On 2 August 2026, the new European AI legislation went live and the transparency obligation took effect: people must be informed when they are dealing with AI. The full high risk regime for business AI follows on 2 December 2027, but the GDPR is already your biggest legal risk today.
What does this mean for you?
In short: your tools and processes take on a high risk character within your operation unless you prepare them for the transparency requirements the law was created to enforce.
6 things you need to know now
We've briefly set out the main points of the new legislation for you below.
1. Any AI that screens or ranks people = high risk.
Every AI tool you currently use for your recruitment or purchasing process becomes high risk. Think of CV scanners, matching algorithms, screening tools, biometric identification and chatbots. The full high risk regime only applies from 2 December 2027, as it has been postponed by the Omnibus. The transparency obligation and the ban on emotion recognition however apply since 2 August 2026.
2. Say upfront that AI is involved
Candidates and clients must know that AI is being used in their assessment or screening. This obligation took effect on 2 August 2026. It applies to anyone who deploys chatbots or AI-generated content. This can be done with watermarks, icons or disclaimers. Our client Fayn has currently solved it this way.
3. A human decides. Always.
The starting point is that a human always has the final judgment and deliberately chooses how AI operates. Employees can always review, overrule or ignore an AI decision. The consequence of a decision made by AI is therefore legally traceable back to the party responsible for the tool. Fully automated rejections without human intervention are not permitted. This requirement applies once the high risk regime takes effect on 2 December 2027.
4. Emotion recognition in conversations is prohibited
Software that reads emotions during a conversation is simply no longer allowed. This ban has already been in force since 2 February 2025 and has been fineable since 2 August 2026, so it already applies now, not only from 2027.
5. Bias in your data will soon be your problem
Systems must be reliable, free of discriminatory bias and GDPR-compliant. If AI tools can modify your database, this is an additional risk in your process. Note: the GDPR is already your biggest legal risk today. The Dutch Data Protection Authority can already impose fines of up to €20 million or 4% of global turnover, since no fine can yet be imposed for the AI Regulation in the Netherlands.
6. You buy a tool, but you can't buy your way out of responsibility
If you use AI in your process, then you must be able to explain how decisions are made, including to clients, applicants and principals. That already applies under the GDPR, and from 2 December 2027 also formally under the AI Regulation.