The Control Journal
Interview GuidanceAugust 24, 20269 min read

AI Hiring Rules in 2026: What You're Entitled to Know

The EU's high-risk recruitment rules moved to December 2027. Here is the disclosure candidates can actually expect from AI interviews as of August 2026.

CControl Editorial Team

If you read that 2 August 2026 was the day AI recruitment tools became tightly regulated in Europe, that reporting is now out of date. Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, and it moved the high-risk obligations for standalone Annex III systems, which include recruitment and employment AI, from 2 August 2026 to 2 December 2027 (White & Case analysis of Regulation (EU) 2026/1744; Lewis Silkin).

What did not move is narrower and more immediately useful to a candidate: the obligation to tell you that you are talking to an AI system, a standing prohibition on inferring your emotions in a workplace context, and a patchwork of US state and city notice laws that were already in force. This guide sets out what applies as of 24 August 2026, what it actually obliges an employer to tell you, and where the gap between a written rule and an enforced one is widest. It is a candidate-side reading of public law and regulator documents, not legal advice.

What moved and what stayed on 2 August 2026

The AI Act classifies AI used for recruitment, candidate filtering, and evaluation during selection as high-risk under Annex III. Chapter III of the Act is what turns that classification into obligations: risk management, data governance, human oversight, accuracy and logging duties, and instructions for deployers.

The Digital Omnibus deferred those Chapter III obligations. It did not defer everything scheduled for 2 August 2026. White & Case states the point plainly: "This deferral is limited to Chapter III and does not apply to other obligations relevant to high-risk AI systems (notably the transparency requirements)."

ProvisionSubjectApplication date
Article 5 prohibitionsEmotion inference at work, biometric categorisationIn force since 2 February 2025
Article 50 transparencyTelling people they are dealing with an AI system2 August 2026
Article 50 machine-readable markingLabelling synthetic audio, image, video, text2 December 2026 for systems already on the market before 2 August 2026
Chapter III, Annex III high-riskRecruitment and employment systems2 December 2027
Chapter III, Annex I high-riskAI embedded in regulated products2 August 2028

So the practical position in the EU right now is that a recruitment AI system is still legally classified as high-risk, but the operational duties that classification triggers are more than a year away.

The disclosure that does apply: Article 50

Article 50(1) of the AI Act requires that "providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system," with an exception where that fact is obvious to a reasonably informed person (Article 50 text).

For a candidate, this is the concrete change. An AI interviewer that speaks to you, asks follow-up questions, and adapts to your answers is an AI system interacting directly with a natural person. From 2 August 2026, in the EU, it is supposed to make that clear rather than let you assume a recruiter wrote the questions.

Article 50 also states that "deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system." If an employer runs either against your interview, the duty to tell you sits with the employer, not the vendor.

Two limits are worth naming. First, this is a design and deployment duty; the article does not create a request mechanism you can invoke, and it does not require the employer to explain how the system scored you. Second, the "obvious to a reasonably informed person" carve-out gives an employer room to argue that an interface labelled as an automated screening step needs no further notice.

Emotion inference in interviews is already prohibited in the EU

This one predates the 2026 debate entirely. Article 5(1)(f) prohibits "the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions," except for medical or safety reasons. Article 5(1)(g) separately prohibits biometric categorisation that deduces race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation. Both have applied since 2 February 2025 (Article 5 text).

Vendors that once marketed facial-expression or vocal-affect scoring have largely stopped describing it that way in the EU, and the prohibition is a plausible reason. Note the boundary carefully: the prohibition targets inferring emotional state. A system that transcribes what you said and scores the content against a rubric is doing something different, and is not caught by 5(1)(f).

One genuine uncertainty: whether a pre-employment interview sits inside "the areas of workplace" is not settled by the article's own text, and the Commission's guidance on prohibited practices is where that reading gets tested rather than in the Act itself. Treat a confident claim in either direction — from a vendor or from a critic — as an argument, not a finding.

The right to an explanation sits in an awkward gap

Article 86 gives "any affected person subject to a decision which is taken by the deployer on the basis of the output from a high-risk AI system listed in Annex III" a right to obtain a clear and meaningful explanation of the role the system played (Article 86 text). Its stated application date is 2 August 2026, and the Digital Omnibus deferral was framed as limited to Chapter III.

Read literally, that means the right to an explanation is live while the duties that would make an explanation possible — logging, documentation, human oversight — are not due until December 2027. Law firm commentary on the final omnibus text does not address Article 86's interaction with the deferral at all (Freshfields; Gibson Dunn). This suggests the practical answer will come from national market surveillance authorities rather than from the text. If you ask for an explanation in the EU today, expect the question of whether you are owed one to be genuinely contested.

The United States is a patchwork of notice rules

There is no federal AI hiring statute. What exists is a set of state and city laws with different triggers, and none of them turn on 2 August 2026.

JurisdictionWhat it requires of employersIn force
New York City, Local Law 144Annual bias audit of automated employment decision tools, published results, and notice to candidates before use5 July 2023
Illinois, Artificial Intelligence Video Interview ActNotice, explanation of how the AI works and what it evaluates, and consent before AI analysis of a video interview1 January 2020
MarylandWritten consent before facial recognition is used during an interview1 October 2020
Illinois, HB 3773Notice when AI is used to influence or facilitate employment decisions; discrimination via AI treated under the Human Rights Act1 January 2026
California, FEHA automated-decision regulationsApplies existing discrimination rules to automated decision systems, with record-keeping duties1 October 2025
Colorado, SB 26-189Advance notice before AI use in consequential decisions, and a plain-language explanation within 30 days of an adverse outcome1 January 2027

Two of these deserve a note. Illinois HB 3773 took effect on 1 January 2026, but the implementing notice rules from the Illinois Department of Human Rights have had an unsettled path — proposed, then withdrawn, then reworked — so the precise content of the required notice is still moving (Seyfarth Shaw on the withdrawal; Hinshaw & Culbertson on the 2026 regulations).

Colorado is the clearest example of the direction of travel. The original Colorado AI Act, SB 24-205, was repealed and replaced by SB 26-189, signed 14 May 2026 and effective 1 January 2027. The replacement dropped the duty of care and mandatory impact assessments and kept disclosure: advance notice, and after an adverse decision, an explanation of the AI's role and a route to human review (Seyfarth Shaw).

Written notice is not the same as enforced notice

The most useful public evidence on this comes from an audit of the best-established of these laws. On 2 December 2025, the New York State Comptroller published an audit of the Department of Consumer and Worker Protection's enforcement of Local Law 144, covering July 2023 through June 2025. Over those two years the agency received two AEDT complaints. When DCWP reviewed 32 companies' websites and posted bias audits it identified a single instance of non-compliance; the state auditors reviewed the same companies and identified at least 17 instances of potential non-compliance. The audit criticised the agency's reliance on complaint-driven enforcement (Office of the New York State Comptroller).

The reasonable inference for a candidate is not that these laws are meaningless. It is that they function as duties on employers that are usually discovered when someone asks, complains, or sues — not as a notice that reliably arrives in your inbox. If you want to know what is being run against your interview, asking is still the mechanism that works.

What to ask before an AI-screened interview

Put the question in writing to the recruiter, before the session, so that the answer is on the record and any accommodation can be arranged in time.

  • Is any part of this stage conducted, scored, or ranked by an automated system?
  • If so, what is the tool's name and vendor?
  • What does it evaluate — the content of my answers, my voice, my face, my typing, my screen?
  • Is the output reviewed by a person before a decision is made, and can I request that review?
  • How long is my recording or transcript retained, and how do I request deletion?

The fifth question is where the answers get vague fastest, and it is the one with the longest tail: a scored interview recording can outlive the application by years. Our candidate checklist for AI interview assistant privacy works just as well in the other direction — the same data-flow questions apply to a tool the employer runs against you. If the stage also involves an ID check, the guide to interview identity verification covers what those checks capture and how long the documents are held.

If the format itself is unfamiliar — a conversational AI interviewer versus a fixed one-way recording — the practical preparation differs, and how to prepare for an AI interview covers the format check and rehearsal steps that matter more than the legal position.

Where this leaves candidate-side tools

The disclosure picture is asymmetric, and it is worth being honest about that rather than treating it as an argument. An employer's duty to tell you about its AI has no bearing on whether you are permitted to use your own during an assessment. That permission comes from the employer's stated rules for the specific interview, and breaking it is a hiring-process problem regardless of what any AI statute says. We have written separately on whether you can use AI during a technical interview, and the short version has not changed: read the rules for the stage you are in, and treat silence as a closed assessment rather than an invitation.

What has changed is the quality of the question you can ask. Knowing that Article 50 disclosure applies in the EU from 2 August 2026, that emotion inference at work has been prohibited since February 2025, and that Illinois, Maryland, New York City, and California already require some form of notice gives you a specific thing to ask for instead of a vague sense that something automated is happening.

What to watch next

Three dates matter for anyone tracking this. 2 December 2026 is when machine-readable marking of synthetic content applies to systems that were already on the market before August. 1 January 2027 is when Colorado's replacement law takes effect. 2 December 2027 is when the EU's high-risk obligations for recruitment AI — human oversight, documentation, and the machinery behind a meaningful explanation — finally apply.

Until then, the honest summary is that candidates in 2026 have a right to be told an AI is in the room, a prohibition protecting them from emotion scoring in the EU, a scattering of US notice laws with thin enforcement, and no reliable right to know why a system rejected them. Asking early and in writing remains the highest-yield thing you can do.

Continue exploring