How the EU AI Act affects UK tech hiring and IT staff

13 min
17
0
0
Published on

Whether you're applying for your next tech role or already working in IT, the EU AI Act has new implications for you — from how AI is used in recruitment decisions to the governance rules now landing on IT department teams. Gerrish Legal's Evane Alexandre decodes the Aug 2026-Dec 2027 Artificial Intelligence rules ‘moving from policy to practice,’ in part one of an exclusive two-part series for Free-Work.

The EU AI Act means at least a heightened level of awareness for UK IT jobs and hiring, as it may apply beyond the EU — notably when an AI system’s output is used in the European Union. That means the UK’s tech job-board users, IT departments and ML/AI consultancies operating across Europe are among those who may fall within the scope of the act. And under Article 50, the act also contains a primary user transparency obligation, in effect and enforceable since August 2nd 2026.

Here’s three main groups who are affected by the EU AI Act, and (briefly) how:

  • Tech job board users: the act categorises the usage of AI to recruit or select IT job candidates as “high-risk.”

  • IT departments: the act ushers in clearer IT departmental policies, training, and tighter controls.

  • AI/ML teams: the act means “strict transparency obligations” (as a Digital Transformation Leader put it) for teams or individuals deploying AI systems, or AI system providers. 

Even where these groups can put beyond doubt with a legal expert’s input that they fall outside the scope of the EU AI Act, EU-facing employers are increasingly reflecting its provisions in procurement, governance and vendor requirements, writes Evane Alexandre, associate lawyer at digital law firm Gerrish Legal.

In this first part of an exclusive two-part series for Free-Work — inspired by the EU AI Act, alongside Dora and the Cyber Security Resilience Act, being said to now be behind cybersecurity becoming the UK’s “single strongest recruitment market,” (STEM hiring giant SThree) — I’ll also come to why firms are rightly being warned that their ‘London servers don’t protect you if those outputs reach EU users’ (as a Principal AI Architect put it).

Article 50: what changed on August 2nd 2026

Since August 2nd 2026, the AI Act’s transparency rules under Article 50 have been in force, and they are likely to be among the parts of the act that tech job users notice most directly

In broad terms, the act says that people (including tech job board users) should now know when they are interacting with an AI system, and certain AI-generated or manipulated content must be identifiable as such.

For IT recruitment, the clearest examples of the EU AI Act’s impact sit at the point of contact with tech job candidates. For instance, a chatbot or virtual ‘recruiter’ that interacts directly with IT job applicants should not be mistaken for a human. This doesn’t mean, however, that every AI-assisted email or job advert needs an “AI-generated” label.

Nevertheless, our recommendation to employers and recruiters — from a law firm that's been advising them since 2018 — is that both organisations and their staffing agents now need to think about where AI sits in the candidate journey, and whether the EU AI Act's relevant transparency requirements are being met.

For IT teams and freelance tech contractors, who might not be specialists in AI, the August 2nd change to the EU AI Act turns transparency into another governance task. And it’s a task that’s three-fold:

1.     Mapping where AI is used

2.     Deciding which disclosures apply 

3.     Making sure the right notices and controls are built into the process

As for AI specialists like ML engineers, the introduction of Article 50’s primary user transparency obligation increasingly becomes a product requirement, too. User-facing disclosures and machine-readable marking are no longer details to merely ‘bolt on’ at the end — they are part of designing AI systems that can actually be deployed compliantly. Spotting what’s non-compliant, or where compliance will be required, is a hireable asset

EU AI Act summary for tech jobs/hiring 

  • The act’s main ‘high-risk’ requirements — including AI in recruitment — apply from December 2027, following the delay agreed under the so-called 2026 Digital Omnibus

  • This EU framework governing Artificial Intelligence usage prohibits certain practices outright, including specified uses of emotion-recognition systems in the workplace.

  • If AI materially influences a recruitment decision, candidates should expect clarity about whether AI is used and what role AI plays.

  • Organisations must ensure an appropriate level of AI literacy among staff dealing with AI systems on their behalf.

  • The EU AI Act introduces a right to an explanation, including for IT job-seekers, where a ‘high-risk’ AI system contributes to a decision producing legal effects or a similarly significant adverse impact.

  • The now enforceable act can apply to UK-only businesses whose AI system outputs reach EU users, and its Article 50 rules require deepfakes and other AI-generated content to be clearly labelled as ‘artificial’ or ‘manipulated.’

Does the EU AI Act apply in the UK?

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) can apply in the UK, even though it’s the EU’s own risk-based framework for AI and not the UK’s, wherever an AI system's output is used in the EU. 

That means the act has implications for UK technologists working for EU employers or clients, and UK employers whose AI systems’ outputs reach individuals in the European Union. For both groups, the August 2nd commencement date may be a flashpoint that prompts action toward EU AI Act compliance. 

Do UK-only servers protect you from the EU AI Act?

No, under Article 2(1)(c) of the EU AI Act, UK-based servers alone don’t protect a business if its AI system outputs reach EU users, observes Bart Chmiel, a Principal AI Architect.

Taking to LinkedIn on August 14th 2026, Chmiel revealed that “the bit most UK teams are getting wrong” relates to the act’s Article 2(1)(c) — and that’s why “your London servers don't protect you if your outputs reach EU users.” 

He then rightly pointed out that the EU AI Act includes what he described in a post as a “deliberate extraterritorial trigger,” found at Article 2(1)(c), which states:

[This Regulation applies to] providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union.”

In a scenario-centred advisory to organisations worried about the EU AI Act, the founder of InfinityTechStack.co.uk added: “Here is the decision tree for your architecture:

  • Scenario A — Purely Domestic UK Product: Your customer base, servers, and data subjects are strictly inside the UK. You have zero EU users and no EU data pipeline outputs. Verdict: The EU AI Act does not legally bind you. You answer to UK law (UK GDPR, ICO guidance, Consumer Duty, sector-specific rules).

  • Scenario B — Global or EU-Facing SaaS / API: You are a UK-registered company, but your web app, API endpoints, agent outputs, or enterprise SaaS are consumed by users or businesses within any of the 27 EU Member States. Verdict: You are in scope. Under Article 2(1)(c), your geographic headquarters does not shield you from EU market surveillance or penalties (up to €35 million or 7% of global turnover for the most serious violations).”

Then, echoing my caution earlier — that even UK employers technically outside the EU AI Act's reach are increasingly reflecting its provisions in procurement, governance and vendor requirements — Chmiel predicted the latter could extend to source code practicalities.

The Principal AI Architect, who is self-employed, warned: “Even teams with no current EU customers often adopt EU-compliant architectural patterns by default — because nobody wants to maintain two divergent codebases when the first enterprise deal in Frankfurt or Amsterdam lands.”

As a technology lawyer who’s specialised in SaaSData and EU Digital regulation since December 2023, I would always endorse making the determination of whether the EU AI Act legally binds you with the assistance of a qualified and experienced legal expert. 

That said, many UK organisations will naturally lean on their tech/AI leaders for initial guidance.

How will the EU AI Act affect tech job-seekers, and AI in tech recruitment?

Under the act, the usage of Artificial Intelligence is categorised as potentially ‘high-risk’ where it relates to:

  • Recruiting or selecting candidates

  • Placing targeted job adverts

  • Filtering applications

  • Evaluating candidates

We believe that the specific, very human activity of seeking a job or trying to get hired — an activity that AI is playing a bigger role in — is where the EU AI Act may feel most personal.

What rights do candidates have under a ‘high-risk’ AI recruitment system?

The act provides people (such as tech job-seekers) with a right to an explanation where a ‘high-risk’ AI system contributes to a decision producing legal effects or a similarly significant adverse impact. Once the relevant rules apply, organisations using such systems will also face requirements around human oversight, monitoring and transparency — including informing people when they are subject to a high-risk system.

In practice, an IT recruitment professional should be able to review and, where necessary, override the output. 

Bottom line: AI should support human decisions, not replace them.

Does the UK GDPR apply to AI used in UK-only recruitment?

Yes, for UK-only recruitment, the UK GDPR still applies, and very much matters alongside a consideration of the EU AI Act.

The Data (Use and Access) Act 2025 made the automated-decision framework more permissive, but significant solely automated decisions remain subject to safeguards: information about the decision, the ability to challenge it, and access to human intervention.

Bottom line: The practical takeaway of the EU AI Act for tech recruitment — whether you’re on the candidate-side or decision-maker side —  is that if AI materially influences a recruitment decision, candidates should expect clarity about whether AI is used and what role it plays.

Does the EU AI Act only affect AI experts in IT departments?

No, for IT professionals and contractors serving the IT department, AI governance is moving into their day job, meaning you need not build AI models as part of your role to encounter the act.

As 2027 comes into sight, organisations using AI that want to be EU AI Act-compliant increasingly need processes around:

  • Approved tools

  • Oversight

  • Logging

  • Risk

  • Staff competence

How does AI literacy relate to the EU AI Act?

Organisations must take measures to ensure an appropriate level of AI literacy among rank-and-file tech staff dealing with AI systems on their behalf. Since the August 2nd transparency obligations took effect under Regulation (EU) 2024/1689 — the EU AI Act — we've seen organisations increasingly ask us what the rules mean for how they use AI.

For IT teams (the members of which might not necessarily be AI experts), the need for AI literacy will trigger clearer IT departmental policiestraining, and tighter controls over which tools can be used, and for what.

Technology departments and workplaces in both the public and private sectors should further be aware that the act prohibits certain practices, including specified uses of emotion-recognition systems.

Bottom line: For IT departmental staff, the practical EU AI Act takeaway is that some changes may appear not in the shape of new technology, but as clearer boundaries around existing tools.

What about the EU AI Act as an ML Engineer?

For ML/AI specialists, as opposed to generalist technologists, EU AI Act literacy will become a technical skill, or at least a differentiator for those of them operating on a freelance basis or selling services as a contractor.

Regulation will account for a larger part of the project spec or contract brief for individuals hired to build or implement AI systems, between now and December 2027, and onwards. As a result, the ability for an ML engineer to identify whether a system falls into a regulated category, and translate that into design and operational requirements, will be increasingly sought-after.

For ‘high-risk’ AI systems, the EU AI Act effectively says that such a design and operational focus includes:

  • Risk management 

  • Data governance

  • Technical documentation

  • Logging

  • Transparency

  • Human oversight

  • Accuracy

  • Robustness

  • Cybersecurity.

But the August 2nd 2026 evolution of the EU AI Act underlines how it’s not just Python programmers who could find themselves on the hook if they skimp on their duties.

What does Article 50 mean for Generative-AI specialists?

Digital Transformation leader Philip Probert reminds that, under the now-in-force Article 50, providers and deployers of AI systems face “strict transparency obligations” across all media formats.

In a three-part advisory aimed at Generative-AI specialists, he posted: 

  1. Text: Synthetic text published to inform the public on matters of public interest must be disclosed as artificially generated or manipulated, unless it has undergone human editorial review and a natural person holds legal responsibility.

  2. Images & Audio/Video (‘Deepfakes’): Any artificial or manipulated content that significantly resembles real people, places, or events must be prominently labelled as artificially created or altered.

  3. Machine-Readable Provenance: AI generators must mark their outputs in a technical, machine-readable format (such as C2PA metadata) so downstream platforms can detect them automatically.

Is Article 50 just ‘telling everyone what to do’?

A self-employed Digital Transformation consultant, Probert doesn’t sound overly enamoured about Article 50, describing it as a “binding, mechanical mandate” that “tells everyone to ‘do as they are told,’” he wrote in a LinkedIn blog.

Well, what’s clear is that Generative-AI specialists join ML engineers on the growing list of professionals who need to understand the act’s separate General Purpose AI (GPAI) and transparency regimes, including requirements concerning AI-generated and manipulated content. Related, the UK’s marketing and social media consultants will likely find their activities impacted, too, making new guidance on the EU AI Act from the DMA a must-read for such digital marketers.

However, while all this change might stem from the EU AI Act, the opportunity is not to become a lawyer — but rather to be the engineer, product lead, architect or other type of contract professional who understands enough of the EU’s framework to build and/or maintain AI systems that can actually be designed and deployed without compliance headaches later on.

The takeaway

The EU AI Act has “moved from policy to practice,” as our firm’s founder Charlotte Gerrish remarked after the August 2nd transparency obligations turned enforceable. For UK tech hiring and IT staff in particular, the EU AI Act is becoming part of the operating environment, notably for UK technology professionals working with EU employers or clients. Likewise, tech job-seekers should understand their rights and the new realities as AI shapes recruitment, IT department teams should expect stronger governance and AI-literacy requirements, and AI specialists should be presenting EU AI Act literacy as an asset. If in doubt about your August 2nd 2026 or December 2027 obligations, consult a lawyer who specialises in this seminal field. Alternatively, a good starting point is the European Commission’s “Guidelines on transparency obligations for providers and deployers of certain AI systems.”

Coming next in this series: how DORA and the Cyber Security Resilience Act  — the second of the two regulatory frameworks driving UK cybersecurity hiring resilience — are reshaping cyber governance and what this means for IT contractors. 

FAQ

Does the EU AI Act apply in the UK?

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) can apply in the UK, even though it's the EU's own risk-based framework for AI and not the UK's, wherever an AI system's output is used in the EU.

Do UK-only servers protect you from the EU AI Act?

No, under Article 2(1)(c) of the EU AI Act, UK-based servers alone don't protect a business if its AI system outputs reach EU users, observes Bart Chmiel, a Principal AI Architect.

How will the EU AI Act affect tech job-seekers, and AI in tech recruitment?

Under the act, the usage of Artificial Intelligence is categorised as potentially "high-risk" where it relates to: recruiting or selecting candidates, placing targeted job adverts, filtering applications, and evaluating candidates.

What rights do candidates have under a "high-risk" AI recruitment system?

The act provides people (such as tech job-seekers) with a right to an explanation where a "high-risk" AI system contributes to a decision producing legal effects or a similarly significant adverse impact.

Does the UK GDPR apply to AI used in UK-only recruitment?

Yes, for UK-only recruitment, the UK GDPR still applies, and very much matters alongside a consideration of the EU AI Act.

Does the EU AI Act only affect AI experts in IT departments?

No, for IT professionals and contractors serving the IT department, AI governance is moving into their day job, meaning you need not build AI models as part of your role to encounter the act.

How does AI literacy relate to the EU AI Act?

A: Organisations must take measures to ensure an appropriate level of AI literacy among rank-and-file tech staff dealing with AI systems on their behalf.

What about the EU AI Act as an ML Engineer?

For ML/AI specialists, as opposed to generalist technologists, EU AI Act literacy will become a technical skill, or at least a differentiator for those of them operating on a freelance basis or selling services as a contractor.

What does Article 50 mean for Generative-AI specialists?

Digital Transformation leader Philip Probert reminds that, under the now-in-force Article 50, providers and deployers of AI systems face "strict transparency obligations" across all media formats.

Is Article 50 just "telling everyone what to do"?

A self-employed Digital Transformation consultant, Probert doesn't sound overly enamoured about Article 50, describing it as a "binding, mechanical mandate" that "tells everyone to 'do as they are told.'"

Written by

Evane Alexandre

Evane Alexandre is a French-qualified lawyer admitted to the Paris Bar, specialising in privacy, data protection, AI and technology law. A graduate of the DJCE programme with an LLM from an American university, she advises international clients – particularly SaaS and AI- driven businesses – on GDPR, AI and digital regulation. Her experience spans law firms, academia and global companies, including the legal department of a French luxury house. At Gerrish Legal, she combines regulatory expertise with a strong foundation in French commercial and contract law, advising on technology contracts and the structuring of compliant products and digital services across jurisdictions.

Continue reading around the topics :

Comment

Connecting Tech-Talent

Free-Work, THE platform for all IT professionals.

Free-workers
Resources
About
Recruiters area
2026 © Free-Work / AGSI SAS
Follow us