
Current as of 26 August 2026. This area is moving quickly — the EU timeline changed in mid-2026 and a lot of published guidance still cites superseded dates. Verify against primary sources before acting, and take legal advice for your jurisdiction. This is an operational summary, not legal advice.
If you use software to screen, rank or filter job applicants, you are now operating inside a regulatory regime rather than a grey area. The rules are not especially onerous, but they are specific, and a meaningful share of the guidance currently circulating is out of date.
Here is what actually applies.
The EU AI Act: the deadline moved, the classification did not
This is the change most guidance has not caught up with.
Recruitment and selection systems — CV filtering, candidate ranking, performance evaluation, termination-related decisions — are listed in Annex III, Section 4 as high risk. That has not changed.
What changed is when the high-risk obligations bite. Under the Digital Omnibus package, provisionally agreed on 7 May 2026 and approved by the European Parliament on 16 June 2026:
| Obligation | Old date | New date |
|---|---|---|
| High-risk duties, stand-alone employment AI | 2 Aug 2026 | 2 Dec 2027 |
| High-risk duties, AI embedded in products | 2 Aug 2026 | 2 Aug 2028 |
Two things to be clear about. First, this is a deferral, not a repeal — employment AI remains squarely high risk and the obligations are coming. Second, it does not defer everything.
What still applies on the original schedule
Article 50 transparency duties take effect 2 August 2026. The one that matters most in hiring: candidates must be told when they are interacting with an AI system. A screening chatbot, an AI interviewer, an automated assessment — the candidate has to know.
The emotion-recognition ban has been in force since February 2025. This one is an outright prohibition, not a compliance burden. An employer may not use an AI system that infers the emotions of employees or candidates. Video interview tools that claim to read enthusiasm, confidence or sincerity from facial expression or tone of voice are not permissible in the EU workplace, full stop. If you are running one, that is today's problem, not 2027's.
What to do with the extra time
The sensible read of an 16-month deferral is not "park it." The high-risk obligations are substantial — risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness testing, conformity assessment. Building those in 2027 under time pressure will be worse than building them now.
The practical starting point is the record-keeping, because it is the part you cannot reconstruct retrospectively. Start logging screening decisions now and you will have a year of evidence when you need it.
NYC Local Law 144: the enforcement picture changed
LL 144 has been in force since July 2023 and the requirements are stable. What changed is enforcement.
What it requires
If you use an automated employment decision tool (AEDT) to substantially assist a hiring or promotion decision:
- An annual bias audit by an independent auditor, conducted no more than one year before use. It measures selection rates across sex and race/ethnicity categories.
- A public summary of the results on your website.
- Candidate notice — at least 10 business days before use — saying an AEDT will be used, what qualifications it assesses, and how to request an alternative process.
"Independent" has teeth: the auditor cannot have been involved in building, selling or using the tool, and cannot have a financial interest in the vendor. A vendor-supplied audit of the vendor's own tool does not satisfy this.
Why 2026 is different
In December 2025, the New York State Comptroller published an audit of the Department of Consumer and Worker Protection's enforcement of LL 144 and concluded the agency had been enforcing it ineffectively. DCWP has since formalised its procedures and adopted an internal enforcement workbook, and major employment practices have been advising clients to expect a materially stricter phase.
Penalties run $500 to $1,500 per violation, and each day a violation continues counts as a separate violation. That structure means a quiet non-compliance sitting unnoticed for a year is not a single penalty.
The scope trap
LL 144 follows the candidate, not the employer. If an applicant resides in any of the five boroughs, the law applies — regardless of where your company is based or where the job is performed.
For anyone hiring remotely across the US, this is much broader than it first appears. A fully distributed company with no New York presence that accepts applications from New York residents is in scope.
The rest of the US patchwork
Illinois — the Artificial Intelligence Video Interview Act requires notice, an explanation of how the AI works and what it evaluates, consent before use, and deletion within 30 days on request. Separately, amendments to the Illinois Human Rights Act addressing AI in employment decisions took effect on 1 January 2026.
Colorado — SB 24-205 covers developers and deployers of high-risk AI systems including employment, with duties around reasonable care against algorithmic discrimination, impact assessments and notice. Its effective date has been subject to legislative revision; confirm the current position before relying on a date.
Maryland — consent required before facial recognition is used in an interview.
Federal — no AI-specific hiring statute, but Title VII, the ADA and the ADEA apply to the outcome regardless of mechanism. Disparate impact is unlawful whether a human or a model produced it, and "the vendor's algorithm did it" is not a defence. The four-fifths rule remains the usual starting heuristic for adverse impact analysis.
A practical compliance baseline
This set covers most of what the regimes above require, and is defensible even where none of them technically apply yet:
- Inventory your tools. List every system that screens, scores, ranks or filters applicants — including features inside your ATS that you may not think of as "AI".
- Determine scope by candidate location, not company location.
- Run a bias audit where required, and where not, run one anyway. Selection rates by group at your actual cutoff. See bias in AI hiring for the mechanics.
- Publish what you are required to publish, and give candidate notice on the required timeline.
- Keep a human in the decision. Documented, real oversight — not a rubber stamp on a ranked list. This is the single requirement common to nearly every regime.
- Log decisions. Inputs, scores, thresholds, who reviewed, what they decided, what was overridden. You cannot reconstruct this later.
- Set retention and deletion policies for applicant data — see GDPR for recruitment data.
- Ask vendors the hard questions and keep the answers in writing. What is the scoring basis? Can you export applicant-level audit data? Nine questions worth asking.
The through-line
Across every regime — EU, New York, Illinois, Colorado, federal anti-discrimination law — the same three obligations recur: tell candidates, keep a human in the decision, and be able to show your working.
A screening process that satisfies those three is most of the way compliant almost anywhere, and it is also, independently, a better hiring process. The regulation is largely codifying what careful hiring already looked like.
Common inquiries regarding this topic.
Has the EU AI Act deadline for recruitment AI been delayed?
Yes, partly. Under the Digital Omnibus agreement reached on 7 May 2026 and approved by the European Parliament on 16 June 2026, the high-risk obligations for stand-alone employment AI systems moved from 2 August 2026 to 2 December 2027, with high-risk AI embedded in products moving to 2 August 2028. This is a deferral, not a repeal — recruitment AI remains classified as high risk under Annex III.
Yes, partly. Under the Digital Omnibus agreement reached on 7 May 2026 and approved by the European Parliament on 16 June 2026, the high-risk obligations for stand-alone employment AI systems moved from 2 August 2026 to 2 December 2027, with high-risk AI embedded in products moving to 2 August 2028. This is a deferral, not a repeal — recruitment AI remains classified as high risk under Annex III.
The Resume World Team
VerifiedProduct & hiring research, Resume World
We build the screening engine behind Resume World. Everything here comes out of working on resume parsing, scoring and hiring workflows day to day — including the parts that turned out harder than expected.
See more than just keywords.
Resume World extracts verifiable evidence from every applicant against role criteria and delivers an explained, ranked shortlist. 100% free to start with zero card required.



