September 16, 2026. AI is increasingly finding its way into recruiting. As a result, the European AI Act (AI Regulation) is becoming highly relevant for employers and recruiters. In the summer of 2026, the EU revised the rules once again.
Categories
September 16, 2026. AI is increasingly finding its way into recruiting. As a result, the European AI Act (AI Regulation) is becoming highly relevant for employers and recruiters. In the summer of 2026, the EU revised the rules once again.
Categories
Tags
Contact info
Silicon Saxony
Marketing, Kommunikation und Öffentlichkeitsarbeit
Manfred-von-Ardenne-Ring 20 F

Recruiters know: AI has long been capable of doing more than just drafting job postings. Systems can analyze applications, preselect candidates, and support hiring decisions. The rule is: The more an AI system influences decisions about people, the stricter the security requirements become.
And this is exactly where the European AI Act comes into play.
Among other things, it determines which applications will be classified as high-risk systems in the future—and which rules will apply to them.
This classification also affects certain tools in the areas of recruiting and human resources management.
For companies, this means, among other things, that they will need to examine even more closely in the future which AI they use, how it works, and which legal requirements apply to it.
Of course, not every AI tool used in human resources is automatically a high-risk system.
However, the AI Act explicitly mentions certain applications in the employment context. These include, in particular, AI systems used for the selection or hiring of individuals—such as for the targeted placement of job postings, the analysis and filtering of applications, or the evaluation of candidates.
Systems that influence decisions regarding working conditions, promotions, or the termination of employment may also fall under this category.
The reasoning behind this is understandable: AI applications that can have a direct impact on a person’s personal circumstances, opportunities, and fundamental rights are considered particularly risky. Consequently, they are to be subject to even stricter regulation.
This classification by no means implies that such AI systems are prohibited.
However, it does entail additional requirements. Depending on a company’s role—such as a provider or operator of a system—the AI Act sets out different requirements for documentation, human oversight, monitoring, and handling the results of a high-risk system.
For companies that use AI in recruiting, this means that the Act makes it even more important to know which systems are in use and what they are used for.
Does that sound like more regulation at first? It does. But there’s also good news.
To put this in context: The AI Act already entered into force on August 1, 2024, but its provisions will be phased in gradually. The first regulations have been in effect since February 2025, with others taking effect in August 2025. As of August 2, 2026, a large portion of the regulation has been in effect—including the transparency requirements under Article 50 of the AI Act. Other requirements, particularly for certain high-risk AI systems, will follow later.
It adopted the AI Omnibus, an EU regulation amending the AI Act, which entered into force on July 27, 2026. The AI Omnibus is intended to take the capabilities of small and medium-sized enterprises into greater account.
Specifically, this means:
The risk is real. For certain violations related to high-risk AI or breaches of transparency obligations, the AI Act provides for a maximum fine of 15 million euros or 3 percent of global annual revenue.
For larger companies, the higher of the two amounts generally applies. With the current reform, however, the EU has also made adjustments in this area.
The AI Omnibus now explicitly takes into account so-called small mid-cap companies (SMCs). Simply put, these are companies that are already too large to meet the classic SME definition but still fall under the broader category of small and medium-sized enterprises.
For these companies, in the case of the violations just described, the fine amount is no longer based on the higher of the two values, but on the lower one.
Example: A small-mid-cap company generates 100 million euros in annual revenue worldwide. Three percent of that amounts to 3 million euros. Under the standard calculation, the higher value—that is, 15 million euros—would set the upper limit. Under the new small-mid-cap rule, however, the cap is 3 million euros.
That’s still a substantial sum. However, it represents the statutory maximum limit. The actual amount of a penalty depends on the circumstances of the specific violation.
We can put your mind at ease here: SMEs and startups were already given special consideration in the original AI Act.
For them, the lower threshold also applies to the maximum fine limits—and in fact, to an even greater extent than under the new Small-Mid-Cap regulation.
Example: Let’s take an SME with 10 million euros in global annual revenue. In the event of a corresponding violation, the options are 15 million euros or three percent of revenue, i.e., 300,000 euros. For the SME, the lower amount applies. In this example, the statutory upper limit would therefore be 300,000 euros instead of 15 million euros.
Even in the case of particularly serious violations of the ban on certain AI practices—for which fines of up to 35 million euros or 7 percent of global annual revenue are generally provided for—this principle of the lower value applies to SMEs.
Small and medium-sized business owners, in particular, should therefore not apply the frequently cited million-euro figures from the AI Act to their own companies without considering the context.
The latest amendments to the AI Act give small and medium-sized enterprises, in particular, additional time to prepare. At the same time, they demonstrate that the regulation is intended to take company size and economic capacity into account to a greater extent.
However, this does not mean that employers should ignore the issue of AI regulation until 2027. After all, the greatest risk associated with using AI isn’t necessarily a fine. Rather, there’s the risk of data breaches, incorrect decisions, legal disputes, angry customers or job applicants—and, above all, a loss of trust.
For example, when employees enter confidential company or customer information into an unauthorized AI tool. When personal data ends up where it doesn’t belong. When flawed AI-generated content or analyses are adopted without being reviewed. Or even when decisions are made using AI without establishing guidelines for its responsible use.
That’s why employers should use this extra time to take a structured approach to AI implementation within their own companies, train employees, and—above all—clearly define the following questions:
The AI Act provides an important regulatory framework for this. However, responsible AI use does not begin only when there is a legal obligation or the threat of a fine. It begins with clear rules, clear responsibilities, and a mindful approach to the technology.
After all, it’s not just about complying with the AI Act. It’s about harnessing the potential of AI without jeopardizing the trust of employees, job applicants, customers, and business partners.
This article is intended solely to provide general information about current legal developments. It does not constitute legal advice and cannot replace an individual legal review or consultation.
The content does not claim to be exhaustive. The legal requirements applicable to a specific company, a particular AI system, or an individual use case depend on the respective circumstances. For specific legal questions, expert legal advice should be sought.
Last updated: September 2026
– – – – –
👉 https://fivehunters.de
Photo: AI-generated with ChatGPT (OpenAI)
You need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from OpenStreetMap. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information