Latest Blog
AI Interviewing Compliance in 2026: Which Rules Bind, and When
Researcher
•
5 min read
Share this post
The first compliance question to put to an AI interviewing vendor is whether the system draws any inference about a candidate's emotional state from voice, face, or phrasing. That practice has been prohibited in the EU since February 2025. The Commission reads the prohibition as covering job candidates and not only employees, and it sits in the AI Act's highest penalty tier.
The high-risk regime most buyers plan around moved to December 2027 this summer, which is the change everyone has heard about. The prohibition did not move by a day. A vendor telling you the AI Act does not bite until 2027 is describing one chapter of it.
Which rule binds an AI interview soonest?
Article 5(1)(f) of the EU AI Act, and it has been binding for eighteen months. The provision prohibits placing on the market or using AI systems to infer emotions of a natural person in the workplace, outside narrow medical and safety exceptions, and it became applicable on 2 February 2025 along with the rest of the prohibited-practices chapter. The Commission's guidelines read "workplace" to cover the hiring process. In the Future of Privacy Forum's summary of them, published 24 March 2026, "hiring processes also fall within the workplace context for the purpose of this prohibition." The medical and safety carve-outs are read narrowly. They cover CE-marked therapeutic devices and the protection of life and health, and neither one reaches a screening interview.
There is one caveat on how far this reaches candidates. Guidelines are the Commission's reading of the Article, not the Article itself, and they do not bind a court. The Article's own word is "workplace." But few employers will want to bet a rollout on the argument that a candidate sits outside it.
A prohibition behaves differently from a deadline. Annex III duties are process work, meaning documentation, logging and risk management, and a year is enough time to build them. Whether a product infers emotion is a question you can answer in a single demo, and the answer either disqualifies a vendor or it doesn't. Ask whether the system scores, flags, or summarises anything resembling confidence, enthusiasm, honesty, nervousness, or engagement. Then ask for the field list instead of the marketing page. Many buyer's guides file emotion inference under demo red flags. It belongs under Article 5, whose penalty tier runs to €35 million or 7% of worldwide annual turnover, whichever is higher. Those penalties have been enforceable since 2 August 2025, six months after the prohibition itself began to bind.
Book a 30-Minute Compliance Walkthrough. Bring your own vendor shortlist and we will go through the Article 5 question on each of them, ours included.
Did the EU high-risk deadline for hiring really move?
It moved by sixteen months, and it moved in law rather than in a proposal. Recruitment and candidate-evaluation systems are high-risk under Annex III, point 4(a). The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July, pushing stand-alone Annex III obligations from 2 August 2026 to 2 December 2027.
Three other obligations did not move with it.
Obligation | Binds from | What a buyer does now |
|---|---|---|
Art. 5(1)(f), emotion inference in the workplace | 2 February 2025 | Get the inference field list from every vendor before you shortlist |
Art. 50 transparency: tell candidates they are dealing with an AI system | 2 August 2026 | Read the live candidate-facing disclosure, in each language you hire in |
Art. 50(2) machine-readable marking of synthetic output, systems already on market | 2 December 2026 | Ask which release ships it, and whether your instance updates automatically |
Annex III, point 4(a) high-risk duties | 2 December 2027 | Start the documentation and logging work now, because sixteen extra months only helps if you use them |
The Article 50 duties took effect on 2 August 2026 and are in force today, with the narrow grace period above for watermarking on systems already marketed. So the deferral gives you sixteen extra months of conformity runway and no extra time at all for telling candidates they are speaking to a machine.
You will also see 2 December 2026 cited as an AI Act deadline. It is one. The Omnibus added two new prohibitions from that date, covering non-consensual intimate imagery and child sexual abuse material. Neither has anything to do with hiring, and a vendor presenting that date as a recruitment milestone has not read the amendment.
There is one more thing to know before anyone sells you a conformity claim. The first European standard written for the AI Act does now exist. EN 18286:2026, the quality-management standard supporting Article 17, was approved on 12 July 2026. But publication by CEN-CENELEC is not the step that counts. Article 40(1) attaches the presumption of conformity only to standards whose references have been published in the Official Journal, and no AI Act standard has been cited there yet. A vendor saying "AI Act certified" in August 2026 is describing work done against a standard that carries no presumption for anyone.
What survives the EEOC pulling its AI guidance?
The statutes survive, and statutes are what create liability. Two EEOC documents came down in January 2025: the May 2023 technical assistance on assessing adverse impact in algorithmic selection, and the May 2022 technical assistance on ADA screen-outs by AI decision tools, which employment counsel catalogued at the time under the heading that the guidance disappeared and the law did not. Don't assume the whole 2022 package went with them. The Justice Department's companion document, Algorithms, Artificial Intelligence, and Disability Discrimination in Hiring, is still published at ada.gov, unrescinded. Check what is live before you tell your own legal team a source has gone.
You are bound by the same rules as before, with less official help on how to follow them. Three fixed points do most of the work an adverse-impact analysis needs.
29 CFR 1607.4(D) says a selection rate below four-fifths of the highest group's rate "will generally be regarded by the Federal enforcement agencies as evidence of adverse impact." Generally, and by those agencies, so it screens rather than decides. Set the threshold before the results arrive.
Under 29 CFR 1606.7, "the primary language of an individual is often an essential national origin characteristic." So a difference in pass rates between your English and your Portuguese candidates sits inside protected-class analysis, particularly where the mechanism producing it is speech recognition performing worse on accented speech.
And the ADA duty to avoid screening out disabled candidates is untouched, which puts the accommodation path in your compliance file and not only in your candidate-experience plan. WCAG 2.2 Success Criterion 2.2.1 is the criterion voice flows trip over, because a capped response window is a time limit under the standard. It carries an essential-function exception, which is where a vendor will point when you raise it. Make them argue it on the specifics of your flow.
Book an Adverse-Impact Working Session. Bring last year's selection rates by language and we will run the four-fifths comparison with you, threshold agreed first.
Which US state and city rules reach an AI interview?
Five jurisdictions reach it directly, and they now point in different directions, which is why "we are compliant" means very little until somebody attaches a jurisdiction to it.
New York City. Local Law 144 has applied since 5 July 2023 and requires an independent bias audit within the preceding twelve months, a published summary, and ten business days' notice before an automated employment decision tool is used. Compliance in practice has been thin. Across 391 employers, Wright et al. found published audit reports for 18 and notices for 13. The State Comptroller then audited the enforcer, and the report dated 2 December 2025 called DCWP's enforcement ineffective, finding that three-quarters of test complaints to 311 never reached the department. Employment counsel read the audit as pressure on DCWP to enforce harder, not as reassurance. Weak enforcement is a temporary condition, and the department responsible has just been publicly criticised for allowing it.
Illinois. HB 3773 amended the Human Rights Act effective 1 January 2026 to prohibit discriminatory AI use in employment decisions and to bar zip code as a proxy for a protected class. The implementing rules are unsettled. IDHR published proposed notice regulations on 15 May 2026 with a comment period running to 29 June, then temporarily withdrew the proposed rules on 2 June 2026 and postponed the 10 June hearing, citing the need to coordinate with other state agencies and giving no revised timeline. The statutory duty binds whether or not the rules ever arrive.
Texas. TRAIGA (HB 149) took effect 1 January 2026 and runs on intent rather than impact. It prohibits development or deployment of an AI system with the intent to discriminate against a protected class, is enforceable only by the Attorney General, and comes with a 60-day cure period and no private right of action. It also nullifies local AI ordinances, so a Texas footprint means one regime instead of several. An intent standard is easier to satisfy than a disparate-impact one, and it shields you from nothing under Title VII, which still runs on effects.
California. The FEHA automated-decision regulations took effect on 1 October 2025 and reach your vendor as well as you. Liability extends to an employer's agent, meaning anyone acting on the employer's behalf to exercise a function the employer traditionally performs, and that covers screening tooling. Records tied to automated decisions must be kept four years. Hire in California and your vendor contract becomes part of your compliance posture.
Colorado. SB 24-205 was delayed to 30 June 2026, then repealed and replaced by SB 26-189, signed 14 May 2026 and effective 1 January 2027. The new law drops impact assessments and risk programmes. It adds pre-use notice, an explanation of an adverse decision within 30 days, and the ability for the person affected to request meaningful human review and reconsideration of that decision where doing so is commercially reasonable. Read those qualifiers closely: on request, adverse outcomes only, and commercial reasonableness as the limit. Teams that spent two years building a programme for SB 24-205 built it for a statute that no longer exists.
Map Your Jurisdictions With Us. Send the list of states and countries you hired in last year, and we will mark which of the five above you are already inside before the call starts.
What should you make a vendor prove?
Make every vendor prove these five things on your own data, and treat a refusal on any of them as an answer in itself.
1. Inference list. Ask for every field the system produces about a candidate, including internal scores that a recruiter never sees. You are looking for anything emotional or dispositional. A vendor who can only describe this in prose has never written it down, and that absence is a finding.
2. Candidate disclosure, live. Article 50 requires candidates to know they are dealing with an AI system. Ask to see the actual screen or hear the actual call opening, in a language other than English, instead of a policy statement about it.
3. Accommodation path, timed. Have someone who has never used the product request an accommodation, and time it. A route running through a support ticket, an unmonitored inbox, or a disclosure of diagnosis to a recruiter will not hold up. Response caps usually exist to deter cheating, so relaxing them for accessibility weakens a control that was added for a good reason. There is no way around that.
4. Reconstruction at six months. Name a candidate from a hypothetical audit and ask the vendor to show which version of which question set that person saw, who changed it, and when. Regional teams start asking for local variants by week three, and whether those take a settings change or a services engagement decides a great deal about year two.
5. Adverse impact on your data, threshold set first. Run the four-fifths comparison across language, and across whatever protected groupings you can lawfully compute, before anyone sees results. Split the data instead of aggregating it. A Portuguese pass rate sitting at, say, 61% of your English one is the finding, and it disappears in an average.
Book a Five-Test Walkthrough. We run tests 1 through 5 against our own platform in front of you, and you keep the notes whether or not you buy.
What can a compliance review not settle?
A review cannot settle three things, and a vendor promising certainty about them is selling you something.
A bias audit is a snapshot of a moving system. Upstream speech and language models get updated, sometimes without notice to your vendor and certainly without notice to you, and a version change can shift score distributions with nobody on your side touching a setting. Version pinning and scheduled re-testing are the only defences, and both cost money that nobody budgets in year one.
Documentation proves consistency, not job-relatedness. Version history and full transcripts let you show a regulator that every candidate got the same question set. Neither one establishes that those questions predict performance in the role. That validation work is yours, and it lives in your job analysis, not in a vendor's audit trail.
Nobody can price enforcement risk for you. New York City has a thinly enforced law with a critical audit attached, Illinois has a statute without rules, and Colorado has a law starting in 2027 that replaced one which never started. Building to the strictest applicable standard is the only stable strategy, and it costs more than building to whichever one you expect to be checked against.
Ask Us Whether to Bother. Twenty minutes on whether an AI interview belongs anywhere in your process. If your volume or your role mix says no, we will say so and bill you nothing for the answer.
Where Tenzo fits
Tenzo runs structured interviews across phone, video and text, sitting alongside your ATS rather than replacing it, with recruiter review over full transcripts, configurable interview design, documented accommodation paths, and version history for audit. Humans review throughout and make all final decisions. Underneath, multiple models run in parallel, for redundancy.
Here are two first-party numbers, with their denominators where we have them. Of candidates who apply to a role and are invited to interview, 80% go on to complete an interview. That is completion out of those invited, not out of everyone who applied, and it is an aggregate, so split it on your own data before it means anything to you. Average candidate satisfaction is 4.6 out of 5.
An adverse-impact number only tells you about your own exposure when it comes from your own candidates. Agree the threshold before anyone sees results and put it in the pilot plan, then run the four-fifths comparison on your pilot data, which is what we do in an evaluation. A selection rate is a property of the rubric, the role and the applicant pool that produced it. If two employers run identical software over different applicant pools, they will get different rates, and the difference tells you about the pools rather than about the software.
We do not claim conformity with the AI Act's high-risk regime, because no AI Act standard has been cited in the Official Journal yet and so no provider has a presumption of conformity to point at. What we can show is the documentation and logging work in progress against the December 2027 date, and you are welcome to audit it instead of taking the summary.
To run these five tests on your own roles, book a working session. Bring the jurisdiction list.
FAQ
Is AI interviewing legal in the EU? Yes, subject to conditions, with one hard prohibition. Recruitment and candidate evaluation are high-risk under Annex III, point 4(a), and those obligations now apply from 2 December 2027 following Regulation (EU) 2026/1744. Article 50 transparency duties were not deferred and have applied since 2 August 2026. Separately, Article 5(1)(f) prohibits inferring emotions in the workplace, and the Commission's guidelines treat hiring as within the workplace, so an interview system that scores emotional state is prohibited rather than regulated.
Is AI interviewing legal under EEOC rules? No statute prohibits it, and Title VII applies to it exactly as it applies to any other selection procedure. The EEOC removed its 2023 technical assistance on algorithmic selection in January 2025, which removed guidance and left every obligation intact. Title VII, the ADA, and the Uniform Guidelines on Employee Selection Procedures all remain in force, so adverse-impact analysis and job-relatedness are still the substance of a defence.
Which AI Act date should we plan around? Three of them, in this order. Article 5(1)(f)'s prohibition on inferring emotions in the workplace already binds and always did. Article 50 transparency has applied since 2 August 2026. Annex III high-risk obligations apply from 2 December 2027, which is the deadline that moved and the only one that gives you runway.
What should we ask an AI interviewing vendor first? Ask for the complete list of fields the system infers about a candidate, including scores recruiters never see. That single question resolves the Article 5 prohibition, tells you whether the vendor documents its own outputs, and sets up every later question about job-relatedness and review.



