High-risk obligations for hiring and worker management moved to December 2027. The transparency duties that bite on AI interviewers landed on 2 August as planned. Reading the first as a reprieve while missing the second is the expensive mistake available this year.
For eighteen months, 2 August 2026 sat in every HR technology roadmap as the date the EU AI Act's high-risk regime arrived for hiring. It did not arrive. It also did not entirely fail to arrive, and the distinction is where the risk now lives.
What was actually enacted
Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is law, not proposal. Its effect on employment is direct: stand-alone high-risk systems under Annex III, which includes point 4, employment and worker management, now apply from 2 December 2027 rather than 2 August 2026. Embedded high-risk systems under Annex I moved from 2 August 2027 to 2 August 2028.
The chronology is worth keeping, because it moved quickly for a file of this size: proposed 19 November 2025, trilogue agreement 7 May 2026, IMCO and LIBE committee stage 2 June, European Parliament plenary 16 June 2026 by 423 votes to 57 with 174 abstentions, and Council final green light on 29 June 2026.
One structural detail deserves more attention than it has had. The Commission's original approach tied the delay to standards readiness — a conditional trigger that could, in principle, have pulled the date forward once harmonised standards existed. The enacted text uses fixed dates instead. There is no longer a mechanism that accelerates the deadline. Whatever else the omnibus did, it converted an uncertain date into a certain one, and that is the part vendors are pricing.
What did not move
Article 50 applied in full on 2 August 2026, exactly as originally scheduled, and it is the provision that touches the fastest-growing category of HR tooling.
Where a person interacts directly with an AI system, they must be told. In HR that lands squarely on conversational screening, AI interviewers, candidate chatbots and any voice agent conducting a first-round call. AI-generated content requires machine-readable marking, with a four-month grace period to 2 December 2026 for systems already on the market before 2 August. Breach exposure under Article 50 runs to €15m or 3 per cent of worldwide annual turnover, whichever is higher. National penalty regimes and the AI Office's expanded supervisory powers are live now.
Article 4, the AI literacy duty, has been in force since 2 February 2025 and is untouched by any of this — a point worth making internally, because in a lot of organisations it was quietly folded into the same "August 2026" workstream that has now been stood down.
The half of the regime that required documentation was postponed. The half that required you to say what you are doing was not. Organisations have generally built the first and skipped the second.
Colorado retreated first, and further
Eight weeks before Brussels, the other flagship algorithmic-accountability regime for employment did something similar and arguably more drastic.
Governor Polis signed SB 26-189 in May 2026, weeks before the Colorado AI Act was due to take effect on 30 June. The new effective date is 1 January 2027. More significant than the delay is what was deleted outright: the Attorney General reporting duty, the impact assessment requirement, the risk management policy requirement, the annual review, the privacy-policy updates and the general AI-interaction notice.
What survives for hiring is narrower but sharper. Clear and conspicuous notice before automated decision technology is used in a consequential decision. Within 30 days of an adverse decision, an explanation of how the technology influenced it, plus meaningful human review and reconsideration, to the extent commercially reasonable. And three-year record retention. Enforcement sits with the Attorney General alone — no private right of action — at up to $20,000 per violation as an unfair trade practice.
Visual 1 — What moved, what stayed, and which is harder
Obligation type | Status after summer 2026 | Retrofit difficulty |
|---|---|---|
Conformity assessment, technical documentation, risk management (EU Annex III) | Deferred to 2 Dec 2027 | High effort, but it is paperwork about a system that already exists |
Impact assessments, AG reporting, risk policy (Colorado) | Deleted by SB 26-189 | N/A — removed |
Disclosure that a candidate is dealing with AI (EU Art. 50) | Live since 2 Aug 2026 | Low — copy and configuration |
Machine-readable marking of AI-generated content (EU Art. 50) | Live; grace to 2 Dec 2026 for pre-existing systems | Moderate — depends on the vendor, not on you |
30-day explanation of how the tool influenced an adverse decision (Colorado) | Live 1 Jan 2027 | High — requires per-decision logging that most ATS deployments do not capture today |
Meaningful human review and reconsideration (Colorado) | Live 1 Jan 2027 | High — a process and staffing commitment, not a configuration |
Three-year record retention (Colorado) | Live 1 Jan 2027 | Moderate — but retention has to start before you need the record |
AI literacy (EU Art. 4) | In force since 2 Feb 2025; unaffected | Low, and frequently forgotten in the stand-down |
How to read it: The obligations that were removed or deferred are broadly documentary. The obligations that survived are behavioural — they change what happens at the moment a candidate is rejected. Documentation can be produced late. An explanation of a decision cannot be produced at all if the decision was never logged.
The retreat is real. The reprieve is smaller than it reads
Two jurisdictions, eight weeks apart, both stepped back from the impact-assessment model of algorithmic accountability. That is a genuine, dated trend and not a mood. Anyone arguing that regulatory pressure on HR AI is intensifying in a straight line has not read the summer.
But look at what each retreat kept. Colorado dropped the assessment and kept the explanation. The EU deferred the documentation and kept the disclosure. In both cases the surviving obligations are the ones that require an architectural decision at the point the system is built, and the discarded ones are the ones you could have written afterwards.
A conformity file can be assembled in the six months before a deadline. A per-decision log explaining how a screening model influenced a specific rejection cannot be reconstructed in 2027 for a rejection that happened in 2026 — unless the logging was switched on at the time. Teams that read the delay as permission to pause are pausing the wrong half.
One genuinely open questionWhether Article 26(7) — the deployer's duty to inform workers' representatives before putting a high-risk system into service — is deferred along with the rest of Chapter III, or survives independently, is not settled in the commentary we have reviewed. Article 26 sits within Chapter III, whose application was deferred; some practitioner analysis nonetheless treats the duty as remaining active. We are flagging the tension rather than resolving it. Anyone relying on either reading should get a direct opinion on Article 113 as amended by Regulation (EU) 2026/1744 rather than on a summary — including this one.
What HR systems owners should do with the next sixteen months
Switch on decision logging now, whatever the deadline says. Which model, which version, which inputs, which threshold, which human saw it and when. This is the single item that becomes impossible rather than merely expensive if deferred.
Audit every candidate-facing conversational surface this quarter. Article 50 is live. Disclosure is a line of copy and a configuration flag, and the gap between the effort and the exposure is the most lopsided in the whole regime.
Ask vendors for their marking plan against 2 December 2026, in writing. Machine-readable marking of AI-generated content is largely their obligation to enable and yours to be caught by. The grace period expires in a little over three months.
Design the reconsideration path before you need it. Meaningful human review at scale is a staffing question. If your rejection volume is high — and if you have read anything about application volumes this year, it is — then thirty days is a service-level commitment, and someone has to own it.
Do not let the stand-down take AI literacy with it. It was never on the August clock.
The deadline that everyone diarised did not so much move as separate. The heavy, expensive, documentary half went to the end of next year. The cheap, quick, behavioural half arrived on schedule and is being widely missed precisely because it arrived alongside a headline about delay. Sixteen months is a useful amount of time. It is only useful to organisations that noticed which half they still have.
Sources and method. An HRHubsMedia original. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal 24 July 2026, in force 27 July 2026, per White & Case and DLA Piper; deferral of Annex III (incl. point 4, employment and worker management) to 2 December 2027 and Annex I to 2 August 2028 per the Council of the EU, 29 June 2026; legislative chronology per the European Parliament Legislative Train; the shift from a standards-readiness trigger to fixed dates per Gibson Dunn. Article 50 application and penalty exposure per European Commission, 2 August 2026, and Jones Walker. Colorado SB 26-189 per Littler, 15 May 2026, and GovTech. The Article 26(7) question is flagged as unresolved in the sources reviewed and is not asserted either way here. Journalism, not legal advice — obligations differ by jurisdiction, system and role. Corrections will be made openly on this article.


