Which EU rules apply to AI in hiring right now?

The EU rules for AI in hiring have been postponed to December 2027. The ban on emotion recognition, the GDPR and the duty to disclose chatbots already apply.

By Nikolay Broeks, Development & SEO

Fewer than most employers think. The strict high-risk rules for AI that screens CVs or scores candidates only apply from 2 December 2027. The ban on emotion recognition and the GDPR apply today. And use is rising fast: in 2025, 33.2 per cent of companies in the Netherlands with ten or more employees used AI, according to Eurostat.

What changed this summer?

The EU AI Act of 2024 sorts AI systems by risk. Hiring sits in the heaviest category that is still allowed: high risk. Annex III spells it out: systems intended to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates. That reaches further than most people assume. An applicant tracking system that scores CVs is covered, and so is software that decides who gets to see your job ad.

High-risk systems come with heavy requirements: risk management, documentation, human oversight, logging. Those were due to apply on 2 August 2026. They did not. On 24 July 2026 Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was published in the Official Journal and entered into force three days later. It moves the high-risk rules for hiring to 2 December 2027.

Plenty of articles and vendor pages still quote the old date. That is the first reason this topic is confusing. The second is that the delay only covers part of the rules.

What already applies today?

The ban on emotion recognition. Since 2 February 2025 you may not use AI that infers the emotions of people in the workplace, except for medical or safety reasons. In its guidelines of February 2025 the European Commission made clear that the recruitment process falls within that. A tool that reads from a face or a voice in a video interview whether a candidate is nervous, keen or unsure has therefore been banned for a year and a half. That ban was not postponed.

Telling candidates they are talking to AI. Since 2 August 2026 an AI system that interacts directly with people must be built so that they know they are dealing with AI. The duty sits with the vendor, but you are the one who notices when it is not met: it is your chatbot on your careers page. The Dutch Data Protection Authority names this requirement explicitly for online and game-based assessments.

The GDPR. This is the rule most often forgotten, and it has applied since 2018. Article 22 says a person may not be subject to a decision made solely by a computer that significantly affects them. A rejection can be such a decision. According to the Dutch regulator, that point is reached quickly once a score is produced fully automatically and has consequences for the applicant. If you put a person in between, that step has to be meaningful: someone who understands the matter and is actually allowed to change the outcome. A recruiter clicking approve on a hundred rejections a day does not count.

AI literacy. Since February 2025 employers who use AI have had to make sure their people understand it. The omnibus did soften that duty: you now have to support the development of that knowledge, no longer guarantee a particular level. It has become a duty of effort rather than a duty of result.

What should you prepare before December 2027?

Fourteen months sounds like plenty. But anyone using AI in hiring will spend most of that time on something that has little to do with technology: knowing what is actually running.

Start with a list. Which systems in your hiring make a decision or prepare one? Think of the applicant tracking system that ranks candidates, knock-out questions that reject automatically, the tool that analyses video interviews, and the advertising software that decides who sees your vacancy. For each one, ask the vendor two things: do you consider this an Annex III system, and what is your plan for December 2027?

From that date you have duties of your own as the user. You run the system according to the vendor's instructions, you have it overseen by someone competent to do so, you keep the logs, and you tell candidates that a high-risk system is part of the decision. If you introduce such a system at work, you also inform employees and their representatives beforehand.

The most useful step you can take now costs nothing. Take a sample of the candidates the system rejected and read them by hand. Our page on AI in recruitment explains why that is exactly where things go wrong. If the system's judgement does not match yours, you find out before a regulator tells you. How to record candidate assessments properly without AI is covered under screening and candidate follow-up.

What do employers ask us about AI in hiring?

Is my applicant tracking system covered by the high-risk rules?

It depends on what the system does, not on what it is called. A system that only stores and forwards applications is not covered. Once it filters CVs, scores candidates or produces a ranking you select from, it falls under Annex III. Many systems offer such a feature as an option. Ask your vendor which features are switched on for you, and whether they classify those as high risk themselves.

Can I use ChatGPT to write a job advert?

Yes. Writing text is not on the Annex III list, so the high-risk rules do not apply to it. Be careful about what you paste in, though. Put candidates' CVs or interview notes into a general chatbot and you are processing personal data, so the GDPR applies. What we do with our own data on that front is set out under data and privacy.

Does this apply if my recruitment agency uses the AI?

Partly. The agency is then the user and carries the duties that come with that. But in the SCHUFA case of 2023 the EU Court of Justice held that a score produced by a third party can already count as an automated decision if the party deciding relies on it decisively. So when choosing a recruitment agency, ask what determined which candidates you got to see.

What happens if I do nothing until 2027?

For the high-risk rules, nothing happens until December 2027. The emotion recognition ban, the chatbot disclosure duty and the GDPR do apply now, and national data protection authorities supervise them. The biggest risk lies with the GDPR, because it has been in force for eight years and an automatic rejection without a meaningful human look can fall under it today.

SocialFind wrote this article from the text of the regulation itself, checked on 25 September 2026. If you would like articles like this in your inbox, sign up for our newsletter.

Our newsletter

What we run into in our work for employers, gathered in one email: new articles, labour market figures and what follows from them in practice.

About one email a week. You can unsubscribe with one click at the bottom of every email. What we do with your details is set out in our privacy statement.

We use cookies

This website uses cookies to work properly and to measure how the site is used. Statistics and marketing are only used with your consent. You can change your choice at any time via "Cookie settings" in the footer.