Digital Omnibus deferral: what really changed for recruitment AI
The regulatory landscape for hiring technology shifted on 13 June 2024, when the EU Council approved the Digital Omnibus Regulation and pushed back the first enforcement date for high-risk AI systems under the EU AI Act. Recruitment artificial intelligence used in sourcing, screening and assessment remains explicitly listed as a high-risk category under Annex III section 4, which means these tools are still treated as sensitive systems in the employment context. For CHROs and staffing businesses that rely on RPO providers such as Korn Ferry, Randstad Sourceright, AMS or Cielo, the sixteen month delay changes the timetable but not the direction of travel.
Under the AI Act’s employment provisions, any automated system that materially shapes hiring decisions is considered high risk and must meet strict obligations on governance, technical documentation and continuous monitoring. The European Commission has been explicit that recruitment tools are listed in Annex III because they can affect fundamental rights, so organizations and employers cannot treat them like low impact HR software. Penalties for non-compliant high-risk systems can reach EUR 15 million or 3 percent of global annual turnover, which makes AI governance a board level risk rather than a back office compliance task.
The Digital Omnibus simply defers the date when these obligations bite for recruitment AI, moving the first high-risk deadline to late 2026, but it does not reclassify any system or relax the definition of high risk. RPO vendors that operate across several member states now face a longer but more complex runway, because national rules in the United States and Europe are moving on different clocks while still targeting the same underlying risk. For buyers, the delayed AI Act timetable is therefore a stress test of their ability to manage data, human oversight and legal exposure across multiple jurisdictions at once.
Patchwork timelines: EU deferral meets US state level enforcement
While Brussels extends the implementation window for high-risk hiring tools, US regulators are accelerating their own rules for automated decision making in recruitment. Illinois now requires employers and staffing agencies to disclose when artificial intelligence is used in video interviews under the Artificial Intelligence Video Interview Act, which has applied since 1 January 2020 and was strengthened by amendments in 2022. Colorado’s AI Act imposes duties on high-risk systems from 1 February 2026, and New Jersey has reinforced anti-discrimination standards for algorithmic recruitment tools through guidance and enforcement actions under its Law Against Discrimination. For RPO providers that run shared platforms for multiple organizations, the same AI system may be treated as a general purpose GPAI model in one jurisdiction and as a tightly regulated high-risk system in another.
This patchwork matters because leading RPO vendors increasingly deploy purpose-built general-purpose AI models for sourcing, matching and assessment inside client Applicant Tracking Systems, often wired through APIs and workflow automation tools. Integrating these artificial intelligence tools into legacy recruitment systems without breaking the pipeline already requires careful engineering, as shown in playbooks on wiring AI agents into an ATS for RPO programs. Layering AI Act obligations on top means that every system used in an employment context must support technical documentation, logging, human oversight controls and clear candidate facing explanations.
One global RPO provider, for example, has already changed its screening process by adding a documented human review step for every automated rejection in EU roles, logging the reviewer’s decision and rationale before a candidate is removed from the funnel. Senior HR leaders should therefore treat the deferral as a window to rationalize their AI tool portfolio, not as permission to add more opaque risk systems. Ask your RPO partner for a full inventory of AI tools, including which GPAI models they embed, what data they process and how human reviewers can override automated decisions. The organizations that use this period to align governance, monitoring and code of practice commitments across both EU member states and US states will be better positioned when high-risk obligations finally become enforceable.
What CHROs must demand from RPO partners before the new deadline
The most sophisticated buyers are already reframing AI Act readiness in recruitment as an operating model question rather than a legal footnote. They are asking how human oversight will work in practice when an AI system flags a candidate as high risk for role fit, and how meaningful human review will be documented in case fundamental rights claims arise later. They are also pressing vendors on fairness metrics, performance thresholds and the continuous monitoring of bias across different candidate segments and member states.
For RPO programs that rely on large staffing agencies and smaller staffing businesses, the priority now is to embed governance into everyday recruitment workflows instead of treating it as an annual audit. That means specifying who owns each system, how data are retained, which teams monitor model drift, and how quickly a problematic tool can be paused when monitoring surfaces a pattern that threatens fairness. It also means aligning AI risk management with other frameworks, such as internal codes of practice, sector specific rules for healthcare recruitment and external guidance on tackling fake candidates through a stronger verification layer, as analysed in work on rebuilding the verification layer in RPO.
CHROs should insist that every high-risk recruitment system used by their RPO partner comes with clear technical documentation, a documented code of practice and a plan for candidate communication that explains how artificial intelligence supports decision making. They should also require evidence that general purpose GPAI models are governed under the same principles, including explicit obligations for vendors and internal teams on monitoring, legal review and escalation. As a practical checklist, ask for: a current AI inventory, role-based accountability for each tool, bias and performance reports by country, a tested escalation path for incidents and a candidate notice template. The organizations that use this extra time to hard wire AI governance into their staffing strategies, from revenue cycle hiring in healthcare to volume contact center recruitment as discussed in analyses of how a revenue cycle specialist strengthens RPO in healthcare on RPO healthcare programs, will find that the real performance metric is not cost per hire but time to productivity.