HOME > BLOG > CAREER & JOB SEARCH
CAREER & JOB SEARCH

You Have the Right to Know an AI Is Interviewing You (EU AI Act, August 2026)

9/11/2026
10 min read
Video call interface on a laptop screen with a person on the other end during a remote interview
Photo by Christina @ wocintechchat.com on Unsplash

Article 50 of the EU AI Act is the transparency rule that says any AI system designed to interact with you must make sure you know you are talking to an AI. Since 2 August 2026 it applies across every EU Member State without needing national transposition — including to any AI system used to interview, screen, or grade you during a job search.

TL;DR

  • 🇪🇺 Article 50(1) in force since 2 August 2026: AI systems that interact directly with you must be designed so you are informed it’s an AI, at the latest at the first interaction
  • 🚫 Article 5(1)(f) since 2 February 2025: AI that infers your emotions from biometric data in a workplace or hiring context is prohibited outright — not just disclosed
  • ⏳ Digital Omnibus delayed the hiring-AI high-risk rules to 2 December 2027 — but Article 50 was not delayed
  • 💰 Fines: up to EUR 35M or 7% of global turnover for prohibited practices; up to EUR 15M or 3% for transparency breaches
  • 👤 GDPR Article 22 stacks on top: independent right to human review of solely automated hiring decisions
  • 📮 Complaint route in Spain: AESIA for AI Act, AEPD for GDPR — both accept candidate complaints

This is a candidate-facing guide, not a compliance manual. It covers what the law actually says, who owes you what, how to spot when the duty was ducked, and what a candidate can practically do about it. Everything cited traces back to the primary text on EUR-Lex or to the European Commission’s own guidance.

What Article 50 Actually Gives You

Article 50 is the disclosure floor. It sits in Chapter IV of the AI Act (Regulation (EU) 2024/1689), separate from the high-risk regime, and its most important paragraph for job seekers is 50(1):

“Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.”

Two details matter more than the rest.

The obliged party is the provider, not necessarily your employer. Under Article 3(3), a “provider” is whoever develops the AI system and places it on the market under its own name — so if your employer bought a video-interview platform from a SaaS vendor, that vendor owes the design duty. Under Article 3(4), a “deployer” is the entity using the system in professional activity — that is your employer. When an employer builds its own AI interviewer under its own trademark, the roles converge: they become the provider and owe Article 50(1) directly. Either way, the disclosure has to happen — the question of who is on the hook does not affect your right to be told.

Timing is fixed in Article 50(5): information “shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure.” Not buried in a privacy policy, not surfaced after you’ve spent 40 minutes on the platform, and not deferred until a rejection email.

The narrow exception — where it’s “obvious” you’re dealing with an AI — is a drafting compromise between disclosure absolutism and cases like public helpdesk bots plainly labelled as such. The European Commission’s Guidelines C(2026) 5054 final, adopted 20 July 2026, set an “almost no doubt left” standard at paragraph 45. Scholars are split on whether a clearly-branded “AI Interviewer” product satisfies the carve-out; the safer read (and the Commission’s read) is that the exception is narrow and disclosure is still owed in-session.

Before Article 50: A Bigger Rule Already Bans Emotion AI in Hiring

Article 50 arrived in August 2026, but the earlier Chapter II of the Act — Prohibited Practices — has been enforceable since 2 February 2025. Its most consequential rule for job candidates is Article 5(1)(f), which prohibits:

“the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons”

The Commission’s Guidelines on prohibited practices (Communication C(2025) 5052 final, 29 July 2025) make three points explicit. First, “workplace” includes the recruitment process — hiring counts, not just employment after signing. Second, the prohibition is limited to inferences based on biometric data. Third, the Commission specifically names, as a prohibited example, HR platforms that use video-interview analysis to infer candidate emotional states.

If a hiring platform is scoring you on facial expressions, vocal stress, “engagement”, or “authenticity” derived from your face or voice, that is not a transparency question. It is an unlawful practice, and the fine ceiling under Article 99(3) is EUR 35 million or 7% of the offender’s worldwide annual turnover — the highest tier the Regulation carries. HireVue famously dropped its facial-analysis feature under external pressure back in 2021; the EU has since made that walk-back the baseline.

The article you are reading is about the disclosure duty. The prohibition matters because it changes what the disclosure duty is even for. If emotion inference is banned outright, the residual space where Article 50(3) transparency applies — deployer duties on emotion-recognition or biometric-categorisation systems — is narrower than the headlines suggest. Non-emotion biometric categorisation still exists (voice-language detection, accent flagging), and there the Article 50(3) disclosure duty on the employer holds.

The Delay That Doesn’t Cover Your Right

You have probably read that “EU hiring AI rules were delayed to 2027.” That is true and misleading in equal measure.

The Digital Omnibus AI (Regulation (EU) 2026/1744) was adopted by the Council on 29 June 2026, published in the Official Journal on 24 July, and entered into force on 27 July. It postpones the standalone Annex III high-risk regime by 16 months — from 2 August 2026 to 2 December 2027 — and delays AI embedded in Annex I regulated products by 12 months. Annex III point 4 is the employment category: hiring tools, workers-management systems, and access to self-employment. Those Chapter III obligations (Articles 8–15 on risk management, data governance, human oversight; Article 26 deployer duties; Article 27 fundamental rights impact assessments for public-sector deployers) are the ones that got pushed back.

Article 50, and specifically the Article 50(1) candidate-facing disclosure duty, was not touched. It sits in Chapter IV. Article 113 of the AI Act lists which chapters have earlier or later application dates, and Chapter IV is not on any exception list — so the general 2 August 2026 date applies, unaffected by the Omnibus.

The plain-language read: the fuller architecture of high-risk hiring-AI protections is not yet biting, but the floor — you get told an AI is involved — is already law. The delay was industry-preparedness politics, not a change of principle.

Three Interview Scenarios and What You Are Owed

Take the three most common shapes an AI-mediated interview takes today.

Scenario A: An AI screener asks scripted questions and scores your answers. A chatbot, an asynchronous voice interview, a “conversational assessment” — the AI is interacting with you directly, generating outputs based on what you say. Article 50(1) applies. The platform vendor owes the design duty, which in practice looks like an in-session banner (“You are interacting with an AI-powered assessment”), a pre-interview email that says the same, or an audible statement at the start of a voice call. If none of that happens and the platform’s name and behaviour don’t make the AI obvious, the disclosure duty has been ducked.

Scenario B: An AI grades your take-home assignment. You submit code; an LLM reviews it, ranks it against other submissions, and generates the feedback the recruiter forwards to you. This is a subtler case. You are interacting with an AI when you receive the feedback, and if that feedback is presented as human-authored (“Our senior engineers reviewed your submission and…”) the disclosure duty triggers. GDPR Article 22 also enters here: if the decision to advance you or reject you is based solely on the AI’s ranking, you have a right to human review.

Scenario C: A live human interviewer, plus AI silently analysing your video. This is where the strongest rule applies. If the AI is doing emotion inference from biometric data — facial expressions, micro-expressions, vocal stress — Article 5(1)(f) prohibits it, in force since February 2025. Not disclosable, prohibited. If the analysis is non-emotion biometric categorisation (grouping candidates by voice traits, accent, language proficiency inferred from speech patterns), Article 50(3) requires the deployer — your employer — to inform you the system is operating on you.

In all three, GDPR Article 22 gives you an independent right. If any decision materially affecting your candidacy is based solely on automated processing — including scoring that determinatively influences the human’s decision, per the Court of Justice’s 2023 ruling in SCHUFA (Case C-634/21) — you can demand human intervention, express your view, and contest the decision.

Four Layers of AI in Hiring: What Each Layer Owes You

LayerApplicable ruleWho is obligedIn force sincePenalty ceilingYour remedy
Direct AI interaction (chatbot, AI voice/text interviewer, AI-graded feedback)Article 50(1)Provider (SaaS vendor or employer if built in-house)2 August 2026EUR 15M or 3% global turnoverComplaint to national market surveillance authority; GDPR access request in parallel
Emotion inference from biometric data in a workplace/recruitment contextArticle 5(1)(f) — prohibited outrightProvider AND deployer (both liable)2 February 2025EUR 35M or 7% global turnoverComplaint to national market surveillance authority; damages if harm proven
Non-emotion biometric categorisation of candidatesArticle 50(3)Deployer (the employer)2 August 2026EUR 15M or 3% global turnoverComplaint route as above; GDPR Article 9 special-category-data overlay
Automated hiring decisions with legal or significant effectGDPR Article 22 (now); Annex III high-risk rules from 2 December 2027Data controller (the employer); provider and deployer for Annex IIIGDPR: 25 May 2018; Annex III: 2 December 2027GDPR fines up to EUR 20M or 4%; AI Act Annex III fines up to EUR 15M or 3%GDPR Article 22 human-review request; national DPA complaint

The right column is where a candidate actually acts. The remedy is not a private civil action against the AI vendor — it is, in the first instance, a written request to the employer and, if that fails, a complaint to whichever authority in your Member State has jurisdiction. In Spain, that is AESIA for the AI Act and AEPD for GDPR.

What To Do If You Weren’t Told

The pattern is the same across all three scenarios: create a paper trail, use the tools GDPR already gives you, and escalate if silence follows.

  1. Ask in writing before you’re rejected. A short email to the recruiter: “Can you confirm whether any part of this interview process — screening, scoring, video analysis, feedback generation — involves an AI system? If so, which parts and which platform?” Silence to a direct question is evidence you can point at later.

  2. Request the meaningful information about the logic. Under GDPR Article 13(2)(f) and 14(2)(g), if automated decision-making is happening, the controller must give you “meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing.” Ask for it. You do not need to invoke the article by number; asking is enough to trigger the duty.

  3. Invoke GDPR Article 22 if the decision was solely automated. If a decision was made about your candidacy without a human meaningfully involved in the outcome, you have the right to human intervention, to express your point of view, and to contest the decision. This is a live right today — it has been since GDPR applied in May 2018.

  4. Complain if silence follows. In Spain, complaints to AESIA (Agencia Española de Supervisión de la Inteligencia Artificial) cover the AI Act side; complaints to AEPD cover the GDPR side. Both are free to file and both accept candidate complaints. Where a Member State has not yet operationalised its AI market surveillance authority, the GDPR route through the national DPA is still open — the Regulation is directly applicable, so the substantive right does not wait for national plumbing.

None of this is legal advice, and outcomes at national authorities are discretionary — do not expect a fine to fall on a specific employer because you filed a complaint. The point is that the enforcement route exists, and that a candidate has real, formal steps to take rather than only informal grumbling.

See what Xeito does end-to-end. Browse all features — application tracker, AI resume + cover letters, interview coach, 130+ job-board sync, built for remote-first developers.

Sources

  1. Regulation (EU) 2024/1689 (AI Act), EUR-Lex
  2. Regulation (EU) 2016/679 (GDPR), consolidated text, EUR-Lex
  3. Regulation (EU) 2026/1744 (Digital Omnibus AI), EUR-Lex
  4. European Commission FAQ, Transparency obligations under Article 50 of the AI Act (updated 24 July 2026)
  5. European Commission Communication C(2026) 5054 final, Guidelines on transparency obligations (adopted 20 July 2026)
  6. European Commission Communication C(2025) 5052 final, Guidelines on prohibited AI practices (adopted 29 July 2025)
  7. CJEU Case C-634/21 SCHUFA Holding (December 2023)
  8. Cooley: EU AI Act Transparency Obligations Take Effect 2 August 2026 (3 August 2026)
  9. Future of Privacy Forum: Red Lines under EU AI Act — the emotion-recognition-in-workplace prohibition
  10. Gibson Dunn: EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes
  11. AESIA — Agencia Española de Supervisión de la Inteligencia Artificial
  12. AEPD — Agencia Española de Protección de Datos
XT
Xeito Team The team building Xeito

Xeito is built and operated by the team at Abellan Labs, S.L.U., an EU-incorporated software studio. The team builds remote-job tooling for European developers, drawing on hands-on experience with EU remote-work and self-employment regimes, EU consumer-rights compliance (CRD / LSSI-CE / GDPR), the cross-border tax and social-security paths most relocation guides paper over, and the AI-agent-driven engineering practice — CI/CD, content pipelines, and direct platform integrations — behind Xeito itself.

AMPLIFY

Know a friend job-hunting in the EU?

Xeito filters out the "remote — US only" traps. Share it with anyone who's tired of finding fake-remote jobs in the EU.

SHARE_THE_WEDGE →
READY_TO_START

FIND_YOUR_DREAM_JOB

Join developers across Europe using AI-powered tools to find remote opportunities