AI in Practice Aug 05, 2026

EU AI Act Compliance: What Changes on 2 August 2026?

EU AI Act Compliance: What Changes on 2 August 2026?

AI in HR is moving from “interesting experimentation” to full legal accountability in the EU. The EU AI Act makes that shift concrete, and for many HR use cases the key date is 2 August 2026, when the strictest obligations start applying. If your company uses AI in hiring or workforce management, the practical goal is to be able to explain what you use, why you use it, and what controls exist around it, not just to say “the vendor is compliant”.

Why HR is under scrutiny under the EU AI Act

The EU AI Act classifies AI systems by risk, and HR sits high on the radar because HR systems can affect a person’s career, income, and privacy. This is why many tools that feel routine inside companies can still fall into the high-risk bucket once they influence recruitment, selection, promotion, termination, task allocation, or performance monitoring. A non-obvious point is that “high-risk” is often less about model sophistication and more about where the output lands in the decision chain. Even a simple ranking or scoring function can create significant obligations if it filters candidates or shapes decisions about employees.

From an operational perspective, most companies will not have a single “AI in HR” system. They will have a chain: ATS features, assessment vendors, analytics layers, and sometimes add-ons in broader platforms. Compliance problems typically appear in the gaps between those tools, when nobody can clearly answer which parts are automated, what data they use, and who is accountable for oversight.

What changes on 2 August 2026, and what already applies before

According to APČR, from 2 August 2026 the strictest rules start applying for the high-risk category, which includes common HR scenarios such as automated CV sorting, evaluation of video interviews, online candidate testing, and systems used for managing workers (promotion, termination, task assignment, performance monitoring). The practical implication is that companies should treat August 2026 as a deadline for having governance in place, not as a deadline for reading the regulation. If you wait, you will end up doing risk classification, vendor due diligence, internal documentation, and training at the same time, which usually produces weak evidence and rushed decisions.

APČR also highlights that some requirements are already effective from February 2025. One example is that workplace emotion recognition systems are described as strictly prohibited, so if anything in your stack resembles emotion detection, it is not a “nice to review later” issue, it is a stop-and-fix issue. APČR also calls out the obligation to ensure AI literacy for employees who work with these technologies, which is often underestimated because it requires consistent practice across HR, hiring managers, legal, and IT, not just a one-time training session. Finally, APČR notes that deployers may need to inform and consult employee representatives before putting a high-risk system into operation (referencing Article 26(11)), which means the rollout plan itself can create compliance risk if consultation happens after go-live.

What employers need to be able to guarantee in practice, and how to start

APČR summarizes four pillars that employers need to be able to guarantee when using high-risk AI tools: human oversight, transparency, audit and fairness, and documentation. Human oversight needs to be real, meaning the machine cannot make final decisions without human control, and oversight cannot be reduced to rubber-stamping outputs. Transparency means people must be clearly informed when AI is involved in a relevant step, and in HR that often involves candidates or employees, not only internal users who already know they clicked an AI feature. Audit and fairness requires regular checks to reduce the risk of unintended discrimination (APČR mentions age and gender as examples), and that is difficult to defend if you cannot reconstruct which model, configuration, and data produced a particular output at a given time. Documentation is the backbone that lets you prove safety and explain how results are produced, and it has to reflect your real deployment, not just generic vendor PDFs.

APČR recommends three practical first steps: audit your tools, verify suppliers, and invest in education. Done well, the audit is not only a list of “AI tools”, it is an inventory of where AI touches HR workflows, including features hidden inside platforms that are not marketed as AI products. Supplier verification should focus on evidence you can operationalize: clear statements of responsibility, access to technical documentation, and the ability to support your oversight, logging, and change-control needs. Education should be continuous and role-based, teaching people how to use outputs responsibly, where AI must not decide, and how to document overrides and exceptions, because those are the details that hold up when questions arrive later.

Enjoy this post? Join our newsletter
Don't forget to share it

The Enterprise AI Platform

Empower your company with AI chat, search, agents, workflows, and recordings, all in one secure platform.

ISO 27001 | GDPR | SSO | Encryption
AI Chat AI Search AI Agents Recordings Workflows Memory Tasks Skills Approvals
OpenAI Google Gemini Anthropic Claude Mistral Model agnostic | EU EU hosted

Related Articles

All posts