Signato signato.ai

Article 26(7): you have to tell workers before high-risk AI screens them

Edition 20. A reading time of about 4 minutes.

The hook

Most of the EU AI Act asks you to do things: run assessments, keep logs, hold a paper trail an auditor can follow. Article 26(7) asks you to say something. Before an employer puts a high-risk AI system to use in the workplace, it has to tell the affected workers and their representatives first. It is a single sentence in the Act, easy to read past, and it sits exactly where AI law meets employment law. It is also the kind of step that costs almost nothing to do on time and is awkward to explain after the fact, once the tool is already screening people.

What this means

The duty is in Article 26(7). The text reads: "Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system. This information shall be provided, where applicable, in accordance with the rules and procedures laid down in Union and national law and practice on information of workers and their representatives" (AI Act, Article 26(7)). Three parts of that sentence decide what it means for you.

The first is who it lands on. The Act calls the party that uses an AI system a "deployer", and Article 26(7) narrows that to "deployers who are employers". If you run the hiring, the duty is yours, not your vendor's. The company using the tool on its own candidates and staff is the one that owes the notice.

The second is when it bites: "before putting into service or using" the system. This is not an annual disclosure or a line in a policy nobody reads. It is a step that comes before go-live. The moment you switch a qualifying tool on for real candidates or workers is the moment the notice needed to have already happened.

The third is what "high-risk" covers here, because the duty only attaches to high-risk systems. For hiring, that is Annex III, point 4: AI used for recruitment or selection, in particular to place targeted job advertisements, to analyse and filter applications, and to evaluate candidates (AI Act, Annex III). An AI CV screener, a ranking or matching engine, an automated shortlisting tool: these are the systems in scope. A spell-checker in your careers page is not.

Two things this duty is, and is not. It is a duty to inform, addressed to the affected workers and their representatives. Where you have a works council or employee representatives, the notice runs through them, and the Act ties it to existing "Union and national law and practice on information of workers", so national rules on works councils and employee information layer on top rather than being replaced. It is not, on its own, a right of veto or a full consultation process. But national labour law in several Member States already requires consultation before introducing monitoring or automated tools, so in practice the AI Act notice often sits alongside a heavier local duty, not in place of it. Read the two together, not in isolation.

Now the timing, which is the part to get right today. Under the AI Act as published, obligations of deployers of high-risk systems sit in Chapter III and apply from the general application date. Article 113 states plainly, "It shall apply from 2 August 2026" (AI Act, Article 113). So on the law as written, this notice duty is a 2 August 2026 obligation. That date is now in motion. The Commission's Digital Omnibus package, which the Council gave its final green light on 29 June 2026, would defer the stand-alone Annex III high-risk obligations, this one included, to 2 December 2027. But as of this writing that package is not yet published in the EU Official Journal, and until it is, the original Act remains the binding law and the 2 August 2026 date formally stands. Publication is widely expected in July 2026. The honest read is: plan for the notice as a duty that could bind from 2 August 2026, and watch the Official Journal for the date to formally move to December 2027.

What to do with this

This is one of the cheaper obligations in the Act to get right, because it is a communication step, not an engineering one.

  1. List the high-risk AI you use or are about to use in hiring. Focus on tools that screen, rank, filter or evaluate candidates, and on anything used to manage or monitor workers. If a system does that, treat it as in scope for this notice.
  2. Build the notice into your rollout, before go-live. Make "inform workers and their representatives" a step that has to be ticked before a qualifying tool is turned on, the same way you would not launch a payroll change without telling staff. Retrofitting a notice after people have already been screened is the outcome to avoid.
  3. Route it through your existing worker-information channels. Where you have a works council or employee representatives, use them, and check what your national law already requires on informing or consulting workers before automated tools go live. The AI Act notice is a floor here, not a ceiling.
  4. Keep a short record. Note what you told people, who you told, and when. The point of the duty is that workers knew before the system was used on them, and a dated record is how you show that later.
  5. Track the date. Treat 2 August 2026 as the working deadline under the Act as published, and watch for the Digital Omnibus to appear in the Official Journal, which would move the stand-alone high-risk obligations to 2 December 2027. Do not let a still-provisional delay talk you out of a step that costs little to prepare now.

Read this way, Article 26(7) is less a compliance burden than a habit: tell your people before an AI system starts making decisions that affect them. The teams that will not scramble are the ones that fold the notice into how they launch tools, and keep a note that they did.


This is educational material and a starting point, not legal advice. The EU AI Act is still being amended, and the application date for the high-risk deployer obligations discussed here is among the provisions proposed for change under the Commission's Digital Omnibus package, which the Council approved on 29 June 2026 but which is not yet published in the Official Journal and not yet final law. Under the Act as published the obligation applies from 2 August 2026; the Omnibus would move the stand-alone high-risk obligations to 2 December 2027 once in force. How the rule applies also depends on your national labour law and on the specific facts. For your situation, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.

Not sure which of your hiring tools count as high-risk? Take the free AI Hiring Risk Self-Assessment to see where you stand, then see the same evidence-first discipline applied to what your AI sends out: the free local trial of the Signato chamber blocks a draft that pairs the wrong person with the wrong subject before it leaves, no card, nothing leaves your machine.

Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. Know someone rolling out AI in hiring in the EU? Forward this to them.


Sources (primary, read 2026-07-06):

- AI Act, Article 26 (Obligations of deployers of high-risk AI systems), Article 26(7): before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the system, in accordance with Union and national law and practice on information of workers. - AI Act, Article 113 (Entry into force and application): the Regulation shall apply from 2 August 2026 (general application date), with earlier dates for prohibitions (2 February 2025) and for governance and conformity-assessment provisions (2 August 2025). Article 26 sits in Chapter III and applies from the general date under the Act as published. - AI Act, Annex III (High-risk AI systems referred to in Article 6(2)), point 4: AI systems used in employment, workers management and access to self-employment, including for recruitment or selection, to analyse and filter applications and to evaluate candidates, are high-risk. - Digital Omnibus status (dates in motion, read 2026-07-06): the Council gave final approval on 29 June 2026 (Council of the EU press release, 29 June 2026); the package would defer stand-alone Annex III high-risk obligations to 2 December 2027 but is not yet published in the Official Journal, so the 2 August 2026 date formally stands until publication. Secondary corroboration: Gibson Dunn, DLA Piper. - Canonical text: Regulation (EU) 2024/1689, EUR-Lex CELEX:32024R1689.

Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.

Know someone who hires in the EU? Forward this to them.

AI hiring law, made operational. Free, weekly.

Plain-language, sourced intelligence for HR and legal teams. Start with the free Starter Kit.

No spam. Unsubscribe in one click. See our Privacy Policy.

Run a newsletter on Beehiiv? Add Signato to your recommendations in one click, and send your readers a clear, sourced read on AI compliance.

Add Signato to your recommendations →