If you have been counting down to August 2, 2026 for the EU AI Act's hiring rules to bite, stop. The Digital Omnibus on AI was published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744 and pushed the high-risk hiring deadline out to December 2, 2027. The rights you thought kicked in this summer did not. But there is a lever you can pull today, and most European employers cannot answer it.
The deadline moved. Here is what actually changed on August 2
The August 2, 2026 compliance date for high-risk AI hiring systems was deferred by 16 months to December 2, 2027 under Regulation (EU) 2026/1744. Standalone Annex III systems - the ones that screen, rank, and score candidates - now have until late 2027 to comply. What did enter into force is a narrower prohibition: AI systems designed to generate non-consensual intimate imagery are banned from December 2, 2026.
For candidates, that means the AI Act letter you were about to send citing Articles 14 and 26 will get a polite "come back in December 2027." The regulation that already gives you leverage is GDPR Article 22, in force since 2018.
- The European Parliament adopted the Omnibus on June 16, 2026 by 423 votes to 57, with 174 abstentions.
- The Council gave final approval on June 29, 2026.
- Publication in the Official Journal followed on July 24, 2026, entry into force on July 27.
- Annex III recruitment systems: full compliance deadline is now December 2, 2027.
While you wait, the vendors screening you (Workday, HireVue, iCIMS, SmartRecruiters) keep filtering. The Mobley v. Workday class action already covers roughly 1.1 million rejections. That is the world you are applying into.
The €35M fine number everyone quotes is wrong for hiring
Hiring breaches under the AI Act cap at €15 million or 3% of global turnover, not €35 million or 7%. The higher ceiling is reserved for Article 5 prohibited practices (social scoring, manipulative systems, the new nudification ban). High-risk deployers, which is what a company using a resume screener is, sit under the lower cap.
Getting this right matters. Half the compliance content circulating this year cites the €35M figure against hiring vendors, and any HR lawyer reading your escalation will clock the error in one line. If you are going to invoke the regulation, cite it correctly.
| Fact | Figure |
|---|---|
| Parliament vote on Omnibus | 423 for, 57 against, 174 abstain |
| Old high-risk hiring deadline | 2 August 2026 |
| New high-risk hiring deadline | 2 December 2027 |
| High-risk deployer fine ceiling | €15M or 3% of turnover |
| Article 5 prohibited practice ceiling | €35M or 7% of turnover |
| Nudification prohibition in force | 2 December 2026 |
The 1,244:1 problem: nobody is home to review your application
Across the six largest EU economies, only 9 people hold titles like "AI Governance," "AI Compliance," or "AI Ethics" on Refolk's index. In five of those markets - Germany, France, the Netherlands, Ireland and Spain - there are 11,193 recruiters and talent acquisition professionals on the same index. That is roughly 1,244 recruiters for every one dedicated AI oversight specialist.
Refolk's index across Germany, France, Netherlands, Ireland and Spain shows 11,193 recruiters and just 9 dedicated AI ethics or compliance staff across those markets plus Italy.
The Act requires a trained human reviewer with authority to override the AI's output. Not a rubber stamp at the end of the pipeline. A named person with the competence and the authority to overrule a ranking. In most companies you will apply to, that role is fictional today. The top employers of EU recruiters in the index skew toward staffing and consulting shops (K2 Partnering Solutions, Theodo, OPUSHERO) rather than governance-heavy enterprises. These are the exact HR stacks least likely to have designated a reviewer by name.
That is your opening. When you ask for the reviewer's name, you are not filing a complaint. You are exposing a staffing gap.
| Segment | Region | Count |
|---|---|---|
| Recruiters / Talent Acquisition | DE, FR, NL, IE, ES | 11,193 |
| AI Governance / Ethics / Compliance titles | DE, FR, NL, IE, ES, IT | 9 |
| Ratio | Five-country base | ~1,244 : 1 |
Why GDPR Article 22 is the lever that already works
Article 22 of the GDPR, in force since May 2018, gives you the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. A rejection from a job application is the paradigm example regulators reach for when they teach this article.
The controller (the employer) must either:
- Have a specific lawful basis for the automated decision (your explicit consent, contractual necessity, or a Member State law).
- Ensure the AI output is not the sole basis for the decision, meaning a human meaningfully reviewed it.
- Provide, on request, meaningful information about the logic involved and the significance and envisaged consequences.
CNIL, the French data protection authority now also designated as the supervisory authority for high-risk AI in recruitment, fined a company €105,000 in 2023 for related violations. HireVue scrapped its facial analysis in 2021 after an FTC complaint. Amazon's own screening tool was withdrawn in 2018 for sex bias. Candidate pressure has a track record.
Article 22 is already in force. Ask under GDPR today, cite the AI Act as the horizon, and watch the response tighten.
The email that forces a human review
Send this the same day the rejection arrives. Address it to the recruiter and cc privacy@ or dpo@ at the employer's domain. It works against any employer whose output affects someone located in the EU, which explicitly includes London and New York based recruiters screening candidates for EU roles.
Subject: Article 22 GDPR request regarding my application to [role, requisition ID]
Dear [recruiter name],
I received a rejection for [role title, requisition ID] on [date]. Under Article 22 of the GDPR, I am exercising my right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. A hiring rejection is such a decision.
I request the following within one month, as required by Article 12(3):
- Confirmation of whether an AI or algorithmic system (for example a resume parser, ranking model, or automated interview scorer) was used to evaluate my application, and the name of the vendor and system.
- Meaningful information about the logic involved, and the significance and envisaged consequences of the processing, per Article 15(1)(h).
- The name and role of the human reviewer who exercised meaningful oversight over the decision, along with the date and duration of that review.
- Confirmation of the lawful basis relied on under Article 22(2) if the decision was solely automated.
- If a human review has not yet occurred, I request one now and reserve the right to contest the decision and express my point of view under Article 22(3).
For context, I note that recruitment systems are classified as high-risk under Annex III of Regulation (EU) 2024/1689 (the AI Act), with full deployer obligations applying from 2 December 2027 following Regulation (EU) 2026/1744.
If I do not receive a substantive response within one month, I will escalate to [CNIL for France, the AP for the Netherlands, the DPC for Ireland, AEPD for Spain, BfDI or the competent Land authority for Germany].
Regards, [Your name]
What to expect back
- A generic "we use tools but a human decided" response. Push back and ask for the reviewer's name and the timestamp of the review.
- Silence past the one-month window. That is your escalation trigger to the supervisory authority.
- A rescinded rejection. Rarer, but the whole point of the letter is that manually reviewing you is cheaper than answering a regulator.
The template does the legal work. The harder job is making sure the resume you sent in the first place was worth a second look. That is the exact work Refolk takes off you: paste the posting, get your resume back rewritten for it, with the cover letter drafted and a fit score attached so you know whether to fight the rejection or move on.
Sourcing vs. screening: the loophole employers will use
Employers will re-label rejection tools as "matching" or "recommendation" engines to escape Annex III. AI that helps a candidate discover a role is low-risk. AI that filters, ranks, or rejects is high-risk. That distinction is the loophole every vendor deck is being rewritten around this quarter.
Your email should force the question of what the tool actually did to your application. Not "did you use AI" (they will say no in the marketing sense), but "did an algorithmic system score, rank, or reduce my application against other candidates before a human read it." The Article 22 script above already forces this. Do not accept a rewording.
If you are applying to a lot of EU roles, the volume problem eats the whole strategy. One carefully argued application to Berlin, Amsterdam or Dublin beats 40 generic ones, because your leverage under Article 22 only exists if the application itself was strong enough that the rejection looks hard to defend. Refolk scores how well you actually fit before you send, so the letters you write later have teeth.
Non-EU candidates: yes, you have standing
The Act and the GDPR apply where outputs affect people located in the EU. A recruiter based in London or New York screening candidates for a Berlin office is in scope. So is a US-based ATS vendor whose scoring lands on an EU applicant.
The practical implication for job seekers outside the EU:
- Applying from the US to a Dublin role: you can invoke GDPR Article 22 against the Irish entity and, where relevant, the US-based screener acting as processor.
- Applying from London to Paris: post-Brexit UK GDPR mirrors Article 22 for the UK side; French CNIL jurisdiction applies to the French controller.
- Applying from Berlin to a US HQ with an EU subsidiary: the EU subsidiary is your controller, address the letter there.
Cross-border enforcement is thin today. But the letter still gets read, still triggers internal escalation, and still occasionally produces the human review that flips the outcome.
FAQ
Does the EU AI Act apply to me if I am applying from outside the EU?
Yes, if the output affects someone located in the EU. The Act's extraterritorial reach captures AI systems placed on the EU market, used in the EU, or whose outputs affect people in the EU. A US-based recruiter using an American ATS to screen candidates for a Berlin role is in scope. In practice, GDPR Article 22 is the cleaner right to invoke today, and it covers the same fact pattern. The employer's EU entity is the controller you should address, with the DPO copied.
What happens if the employer ignores my Article 22 request?
You have one month for the substantive response under Article 12(3), extendable by two months for complex requests if the controller notifies you within the first month. If nothing comes back, escalate to the supervisory authority in the country of the controller: CNIL in France, the AP in the Netherlands, the DPC in Ireland, AEPD in Spain, BfDI or the relevant Land authority in Germany. CNIL's €105,000 fine in 2023 shows the mechanism is not theoretical, though enforcement is slow.
Should I still mention the AI Act if the deadline moved to December 2027?
Yes, as the horizon rather than the immediate hook. Cite Regulation 2024/1689 and note that recruitment is classified as high-risk under Annex III, with deployer obligations applying from December 2, 2027 following Regulation 2026/1744. That signals you know the direction of travel without overreaching. The immediate legal weight comes from GDPR Article 22, which has been in force since 2018 and covers the same rejection.
How do I know if my rejection was actually automated?
You often do not, which is why the Article 22 letter asks the controller to confirm. Signals that AI was involved include a rejection arriving within minutes or hours of submission, generic language with no role-specific feedback, no human name attached to the decision, and application through a known ATS (Workday, iCIMS, SmartRecruiters). The Mobley v. Workday class action alleges roughly 1.1 million rejections were driven by algorithmic scoring across employers using the same platform. Even if a human clicked send, the underlying decision may still count as solely automated under Article 22.