EU AI Act: What Employers Need to Know

Last reviewed: July 2026

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive AI law. It uses a risk-based approach with phased enforcement through 2027. If you use AI hiring tools and evaluate EU candidates, this applies to you — regardless of where your company is located.

The 4 Risk Tiers

1. Prohibited AI (Banned)

Social scoring, emotion recognition in workplaces, manipulative AI, biometric categorization by sensitive attributes.

Penalty: Up to €35M or 7% of global revenue

Enforcement since February 2, 2025

2. High-Risk AI (Strict Requirements)

AI used in employment, hiring, promotion, credit scoring, education, healthcare, biometric identification, critical infrastructure.

Requires: Risk management, data governance, technical documentation, record-keeping, transparency, human oversight, conformity assessment, CE marking

Enforcement: December 2, 2027

3. Limited Risk (Transparency Only)

Chatbots, deepfakes, emotion recognition (non-workplace). Users must be informed they are interacting with AI.

Requires: Transparency obligations under Article 50

Enforcement: August 2, 2026

4. Minimal Risk (No Requirements)

AI games, spam filters, content recommendations. No specific obligations under the Act.

Phased Enforcement Timeline

February 2, 2025

Prohibited AI ban in effect

August 2, 2026

Article 50 transparency obligations take effect

December 2, 2027

Annex III high-risk AI obligations take effect (includes hiring tools)

What High-Risk AI Requires

If your AI hiring tool is classified as high-risk (Annex III), you must comply with these 8 requirements before deployment:

  1. Risk management system — Document risks throughout the AI lifecycle
  2. Data governance — Training data quality, bias mitigation, representativeness
  3. Technical documentation — System design, training data, model architecture
  4. Record-keeping — Logs of all AI decisions for audit trails
  5. Transparency — User information about AI use and capabilities
  6. Human oversight — Human-in-the-loop with ability to override
  7. Accuracy, robustness, cybersecurity — Technical standards and testing
  8. Conformity assessment — Third-party or self-assessment + CE marking

Source: EU AI Act Articles 8–17; Annex III

Does It Apply to US Companies?

Yes. The EU AI Act has extraterritorial reach, similar to GDPR. If your AI system is deployed in the EU market or its outputs affect EU citizens, the Act applies. A US company using AI to screen candidates for a London office is covered.

Penalty Structure

Violation TypeMax Penalty
Prohibited AI€35M or 7% of global revenue
High-risk non-compliance€15M or 3% of global revenue
Documentation failure€7.5M or 1.5% of global revenue
Incorrect information to authorities€7.5M or 1% of global revenue

Source: EU AI Act Article 99. The higher of the fixed amount or percentage applies.

Sources: EU Regulation 2024/1689 (EU AI Act); EU AI Act Articles 8–17, 50, 99; Annex III.

Disclaimer: This guide provides general information, not legal advice.

Get EU AI Act Compliance Updates

Monthly email with EU AI Act enforcement milestones, new guidance, and deadline reminders. Free, no spam.

Free. No spam. Unsubscribe anytime. We never share your email.