Start free trial of Lex HR →

EU AI Act and HR: what employers must do

How the EU AI Act classifies recruitment, monitoring and people-management systems as high risk, which obligations fall on employers as deployers, and the compliance deadlines that matter for HR.

Last updated 3 September 2026

The EU AI Act is the first comprehensive AI law anywhere, and employment is one of the areas it treats most strictly. If your organisation recruits, manages or monitors people in the EU — even from the UK or US — parts of it apply to you.

This guide explains what the Act means for HR specifically: which systems are caught, what an employer has to do as a deployer, and how the timeline works.

Why HR is singled out

The Act works on a risk pyramid. A small number of practices are banned outright; a larger group is classified high risk and carries substantive obligations; the rest is subject to transparency rules or nothing at all.

Annex III of the Act lists employment, worker management and access to self-employment as a high-risk category. In practice that covers:

  • systems used to place targeted job advertisements or filter applications
  • systems that analyse or score candidates, including CV parsers and ranking tools
  • systems used to make or materially inform decisions on promotion, termination and task allocation
  • systems that monitor or evaluate performance and behaviour at work

Two bans matter directly to HR: emotion-recognition systems in the workplace, and biometric categorisation that infers protected characteristics. If a vendor offers "engagement" or "sentiment" scoring from webcam or voice data in a work context, treat that as a prohibited-practice question, not a procurement question.

Employers are "deployers", not "providers"

Most employers buy AI rather than build it. The Act calls the builder a provider and the organisation using it a deployer, and it puts different duties on each. Deployer duties are lighter but real:

  • Use the system as intended. Follow the provider's instructions for use. Improvising a new use case can flip you into provider obligations.
  • Assign human oversight. Oversight must be given to people with the competence, training and authority to override or ignore the system's output. A recruiter who cannot reject the ranking is not oversight.
  • Ensure input data is relevant and representative to the extent you control it. Feeding an unrepresentative internal dataset into a screening tool is your problem, not the vendor's.
  • Monitor operation and keep logs. Retain automatically generated logs where they are under your control, generally for at least six months.
  • Inform affected workers. Before putting a high-risk system into use in the workplace, employers must inform workers and their representatives that they will be subject to it.
  • Tell individuals when asked. People subject to a decision made or informed by a high-risk system have a right to a meaningful explanation.

If you significantly modify a system, or put your own name or trademark on it, you can become the provider — with the full conformity-assessment burden attached. This catches employers who fine-tune models on their own HR data.

Fundamental-rights impact assessments

Public bodies and certain private operators deploying Annex III systems must complete a fundamental-rights impact assessment (FRIA) before first use, covering the process the system is used in, the categories of people affected, the specific risks of harm, and the human-oversight and remedy arrangements. Even where an FRIA is not strictly required, it is the most useful single document to produce: it forces the questions a regulator or tribunal will ask later. Where you already run a GDPR data-protection impact assessment, run the two together rather than in parallel.

AI literacy is already in force

The AI literacy obligation applies to providers and deployers alike: staff dealing with the operation and use of AI systems must have a sufficient level of AI literacy, taking account of their technical knowledge and the context of use. For HR that means recruiters, HR business partners and line managers who touch AI tools need documented training — not just the IT team.

What to do now

  1. Inventory. List every AI or algorithmic system touching recruitment, performance, allocation of work, monitoring or termination, including features inside your ATS, HRIS and productivity suite.
  2. Classify. Mark each as prohibited, high risk, limited risk or minimal risk, and write down the reasoning.
  3. Check the ban list first. Emotion recognition and biometric categorisation at work need to stop, not be documented.
  4. Get provider documentation. Ask for the instructions for use, the declaration of conformity and the CE marking for anything high risk. If a vendor cannot produce them, that is a contract issue.
  5. Write the oversight model down. Who can override, on what basis, and how is the override recorded?
  6. Consult and inform. Brief works councils and employee representatives early; in several member states, monitoring and evaluation tools require consultation under national law regardless of the AI Act.
  7. Train. Deliver and record AI literacy training for everyone using these systems.

Does it apply to UK employers?

Yes, in two situations. First, if you deploy an in-scope system and are established in the EU or your workers are located there. Second, if the output of the system is used in the EU. A UK-headquartered employer screening applicants for a Dublin or Amsterdam office is in scope for those hires. UK-only hiring is governed instead by UK GDPR and the Equality Act 2010 — different rules, similar controls.

The practical takeaway

The Act does not ban AI in HR. It bans a narrow set of intrusive practices, and it demands that everything else be documented, overseen by a trained human, and explained to the people it affects. Employers who already run bias audits and keep a decision log are close to compliant; employers who cannot say which tools are in use are not.

This guide is general information for HR professionals, not legal advice. Take advice on your own facts before acting.

Related guides

The Weekly Briefing

Get AI & HR insights every week

One email a week with the latest cases, regulations and practical guidance on AI in the workplace.

Protected by reCAPTCHA. Privacy & Terms.