If you are reading anything about AI for HR that was published before the end of July 2026, its compliance dates are probably wrong. The EU’s high-risk deadline for employment AI moved β six days before it was due to bite. Meanwhile the exposure in the United States went up, not down, and for a reason that has nothing to do with new AI legislation.
Here is the accurate picture as of 21 August 2026, what you can safely automate in hiring, and the one rule that keeps you out of trouble regardless of jurisdiction. This is general information, not legal advice β for anything consequential, talk to an employment lawyer in your jurisdiction.
What actually changed in the EU
The AI Act classifies AI used in recruitment, screening and employment decisions as high-risk, with obligations covering risk management, transparency, human oversight and record-keeping. Those obligations were due to apply from 2 August 2026.
They no longer do. Regulation (EU) 2026/1744 β the Digital Omnibus on AI β was published in the Official Journal on 24 July 2026 and entered into force on 27 July, deferring the stand-alone high-risk obligations to 2 December 2027. AI embedded in products already covered by EU product-safety law moves to 2 August 2028. The delay happened because the supporting machinery β harmonised standards, notified bodies, national supervisory authorities β was not ready.
But “the EU delayed the AI Act” is half true and misleading. Three things did not move:
- Transparency duties under Article 50 applied from 2 August 2026 as originally scheduled, with the machine-readable marking requirement reaching legacy systems from 2 December 2026.
- The AI literacy obligation stayed on its original timeline β staff using these systems need appropriate training.
- New prohibited practices arrive from 2 December 2026.
Systems already on the EU market before the new deadlines are largely grandfathered unless substantially modified β a threshold regulators have not yet defined, which is itself worth watching.
Why US exposure rose while EU deadlines slipped
This is the part that catches small employers out. American exposure here does not depend on new AI statutes at all. It rests on Title VII, the ADEA and the ADA, which have been in force for decades and are indifferent to how a decision was produced.
The case to know is Mobley v. Workday in the Northern District of California. The court allowed claims to proceed on the theory that the software vendor was acting as an agent of its client employers, bringing it within the statutory definition of employer. A collective action on the age-discrimination claim was preliminarily certified in May 2025, with notice authorised in February 2026, and further rulings through mid-2026 have kept the case expanding rather than narrowing. A July 2025 order required the vendor to identify employers who had enabled its AI screening features β meaning ordinary companies were pulled into the orbit of litigation they never joined.
A separate January 2026 class action against another hiring platform runs a different theory entirely, alleging the vendor operated as an unregistered consumer reporting agency under the Fair Credit Reporting Act. One case attacks outcomes; the other attacks process. Both point the same way for you as the buyer.
State law is layered on top and is genuinely inconsistent:
| Jurisdiction | What it requires |
|---|---|
| New York City | Independent bias audit of automated employment decision tools, published results, candidate notice. The duty sits with the employer, not the vendor |
| Illinois | Human Rights Act amendment effective 1 January 2026 covering AI in hiring, promotion, discipline and discharge, and expressly barring zip codes as proxies for protected classes |
| California | Civil Rights Department automated-decision regulations in force since October 2025; separate privacy-agency rules on automated decision-making technology require compliance by January 2027 |
| Colorado | Its original AI statute was frozen and rewritten; the replacement was signed in May 2026 with effect from January 2027, and covers vendors as well as employers |
Note the definitional trap: what counts as a regulated tool differs by law. New York City’s definition is narrow and turns on whether the tool substantially assists or replaces human decision-making. California’s reaches much further, into resume scanners and assessment software. Illinois does not define a tool category at all β it looks at outcomes. Building to the narrowest definition you are exposed to is how employers end up non-compliant somewhere else.
The rule that survives every jurisdiction
AI can widen the top of the funnel. A human makes every rejection and every hire.
Every serious AI for HR obligation described above is aimed at automated exclusion. Keep the exclusion decision human and the compliance surface shrinks to something a small employer can actually manage β which is also the honest answer to whether a paid tool is needed at all, discussed in free vs paid AI tools.
Almost everything in the tables above is an attempt to regulate automated exclusion. If no candidate is screened out by software, most of the risk simply does not arise β and the residual obligations become manageable. That single design decision does more for a small employer than any compliance document.
| Task | Verdict |
|---|---|
| Drafting and de-jargoning job descriptions | Safe, and genuinely useful β ask it to flag exclusionary or gendered language |
| Scheduling, reminders, status emails to candidates | Safe. This is where most of the time actually goes |
| Answering candidate FAQs about the role or process | Safe with guardrails β treat it like any public bot, see building an AI chatbot without code |
| Building structured interview questions and scorecards | Safe, and reduces bias rather than adding it |
| Summarising interview notes you took | Safe. Recording the interview itself needs consent β see Otter vs Fireflies |
| Ranking or scoring candidates | Regulated. Bias audits, notices and record-keeping likely apply |
| Automatic rejection below a threshold | Highest risk. Do not do this without legal advice and audit evidence |
| Video, facial, voice or personality analysis | Avoid. Disability and accent effects are foreseeable and hard to defend |
| Running AI detectors on candidate writing samples | Avoid. False positives fall disproportionately on non-native English speakers β the evidence is in our Grammarly review |
Proxies are how well-meaning systems discriminate
Nobody builds a tool that screens on protected characteristics. Systems discriminate through correlates, and the correlates are ordinary-looking fields:
- Postcode or zip code β a well-documented proxy for race, now expressly named in at least one state statute.
- Graduation year β a direct proxy for age, and the reason age claims are the ones getting certified.
- Employment gaps β correlate with caring responsibilities, disability and health.
- Named institutions β encode class, geography and national origin.
- Writing style and fluency β filter out non-native speakers and some disabilities.
- Continuous availability or response speed β filters carers and people in other time zones.
Practical test: for each field your process uses, ask what else it predicts. If the honest answer names a protected characteristic, either remove it or be ready to justify it as job-related and consistent with business necessity.
What to ask an AI for HR vendor before you buy
You are the deployer. In most of these regimes the obligation lands on you regardless of what the vendor promised, and the agent theory in Mobley shows the vendor being pulled in alongside rather than instead of the employer. Ask, and keep the answers in writing:
- Has this tool had an independent bias audit, when, and can we see the results?
- What data was the model trained on, and what fields does it actually use?
- What happens to candidate data β retention period, deletion, and whether it trains your models?
- Can we disable automatic scoring or ranking and keep only the workflow features?
- What documentation will you provide if we face a claim or an audit?
- Do you contractually indemnify us for discrimination claims arising from your tool?
Vagueness on any of the first four is a reason to walk. The same procurement discipline applies as in what AI agents can and can’t do: ask for evidence, not demonstrations.
Keep the paperwork, because that is the defence
- Record who reviewed each rejection and on what basis. Human review that is not documented is, in a dispute, indistinguishable from no human review.
- Keep application and outcome data long enough to run a comparison across groups β the traditional four-fifths screening test remains the practical benchmark for spotting adverse impact.
- Keep candidate notices, and the dates you changed them.
- Diary a quarterly review. Three of the four US regimes above are still in motion, and the EU dates have already moved once.
- Note that a 2026 ruling in the Workday litigation treated some bias-testing material as privileged in certain circumstances β an area where a lawyer’s involvement early genuinely changes your position later.
Where AI for HR actually pays off
Strip out the regulated parts and there is still a real case for AI for HR β it is just not the exciting part. Scheduling, candidate communication, job description drafting, interview structuring, and the administrative tail around offers. These are high-volume, low-stakes and easy to check, which is exactly the profile that works, as we set out in automating work with AI tools.
Screening is the glamorous use case and the one with all the liability. For most small employers it is also unnecessary: if you receive forty applications rather than four thousand, the bottleneck was never reading them. For the broader stack, see best AI tools for small business owners and cutting business costs with AI.
Frequently asked questions
Is AI screening of job applicants legal?
It is not banned, but it is regulated in a growing number of places and it carries discrimination exposure under long-standing employment law regardless of any AI-specific statute. Automated ranking and automatic rejection attract the most obligations. Keeping a human decision on every rejection removes most of the risk.
Did the EU AI Act deadline for hiring AI change?
Yes. The Digital Omnibus on AI entered into force on 27 July 2026 and deferred stand-alone high-risk obligations β which include employment AI β from 2 August 2026 to 2 December 2027. Transparency duties, the AI literacy obligation and new prohibitions were not deferred.
Am I liable if the AI vendor’s tool discriminates?
Potentially yes. In most US regimes the employer is the regulated party, and the Workday litigation has allowed claims against a vendor on the basis that it acted as the employer’s agent β which pulls both in rather than shifting blame. Contractual indemnities are worth negotiating but do not remove your regulatory duties.
What can I safely automate in recruitment?
Scheduling, reminders, candidate FAQs, job description drafting, structured interview questions, and summarising notes you took yourself. Avoid ranking, automatic rejection, and video or voice analysis unless you have legal advice and audit evidence.
Do I need a bias audit?
In New York City, employers using automated employment decision tools must commission an independent bias audit and publish results. Elsewhere it may not be a named requirement but remains strong evidence if you are challenged. If you rank or score candidates anywhere, treat an audit as the cost of doing so.
Should I use an AI detector on candidate writing samples?
No. Detection is unreliable and flags non-native English writing at markedly higher rates, so you would be introducing national-origin exposure into your process to solve a problem better handled by a live task or a structured interview.
Sources
- US Equal Employment Opportunity Commission
- Gibson Dunn β EU AI Act Omnibus and the postponed high-risk deadlines
- Freshfields β key amendments in the final Digital Omnibus on AI
- Norton Rose Fulbright β bias-testing data and privilege in Mobley v. Workday
Legal position checked 21 August 2026. This area is moving quickly β EU dates changed in July 2026 and several US state regimes are still being written. Nothing here is legal advice; consult an employment lawyer in your jurisdiction before deploying screening tools.