EU AI Act in HR: What You Can & Cannot Automate
For two years, every AI Act compliance deck pointed at the same date: 2 August 2026, the day the high-risk rules were supposed to bite. Five weeks before it arrived, the EU moved it. The European Parliament approved the "Digital Omnibus on AI" on 16 June 2026, the Council followed on 29 June, and the headline duties for HR-relevant AI now start on 2 December 2027.
Two wrong conclusions are doing the rounds: "AI in HR is basically illegal now" and "nothing applies until 2028, ignore it". This post sorts the tiers instead, checked against the official texts and stamped as of July 2026. None of it is legal advice; it's a map for deciding which questions to bring to a lawyer.
The Act regulates uses, not tools
The AI Act (Regulation 2024/1689) sorts AI by what you point it at, not by what it is:
- Prohibited practices: a short list of uses the EU considers unacceptable. Two of them live in the workplace.
- High-risk systems: uses listed in Annex III, allowed but wrapped in obligations. Employment is point 4, by name.
- Everything else: minimal duties, mostly transparency. Most day-to-day HR use of AI lands here.
Already banned at work, since February 2025
The prohibitions have applied since 2 February 2025. The omnibus did not loosen them; it added one, banning AI that generates non-consensual intimate imagery. The one aimed squarely at HR is Article 5(1)(f): AI systems that infer the emotions of a natural person in the workplace are banned, with a narrow exception for medical or safety reasons. Sentiment analysis on employee calls, webcam "engagement scoring", mood detection at the desk: prohibited today, not from 2027. Social scoring based on behaviour or personality traits, with unjustified consequences, is banned too (Article 5(1)(c)).
The fines here are the Act's top tier: up to EUR 35 million or 7% of worldwide turnover. The same date also switched on Article 4, which expects organisations using AI to give their staff adequate AI literacy. If a monitoring vendor's pitch includes reading feelings, that is a current problem, not a 2027 one.
High-risk means AI that judges people's jobs
Annex III, point 4 puts two families of HR use in the high-risk tier:
- Getting hired: systems for recruitment or selection, "in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates".
- Being managed: systems that make decisions on promotion or termination, allocate tasks based on individual behaviour or personal traits, or monitor and evaluate performance and behaviour.
The trigger is the decision. Article 6(3) carves out systems doing narrow procedural or preparatory work without "materially influencing the outcome of decision making", but it closes the moment a system profiles people: profiling is always high-risk. If a tool scores, ranks, filters or flags humans, assume Annex III applies, whatever the brochure calls it.
This is the tier whose start date just moved: 2 December 2027 for standalone Annex III systems, 2 August 2028 for AI embedded in regulated products. Fixed dates, not "when the standards are ready". But a delay is not a repeal. The scope did not shrink by a word, and sixteen months disappear faster than a procurement cycle.
You don't have to build it to be on the hook
Most obligations people quote fall on providers, the companies building the AI. Article 26 puts a separate set on deployers: anyone using a high-risk system professionally. Buy someone's CV-screening tool and, from December 2027, you carry duties of your own:
- Use it as instructed, per the provider's instructions for use.
- Assign real human oversight, to named people with "the necessary competence, training and authority". A recruiter rubber-stamping model rankings at two hundred CVs an hour does not pass.
- Feed it the right data. To the extent you control the input, it must be "relevant and sufficiently representative" for the system's purpose.
- Monitor it, and report serious incidents to the provider and the market surveillance authority.
- Keep the logs for at least six months.
- Tell your people first. Article 26(7): before using a high-risk AI system at the workplace, employers must inform affected workers and their representatives.
Deployer breaches carry fines up to EUR 15 million or 3% of turnover (SMEs pay the lower of the two caps). Small does not mean exempt.
The tier where most of us actually live
The part the scare-marketing skips: most of what a small company does with AI in HR sits in no annex at all. Drafting a job ad or a policy. Summarizing a survey's open comments. Q&A over your own handbook. An assistant acting on instruction under a human's permissions: file this request, pull that report, prepare the onboarding checklist. None of that judges anyone. The human decides; the AI fetches and types.
There is a legal point in that pattern. The trigger is influence over the employment decision: an assistant that retrieves an absence report has decided nothing, while a tool turning the same report into an automatic warning letter has crossed into Annex III (and was already in trouble under GDPR Article 22, which limits purely automated decisions). Human-in-command is what holds you in the light-touch tier, a legal property, not a soft cultural one.
Hygiene still applies. Article 50's transparency duties kept their 2 August 2026 date: tell people when they are dealing with an AI system unless it is obvious, label synthetic content. And watch scope creep: the drafting assistant someone quietly starts using to rank candidates has changed tier without changing vendor.
Six questions for anyone selling you "AI-powered HR"
- Which tier does each feature sit in, and will you put that classification in writing?
- Does anything score, rank, filter or flag people? If yes, what is your Annex III plan and by when?
- Where are your instructions for use? Our Article 26 duties start from them.
- Can we export the system's logs and keep them six months?
- Can a human overrule every output, and does the product record who did?
- What happens when the AI is asked to do something the asking user is not allowed to do?
A vendor who answers "it's all been delayed anyway" has told you something more useful than they intended.
Where we landed (disclosure: we make one of these)
We build SquadBear, an HR tool with AI assistants attached, so we ran this classification on ourselves. Our answer is the light-touch tier, held there by design: assistants operate the system under the permissions of the human who connected them, and they draft, fetch and file but issue no verdicts about people. The Bradford factor report computes a number, shows it to a human and stops; nothing fires at a threshold. Data stays where it lives, queried in place rather than pooled into someone's cloud. We wrote both up long before the omnibus, as product philosophy; it turns out to double as the compliance posture.
To audit your own setup, ask any connected assistant the tier question in miniature:
"What can you do in this workspace on your own, and which actions always need a human decision first?"
The map, folded
As of July 2026: inferring feelings at work has been banned since February 2025. Anything that decides or materially shapes hiring, firing, promotion, task allocation or monitoring is high-risk, and using it brings duties of your own from 2 December 2027. Everything else, which is most of it, needs a human in command and a little transparency. Dates have moved once and could move again: check the Commission's AI Act page before relying on one. The shape of the law is settled, though, and it is friendlier to honest automation than the panic suggests.