If you run talent acquisition and you read a headline in June saying the EU had delayed its AI rules for hiring, you read something true. What most coverage left out is which rules moved and which did not — and the ones that did not move include the single obligation most likely to touch an AI interview: the duty to tell a candidate they are talking to a machine.
That duty is Article 50 of the EU AI Act. It applies from 2 August 2026. That is less than two weeks from the date of this piece.
This explainer is written for a Head of Talent Acquisition or CHRO in Hong Kong or the wider APAC region who has filed "EU AI Act" under 2027 and moved on. The filing is half right. Here is the other half.
What the Digital Omnibus actually did
The European Commission proposed a package of amendments to the AI Act — the "Digital Omnibus on AI" — and it has now completed the legislative process. The European Parliament adopted the final text on 16 June 2026, the Council gave final approval on 29 June 2026, and the act was signed on 8 July 2026 (Council of the EU press release; Freshfields).
What it changed, in the part that concerns hiring:
- High-risk obligations for stand-alone Annex III systems — which is where recruitment and employment sit — moved from 2 August 2026 to 2 December 2027. High-risk AI embedded in products already regulated under EU safety law moved to 2 August 2028 (Gibson Dunn).
- The Commission's originally proposed "conditional trigger" — where the delay would depend on technical standards being ready — was dropped in favour of these fixed dates (Gibson Dunn).
That is the delay everyone reported, and it is a real and significant one. A recruitment-screening system classified as high-risk gets sixteen extra months before the conformity assessment, risk management, logging, human oversight and deployer-side obligations bite.
Article 50 was not part of that delay. Its transparency obligations still apply from 2 August 2026 (Sidley).
There is one narrow exception, and it is worth stating precisely because it is the sort of detail that gets over-generalised into "Article 50 was delayed too." The Omnibus gave a grace period to the machine-readable marking obligation in Article 50(2) — the watermarking of AI-generated audio, image, video and text — for systems already placed on the market before 2 August 2026. Those have until 2 December 2026. Commentators describe this variously as a three-month or a four-month grace period; the operative date they all land on is 2 December 2026 (Gibson Dunn; Freshfields).
The AI-interaction disclosure in Article 50(1) got no such grace period.
What Article 50(1) says
The operative sentence is short enough to read in full:
"Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use."
(Article 50(1) continues with a carve-out for AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences. It has no application to hiring, and we have not reproduced it.)
— Article 50(1), AI Act (European Commission AI Act Service Desk)
And Article 50(5), which governs how the disclosure is made:
"The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements."
Three things follow that matter operationally.
First, this is not a high-risk rule. Article 50 applies to the listed situations regardless of whether the system is classified high-risk. A candidate-facing AI interviewer is squarely an "AI system intended to interact directly with natural persons." The Annex III delay does not reach it.
Second, the disclosure has to arrive at first contact. Not in a privacy policy. Not in terms accepted at account creation three weeks earlier. "At the latest at the time of the first interaction," in a "clear and distinguishable manner."
Third, the "obvious" exception is, on our reading, narrower than it feels. The test is what a reasonably well-informed, observant and circumspect person would take from the circumstances — and a synthetic video avatar that looks and sounds like a person is, by design, working against obviousness. The Commission's draft Article 50 guidelines point the same way, though they are interpretive rather than binding (see below). This is a reading rather than settled law, and it is the reading we would rather be wrong about cheaply: anyone planning to rely on the exception should document why, in advance, rather than argue it afterwards.
Who actually carries the obligation
This is where the vendor/customer split matters, and where a lot of marketing in this category is sloppy.
Article 50(1) binds the provider — the party that develops the AI system and places it on the market under its own name. For an AI-interview product, that is the vendor. It is a design obligation: build the system so the disclosure happens.
Article 50(4) binds the deployer for deepfakes, and Article 50(3) binds deployers of emotion-recognition and biometric-categorisation systems (Sidley). If your screening stack infers emotional state from a candidate's face or voice, look hard at 50(3) — and note that emotion recognition in the workplace is separately restricted elsewhere in the Act.
Practically: in the ordinary case — an employer licensing a vendor's interview product and running it as supplied — Article 50(1) is not the employer's obligation, so there is nothing for the employer to buy its way out of. One qualification worth knowing: "provider" turns on who places the system on the market under its own name or trademark (Article 3(3)). An employer that white-labels an AI interviewer as its own product, or builds its own on top of a supplier's model, can find itself holding the provider obligation directly. (The Act's explicit deeming rule in Article 25, which converts a deployer into a provider on substantial modification, is written for high-risk systems and does not by its terms govern the Article 50 analysis — a distinction often blurred in vendor marketing.) Either way, an employer absolutely can inherit the consequence of a vendor that ignored it — a screening round that cannot be defended, and candidates who found out after the fact. The right question to a vendor is not "are you compliant?" It is "show me the disclosure, at first interaction, in the candidate's language, and show me it cannot be switched off."
Does any of this reach a Hong Kong employer?
Possibly, and this is the part worth checking with counsel rather than assuming.
Article 2(1)(c) extends the AI Act to providers and deployers established in a third country "where the output produced by the AI system is used in the Union" (Article 2, AI Act). It is the Act's broadest jurisdictional hook. An HK-headquartered employer running AI screening on candidates located in the EU, or hiring into an EU entity, has a real question to answer. An HK employer hiring only within HK, for HK roles, with no EU candidates and no EU entity in the group, has a much weaker connecting factor — but that is a conclusion to reach on your own facts with your own adviser, not one to take from a vendor's blog.
We are not going to pretend that line is crisp, and nothing in this section should be treated as a determination that the Act does or does not reach you. The scope of "output used in the Union" is one of the genuinely contested questions under the Act and reasonable advisers disagree. What we will say is that the exposure is not trivial: breaches of Article 50 sit in the tier carrying administrative fines up to EUR 15,000,000 or 3% of total worldwide annual turnover, whichever is higher (Article 99, AI Act). For SMEs and start-ups the calculation inverts to the lower of the two figures, which is a meaningful proportionality protection for smaller employers.
To be explicit about what those numbers are and are not: they are the ceiling if you are within scope. They are not a reason to assume you are. If the territorial analysis above puts you outside the Act, the fine tier is simply irrelevant to you, and we would rather say so than let a large number do persuasive work the law does not support.
The AI-literacy obligation, which nobody delayed either
Article 4 requires providers and deployers to take measures on AI literacy for staff dealing with AI systems. It has applied since 2 February 2025 — it is not new and it was never part of the August 2026 tranche.
The Omnibus did soften it. The Commission originally proposed removing the duty from providers and deployers entirely; Parliament pushed back, and the landing point is a duty to support the improvement of AI literacy rather than to ensure a sufficient level of it (Gibson Dunn). An obligation of effort rather than result.
For a TA function this is less onerous than it sounds and more useful than it looks. It means the recruiters operating your screening tool should be able to explain what the score represents, what it does not, and where a human decision enters. That is the same capability you need to survive a candidate complaint, so the compliance work and the operational work are the same work.
What is still unsettled — stated plainly
We would rather flag the soft ground than paper over it.
- Official Journal publication. As at the date of this piece, the Omnibus had been signed on 8 July 2026 and was awaiting publication in the Official Journal; it enters into force on the third day after publication. Until then, the unamended AI Act is the operative text. Verify current status before relying on the amended dates.
- The Commission's Article 50 guidelines are non-binding. The Commission published draft guidelines on 8 May 2026 with consultation closing 3 June 2026 (European Commission). They are interpretive, not law, and a national authority is not bound by them.
- The Code of Practice on Transparency of AI-Generated Content is voluntary. The Commission published the final Code on 10 June 2026 and it is undergoing an adequacy assessment by the Commission and the AI Board (European Commission). It is primarily aimed at the Article 50(2) marking obligation rather than at 50(1) interaction disclosure.
- Member State enforcement is uneven. The Act is a Regulation, but designation and resourcing of national market surveillance authorities has not moved at the same pace everywhere.
And the obligation that does not depend on the EU at all
For an HK employer, the nearer-term instrument is the Personal Data (Privacy) Ordinance and the Privacy Commissioner's guidance. The PCPD's Artificial Intelligence: Model Personal Data Protection Framework (PCPD, June 2024) is voluntary, but voluntary guidance from a regulator is the benchmark that regulator will measure you against. The PCPD is also actively looking: it announced on 19 May 2026 that it had completed compliance checks on 60 organisations regarding the impact of AI use on personal data privacy (PCPD).
Telling a candidate they are being interviewed by an AI is good practice under the PDPO's transparency and collection principles whether or not any EU rule reaches you.
A short practical list
- Inventory every candidate-facing AI touchpoint — screening interview, chatbot, scheduling assistant, automated messaging.
- For each, establish who is the provider and who is the deployer. Write it down.
- Check the disclosure exists at first interaction, is clear and distinguishable, and is translated into every language the candidate flow supports.
- Ask each vendor, in writing, whether their disclosure can be disabled or overridden by a customer — and what happens if it is.
- Check separately for any emotion-inference or biometric-categorisation feature. Different paragraph, different obligations.
- Run the Article 2(1)(c) territorial question with counsel. Once.
- Keep the Annex III work on the calendar for 2 December 2027. It was delayed, not cancelled, and sixteen months is not long for a conformity assessment.
Where NiceHire stands
We read our own code before writing this, and the first read was more mixed than we would have liked. We are publishing what that read found — the gaps included — because a piece about disclosure duties that soft-pedals its own author's disclosure record is worth less than nothing.
What the first read found. NiceHire's AI screening opens with a scripted greeting, and three of our default greeting paths identified the interviewer as an AI: the video interview default, the English-language phone interview, and the quick-evaluation video flow. Four paths, though, shipped with no disclosure at all:
- The Japanese-language phone screening greeting did not mention AI. The English one did. A disclosure that exists in one language and not another is not a disclosure — and Article 50(5)'s "clear and distinguishable" test is applied in the language the candidate is actually addressed in.
- The reconnect greeting — what a candidate hears when a dropped interview resumes — omitted it.
- Three of the five greeting presets we shipped in our own template editor omitted it. A customer could defeat the disclosure without writing a word, just by picking from our menu.
- Our own AI template generator produced a greeting with no disclosure. Because a template greeting replaced the default rather than adding to it, generating a template silently removed the disclosure that would otherwise have been there.
That last one mattered most, because it was not a customer misconfiguring our product. It was our product removing its own disclosure.
What we changed before publishing this. The four gaps were never four bugs; they were one. The disclosure lived inside a fallback, so it was only present when nothing else was supplied — which meant the next preset, the next language, the next generated template was always free to drop it again. Fixing the instances without fixing that structure would have been cosmetic, so the fix is structural: every greeting-producing path now passes through a single control that checks whether the greeting identifies the speaker as an AI and, if it does not, prepends a one-sentence disclosure in the greeting's language. That covers English, Japanese, Traditional and Simplified Chinese; first attempts and reconnects; all five shipped presets; and the template generator. A customer or template greeting can change the wording and tone of the greeting; it cannot remove the disclosure. Each statement in this paragraph is recorded in our internal public-claims register with the implementing code and a test suite behind it, and was re-verified against the shipped code on the date of this piece.
On transcripts. Completed AI screening interviews record a transcript against the application, which is the raw material for showing a candidate or a regulator what was actually asked and answered. Two limits: the transcript is whatever the interview provider returns, so a session that ends without one is stored without one; and re-running a screening clears the previous attempt's transcript rather than versioning it.
We will also say what we are not claiming. We do not eliminate bias, we do not replace recruiters, and no vendor — us included — can make you compliant with a regime that requires an independent audit.
We also do not claim audit-readiness, which is the phrase our industry reaches for at exactly this point. Earning it would take three things: a disclosure on every path, a transcript that survives a re-run, and an immutable record of what the system was asked to evaluate. On today's code we have the first — that is what the fix above bought — the second only partially, and not the third: our screenings reference the interview template that was used, but that reference points at a live, editable row rather than a snapshot, so editing a template changes what the record says about interviews that already happened. Those are engineering tasks with owners, not a marketing line. When they land we will say so, and you will be able to check. The audit itself still has to be somebody else's signature.
How this was produced
This article was drafted with AI writing tools, then put through three checks before it reached you. Every legal claim was verified against primary sources and links to the regulation text, an official EU or Hong Kong government publication, or a named law firm's published analysis. It was then reviewed for legal risk, and separately fact-checked against our own source code: each product statement in "Where NiceHire stands" was traced to the specific files that implement it and recorded in our internal public-claims register, which is what a colleague or an auditor would use to check our work rather than take it on trust.
That process changed the piece — and then the product. An earlier draft claimed every screening session stores a transcript; the code says otherwise, and the paragraph above now says what the code says. An earlier draft also described our disclosure gap as something a customer could cause; the fact-check showed we shipped it ourselves, and the piece was corrected to say so. The same fact-check sent the four gaps to our product team as defects, the structural fix described above landed before publication, and the "what we changed" paragraph was then verified against the shipped code and its test suite rather than against the fix's description. Where sources disagree or a question is genuinely unsettled, we have said so in the text rather than pick the tidier answer.
This is not legal advice, and we are not lawyers. This is an explainer written by a hiring-software vendor with an obvious commercial interest in the subject — we sell AI interview software, and a piece about AI interview disclosure rules is not a neutral document. We have tried to mark the difference between what the legislation says, what is genuinely contested, and what is our own reading; where we have given a reading, we have labelled it as one. None of it is a determination about your organisation's obligations, and no part of it should be relied on in place of advice. Regulatory positions change and dates in this area have moved more than once; verify current status before acting. For your own exposure, instruct qualified counsel in the relevant jurisdiction.
Ready to transform your hiring?
See how NiceHire's AI-powered hiring platform works for your team.
Get Started