← Blog AI & HR

AI in hiring: what applies since 2 August 2026, and what arrives in December 2027

Laptop with a candidate list and a printed CV on a bright desk

For two years, 2 August 2026 sat in every compliance calendar as the day the EU's high-risk rules for AI in employment would start to bite. A few days before the deadline, on 27 July 2026, Regulation (EU) 2026/1744 entered into force. Brussels calls it the Digital Omnibus on AI. It moves exactly those obligations to 2 December 2027.

Reading that as "nothing to do" misses two things. First, several duties and bans stayed on their original schedule and are in force now. Second, Switzerland has its own law, and it already sets conditions for automated decisions about people. This article sorts out what applies since August, what arrives at the end of 2027, and what an SME using AI anywhere in its hiring process settles in six steps.

What the postponement means

The AI Act classifies AI in employment as high risk: systems for recruitment and selection, for decisions on promotion and termination, for allocating tasks, and for monitoring and evaluating performance and behaviour. This category (Annex III) originally had a start date of 2 August 2026. The new date is 2 December 2027. AI built into regulated products as a safety component (Annex I) now has until 2 August 2028.

From December 2027, providers of such systems owe risk management, requirements on training and test data, technical documentation, logging, human oversight and accuracy. Deployers, meaning the company that uses the system, must use it according to the instructions, monitor it, assign trained people to oversee it, and inform the employees and candidates concerned.

The delay is above all a gift to the vendors. For a company running recruiting software with AI features, it is a deadline: 15 months to know what its own software does and whether the vendor will be ready by December 2027.

What applies since 2 August 2026

The transparency duties of Art. 50 AI Act stayed on the original timetable. Since 2 August 2026:

  • AI that interacts directly with people must be recognisable as AI. That covers the chatbot on the careers page, the assistant that walks candidates through the application form, and the automated first-round interview. The only exception is where it is obvious to a reasonably informed person anyway.
  • Anyone deploying emotion recognition or biometric categorisation must inform the people exposed to it. In an employment context this is largely moot, because the ban applies (next section).
  • AI-generated content must be labelled. Relevant for HR the moment job videos or images are produced with AI.

Then there are the prohibitions of Art. 5, in force since 2 February 2025. Two of them hit HR directly. Systems that infer the emotions of employees or candidates in the workplace are banned, except for medical or safety reasons. So is biometric categorisation that infers trade union membership, religion, political opinion or sexual orientation from a face or a voice. A video interview tool that reads "engagement" or "stress resilience" from facial expressions has been unlawful in the EU for a year and a half.

Which Swiss companies the AI Act reaches

The AI Act is EU law. It reaches Swiss companies in three situations: when they employ people in the EU and use AI in HR there, when they hire for roles in the EU and assess candidates in the EU with AI, or when the output of an AI system is used in the EU, for instance by a subsidiary that receives a shortlist produced in Zurich.

An SME hiring in Winterthur for Winterthur is outside its scope. It sits under Swiss law instead, and on automated decisions Swiss law is clearer than many assume.

What Swiss law requires today

Art. 21 of the Federal Act on Data Protection governs automated individual decisions. Where a system decides on its own, with no human involvement, and the decision has legal effects for the person or affects them significantly, the company must inform the person. The person can state their view and can ask for the decision to be reviewed by a human being. A rejection sent by software with no human check because a file scored below a threshold is exactly such a decision.

Art. 19 of the same Act requires candidates to be told, when their data is collected, what it will be used for. The use of AI in the process belongs in that notice.

Art. 328b of the Code of Obligations allows an employer to process only data that concerns the person's suitability for the job or is needed to perform the contract. A tool that infers personality traits from public profiles leaves that frame quickly.

The Gender Equality Act prohibits discrimination in hiring. Software trained on past hiring decisions inherits their patterns. The employer is liable for the outcome, whether a person or a model produced it.

And Swiss AI regulation itself? In February 2025 the Federal Council decided to ratify the Council of Europe's AI Convention and to adapt existing laws where needed, rather than write an AI act of its own. The Federal Office of Justice is due to present a consultation draft by the end of 2026. A law in force is several years away. The rules above apply in the meantime.

Six steps for an SME

1. Inventory. List every tool that contains AI features in hiring, appraisal or administration: the recruiting software with "matching", the chatbot on the careers page, the video interview tool, the assistant that drafts job ads and reference letters. Many of these features arrived by update inside software the company has used for years.

2. Classification. One question per tool: does it prepare, or does it decide? A draft job ad is preparation. A ranked list of applications is preparation as long as a person reads the list. An automatic rejection is a decision. Wherever a tool decides, Art. 21 applies.

3. Four questions to the vendor. What data was the model trained on, and was it tested for bias by gender, age and origin? Can the system explain why a file ranks high or low? Can a recruiter override any score, and is that logged? Where is the data processed, and is there a data processing agreement? A vendor who cannot answer these four questions in September 2026 will struggle in December 2027.

4. A notice for candidates. Two sentences in the application form are enough: that AI is used to prepare the process, and that every decision is taken by a person. The notice satisfies the information duty under Art. 19 and, for chatbots and interviews, the recognisability rule of Art. 50 AI Act.

5. A documented human-review rule. Write down who checks which AI output before an invitation or a rejection goes out. Half a page, and in a dispute it is worth more than any assurance from the vendor.

6. A timeline to December 2027. Companies with an EU footprint need, by then, a written answer from their vendor on high-risk conformity, a named person for oversight, and the information for the people affected. Companies without an EU footprint gain, with the same steps, order in an area that Swiss legislation will regulate in the coming years as well.

How we handle it at clever hr

We use AI in recruitment because it saves time, and we bill that time by the hour, with no placement commission. The division of labour is fixed: AI screens and sorts, a recruiter reads, talks to people and decides every invitation and every rejection. We recruit in your name and on your behalf as an outsourced HR function, and your candidate data never enters public AI tools. Our guide to recruitment without placement fees and our recruitment service describe what that looks like day to day.

If you would like to walk through the six steps for your own company, we can do it in an afternoon. Our AI advisory starts with the inventory and ends with a human-review rule you can sign. For a broader view of where AI helps in HR today, read AI in HR: what is changing for Swiss SMEs.

Conclusion

The EU has bought companies time, and it has not given the all-clear. Since 2 August 2026, AI that talks to candidates must be recognisable as AI. Since February 2025, emotion recognition at work has been banned. And in Switzerland, Art. 21 of the Data Protection Act requires information, a hearing and a human reviewer for every fully automated decision. Complete the inventory, the four questions and the human-review rule now, and December 2027 arrives with the work already done. Let's talk about it for 30 minutes: book an intro call.

Frequently asked questions

Does the EU AI Act apply to a Swiss SME?

It applies directly if your company employs people in the EU, hires for roles in the EU, or if the output of an AI system is used in the EU, for example through a subsidiary. Hiring in Switzerland with candidates in Switzerland falls under Swiss law, above all the Federal Act on Data Protection and the Code of Obligations.

Can I let AI pre-screen applications?

Yes, on two conditions. First, a person decides who is invited and who is turned down; the AI sorts. Second, you tell candidates that AI is used in the process. If the decision is fully automated instead, Art. 21 of the Swiss Data Protection Act requires that the candidate is informed, can state their view and can ask for a review by a person.

What changes on 2 December 2027?

From that date the EU high-risk obligations apply to AI systems used for recruitment, selection, promotion, termination, task allocation and performance monitoring: risk management, data governance, technical documentation, human oversight and transparency towards the people affected. Deployers must use the systems as instructed, monitor them and inform the people concerned.

What about chatbots and AI interviews on the careers page?

Since 2 August 2026, systems that interact directly with people must be recognisable as AI unless that is obvious anyway. A chatbot on the careers page or an automated first interview therefore needs a clear notice. Emotion recognition in interviews is prohibited in the workplace.

Does this sound like your situation?

Let us talk about your HR for 30 minutes, without obligation.

Book an intro call