Article 50 of the EU AI Act takes effect August 2, requiring employers using AI systems for hiring, performance reviews or workforce monitoring to disclose when candidates and employees are interacting with AI and to label AI-generated content, according to an analysis published July 31 by law firm Ogletree Deakins. Employers relying on third-party AI vendors for employment purposes must follow the vendor’s instructions for use, which vendors are legally obligated to provide under the regulation.
TL;DR: The EU AI Act’s August 2 disclosure requirement applies immediately to HR teams using AI in hiring or performance management, while separate high-risk employment AI provisions arrive December 2, 2027.
The August 2 deadline covers transparency and labeling obligations. A broader set of high-risk provisions specifically targeting employment-related AI—including applicant tracking systems, candidate evaluation tools and performance monitoring software—has been pushed to December 2, 2027 under the EU’s Digital Omnibus package, the Ogletree Deakins analysis shows.
Compliance Gaps Across HR AI Deployments
Global data released ahead of the deadline shows most companies have not established AI governance frameworks. The Thomson Reuters Foundation and UNESCO’s AI Company Data Initiative, which analyzed disclosures from nearly 3,000 companies across 11 sectors, found only 13% of companies publicly commit to any AI governance framework. Among companies that do cite a framework, 53% reference the EU AI Act even when operating outside the EU, making it the default global standard.

Workforce-specific numbers are lower. Just 31% of companies show evidence of AI training or reskilling programs, and only 12% of those describe structured training available organization-wide, the study found. Fourteen percent have policies to protect workers from negative AI effects. About 2% report an internal complaints channel for AI-related concerns. Among companies using AI in HR specifically, only 7.4% consult diversity and inclusion staff on those projects.
Ogletree Deakins identifies “high-risk” employment systems as AI used to place targeted job advertisements, filter applications, evaluate candidates, make decisions affecting employment terms, promotions, terminations and task allocation, and monitor or evaluate worker performance or behavior. That scope covers much of the recruitment technology already deployed in applicant tracking and screening workflows.
AI Literacy Requirement Already Passed Deadline
The compliance framing misses the underlying capability gap, according to Michael Burch, vice president of AI enablement and acceleration at security training platform Security Journey. The EU AI Act’s AI literacy requirement took effect in February 2025, meaning organizations should already have training and literacy measures in place.
“Access to AI is not the same as capability with it,” Burch said in a statement. “Giving someone an AI tool without training is like handing them the keys to a motorcycle. It’s powerful, useful and potentially dangerous if not used in the right way. Organizations have spent 18 months distributing the keys without teaching anyone how to ride.”
Burch described a pattern he has observed directly: “I’ve watched experienced teams stunned by how easily an AI-generated workflow can execute malicious code on their machine, simply because they have never been trained to check.” He calls this a “failure of literacy” and the gap the EU AI Act is attempting to close through its mandatory training provisions.
HR teams using AI-powered applicant tracking systems or automated resume parsing tools face the immediate August 2 disclosure requirement if they operate in the EU or process EU applicants. The requirement applies regardless of whether the AI system is hosted internally or provided by a third-party vendor. Vendors must supply instructions for use, and employers must follow them.
What Happens Next
The August 2 disclosure deadline creates an immediate compliance checkpoint for HR teams using AI in hiring or workforce management. Organizations that have not yet implemented transparency measures—clear disclosure when AI is screening applications, evaluating candidates or monitoring performance—now face regulatory exposure. The December 2027 high-risk provisions will add additional requirements around human oversight, data quality and bias testing for employment AI systems.
The Thomson Reuters/UNESCO data suggests most organizations have not yet built the governance infrastructure or training programs required to meet either deadline. HR teams should audit their current recruitment technology stack to identify which tools fall under the regulation’s employment-AI provisions, confirm whether vendors have provided required instructions for use, and establish disclosure protocols before August 2.
For organizations that missed the February 2025 AI literacy deadline, implementing structured training programs now becomes both a compliance requirement and a practical risk-mitigation step. Governance and data quality barriers continue to block HR tech scaling more than technical capability gaps, making the literacy and oversight requirements central to effective AI deployment in hiring workflows.










