The EU AI Act's August 2026 Deadline: What Actually Hit Sourcing
The EU AI Act reached full application in August 2026. Here is which sourcing behaviors became high-risk, which fines apply, and how to stay auditable.
If you run sourcing at a company that touches even one EU-based candidate, August 2, 2026 changed your exposure. The AI Act reached full application, Article 50 transparency obligations went live, and the €35M penalty ceiling is now enforceable across borders. Most vendors and most recruiting leaders still cannot draw the line between which parts of their stack are "high-risk" and which are not, and the wrong guess is expensive.
What actually became enforceable on August 2, 2026
Full application of the AI Act landed on August 2, 2026, but the part that hit sourcing hardest is Article 50 transparency, not the Annex III high-risk hiring regime. Under the pending Digital Omnibus, Annex III hiring obligations have been deferred to December 2, 2027, a deferral approved by the European Parliament as of June 2026 and awaiting Council adoption. That nuance matters: vendors selling "August 2026 high-risk compliance" panic are either behind or selling fear.
Here is what is actually live right now:
- Article 50 disclosure. AI-generated outreach, deepfakes, and machine-written text must be flagged as such. This lands directly on recruiters running LLM-drafted InMails.
- Article 4 AI literacy. Staff who use AI systems must be trained on their capabilities and risks. Live since February 2, 2026.
- Article 5 prohibited practices. Live since February 2, 2025. Workplace emotion recognition, biometric categorization of protected traits, social scoring, and manipulative systems are banned outright.
- Article 99 penalties. €35M or 7% of global turnover for prohibited practices. €15M or 3% for high-risk non-compliance. €7.5M or 1% for supplying incorrect information to authorities.
The €35M / 7% ceiling sits above GDPR's €20M. If your compliance instincts were calibrated to GDPR, they are now under-tuned.
The line that saves your stack: sourcing vs screening
AI sourcing is generally low-risk. AI screening is high-risk. Sourcing means finding, matching, and reaching out. Screening means ranking, filtering, or scoring candidates for a specific requisition, and that is what Annex III, Section 4 covers.
The mechanism behind the split is intent and specificity. A tool that surfaces "engineers who worked on Kubernetes at a Series B" is not making an employment decision about a named individual for a named req. A tool that ranks 40 CVs against a JD and hands the recruiter a "top 5" is. The first is discovery; the second is decision support with legal weight.
That is the exact positioning where Refolk sits: you describe the person you need in plain English, and Refolk returns a shortlist from across GitHub, LinkedIn, and the open web. Discovery, not scoring a named candidate against a specific req. This is not a legal loophole, it is how the Commission has drafted the scope: DLA Piper's reading of the draft Commission guidelines suggests general employer branding and outreach tooling may sit outside Annex III 4(a) entirely, because it does not attach to a specific recruitment process.
If you want to stay on the safe side of the line, the redesign is straightforward:
- Use AI to find candidates, not to rank them for a named opening.
- Keep the JD-to-candidate comparison a human step, or use a screening vendor that has published a technical file, bias audit, and DPIA inputs.
- Log the prompt, the returned list, and the human decision at every step so the audit trail exists before anyone asks for it.
Who is a "deployer" and why buying a compliant tool does not save you
Buying a compliant AI tool does not make you compliant. The Act splits liability between "providers" (the company that builds the AI) and "deployers" (the company that uses it), and if you use AI to screen candidates you are a deployer with your own obligations. That includes human oversight, monitoring, logging, and, in many member states, informing candidates and workers' representatives.
A recruiter pasting 40 CVs into ChatGPT and asking for a top 5 is, under the Act, a high-risk deployer using a general-purpose model as a hiring tool. The provider (OpenAI) has its own obligations, but the recruiter's employer is personally on the hook for the deployer obligations, and no purchase order shifts that.
Italy has already gone further. Its draft implementing decree explicitly requires human oversight for key employment decisions, and other member states are drafting similar tightening. Assume the base Act is the floor, not the ceiling.
Buying a compliant tool does not make you compliant. The Act creates a liability chain your PO cannot escape.
The extraterritorial trap for US recruiters
The AI Act applies wherever the AI's output affects a person in the EU, which means a US-based recruiter screening a Berlin candidate is fully in scope. A London recruiter working an Amsterdam req is in scope. This is the part most US legal teams have not priced in.
The exposure math is lopsided. In Refolk's index of professional profiles, there are roughly 21,871 sourcers and technical recruiters in the United States against about 715 across the EU-5 (Germany, France, Netherlands, Ireland, Spain). US sourcing teams outnumber their EU-5 counterparts by roughly 30 to 1, but extraterritoriality drags every one of them into scope the moment they email a candidate in Munich.
| Segment | Count | Source |
|---|---|---|
| Sourcers and technical recruiters, EU-5 | 715 | Refolk index |
| Sourcers and technical recruiters, United States | 21,871 | Refolk index |
| AI governance / responsible-AI / AI-compliance pros, EU-7 | 15 | Refolk index |
| Ratio of EU sourcers to EU AI-governance staff | ~48:1 | Refolk index, computed |
| Ratio of US to EU-5 sourcing headcount | ~30.6:1 | Refolk index, computed |
| Max fine, prohibited practices | €35M or 7% turnover | Article 99 |
| Max fine, high-risk non-compliance | €15M or 3% turnover | Article 99 |
The concentration of exposure is also uneven inside the EU. In Refolk's index the top employers of EU technical recruiters include Meta (Berlin and Dublin), GetYourGuide (Berlin), Huawei Ireland Research Center, Yelp, and Eli Lilly. Every one of them is a deployer under the Act the moment they use an AI screening tool on a candidate in the block.
The buried headline: the EU cannot staff its own compliance
There is a talent shortage nobody is pricing in. In Refolk's index, only about 15 professionals hold "AI Governance," "Responsible AI," "AI Compliance," or "AI Ethics" titles across seven major EU countries (Germany, France, Netherlands, Ireland, Spain, Belgium, and Italy). That is roughly 48 EU sourcers for every 1 AI-governance professional in the same geography.
The mechanism behind this shortage matters. AI governance as a distinct HR-adjacent function barely existed 18 months ago. The people who can read Annex III, draft a DPIA input, and translate the technical file to a hiring workflow are almost all in law firms, in AI labs, or in a handful of Big Tech policy teams. They are not sitting inside recruiting orgs, which is precisely where deployer obligations land.
Two consequences follow:
- Vendors that ship pre-baked documentation win by default. Warden AI is a good example: purpose-built for bias auditing under NYC Local Law 144 and the AI Act, shipping the artifacts a deployer needs. Truffle openly positions its one-way interview tool as high-risk and provides the technical file rather than dodging the label.
- In-house teams that want to hire this expertise will not find it locally. The pool is small enough that when I run the query in Refolk, the entire in-scope EU governance market fits on one screen. If you need one of these people in Q1, start now.
A sourcing workflow that stays auditable
An auditable candidate sourcing workflow logs the prompt, the returned list, the human review, and the outreach, and keeps AI out of any ranking tied to a named requisition. Here is the redesign that works today and holds up under the Digital Omnibus timeline through December 2027.
1. Separate discovery from decisioning
Use AI to build the long list. Use humans, with structured rubrics, for the short list. The discovery step is where tools like Refolk do their real work: you ask "backend engineers in Amsterdam who have shipped payment systems and contributed to open-source Rust projects," and you get people, not scores against a specific JD.
2. Flag AI-generated outreach
Article 50 is now live. If your outreach copy is drafted by an LLM, disclose it. The cleanest pattern is a footer line on first-touch messages. It costs you nothing and removes the single most common Article 50 violation.
3. Train the humans in the loop
Article 4 AI literacy is not a policy PDF. It is documented training on what your tools do, what they cannot do, and where a human must override. If you cannot produce the sign-off sheet, you cannot claim compliance.
4. Keep the audit trail at the sourcing layer
The trail is easier to maintain if your sourcing tool logs every query and every returned candidate. This is another reason to concentrate discovery in a single system: fifteen point tools mean fifteen partial logs. Refolk keeps a query history per user so you can reconstruct why a person entered your pipeline months later, which is the artifact a DPA or works council will actually ask for.
5. Uninstall the banned categories now
Any vendor pitching workplace emotion recognition, tone analysis, facial cue reading, or biometric categorization has been out of compliance since February 2, 2025. This is not an August 2026 issue. If it is in your stack, remove it before the next procurement review.
What to do in the next 30 days
Map your stack against the sourcing-vs-screening line, close the Article 50 gap, and start hiring for governance before the shortage bites. The compliance work is finite, the timeline is public, and the fines are large enough that even one enforcement action reshapes a Series B budget.
- Inventory every AI tool that touches an EU candidate, including general-purpose LLMs used ad hoc.
- For each, label it "sourcing" (discovery) or "screening" (ranks a named candidate against a specific req).
- For screening tools, request the technical file, bias audit summary, and DPIA inputs. If the vendor cannot produce them, put a replacement on the roadmap.
- Add the Article 50 disclosure to LLM-drafted outreach templates this week.
- Book Article 4 literacy training for every recruiter and sourcer with AI access. Document attendance.
- Start the governance hire. The pool is 15 people across seven countries, and every one of your competitors is about to run the same search.
FAQ
Does the AI Act apply to a US company with no EU office?
Yes, if the AI's output affects a person in the EU. A US recruiter using an AI screener on a Berlin candidate is in scope, and the deployer obligations attach to the US employer. Extraterritoriality is the default posture of the Act, matching the GDPR pattern, and the €35M ceiling applies regardless of where the deployer is incorporated.
Is Boolean sourcing on LinkedIn considered AI under the Act?
No. Boolean search and keyword filters are not AI systems under Article 3. The moment you layer a machine-learning ranker on top that scores candidates against a specific req, that component becomes an AI system, and if it is used for hiring decisions it falls under Annex III. The Act cares about the ranker, not the search box.
What is the difference between a provider and a deployer?
A provider builds and places an AI system on the market. A deployer uses it under their authority. If you buy a screening tool and run it on your candidates, you are the deployer, and you have your own obligations for human oversight, monitoring, logging, and information duties to candidates. The provider's compliance does not extinguish yours, and this shared-liability chain is what most procurement contracts still miss.
Did the high-risk hiring rules actually get delayed?
Probably, but not officially. Under the Digital Omnibus, Annex III high-risk hiring obligations have been deferred to December 2, 2027. As of June 2026 the European Parliament approved the deferral and it awaits Council adoption. Plan for the December 2027 timeline but do not bet the company on it, and treat Article 50, Article 4, and the Article 5 prohibitions as fully live today.
Try it on your own search
Stop building boolean strings. Just describe the person.
Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.
- One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
- Read live at search time, not from a database that went stale last quarter.
- Watch every step as it runs, and see why each name made the list.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
500 free credits on sign-up. No card, no demo call. See real searches.