

AI Ethics in IT Consulting: Does the AI Act Delay Change the Target Recruitment Profile?
AI Ethics in IT Consulting: Does the AI Act Delay Change the Target Recruitment Profile?
AI Ethics in IT Consulting: Does the AI Act Delay Change the Target Recruitment Profile?
Share
For two years, artificial intelligence ethics has been treated in digital service companies as a matter of personal conviction, championed by volunteers, without a clear mandate or stable positioning. The European regulation on artificial intelligence was supposed to close this period on August 2, 2026, the date on which the obligations on high-risk systems came into effect.
That did not happen. A regulation published on July 24, 2026, eight days before the deadline, postponed these obligations by sixteen months. At the same time, other provisions of the text did enter into force on the scheduled date.
The result is an asymmetrical situation that many organizations misinterpret: part of the regulation applies today, while the other will apply at the end of 2027. Recruitment decisions made on an overall reading of the schedule are mechanically poorly calibrated.
Key Figures to Know
Element | Data |
|---|---|
Reference text | Regulation (EU) 2024/1689, known as the AI Act, entered into force on August 1, 2024 |
Amending text | Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, published in the OJEU on July 24, 2026, in force on July 27, 2026 |
Prohibitions and AI literacy | applicable since February 2, 2025, unchanged |
General-purpose AI models, governance, penalties | applicable since August 2, 2025, unchanged |
Transparency obligations under Article 50 | applicable since August 2, 2026, unchanged |
Machine-readable marking of generated content | tolerance until December 2, 2026, for pre-existing systems |
Annex III high-risk systems | postponed from August 2, 2026, to December 2, 2027 |
Annex I high-risk systems | postponed from August 2, 2027, to August 2, 2028 |
Maximum penalty, prohibited practices | 35 million euros or 7% of global turnover, unchanged |
Maximum penalty, other non-compliance | 15 million euros or 3% of global turnover |
Why This Topic Matters Now
Three events occurred in just a few weeks.
The postponement was adopted at the eleventh hour. The political agreement was reached in early May 2026, the Parliament approved it in June, and the text was published on July 24, eight days before the deadline it neutralized. Many organizations had based their planning on August 2.
The transparency obligations, however, did enter into force on August 2, 2026. Informing a person that they are interacting with an artificial intelligence system, flagging generated or manipulated content, marking the outputs of generative systems in a machine-readable format: these requirements apply today. Systems already deployed benefit from a grace period until December 2, 2026, for the marking.
Prior obligations remain in force. Prohibited practices and the obligation of artificial intelligence literacy have applied since February 2025. The sanctions regime has applied since August 2025. The postponement does not affect them.
The correct reading is therefore not "the AI Act is postponed." It is: the foundation applies, the most demanding layer arrives at the end of 2027.
Consolidated Calendar After the Postponement
Date | What Applies | Status |
|---|---|---|
February 2, 2025 | Prohibited practices, AI literacy obligation | In force |
August 2, 2025 | General-purpose models, governance, sanctions regime | In force |
August 2, 2026 | Article 50 transparency: interaction, generated content, marking | In force |
December 2, 2026 | End of the grace period for marking pre-existing systems | Upcoming |
December 2, 2027 | Annex III high-risk systems, including employment and worker management | Postponed by 16 months |
August 2, 2028 | High-risk systems embedded in regulated products, Annex I | Postponed by 12 months |
The postponement concerns the application dates, not the content of the obligations. What will be required at the end of 2027 is what was supposed to be required in August 2026.
What the Postponement Really Changes for Recruitment
Four effects, two of which pull in opposite directions.
Organizations that had an open position are freezing it. This is the immediate and most frequent reaction. A sixteen-month delay is enough to de-prioritize a recruitment in a budget trade-off.
Those that had a transparency obligation are just discovering it. Article 50 concerns conversational interfaces, content generation systems, and assistants integrated into delivered products. Many digital service companies operate them without having identified the obligation because they were waiting for a global deadline.
The market for talent is temporarily easing. The pressure on artificial intelligence compliance skills mechanically decreases when the deadline moves away. For an organization recruiting now, this is a window of opportunity. It will close at the end of 2027, with a predictable scarcity effect.
Preparation, however, cannot be postponed. Compiling technical documentation, tracing training datasets, and setting up logging and a quality management system takes more than sixteen months in an organization that produces systems in series. A company that waits until December 2027 to start will not be ready.
This is exactly the pattern observed with the sustainability reporting directive, which was also postponed by two years: the delay concerns publication, not the building process.
Provider or Deployer: The Question That Decides Everything
The regulation distinguishes several roles, and the obligations differ radically depending on the one occupied.
The provider develops an artificial intelligence system or places it on the market under its name. It carries the bulk of the obligations for high-risk systems: risk management, data governance, technical documentation, conformity assessment, marking, and registration.
The deployer uses a system under its own authority. Its obligations are real but lighter: use in accordance with the instructions, human oversight, monitoring, and informing the individuals concerned. Article 50 directly imposes transparency on them, which is applicable today.
For a digital service company, the difficulty is that the role varies from one project to another, sometimes within the same contract. Developing a component delivered under the client's brand, providing a solution under its own brand, or operating a system on behalf of a third party: these three situations do not entail the same responsibilities.
This qualification is not an auxiliary legal point. It determines the level of the position to be created and the profile to be recruited. An organization that is predominantly a deployer needs oversight capability. An organization acting as a provider for systems that will shift to high-risk at the end of 2027 needs a executive-level function, and it needs it now.
What High Risk Will Impose at the End of 2027
For a system classified as high-risk, the provider must be able to produce and keep up to date:
a risk management system covering the entire lifecycle,
governance of training, validation, and testing datasets,
comprehensive technical documentation,
automatic event logging to ensure traceability,
instructions for use allowing the deployer to understand and monitor the system,
human oversight arrangements,
a demonstrated level of accuracy, robustness, and cybersecurity,
a quality management system.
None of these elements are a matter of personal conviction. All require documentary proof, exactly like an industrial compliance file. This is the point that most analyses miss: the function sought is a compliance and quality function, not an awareness-raising function.
Systems used in employment and worker management are among the cases listed in Annex III. Candidate screening and employee evaluation tools are therefore directly affected by the December 2027 deadline.
The Four Core Competencies to Cover
Regulatory qualification. Determining, project by project, the company's role and the system's risk level. A legal and technical skill, the rarest on the market.
Documentary compliance. Producing and maintaining the required files. A profile coming from quality assurance, industrial compliance, or information systems auditing.
Technical evaluation of models. Bias, robustness, explainability, testing. Data science skills applied to auditing.
Client and commercial dialogue. Responding to compliance clauses in tenders, reassuring a client's executive committee. A pre-sales skill as much as a compliance skill.
A single person cannot cover all four dimensions. The question to decide before any recruitment is which one constitutes the bottleneck of the organization.
Where to Position the Function
Three organizational placements are commonly used, with different effects.
Reporting to the Legal Department. Consistent with the regulatory nature of the obligation. Risk of late involvement, at the end of the project cycle, when design choices are already locked in.
Reporting to the Technical Department. Guarantees upstream intervention. Risk of conflict of interest, with the same department managing both performance and its monitoring.
Reporting to General Management or the Quality Department. Provides the necessary cross-functional authority. This is the approach of organizations that have treated the topic as an industrial challenge rather than an image issue.
Reporting to communications or product marketing produces a function without authority, unable to obtain documentation from development teams.
The Most Common Recruitment Mistakes
Reading the postponement as a cancellation. The core rules already apply, transparency has been in effect since August 2026, and the content of high-risk obligations remains unchanged.
Freezing recruitment until 2027. Building technical documentation for a portfolio of systems cannot be done in a few months.
Recruiting an evangelist profile. What is required is an ability to produce legally defensible documentation, not to raise awareness.
Creating the position without qualifying roles. An organization that does not know whether it is a provider or a deployer in its main contracts does not know what level of position to open.
Searching for a unicorn. The profile that masters law, data science, quality assurance, and pre-sales is virtually non-existent.
Confusing data protection with AI compliance. The two regimes partially overlap. A data protection officer is not automatically competent in qualifying a high-risk system.
How to Assess an AI Compliance Profile
Have they already qualified a system under the regulation? Ask for a real-life case, the conclusion reached, and the reasoning followed.
Do they know how to distinguish the obligations of the provider from those of the deployer? An immediate screening question.
Do they know the precise state of the schedule after the July 2026 regulation? A profile still talking about an August 2, 2026 deadline has not kept up.
Have they produced legally defensible technical documentation? The difference between knowing the text and having built a file is decisive.
Have they worked with reluctant development teams? The function is cross-functional, without direct hierarchical authority.
Frequently Asked Questions
Was the AI Act postponed? Partially. A regulation published on July 24, 2026, postpones the obligations related to Annex III high-risk systems, originally scheduled for August 2, 2026, to December 2, 2027, and those of Annex I to August 2, 2028. Other provisions are unaffected.
What applies today? Prohibited practices and the AI literacy obligation since February 2025. Obligations on general-purpose models, governance, and penalties since August 2025. Transparency obligations under Article 50 since August 2, 2026, with a grace period until December 2, 2026, for machine-readable marking of pre-existing systems.
Is recruitment considered a high-risk use case? Systems used in employment and worker management are among the cases listed in Annex III. They are therefore affected by the postponed deadline of December 2027, and not that of August 2026.
Should we freeze AI compliance recruitment because of the postponement? The postponement affects the application date, not the content of the obligations or the time needed to prepare for them. Compiling technical documentation, tracing datasets, and setting up a quality management system for a portfolio of systems takes well over sixteen months.
Is a digital service company a provider or a deployer? Both, depending on the project. It is a provider when it develops a system and places it on the market under its name, and a deployer when it uses a system under its own authority. Qualification is done contract by contract.
Have the penalties been modified? No. Up to 35 million euros or 7% of global turnover for prohibited practices, and up to 15 million euros or 3% for most other violations.
Key Takeaways
The regulation published on July 24, 2026, postpones the obligations for Annex III high-risk systems to December 2, 2027, and those for Annex I to August 2, 2028.
The foundation already applies: prohibitions and literacy since February 2025, general-purpose models and penalties since August 2025, transparency since August 2, 2026.
The content of the obligations remains unchanged. Only the dates are moving.
Employment and worker management systems fall under high-risk, thus target the December 2027 deadline.
Defining the role as either provider or deployer determines the level of the position to open.
Preparation cannot be postponed. Sixteen months is a short timeframe to document a portfolio of systems.
Laroze Partners' Perspective
Two major European texts have been postponed in eighteen months: sustainability reporting and high-risk obligations in artificial intelligence. In both cases, the dominant reaction of organizations was to freeze ongoing recruitment.
This is an erroneous interpretation of the same phenomenon. The legislator postpones a publication or compliance date; they do not reduce the time needed to get there. The companies that will meet their deadlines are those that will have used the extra time, not those that will have wasted it.
The preliminary question is not who to recruit. It is what responsibility the company actually carries under the regulation, contract by contract, and by what deadline. Once this qualification is made, the profile becomes clear.
For two years, artificial intelligence ethics has been treated in digital service companies as a matter of personal conviction, championed by volunteers, without a clear mandate or stable positioning. The European regulation on artificial intelligence was supposed to close this period on August 2, 2026, the date on which the obligations on high-risk systems came into effect.
That did not happen. A regulation published on July 24, 2026, eight days before the deadline, postponed these obligations by sixteen months. At the same time, other provisions of the text did enter into force on the scheduled date.
The result is an asymmetrical situation that many organizations misinterpret: part of the regulation applies today, while the other will apply at the end of 2027. Recruitment decisions made on an overall reading of the schedule are mechanically poorly calibrated.
Key Figures to Know
Element | Data |
|---|---|
Reference text | Regulation (EU) 2024/1689, known as the AI Act, entered into force on August 1, 2024 |
Amending text | Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, published in the OJEU on July 24, 2026, in force on July 27, 2026 |
Prohibitions and AI literacy | applicable since February 2, 2025, unchanged |
General-purpose AI models, governance, penalties | applicable since August 2, 2025, unchanged |
Transparency obligations under Article 50 | applicable since August 2, 2026, unchanged |
Machine-readable marking of generated content | tolerance until December 2, 2026, for pre-existing systems |
Annex III high-risk systems | postponed from August 2, 2026, to December 2, 2027 |
Annex I high-risk systems | postponed from August 2, 2027, to August 2, 2028 |
Maximum penalty, prohibited practices | 35 million euros or 7% of global turnover, unchanged |
Maximum penalty, other non-compliance | 15 million euros or 3% of global turnover |
Why This Topic Matters Now
Three events occurred in just a few weeks.
The postponement was adopted at the eleventh hour. The political agreement was reached in early May 2026, the Parliament approved it in June, and the text was published on July 24, eight days before the deadline it neutralized. Many organizations had based their planning on August 2.
The transparency obligations, however, did enter into force on August 2, 2026. Informing a person that they are interacting with an artificial intelligence system, flagging generated or manipulated content, marking the outputs of generative systems in a machine-readable format: these requirements apply today. Systems already deployed benefit from a grace period until December 2, 2026, for the marking.
Prior obligations remain in force. Prohibited practices and the obligation of artificial intelligence literacy have applied since February 2025. The sanctions regime has applied since August 2025. The postponement does not affect them.
The correct reading is therefore not "the AI Act is postponed." It is: the foundation applies, the most demanding layer arrives at the end of 2027.
Consolidated Calendar After the Postponement
Date | What Applies | Status |
|---|---|---|
February 2, 2025 | Prohibited practices, AI literacy obligation | In force |
August 2, 2025 | General-purpose models, governance, sanctions regime | In force |
August 2, 2026 | Article 50 transparency: interaction, generated content, marking | In force |
December 2, 2026 | End of the grace period for marking pre-existing systems | Upcoming |
December 2, 2027 | Annex III high-risk systems, including employment and worker management | Postponed by 16 months |
August 2, 2028 | High-risk systems embedded in regulated products, Annex I | Postponed by 12 months |
The postponement concerns the application dates, not the content of the obligations. What will be required at the end of 2027 is what was supposed to be required in August 2026.
What the Postponement Really Changes for Recruitment
Four effects, two of which pull in opposite directions.
Organizations that had an open position are freezing it. This is the immediate and most frequent reaction. A sixteen-month delay is enough to de-prioritize a recruitment in a budget trade-off.
Those that had a transparency obligation are just discovering it. Article 50 concerns conversational interfaces, content generation systems, and assistants integrated into delivered products. Many digital service companies operate them without having identified the obligation because they were waiting for a global deadline.
The market for talent is temporarily easing. The pressure on artificial intelligence compliance skills mechanically decreases when the deadline moves away. For an organization recruiting now, this is a window of opportunity. It will close at the end of 2027, with a predictable scarcity effect.
Preparation, however, cannot be postponed. Compiling technical documentation, tracing training datasets, and setting up logging and a quality management system takes more than sixteen months in an organization that produces systems in series. A company that waits until December 2027 to start will not be ready.
This is exactly the pattern observed with the sustainability reporting directive, which was also postponed by two years: the delay concerns publication, not the building process.
Provider or Deployer: The Question That Decides Everything
The regulation distinguishes several roles, and the obligations differ radically depending on the one occupied.
The provider develops an artificial intelligence system or places it on the market under its name. It carries the bulk of the obligations for high-risk systems: risk management, data governance, technical documentation, conformity assessment, marking, and registration.
The deployer uses a system under its own authority. Its obligations are real but lighter: use in accordance with the instructions, human oversight, monitoring, and informing the individuals concerned. Article 50 directly imposes transparency on them, which is applicable today.
For a digital service company, the difficulty is that the role varies from one project to another, sometimes within the same contract. Developing a component delivered under the client's brand, providing a solution under its own brand, or operating a system on behalf of a third party: these three situations do not entail the same responsibilities.
This qualification is not an auxiliary legal point. It determines the level of the position to be created and the profile to be recruited. An organization that is predominantly a deployer needs oversight capability. An organization acting as a provider for systems that will shift to high-risk at the end of 2027 needs a executive-level function, and it needs it now.
What High Risk Will Impose at the End of 2027
For a system classified as high-risk, the provider must be able to produce and keep up to date:
a risk management system covering the entire lifecycle,
governance of training, validation, and testing datasets,
comprehensive technical documentation,
automatic event logging to ensure traceability,
instructions for use allowing the deployer to understand and monitor the system,
human oversight arrangements,
a demonstrated level of accuracy, robustness, and cybersecurity,
a quality management system.
None of these elements are a matter of personal conviction. All require documentary proof, exactly like an industrial compliance file. This is the point that most analyses miss: the function sought is a compliance and quality function, not an awareness-raising function.
Systems used in employment and worker management are among the cases listed in Annex III. Candidate screening and employee evaluation tools are therefore directly affected by the December 2027 deadline.
The Four Core Competencies to Cover
Regulatory qualification. Determining, project by project, the company's role and the system's risk level. A legal and technical skill, the rarest on the market.
Documentary compliance. Producing and maintaining the required files. A profile coming from quality assurance, industrial compliance, or information systems auditing.
Technical evaluation of models. Bias, robustness, explainability, testing. Data science skills applied to auditing.
Client and commercial dialogue. Responding to compliance clauses in tenders, reassuring a client's executive committee. A pre-sales skill as much as a compliance skill.
A single person cannot cover all four dimensions. The question to decide before any recruitment is which one constitutes the bottleneck of the organization.
Where to Position the Function
Three organizational placements are commonly used, with different effects.
Reporting to the Legal Department. Consistent with the regulatory nature of the obligation. Risk of late involvement, at the end of the project cycle, when design choices are already locked in.
Reporting to the Technical Department. Guarantees upstream intervention. Risk of conflict of interest, with the same department managing both performance and its monitoring.
Reporting to General Management or the Quality Department. Provides the necessary cross-functional authority. This is the approach of organizations that have treated the topic as an industrial challenge rather than an image issue.
Reporting to communications or product marketing produces a function without authority, unable to obtain documentation from development teams.
The Most Common Recruitment Mistakes
Reading the postponement as a cancellation. The core rules already apply, transparency has been in effect since August 2026, and the content of high-risk obligations remains unchanged.
Freezing recruitment until 2027. Building technical documentation for a portfolio of systems cannot be done in a few months.
Recruiting an evangelist profile. What is required is an ability to produce legally defensible documentation, not to raise awareness.
Creating the position without qualifying roles. An organization that does not know whether it is a provider or a deployer in its main contracts does not know what level of position to open.
Searching for a unicorn. The profile that masters law, data science, quality assurance, and pre-sales is virtually non-existent.
Confusing data protection with AI compliance. The two regimes partially overlap. A data protection officer is not automatically competent in qualifying a high-risk system.
How to Assess an AI Compliance Profile
Have they already qualified a system under the regulation? Ask for a real-life case, the conclusion reached, and the reasoning followed.
Do they know how to distinguish the obligations of the provider from those of the deployer? An immediate screening question.
Do they know the precise state of the schedule after the July 2026 regulation? A profile still talking about an August 2, 2026 deadline has not kept up.
Have they produced legally defensible technical documentation? The difference between knowing the text and having built a file is decisive.
Have they worked with reluctant development teams? The function is cross-functional, without direct hierarchical authority.
Frequently Asked Questions
Was the AI Act postponed? Partially. A regulation published on July 24, 2026, postpones the obligations related to Annex III high-risk systems, originally scheduled for August 2, 2026, to December 2, 2027, and those of Annex I to August 2, 2028. Other provisions are unaffected.
What applies today? Prohibited practices and the AI literacy obligation since February 2025. Obligations on general-purpose models, governance, and penalties since August 2025. Transparency obligations under Article 50 since August 2, 2026, with a grace period until December 2, 2026, for machine-readable marking of pre-existing systems.
Is recruitment considered a high-risk use case? Systems used in employment and worker management are among the cases listed in Annex III. They are therefore affected by the postponed deadline of December 2027, and not that of August 2026.
Should we freeze AI compliance recruitment because of the postponement? The postponement affects the application date, not the content of the obligations or the time needed to prepare for them. Compiling technical documentation, tracing datasets, and setting up a quality management system for a portfolio of systems takes well over sixteen months.
Is a digital service company a provider or a deployer? Both, depending on the project. It is a provider when it develops a system and places it on the market under its name, and a deployer when it uses a system under its own authority. Qualification is done contract by contract.
Have the penalties been modified? No. Up to 35 million euros or 7% of global turnover for prohibited practices, and up to 15 million euros or 3% for most other violations.
Key Takeaways
The regulation published on July 24, 2026, postpones the obligations for Annex III high-risk systems to December 2, 2027, and those for Annex I to August 2, 2028.
The foundation already applies: prohibitions and literacy since February 2025, general-purpose models and penalties since August 2025, transparency since August 2, 2026.
The content of the obligations remains unchanged. Only the dates are moving.
Employment and worker management systems fall under high-risk, thus target the December 2027 deadline.
Defining the role as either provider or deployer determines the level of the position to open.
Preparation cannot be postponed. Sixteen months is a short timeframe to document a portfolio of systems.
Laroze Partners' Perspective
Two major European texts have been postponed in eighteen months: sustainability reporting and high-risk obligations in artificial intelligence. In both cases, the dominant reaction of organizations was to freeze ongoing recruitment.
This is an erroneous interpretation of the same phenomenon. The legislator postpones a publication or compliance date; they do not reduce the time needed to get there. The companies that will meet their deadlines are those that will have used the extra time, not those that will have wasted it.
The preliminary question is not who to recruit. It is what responsibility the company actually carries under the regulation, contract by contract, and by what deadline. Once this qualification is made, the profile becomes clear.
For two years, artificial intelligence ethics has been treated in digital service companies as a matter of personal conviction, championed by volunteers, without a clear mandate or stable positioning. The European regulation on artificial intelligence was supposed to close this period on August 2, 2026, the date on which the obligations on high-risk systems came into effect.
That did not happen. A regulation published on July 24, 2026, eight days before the deadline, postponed these obligations by sixteen months. At the same time, other provisions of the text did enter into force on the scheduled date.
The result is an asymmetrical situation that many organizations misinterpret: part of the regulation applies today, while the other will apply at the end of 2027. Recruitment decisions made on an overall reading of the schedule are mechanically poorly calibrated.
Key Figures to Know
Element | Data |
|---|---|
Reference text | Regulation (EU) 2024/1689, known as the AI Act, entered into force on August 1, 2024 |
Amending text | Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, published in the OJEU on July 24, 2026, in force on July 27, 2026 |
Prohibitions and AI literacy | applicable since February 2, 2025, unchanged |
General-purpose AI models, governance, penalties | applicable since August 2, 2025, unchanged |
Transparency obligations under Article 50 | applicable since August 2, 2026, unchanged |
Machine-readable marking of generated content | tolerance until December 2, 2026, for pre-existing systems |
Annex III high-risk systems | postponed from August 2, 2026, to December 2, 2027 |
Annex I high-risk systems | postponed from August 2, 2027, to August 2, 2028 |
Maximum penalty, prohibited practices | 35 million euros or 7% of global turnover, unchanged |
Maximum penalty, other non-compliance | 15 million euros or 3% of global turnover |
Why This Topic Matters Now
Three events occurred in just a few weeks.
The postponement was adopted at the eleventh hour. The political agreement was reached in early May 2026, the Parliament approved it in June, and the text was published on July 24, eight days before the deadline it neutralized. Many organizations had based their planning on August 2.
The transparency obligations, however, did enter into force on August 2, 2026. Informing a person that they are interacting with an artificial intelligence system, flagging generated or manipulated content, marking the outputs of generative systems in a machine-readable format: these requirements apply today. Systems already deployed benefit from a grace period until December 2, 2026, for the marking.
Prior obligations remain in force. Prohibited practices and the obligation of artificial intelligence literacy have applied since February 2025. The sanctions regime has applied since August 2025. The postponement does not affect them.
The correct reading is therefore not "the AI Act is postponed." It is: the foundation applies, the most demanding layer arrives at the end of 2027.
Consolidated Calendar After the Postponement
Date | What Applies | Status |
|---|---|---|
February 2, 2025 | Prohibited practices, AI literacy obligation | In force |
August 2, 2025 | General-purpose models, governance, sanctions regime | In force |
August 2, 2026 | Article 50 transparency: interaction, generated content, marking | In force |
December 2, 2026 | End of the grace period for marking pre-existing systems | Upcoming |
December 2, 2027 | Annex III high-risk systems, including employment and worker management | Postponed by 16 months |
August 2, 2028 | High-risk systems embedded in regulated products, Annex I | Postponed by 12 months |
The postponement concerns the application dates, not the content of the obligations. What will be required at the end of 2027 is what was supposed to be required in August 2026.
What the Postponement Really Changes for Recruitment
Four effects, two of which pull in opposite directions.
Organizations that had an open position are freezing it. This is the immediate and most frequent reaction. A sixteen-month delay is enough to de-prioritize a recruitment in a budget trade-off.
Those that had a transparency obligation are just discovering it. Article 50 concerns conversational interfaces, content generation systems, and assistants integrated into delivered products. Many digital service companies operate them without having identified the obligation because they were waiting for a global deadline.
The market for talent is temporarily easing. The pressure on artificial intelligence compliance skills mechanically decreases when the deadline moves away. For an organization recruiting now, this is a window of opportunity. It will close at the end of 2027, with a predictable scarcity effect.
Preparation, however, cannot be postponed. Compiling technical documentation, tracing training datasets, and setting up logging and a quality management system takes more than sixteen months in an organization that produces systems in series. A company that waits until December 2027 to start will not be ready.
This is exactly the pattern observed with the sustainability reporting directive, which was also postponed by two years: the delay concerns publication, not the building process.
Provider or Deployer: The Question That Decides Everything
The regulation distinguishes several roles, and the obligations differ radically depending on the one occupied.
The provider develops an artificial intelligence system or places it on the market under its name. It carries the bulk of the obligations for high-risk systems: risk management, data governance, technical documentation, conformity assessment, marking, and registration.
The deployer uses a system under its own authority. Its obligations are real but lighter: use in accordance with the instructions, human oversight, monitoring, and informing the individuals concerned. Article 50 directly imposes transparency on them, which is applicable today.
For a digital service company, the difficulty is that the role varies from one project to another, sometimes within the same contract. Developing a component delivered under the client's brand, providing a solution under its own brand, or operating a system on behalf of a third party: these three situations do not entail the same responsibilities.
This qualification is not an auxiliary legal point. It determines the level of the position to be created and the profile to be recruited. An organization that is predominantly a deployer needs oversight capability. An organization acting as a provider for systems that will shift to high-risk at the end of 2027 needs a executive-level function, and it needs it now.
What High Risk Will Impose at the End of 2027
For a system classified as high-risk, the provider must be able to produce and keep up to date:
a risk management system covering the entire lifecycle,
governance of training, validation, and testing datasets,
comprehensive technical documentation,
automatic event logging to ensure traceability,
instructions for use allowing the deployer to understand and monitor the system,
human oversight arrangements,
a demonstrated level of accuracy, robustness, and cybersecurity,
a quality management system.
None of these elements are a matter of personal conviction. All require documentary proof, exactly like an industrial compliance file. This is the point that most analyses miss: the function sought is a compliance and quality function, not an awareness-raising function.
Systems used in employment and worker management are among the cases listed in Annex III. Candidate screening and employee evaluation tools are therefore directly affected by the December 2027 deadline.
The Four Core Competencies to Cover
Regulatory qualification. Determining, project by project, the company's role and the system's risk level. A legal and technical skill, the rarest on the market.
Documentary compliance. Producing and maintaining the required files. A profile coming from quality assurance, industrial compliance, or information systems auditing.
Technical evaluation of models. Bias, robustness, explainability, testing. Data science skills applied to auditing.
Client and commercial dialogue. Responding to compliance clauses in tenders, reassuring a client's executive committee. A pre-sales skill as much as a compliance skill.
A single person cannot cover all four dimensions. The question to decide before any recruitment is which one constitutes the bottleneck of the organization.
Where to Position the Function
Three organizational placements are commonly used, with different effects.
Reporting to the Legal Department. Consistent with the regulatory nature of the obligation. Risk of late involvement, at the end of the project cycle, when design choices are already locked in.
Reporting to the Technical Department. Guarantees upstream intervention. Risk of conflict of interest, with the same department managing both performance and its monitoring.
Reporting to General Management or the Quality Department. Provides the necessary cross-functional authority. This is the approach of organizations that have treated the topic as an industrial challenge rather than an image issue.
Reporting to communications or product marketing produces a function without authority, unable to obtain documentation from development teams.
The Most Common Recruitment Mistakes
Reading the postponement as a cancellation. The core rules already apply, transparency has been in effect since August 2026, and the content of high-risk obligations remains unchanged.
Freezing recruitment until 2027. Building technical documentation for a portfolio of systems cannot be done in a few months.
Recruiting an evangelist profile. What is required is an ability to produce legally defensible documentation, not to raise awareness.
Creating the position without qualifying roles. An organization that does not know whether it is a provider or a deployer in its main contracts does not know what level of position to open.
Searching for a unicorn. The profile that masters law, data science, quality assurance, and pre-sales is virtually non-existent.
Confusing data protection with AI compliance. The two regimes partially overlap. A data protection officer is not automatically competent in qualifying a high-risk system.
How to Assess an AI Compliance Profile
Have they already qualified a system under the regulation? Ask for a real-life case, the conclusion reached, and the reasoning followed.
Do they know how to distinguish the obligations of the provider from those of the deployer? An immediate screening question.
Do they know the precise state of the schedule after the July 2026 regulation? A profile still talking about an August 2, 2026 deadline has not kept up.
Have they produced legally defensible technical documentation? The difference between knowing the text and having built a file is decisive.
Have they worked with reluctant development teams? The function is cross-functional, without direct hierarchical authority.
Frequently Asked Questions
Was the AI Act postponed? Partially. A regulation published on July 24, 2026, postpones the obligations related to Annex III high-risk systems, originally scheduled for August 2, 2026, to December 2, 2027, and those of Annex I to August 2, 2028. Other provisions are unaffected.
What applies today? Prohibited practices and the AI literacy obligation since February 2025. Obligations on general-purpose models, governance, and penalties since August 2025. Transparency obligations under Article 50 since August 2, 2026, with a grace period until December 2, 2026, for machine-readable marking of pre-existing systems.
Is recruitment considered a high-risk use case? Systems used in employment and worker management are among the cases listed in Annex III. They are therefore affected by the postponed deadline of December 2027, and not that of August 2026.
Should we freeze AI compliance recruitment because of the postponement? The postponement affects the application date, not the content of the obligations or the time needed to prepare for them. Compiling technical documentation, tracing datasets, and setting up a quality management system for a portfolio of systems takes well over sixteen months.
Is a digital service company a provider or a deployer? Both, depending on the project. It is a provider when it develops a system and places it on the market under its name, and a deployer when it uses a system under its own authority. Qualification is done contract by contract.
Have the penalties been modified? No. Up to 35 million euros or 7% of global turnover for prohibited practices, and up to 15 million euros or 3% for most other violations.
Key Takeaways
The regulation published on July 24, 2026, postpones the obligations for Annex III high-risk systems to December 2, 2027, and those for Annex I to August 2, 2028.
The foundation already applies: prohibitions and literacy since February 2025, general-purpose models and penalties since August 2025, transparency since August 2, 2026.
The content of the obligations remains unchanged. Only the dates are moving.
Employment and worker management systems fall under high-risk, thus target the December 2027 deadline.
Defining the role as either provider or deployer determines the level of the position to open.
Preparation cannot be postponed. Sixteen months is a short timeframe to document a portfolio of systems.
Laroze Partners' Perspective
Two major European texts have been postponed in eighteen months: sustainability reporting and high-risk obligations in artificial intelligence. In both cases, the dominant reaction of organizations was to freeze ongoing recruitment.
This is an erroneous interpretation of the same phenomenon. The legislator postpones a publication or compliance date; they do not reduce the time needed to get there. The companies that will meet their deadlines are those that will have used the extra time, not those that will have wasted it.
The preliminary question is not who to recruit. It is what responsibility the company actually carries under the regulation, contract by contract, and by what deadline. Once this qualification is made, the profile becomes clear.
See more
See more

IT Services Companies and AI: The Leadership Challenge Transforming the Model

IT Services Companies and AI: The Leadership Challenge Transforming the Model

Chief GenIA Officer: The leader of transformation through generative AI

Chief GenIA Officer: The leader of transformation through generative AI

AI and Consulting: Avoiding Groupthink in Executive Teams

AI and Consulting: Avoiding Groupthink in Executive Teams

Generative AI: opportunities for investors and financial advice

Generative AI: opportunities for investors and financial advice
CONTACT
Let's talk about your next recruitment
Outline your needs in a few lines. Your request will be treated with the strictest confidentiality.
CONTACT
Let's talk about your next recruitment
Outline your needs in a few lines. Your request will be treated with the strictest confidentiality.
CONTACT
Let's talk about your next recruitment
Outline your needs in a few lines. Your request will be treated with the strictest confidentiality.


