Skip to main content

AI recruiting tools and the EU AI Act: what applies now, and what waits until December 2027

The hiring high-risk deadline moved to 2 December 2027 — but the emotion-recognition ban is already live. What four AI recruiting vendors actually disclose.

AgentsIndex's profile

Written by AgentsIndex

Editorial team7 min read

Most of what has been written about AI hiring tools and the EU AI Act is aimed at the wrong date, and skips the obligation that is already in force. This page fixes both, then does the thing no law-firm explainer does: names vendors and says what each one actually publishes.

The date that moved

On 27 July 2026, Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force and rewrote the AI Act's timetable. Its point (40) replaces the third paragraph of Article 113. The new point (c) reads:

"Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III"

Recruitment is squarely inside Annex III, at point 4(a): systems "intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates".

So the high-risk package for hiring tools — risk management (Art 9), data governance (Art 10), technical documentation (Art 11), logging (Art 12), transparency (Art 13), human oversight (Art 14), accuracy and cybersecurity (Art 15) — begins on 2 December 2027, not 2 August 2026.

Now the part most write-ups miss. Section 3 of Chapter III is where Article 26 lives, and Article 26 is the deployer's obligations — yours, as the employer. Assigning human oversight to people with "the necessary competence, training and authority" (Art 26(2)), keeping the logs, and informing workers' representatives and affected workers before you switch the system on (Art 26(7)). Section 3 is named in the deferral. All of it moves to December 2027 too.

That is worth stating plainly, because the pages ranking highest on this question say otherwise. HeyMilo's post on the delay tells readers that "the deployer obligations under Article 26 still apply." Read against the amended Article 113, they do not — not yet, and not for Annex III systems. And HeyMilo's older explainer, marked "Updated April 2026" and still live as of today, still tells employers that "Full enforcement of high-risk AI rules begins on August 2, 2026," and never mentions December 2027 at all. Two posts on one vendor's site, giving buyers two different answers.

What actually binds you today

The deferral bought you time on paperwork. It bought you nothing on the prohibition — and the prohibition is the expensive one.

Emotion recognition in hiring is already banned. The Omnibus rewrote Article 113's point (a) too, and kept Chapters I and II applying from 2 February 2025 — the only new carve-out is a set of freshly added bans on intimate-image and CSAM material, which start 2 December 2026. Article 5(1)(f) has therefore been in force for eighteen months: AI systems that infer emotions from a person's biometric data in the workplace are prohibited, outside narrow medical and safety exceptions. The Commission's guidelines on prohibited practices read "workplace" broadly enough to cover the hiring process, and treat inferences drawn from voice or gesture as squarely within scope (analysis). Breach of Article 5 carries the AI Act's top penalty band — up to €35 million or 7% of worldwide turnover, versus €15 million or 3% for high-risk failures (Art 99).

Article 50 transparency applies from 2 August 2026 and was not deferred: people must be told when they are interacting with an AI. The one concession is a new Article 111(4), which gives providers of systems generating synthetic content that were on the market before 2 August 2026 until 2 December 2026 to meet the Article 50(2) marking rules.

Article 4 AI literacy has applied since February 2025, and GDPR Article 22 — the right not to be subject to a solely automated decision with legal or similarly significant effects — was never part of this timetable at all.

The short version: the compliance file can wait until 2027. The ban, the disclosure duty and GDPR cannot.

The question to ask before any other

Does the tool score anything derived from how a candidate sounds or looks, rather than what they say?

Of the four recruiting tools we list, exactly one answers in public. HeyMilo states that "Candidates are scored based on a transcription of their responses" and that it "does not incorporate accents, facial expressions, race, gender, or other characteristics into scoring." That is the sentence an EU buyer needs, and it is the only one of its kind across the four.

Humanly runs "structured AI video, voice, and async interviews" and publishes no equivalent statement. Paradox's ethical AI page does not use the word emotion anywhere. Juicebox is candidate search and outreach rather than interview scoring, so the question mostly does not arise.

An absent statement is not evidence of a prohibited practice. It is evidence that you will have to get the answer in writing yourself, from a vendor who has not volunteered it — and that this is a live legal question today, not a 2027 one.

Who publishes an audit, and who publishes essays about audits

Independent bias auditLatest published resultEU AI Act position
JuiceboxWarden AI, monthly6 Aug 2026 — 34,596 profiles, 102 clear / 0 consider / 0 concernDashboard carries an EU AI Act report; trust centre cites ISO 42001 alignment
HeyMiloWarden AI, monthly9 Jul 2026 — 17,442 profiles, 100 clear / 0 / 0States classification analysis completed for standard configurations
ParadoxNone namedNone publishedNo mention of the EU AI Act
HumanlyNone publishedNone publishedNo mention of the EU AI Act

Juicebox and HeyMilo both use the same third-party assurance provider, Warden AI, and both publish live dashboards covering 15 protected categories plus a sex × race/ethnicity intersection, against NYC Local Law 144, the EU AI Act, Colorado and California FEHA. Juicebox's is the more current of the two.

Paradox says only that it "regularly conducts bias evaluations and reviews" of its AI systems. No auditor is named, no cadence given, no results published; the page does not contain the word "audit" at all. Humanly is the sharpest contrast in the set: it publishes a five-step AI Interview Bias Audit framework and a defensible hiring playbook, and discloses no independent audit of its own product, no certifications and no EU AI Act position.

One caveat that cuts against reading too much into a green dashboard. The Omnibus adds a route for providers and deployers to process special categories of personal data specifically "to ensure bias detection and correction" — and ends that provision with a flat sentence: "This paragraph does not create any obligation to conduct such bias detection and correction." Publishing an audit is a procurement signal and useful evidence for your own Article 9 file later. It is not compliance, and no vendor's audit discharges a duty that will land on you.

Data residency: one vendor answers the question

Juicebox states it outright: "Data hosted by our cloud providers is hosted by AWS in North Virginia, USA and GCP in Iowa, USA," alongside 20 named subprocessors — OpenAI and Anthropic among them — all US-based. That is the clearest disclosure of the four, and for a buyer who needs EU residency it is also clearly disqualifying. Both facts follow from the same sentence, which is the point of publishing it.

Paradox holds ISO 27001 and SOC 2 Type II and participates in the EU–US Data Privacy Framework and its UK and Swiss extensions, but states no hosting region. HeyMilo reports SOC 2 Type II, GDPR compliance, a commitment that customer data is never used to train models, and a DPO reporting to the board — but does not publish a region either. Humanly's privacy policy promises "appropriate safeguards" for transfers outside the EEA without saying where data goes; notably, the right to request human review of a solely automated decision is spelled out there only for South African users under POPIA.

Security is a high-risk obligation too

In June 2025, researchers Ian Carroll and Sam Curry logged into the administrator panel of McHire — McDonald's hiring platform, built by Paradox — using "123456" as both username and password. Combined with an insecure direct object reference, that gave access to the personal data of more than 64 million applicants, including names, contact details and interview transcripts. Disclosure was on 30 June 2025; the default credentials were disabled within about two hours and Paradox confirmed resolution the following day.

The remediation was fast, and Article 15's cybersecurity requirements do not bite until December 2027. GDPR Article 32 applied then and applies now. If Paradox is on your shortlist, the post-incident review is a reasonable thing to ask for, and its absence from the ethical AI and security pages is a reasonable thing to notice.

So which one

Screening EU candidates and you need defensible evidence today: HeyMilo. It is the only one of the four that pairs an explicit no-affect-scoring statement — the thing Article 5 actually turns on — with a public, independent, recurring bias audit. Two conditions: get data residency in writing, because it is not published, and do not take the compliance dates from its own explainers.

Sourcing rather than screening, and you want the audit trail: Juicebox. The most recent audit in the set, the most honest infrastructure disclosure, and the only one of the four to publish list pricing at all — a free tier and per-seat plans, with a discount for annual billing, where the other three are demo-gated. The all-US hosting rules it out if you need EU residency.

High-volume hourly hiring at ATS scale: Paradox. The strongest security certifications of the four and the weakest fairness disclosure, plus a breach in its recent history. Buyable, but ask for the bias evaluation and the McHire post-incident review as documents, not assurances.

Humanly publishes the most compliance content and the least about itself. If it wins on product, make disclosure a contract term rather than a hope.

Whichever you pick, the deployer obligations in December 2027 are yours and do not transfer. Four things worth putting in the contract now, while you still have leverage: a named hosting region; a written statement on whether any affect, tone or facial signal enters scoring; a commitment to an annual independent bias audit with results you may see; and an obligation to supply the Article 13 instructions-for-use you will need for your own file. If you want tooling to run that evidence on your side, Credo AI ships EU AI Act policy packs and audit-ready evidence recording, and Holistic AI offers built-in frameworks for the EU AI Act, ISO 42001 and NYC Local Law 144 with automated control mapping — both are governance platforms for the deployer's own file, not independent auditors of your vendor.

Share: