Skip to the content.

Deployer Checklist

What your organization owes once you deploy an HR AI system that touches EU-based workers or candidates. This is the employer-side counterpart to the vendor intake.

Mapped to Article 26 of the EU AI Act, with hooks into GDPR and existing HR practice. Not legal advice. Pair with Legal, Privacy, Works Council liaison, and HRBP review.

Timing

High-risk obligations for HR systems under Annex III apply from 2 December 2027 instead of 2 August 2026, under the AI Omnibus simplification package. The Omnibus is now law: Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 (verified against the regulation text on EUR-Lex). December 2027 is a fixed calendar date, not a conditional one: the Commission’s original proposal would have tied the deadline to standards readiness, and the final agreement rejected that mechanism in favor of a fixed date, so don’t plan around further slippage. Embedded high-risk AI under Annex I (regulated products) gets a separate deferral, to 2 August 2028. Build the practice now. Vendors and customers are already asking for the evidence trail.

The deployer obligations, in plain English

1. Use the system per the instructions for use

Article 26(1). The deployer must use the high-risk system in accordance with the vendor’s instructions for use, and assign human oversight to people who have the competence, training, authority, and support to do it.

Action items:

2. Input data quality and control

Article 26(4). Where the deployer controls input data, the deployer must ensure input data is relevant and sufficiently representative for the intended purpose.

Action items:

3. Monitor operation and pause when needed

Article 26(5). The deployer must monitor the system’s operation based on the instructions for use, and, where a risk arises, inform the provider and pause the use of the system.

Action items:

4. Keep the logs

Article 26(6). The deployer must keep the logs generated by the system for at least six months, unless other Union or national law requires longer. GDPR retention rules often require longer.

Action items:

5. Inform workers and their representatives

Article 26(7). Before putting a high-risk system into service in the workplace, deployers that are employers must inform workers’ representatives and the affected workers that they will be subject to the system.

Action items:

6. Use system output responsibly under Article 22 GDPR

When the system contributes to a decision with legal or similarly significant effect on a person, GDPR Article 22 protections may apply on top of AI Act duties. This is not a future obligation tied to the AI Act’s Annex III clock. Article 22 has been enforceable since May 2018, and regulators are actively saying so: at a July 2026 Parliament conference, the EDPS and EDPB stated that the AI Act Omnibus’s delay to December 2027 creates no GDPR safe harbor. Separately, the EDPB’s 2026 Coordinated Enforcement Framework covers GDPR transparency obligations broadly (Articles 12 to 14) across roughly 25 national DPAs, not an AI-hiring-specific audit, but recruitment and AI hiring notices are among the areas likely to draw scrutiny.

Action items:

7. Run a DPIA where required

GDPR Article 35 requires a DPIA when processing is likely to result in high risk. HR AI systems generally meet this threshold.

Action items:

8. Fundamental rights impact assessment (Article 27)

For certain deployers, including bodies governed by public law and private actors providing public services, a fundamental rights impact assessment is required before first use of a high-risk system.

Action items:

9. Cooperate with authorities and respect transparency duties

Article 26(11) and Article 26(12). Deployers must cooperate with competent authorities and follow the transparency rules in Article 50 for systems generating or manipulating content, deepfakes, or emotion recognition.

Action items:

10. Stop if the system causes serious incidents

Article 26(5) and Article 73 reporting obligations.

Action items:

Worker notice template (starting point)

Adapt per jurisdiction and consult Works Council liaison.

[Company] uses [system name] to support [decision stage, for example: first-pass screening of inbound applications]. The system [what it does, for example: scores applications against role requirements]. A [oversight role, for example: senior recruiter] reviews the system’s outputs and is responsible for the final decision. The system uses [data categories, for example: information from your application and résumé]. You can: request a human review, contest a decision, ask what data was used, and ask how the system reached its result. To exercise these rights, contact [named role and channel]. This notice is provided ahead of deployment on [date], in line with our obligations under the EU AI Act and GDPR. The system version is [version], dated [date].

Monthly monitoring template (starting point)

Metric Threshold This month Owner Action if breached
Override rate 5 to 15 percent   Oversight owner Investigate calibration
Disparity ratio (4 / 5ths rule, where applicable) 0.80 or higher   HRBP Pause and rerun fairness audit
Incident count 0   Oversight owner Postmortem and provider notification
Worker queries Track only   HR Ops Quarterly review
Model version Unchanged or noted change   Oversight owner Re-confirm IfU and intake card