What the EU AI Act Means for AI Interviews in 2026
The EU AI Act's main enforcement clock turned over on 2 August 2026, but most HR teams are not in scope for the headline obligations yet. What is in force today is narrower than the headlines suggest: a workplace emotion-recognition ban that has been live since 2 February 2025, a transparency rule for any AI that talks to candidates (Article 50), and the general enforcement powers of national market surveillance authorities. The full "high-risk" regime for hiring AI — Annex III, point 4(a) — does not apply until 2 December 2027, after the Digital Omnibus deferral agreed in May 2026. Read on for what is enforceable now, what your vendor should be doing, and a 30-day checklist for HR teams.
Plain-English version: most of the high-risk obligations HR teams have been dreading are deferred. The transparency duties and the emotion-recognition ban are not.
What's actually in force on 2 August 2026 (and what isn't)
Three things are live today, and one big thing is not.
Live on 2 August 2026:
- Article 50 transparency obligations. Any AI system that interacts directly with a person must tell the user they are talking to a machine. Deployers of emotion-recognition or biometric-categorisation systems must inform exposed individuals. AI-generated text and deepfakes must be labelled (European Commission, AI Act Service Desk; DLA Piper, 6 August 2026).
- General enforcement powers of national market surveillance authorities and the EU AI Office (DLA Piper Innovation Law Insights, 6 August 2026).
- Article 50(2) machine-readable marking for generative AI already on the EEA market before 2 August 2026 — a four-month transition only, ending 2 December 2026.
Deferred (Digital Omnibus, May 2026):
- Annex III high-risk obligations — the ones that explicitly cover AI for "recruitment or selection of natural persons… to analyse and filter job applications, and to evaluate candidates" — now apply from 2 December 2027, not 2 August 2026 (CloseIT, June 2026; DLA Piper, 6 August 2026).
- Annex I product-safety high-risk obligations: 2 August 2028.
- Fines: up to €15M or 3% of worldwide turnover for high-risk violations, up to €35M or 7% for prohibited practices, up to €7.5M or 1% for misleading information (Article 99).
The Commission's position is consistent: a "substantial factor" in a consequential decision is enough to bring a tool into scope — the system does not need to be the only decision-maker (European Commission AI Office, 2026).
When AI hiring becomes a "high-risk" use case
AI hiring is high-risk under Annex III, point 4(a) of Regulation (EU) 2024/1689. That covers CV screeners, automated shortlisting, candidate ranking, job-ad targeting algorithms, automated video interview analysis, psychometric testing platforms, and similar tools (Regulation (EU) 2024/1689, Annex III). The bulk of the high-risk obligations — risk management (Article 9), technical documentation (Article 11), logging (Article 12), human oversight (Article 14), and accuracy/robustness/cybersecurity (Article 15) — applies to standalone Annex III systems from 2 December 2027 after the Digital Omnibus deferral (DLA Piper, 6 August 2026; Council approval 29 June 2026; in force 27 July 2026).
The narrow Article 6(3) "procedural task" exemption does not apply if the system profiles natural persons under GDPR Article 4(4). A voice interview that evaluates personality, communication style, or fit is a profile; it is high-risk (artificialintelligenceact.eu, 2026). The Commission signalled in May/June 2026 draft guidelines that the "material influence" test is explicit: an AI that meaningfully shapes who is interviewed, shortlisted, or ranked is in scope even if a human makes the final call (Commission Communication COM(2026)234).
Article 26 also imposes a specific deployer duty: notify workers and their representatives before deploying high-risk AI that affects them. That duty is real and the obligation to start the works-council conversation in 2026 is the right move.
Article 50 disclosure duties that hit HR teams today
Article 50 is enforceable now. Two sub-paragraphs matter most for an interview process:
- Article 50(1) — providers of AI systems that interact directly with people must design the system so users know they are interacting with AI. The candidate must be told, in plain language, before the conversation starts, that the interviewer is a machine.
- Article 50(3) — deployers of emotion-recognition or biometric-categorisation systems must inform exposed individuals. If you are running any biometric or affect-inference system in your hiring flow, the candidate must know.
Practical mechanics: a pre-interview consent screen that names the AI system, the controller, the purpose, and the data categories captured (voice, transcript, derived scorecard) — timestamped and IP-logged. The Commission confirmed the 2 August 2026 date on 31 July 2026; the disclosure obligation is not a "deferral-friendly" item (DLA Piper, 31 July 2026; Cooley, 3 August 2026).
The Article 5(1)(f) emotion-recognition ban (and why it matters for video)
Article 5(1)(f) is not a high-risk category. It is an outright, prohibited practice. Inferring emotional state from facial geometry, voice tone, body movement, or keystroke dynamics for employment decisions has been banned since 2 February 2025 (European Commission, 4 February 2025 guidelines; Wolters Kluwer, 2025).
Two reasons this matters in 2026. First, the financial exposure is the largest the Act sets: fines reach €35M or 7% of worldwide turnover under Article 99(3). Second, several legacy video-interview products infer emotion from video — affect analysis, micro-expression scoring, voice-stress detection. If your current vendor is doing any of those things, the clock started running 18 months ago.
The legal exposure falls on the deployer (the employer) and the provider (the vendor). A vendor that markets "emotion analytics" or "candidate mood scoring" as a hiring feature is selling a product whose intended use is unlawful in the EU. An employer that buys it inherits that exposure.
What "AI-assisted, human-decided" means in legal terms
"AI-assisted, human-decided" is not marketing copy. It is a specific architectural posture that maps onto the regulation.
- AI flags. The system scores structured competencies (problem-solving, domain reasoning, communication clarity) against a published rubric. Outputs are explainable per-question with evidence quotes. The score is a flag, not a decision.
- Human decides. A named recruiter reviews the full transcript, the rubric scores, and the evidence. The human records the decision with a written rationale. The human can override the AI.
- Audit trail. Every AI action on a candidate record is logged: which model version scored which response, when, with what rubric, and what the human reviewer did next.
That posture satisfies Article 14 (effective human oversight — the reviewer must be able to understand, supervise, and override the AI), Article 11 + Annex IV (technical documentation), Article 22 GDPR (right to human review of automated decisions), and the defensible-reasoning expectations of every other AI hiring regime — NYC Local Law 144, Colorado SB 24-205 / SB 26-189, Illinois AIVIA, DIFC DP Law No. 5 of 2020 (Voxxhire compliance synthesis, August 2026).
What it does not do: it does not protect a tool that profiles candidates and presents a single score that recruiters rubber-stamp. "Human review" of a summary score with no transcript and no override pathway is not human-in-the-loop; it is human-as-rubber-stamp.
What your AI interview vendor should be doing in 2026
A defensible vendor stack in 2026 exposes, on request, six things.
- A Model Card describing inputs, training data sources, model architecture, validation methodology, disaggregated accuracy across sex, race/ethnicity, age band and intersectional categories, and known limitations.
- An Article 5(1)(f) self-attestation confirming that no emotion-recognition, biometric-categorisation, or social-scoring features are active. The vendor is the entity making this claim; the deployer relies on it.
- A bias monitoring service that runs adverse-impact tests against the EEOC four-fifths rule (or an equivalent local standard) on the customer's own data, at the position level, not just the pool level. A 2025 study of 4 million applications found that an AI screening tool can pass an aggregate audit while still discriminating in 26% of submissions for Black applicants and 15% for Asian applicants at the position level (HCAMag, 2025). Pool-level audits are no longer sufficient.
- Candidate-facing notice templates in the customer's hiring languages, satisfying Article 50 and parallel disclosure rules in NYC, Colorado, Illinois and the UAE.
- A sub-processor and data-residency list with SCCs and Transfer Risk Assessments for cross-border flows, plus an incident response commitment with 72-hour breach notification.
- EU AI Act Article 11 technical documentation supporting the customer's FRIA (where one applies) and standing ready for the December 2027 obligations.
If a vendor cannot produce any of these on request, the conversation is not yet serious.
A 30-day compliance checklist for HR teams
Use this as a working list. Most of it is documentation, not technology.
- Confirm Article 50 disclosure is in place on every AI-led candidate interaction: pre-interview screen, recorded consent, AI identity, controller name, purpose, retention, withdrawal right.
- Confirm no emotion recognition is active in any vendor. Ask for written confirmation under Article 5(1)(f).
- Run a position-level bias audit on at least one recent hiring cycle. Aggregate-only is not enough.
- Document a human-in-the-loop workflow: named reviewer, full transcript access, override pathway, written rationale captured per decision.
- Update the candidate privacy notice to name the AI system, the categories of data captured, the retention window, and the right to human review.
- Set retention windows: 90–180 days post-role-closure is the defensible band. Wire deletion into the workflow, not a policy.
- Map data flows: which sub-processors touch candidate data, where inference runs, where storage sits, and the legal basis for any cross-border transfer.
- Notify workers and representatives in advance of any high-risk AI rollout (Article 26 deployer duty — start the conversation in 2026, before the obligation bites in December 2027).
- Brief the legal team on the December 2027 high-risk deadline and begin gathering the technical documentation the customer will need from the vendor.
- Pick the QA cadence: monthly disaggregated accuracy review, quarterly position-level bias audit, annual independent third-party audit for the NYC/California footprint.
FAQ
Does the EU AI Act apply if my company is not in the EU? Yes. The Act is extraterritorial. Any vendor placing an Annex III product on the EU market, or any deployer using one to evaluate EU-resident candidates, is in scope regardless of headquarters (Regulation (EU) 2024/1689, Article 2).
Is my AI video interview tool now illegal in the EU? Only if it infers emotional state from video, voice, or behaviour for an employment decision. Tools that score structured competencies on transcript text, with human review, are not prohibited. Check the Article 5(1)(f) self-attestation.
What is the "human-in-the-loop" requirement in practice? The reviewer must be able to understand, supervise, and override the AI. That means full transcript access, a published rubric, evidence quotes per score, and a recorded override pathway (Article 14).
What is the maximum fine? Up to €35M or 7% of worldwide turnover for prohibited practices (Article 5 violations). Up to €15M or 3% for high-risk violations. Up to €7.5M or 1% for misleading information (Article 99).
What changes on 2 December 2027? The bulk of the high-risk regime — Articles 9 to 17 for providers, Article 26 for deployers — becomes applicable to standalone Annex III systems, after the Digital Omnibus deferral. HR teams should be ready with documented workflows by mid-2027, not the day the deadline hits.
Voxxhire is AI-assisted, human-decided. This article is for information and does not constitute legal advice; consult qualified counsel in each jurisdiction where you operate.