The EU AI Act and hiring in plain terms: what applies now and what applies in 2027
What already applies to AI in hiring under the EU AI Act, what has applied since 2 August 2026, and what applies from 2 December 2027. Not legal advice.
Emotion recognition at work: prohibited since February 2025. Transparency: in force since 2 August 2026. High-risk obligations in recruitment: from 2 December 2027. A person decides, a log exists, the candidate can contest.
Three dates matter for AI in hiring in the EU. Emotion recognition in the workplace has been prohibited since 2 February 2025. Transparency obligations have applied since 2 August 2026. The obligations for high-risk systems in recruitment apply from 2 December 2027, under Regulation (EU) 2026/1744. This is a plain-language summary for people who run interviews, not legal advice.
What is already prohibited?
Article 5 of the EU AI Act lists practices that are prohibited outright. One of them is emotion recognition in the workplace and in education, outside medical or safety reasons. Since 2 February 2025, an AI system that infers a candidate's emotions from their face, voice or body during an interview is not a risky choice to be managed. It is prohibited.
This matters because "engagement scores", "confidence analysis" and "personality insights" from video were a common feature of interview tools. Whatever the label, if the system infers emotions or affective states from a person at work or in hiring, it falls under the prohibition. Vettasy does not analyze facial expressions, tone of voice, emotions or "personality", for this reason and because the evidence that they predict job performance is missing.
What has applied since August 2026?
Article 50 sets transparency obligations, and they have applied since 2 August 2026. In hiring, the practical meaning is that people must know when they are interacting with an AI system and when content is generated by AI. For an interview tool, that means disclosing the use of AI to the candidate before the interview, not burying it in a policy.
Vettasy discloses the use of AI in the invitation, on the consent screen and in the app. Every AI output is labeled as an AI draft until a person confirms it, and the confirmation shows who confirmed it and when. There is no automatic rejection, and the AI does not rank candidates.
What applies from December 2027?
Annex III of the AI Act lists high-risk uses, and recruitment is one of them: systems used to place targeted job advertisements, to filter applications and to evaluate candidates. For these systems, the obligations apply from 2 December 2027. The date was set by Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, which moved it from August 2026. The obligations include risk management, data quality, technical documentation, logging, human oversight, and requirements for accuracy, robustness and cybersecurity.
The obligations fall on the providers of such systems and on the organizations that deploy them. An employer using an AI tool to evaluate candidates will need to show that a person oversees the system's outputs, that the system's use is logged, and that the documentation exists. Vettasy is built for this now rather than in 2027: the decision log records who decided, when and on which evidence, human-oversight records are kept for every AI draft, and the documentation exports as a package for customers.
What counts as high-risk in hiring?
The short version: anything that evaluates people for a job. A tool that drafts a scorecard from a transcript, a tool that ranks applicants, a tool that screens resumes. The threshold is the purpose, not the sophistication of the model. A simple keyword filter that rejects applications is closer to high-risk than a large model that only transcribes.
The safest posture for an employer is to assume that the evaluation step is high-risk and to insist on what the regulation will require: a person who decides, a log of what happened, documentation of how the system works, and a way for the candidate to contest an outcome.
What does this mean for an interview tool?
It means four design choices, and each one can be checked rather than promised.
- No emotion recognition, anywhere in the product. Not as a feature, not as a hidden signal.
- Disclosure before the interview, and a label on every AI output until a person confirms it.
- A person decides. AI drafts scorecards; system checks mark signals; a person confirms every score and makes every decision, and the log shows it.
- A way to contest. In Vettasy, any signal in the session report can be disputed within 14 days, a person reviews it, and both sides see the outcome.
GDPR sits alongside all of this. Consent to the recording and to Verified Session is collected in the app before the call starts. The data processing addendum, the list of subprocessors and the storage region in the EU are published in the Trust center, and data-subject requests are handled through the product: access through the candidate's own copy, deletion within 30 days, objection through the dispute.
What should an employer ask a vendor?
Five questions cover most of it. Does the system infer emotions from video or voice, under any name. When and how is the candidate told that AI is used. Can the system reject or rank a candidate without a person confirming it. Where is the decision log, and can it be exported. How does a candidate contest an outcome, and who reviews it.
Outside the EU, the direction is similar. New York City's Local Law 144 requires bias audits for automated employment decision tools, and the Illinois Artificial Intelligence Video Interview Act requires notice, consent and deletion on request when AI analyzes video interviews. A tool that meets the EU AI Act's requirements for human oversight, disclosure and logging is most of the way there, and Vettasy provides the data a bias audit needs when a customer uses the product as a substantial factor in a decision.
None of this replaces advice from counsel. It does describe what to expect, and what to look for, in the tools that will run interviews between now and December 2027.
Sources
- Regulation (EU) 2024/1689, the AI Act: Article 5(1)(f), Article 50, Annex III and Article 113.
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI): application dates for high-risk systems.
- Regulation (EU) 2016/679, the GDPR.
- New York City Department of Consumer and Worker Protection, Automated employment decision tools (Local Law 144 of 2021).
- Illinois Artificial Intelligence Video Interview Act, 820 ILCS 42.
- Vettasy, AI Notice and Trust center.
Written by the Vettasy teamVettasy is a desktop application for job interviews. Employers run structured, recorded interviews in it with verified participants. It is free for candidates. Windows and macOS.