The algorithm runs in Bengaluru. The candidate is in Frankfurt. The liability is yours.
A law written in Brussels now reaches the screening desk in Bengaluru. If your AI sorts a candidate sitting in the EU, you are the deployer -- and the deployer, not the vendor, answers for it.
Issue 014. The EU AI Act treats AI hiring as high-risk, makes the deployer liable rather than the software firm, and reaches any operation whose systems touch people in the EU. India runs the offshore screening desks. The exposure is already here -- the only open question is the date it is enforced.
The EU AI Act's top penalty ceiling -- 35 million euros or 7 percent of global turnover, whichever is higher, for prohibited practices; 15 million euros or 3 percent for a deployer that fails its high-risk obligations. Both are extraterritorial. A candidate in Frankfurt screened from Bengaluru is a person in the EU, and the desk that screened them is the deployer.
If the deployer is liable, the vendor's paperwork is your floor, not your shield. The durable move is to build the deployer-side controls the Act actually puts in your name.
- Map the exposure first.
- Own the deployer obligations.
- Build to the August date.
Rising
- AI-hiring compliance officer↗
- Algorithmic-bias auditor↗
- Human-in-the-loop review lead↗
Cuts this wk
- Rackspace−750
The EU AI Act's top penalty ceiling -- 35 million euros or 7 percent of global turnover, whichever is higher, for prohibited practices; 15 million euros or 3 percent for a deployer that fails its high-risk obligations. Both are extraterritorial. A candidate in Frankfurt screened from Bengaluru is a person in the EU, and the desk that screened them is the deployer.
The number is not aimed where most assume. The Act reaches any deployer whose AI touches people in the EU, regardless of where it sits, and it puts the liability on the operation that uses the system, not the firm that built it. India runs the deepest base of recruitment-process and HR-shared-services outsourcing on earth, much of it for European clients -- so the deployer obligations land on the offshore screening desk, in its own name, no matter whose software it licensed.
From what does AI replace? -> To who answers for what AI decides?
Accountability does not offshore the way a process does. A vendor can hand you a documented, bias-tested, CE-marked system and you, the deployer, still owe oversight, monitoring and an impact assessment on top -- on your real candidates, in your real pipeline. And it compounds with law already in force: GDPR Article 22 already gave a rejected candidate the right to human review, so the autonomous-rejection workflow was exposed before the Act even arrived.
If the deployer is liable, the vendor's paperwork is your floor, not your shield. The durable move is to build the deployer-side controls the Act actually puts in your name.
- Map the exposure first. You cannot govern an AI system you have not inventoried. List every screening, ranking and evaluation tool in the pipeline, mark which ones touch an EU-based candidate, and classify each against the Act's high-risk criteria -- the inventory is the precondition for every other control.
- Own the deployer obligations. The vendor's CE mark covers the tool as designed, not how you use it. Stand up the human oversight, the logging, the fundamental-rights impact assessment and the incident reporting in your own name, because provider compliance does not discharge a single one of them for the deployer.
- Build to the August date. The Omnibus deferral to December 2027 is agreed but not law until the Council adopts it, anticipated in July. Prepare to the live 2 August 2026 date and be pleasantly surprised by the deferral, not the reverse -- an operation that stood down on the headline has bet its compliance on a date that has not yet arrived.
Career vectors.
Two weeks of named layoffs. 6 rising role categories with sourced hiring signals.
Announced layoffs · week-on-week
Rising role categories
Hiring signal · named companies · this week
AI-hiring compliance officer
The seat that owns the deployer obligations the vendor's paperwork does not cover. As the EU AI Act makes the operation using an AI screening tool liable rather than the software firm, someone has to own the human oversight, logging and impact assessment in the deployer's own name.
Algorithmic-bias auditor
The role the Act and New York's Local Law 144 both require rather than assume. Bias testing of hiring algorithms has to be run, documented and in some jurisdictions published, so the auditor who can produce the test under a regulator's question becomes a control function, not a courtesy.
Human-in-the-loop review lead
The seat GDPR Article 22 and the EU AI Act together turn from courtesy into requirement. A candidate has the right not to be rejected by an algorithm alone, so the human who reviews the automated decision before it counts is now a legal step in the pipeline, not an optional one.
Sovereign-AI-governance lead
The Gulf seat that writes the region's posture rather than importing the EU's. The UAE and Saudi Arabia are building their own AI strategies and frameworks, and DIFC and ADGM run independent data regimes, so the lead who designs governance as sovereign policy rather than borrowed compliance is a distinct and funded role.
AI-systems inventory and FRIA lead
The role that maps the exposure before it is enforced. You cannot govern an AI system you have not inventoried, so the lead who catalogues every screening and ranking tool, classifies which touch the EU, and runs the fundamental-rights impact assessment is the precondition for every other control.
Offshore-deployer assurance lead
The seat inside the RPO or GCC that makes the screening desk defensible. As the EU AI Act reaches any deployer whose systems touch the EU, the offshore operation needs the lead who can produce the audit trail and the impact assessment for European clients, turning a liability surface into an assured service.
Three regions. Three speeds.
Short read · this week's signal through the India, Middle East, and Africa lens
The deployer desk of the world. India runs the deepest base of recruitment-process and HR-shared-services outsourcing anywhere, its GCC estate alone more than 1,700 centres and over 1.9 million people, much of it screening and administering hiring for global clients including European employers. Under the EU AI Act that makes the Indian operation the deployer of a high-risk system the moment its AI sorts an EU-facing candidate -- carrying human oversight, logging and a fundamental-rights impact assessment in its own name, no matter whose software it licensed.
Writing its own rule rather than inheriting one. The Gulf is not waiting to import EU compliance: the UAE and Saudi Arabia are issuing national AI strategies and frameworks, and the common-law hubs of DIFC and ADGM run independent data-protection regimes. Combined with Emiratisation and Saudisation favouring nationals in skilled roles, that lets the Gulf govern AI hiring as a sovereign and workforce-policy matter, deliberately, rather than as borrowed rules arriving from Brussels.
Entering EU-facing work into the same liability. Africa's growing business-process and recruitment-outsourcing base, concentrated in South Africa, Kenya and Nigeria, takes on EU-facing screening and administration just as the deployer-liability rules bite -- so the continent arrives at the exposure at the same moment it reaches for the work. The opening is to build the governance layer in from the start, entering as an assured deployer rather than a cheap screening desk.
Nine sectors. Nine weathers.
Short read · this week's signal across the nine sectors we cover
The lead weather, because the deployer desk lives here. RPO providers, staffing firms, Employers of Record and the HR-shared-services arms of consulting and GCC operations all run AI screening for clients, and the Act makes each of them the liable deployer, not the vendor. The same advisory firms also gain a new engagement: helping clients inventory, classify and govern their AI hiring before the August date. The liability and the opportunity sit in the same sector.
The provider side of the split, and the lighter exposure. The vendors that build applicant-tracking and screening AI carry the provider obligations -- documentation, bias testing, CE marking -- but the Act deliberately does not let provider compliance discharge the deployer's duties. So the technology sector's exposure is real but bounded: build a compliant tool, and the harder, ongoing liability still sits with whoever deploys it.
High-volume, high-scrutiny hiring and a parallel governance muscle. Banks and financial firms screen at scale and already run model-risk and control functions, so the AI-hiring obligations land on an operation that understands documented, audited decision-making -- but also on one whose offshore GCCs run much of that screening from India, inheriting the deployer exposure directly.
Volume hiring is the exposure. Retail recruits at scale and seasonally, exactly the pattern that pushes employers toward automated screening to handle application volume -- and high-volume automated screening of EU-based applicants is squarely the high-risk use the Act targets. The convenience that makes automation attractive is the same feature that makes the compliance obligation unavoidable.
Workforce-critical hiring under a stricter eye. Healthcare recruits constantly and across borders, and the sector's regulatory culture means automated screening here draws particular scrutiny on fairness and documentation. The fundamental-rights framing of the Act lands hard where the workforce decision affects access to a regulated profession.
Cross-border hiring and supplier-chain workforce exposure. Manufacturers hire across multiple jurisdictions and increasingly screen with AI, so the extraterritorial reach of the Act catches any EU-facing recruitment run from a shared-services centre, wherever that centre sits. The exposure travels with the candidate, not the company's headquarters.
High-churn, high-volume recruitment and lighter but real exposure. Hospitality's constant hiring pushes toward automated screening, and where that screening touches EU-based applicants the high-risk obligations apply, even though the sector's individual decisions are lower-stakes than in finance or healthcare. Volume, not complexity, is what draws the obligation here.
Modest direct hiring exposure, mostly through outsourced administration. Real estate firms hire less at volume than retail or hospitality, so the AI-hiring exposure is lighter and concentrated where recruitment is outsourced to a screening provider -- at which point the deployer-liability question moves to that provider, and the chain of responsibility has to be mapped.
Specialised, lower-volume hiring and the lightest exposure of the nine. Energy recruits for technical, often scarce roles where human judgement dominates and automated mass-screening is least useful, so the AI-hiring obligation bites least here. The exposure is real only where the sector adopts screening AI for its higher-volume administrative and support hiring.
Five skills to master this week.
For Editor reAImagine · curated to this issue's signal · 90-day horizon
Where the operations or HR lead transitions into the AI-systems inventory lead. You cannot govern an exposure you have not mapped, so the first move is cataloguing every screening, ranking and evaluation tool and classifying which touch the EU.
Where the compliance or HR-operations analyst transitions into the AI-hiring compliance officer. The deployer obligations are distinct from the vendor's, so the skill is owning the oversight, logging and impact assessment in your own name.
Where the analyst or data lead transitions into the algorithmic-bias auditor. The Act and laws like New York's Local Law 144 require the bias test to be run and documented, so the skill is producing the audit, not assuming the tool is fair.
Where the recruiter or pipeline lead transitions into the human-in-the-loop review lead. GDPR Article 22 and the Act together make the human on the rejection a legal step, so the skill is designing review that is real oversight, not a rubber stamp.
Where the policy or technical lead transitions into the sovereign-AI-governance lead. The Gulf is writing its own rules rather than importing the EU's, so the skill is designing governance as regional policy rather than borrowed compliance.
Intelligence for your board.
Issue 014's lead is, in board terms, a liability sitting in an offshore cost centre that no one has put on the risk register. If any part of your hiring or screening touches a candidate in the EU, your operation is the deployer of a high-risk AI system under the EU AI Act -- and the deployer, not the software vendor, answers for it, with penalties up to 35 million euros or 7 percent of global turnover at the top tier and 15 million euros or 3 percent for a deployer that fails its high-risk duties. Three questions sit between you and your next AGM. Do you have an inventory of every AI screening and ranking tool in your hiring pipeline, and do you know which ones touch the EU? Do you have the deployer-side controls -- human oversight, logging, a fundamental-rights impact assessment -- in your own name, rather than relying on a vendor's CE mark? And have you prepared to the live 2 August 2026 date rather than betting on a deferral that is agreed but not yet law? The Board AI Briefing, reAImagine.work x InGovern, datelined Bengaluru and Dubai, reads each week's signal at the resolution your risk register needs. Read more at reaimagine.work/board-briefing.
What you receive
A board-ready brief tied to your sector and the workforce decisions in front of you this quarter, this fiscal year, and twelve-plus months out.
Who it's built with
Editorial by reAImagine.work, founded by Debu Mishra. Board governance practice from InGovern Research Services, founded by Shriram Subramanian. Bengaluru and Dubai.
How it lands
Approve. Appoint. Commission. Separate. Deploy. Decide. Establish. Stakes in INR or USD ranges. No theatre.