EU AI Act and HR: what the 2 December 2026 date actually means

Growee

7 days ago

A document approval workflow showing labor contracts and an approve or reject action menu

On 2 August 2026, the transparency rules in Article 50 of the EU AI Act became something a company can be fined for ignoring. The European Commission’s own FAQ is blunt about it: “Article 50 of the AI Act applies as from 2 August 2026. From that date onwards, providers and deployers of AI systems must comply with the transparency obligations laid down in that provision.”

Much of the coverage since then has pointed at a different date, 2 December 2026, as if that were the deadline HR teams should be working toward. It is not. Below is what each date actually covers, which parts land on your vendor and which land on you, and a short list of things worth doing before your next AI tool goes live.

This is not legal advice. It is a plain-language summary written by a software team, and every legal claim below links to a primary source. Review your own setup with your counsel before you rely on any of it.

The three dates people keep mixing up

2 August 2026 is the real one. It is the AI Act’s general date of application under Article 113, which states that the Regulation “shall apply from 2 August 2026.” Article 50 has applied in full since then, with one narrow exception.

2 December 2026 is that exception, and it is smaller than the headlines suggest. The Commission FAQ says it precisely:

A limited grace period is envisaged only for AI systems placed on the market before 2 August 2026 and only as regards the marking and detection obligation for AI-generated content (Article 50(2) of the AI Act). Providers of such systems must comply with those obligations only as from 2 December 2026.

The word “only” appears twice in that sentence, and it is doing all the work. The grace period covers systems that were already on the market before 2 August 2026, so anything shipped after that date has no runway whatsoever. And it covers one duty, the machine-readable marking and detection of AI-generated content, not the rest of Article 50. Law firm Cooley reads it the same way, noting that providers of existing generative systems “have until 2 December 2026 to comply” with that specific requirement.

2 December 2027 is a different regime entirely, and it is the one most HR teams should have in their calendar. AI used for “the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates” is listed in Annex III as high-risk, alongside AI used to decide on promotions, terminations, task allocation and performance monitoring. That triggers Chapter III duties, which are a different order of magnitude: risk management, data governance, human oversight, conformity assessment, registration. A separate amendment package, the Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026, pushed the compliance date for stand-alone Annex III systems to 2 December 2027, and the Commission’s own Article 113 page acknowledges the provision has been amended. Beyond that 2 December 2026 grace period, the Omnibus does not defer the Article 50 transparency obligations, which have applied since 2 August 2026.

Transparency now, high-risk later. The December date in the headlines is a footnote for legacy generative systems.

Who this actually hits inside an HR team

Three shapes of AI turn up in HR, and they land in different places legally.

Things a person talks to. Candidate FAQ bots on a careers page, screening chatbots, WhatsApp or SMS assistants that qualify applicants, internal helpdesk bots that answer employee questions about leave or payroll. This is the classic Article 50(1) case.

Things that write. AI-drafted job ads, outreach emails, rejection notes, interview summaries, policy text. This is where Article 50(2) marking and the deepfake rules in Article 50(4) come into view, depending on what is produced and where it ends up.

Things that read people. CV parsing and scoring, ranking, video interview analysis, anything that infers emotion or sorts people by biometric traits. This is where you cross into Annex III high-risk territory, and where the emotion recognition and biometric categorisation cases additionally pull in an Article 50(3) duty that sits on you directly.

If you use all three, you have three separate conversations to have, not one.

Provider versus deployer, in plain language

The Act splits duties between two roles defined in Article 3. A provider is the party that “develops an AI system… and places it on the market or puts the AI system into service under its own name or trademark.” A deployer is the party “using an AI system under its authority” outside personal, non-professional use.

If your HR team bought the tool rather than built it, you are typically the deployer and the vendor is the provider. That split matters, because Article 50 allocates its four core duties unevenly:

Article 50(1), on the provider. Providers must ensure AI systems “intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious.” The “you are chatting with a bot” notice is an engineering duty on the party that built the bot.

Article 50(2), on the provider. Providers of systems generating synthetic audio, image, video or text “shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.” Machine-readable marking is not something a buyer can bolt on afterward. This is the duty that gets the 2 December 2026 grace period for legacy systems.

Article 50(3), on the deployer. Deployers of an emotion recognition or biometric categorisation system “shall inform the natural persons exposed thereto of the operation of the system.” If a video interview product scores candidate affect, telling candidates is your job, not the vendor’s.

Article 50(4), on the deployer. Deployers of AI that generates or manipulates content constituting a deep fake “shall disclose that the content has been artificially generated or manipulated,” and the same article covers AI-generated text published to inform the public on matters of public interest. Read narrowly, that text limb is about public-interest publishing, which is not the ordinary description of a job ad or a candidate email. Whether your specific content falls inside it is a question for your counsel, not for a blog post.

Two things follow. First, the hardest engineering duties are your vendor’s, which means your leverage is in procurement rather than in your own backlog. Second, your own direct duties are narrower but real, and they bite exactly where HR reaches for emotion analysis or synthetic media. Article 50 also sits on top of the high-risk rules rather than replacing them, so a recruitment tool can owe both sets at once.

A checklist for a small HR team

Inventory first. List every tool in your HR stack that generates text, holds a conversation, or scores a person. Include the ones nobody bought centrally: the browser extension a recruiter uses to write outreach, the assistant inside your job board.

Then ask each vendor six questions.

  1. Was this system placed on the market before or after 2 August 2026, and does the 2 December 2026 grace period apply to any part of it?
  2. Where exactly does the product tell a person they are dealing with AI, and can we see the wording?
  3. Is AI-generated output marked in a machine-readable, detectable format, and by what method?
  4. Does the product label AI-authored content for us, the reviewers, and separately for the person receiving it? Those are two different questions and vendors often answer only the first.
  5. Does anything in the product perform emotion recognition or biometric categorisation? A yes creates a disclosure duty on us, so we need to know before it ships.
  6. Which parts of the product are Annex III high-risk, and what is your plan for 2 December 2027?

Then fix your own side. Decide in writing which AI outputs need a human signature before anyone outside the company sees them, default AI-authored outbound to draft rather than send, and keep the vendor answers on file. Documentation is what you will be asked for.

Fines, and the SME break that is easy to misread

Article 99(4) sets administrative fines for breaching operator obligations, including “transparency obligations for providers and deployers pursuant to Article 50”, of “up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.”

The same article softens that for smaller companies: “In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.” For a small company the cap flips from whichever is higher to whichever is lower. That is a genuine proportionality break, and it is still not a number anyone wants attached to a careers-page chatbot.

The Commission has also published guidelines on the transparency obligations alongside a code of practice on transparency of AI-generated content, which is the closest thing to an official implementation reference available today.

Where Growee sits, honestly

Growee has AI in it, so it is fair to say what that means rather than leave it implied. Ask AI is an internal assistant: an HR person who is already logged in asks a question and gets an answer from their own company data. Growee also ships AI employees, agents your own staff message in Slack or inside the app, which are internal in the same way. There is no candidate-facing chat widget anywhere in the product, which is a materially different situation from a screening bot on a careers page. Where Growee does generate content the default is draft first, with AI-drafted campaign messages saved as an editable draft, campaign auto-send off by default, campaigns drafted through the MCP integration landing the same way, and AI scores in hiring shown to the reviewer under an explicit AI label. What Growee does not have is a purpose-built Article 50 feature: no automatic “written by AI” notice on a campaign email or generated job posting for the external recipient, and no machine-readable watermark on generated text. The AI labels are aimed at the staff member reviewing the output, not at the person who eventually reads it. Worth knowing which of those two a vendor means when they say their tool labels AI content.

Common questions

Does the EU AI Act apply to HR software? Yes, in two separate ways. The Article 50 transparency rules apply to AI systems that interact with people or generate synthetic content, and they have applied since 2 August 2026. Separately, AI used for recruitment, selection, promotion, termination, task allocation and performance monitoring is listed in Annex III as high-risk, which brings much heavier Chapter III obligations on a later timeline.

What happens on 2 December 2026 under the EU AI Act? It is the end of a narrow grace period, not a general deadline. Per the European Commission it applies only to AI systems placed on the market before 2 August 2026, and only to the Article 50(2) duty to mark AI-generated output in a machine-readable, detectable format. Everything else in Article 50 applied from 2 August 2026, and systems placed on the market after that date get no grace period.

Is my HR team a provider or a deployer under the EU AI Act? If you bought the tool rather than built it, you are typically the deployer and your vendor is the provider. A provider develops an AI system and places it on the market under its own name. A deployer uses one under its own authority in a professional context. Fine-tuning, rebranding or substantially modifying a system and putting it out under your own name can change that analysis, which is a question for your counsel.

Do we have to tell candidates that a job description was written by AI? Article 50(4) requires deployers to disclose deepfakes and AI-generated text published to inform the public on matters of public interest. A job ad or a candidate email is not the ordinary description of public-interest text, so that limb usually does not bite. GDPR, national employment law and the Annex III high-risk rules can still apply, so confirm your position with your counsel.

What are the fines for breaking Article 50 transparency rules? Article 99(4) sets administrative fines of up to EUR 15,000,000 or, for an undertaking, up to 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs including startups, the same article caps the fine at whichever of those two figures is lower rather than higher.

Does the Digital Omnibus delay the EU AI Act for HR? It delays part of it. The Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026, moved the compliance date for stand-alone Annex III high-risk systems, which include recruitment and employment tools, to 2 December 2027. Apart from the 2 December 2026 grace period for the Article 50(2) marking duty on systems already on the market before 2 August 2026, it does not defer the Article 50 transparency obligations, which have applied since 2 August 2026.

What to do this month

If you only have an hour, spend it on the inventory and on question four. Most teams find two or three AI touchpoints nobody had written down, and most vendors answer clearly about labeling for the reviewer and vaguely about labeling for the recipient. Chase the vague answers first.

Explore more articles

Who is liable when the AI rejects a candidate?

Who is liable when the AI rejects a candidate?

Mobley v. Workday lets discrimination claims run against the software vendor as an agent of the employers who delegated screening to it. What that changes when you buy hiring software.

Growee

1 day ago

Growee at ATIC HR & Recruitment Conference 6.0: Our Takeaways

Growee at ATIC HR & Recruitment Conference 6.0: Our Takeaways

Growee attended the ATIC HR & Recruitment Conference 6.0 in Chișinău. Here's what we heard from HR professionals about AI adoption, automation appetite, and the trust gap, and what it means for how we're building Growee.

Liza Bazilevici
Liza Bazilevici

3 months ago

AI In Recruiting: How To Use It Without Losing The Human Touch

AI In Recruiting: How To Use It Without Losing The Human Touch

Optimize, organize, and take control of your operations with Growee, the all-in-one management solution designed to transform how you work.

Silvia Rad
Silvia Rad

9 months ago