Skip to content
Blog

Governance

AI Act deferred to 2027: what still applies

The high-risk rules move to 2 December 2027. But telling a candidate they are talking to an AI has been required since 2 August 2026, and GDPR never moved at all.

Yes, but not the part you think. Regulation (EU) 2026/1744, in force since 27 July 2026, moves the Annex III high-risk obligations from 2 August 2026 to 2 December 2027. Recruitment is in Annex III.

The transparency obligation, however, has applied since 2 August 2026. It was not deferred. And GDPR was never on that timetable at all.

Put differently: what moved is the heavy, distant part; what remains is the short, immediate one: the part that actually concerns a staffing firm whose agent writes to candidates.

What was deferred, precisely

Annex III of the AI Act lists what counts as high-risk. Recruitment is on it: tools used to recruit, select or evaluate people fall under it, alongside credit scoring and education use cases.

Those systems were due to be compliant by 2 August 2026. They now have until 2 December 2027. High-risk systems embedded in products already covered by product safety legislation move to 2 August 2028.

What has been pushed back is not trivial: conformity assessment, technical documentation, CE marking, registration in the EU database, documented human oversight, adverse-impact analysis on candidate data. Sixteen months of administrative work, for vendors and for some deployers.

The deferral is settled. This is no longer a provisional political agreement: the text was published in the Official Journal on 24 July 2026.

What has applied since 2 August 2026

The transparency obligations.

In practice the rule fits in a sentence: a person interacting with an AI system must be able to know it. For a staffing firm, that lands squarely on the case where an agent writes to a candidate, replies in a thread, or follows up on LinkedIn.

It is the more operational of the two duties, and it is the one in force. The paradox is worth spelling out: many companies took away “the AI Act has been deferred” and concluded there was nothing to do, when the only obligation that touches their day-to-day has just started applying.

The good news is that it costs nothing. A signature that says what it is will do, and announcing it up front costs less than being found out.

What never depended on the AI Act

GDPR.

Its provision on fully automated decisions producing a legal or similarly significant effect has applied since 2018, and an application rejected without human involvement falls under it. No AI Act deferral changes that.

This is a frequent and expensive confusion: people hear “the AI rules are deferred” and infer that letting a tool reject profiles is risk-free until 2027. It is not, and the exposure sits with a different regulator on a different timetable.

The practical rule has not moved an inch: an agent may rank, flag and prepare; the decision not to proceed belongs to a person who can explain it.

What the deferral actually changes for a staffing firm

Three things, and none of them is “nothing to do”.

You can choose a vendor rather than be rushed into one. Until the deferral, a 2 August 2026 deadline pushed firms to sign with whoever advertised compliance, real or claimed. Sixteen more months allow a better question: does the tool log what it does, does it distinguish an internal action from an outbound one, does it refuse to decide.

You can build governance in the right order. The Annex III obligations, human oversight, logging, documentation, describe exactly what an agent deployment needs regardless. Putting them in place because they are useful produces a better result than putting them in place because an auditor is coming.

You have no excuse left on transparency. It is in force, it is free, and its absence shows: a candidate who finds out afterwards feels deceived, and says so.

Why the deferral happened, and what it signals

Worth a paragraph, because it tells you something about the next two years.

The Digital Omnibus was driven by a simple observation: the standards, guidance and notified bodies the high-risk regime depends on were not going to exist in time. Asking companies to certify against a framework whose technical standards were still being written was a deadline that would have been met on paper only.

The signal for a buyer is not “the rules are softening”. It is that the infrastructure of compliance is still being built, and that anyone claiming to be certified against it today is describing an intention. Sixteen months from now that will change, and the vendors who spent the interval building logs, oversight and traceability will convert quickly.

The mistake not to make

Treating the deferral as a dispensation.

That is the reading that will dominate the next six months, and it is the one that turns a delay into a debt. Firms that wait until December 2027 to look at this will have to do everything at once: choose a tool, write a governance rule, document systems already in production, and retrain teams that spent sixteen months forming bad habits.

There is also a less visible reason not to wait. Human oversight, logging and traceability are not constraints bolted onto an agent project: they are the conditions of its survival. A project without governance stops at its first incident, long before a regulator takes an interest.

Who is caught: the vendor or the user?

The question comes up every time, and the answer surprises people.

The AI Act separates the provider, who places the system on the market, from the deployer, who uses it professionally. A staffing firm buying a recruitment tool is a deployer: the bulk of the documentary burden, conformity assessment, CE marking, EU registration, sits with the vendor.

But the deployer is not off the hook. It has to ensure effective human oversight, use the system in line with its instructions, keep the logs, and inform the people concerned. That last duty is precisely the one already in force.

Watch one trap: substantially modifying a system, or putting it on the market under your own name, turns a deployer into a provider, with every obligation that carries. A firm reselling an agent to its clients under its own brand should look closely.

What it means when choosing a tool

The deferral moves the question away from “are you compliant?” towards something more verifiable, because formal compliance will not exist anywhere before the end of 2027.

Three questions beat any certificate. Does the system log what it does, and can you export that log? That is what the record-keeping duty will require, and it is already what you need after an incident. Does it distinguish an internal action from an outbound one? Without that distinction, human oversight is either total or nonexistent. Does it refuse to take a final decision? A tool willing to reject candidates on its own exposes you under GDPR today, not in 2027, which is the same line as who approves what in daily use.

A vendor who answers those three well will be compliant in December 2027 without much effort. A vendor waving early compliance with a deadline that has just moved by sixteen months is mostly selling vocabulary.

What to do this quarter

Three actions, none of them legal.

Check that your AI-generated outbound messages say what they are. That is the obligation in force, and it is a signature line.

Write down who approves what, in a sentence the team remembers. What leaves waits for approval, what stays inside goes on its own, what closes a door is decided by a person.

Make sure your tool keeps a record of what it did and who approved it. Without a log you will be compliant neither in December 2027, nor with the first candidate who writes to ask why.

The calendar changed. The work did not.

Frequently asked questions

Is the deferral final or still under discussion?

Final. Regulation (EU) 2026/1744 was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July. It is no longer a proposal; it is applicable law.

So what applies from 2 August 2026?

The transparency obligations. In practice, a person interacting with an AI system must be able to know it. For a staffing firm whose agent writes to candidates, that is the most directly operational duty of the two, and it is in force, not deferred.

Can an AI screen applications between now and December 2027?

Screen, yes. Decide alone to reject, no, and that has nothing to do with the AI Act. GDPR governs fully automated decisions producing a significant effect, it has applied since 2018, and a rejected application qualifies.

Should we wait until 2027 to get compliant?

No, for a practical rather than a legal reason: the Annex III obligations, human oversight, documentation, logging, impact assessment, are exactly what a working agent deployment needs anyway. The deadline only moved the date on which their absence becomes a fine.

Sources

  1. Regulation (EU) 2026/1744, Digital Omnibus on AI, OJEU publicationnicfab.eu
  2. Gibson Dunn, Postponed high-risk deadlines and other key changesgibsondunn.com
  3. K&L Gates, EU Digital Omnibus on AI enters into forceklgates.com

Read next

€100 in credits when you sign up

Join the waitlist.

Leave your email address and we will let you know as soon as Balt can join your team.

Already 247 staffing firms on the waitlist