The risk tiers

The AI Act does not regulate the technology. It regulates the purpose. The same language model can sit on one tier when it drafts job ad copy and on another when it scores applications. Four tiers: prohibited practices, including emotion recognition in the workplace. High-risk systems with extensive duties, including most decision systems in the employment context. Systems with transparency duties, such as chatbots that must identify themselves as AI. And everything else, for which no particular duties apply. For HR teams the practical question is therefore never "do we use AI" but "what does the tool do with people".

Which HR uses count as high-risk

High-riskCandidate selection and evaluation of applicationsScreening, ranking, shortlisting, targeted job advertising to individuals. Annex III, point 4(a).
High-riskDecisions within the employment relationshipPromotion, termination, task allocation based on behaviour, monitoring and evaluation of performance. Annex III, point 4(b).
Not high-riskText drafts without reference to a personJob ads, policy drafts, general onboarding texts. Usually minimal risk, as long as no pre-selection hangs off them.

Prohibited, not merely high-risk: systems that infer emotions in the workplace, except for medical or safety reasons. That covers, for example, tools that want to read mood or stress in video interviews.

Duties of the deployer

For most HR teams the picture is this: the system provider carries the heavy duties, risk management, technical documentation, conformity assessment, registration in the EU database. The employer as deployer has its own, smaller duties, and they are concrete:

  1. Use in line with the provider's instructionsDeploy the system as the provider's instructions for use foresee, not beyond.
  2. Human oversightNamed people with the competence and authority to supervise the system and intervene. No automated decision without a human.
  3. Informing those affectedEmployees and applicants learn that a high-risk system is in use.
  4. Informing the works councilBefore putting the system into service, named explicitly in the Act. This lines up with co-determination under Section 87 of the Works Constitution Act (BetrVG).
  5. Keeping logsAt least six months, where the system generates them.
  6. AI literacyUsers are trained, and it is documented. Applies since February 2025 to all AI systems, not only high-risk.
  7. Data protection impact assessmentThe Act refers to the GDPR duty where it applies.

Provider or deployer: the difference that counts

If you use a vendor's tool, you are a deployer. If you build your own system, substantially modify an existing one or offer it under your own name, you become a provider yourself, with conformity assessment, registration and technical documentation. For HR teams that means: your own prompts in Copilot or ChatGPT Enterprise do not make you a provider. A model trained on your own applicant data does. Anyone in between, for instance with a heavily customised tool from a small vendor, should settle that with a law firm before the rollout, not after. For international groups, note that the deployer is the entity using the system in the EU, so a tool selected by headquarters outside the EU still makes the German subsidiary the deployer.

Deadlines

The Act applies in stages. Three dates matter for HR teams:

2024Feb. 2025Aug. 2025Aug. 2026Aug. 2027
Prohibitions, AI literacy duty
Transparency duties, governance
High-risk duties in the employment context
Transition periods for high-risk in regulated products

Anyone introducing a screening tool today plans with the full high-risk duties. Anyone already using one has until August 2026 to bring the frame up to date, and should not leave that to the last month, because the works council agreement alone takes two to four months.

Relation to the works council agreement

A works council agreement on AI should, for high-risk uses, refer explicitly to the AI Act classification and the deployer duties, so that the works council and the workforce know that additional obligations apply: who exercises human oversight, how those affected are informed, where the logs are kept. The duty to inform the works council under the Act and the co-determination right under Section 87 BetrVG run together here, not side by side. Details on the agreement itself are under The Works Council AI Agreement, the data protection side under GDPR and AI in HR.

Free · Excel template

AI register template for HR uses

A table to record and document your AI use cases by risk tier: use case, tool, data, tier under the AI Act, deployer duties, owners, status of the works council agreement. The basis for the works council, the data protection officer and any audit.

You join the HR Briefing list on this topic. No sharing, unsubscribe anytime.

Frequently asked questions

From when do these duties apply?

The AI Act applies in stages. Prohibitions and the AI literacy duty since February 2025, transparency duties since August 2025, the full high-risk duties for the employment context from August 2026. Anyone introducing a screening tool today plans with the high-risk duties.

Does this affect small companies too?

Yes. The AI Act does not distinguish by company size but by the risk tier of the use. A company with 60 employees that pre-sorts applications with AI is deploying a high-risk system.

Are we a provider or a deployer?

If you use a vendor's tool, you are a deployer. If you build your own system or substantially modify an existing one, you become a provider with considerably more duties. Your own prompts do not make you a provider. A model you trained yourself does.

Does a language model like ChatGPT count as high-risk?

The model itself does not. What decides is the purpose. A language model used to score applications is a high-risk system in the employment context. The same model used for job ads is not.

What about the AI literacy duty?

Since February 2025 companies must ensure that employees who use AI systems are adequately trained. For HR teams that means training before use, documented. It belongs in the works council agreement and the policy.