EU publishes Digital Omnibus, delays AI Act high‑risk rules
The EU published Regulation (EU) 2026/1744 on 24 July 2026, postponing several AI Act high‑risk obligations including those for employment and recruitment AI.

The European Union has formally published Regulation (EU) 2026/1744 — the so‑called Digital Omnibus — in the Official Journal, postponing the application of multiple high‑risk obligations under the AI Act that directly affect employment, recruitment and workforce‑management systems.
Regulation (EU) 2026/1744 was published on 24 July 2026 and enters into force three days later. The text delays the application of several Annex III obligations that class employers' talent‑and‑workforce systems as high‑risk, and adjusts implementation timelines and conformity requirements that HR teams and people‑analytics vendors have been preparing to meet.
The Council of the European Union, which gave final political approval to the package on 29 June, framed the measure as an effort to simplify and streamline the AI Act's compliance pathway. In its June statement the Council said the changes were intended to recalibrate obligations and ease administrative burdens while preserving the Act's core risk‑management architecture.
For employers and HR‑technology suppliers the practical effect is immediate uncertainty about when particular compliance duties take effect. The regulation postpones key Annex III obligations — including those tied to mandatory conformity assessments, technical documentation and certain post‑market monitoring requirements — which vendors typically rely on to certify products used in recruitment, screening, candidate ranking and workforce management. That shifts the timetable for independent conformity testing, certification costs and for contractual clauses that allocate regulatory liability between buyers and suppliers.
HR teams that have been mapping vendor contracts, updating procurement specifications and funding new technical‑compliance projects will still need to maintain readiness, industry lawyers and compliance officers say. Vendors positioned to sell high‑risk HR systems must decide whether to continue rolling out features that trigger high‑risk classification or to delay launches until conformity pathways are clarified. Several people‑analytics firms that had started third‑party audits and documentation projects now face a choice about pausing expensive certification work or pressing ahead on the assumption that the underlying obligations will resume at a later, as‑yet unspecified date.
The Digital Omnibus follows months of debate between member states, industry groups and the European institutions about the pace of enforcement. EU Law Live flagged the Official Journal entry on 24 July, noting the regulatory text and its amendments to sectoral laws. The Council's June communication made clear the policy intention to streamline technical requirements, but left operational detail to the published regulation and subsequent guidance from EU bodies.
What the text does not set out is a clear, obligation‑by‑obligation schedule for employers and vendors. The published regulation postpones application in general terms but does not, in the Official Journal copy, provide a comprehensive calendar for when each delayed Annex III duty will resume, nor does it resolve whether existing conformity assessments completed before publication will be grandfathered for the same scope of HR use‑cases. The regulation also stops short of clarifying how national labour and equality enforcement bodies should treat systems already in active use that have been subject to bias or discrimination complaints.
The net effect for HR leaders is a breathing space that will not erase the need for compliance planning. Employers still face the long‑term prospect of robust documentation, transparency and auditing obligations for AI systems that affect hiring and workforce decisions; the Digital Omnibus has deferred the timetable but not the obligations themselves. Legal teams, procurement and people‑analytics leaders will now be watching guidance from the European Commission and the European Artificial Intelligence Office for implementation rules, while updating risk registers and vendor‑management frameworks to reflect the changed schedule and lingering enforcement risks.