Executive summary: the bifurcated timeline
The AI Digital Omnibus agreement of 7 May 2026 structurally split the EU AI Act enforcement calendar into two distinct phases for organisations deploying AI in employment and recruitment contexts. Understanding this split is operationally critical — the two deadlines carry different obligations and different levels of urgency.
Confirmed enforcement timeline — post-Omnibus
Article 50(1) — Proactive AI transparency
Candidate-facing chatbots, automated screening interfaces, AI-generated content disclosures. Not extended by the Omnibus agreement.
Title III / Article 26 — Full high-risk deployer obligations
Governance, logging, human oversight, risk management, Article 86 right to explanation. Extended 16 months under the Omnibus.
1. Legal architecture: the recruitment agency as deployer
The EU AI Act structures obligations based on an entity's position in the technology supply chain. Misclassifying an organisation's role invalidates its compliance approach. Recruitment agencies and staffing firms are in almost all operational configurations classified as deployers, not providers.
1.1 Statutory definition — Article 3(4)
"…any natural or legal person, public authority, agency or other body using an AI system under its own authority except where the AI system is used in the course of a personal non-professional activity."
— Article 3(4), Regulation (EU) 2024/1689
1.2 Operational application to recruitment
A recruitment agency is classified as a deployer whenever it integrates third-party software featuring algorithmic filtering, predictive scoring, or automated candidate ranking into its business operations. The agency operates the system "under its own authority" because it retains control over three critical operational parameters:
- Selection of the software vendor and the contractual terms under which the system is provided.
- The parameters, job descriptions, and criteria fed into the system.
- The ultimate business decision — whether a candidate is advanced, shortlisted, or rejected.
2. Risk categorisation: why recruitment AI is high-risk by statute
The EU AI Act applies a risk-based tiering system. AI systems used in recruitment are explicitly codified as high-risk in Annex III, removing operational ambiguity about classification.
2.1 Statutory reference — Annex III, Category 4(a)
"AI systems intended to be used for recruitment or selection of natural persons, notably for advertising vacancies, screening or filtering applications, evaluating candidates in the course of interviews or tests."
— Annex III, Point 4(a), Regulation (EU) 2024/1689
2.2 Systems that trigger the high-risk classification
If your agency uses any of the following technical capabilities, it is deploying a high-risk AI system for the purposes of Annex III:
- Applicant Tracking Systems (ATS) featuring automated match-scoring or CV-ranking algorithms.
- AI video interview platforms that analyse speech, text, or inferred behavioural patterns to evaluate candidate suitability.
- Psychometric or cognitive testing software that uses algorithmic models to score, tier, or generate candidate profiles.
- Programmatic job advertising tools that algorithmically target or restrict vacancy visibility based on inferred demographic profiles.
2.3 The profiling absolute — Article 6(4)
Article 6 contains a narrow exception where an Annex III system may not be treated as high-risk if it does not materially influence decision-making. Article 6(4) removes this exception entirely where the system performs profiling of natural persons:
"An AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons."
— Article 6(4), Regulation (EU) 2024/1689
Because modern recruitment screening tools inherently evaluate personal data to predict candidate suitability, they constitute profiling under Article 3(4) of the GDPR. The Article 6(3) exception is therefore not available to most recruitment AI deployments; the high-risk classification applies without the possibility of claiming an exemption for automated candidate filtering. This should be the default working assumption for any agency conducting a classification assessment, absent specific documented analysis to the contrary.
3. Statutory deployer obligations — Article 26
Enforcement date: 2 December 2027 (extended by AI Digital Omnibus, May 2026)
Once a system is identified as high-risk, the recruitment agency bears direct, non-delegable statutory obligations under Article 26. These obligations are independent of the software provider's own compliance status.
3.1 Article 26(1) — adherence to instructions for use
Deployers must implement technical and organisational measures to ensure the system is operated strictly in accordance with the instructions for use provided by the technology vendor.
Operational execution:Agencies cannot repurpose a tool beyond its validated scope. If an AI tool was validated by the vendor for high-volume graduate retail screening, deploying it to screen senior executive profiles or medical personnel without documented reassessment likely constitutes a breach of Article 26(1). The deployment configuration must match the vendor's technical documentation.
- ☐Obtain and retain the current instructions for use from each AI vendor.
- ☐Map current deployment configurations against the documented intended use.
- ☐Maintain an AI Operational Parameters Log recording how each tool is actually deployed versus its documented scope.
- ☐Where deployment deviates from documented scope, seek written clarification from the vendor.
3.2 Article 26(2) — mandatory assignment of competent human oversight
Human oversight cannot be a passive or nominal exercise. The agency must formally assign oversight duties to natural persons who possess the necessary competence, training, and authority. Specifically, designated individuals must have:
- The technical competence and specific training to understand the system's inherent limitations, known biases, and potential error modes (including automation bias).
- The explicit organisational authority to override, disregard, or deactivate the AI system's outputs without facing internal operational penalties for doing so.
- ☐Formally designate human oversight officers for each high-risk AI tool.
- ☐Document their training, including specific understanding of the tool's documented failure modes.
- ☐Confirm in writing that they have the authority to override AI outputs.
- ☐Maintain records of instances where AI outputs were overridden or adjusted.
3.3 Article 26(3) — input data quality and relevance
Deployers must ensure that data fed into the high-risk AI system is relevant, accurate, and of sufficient quality, to the extent they exercise operational control over the inputs.
Operational execution: Inputting unstructured or biased job descriptions into an algorithmic ranking tool — for example, using gendered language that causes the system to systematically disadvantage certain candidate demographics — may constitute a direct breach of Article 26(3). Agencies should implement a standardised data ingestion protocol for recruiters covering authorised data fields and pre-submission bias checks.
3.4 Article 26(5) — operational log retention
Deployers must retain the operational logs automatically generated by the high-risk AI system to the extent such logs are under their control. The Regulation establishes a baseline expectation of at least six months, subject to applicable national employment limitation periods.
Irish context: Under the Employment Equality Acts 1998–2015, the standard limitation period for discrimination complaints is six months (extendable to twelve months in exceptional circumstances). Specific contractual actions may carry longer limitation periods. Log retention periods should be assessed against both the EU AI Act baseline and applicable Irish employment law limitation periods.
- ☐Confirm with each AI vendor whether operational logs are generated and whether they are accessible to your agency.
- ☐Establish a secure log archive with automated retention policies of at least six months.
- ☐Align retention periods with GDPR data retention schedules and applicable Irish employment limitation periods.
- ☐Document who has access to retained logs and for what purposes.
4. Article 50: proactive transparency — the August 2026 obligation
Enforcement date: 2 August 2026 — not extended by Omnibus
Article 50(1) of the Regulation requires that where an AI system directly interacts with a natural person, the deployer must ensure that the individual is informed of this fact immediately and in a clear, prominent manner. This obligation is not subject to the December 2027 extension introduced by the AI Digital Omnibus — it remains active from 2 August 2026.
4.1 When Article 50(1) applies in a recruitment context
Article 50(1) is triggered whenever a candidate interacts directly and in real time with an AI system operated by the agency. The most common recruitment configurations that trigger this obligation include:
- AI chatbots used for initial candidate intake, application assistance, or preliminary qualification screening.
- Automated AI-powered voice or video interview platforms that candidates engage with in real time before any human contact.
- AI messaging systems that conduct pre-screening Q&A conversations with applicants.
Backend AI systems — such as CV-ranking algorithms that process submitted applications without direct candidate interaction — do not directly trigger Article 50(1), although they are subject to the full Article 26 obligation framework from December 2027.
4.2 What a compliant Article 50(1) disclosure requires
The Regulation requires that notification be timely and clear. Based on the regulatory text and available guidance, a compliant disclosure should be:
- Delivered at the point of interaction — before or immediately upon the candidate beginning to interact with the AI system.
- Clear and prominent — distinct from general privacy policy text and not buried in terms and conditions.
- Specific to the AI interaction — a general statement that 'we use technology' is unlikely to satisfy the standard.
- ☐Audit all candidate-facing digital touchpoints for AI-powered interactions.
- ☐Implement hard-coded UI/UX disclosures at the point of each AI interaction before 2 August 2026.
- ☐Ensure disclosures are distinct from general privacy policy language.
- ☐Document the disclosure mechanism and its implementation date.
5. Article 86: the candidate right to explanation
Enforcement date: 2 December 2027
5.1 Statutory right
"Any affected person subject to a decision taken by the deployer that is based on the output of a high-risk AI system listed in Annex III… and that produces legal effects or similarly significantly affects that person in a significant way, shall have the right to obtain from the deployer clear and meaningful explanations of the role that the AI system played in the decision-making procedure and the main elements of the decision taken."
— Article 86(1), Regulation (EU) 2024/1689
5.2 Trigger conditions and mandatory response content
Article 86 is activated when a candidate is subject to a significant decision — typically, a rejection from a shortlisting process where an AI ranking or filtering tool materially influenced the outcome. A compliant response to an Article 86 request must include:
- The specific role the AI system played in the decision-making procedure.
- The main parameters, inputs, and elements the system took into account when evaluating the candidate.
- The human oversight review that validated or overrode the AI output.
Agencies should establish an Article 86 response procedure capable of exporting algorithmic scoring criteria and human review records into plain-English documentation within applicable response windows.
5.3 The GDPR intersection
Article 22 of the GDPR provides data subjects with rights relating to solely automated decisions that produce legal or similarly significant effects. This obligation is already in force. For recruitment agencies using AI systems that contribute to candidate rejection decisions, the Article 22 GDPR obligation should be assessed alongside Article 86 of the AI Act. These are overlapping but legally distinct obligations that may be satisfied by the same documentation infrastructure, subject to legal review.
6. The Irish jurisdictional framework
Deployers operating in Ireland must navigate a coordinated multi-agency regulatory landscape established by the General Scheme of the Regulation of Artificial Intelligence Bill 2026, published February 2026.
Irish AI regulatory structure — as confirmed February 2026
Oifig Intleachta Shaorga na hÉireann
AI Office of Ireland · Central coordinating body
Workplace Relations Commission
WRC · MSA for employment AI
Relevant for recruitment
Data Protection Commission
DPC · GDPR enforcement
6.1 AI Office of Ireland — central coordinator
Under the General Scheme of the Regulation of Artificial Intelligence Bill 2026, Ireland established the Oifig Intleachta Shaorga na hÉireann as the national competent authority and single point of contact for the European AI Board. The AI Office of Ireland coordinates across fifteen sector-specific competent authorities, each responsible for AI Act oversight in their domain.
6.2 Workplace Relations Commission — the authority for recruitment AI
For recruitment agencies and HR technology operators, the designated sector-specific competent authority and market surveillance authority is the Workplace Relations Commission (WRC). The WRC has been designated under the 2026 Bill as the authority responsible for supervising compliance with the EU AI Act in employment and labour market contexts, including recruitment. The WRC possesses the statutory power to:
- Inspect recruitment agencies and demand production of compliance documentation.
- Investigate complaints of algorithmic discrimination brought by candidates.
- Initiate enforcement proceedings under both the EU AI Act and the Employment Equality Acts 1998–2015.
6.3 The burden of proof problem
Under Irish employment law, once a complainant establishes a prima facie case of disparate impact from an AI filtering process, the burden of proof shifts to the employer or agency to demonstrate that the selection tool is objectively justified by a legitimate aim and that the means are appropriate and necessary.
An agency that lacks Article 26 documentation — no instructions-for-use records, no human oversight logs, no audit trail of AI outputs — will structurally fail this legal test if a WRC complaint is lodged. The documentation infrastructure required by the EU AI Act is not administrative overhead; it is the evidentiary foundation that allows the agency to defend itself in an employment equality proceeding.
6.4 GDPR and the DPC
The Data Protection Commission retains full oversight over the processing of candidate personal data under the GDPR. High-risk AI deployments in recruitment inherently constitute high-risk processing under Article 35 GDPR, making a Data Protection Impact Assessment (DPIA) mandatory before deployment. Agencies that have not conducted a DPIA for each AI system used in candidate evaluation should treat this as an immediate compliance gap, independent of the AI Act timeline.
7. Operational compliance checklist for agency directors
The following assets are required to establish a defensible compliance position before the WRC and the AI Office of Ireland.
AI system inventory: audit and catalog every algorithmic, ranking, or predictive tool active across all hiring workflows.
Article 50 UI/UX implementation: hard-code proactive AI disclosures onto all candidate-facing chatbots and assessment portals.
Article 13 vendor audit: formally request compliant instructions for use and bias/accuracy metrics from all ATS and screening vendors.
Human oversight protocols: formally designate and train oversight officers; document all AI output overrides.
Article 86 response infrastructure: create data export workflows to fulfil candidate requests for algorithmic explanations.
8. Sources
- [1]Regulation (EU) 2024/1689 — AI Act, OJ L, 12 July 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202401689
- [2]European Commission — AI Digital Omnibus, provisional political agreement, 7 May 2026. https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence
- [3]Council of the EU press release — AI Digital Omnibus agreement, 7 May 2026. https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/
- [4]Ireland — General Scheme of the Regulation of Artificial Intelligence Bill 2026, published February 2026. https://www.gov.ie/en/press-release/
- [5]Data Protection Commission (Ireland) — AI and GDPR guidance. https://www.dataprotection.ie
- [6]Workplace Relations Commission (Ireland). https://www.workplacerelations.ie
- [7]Matheson LLP — EU AI Omnibus deal analysis, May 2026. https://www.matheson.com/insights/eu-legislators-reach-agreement-on-ai-digital-omnibus-regulation/
This document (KADYA-AI-ACT-RECRUIT-V2.1) is published by Kadya for informational purposes only. Kadya is a compliance software company, not a law firm. Nothing in this document constitutes legal advice. Readers with specific compliance questions should seek independent legal counsel, in particular from solicitors with expertise in Irish employment law and EU regulatory frameworks. © Kadya 2026.
