Refolk
September 21, 2026·9 min read

EU AI Act Hiring Split: 831 Recruiters Per Governance Hire

The Digital Omnibus deferred Annex III to December 2027. Why CV screeners face €15M fines while outbound sourcing can still fit through Article 6(3).

EU AI Act recruitingAI resume screening compliancehigh-risk AI hiringEU AI Act sourcingAnnex III recruitment
EU AI Act Hiring Split: 831 Recruiters Per Governance Hire

On July 24, 2026, six days before the EU AI Act's high-risk hiring obligations were set to bite, the Digital Omnibus dropped in the Official Journal and pushed the Annex III deadline to December 2, 2027. That is a 16-month reprieve, not a pardon. Every ATS with a "rank candidates" toggle still sits in the same €15M / 3%-of-turnover blast radius it did in July, and the teams that use the runway to redesign their hiring stack (rather than to paper over it) will avoid the entire compliance regime.

What actually changed on July 24, 2026

The Digital Omnibus deferred the AI Act's high-risk deadlines but left the substantive obligations untouched. Regulation (EU) 2026/1744 was published on July 24, 2026 and entered into force on July 27, 2026, six days before the original August 2, 2026 trigger date.

The Parliament passed the package 423-57 on June 16, 2026 (with 174 abstentions), and the Council signed off on June 29, 2026. The Commission cited the harmonized standards bodies, CEN and CENELEC, as not yet ready with the technical specs providers need to conform. So the calendar moved.

Here is what the new calendar looks like, and what it costs to miss it:

MetricValue
Annex III (standalone high-risk) deadlineAug 2, 2026 → Dec 2, 2027
Annex I (embedded in regulated products) deadlineAug 2, 2027 → Aug 2, 2028
Max fine, high-risk breach€15M or 3% of global turnover
Max fine, prohibited practice€35M or 7% of global turnover
Max fine, misleading information to authorities€7.5M or 1% of global turnover
Recruiters/TA/sourcers in top 9 EU markets14,962
AI Governance / Responsible AI professionals, same 9 markets18
Ratio of recruiters to AI-governance specialists~831:1

The last three rows are the ones that should ruin a Chief People Officer's week. More on those below.

Why CV screening is high-risk and sourcing (mostly) is not

A system that ranks, scores, filters, or shortlists candidates is high-risk under Annex III item 4(a). A system that surfaces names to a human recruiter, who then makes the shortlist decision, has a legal route out under Article 6(3). The obligations attach to the function, not the label on the tool.

Annex III item 4(a) covers systems used for:

  • Recruitment and selection (including screening applications and evaluating candidates)
  • Employee monitoring and performance evaluation
  • Promotion, task allocation, and termination decisions

Article 6(3) is the escape hatch. It says a system that would otherwise fall in Annex III is not high-risk when there is no significant risk of harm to health, safety, or fundamental rights, on the basis of a documented self-assessment the provider files before the system is launched. The mechanism protecting outbound sourcing is not an explicit sourcing exemption. It is Article 6(3) plus meaningful human review of the shortlist.

Two vendor camps read this differently. Jobful and similar tools argue sourcing is low-risk by default. Pin.com argues every major AI recruiting function, sourcing included, is captured by Annex III. The text sits between them: sourcing is eligible for the Article 6(3) exception when a human, not the model, decides who moves forward. If your tool ranks and auto-rejects, you are the deployer of a high-risk system. If it suggests and a recruiter picks, you have a defensible path.

This is where the product I work on sits by design. Refolk returns a ranked shortlist to a human sourcer, in plain English, with no auto-reject and no candidate-facing decision loop. Ask for "backend engineers in Berlin who shipped Rust in the last 18 months and mention distributed systems on their profile," get 40 names back, review them yourself. The human is the decision-maker on record, which is what Article 6(3) requires to hold.

The €15M setting hiding in your ATS

Turning on a checkbox re-classifies you as a deployer of a high-risk AI system. Herohunt's teardown of Manatal makes the mechanism explicit: the AI Recommendations and automatic candidate scoring bundled into even the entry plan are precisely an Annex III high-risk function.

Switch them on and Article 26 attaches. That means:

  1. Assign a competent human to oversee the scoring
  2. Retain the system logs for at least six months
  3. Inform candidates the AI is in the loop
  4. Monitor outputs for drift and disparate impact
  5. Complete a Fundamental Rights Impact Assessment (Article 27) if you are in the public sector or an essential-services provider
€15M
Maximum fine for a single high-risk breach
Or 3% of global annual turnover, whichever is higher. A $15/user/month ATS toggle can trigger it.

The uncomfortable part: a $15/user/month setting is not priced as a €15M liability, but it functions as one. Most TA leaders have never mapped which of their vendor toggles push them across the Annex III line. December 2, 2027 is the day that omission starts getting audited.

The shadow LLM problem nobody is auditing

General-purpose LLMs used to screen CVs are the biggest silent exposure in most hiring stacks. Per Omnivoo's read of the text, using a general-purpose AI system specifically to screen CVs for an EU position turns the deployer into a deployer of a high-risk AI system under Annex III item 4(a). Article 6(3) does not save you here, because the "specific purpose" is the regulated one.

Pasting a stack of resumes into ChatGPT with a "rank these for the Berlin role" prompt is, in the eyes of the Act, indistinguishable from running a purpose-built AI screener. Nobody logs it. Nobody informs the candidate. Nobody keeps the six-month record. That is three Article 26 violations before lunch.

The audit order for the next 18 months should be:

  • Shadow LLM use inside TA (Copilot, ChatGPT, Claude, Gemini): interview every recruiter, kill CV-ranking prompts
  • ATS AI features (scoring, matching, auto-reject rules): map every toggle to a function, then to Annex III
  • Interview tooling (video scoring, voice analysis, coding assessments): the highest-risk category, name-check HeyMilo as an example of a vendor that evaluates response content rather than facial or voice cues
  • Outbound sourcing tools: verify a human owns the shortlist decision and that decision is logged

The deployer capacity gap: 831 recruiters per governance hire

In Refolk's index of professional profiles across the nine largest EU hiring markets (Germany, France, Netherlands, Ireland, Spain, Belgium, Italy, Sweden, Poland), there are 14,962 identifiable recruiters, TA specialists, and sourcers. In that same footprint, only 18 professionals carry "AI Governance," "Responsible AI," or "AI Ethics" in their current title. That is roughly one AI-governance specialist for every 831 recruiters.

831:1
EU recruiters per AI-governance specialist
In Refolk's index across the nine largest EU hiring markets. December 2027 is a hiring problem before it is a compliance problem.

The named employers in that 18-person cohort include Fraunhofer IAIS, NXP Semiconductors, the European Parliament, and Apple. Even if the ratio is undercounted by a factor of ten (which is generous), the population that will actually run Article 26 human oversight, Article 27 impact assessments, and Article 12 log retention at scale does not exist yet.

That is a market signal. Every TA org above 200 headcount in the EU will need at least a fractional AI-governance owner by late 2027. Most will discover this in Q3 2027, alongside every one of their competitors.

If you are hiring into this gap now, Refolk is useful precisely because the population is tiny and buried under adjacent titles (privacy counsel, data protection officers, ML compliance leads). Describe the person in plain English, get the 18 back, plus the next 50 who could plausibly grow into the role.

The runway the Omnibus handed you is for building the oversight controls, not for hoping the definition changes.

The extension is a design deadline, not a compliance one

December 2, 2027 is the last date on which you can decide whether AI in your hiring loop makes decisions or makes suggestions. Teams that architect around outbound sourcing plus meaningful human review avoid the entire Article 9-15 provider stack. Teams that leave auto-ranking on will inherit it in full.

The design choices to lock in over the next 16 months:

  • Move screening decisions to humans. Any auto-reject rule, any threshold-based filter, any "top 10%" cutoff run by a model without a human sign-off is Annex III. Turn them off, or make a human own the cut.
  • Keep sourcing tools on the suggestion side of the line. A ranked list surfaced to a recruiter is not a decision. A ranked list that auto-messages candidates is.
  • Log everything for six months minimum. Article 26(6). Set retention now, not in October 2027.
  • Inventory your shadow LLM use before your ATS toggles. The exposure is bigger and the fix is cheaper.
  • Publish candidate-facing disclosures. Article 26 requires informing candidates the AI is in the loop. Get the copy through legal now.
  • Hire, or fractionally rent, an AI-governance owner. The 831:1 ratio only gets worse.

Extraterritorial reach makes this a UK and US problem too. The Act catches systems where they are placed on the EU market, used in the EU, or where their outputs affect people located in the EU. A London or New York recruiter screening candidates for an EU-based role is in scope. Clearview AI has collected combined EU fines exceeding €65 million across France, Italy, Greece, and Austria under adjacent data-protection law. The precedent for large hiring-adjacent fines is established.

Meanwhile, per SHRM and IAPP surveys cited by Pin.com, 51% of organizations use AI in recruiting and roughly 70% say they do not understand their obligations under the Act. That gap will close in one of two ways: through voluntary redesign in 2026 and 2027, or through enforcement in 2028.

FAQ

Is outbound sourcing definitely exempt from Annex III?

No, and any vendor telling you it is definitely exempt is overselling. The text of Annex III item 4(a) covers recruitment broadly. What sourcing tools have going for them is Article 6(3), which lets a provider self-assess out of high-risk classification when there is no significant risk to fundamental rights, plus the fact that a human recruiter (not the model) makes the shortlist decision. That combination is defensible. It is not automatic, and it depends on how the tool is used, not just how it is marketed.

Does the December 2, 2027 deadline apply to systems already in production?

Yes. The Omnibus deferred the application date of the high-risk obligations for Annex III systems, but it did not grandfather anything. A CV-screening tool your team deployed in 2024 has the same obligations on December 2, 2027 as one deployed the day before. Legacy is not a defense. The runway is meant for retrofitting oversight, logging, and disclosure, not for waiting out the rule.

What if we are a US company hiring in the EU but do not have an EU entity?

You are still in scope. The Act applies where outputs affect people located in the EU, which explicitly includes a US recruiter screening a candidate for a Berlin, Paris, or Dublin role. Same fine tiers apply: up to €15M or 3% of global turnover for high-risk breaches. The practical implication is that a US ATS you already use may need EU-specific configuration, especially around candidate disclosure and log retention, before December 2027.

What is the single fastest thing to fix before the deadline?

Audit shadow LLM use inside your TA team. Pasting resumes into ChatGPT to rank them for an EU role is, under Omnivoo's reading of Article 6 and Annex III item 4(a), high-risk deployment with none of the required safeguards. It is invisible, ubiquitous, and cheap to fix (a policy plus a training session). Everything else, the ATS toggles, the vendor renegotiations, the governance hire, takes months. The LLM audit takes a week.

Try it on the search you came here for

Stop building boolean strings. Just describe the person.

Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.

  1. 01Describe them

    One plain sentence. Role, city, stack, stage, whatever matters to you.

  2. 02I read the web live

    GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.

  3. 03You read the shortlist

    Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.

  • No boolean, no filters, no seat to buy. One box.
  • Read at search time, so a profile updated yesterday counts today.
  • Every step visible as it runs, every name with its reason.

500 free credits on sign-up. No card, no demo call. See real searches.

Read next