex III system to your inventory.
  4. Write the LIA before you scale outbound. Legitimate interest is defensible only if documented. Use the ATS you already have (Greenhouse, for example, already exposes legitimate-interest and contract as legal-basis toggles at the config level) to pin the basis per candidate record.
  5. Book notified body capacity early. If your vendors need external conformity assessment, get in the queue in 2026, not 2027. The capacity constraint is the reason the deferral happened.

FAQ

Did the August 2, 2026 EU AI Act deadline actually take effect for hiring tools?

Only partly. Article 50 transparency duties (telling candidates when they are interacting with AI) and Article 4 AI literacy (training staff who use AI systems) took effect as scheduled. The Annex III high-risk obligations for hiring AI (screening, ranking, interview scoring, promotion decisions) were deferred by Regulation (EU) 2026/1744 to 2 December 2027, with product-embedded Annex I systems moved to 2 August 2028.

Does the EU AI Act apply to a US recruiter sourcing for a European role?

Yes. The Act's extraterritoriality clause covers any AI system whose outputs affect people located in the EU, so a New York or London recruiter whose AI shortlist is read by an EU-based hiring manager is in scope. The wedge is between outbound discovery, which is a GDPR matter, and inbound ranking, which is Annex III high-risk regardless of where the recruiter sits.

Is outbound sourcing really outside the AI Act's high-risk scope?

Outbound sourcing on public data is regulated by GDPR (specifically Article 6(1)(f) legitimate interest), not by Annex III of the AI Act, because finding a candidate is data collection rather than an automated decision about an applicant. The loophole holds only if you have a documented Legitimate Interest Assessment and respect data-subject rights on request. Without those, you are exposed to GDPR fines of up to €20M or 4% of global turnover.

What are the real penalty numbers for hiring AI non-compliance?

For Annex III high-risk non-compliance, the ceiling is €15 million or 3% of global annual turnover, whichever is higher. The €35 million or 7% figure that has circulated widely applies only to prohibited practices such as workplace emotion recognition, not to standard high-risk hiring tools. Both ceilings exceed GDPR's €20 million or 4%, so the AI Act is now the higher-stakes regime for the parts of your stack it covers.

Try it on the search you came here for

Stop building boolean strings. Just describe the person.

Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.

  1. 01Describe them

    One plain sentence. Role, city, stack, stage, whatever matters to you.

  2. 02I read the web live

    GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.

  3. 03You read the shortlist

    Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.

  • No boolean, no filters, no seat to buy. One box.
  • Read at search time, so a profile updated yesterday counts today.
  • Every step visible as it runs, every name with its reason.

500 free credits on sign-up. No card, no demo call. See real searches.

Read next