Regulatory snapshot. The implementation timetable has changed during 2026. This guide reflects the European Commission’s position available on 10 August 2026 and links to the primary sources below.
When employment AI is high-risk
Annex III covers AI systems intended for certain employment and worker-management uses. Examples include placing targeted job advertisements, analysing or filtering applications, and evaluating candidates.
Start with intended use, not the label on the software.
Some Annex III systems may fall outside the high-risk classification in limited circumstances under Article 6(3). Profiling of natural persons remains high-risk. Classification should be documented and reviewed against the system’s actual intended purpose.
Provider and deployer are different roles.
The obligations depend on how an organisation participates in the system. A provider develops or places the system on the market under its name; a deployer uses it under its authority. An organisation can move between roles when it substantially modifies a system or changes its intended purpose.
Builds and demonstrates conformity.
Owns the quality-management system, technical documentation, conformity assessment, registration, and post-market responsibilities.
Uses, monitors, and oversees.
Follows the instructions for use, assigns capable human oversight, monitors operation, and meets applicable information duties.
The obligation set is a connected system.
For high-risk systems, compliance is not one disclosure or one document. The requirements connect design, data, operation, oversight, and evidence.
Risk management
Identify foreseeable risks, define controls, and keep the process active throughout the system lifecycle.
Data governance
Assess the relevance, representativeness, and quality of data used for the intended purpose.
Documentation & logs
Maintain technical documentation and automatic records that support traceability.
Transparency
Give deployers clear information about the system, its intended purpose, limits, and expected oversight.
Human oversight
Design and operate the system so an equipped person can understand, monitor, and intervene.
Accuracy & security
Set and maintain appropriate levels of accuracy, robustness, and cybersecurity.
The current implementation timeline
The original Act used a phased timetable. A political agreement announced in May 2026 moved the Annex III high-risk rules to December 2027. Teams should monitor the Commission’s implementation pages as the legal and standards work continues.
- 1 Aug 20241
The AI Act entered into force
The regulation began its phased application.
- 2 Aug 20262
Most provisions apply
This includes the Article 50 transparency rules for certain AI systems.
- 2 Dec 20273
Current high-risk implementation date
Following the 2026 political agreement on simplification, Annex III high-risk rules, including employment use cases, are scheduled for this date.
Questions to bring into the next review
What decision is the system actually influencing?
Which organisation is the provider, and which is the deployer?
Can a reviewer trace an output back to its inputs and criteria?
Who is equipped and authorised to exercise human oversight?
How are affected workers or candidates informed where required?
What changes would trigger a new classification or conformity review?
Read the primary sources
This guide is an orientation layer. Use the current official text and implementation guidance for legal analysis.