The representation of a humanoid robot that reflects, symbolizing ethical reflection in tech.
The representation of a humanoid robot that reflects, symbolizing ethical reflection in tech.

AI Ethics in IT Consulting: Does the AI Act Delay Change the Target Recruitment Profile?

AI Ethics in IT Consulting: Does the AI Act Delay Change the Target Recruitment Profile?

AI Ethics in IT Consulting: Does the AI Act Delay Change the Target Recruitment Profile?

Share

For two years, artificial intelligence ethics has been treated in digital service companies as a matter of personal conviction, championed by volunteers, without a clear mandate or stable positioning. The European regulation on artificial intelligence was supposed to close this period on August 2, 2026, the date on which the obligations on high-risk systems came into effect.

That did not happen. A regulation published on July 24, 2026, eight days before the deadline, postponed these obligations by sixteen months. At the same time, other provisions of the text did enter into force on the scheduled date.

The result is an asymmetrical situation that many organizations misinterpret: part of the regulation applies today, while the other will apply at the end of 2027. Recruitment decisions made on an overall reading of the schedule are mechanically poorly calibrated.

Key Figures to Know

Element

Data

Reference text

Regulation (EU) 2024/1689, known as the AI Act, entered into force on August 1, 2024

Amending text

Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, published in the OJEU on July 24, 2026, in force on July 27, 2026

Prohibitions and AI literacy

applicable since February 2, 2025, unchanged

General-purpose AI models, governance, penalties

applicable since August 2, 2025, unchanged

Transparency obligations under Article 50

applicable since August 2, 2026, unchanged

Machine-readable marking of generated content

tolerance until December 2, 2026, for pre-existing systems

Annex III high-risk systems

postponed from August 2, 2026, to December 2, 2027

Annex I high-risk systems

postponed from August 2, 2027, to August 2, 2028

Maximum penalty, prohibited practices

35 million euros or 7% of global turnover, unchanged

Maximum penalty, other non-compliance

15 million euros or 3% of global turnover

Why This Topic Matters Now

Three events occurred in just a few weeks.

The postponement was adopted at the eleventh hour. The political agreement was reached in early May 2026, the Parliament approved it in June, and the text was published on July 24, eight days before the deadline it neutralized. Many organizations had based their planning on August 2.

The transparency obligations, however, did enter into force on August 2, 2026. Informing a person that they are interacting with an artificial intelligence system, flagging generated or manipulated content, marking the outputs of generative systems in a machine-readable format: these requirements apply today. Systems already deployed benefit from a grace period until December 2, 2026, for the marking.

Prior obligations remain in force. Prohibited practices and the obligation of artificial intelligence literacy have applied since February 2025. The sanctions regime has applied since August 2025. The postponement does not affect them.

The correct reading is therefore not "the AI Act is postponed." It is: the foundation applies, the most demanding layer arrives at the end of 2027.

Consolidated Calendar After the Postponement

Date

What Applies

Status

February 2, 2025

Prohibited practices, AI literacy obligation

In force

August 2, 2025

General-purpose models, governance, sanctions regime

In force

August 2, 2026

Article 50 transparency: interaction, generated content, marking

In force

December 2, 2026

End of the grace period for marking pre-existing systems

Upcoming

December 2, 2027

Annex III high-risk systems, including employment and worker management

Postponed by 16 months

August 2, 2028

High-risk systems embedded in regulated products, Annex I

Postponed by 12 months

The postponement concerns the application dates, not the content of the obligations. What will be required at the end of 2027 is what was supposed to be required in August 2026.

What the Postponement Really Changes for Recruitment

Four effects, two of which pull in opposite directions.

Organizations that had an open position are freezing it. This is the immediate and most frequent reaction. A sixteen-month delay is enough to de-prioritize a recruitment in a budget trade-off.

Those that had a transparency obligation are just discovering it. Article 50 concerns conversational interfaces, content generation systems, and assistants integrated into delivered products. Many digital service companies operate them without having identified the obligation because they were waiting for a global deadline.

The market for talent is temporarily easing. The pressure on artificial intelligence compliance skills mechanically decreases when the deadline moves away. For an organization recruiting now, this is a window of opportunity. It will close at the end of 2027, with a predictable scarcity effect.

Preparation, however, cannot be postponed. Compiling technical documentation, tracing training datasets, and setting up logging and a quality management system takes more than sixteen months in an organization that produces systems in series. A company that waits until December 2027 to start will not be ready.

This is exactly the pattern observed with the sustainability reporting directive, which was also postponed by two years: the delay concerns publication, not the building process.

Provider or Deployer: The Question That Decides Everything

The regulation distinguishes several roles, and the obligations differ radically depending on the one occupied.

The provider develops an artificial intelligence system or places it on the market under its name. It carries the bulk of the obligations for high-risk systems: risk management, data governance, technical documentation, conformity assessment, marking, and registration.

The deployer uses a system under its own authority. Its obligations are real but lighter: use in accordance with the instructions, human oversight, monitoring, and informing the individuals concerned. Article 50 directly imposes transparency on them, which is applicable today.

For a digital service company, the difficulty is that the role varies from one project to another, sometimes within the same contract. Developing a component delivered under the client's brand, providing a solution under its own brand, or operating a system on behalf of a third party: these three situations do not entail the same responsibilities.

This qualification is not an auxiliary legal point. It determines the level of the position to be created and the profile to be recruited. An organization that is predominantly a deployer needs oversight capability. An organization acting as a provider for systems that will shift to high-risk at the end of 2027 needs a executive-level function, and it needs it now.

What High Risk Will Impose at the End of 2027

For a system classified as high-risk, the provider must be able to produce and keep up to date:

  • a risk management system covering the entire lifecycle,

  • governance of training, validation, and testing datasets,

  • comprehensive technical documentation,

  • automatic event logging to ensure traceability,

  • instructions for use allowing the deployer to understand and monitor the system,

  • human oversight arrangements,

  • a demonstrated level of accuracy, robustness, and cybersecurity,

  • a quality management system.

None of these elements are a matter of personal conviction. All require documentary proof, exactly like an industrial compliance file. This is the point that most analyses miss: the function sought is a compliance and quality function, not an awareness-raising function.

Systems used in employment and worker management are among the cases listed in Annex III. Candidate screening and employee evaluation tools are therefore directly affected by the December 2027 deadline.

The Four Core Competencies to Cover

Regulatory qualification. Determining, project by project, the company's role and the system's risk level. A legal and technical skill, the rarest on the market.

Documentary compliance. Producing and maintaining the required files. A profile coming from quality assurance, industrial compliance, or information systems auditing.

Technical evaluation of models. Bias, robustness, explainability, testing. Data science skills applied to auditing.

Client and commercial dialogue. Responding to compliance clauses in tenders, reassuring a client's executive committee. A pre-sales skill as much as a compliance skill.

A single person cannot cover all four dimensions. The question to decide before any recruitment is which one constitutes the bottleneck of the organization.

Where to Position the Function

Three organizational placements are commonly used, with different effects.

Reporting to the Legal Department. Consistent with the regulatory nature of the obligation. Risk of late involvement, at the end of the project cycle, when design choices are already locked in.

Reporting to the Technical Department. Guarantees upstream intervention. Risk of conflict of interest, with the same department managing both performance and its monitoring.

Reporting to General Management or the Quality Department. Provides the necessary cross-functional authority. This is the approach of organizations that have treated the topic as an industrial challenge rather than an image issue.

Reporting to communications or product marketing produces a function without authority, unable to obtain documentation from development teams.

The Most Common Recruitment Mistakes

Reading the postponement as a cancellation. The core rules already apply, transparency has been in effect since August 2026, and the content of high-risk obligations remains unchanged.

Freezing recruitment until 2027. Building technical documentation for a portfolio of systems cannot be done in a few months.

Recruiting an evangelist profile. What is required is an ability to produce legally defensible documentation, not to raise awareness.

Creating the position without qualifying roles. An organization that does not know whether it is a provider or a deployer in its main contracts does not know what level of position to open.

Searching for a unicorn. The profile that masters law, data science, quality assurance, and pre-sales is virtually non-existent.

Confusing data protection with AI compliance. The two regimes partially overlap. A data protection officer is not automatically competent in qualifying a high-risk system.

How to Assess an AI Compliance Profile

  1. Have they already qualified a system under the regulation? Ask for a real-life case, the conclusion reached, and the reasoning followed.

  2. Do they know how to distinguish the obligations of the provider from those of the deployer? An immediate screening question.

  3. Do they know the precise state of the schedule after the July 2026 regulation? A profile still talking about an August 2, 2026 deadline has not kept up.

  4. Have they produced legally defensible technical documentation? The difference between knowing the text and having built a file is decisive.

  5. Have they worked with reluctant development teams? The function is cross-functional, without direct hierarchical authority.

Frequently Asked Questions

Was the AI Act postponed? Partially. A regulation published on July 24, 2026, postpones the obligations related to Annex III high-risk systems, originally scheduled for August 2, 2026, to December 2, 2027, and those of Annex I to August 2, 2028. Other provisions are unaffected.

What applies today? Prohibited practices and the AI literacy obligation since February 2025. Obligations on general-purpose models, governance, and penalties since August 2025. Transparency obligations under Article 50 since August 2, 2026, with a grace period until December 2, 2026, for machine-readable marking of pre-existing systems.

Is recruitment considered a high-risk use case? Systems used in employment and worker management are among the cases listed in Annex III. They are therefore affected by the postponed deadline of December 2027, and not that of August 2026.

Should we freeze AI compliance recruitment because of the postponement? The postponement affects the application date, not the content of the obligations or the time needed to prepare for them. Compiling technical documentation, tracing datasets, and setting up a quality management system for a portfolio of systems takes well over sixteen months.

Is a digital service company a provider or a deployer? Both, depending on the project. It is a provider when it develops a system and places it on the market under its name, and a deployer when it uses a system under its own authority. Qualification is done contract by contract.

Have the penalties been modified? No. Up to 35 million euros or 7% of global turnover for prohibited practices, and up to 15 million euros or 3% for most other violations.

Key Takeaways

The regulation published on July 24, 2026, postpones the obligations for Annex III high-risk systems to December 2, 2027, and those for Annex I to August 2, 2028.

The foundation already applies: prohibitions and literacy since February 2025, general-purpose models and penalties since August 2025, transparency since August 2, 2026.

The content of the obligations remains unchanged. Only the dates are moving.

Employment and worker management systems fall under high-risk, thus target the December 2027 deadline.

Defining the role as either provider or deployer determines the level of the position to open.

Preparation cannot be postponed. Sixteen months is a short timeframe to document a portfolio of systems.

Laroze Partners' Perspective

Two major European texts have been postponed in eighteen months: sustainability reporting and high-risk obligations in artificial intelligence. In both cases, the dominant reaction of organizations was to freeze ongoing recruitment.

This is an erroneous interpretation of the same phenomenon. The legislator postpones a publication or compliance date; they do not reduce the time needed to get there. The companies that will meet their deadlines are those that will have used the extra time, not those that will have wasted it.

The preliminary question is not who to recruit. It is what responsibility the company actually carries under the regulation, contract by contract, and by what deadline. Once this qualification is made, the profile becomes clear.

For two years, artificial intelligence ethics has been treated in digital service companies as a matter of personal conviction, championed by volunteers, without a clear mandate or stable positioning. The European regulation on artificial intelligence was supposed to close this period on August 2, 2026, the date on which the obligations on high-risk systems came into effect.

That did not happen. A regulation published on July 24, 2026, eight days before the deadline, postponed these obligations by sixteen months. At the same time, other provisions of the text did enter into force on the scheduled date.

The result is an asymmetrical situation that many organizations misinterpret: part of the regulation applies today, while the other will apply at the end of 2027. Recruitment decisions made on an overall reading of the schedule are mechanically poorly calibrated.

Key Figures to Know

Element

Data

Reference text

Regulation (EU) 2024/1689, known as the AI Act, entered into force on August 1, 2024

Amending text

Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, published in the OJEU on July 24, 2026, in force on July 27, 2026

Prohibitions and AI literacy

applicable since February 2, 2025, unchanged

General-purpose AI models, governance, penalties

applicable since August 2, 2025, unchanged

Transparency obligations under Article 50

applicable since August 2, 2026, unchanged

Machine-readable marking of generated content

tolerance until December 2, 2026, for pre-existing systems

Annex III high-risk systems

postponed from August 2, 2026, to December 2, 2027

Annex I high-risk systems

postponed from August 2, 2027, to August 2, 2028

Maximum penalty, prohibited practices

35 million euros or 7% of global turnover, unchanged

Maximum penalty, other non-compliance

15 million euros or 3% of global turnover

Why This Topic Matters Now

Three events occurred in just a few weeks.

The postponement was adopted at the eleventh hour. The political agreement was reached in early May 2026, the Parliament approved it in June, and the text was published on July 24, eight days before the deadline it neutralized. Many organizations had based their planning on August 2.

The transparency obligations, however, did enter into force on August 2, 2026. Informing a person that they are interacting with an artificial intelligence system, flagging generated or manipulated content, marking the outputs of generative systems in a machine-readable format: these requirements apply today. Systems already deployed benefit from a grace period until December 2, 2026, for the marking.

Prior obligations remain in force. Prohibited practices and the obligation of artificial intelligence literacy have applied since February 2025. The sanctions regime has applied since August 2025. The postponement does not affect them.

The correct reading is therefore not "the AI Act is postponed." It is: the foundation applies, the most demanding layer arrives at the end of 2027.

Consolidated Calendar After the Postponement

Date

What Applies

Status

February 2, 2025

Prohibited practices, AI literacy obligation

In force

August 2, 2025

General-purpose models, governance, sanctions regime

In force

August 2, 2026

Article 50 transparency: interaction, generated content, marking

In force

December 2, 2026

End of the grace period for marking pre-existing systems

Upcoming

December 2, 2027

Annex III high-risk systems, including employment and worker management

Postponed by 16 months

August 2, 2028

High-risk systems embedded in regulated products, Annex I

Postponed by 12 months

The postponement concerns the application dates, not the content of the obligations. What will be required at the end of 2027 is what was supposed to be required in August 2026.

What the Postponement Really Changes for Recruitment

Four effects, two of which pull in opposite directions.

Organizations that had an open position are freezing it. This is the immediate and most frequent reaction. A sixteen-month delay is enough to de-prioritize a recruitment in a budget trade-off.

Those that had a transparency obligation are just discovering it. Article 50 concerns conversational interfaces, content generation systems, and assistants integrated into delivered products. Many digital service companies operate them without having identified the obligation because they were waiting for a global deadline.

The market for talent is temporarily easing. The pressure on artificial intelligence compliance skills mechanically decreases when the deadline moves away. For an organization recruiting now, this is a window of opportunity. It will close at the end of 2027, with a predictable scarcity effect.

Preparation, however, cannot be postponed. Compiling technical documentation, tracing training datasets, and setting up logging and a quality management system takes more than sixteen months in an organization that produces systems in series. A company that waits until December 2027 to start will not be ready.

This is exactly the pattern observed with the sustainability reporting directive, which was also postponed by two years: the delay concerns publication, not the building process.

Provider or Deployer: The Question That Decides Everything

The regulation distinguishes several roles, and the obligations differ radically depending on the one occupied.

The provider develops an artificial intelligence system or places it on the market under its name. It carries the bulk of the obligations for high-risk systems: risk management, data governance, technical documentation, conformity assessment, marking, and registration.

The deployer uses a system under its own authority. Its obligations are real but lighter: use in accordance with the instructions, human oversight, monitoring, and informing the individuals concerned. Article 50 directly imposes transparency on them, which is applicable today.

For a digital service company, the difficulty is that the role varies from one project to another, sometimes within the same contract. Developing a component delivered under the client's brand, providing a solution under its own brand, or operating a system on behalf of a third party: these three situations do not entail the same responsibilities.

This qualification is not an auxiliary legal point. It determines the level of the position to be created and the profile to be recruited. An organization that is predominantly a deployer needs oversight capability. An organization acting as a provider for systems that will shift to high-risk at the end of 2027 needs a executive-level function, and it needs it now.

What High Risk Will Impose at the End of 2027

For a system classified as high-risk, the provider must be able to produce and keep up to date:

  • a risk management system covering the entire lifecycle,

  • governance of training, validation, and testing datasets,

  • comprehensive technical documentation,

  • automatic event logging to ensure traceability,

  • instructions for use allowing the deployer to understand and monitor the system,

  • human oversight arrangements,

  • a demonstrated level of accuracy, robustness, and cybersecurity,

  • a quality management system.

None of these elements are a matter of personal conviction. All require documentary proof, exactly like an industrial compliance file. This is the point that most analyses miss: the function sought is a compliance and quality function, not an awareness-raising function.

Systems used in employment and worker management are among the cases listed in Annex III. Candidate screening and employee evaluation tools are therefore directly affected by the December 2027 deadline.

The Four Core Competencies to Cover

Regulatory qualification. Determining, project by project, the company's role and the system's risk level. A legal and technical skill, the rarest on the market.

Documentary compliance. Producing and maintaining the required files. A profile coming from quality assurance, industrial compliance, or information systems auditing.

Technical evaluation of models. Bias, robustness, explainability, testing. Data science skills applied to auditing.

Client and commercial dialogue. Responding to compliance clauses in tenders, reassuring a client's executive committee. A pre-sales skill as much as a compliance skill.

A single person cannot cover all four dimensions. The question to decide before any recruitment is which one constitutes the bottleneck of the organization.

Where to Position the Function

Three organizational placements are commonly used, with different effects.

Reporting to the Legal Department. Consistent with the regulatory nature of the obligation. Risk of late involvement, at the end of the project cycle, when design choices are already locked in.

Reporting to the Technical Department. Guarantees upstream intervention. Risk of conflict of interest, with the same department managing both performance and its monitoring.

Reporting to General Management or the Quality Department. Provides the necessary cross-functional authority. This is the approach of organizations that have treated the topic as an industrial challenge rather than an image issue.

Reporting to communications or product marketing produces a function without authority, unable to obtain documentation from development teams.

The Most Common Recruitment Mistakes

Reading the postponement as a cancellation. The core rules already apply, transparency has been in effect since August 2026, and the content of high-risk obligations remains unchanged.

Freezing recruitment until 2027. Building technical documentation for a portfolio of systems cannot be done in a few months.

Recruiting an evangelist profile. What is required is an ability to produce legally defensible documentation, not to raise awareness.

Creating the position without qualifying roles. An organization that does not know whether it is a provider or a deployer in its main contracts does not know what level of position to open.

Searching for a unicorn. The profile that masters law, data science, quality assurance, and pre-sales is virtually non-existent.

Confusing data protection with AI compliance. The two regimes partially overlap. A data protection officer is not automatically competent in qualifying a high-risk system.

How to Assess an AI Compliance Profile

  1. Have they already qualified a system under the regulation? Ask for a real-life case, the conclusion reached, and the reasoning followed.

  2. Do they know how to distinguish the obligations of the provider from those of the deployer? An immediate screening question.

  3. Do they know the precise state of the schedule after the July 2026 regulation? A profile still talking about an August 2, 2026 deadline has not kept up.

  4. Have they produced legally defensible technical documentation? The difference between knowing the text and having built a file is decisive.

  5. Have they worked with reluctant development teams? The function is cross-functional, without direct hierarchical authority.

Frequently Asked Questions

Was the AI Act postponed? Partially. A regulation published on July 24, 2026, postpones the obligations related to Annex III high-risk systems, originally scheduled for August 2, 2026, to December 2, 2027, and those of Annex I to August 2, 2028. Other provisions are unaffected.

What applies today? Prohibited practices and the AI literacy obligation since February 2025. Obligations on general-purpose models, governance, and penalties since August 2025. Transparency obligations under Article 50 since August 2, 2026, with a grace period until December 2, 2026, for machine-readable marking of pre-existing systems.

Is recruitment considered a high-risk use case? Systems used in employment and worker management are among the cases listed in Annex III. They are therefore affected by the postponed deadline of December 2027, and not that of August 2026.

Should we freeze AI compliance recruitment because of the postponement? The postponement affects the application date, not the content of the obligations or the time needed to prepare for them. Compiling technical documentation, tracing datasets, and setting up a quality management system for a portfolio of systems takes well over sixteen months.

Is a digital service company a provider or a deployer? Both, depending on the project. It is a provider when it develops a system and places it on the market under its name, and a deployer when it uses a system under its own authority. Qualification is done contract by contract.

Have the penalties been modified? No. Up to 35 million euros or 7% of global turnover for prohibited practices, and up to 15 million euros or 3% for most other violations.

Key Takeaways

The regulation published on July 24, 2026, postpones the obligations for Annex III high-risk systems to December 2, 2027, and those for Annex I to August 2, 2028.

The foundation already applies: prohibitions and literacy since February 2025, general-purpose models and penalties since August 2025, transparency since August 2, 2026.

The content of the obligations remains unchanged. Only the dates are moving.

Employment and worker management systems fall under high-risk, thus target the December 2027 deadline.

Defining the role as either provider or deployer determines the level of the position to open.

Preparation cannot be postponed. Sixteen months is a short timeframe to document a portfolio of systems.

Laroze Partners' Perspective

Two major European texts have been postponed in eighteen months: sustainability reporting and high-risk obligations in artificial intelligence. In both cases, the dominant reaction of organizations was to freeze ongoing recruitment.

This is an erroneous interpretation of the same phenomenon. The legislator postpones a publication or compliance date; they do not reduce the time needed to get there. The companies that will meet their deadlines are those that will have used the extra time, not those that will have wasted it.

The preliminary question is not who to recruit. It is what responsibility the company actually carries under the regulation, contract by contract, and by what deadline. Once this qualification is made, the profile becomes clear.

For two years, artificial intelligence ethics has been treated in digital service companies as a matter of personal conviction, championed by volunteers, without a clear mandate or stable positioning. The European regulation on artificial intelligence was supposed to close this period on August 2, 2026, the date on which the obligations on high-risk systems came into effect.

That did not happen. A regulation published on July 24, 2026, eight days before the deadline, postponed these obligations by sixteen months. At the same time, other provisions of the text did enter into force on the scheduled date.

The result is an asymmetrical situation that many organizations misinterpret: part of the regulation applies today, while the other will apply at the end of 2027. Recruitment decisions made on an overall reading of the schedule are mechanically poorly calibrated.

Key Figures to Know

Element

Data

Reference text

Regulation (EU) 2024/1689, known as the AI Act, entered into force on August 1, 2024

Amending text

Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, published in the OJEU on July 24, 2026, in force on July 27, 2026

Prohibitions and AI literacy

applicable since February 2, 2025, unchanged

General-purpose AI models, governance, penalties

applicable since August 2, 2025, unchanged

Transparency obligations under Article 50

applicable since August 2, 2026, unchanged

Machine-readable marking of generated content

tolerance until December 2, 2026, for pre-existing systems

Annex III high-risk systems

postponed from August 2, 2026, to December 2, 2027

Annex I high-risk systems

postponed from August 2, 2027, to August 2, 2028

Maximum penalty, prohibited practices

35 million euros or 7% of global turnover, unchanged

Maximum penalty, other non-compliance

15 million euros or 3% of global turnover

Why This Topic Matters Now

Three events occurred in just a few weeks.

The postponement was adopted at the eleventh hour. The political agreement was reached in early May 2026, the Parliament approved it in June, and the text was published on July 24, eight days before the deadline it neutralized. Many organizations had based their planning on August 2.

The transparency obligations, however, did enter into force on August 2, 2026. Informing a person that they are interacting with an artificial intelligence system, flagging generated or manipulated content, marking the outputs of generative systems in a machine-readable format: these requirements apply today. Systems already deployed benefit from a grace period until December 2, 2026, for the marking.

Prior obligations remain in force. Prohibited practices and the obligation of artificial intelligence literacy have applied since February 2025. The sanctions regime has applied since August 2025. The postponement does not affect them.

The correct reading is therefore not "the AI Act is postponed." It is: the foundation applies, the most demanding layer arrives at the end of 2027.

Consolidated Calendar After the Postponement

Date

What Applies

Status

February 2, 2025

Prohibited practices, AI literacy obligation

In force

August 2, 2025

General-purpose models, governance, sanctions regime

In force

August 2, 2026

Article 50 transparency: interaction, generated content, marking

In force

December 2, 2026

End of the grace period for marking pre-existing systems

Upcoming

December 2, 2027

Annex III high-risk systems, including employment and worker management

Postponed by 16 months

August 2, 2028

High-risk systems embedded in regulated products, Annex I

Postponed by 12 months

The postponement concerns the application dates, not the content of the obligations. What will be required at the end of 2027 is what was supposed to be required in August 2026.

What the Postponement Really Changes for Recruitment

Four effects, two of which pull in opposite directions.

Organizations that had an open position are freezing it. This is the immediate and most frequent reaction. A sixteen-month delay is enough to de-prioritize a recruitment in a budget trade-off.

Those that had a transparency obligation are just discovering it. Article 50 concerns conversational interfaces, content generation systems, and assistants integrated into delivered products. Many digital service companies operate them without having identified the obligation because they were waiting for a global deadline.

The market for talent is temporarily easing. The pressure on artificial intelligence compliance skills mechanically decreases when the deadline moves away. For an organization recruiting now, this is a window of opportunity. It will close at the end of 2027, with a predictable scarcity effect.

Preparation, however, cannot be postponed. Compiling technical documentation, tracing training datasets, and setting up logging and a quality management system takes more than sixteen months in an organization that produces systems in series. A company that waits until December 2027 to start will not be ready.

This is exactly the pattern observed with the sustainability reporting directive, which was also postponed by two years: the delay concerns publication, not the building process.

Provider or Deployer: The Question That Decides Everything

The regulation distinguishes several roles, and the obligations differ radically depending on the one occupied.

The provider develops an artificial intelligence system or places it on the market under its name. It carries the bulk of the obligations for high-risk systems: risk management, data governance, technical documentation, conformity assessment, marking, and registration.

The deployer uses a system under its own authority. Its obligations are real but lighter: use in accordance with the instructions, human oversight, monitoring, and informing the individuals concerned. Article 50 directly imposes transparency on them, which is applicable today.

For a digital service company, the difficulty is that the role varies from one project to another, sometimes within the same contract. Developing a component delivered under the client's brand, providing a solution under its own brand, or operating a system on behalf of a third party: these three situations do not entail the same responsibilities.

This qualification is not an auxiliary legal point. It determines the level of the position to be created and the profile to be recruited. An organization that is predominantly a deployer needs oversight capability. An organization acting as a provider for systems that will shift to high-risk at the end of 2027 needs a executive-level function, and it needs it now.

What High Risk Will Impose at the End of 2027

For a system classified as high-risk, the provider must be able to produce and keep up to date:

  • a risk management system covering the entire lifecycle,

  • governance of training, validation, and testing datasets,

  • comprehensive technical documentation,

  • automatic event logging to ensure traceability,

  • instructions for use allowing the deployer to understand and monitor the system,

  • human oversight arrangements,

  • a demonstrated level of accuracy, robustness, and cybersecurity,

  • a quality management system.

None of these elements are a matter of personal conviction. All require documentary proof, exactly like an industrial compliance file. This is the point that most analyses miss: the function sought is a compliance and quality function, not an awareness-raising function.

Systems used in employment and worker management are among the cases listed in Annex III. Candidate screening and employee evaluation tools are therefore directly affected by the December 2027 deadline.

The Four Core Competencies to Cover

Regulatory qualification. Determining, project by project, the company's role and the system's risk level. A legal and technical skill, the rarest on the market.

Documentary compliance. Producing and maintaining the required files. A profile coming from quality assurance, industrial compliance, or information systems auditing.

Technical evaluation of models. Bias, robustness, explainability, testing. Data science skills applied to auditing.

Client and commercial dialogue. Responding to compliance clauses in tenders, reassuring a client's executive committee. A pre-sales skill as much as a compliance skill.

A single person cannot cover all four dimensions. The question to decide before any recruitment is which one constitutes the bottleneck of the organization.

Where to Position the Function

Three organizational placements are commonly used, with different effects.

Reporting to the Legal Department. Consistent with the regulatory nature of the obligation. Risk of late involvement, at the end of the project cycle, when design choices are already locked in.

Reporting to the Technical Department. Guarantees upstream intervention. Risk of conflict of interest, with the same department managing both performance and its monitoring.

Reporting to General Management or the Quality Department. Provides the necessary cross-functional authority. This is the approach of organizations that have treated the topic as an industrial challenge rather than an image issue.

Reporting to communications or product marketing produces a function without authority, unable to obtain documentation from development teams.

The Most Common Recruitment Mistakes

Reading the postponement as a cancellation. The core rules already apply, transparency has been in effect since August 2026, and the content of high-risk obligations remains unchanged.

Freezing recruitment until 2027. Building technical documentation for a portfolio of systems cannot be done in a few months.

Recruiting an evangelist profile. What is required is an ability to produce legally defensible documentation, not to raise awareness.

Creating the position without qualifying roles. An organization that does not know whether it is a provider or a deployer in its main contracts does not know what level of position to open.

Searching for a unicorn. The profile that masters law, data science, quality assurance, and pre-sales is virtually non-existent.

Confusing data protection with AI compliance. The two regimes partially overlap. A data protection officer is not automatically competent in qualifying a high-risk system.

How to Assess an AI Compliance Profile

  1. Have they already qualified a system under the regulation? Ask for a real-life case, the conclusion reached, and the reasoning followed.

  2. Do they know how to distinguish the obligations of the provider from those of the deployer? An immediate screening question.

  3. Do they know the precise state of the schedule after the July 2026 regulation? A profile still talking about an August 2, 2026 deadline has not kept up.

  4. Have they produced legally defensible technical documentation? The difference between knowing the text and having built a file is decisive.

  5. Have they worked with reluctant development teams? The function is cross-functional, without direct hierarchical authority.

Frequently Asked Questions

Was the AI Act postponed? Partially. A regulation published on July 24, 2026, postpones the obligations related to Annex III high-risk systems, originally scheduled for August 2, 2026, to December 2, 2027, and those of Annex I to August 2, 2028. Other provisions are unaffected.

What applies today? Prohibited practices and the AI literacy obligation since February 2025. Obligations on general-purpose models, governance, and penalties since August 2025. Transparency obligations under Article 50 since August 2, 2026, with a grace period until December 2, 2026, for machine-readable marking of pre-existing systems.

Is recruitment considered a high-risk use case? Systems used in employment and worker management are among the cases listed in Annex III. They are therefore affected by the postponed deadline of December 2027, and not that of August 2026.

Should we freeze AI compliance recruitment because of the postponement? The postponement affects the application date, not the content of the obligations or the time needed to prepare for them. Compiling technical documentation, tracing datasets, and setting up a quality management system for a portfolio of systems takes well over sixteen months.

Is a digital service company a provider or a deployer? Both, depending on the project. It is a provider when it develops a system and places it on the market under its name, and a deployer when it uses a system under its own authority. Qualification is done contract by contract.

Have the penalties been modified? No. Up to 35 million euros or 7% of global turnover for prohibited practices, and up to 15 million euros or 3% for most other violations.

Key Takeaways

The regulation published on July 24, 2026, postpones the obligations for Annex III high-risk systems to December 2, 2027, and those for Annex I to August 2, 2028.

The foundation already applies: prohibitions and literacy since February 2025, general-purpose models and penalties since August 2025, transparency since August 2, 2026.

The content of the obligations remains unchanged. Only the dates are moving.

Employment and worker management systems fall under high-risk, thus target the December 2027 deadline.

Defining the role as either provider or deployer determines the level of the position to open.

Preparation cannot be postponed. Sixteen months is a short timeframe to document a portfolio of systems.

Laroze Partners' Perspective

Two major European texts have been postponed in eighteen months: sustainability reporting and high-risk obligations in artificial intelligence. In both cases, the dominant reaction of organizations was to freeze ongoing recruitment.

This is an erroneous interpretation of the same phenomenon. The legislator postpones a publication or compliance date; they do not reduce the time needed to get there. The companies that will meet their deadlines are those that will have used the extra time, not those that will have wasted it.

The preliminary question is not who to recruit. It is what responsibility the company actually carries under the regulation, contract by contract, and by what deadline. Once this qualification is made, the profile becomes clear.

CONTACT

Let's talk about your next recruitment

Outline your needs in a few lines. Your request will be treated with the strictest confidentiality.

The information collected is processed by Laroze Partners to respond to your enquiry and to manage our business relationship. It is retained for three years from the date of last contact. You have the right to access, rectify, erase and object to the processing of your data, exercisable at thomas@larozepartners.com. Privacy policy.

CONTACT

Let's talk about your next recruitment

Outline your needs in a few lines. Your request will be treated with the strictest confidentiality.

The information collected is processed by Laroze Partners to respond to your enquiry and to manage our business relationship. It is retained for three years from the date of last contact. You have the right to access, rectify, erase and object to the processing of your data, exercisable at thomas@larozepartners.com. Privacy policy.

CONTACT

Let's talk about your next recruitment

Outline your needs in a few lines. Your request will be treated with the strictest confidentiality.

The information collected is processed by Laroze Partners to respond to your enquiry and to manage our business relationship. It is retained for three years from the date of last contact. You have the right to access, rectify, erase and object to the processing of your data, exercisable at thomas@larozepartners.com. Privacy policy.

Laroze Partners Logo

© 2026 Laroze Partners. All rights reserved.

thomas@larozepartners.com

Laroze Partners Logo

© 2026 Laroze Partners. All rights reserved.

thomas@larozepartners.com

Laroze Partners Logo

© 2026 Laroze Partners. All rights reserved.

thomas@larozepartners.com