Using AI to monitor, score or manage employees? Learn what the EU AI Act already bans, what becomes high-risk, and when employers must inform staff.

01

One workplace AI practice is already prohibited

AI is moving beyond recruitment. Businesses are starting to use it to analyse performance, allocate work, monitor behaviour, recommend promotions and identify employees who may need additional support.

Since 2 February 2025, the AI Act has prohibited AI systems used to infer a person's emotions in the workplace, except where the use is intended for medical or safety reasons.

This can include systems attempting to infer emotions such as anger, happiness or frustration from biometric data such as facial expressions or voice. The European Commission's prohibited-practices guidance includes examples involving workers' voices or video.

This prohibition is already law. It should not be confused with the later rules for high-risk workplace AI.

02

Which workplace AI can become high-risk?

Annex III identifies several employment-related uses that can be high-risk. These include AI intended to recruit or select candidates, influence employment terms, promotion or termination, allocate tasks based on individual behaviour or characteristics, or monitor and evaluate performance or behaviour.

Not every AI tool used by HR is automatically high-risk. Article 6 includes exceptions where a listed system does not pose a significant risk and does not materially influence decision-making, such as some narrow procedural or preparatory tasks. Profiling systems listed in Annex III remain high-risk.

The Commission's current draft classification guidance illustrates the distinction. A system that scores or ranks employees may be high-risk. A writing assistant that only improves the wording of an assessment after a manager has already made the decision may not be.

Those examples are draft Commission guidance, not binding law. The consultation closed on 23 July 2026, and final guidelines are expected by the end of 2026.

03

When do employers have to tell employees?

Article 26 introduces a specific workplace information requirement. Before putting a high-risk AI system into service or using it in the workplace, a deployer who is an employer must inform affected workers and workers' representatives that they will be subject to the system.

This requirement does not replace duties under employment, consultation or data protection law. For Annex III workplace AI, the high-risk rules are scheduled to apply from 2 December 2027 following the 2026 changes to the implementation timetable.

The Article 26 workplace information requirement is therefore not yet generally applicable to Annex III employment systems. Employers still have a useful preparation window.

04

GDPR can already require transparency

Waiting until 2027 does not mean workplace AI is currently unregulated. If a system processes employee personal data, existing GDPR requirements can already apply.

The Irish Data Protection Commission says people must receive clear information about automated decision-making and profiling where relevant, including meaningful information about how decisions are made and their significance and consequences.

Article 22 also restricts certain decisions based solely on automated processing where they produce legal or similarly significant effects. Exceptions exist, but suitable safeguards may be required, including human intervention and the ability to challenge a decision.

AI Act compliance should therefore be assessed alongside data protection, not in isolation.

05

Four things employers should do now

  1. Inventory workplace AI. Identify AI used in HR, management, scheduling, productivity, monitoring and recruitment systems. Do not look only for products marketed as AI.
  2. Check what each system influences. Ask whether it assists an administrative process or affects decisions about a person. Intended purpose and actual use matter more than the product name.
  3. Review employee transparency. Check what employees currently know about monitoring, profiling and decision-support systems that process their personal data.
  4. Put HR AI through governance review. Assess purpose, data, risk, human oversight and employee impact before enabling a new feature.
06

Blanche perspective

The biggest mistake with workplace AI is treating it as another software feature.

A tool that helps draft an email and a system that scores an employee's performance may both contain AI, but they create very different risks.

The practical question is not simply whether HR uses AI. It is: what does the AI influence about a person? That question should sit at the centre of every workplace AI review.

S

Sources

Primary and authoritative sources used for this Insight.

  1. Regulation (EU) 2024/1689, current consolidated version (binding EU law)
  2. European Commission: AI Act regulatory framework and implementation timetable
  3. European Commission: Draft guidelines on the classification of high-risk AI systems, 19 May 2026
  4. EU AI Act Service Desk: Annex III employment, workers' management and access to self-employment
  5. Data Protection Commission: The right to be informed under Articles 13 and 14 GDPR
  6. Data Protection Commission: Automated decision-making and profiling under Article 22 GDPR
Share this Insight