← writing / article

The EU AI Act's high-risk rules are live. If your AI touches hiring, you're in scope

On 2 August 2026 the EU AI Act's high-risk obligations became binding. Employment AI is explicitly listed. The deadline rewards the discipline you already owed.

27 Aug 20264 min readai · governance · leadership

The date that stopped being in the future

For two years the EU AI Act was the item every AI roadmap acknowledged and no roadmap actually planned around. It had a date, and the date was in the future, which is a comfortable way of saying it did not exist yet. On 2 August 2026 that comfort expired. The high-risk obligations became binding and enforceable, covering provider requirements under Articles 9 through 17 and deployer requirements under Article 26. The clause everyone filed under “later” is now the operative one, and the grace period it was hiding behind is gone.

Some of the heaviest obligations for certain systems have been sequenced further out, to late 2027 and 2028, and there has been the usual noise about delays that have not actually been enacted into law. None of that changes the operative fact. As of this month, if you build or deploy a high-risk AI system touching the EU, the requirements apply to you now, and a large share of organizations are not ready.

“High-risk” is not an abstraction if you touch hiring

Here is the part that turns this from a compliance newsletter into something with your name on it. High-risk is not a vague category reserved for facial recognition and self-driving cars. The Act’s Annex III lists it explicitly, and employment, worker management, and access to essential services sit squarely inside it, alongside credit scoring, education, and law enforcement. If your system screens CVs, ranks candidates, scores an assessment, or informs a decision to hire, promote, or let someone go, you are not adjacent to the high-risk tier. You are in it.

I write this as someone who runs a platform whose output informs decisions about people, so I am not narrating from the stands. For a talent product, Annex III is not a thought experiment about someone else’s compliance headache. It is a set of obligations with dates attached: a conformity assessment before the system goes to market, technical documentation and risk management that actually exist on paper, meaningful human oversight designed into the workflow, CE marking, and registration in an EU database. The question stopped being whether this applies. It applies. The only question left is whether you built the last two years in a way that makes answering for it a formality or a fire drill.

The deadline audits the work you already owed

And that is the genuinely interesting thing about this deadline, the reason it is worth an essay rather than a link to a law firm. It does not ask for anything that good engineering leadership was not already asking for. Read the high-risk requirements next to the arguments I have been making on this site and they line up almost point for point.

The Act wants you to be able to state what your system is supposed to do and show it does that. That is an eval suite, the thing that writes down what “correct” means for a non-deterministic feature, which most teams still do not have. The Act wants documented limits on system behavior with a named owner. That is treating guardrails as a business decision with an explicit risk appetite rather than inheriting a framework’s defaults. The Act wants meaningful human oversight and a clear line of accountability. That is the oldest argument here, that a human owns every merge and that someone must be on call for model quality rather than leaving it to drift. The regulation did not invent a new discipline. It wrote the discipline that responsible teams were already practicing into law, and put a date on it.

So the deadline sorts organizations cleanly into two groups, and which group you are in was decided months ago. If you built evals, documented your guardrails, assigned ownership of model quality, and kept a human meaningfully in the loop because those were simply good engineering, then the conformity assessment is mostly the work of writing down what you already do. If you treated all of that as optional overhead to be added later, you are now learning that “the AI wrote it” is no longer just a quality dodge you can apologize for. It is a legal exposure, with CE marking and a public registration standing between your feature and your market.

Compliance was the audit all along

The teams scrambling this month are not scrambling because a regulation appeared. They are scrambling because a regulation made visible a gap that was always there, and that they had been free to ignore as long as no one with authority was looking. That is what a compliance deadline actually is: an external audit of your internal discipline, run on someone else’s schedule, with your access to a market as the stakes.

The EU AI Act did not turn responsible engineering into a legal requirement so much as reveal that, for anything touching decisions about people, they were the same thing the whole time. The discipline was never optional for a system that can change the course of someone’s career. The law just made the bill legible, and handed it, on 2 August, to everyone who had been pretending it would not come.

If this maps to problems you're working on, my inbox is open — the conversation continues on LinkedIn.