For more than a year, August 2, 2026 was the date. It was the day the EU AI Act’s high-risk regime was supposed to reach the systems that decide who gets hired, who gets promoted, who gets scheduled and who gets cut. The date arrived. The regime did not.
Annex III is where the employment use cases live, and the list is unusually concrete: placing targeted job advertisements, analyzing and filtering job applications, evaluating candidates, and making decisions about employment terms, promotion, termination, task allocation based on individual behavior or personal traits, and monitoring or evaluating worker performance. Any AI system running in those lanes is high-risk, and the employer running it picks up a set of duties — tell workers the system is in use, put a human in the loop who can actually intervene, watch for discriminatory outcomes, keep the system logs, meet the data rules.
Those duties now apply from December 2, 2027. Sixteen months of runway.
Who moved the date
This was not a regulator quietly declining to enforce. It was a legislative amendment that went the whole distance.
On May 7, the European Parliament, the Council and the Commission struck a provisional deal on the Digital Omnibus on AI. On June 16, Parliament approved it. On June 29, the Council gave final approval, filing the amendment under the Omnibus VII simplification package.
The new schedule is a set of dates, not one:
- Stand-alone high-risk systems, including every employment use case: December 2, 2027
- High-risk AI embedded in regulated products: August 2, 2028
- National regulatory sandboxes: also December 2, 2027
The stated reason is readiness. National authorities are not staffed for it and the harmonized technical standards are not finished. Law firms briefing employers have converged on one line: this is a reprieve, not a repeal. Nothing came off the Annex III list. Conformity assessments, technical documentation, human-oversight controls and EU database registration are all still coming, 16 months later than booked.
What August 2 did carry
The day was not empty. Article 50, the transparency layer, applied on schedule, and it is a different animal from the high-risk regime.
Article 50 says: systems that interact directly with people must let those people know they are talking to an AI. Providers of systems that generate or manipulate audio, image, video or text must mark the output in a machine-readable format. Deployers of emotion recognition or biometric categorization systems must tell the people exposed to them. Deepfakes must be disclosed. AI-generated text published to inform the public on matters of public interest must generally say so, with a carve-out where a human has reviewed it and someone holds editorial responsibility.
The penalty tier is real. Article 50 violations carry a statutory ceiling of €15M or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. That is a ceiling, not an automatic fine, and for qualifying SMEs and startups the applicable maximum flips to the lower of the two figures.
One transition is easy to misread as a general postponement. Providers of covered content-generating systems already on the market before August 2 have until December 2, 2026 to build the technical marking. That grace period covers the provider-side marking duty and nothing else, and it does not reach systems placed on the market from August 2 forward.
Two regimes, two different things being protected
Line the arrived-on-time obligations up against the deferred ones and the split is clean.
What landed protects you from being fooled by AI. The chatbot has to tell you it is a chatbot. The synthetic video has to be labeled. The system reading your face has to give you notice first.
What slipped protects you from being managed by AI. An algorithm scored your application, and you would have had the right to know. A system put you on a termination list, and a human would have had to review it. The model produced skewed outcomes across a protected group, and the employer would have had to find that and log it.
The first set is about whether what you are looking at is real. The second set is about your job. Europe shipped the first one.
What European workers hold for the next 16 months
National labor law, whatever their union negotiated, and the automated-decision provision in GDPR. None of the three was drafted for the specific case of an AI system participating in a dismissal.
The comparison that makes the gap legible runs the other way across the Atlantic.
Illinois has required employers to notify applicants and employees when AI is used in hiring and employment decisions since January 1, 2026. Colorado’s AI Act took effect June 30, 2026. The notice right those two statutes create is precisely the one Europe just pushed to the end of 2027. On the narrow question of whether you are entitled to know an algorithm screened your resume, a jobseeker in Chicago is currently standing further forward than a jobseeker in Berlin.
On July 16, 26 Meta employees sued, alleging that a stack of internal AI systems scored and ranked them onto the May layoff list. The complaint names an internal system called Metamate, employee-trained “second-brain” agents, keystroke and activity monitoring, AI-token-usage dashboards, and algorithmically assisted performance ranking and calibration. Meta’s answer is that people made the decisions, not AI. That case now has to be proven by the plaintiffs inside the American litigation system (we covered it in July). Had Annex III landed on August 2 and had the same facts occurred inside the EU, the logs the employer was obliged to keep, the human review it was obliged to perform and the notice it was obliged to give would already be sitting there as an evidentiary chain. That chain now gets welded in December 2027.
The same vacuum already has names attached to it in the U.S. Buried in Challenger’s August 6 monthly report is a passage that is not a statistic: Montefiore in the Bronx eliminated 12 utilization review nursing positions and moved the work to software from Datavant. The nurses’ union filed a class-action grievance, resting on the AI-protection language in the contract it won after a 41-day strike (we covered that on August 6). They have a fight to have because they bargained for one, not because a statute gave them one.
What this means if you are working or looking
Do not treat “AI was involved in this decision” as a right you can cite. In the EU, before December 2, 2027, no employer is legally required to tell you what system sat in the hiring process. The routes to that information today are a union, a collective agreement, or a GDPR automated-decision request. All three are slower and less certain than a statute that simply obliges disclosure.
In the gap, enforceable protection comes off a bargaining table. Those 12 nurses at Montefiore have a clause to point at because they struck and got it written into the contract. For the next 16 months, AI language in a union contract is the fastest-moving worker protection available anywhere in this space.
The most exposed roles are the continuously scored ones. The closest-fitting line in Annex III is “monitoring or evaluating worker performance or behavior.” Performance ranking, activity monitoring and output metering are running at the same intensity in the U.S. and the EU. The only question was which side would first require someone to keep the logs. For now, neither does.
Put December 2, 2027 in the calendar. The advice lawyers are giving employers is to spend the 16 months as runway rather than as a cancellation. That reads the same way from the other side of the desk. That date is not the finish line — it is the point at which employers have to start talking.
Sources
- AI Act: EP approves simplification measures and nudifier app ban (European Parliament, June 16, 2026)
- Artificial intelligence: Council gives final green light to simplify and streamline rules (Council of the EU, June 29, 2026)
- EU AI Act, Annex III (high-risk use cases)
- EU AI Act, Article 50 (transparency obligations)
- EU Nears Approval of Agreement to Delay Rules for AI Use in Employment Decisions (Ogletree Deakins, June 16, 2026, with June 29 editor’s update)
- Yes, August 2 Still Matters: The EU Approved a High-Risk AI Delay, but Most Transparency Obligations Remain (Jones Walker, July 16, 2026)