The EU AI Act – What’s already in force and what’s to come

Article written by HR Director, Michael George, who has worked previously for business including NOKIA, Telefonica and Comcast.

The EU has introduced the world’s first comprehensive law on AI. It singles out employment as one of the areas where AI can do the most harm.

With organisations investing heavily in both generative and agentic AI to help them hire, manage and develop people, and to automate much of the day-to-day running of HR, the EU AI Act could have a significant impact on these newly tech-enabled practices.

AI is already being used to write job adverts, read and sort CVs, schedule interviews, answer employee questions on policy and pay, recommend training, flag employees at risk of leaving, and track productivity and performance. Much of it arrives quietly, switched on as part of a routine system upgrade, rather than through a deliberate decision by HR.

What’s already in force today

Several existing laws already apply, and candidates and workers are already taking legal action.

Data protection law is the first line of defence. Under GDPR, people in the EU have the right not to be subject to important decisions made purely by a computer, such as an automatic rejection with no human involved, unless strict conditions are met. Organisations must also carry out a formal risk assessment before using technology that could seriously affect people. The UK has its own version, recently updated by the Data (Use and Access) Act 2025. It gives organisations a little more flexibility, but still lets people ask for an explanation, ask for a human to review the decision and challenge it.

Equality law is the second. It makes no difference whether a person or a piece of software made the discriminatory decision. If a tool treats people unfairly because of their age, sex, race or disability, the employer is responsible.

Germany goes further than most. Under its Works Constitution Act, an employer must get the agreement of its works council before introducing any technology that is capable of monitoring employees’ behaviour or performance. The legal test is whether the technology could be used to monitor people, not whether it is actually used that way. German courts have interpreted this very broadly, so in practice most HR software with AI features needs works council approval before it goes live. A works council can stop a rollout until an agreement is reached. Germany updated this law in 2021 to refer to AI directly. Works councils can now bring in an outside expert to assess AI tools, and they have a say when AI is used to set the rules for hiring, transfers or dismissals.

Some of the new EU AI Act is also already law. Since February 2025, it has been illegal in the EU to use AI that tries to read how employees or candidates are feeling from their face, voice or body language, except for medical or safety reasons. A video interview tool that scores a candidate on how enthusiastic or nervous they appear is now banned.

Since the same date, every organisation using AI tools has had a duty to help its employees understand these tools through training, guidance and clear rules. And since August 2026, people must be told when they are dealing with a chatbot rather than a person.

Employment claims involving AI are already starting to happen, and they are not limited to the EU. In the UK, Uber Eats driver Pa Edrissa Manjang brought a race discrimination claim after he was removed from the platform when its facial recognition checks repeatedly failed to recognise him. The Equality and Human Rights Commission backed the case, and Uber Eats settled the case before it reached an employment tribunal in 2024. In the US, the Equal Employment Opportunity Commission took action against iTutorGroup, whose recruitment software automatically rejected older applicants; the company paid $365,000 to settle. CVS settled a claim brought by a job applicant under Massachusetts’ lie detector law over an AI video interview tool. A complaint has been filed against Intuit and HireVue on behalf of a deaf Indigenous applicant who says an AI interview process discriminated against her.

The most significant case is Mobley vs. Workday. A US court has allowed a nationwide claim to go ahead on behalf of job applicants aged 40 and over, who allege that Workday’s AI screening tools unfairly rejected them. The court also accepted that Workday, as the software supplier, could potentially be held responsible, not just the employers using it. The allegations have not been proven and the case is ongoing, but it has the potential to change how HR technology suppliers design and stand behind their software.

The EU AI Act: What it is, when it comes in and what it prohibits

The EU Artificial Intelligence Act became law on 1 August 2024, after three years of negotiation between the European Commission, the European Parliament and EU governments. It is a regulation, not a directive. That means it applies directly in every EU country and doesn’t need to be turned into national law, much like GDPR.

The Act categorises AI into four groups according to how much harm it could do:

  • Unacceptable risk (banned outright): Systems that seriously threaten people’s rights or manipulate their behaviour. Examples include social scoring, building facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage, trying to read how people feel at work, and hidden techniques designed to influence behaviour.
  • High risk (strictly regulated): Systems that affect people’s safety or their access to important opportunities in life. These are allowed, but only with strict safeguards. Examples include critical infrastructure, exam grading, biometrics, and recruitment and employment software. This is where most HR technology sits.
  • Limited risk (transparency required): People must know when they are talking to, or looking at something made by, AI. Chatbots must identify themselves, and deepfakes and AI-generated text, images and video must be clearly labelled.
  • Minimal risk (no new rules): Everything else, which is free to use with no new obligations under the Act. This covers most everyday AI, such as spam filters and video games.

The banned list has applied since February 2025. It prohibits AI that manipulates people in harmful ways or exploits their age, disability or financial situation. It also bans “social scoring”, where people are rated on their behaviour or personality in ways that lead to unfair treatment, and predicting whether someone will commit a crime based only on their profile. Building facial recognition databases by scraping images from the internet or CCTV is banned, as is using people’s physical features to guess their race, religion, politics, sexuality or trade union membership. Live facial recognition by police in public places is banned apart from narrow exceptions. The ban on reading how people feel at work also sits on this list. From December 2026, AI that creates fake sexual images of real people will be added.

For HR, the most important part is the high-risk list. The Act names employment as a high-risk area and covers AI used to:

  • target job adverts
  • screen and rank applications
  • assess candidates
  • make or influence decisions about promotion, pay terms and dismissal
  • allocate work based on people’s behaviour or personal traits
  • monitor or rate performance

In practice, this captures a large share of the AI now built into HR systems.

Suppliers of HR tools will have to prove their systems are accurate, tested for bias, secure and properly documented, and register them in an EU database before selling them. Employers using the tools will have to follow the supplier’s instructions and put trained people in charge of overseeing decisions, with real authority to overrule the system. They will also need to check that any data put into the tool is relevant and fair, keep records, tell employee representatives and employees before introducing the tool, and explain decisions to individuals who ask.

These high-risk rules were originally due in August 2026. In July 2026, the EU passed an amending law that delays them to 2 December 2027, giving businesses and regulators more time to prepare. The same amendment softened the employee training duty slightly: organisations now have to take reasonable steps to build understanding rather than guarantee a particular level of knowledge.

The new Act builds on the existing rules rather than replacing them. GDPR protects people’s data and their right to challenge computer-made decisions. The AI Act adds requirements for how the tool itself is designed, tested and supervised before it is ever used. Equality law punishes discrimination after it happens; the AI Act requires organisations to check for bias before it happens. In Germany, the works council already decides whether a monitoring tool can be introduced. The AI Act now gives works councils far more information to work with, because suppliers must document how their tools work, what their limits are and how they have been tested. It also makes informing workers a legal duty across the whole EU, not only in countries with strong works council traditions.

Which countries it covers, and will the UK follow?

The Act applies across all 27 EU member states. It is expected to extend to Norway, Iceland and Liechtenstein through the European Economic Area agreement, although that hasn’t been finalised. Each country has to appoint national regulators to enforce it. Many missed the August 2025 deadline to do so, but that doesn’t change businesses’ obligations.

The UK is unlikely to adopt the EU AI Act. Since Brexit, the UK has usually relied on existing regulators such as the Information Commissioner’s Office to apply current law to AI rather than creating a single AI law. The government has talked about AI legislation, but no AI bill has been introduced in Parliament.

That does not mean UK employers can ignore it. Like GDPR, the AI Act reaches beyond the EU’s borders. It applies to any organisation, wherever it is based, whose AI is used to make decisions about people in the EU. A UK company hiring into Dublin, managing staff in Amsterdam or running a European shared service centre is very likely in scope. Many global employers will also choose to apply the EU standard everywhere, simply because running two different hiring processes isn’t practical.

The likely impact on the market, and the cost of getting it wrong

The Act will change how HR technology is built, bought and used. The likely impacts include:

  • Unofficial AI use will need careful governance. Managers pasting CVs into free AI tools to shortlist candidates may be the biggest blind spot of all. Organisations will need clear policies, management awareness and training, and consequences for misuse.
  • Buying HR technology will change. Procurement teams will need to ask for evidence of bias testing, clear documentation and legal compliance. Contracts will need to set out clearly who carries the commercial liability if a tool fails or breaches the law.
  • Employee monitoring faces its biggest test. Software that tracks productivity, activity or performance falls into the high-risk category and will face the most scrutiny from regulators and works councils.
  • People decisions will become human-led again. Processes will move away from AI making decisions towards AI supporting the people who make them, with more emphasis on low risk uses such as drafting job adverts or scheduling interviews. The requirement for human oversight will be tested. A manager clicking “approve” on a long list of AI shortlists will not count as real oversight unless that person understands the tool and has the time and authority to question it.
  • HR will need new capabilities. Demand will grow for HR technology specialists who understand both the systems and the rules around them, and who can test, explain and defend the tools an organisation uses.
  • Works councils and unions will gain a stronger voice. Expect more collective agreements on how AI is used at work, especially in Germany, the Netherlands and the Nordics.
  • Candidates will start asking questions. More applicants will ask whether AI was used in decisions about them and request an explanation, adding to the data requests HR teams already handle. Recruitment agencies and outsourced recruitment providers using AI screening are in scope too, and their clients will expect proof of compliance.
  • Training demand will increase. The legal duty to build AI understanding among employees will drive strong demand for practical, role-specific AI training for managers and HR teams.
  • AI will become a board-level issue. AI use in people decisions will increasingly appear on risk registers and board agendas, with HR leaders expected to answer for it.
  • HR technology products will change, and the supplier market will consolidate. Proving that a tool is fair, accurate and explainable takes time, specialist expertise and money. The largest suppliers have been preparing for some time; Workday, for example, says it already operates to an “EU AI Act-ready” standard. Smaller suppliers may struggle to absorb the cost, and I’d expect more of them to be acquired by larger players. Tools that read how people feel are already banned in Europe. Tools that give a candidate a score without being able to explain why will become much harder to sell. Some suppliers may switch features off in Europe or offer a slimmed-down EU version, which creates headaches for global organisations that want consistent processes. At worst, some products may be withdrawn from the European market altogether. Either way, compliance costs are likely to show up in licence prices.
  • A new market for AI auditors will open up. Just as GDPR created a boom for data protection consultants, expect growth in independent and in-house AI auditors offering checks, bias testing and certification of HR tools.
  • The EU rules may become the global standard. New York City already requires bias audits of hiring tools and several US states have passed their own laws, so many multinationals will simply adopt the EU standard everywhere.

The cost of getting it wrong

This comes in several forms. Under the AI Act, fines can reach 35 million euros or 7% of global annual turnover for using a banned practice, and 15 million euros or 3% for most other breaches. GDPR fines of up to 20 million euros or 4% of turnover sit alongside these.

Discrimination claims carry their own costs. In the UK, compensation for discrimination is uncapped, and the US cases show how quickly a single claim can grow into a class action covering thousands of applicants. In Germany, a works council can stop a system going live, which means wasted licence fees and delayed projects. There’s also the cost of switching off or replacing a tool partway through a contract, and of revisiting the decisions it influenced. The hardest to measure is reputation: no employer wants to be known as the company whose AI rejected candidates unfairly.

Do we need to undo the investment we’ve made in AI?

This is the question many HR leaders and boards are asking. My view is no, but much of it will need to be revisited.

The Act doesn’t ban AI in recruitment or people management. It doesn’t stop organisations using technology to screen applications, match skills or support workforce planning. What it does is end the era of using these tools without being able to show how they work, whether they are fair and who is accountable for them. The investment that will hold its value is in tools that are transparent, tested and properly supervised. The investment most at risk is in tools that can’t explain themselves, that read how people feel or that were switched on without anyone in HR fully understanding what they do.

For many organisations, the bigger task is governance rather than technology. That means knowing where AI is being used across people process, including features quietly switched on inside existing systems. It means asking suppliers hard questions and getting the answers in writing, involving employee representatives early, and building enough understanding within HR to question the tools rather than simply trust them.

The delay to December 2027 gives organisations valuable time to get this right, and it shouldn’t be a reason to pause. It is a chance to review the tools already in place, understand how they work and put the right checks around them. It is also a rare opportunity for HR to lead rather than react, because HR understands the people, the processes and the risks better than anyone else in the organisation. The aim is not to undo the progress made with AI, but to make sure it is fair, transparent and robust enough to stand up to scrutiny from employees, candidates and regulators alike. Organisations that start now will be well placed when the rules take effect, and better still, they will have earned the trust of the people their tools affect.

Leave a Reply

Your email address will not be published. Required fields are marked *