EU AI Act Compliance for Public-Sector HR: What the 2027 Delay Changes

The high-risk HR deadline slipped to December 2027, but two AI bans already apply to every employer and one 2027 duty falls on public bodies alone. A runway checklist.

Avatar photo
By Eliana Kovalenko Vardi, Director, Work & AI Experience Design, Gloat
Trulli

Most public-sector HR leaders read the July headline the same way: the high-risk deadline you spent a year bracing for, 2 August 2026, is gone. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the old date would have taken effect (Lewis Silkin; K&L Gates).

The stand-alone high-risk obligations under Article 6(2), which cover AI used in employment and worker management, now apply from 2 December 2027 (DLA Piper). Product-embedded high-risk systems under Annex I move to 2 August 2028 (Lewis Silkin).

Sixteen months of runway. Treat it as a reprieve and you will spend it doing nothing, then repeat the same August scramble in the winter of 2027. DLA Piper’s advice to employers is blunt: continue your compliance preparations in line with the existing deadline. Deferred is not cancelled.

There is also a sharper reason not to relax. Part of the regime never moved, and it already governs how your teams use AI on people.

What still applies to public-sector HR right now

The deferral touched the high-risk suite. It left the Article 5 prohibitions where they have sat since 2 February 2025 (AI Act implementation timeline). Two of those bans sit squarely in HR.

The first is emotion recognition in the workplace. If a vendor is selling you interview software that scores a candidate’s mood, engagement, or sincerity from face or voice, that is a prohibited practice today, delay or no delay. The second is social scoring. Ranking or profiling workers across unrelated contexts in ways that produce detrimental treatment is out.

Article 50 transparency duties for AI-generated content also stand, as do the obligations on general-purpose AI providers. The prohibitions carry the heaviest penalties in the Act: up to EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher (Article 99). Fines on national public authorities are left to each Member State to set under Article 99(8), and EU institutions face separate, lower caps enforced by the European Data Protection Supervisor (Article 100), so a public body’s direct exposure to that 7% figure varies by country rather than applying automatically. The point stands regardless of the number: an emotion-recognition tool in your hiring stack is a live problem, not a 2027 one.

The honest reframing: you did not get a holiday. You got time to prepare for December 2027, plus an obligation to fix anything already prohibited.

The duty that singles out government employers

Public-sector HR carries one duty that no private employer running the same software does.

When the high-risk rules attach in December 2027, most deployer duties fall on public and private employers alike. One does not. The Fundamental Rights Impact Assessment under Article 27 is required only of deployers that are bodies governed by public law, or private entities delivering public services, when they use an Annex III high-risk employment system. An ordinary private company deploying the exact same recruitment AI does not have to perform it. You do.

A FRIA is not a data-protection assessment reheated. Article 27 asks you to document the processes the system will run inside and its intended purpose, the period and frequency of use, the categories of people and groups likely to be affected, the specific risks of harm to them, the human-oversight measures you will apply, and the internal governance and complaint mechanisms you will use if a risk materializes. It has to be done before first use and its results notified to the market surveillance authority.

That is a real body of work, and it needs input from legal, HR, and whoever owns the AI system. Sixteen months is enough time. Six weeks is not.

A runway checklist for public-sector HR

EU AI Act HR compliance for the public sector comes down to preparation you can start today. Use the deferral as a build period and work through these moves in order.

1. Inventory where AI touches people decisions

List every place a model influences a candidate or an employee: CV filtering, candidate evaluation, task allocation, promotion and termination inputs, performance and behaviour monitoring. Annex III point 4 names these categories explicitly (Annex III). You cannot govern what you have not mapped, and keeping that map current as systems change is its own task, the kind a workforce Knowledge Graph is built to carry.

2. Classify which uses are high-risk

Not every HR tool is Annex III. Match each system on your inventory against point 4 and separate the high-risk uses from the routine ones. This decides what the December 2027 obligations actually cover.

3. Confirm you are the deployer and map your duties

Public-sector HR is a deployer, not a provider. The vendor handles conformity assessment, technical documentation, CE marking, and system registration. You own the deployer duties under Article 26: assigning trained human oversight, monitoring the system, and keeping the logs it generates for at least six months.

4. Start the FRIA now

It is your longest-lead item and your public-sector-specific one. Draft it against the six elements above while you have room to consult properly.

5. Stand up human oversight and worker notification

Article 26(7) requires an employer to inform workers’ representatives and affected workers before a high-risk system goes into use at the workplace. Article 26(11) and the right to explanation in Article 86 require you to inform individuals subject to decisions the system makes or assists. Plan the works-council conversation early; it does not compress well.

6. Prepare your EU-database registration

Under Article 49(3), a public-authority deployer must register its use of an Annex III high-risk system in the EU database before putting it into service. Know which systems this covers before the deadline, not after.

7. Act on the Article 5 bans that already apply

This one is not on the runway. Audit your stack for emotion recognition and social scoring and remove them now.

Governed AI is easier to prove than to promise

The Act rewards deployers who can show their work: who was informed, who oversaw the decision, what the logs say, why the system did what it did. That is an operational problem before it is a legal one. Governance you can demonstrate on demand beats a policy you wrote and filed. Gloat’s Governance Engine exists to make governed autonomy the default, with human oversight, explainability, and audit trails built into how agents act rather than bolted on after. You can see how that plays out across HR workflows in the agent use cases, and the Agentic HR Academy goes deeper on governance and bias auditing.

A deferred deadline is not a shorter to-do list. It is a longer one you now have time to finish.

The public bodies that use these sixteen months well will treat December 2027 as a formality. Want to see what governed HR AI looks like in practice?

Request a demo →

Related