Kadya
Kadya

Kadya Research · Published May 2026 · Document KADYA-AI-ACT-RECRUIT-V2.1

Updated post-Omnibus · 7 May 2026 agreement incorporated

EU AI Act: Complete Obligation Reference for Recruitment Deployers

Post-Omnibus operational analysis. Statutory obligations, confirmed Irish regulatory structure, and implementation timeline — May 2026 edition.

This is a companion document to the foundational guide. If you are new to EU AI Act concepts, begin with the operational obligation reference (v1.1) published April 2026. This document assumes familiarity with the core framework and focuses on the structural changes introduced by the AI Digital Omnibus agreement of 7 May 2026.
Disclaimer. This document reflects an operational interpretation of Regulation (EU) 2024/1689 and the provisional AI Digital Omnibus agreement as of May 2026. It is provided for educational and informational purposes only. It does not constitute legal advice. Organisations must seek independent employment counsel to validate their specific governance structures. Kadya is a software company, not a law firm.

Executive summary: the bifurcated timeline

The AI Digital Omnibus agreement of 7 May 2026 structurally split the EU AI Act enforcement calendar into two distinct phases for organisations deploying AI in employment and recruitment contexts. Understanding this split is operationally critical — the two deadlines carry different obligations and different levels of urgency.

Confirmed enforcement timeline — post-Omnibus

Article 50(1) — Proactive AI transparency

Candidate-facing chatbots, automated screening interfaces, AI-generated content disclosures. Not extended by the Omnibus agreement.

2 August 2026

Title III / Article 26 — Full high-risk deployer obligations

Governance, logging, human oversight, risk management, Article 86 right to explanation. Extended 16 months under the Omnibus.

2 December 2027
Why the split matters for recruitment agencies. Agencies that use only backend CV-ranking or automated shortlisting tools (no candidate-facing AI interface) face the December 2027 deadline as their primary compliance horizon. Agencies that also deploy AI chatbots for initial candidate intake, or automated AI-powered interview platforms that candidates interact with directly, must comply with Article 50(1) proactive disclosure requirements by 2 August 2026 — this year. The distinction turns on whether the AI interacts with the candidate in real time, not on whether the AI influences the hiring outcome.

1. Legal architecture: the recruitment agency as deployer

The EU AI Act structures obligations based on an entity's position in the technology supply chain. Misclassifying an organisation's role invalidates its compliance approach. Recruitment agencies and staffing firms are in almost all operational configurations classified as deployers, not providers.

1.1 Statutory definition — Article 3(4)

"…any natural or legal person, public authority, agency or other body using an AI system under its own authority except where the AI system is used in the course of a personal non-professional activity."
— Article 3(4), Regulation (EU) 2024/1689

1.2 Operational application to recruitment

A recruitment agency is classified as a deployer whenever it integrates third-party software featuring algorithmic filtering, predictive scoring, or automated candidate ranking into its business operations. The agency operates the system "under its own authority" because it retains control over three critical operational parameters:

  • Selection of the software vendor and the contractual terms under which the system is provided.
  • The parameters, job descriptions, and criteria fed into the system.
  • The ultimate business decision — whether a candidate is advanced, shortlisted, or rejected.
The vendor compliance misconception.A common error is assuming that because the AI tool was built and trained by a third-party provider, the compliance obligation rests with that provider. Provider obligations under Articles 16–25 of the Regulation apply to the organisation that developed the system. Deployer obligations under Article 26 apply to the organisation using it. These are parallel, non-substitutable obligations. Your AI vendor's compliance does not satisfy your deployer obligations.

2. Risk categorisation: why recruitment AI is high-risk by statute

The EU AI Act applies a risk-based tiering system. AI systems used in recruitment are explicitly codified as high-risk in Annex III, removing operational ambiguity about classification.

2.1 Statutory reference — Annex III, Category 4(a)

"AI systems intended to be used for recruitment or selection of natural persons, notably for advertising vacancies, screening or filtering applications, evaluating candidates in the course of interviews or tests."
— Annex III, Point 4(a), Regulation (EU) 2024/1689

2.2 Systems that trigger the high-risk classification

If your agency uses any of the following technical capabilities, it is deploying a high-risk AI system for the purposes of Annex III:

  • Applicant Tracking Systems (ATS) featuring automated match-scoring or CV-ranking algorithms.
  • AI video interview platforms that analyse speech, text, or inferred behavioural patterns to evaluate candidate suitability.
  • Psychometric or cognitive testing software that uses algorithmic models to score, tier, or generate candidate profiles.
  • Programmatic job advertising tools that algorithmically target or restrict vacancy visibility based on inferred demographic profiles.

2.3 The profiling absolute — Article 6(4)

Article 6 contains a narrow exception where an Annex III system may not be treated as high-risk if it does not materially influence decision-making. Article 6(4) removes this exception entirely where the system performs profiling of natural persons:

"An AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons."
— Article 6(4), Regulation (EU) 2024/1689

Because modern recruitment screening tools inherently evaluate personal data to predict candidate suitability, they constitute profiling under Article 3(4) of the GDPR. The Article 6(3) exception is therefore not available to most recruitment AI deployments; the high-risk classification applies without the possibility of claiming an exemption for automated candidate filtering. This should be the default working assumption for any agency conducting a classification assessment, absent specific documented analysis to the contrary.

3. Statutory deployer obligations — Article 26

Enforcement date: 2 December 2027 (extended by AI Digital Omnibus, May 2026)

Once a system is identified as high-risk, the recruitment agency bears direct, non-delegable statutory obligations under Article 26. These obligations are independent of the software provider's own compliance status.

3.1 Article 26(1) — adherence to instructions for use

Deployers must implement technical and organisational measures to ensure the system is operated strictly in accordance with the instructions for use provided by the technology vendor.

Operational execution:Agencies cannot repurpose a tool beyond its validated scope. If an AI tool was validated by the vendor for high-volume graduate retail screening, deploying it to screen senior executive profiles or medical personnel without documented reassessment likely constitutes a breach of Article 26(1). The deployment configuration must match the vendor's technical documentation.

  • Obtain and retain the current instructions for use from each AI vendor.
  • Map current deployment configurations against the documented intended use.
  • Maintain an AI Operational Parameters Log recording how each tool is actually deployed versus its documented scope.
  • Where deployment deviates from documented scope, seek written clarification from the vendor.

3.2 Article 26(2) — mandatory assignment of competent human oversight

Human oversight cannot be a passive or nominal exercise. The agency must formally assign oversight duties to natural persons who possess the necessary competence, training, and authority. Specifically, designated individuals must have:

  • The technical competence and specific training to understand the system's inherent limitations, known biases, and potential error modes (including automation bias).
  • The explicit organisational authority to override, disregard, or deactivate the AI system's outputs without facing internal operational penalties for doing so.
The authority requirement is structural, not nominal. A recruiter who nominally reviews AI-generated shortlists but operates under volume pressure or target incentives that discourage deviation from the AI output does not satisfy Article 26(2) in substance. Effective oversight requires that the organisation's operational processes genuinely accommodate the possibility of AI output rejection.
  • Formally designate human oversight officers for each high-risk AI tool.
  • Document their training, including specific understanding of the tool's documented failure modes.
  • Confirm in writing that they have the authority to override AI outputs.
  • Maintain records of instances where AI outputs were overridden or adjusted.

3.3 Article 26(3) — input data quality and relevance

Deployers must ensure that data fed into the high-risk AI system is relevant, accurate, and of sufficient quality, to the extent they exercise operational control over the inputs.

Operational execution: Inputting unstructured or biased job descriptions into an algorithmic ranking tool — for example, using gendered language that causes the system to systematically disadvantage certain candidate demographics — may constitute a direct breach of Article 26(3). Agencies should implement a standardised data ingestion protocol for recruiters covering authorised data fields and pre-submission bias checks.

3.4 Article 26(5) — operational log retention

Deployers must retain the operational logs automatically generated by the high-risk AI system to the extent such logs are under their control. The Regulation establishes a baseline expectation of at least six months, subject to applicable national employment limitation periods.

Irish context: Under the Employment Equality Acts 1998–2015, the standard limitation period for discrimination complaints is six months (extendable to twelve months in exceptional circumstances). Specific contractual actions may carry longer limitation periods. Log retention periods should be assessed against both the EU AI Act baseline and applicable Irish employment law limitation periods.

  • Confirm with each AI vendor whether operational logs are generated and whether they are accessible to your agency.
  • Establish a secure log archive with automated retention policies of at least six months.
  • Align retention periods with GDPR data retention schedules and applicable Irish employment limitation periods.
  • Document who has access to retained logs and for what purposes.

4. Article 50: proactive transparency — the August 2026 obligation

Enforcement date: 2 August 2026 — not extended by Omnibus

Article 50(1) of the Regulation requires that where an AI system directly interacts with a natural person, the deployer must ensure that the individual is informed of this fact immediately and in a clear, prominent manner. This obligation is not subject to the December 2027 extension introduced by the AI Digital Omnibus — it remains active from 2 August 2026.

4.1 When Article 50(1) applies in a recruitment context

Article 50(1) is triggered whenever a candidate interacts directly and in real time with an AI system operated by the agency. The most common recruitment configurations that trigger this obligation include:

  • AI chatbots used for initial candidate intake, application assistance, or preliminary qualification screening.
  • Automated AI-powered voice or video interview platforms that candidates engage with in real time before any human contact.
  • AI messaging systems that conduct pre-screening Q&A conversations with applicants.

Backend AI systems — such as CV-ranking algorithms that process submitted applications without direct candidate interaction — do not directly trigger Article 50(1), although they are subject to the full Article 26 obligation framework from December 2027.

4.2 What a compliant Article 50(1) disclosure requires

The Regulation requires that notification be timely and clear. Based on the regulatory text and available guidance, a compliant disclosure should be:

  • Delivered at the point of interaction — before or immediately upon the candidate beginning to interact with the AI system.
  • Clear and prominent — distinct from general privacy policy text and not buried in terms and conditions.
  • Specific to the AI interaction — a general statement that 'we use technology' is unlikely to satisfy the standard.
  • Audit all candidate-facing digital touchpoints for AI-powered interactions.
  • Implement hard-coded UI/UX disclosures at the point of each AI interaction before 2 August 2026.
  • Ensure disclosures are distinct from general privacy policy language.
  • Document the disclosure mechanism and its implementation date.
Interpretation uncertainty. As of the assessment date, there is limited published guidance from the EU AI Office on precisely what language satisfies the "timely and clear" standard in a recruitment context. Agencies implementing Article 50(1) disclosures before August 2026 should document their interpretation rationale and seek independent legal review of the disclosure language.

5. Article 86: the candidate right to explanation

Enforcement date: 2 December 2027

5.1 Statutory right

"Any affected person subject to a decision taken by the deployer that is based on the output of a high-risk AI system listed in Annex III… and that produces legal effects or similarly significantly affects that person in a significant way, shall have the right to obtain from the deployer clear and meaningful explanations of the role that the AI system played in the decision-making procedure and the main elements of the decision taken."
— Article 86(1), Regulation (EU) 2024/1689

5.2 Trigger conditions and mandatory response content

Article 86 is activated when a candidate is subject to a significant decision — typically, a rejection from a shortlisting process where an AI ranking or filtering tool materially influenced the outcome. A compliant response to an Article 86 request must include:

  • The specific role the AI system played in the decision-making procedure.
  • The main parameters, inputs, and elements the system took into account when evaluating the candidate.
  • The human oversight review that validated or overrode the AI output.

Agencies should establish an Article 86 response procedure capable of exporting algorithmic scoring criteria and human review records into plain-English documentation within applicable response windows.

5.3 The GDPR intersection

Article 22 of the GDPR provides data subjects with rights relating to solely automated decisions that produce legal or similarly significant effects. This obligation is already in force. For recruitment agencies using AI systems that contribute to candidate rejection decisions, the Article 22 GDPR obligation should be assessed alongside Article 86 of the AI Act. These are overlapping but legally distinct obligations that may be satisfied by the same documentation infrastructure, subject to legal review.

6. The Irish jurisdictional framework

Deployers operating in Ireland must navigate a coordinated multi-agency regulatory landscape established by the General Scheme of the Regulation of Artificial Intelligence Bill 2026, published February 2026.

Irish AI regulatory structure — as confirmed February 2026

Oifig Intleachta Shaorga na hÉireann

AI Office of Ireland · Central coordinating body

Workplace Relations Commission

WRC · MSA for employment AI

Relevant for recruitment

Data Protection Commission

DPC · GDPR enforcement

6.1 AI Office of Ireland — central coordinator

Under the General Scheme of the Regulation of Artificial Intelligence Bill 2026, Ireland established the Oifig Intleachta Shaorga na hÉireann as the national competent authority and single point of contact for the European AI Board. The AI Office of Ireland coordinates across fifteen sector-specific competent authorities, each responsible for AI Act oversight in their domain.

6.2 Workplace Relations Commission — the authority for recruitment AI

For recruitment agencies and HR technology operators, the designated sector-specific competent authority and market surveillance authority is the Workplace Relations Commission (WRC). The WRC has been designated under the 2026 Bill as the authority responsible for supervising compliance with the EU AI Act in employment and labour market contexts, including recruitment. The WRC possesses the statutory power to:

  • Inspect recruitment agencies and demand production of compliance documentation.
  • Investigate complaints of algorithmic discrimination brought by candidates.
  • Initiate enforcement proceedings under both the EU AI Act and the Employment Equality Acts 1998–2015.

6.3 The burden of proof problem

Under Irish employment law, once a complainant establishes a prima facie case of disparate impact from an AI filtering process, the burden of proof shifts to the employer or agency to demonstrate that the selection tool is objectively justified by a legitimate aim and that the means are appropriate and necessary.

An agency that lacks Article 26 documentation — no instructions-for-use records, no human oversight logs, no audit trail of AI outputs — will structurally fail this legal test if a WRC complaint is lodged. The documentation infrastructure required by the EU AI Act is not administrative overhead; it is the evidentiary foundation that allows the agency to defend itself in an employment equality proceeding.

6.4 GDPR and the DPC

The Data Protection Commission retains full oversight over the processing of candidate personal data under the GDPR. High-risk AI deployments in recruitment inherently constitute high-risk processing under Article 35 GDPR, making a Data Protection Impact Assessment (DPIA) mandatory before deployment. Agencies that have not conducted a DPIA for each AI system used in candidate evaluation should treat this as an immediate compliance gap, independent of the AI Act timeline.

7. Operational compliance checklist for agency directors

The following assets are required to establish a defensible compliance position before the WRC and the AI Office of Ireland.

CL-01

AI system inventory: audit and catalog every algorithmic, ranking, or predictive tool active across all hiring workflows.

Immediate
CL-02

Article 50 UI/UX implementation: hard-code proactive AI disclosures onto all candidate-facing chatbots and assessment portals.

2 Aug 2026
CL-03

Article 13 vendor audit: formally request compliant instructions for use and bias/accuracy metrics from all ATS and screening vendors.

1 Jan 2027
CL-04

Human oversight protocols: formally designate and train oversight officers; document all AI output overrides.

1 Jun 2027
CL-05

Article 86 response infrastructure: create data export workflows to fulfil candidate requests for algorithmic explanations.

2 Dec 2027
Implementation sequencing. CL-01 (the inventory) is the prerequisite for all other actions. Without an accurate picture of which AI systems are in use and how they are deployed, subsequent steps — vendor audits, oversight designation, log retention — cannot be scoped correctly. This should be the first action taken regardless of the compliance timeline.

8. Sources

  1. [1]Regulation (EU) 2024/1689 — AI Act, OJ L, 12 July 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202401689
  2. [2]European Commission — AI Digital Omnibus, provisional political agreement, 7 May 2026. https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence
  3. [3]Council of the EU press release — AI Digital Omnibus agreement, 7 May 2026. https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/
  4. [4]Ireland — General Scheme of the Regulation of Artificial Intelligence Bill 2026, published February 2026. https://www.gov.ie/en/press-release/
  5. [5]Data Protection Commission (Ireland) — AI and GDPR guidance. https://www.dataprotection.ie
  6. [6]Workplace Relations Commission (Ireland). https://www.workplacerelations.ie
  7. [7]Matheson LLP — EU AI Omnibus deal analysis, May 2026. https://www.matheson.com/insights/eu-legislators-reach-agreement-on-ai-digital-omnibus-regulation/

This document (KADYA-AI-ACT-RECRUIT-V2.1) is published by Kadya for informational purposes only. Kadya is a compliance software company, not a law firm. Nothing in this document constitutes legal advice. Readers with specific compliance questions should seek independent legal counsel, in particular from solicitors with expertise in Irish employment law and EU regulatory frameworks. © Kadya 2026.