The boilr Agent is live Read now
Guides

The EU AI Act Deadline Just Moved to 2027. Here Is What Recruitment Agencies Should Actually Do Now

The EU AI Act's high-risk employment rules were just deferred to 2 December 2027. Here is what changed, what did not (GDPR still applies today), and the practical steps recruitment agencies should take now.

TB Team Boilr
· July 23, 2026 · 15 min read
Abstract dark liquid-metal texture representing shifting regulatory deadlines

TL;DR

On 19 November 2025 the European Commission proposed deferring the EU AI Act's high-risk obligations for Annex III systems, including recruitment and employment AI, from 2 August 2026 to 2 December 2027 [1]. The European Parliament endorsed the deferral on 16 June 2026 (423 votes to 57, with 174 abstentions) [2], the Council gave its final green light on 29 June 2026 [3], and the final act was signed on 8 July 2026, now awaiting publication in the Official Journal [4]. This is a genuine 16-month runway, not a reason to stand down. GDPR Article 22 has restricted automated hiring decisions since 2018 and is untouched by this delay [5]. Agencies that use AI to screen, rank or score candidates - or to route and prioritise leads - are "deployers" under the Act and carry independent obligations once the high-risk rules land [6]. The agencies in the strongest position by December 2027 will be the ones that spent 2026 building a documented, explainable record of why a company or candidate was scored the way it was, not the ones that filed this under "sorted, check back in 2027."

This is relevant to your agency if:

  • You screen, rank, shortlist or score candidates using any AI-assisted tool, whether bought off the shelf or built in-house.
  • You route, score or prioritise leads or companies for BD using AI, even if no candidate is being ranked.
  • You place candidates with clients in the EU, or you operate in an EU or DACH jurisdiction yourself.
  • A client, prospect or works council has already asked what your AI tools do with candidate or company data.

What Actually Changed on 19 November 2025

The European Commission's "Digital Omnibus on AI" proposed pushing back the compliance deadline for high-risk AI systems under Annex III of the EU AI Act - the category that covers recruitment, candidate screening, application filtering, candidate evaluation, and worker monitoring - from 2 August 2026 to 2 December 2027 [1]. AI embedded in already-regulated products (Annex I, think medical devices or machinery with an AI component) gets an even longer runway, to 2 August 2028 [1].

  • 19 November 2025: European Commission proposes the deferral as part of the wider Digital Omnibus package [1].
  • 7 May 2026: Council and Parliament reach provisional political agreement to simplify and streamline the rules [3].
  • 16 June 2026: European Parliament formally endorses the deferral, 423 votes to 57, with 174 abstentions [2].
  • 29 June 2026: Council of the EU gives its final green light to the simplification package [3].
  • 8 July 2026: The final act is signed. It is now awaiting publication in the Official Journal, with entry into force three days after publication [4].

That timeline matters for one reason: this was not a quiet administrative tweak. It went through the full EU legislative process, a large majority backed it, and the driving reason was practical, not political - the harmonised technical standards that businesses need to actually benchmark compliance against were not ready in time for the original August 2026 deadline [7].

Why "Compliance Can Wait" Is the Wrong Read

It is easy to hear "deferred to December 2027" and file AI compliance under next year's problem. That reading misses four things that are true right now, in July 2026, regardless of what happens with Annex III:

1. GDPR Never Moved

GDPR Article 22 has restricted solely automated decisions with legal or similarly significant effects since May 2018, and the AI Act deferral does not touch it [5]. The Court of Justice of the EU's SCHUFA ruling (Case C-634/21, December 2023) confirmed that a scoring tool falls within Article 22's scope if it "materially influences" a decision, even when a human formally signs off afterwards [8]. If your agency's screening tool ranks or eliminates candidates and a recruiter's review of that output is a rubber stamp rather than a real override, that is an Article 22 exposure today, not a 2027 one.

2. Article 50 Transparency Duties Still Land in August 2026

The high-risk regime moved, but the AI Act's separate transparency obligations under Article 50 did not. Providers must disclose that people are interacting with an AI system, AI-generated content needs to be marked where technically feasible, and deployers of biometric or emotion-recognition systems must inform the people exposed to them [9]. If a client-facing chatbot, an AI phone screener, or a candidate-facing assessment tool touches any of that, 2 August 2026 is still a live date.

3. Deployer Obligations Are Independent of Your Vendor's Compliance

Article 26 puts obligations on the deployer of a high-risk AI system, not just the provider that built it. An agency that buys a third-party screening or scoring tool cannot outsource its own duties to that vendor's contract terms - the obligations are non-transferable [6]. Once the high-risk regime is live, deployers who are employers must, among other things, assign human oversight to someone with the training and authority to actually override the system, and inform workers and their representatives before the system is used [6].

4. The EDPB Is Already Auditing the Gap

The European Data Protection Board's 2026 Coordinated Enforcement Framework action is examining transparency compliance across roughly 25 jurisdictions right now, with a specific focus on whether organisations can actually document that a human reviewer meaningfully evaluated an automated output, rather than just approving it in name [8]. That is a GDPR enforcement action, running in parallel with the AI Act timeline, not dependent on it.

The deadline moved. The audit trail requirement did not. That gap is exactly where agencies get caught out.

What Is Actually Deferred to 2 December 2027

To be precise about what did and did not change, here is the before/after on the dates that matter to a recruitment agency:

Obligation Original deadline New deadline / status
High-risk obligations for Annex III systems (recruitment, candidate screening/ranking, worker monitoring) 2 August 2026 2 December 2027 [1]
High-risk obligations for AI embedded in Annex I regulated products 2 August 2026 2 August 2028 [1]
Article 50 transparency duties (AI-interaction disclosure, deepfake/synthetic content marking) 2 August 2026 Unchanged - still 2 August 2026 [9]
GDPR Article 22 (restriction on solely automated decisions with significant effect) In force since May 2018 Unchanged - already in force [5]
National works-council / co-determination rights over new hiring systems (e.g. German Betriebsrat, BetrVG) Already in force Unchanged - already in force

Where Recruitment Agencies Sit in the Act

Annex III, point 4 classifies AI used for "recruitment or selection of natural persons" as high-risk - in particular systems that place targeted job adverts, analyse and filter applications, or evaluate candidates [6]. That description is not written for HR departments in isolation. A recruitment agency running AI-assisted candidate screening, CV parsing and ranking, or automated shortlisting on behalf of a client is doing exactly that activity, which is why agencies (not only the end-hiring employer) can themselves be deployers - and in some setups, providers - under the Act.

  • If you buy a third-party ATS/screening tool and use it as configured: you are typically a deployer, with the Article 26 obligations described above.
  • If you customise or fine-tune a tool beyond its intended purpose: you risk being treated as a provider, which carries heavier obligations again.
  • If AI only surfaces leads, signals or research for a human consultant to act on: that is a materially different risk profile from AI that filters or ranks job applicants, because no automated decision is being made about a natural person's employment prospects. That distinction is worth understanding precisely for your own stack - it is not a technicality.

Ad Hoc Spreadsheets vs an Explainable Scoring Trail

Whichever bucket your tools fall into, the practical question regulators, works councils and clients are increasingly asking is the same: can you show your working? Two agencies using functionally similar AI can be in very different positions:

Practice Ad hoc / black-box approach Documented, explainable approach
Why was this candidate/company ranked here? "The tool said so" - no retrievable rationale A stored record of the signal, ICP fit or pattern that drove the score
Human review evidence A sign-off click with no substantive record A reviewable trail showing what a person actually assessed and could have overridden
Consistency across consultants Every consultant's spreadsheet uses different, undocumented criteria One shared, versioned set of criteria the whole agency scores against
Continuity when someone leaves Scoring logic and rationale leave with the consultant The rationale is retained centrally, independent of headcount
Response to a client or regulator asking "why" Reconstructed after the fact, inconsistently, under time pressure Already documented, retrievable on request

Six Practical Steps for the Rest of 2026

  • Map every AI touchpoint that touches a candidate or a company record. Screening, ranking, CV parsing, lead scoring, automated outreach drafting - list them all, including ones bought as off-the-shelf SaaS.
  • Classify deployer vs provider status for each tool. Off-the-shelf and used as intended usually means deployer; heavily customised may tip into provider. Get this in writing from your vendor where it is unclear.
  • Separate "what applies today" from "what lands in 2027" in every client conversation. GDPR Article 22 and works-council rights are today's conversation. Annex III high-risk conformity is the 2027 one. Conflating them undermines credibility with clients who have their own legal counsel checking your claims.
  • Put a real human-override step in front of any automated ranking or filtering of candidates, and keep a record that shows the reviewer actually engaged with the specific case, not just clicked approve.
  • Start recording the "why" behind every score, today, even where no rule strictly requires it yet. A 16-month runway is exactly the time to build the habit before it is mandatory, not after.
  • Revisit this quarterly, not annually. The Official Journal publication, national implementing guidance, and harmonised technical standards are all still moving through 2026 and 2027 [1]. Treat this as a live file, not a box ticked once.

How boilr Fits - and Where It Does Not

boilr is an AI sales employee for recruitment agencies - it detects hiring and buying signals, enriches and scores companies and candidates against your ICP, and drafts outreach for a consultant to verify and send. It is worth being precise about what that does and does not mean for your compliance position:

  • Company Brain keeps a record, not a black box. Every score is tied to the ICP pattern or signal that drove it, and the dashboard is built to show that reasoning back to the consultant - "you see the intelligence, not just a black box" is the explicit design principle, not a compliance claim.
  • The scoring logic survives consultant turnover. Winning patterns, ICP fit and message angles are stored centrally rather than in one person's head or one person's spreadsheet, so the rationale behind a prioritisation decision does not disappear when someone hands in their notice.
  • Consultants verify and send - the tool does not decide. boilr surfaces scored, ranked leads and drafted outreach; a human consultant reviews, edits and sends. That keeps the final action firmly human-led.
  • boilr is a business-development tool, not a candidate-screening or hiring-decision system. It does not make employment decisions about job applicants on behalf of a hiring company, which is the activity Annex III, point 4 is built around. That is an important, honest distinction - do not take this article as saying boilr is, or needs to be, AI Act "high-risk" certified, because that is not the category it operates in.
  • The discipline transfers regardless. If your agency also runs a separate ATS or screening tool that does filter or rank job applicants, the same practice - documented, explainable, human-reviewed scoring - is exactly what Article 26 and GDPR Article 22 will keep asking for, whichever tool is involved.

What still needs a person, always: interpreting a candidate's motivations, negotiating terms, reading a client relationship, and any decision that materially affects someone's job prospects. No AI Act compliance posture changes that.

Five Mistakes to Avoid Right Now

Mistake #1: Treating the Deferral as a Cancellation

Why it fails: "Deferred to December 2027" is doing a lot of work in that sentence, and it is not "cancelled." Annex III recruitment AI remains squarely high-risk under the Act [6].

Fix: Communicate the deferral accurately to clients and internally: the date moved, the category did not.

Mistake #2: Ignoring GDPR Because "the Big One Got Delayed"

Why it fails: GDPR Article 22 was never part of the deferral. It has applied since 2018 and the CJEU has already tested it against automated scoring tools [5] [8].

Fix: Audit your Article 22 exposure now, independent of the AI Act timeline.

Mistake #3: Assuming a Vendor's Compliance Covers You

Why it fails: Deployer obligations under Article 26 are non-transferable. Your contract with a screening or ATS vendor does not shield your agency's own duties [6].

Fix: Confirm your deployer vs provider status per tool, in writing, and document your own oversight practice separately from the vendor's certification.

Mistake #4: No Retrievable Record of Human Review

Why it fails: The EDPB's current enforcement focus is explicitly on whether agencies can prove a human reviewer meaningfully assessed an automated output, not just approved it in name [8].

Fix: Build a lightweight log of what was reviewed, by whom, and what they could have changed.

Mistake #5: Waiting Until Late 2027 to Start

Why it fails: Sixteen months sounds like a lot of runway until the harmonised technical standards land mid-cycle and every agency in your market starts scrambling for the same specialist advice at once [1].

Fix: Use 2026 to build the habit of documented, explainable scoring before it is mandatory, while it is still a competitive advantage rather than a compliance cost.

A 30-Day Plan to Get Ahead of This

Days 1-5: Inventory

List every AI tool touching candidate or company data - ATS, screening, sourcing, lead scoring, outreach drafting. Note who built it, who configured it, and who reviews its output.

Days 6-10: Classify

For each tool, work out deployer vs provider status, and separately, whether it makes or materially influences a decision about a natural person (candidate) versus only surfacing information for a human consultant to act on.

Days 11-15: Document the "Why"

For your highest-stakes tools - anything that ranks or filters job applicants - start recording the rationale behind each output and evidence that a human genuinely reviewed it, not just clicked approve.

Days 16-20: Brief Your Team

Make sure every consultant can explain, in one sentence, what changed on the AI Act timeline and what did not. Getting this wrong in a client pitch damages credibility faster than getting it right builds it.

Days 21-25: Talk to Your Legal Counsel

This article is not legal advice - use it to ask better questions of your own counsel about your specific tools, jurisdictions and client base, particularly if you operate across multiple EU member states with different works-council or co-determination regimes.

Days 26-30: Set a Quarterly Review

Put a recurring calendar reminder to re-check the Official Journal publication status, national implementing measures, and technical standards as they land through 2026 and 2027.

Want a scoring and prioritisation layer that already keeps an explainable record of every company and candidate signal it acts on? See how boilr's Company Brain works.

Frequently Asked Questions

When do the EU AI Act's high-risk rules for recruitment now take effect?

High-risk obligations for standalone Annex III systems, including recruitment and employment AI, are deferred from 2 August 2026 to 2 December 2027. The deferral was proposed by the European Commission on 19 November 2025, endorsed by the European Parliament on 16 June 2026, and given final Council approval on 29 June 2026 [1] [2] [3]. The final act was signed on 8 July 2026 and is awaiting Official Journal publication [4].

Does the deferral mean recruitment agencies have no AI obligations until 2027?

No. GDPR Article 22, which restricts solely automated decisions with legal or similarly significant effects, has applied since May 2018 and is completely unaffected by the AI Act deferral [5]. Separately, the AI Act's Article 50 transparency duties (disclosing AI interactions, labelling AI-generated or synthetic content) were not deferred and still apply from 2 August 2026 [9]. National works-council and co-determination rights over new workplace systems also remain unaffected.

Are recruitment agencies "deployers" under the EU AI Act?

Often, yes. Annex III, point 4 classifies AI used for recruitment or selection, including filtering applications and evaluating candidates, as high-risk. An agency using a third-party tool for this as configured is typically a deployer under Article 26, with independent obligations including human oversight and worker notification once the high-risk regime takes effect [6]. Agencies that only use AI to surface leads or research for a human consultant, without the AI itself filtering or ranking job applicants, sit in a different risk category - it is worth getting this distinction confirmed for your specific tools rather than assuming either way.

What is the difference between a provider and a deployer under the AI Act?

A provider builds or substantially customises an AI system and places it on the market. A deployer uses a system under its own authority, typically as configured by the provider. Most recruitment agencies using off-the-shelf screening or scoring tools are deployers, but customising a tool beyond its intended use can tip an agency into provider obligations, which are more extensive [6].

What did the CJEU's SCHUFA ruling establish about automated scoring?

In Case C-634/21 (December 2023), the Court of Justice of the EU found that a scoring tool falls within GDPR Article 22's scope where it materially influences a decision, even if a human formally reviews the output afterwards. That significantly narrows the "there was a human in the loop" defence for agencies whose review step is not a genuine, substantive check [8].

Should we tell clients the AI Act deadline was pushed back?

Be accurate rather than reassuring. The honest version is: the high-risk compliance date moved to December 2027, but GDPR obligations on automated candidate decisions are unchanged and apply today, and Article 50 transparency duties still land in August 2026. Overstating the delay as "nothing to worry about until 2027" is the kind of claim that damages credibility with clients who have their own legal and compliance teams.

How does boilr help with this without claiming to be a compliance product?

boilr's Company Brain keeps an explainable, centrally stored record of why a company or candidate was scored the way it was, tied to the ICP pattern or signal behind it, and that record survives consultant turnover. That is the same discipline - documented, explainable, human-reviewed scoring - that GDPR Article 22 and, eventually, AI Act Article 26 keep asking for. boilr itself is a business-development and sourcing tool, not a candidate-screening or hiring-decision system, so it is not the AI Act's Annex III "high-risk" category - but the habit of keeping a defensible scoring trail is one every agency should be building regardless of which specific tool touches candidate data.

What should a recruitment agency actually do in the next 30 days?

Inventory every AI tool touching candidate or company data, classify each as deployer or provider, document the rationale behind any tool that ranks or filters job applicants, brief your team on what changed and what did not, and get your specific tools and jurisdictions reviewed by legal counsel rather than relying on general commentary, including this article.

Sources

Information sourced from public EU institutional communications, law firm analyses and industry reporting as of July 2026. This article is provided for general information only and does not constitute legal advice; consult qualified counsel for guidance specific to your agency, tools and jurisdictions.

  1. Gibson Dunn - EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes
  2. Ogletree - EU AI Act Amended: Parliament Votes to Delay Key Deadlines
  3. Council of the EU - Artificial Intelligence: Council and Parliament Agree to Simplify and Streamline Rules
  4. Freshfields - EU AI Act Unpacked #34: The Final Digital Omnibus on AI
  5. Secure Privacy - GDPR Article 22 and Automated Decision-Making: What It Covers, When It Applies, and How to Comply
  6. EU Artificial Intelligence Act - Article 26: Obligations of Deployers of High-Risk AI Systems
  7. DLA Piper - The Digital AI Omnibus: Proposed Deferral of High-Risk AI Obligations Under the AI Act
  8. Tech Times - Automated Hiring Has Broken GDPR Article 22 Since 2018, EU Regulators Confirm
  9. Mondaq - Yes, August 2 Still Matters: The EU Approved a High-Risk AI Delay, But Most Transparency Obligations Remain

Hire your AI sales employee today.

One employee per consultant that researches companies, sources candidates and drafts outreach, while you verify and send. Live in a day.