Using AI in HR: 7 Actions to Comply with the AI Act 

Artificial intelligence (AI) is now involved in almost every stage of the employee lifecycle: drafting job postings, screening CVs, conducting video interviews, supporting internal mobility, delivering training, evaluating performance, and workforce planning. While these applications can significantly improve HR efficiency, they also expose organizations to risks related to discrimination, lack of transparency, excessive monitoring, and decisions that are difficult to challenge. 

The AI Act, the European Union’s regulation on artificial intelligence, governs the development, commercialization, and use of AI systems within the EU. It adopts a risk-based approach: the greater the potential impact on fundamental rights, the stricter the applicable requirements. 

In the HR domain, certain AI systems are explicitly classified as high-risk under the AI Act. As a result, organizations must move beyond a simple generative AI usage policy. In practice, they need to identify their AI systems, determine their role and associated obligations, assess suppliers, train users, and maintain evidence of compliance. 

This article outlines seven practical actions to structure an AI compliance program for HR. 

A note on timing 

The AI Act’s requirements are being implemented gradually following its entry into force on August 1, 2024: 

  • Prohibited practices and AI literacy obligations have applied since February 2, 2025. 
  • Rules relating to general-purpose AI models and EU and national governance frameworks began to apply on August 2, 2025. 
  • Most provisions become applicable on August 2, 2026, including transparency requirements. 
  • Certain obligations follow a separate schedule. This is notably the case for high-risk AI systems listed in Annex III of the AI Act, whose specific obligations become applicable from December 2, 2027. 

Organizations should therefore verify the compliance timeline applicable to each AI system and monitor regulatory developments. 

Why Is AI in HR Subject to Increased Scrutiny Under the AI Act? 

AI systems used to recruit, evaluate, assign, or monitor workers may be classified as high-risk because their outputs directly affect access to employment and working conditions. 

Annex III of the AI Act specifically covers AI systems intended to: 

  • Recruit or select candidates; 
  • Target job advertisements; 
  • Analyze or filter applications; 
  • Assess candidates during recruitment processes; 
  • Make decisions regarding working conditions; 
  • Decide on promotions, internal mobility, or termination of employment; 
  • Allocate tasks based on behavior or personal characteristics; 
  • Monitor or evaluate worker performance and conduct. 

However, an HR tool incorporating AI is not automatically classified as high-risk. Classification depends on its purpose, actual operation, and influence on decision-making. 

For example, an assistant that merely corrects spelling mistakes in a job posting presents a different level of risk than a system that automatically ranks candidates according to their likelihood of success. 

This exception must nevertheless be handled carefully. In certain circumstances, a system operating within a high-risk area may not itself be considered high-risk if it performs only a limited procedural task, enhances the outcome of a human activity already completed, detects deviations without replacing human assessment, or performs preparatory work for an evaluation process. Such assessments should be documented. In addition, any system performing profiling of natural persons remains classified as high-risk. 

Classification of Common HR AI Use Cases 

Use Case Likely Risk Level Key Concern 
Job posting spell-checking Limited Data confidentiality 
Job description generation Limited to moderate Stereotypes and human validation 
Candidate information chatbot Transparency obligations Inform users they are interacting with AI 
Automated CV screening or ranking Likely high-risk Discrimination and access to employment 
Candidate scoring Likely high-risk Explainability and human oversight 
Task allocation based on behavior Likely high-risk Working conditions and surveillance 
Automated performance evaluation Likely high-risk Individual decisions and contestability 
Emotion analysis during interviews Prohibited use, except for medical or safety reasons Fundamental rights impact 
Occasional use of generative AI by recruiters Depends on usage Personal data, bias, and overreliance 

Classification should not rely solely on a product’s marketing description. Organizations must assess the intended purpose, input data, outputs, and how HR teams actually use the system. 

Action 1: Create an Inventory of All AI Systems Used in HR

The first step is to establish a centralized inventory of all AI systems used within HR, including purchased tools, AI features embedded in existing software, and unauthorized or unofficial uses.

An organization cannot bring AI systems into compliance if it is unaware of their existence. Yet many AI-related activities fall outside traditional procurement and IT processes.

For example, a recruitment platform may activate a new automated ranking feature without the knowledge of the DPO or compliance manager. Likewise, a recruiter may upload CVs into a public generative AI assistant to obtain a summary.

The AI inventory should cover all AI systems and models used across the organization, including:

  • HR software incorporating algorithmic functionality;
  • Recruitment SaaS platforms;
  • Talent management and internal mobility solutions;
  • Generative AI assistants;
  • Video or voice analysis tools;
  • Automated workforce planning systems;
  • Productivity monitoring tools;
  • Internally developed solutions;
  • Pilot projects and proof-of-concept initiatives;
  • Unofficial or unapproved AI uses, often referred to as Shadow AI.

Information to Document for Each System

For each system, the organization should, at a minimum, record:

  1. The name of the system and its provider;
  2. Its intended purpose;
  3. The individuals affected;
  4. The data processed;
  5. The outputs produced;
  6. The decisions influenced;
  7. The business owner;
  8. The authorized users;
  9. The countries where it is deployed;
  10. Interfaces with the information system;
  11. The presumed risk level;
  12. The system status (project, testing, production, or retired).

Best Practice

Include AI-related questions in procurement forms, supplier reviews, GDPR assessments, and project management processes. This allows the inventory to be continuously updated rather than reconstructed once a year.

Action 2: Determine the Organization’s Role and the Risk Level of Each Use Case

Organizations must determine whether they act as a provider, deployer, importer, or distributor, and then classify each system according to the AI Act’s risk categories.

In most HR projects, the employer will act as a deployer, meaning an organization that uses an AI system under its authority. However, it may become a provider if it develops a system, places it on the market, operates it under its own name, or substantially modifies it.

This distinction is critical because the obligations imposed on a provider of a high-risk AI system are significantly more extensive than those applicable to a deployer.

The Four Risk Categories to Assess

1. Prohibited Practices

Since 2 February 2025, certain AI practices have been prohibited.

In the workplace context, one of the most sensitive areas concerns the use of systems designed to infer a person’s emotions at work, except where the use is justified for medical or safety reasons.

Any solution claiming to measure a candidate’s motivation, enthusiasm, sincerity, or similar traits based on facial expressions or voice analysis should therefore trigger immediate concern.

2. High-Risk Systems

Candidate screening, applicant scoring, performance evaluation, and algorithmic task allocation may fall within this category, in accordance with Annex III of the AI Act.

3. Systems Subject to Transparency Obligations

A recruitment chatbot that interacts directly with a candidate must, under the circumstances specified by the Regulation, enable that individual to understand that they are interacting with an AI system.

4. Limited or Minimal-Risk Systems

A tool that simply rewrites an HR email may fall into a lower-risk category. However, this does not exempt the organization from complying with GDPR, confidentiality requirements, employment law, security obligations, and internal policies.

Documenting the Classification Decision

The AI system assessment record should make it possible to answer the following questions:

  • Does the system contribute to a decision affecting an individual?
  • Does it influence access to employment, promotion, or training?
  • Does it carry out ranking, recommendation, or profiling activities?
  • Are its outputs genuinely optional for users?
  • Can individuals challenge the outcome?
  • Does the system analyze behavior, voice, facial characteristics, or emotions?
  • Does an internal modification alter its original intended purpose?
  • Does the organization possess sufficient information from the provider to justify the classification?

A purely formal human review is not sufficient to reduce risk. If recruiters systematically follow rankings generated by the tool, the system effectively exerts a decisive influence over the final decision.

Action 3: Conduct a Combined AI Act, Fundamental Rights, and GDPR Impact Assessment 

An impact assessment should simultaneously evaluate regulatory risks, potential infringements of fundamental rights, data protection concerns, and business implications. 

The AI Act and the GDPR are complementary regulations. As a result, an AI system may comply with certain technical requirements of the AI Act while still processing personal data in a manner that is not compliant with the GDPR. 

For sensitive HR use cases, the assessment should cover, in particular: 

  • The risk of direct or indirect discrimination 
  • Biases in training or evaluation data 
  • Performance disparities affecting different individuals or groups 
  • Lack of transparency in ranking or scoring criteria 
  • Excessive data collection 
  • Use of sensitive personal data 
  • International data transfers 
  • Retention of applications and assessment results 
  • Data security 
  • The risk of automated decision-making under Article 22 of the GDPR 
  • Available remedies and correction mechanisms 
  • The psychological or social impact of monitoring activities 

Is a Data Protection Impact Assessment (DPIA) Required? 

A Data Protection Impact Assessment (DPIA) is required when processing is likely to result in a high risk to the rights and freedoms of individuals. 

Candidate scoring systems, behavioral analysis tools, and employee monitoring solutions are likely to meet this threshold. The assessment should be conducted before deployment and updated whenever the system, the data used, or the conditions of use change. 

What About a Fundamental Rights Impact Assessment? 

The AI Act requires, in specific circumstances, a fundamental rights impact assessment for certain deployers of high-risk AI systems. This obligation notably applies to some public sector bodies and certain private entities providing public services. 

A typical private company should therefore not automatically assume that it is subject to this formal requirement for all HR projects. Nevertheless, adopting a similar methodology remains beneficial to identify and address risks related to discrimination, privacy violations, or lack of effective recourse. 

What to avoid: conducting several separate assessments that contradict one another. The DPO, CISO, HR team, legal counsel, compliance officers, and business stakeholders should rely on a shared risk framework and common mitigation measures to ensure effective AI governance. 

Action 4: Govern Suppliers and Review Documentation 

An employer cannot transfer its responsibilities entirely to a supplier. It must obtain the information necessary to use the system as intended and properly manage associated risks. 

Before selecting an HR AI tool, organizations should conduct a structured supplier assessment. 

Questions to Ask Suppliers 

  • What is the intended purpose of the system? 
  • Is the system classified as high-risk? 
  • On what basis was this classification determined? 
  • What data was used to train, test, and validate the system? 
  • What measures are in place to detect and mitigate bias? 
  • Are testing results available for relevant populations? 
  • What are the known error rates and limitations? 
  • How can users interpret the outputs? 
  • What logs are generated and how long are they accessible? 
  • Can the model or its components evolve automatically? 
  • Is customer data reused to train the system? 
  • Where is data hosted? 
  • Which subcontractors are involved? 
  • How are incidents reported? 
  • Which cybersecurity measures are implemented? 
  • Can the supplier provide evidence of compliance? 

Priority Contractual Provisions 

Before deploying an AI tool, organizations should ensure contracts address: 

  • Authorized purposes 
  • Prohibited uses 
  • Allocation of roles and responsibilities under the AI Act and GDPR 
  • Access to user instructions and documentation 
  • Notification of model changes 
  • Performance maintenance commitments 
  • Log availability 
  • Incident response cooperation 
  • Audit rights 
  • Security requirements 
  • Exit and reversibility provisions 
  • Data deletion or return obligations 
  • Liability in cases of non-compliance 

Practical Example 

If a supplier modifies its CV-ranking algorithm, the organization should be able to determine whether previous testing and validation remain valid. A simple commercial notification is insufficient when changes may affect candidates’ rights. 

Action 5: Establish Effective Human Oversight 

Human oversight must enable individuals to understand, review, challenge, and, where necessary, disregard or halt AI-generated outputs. 

The concept of a “human in the loop” is not satisfied by simply adding a checkbox to a workflow. 

Oversight personnel should have: 

  • Appropriate skills and knowledge 
  • Real authority to modify decisions 
  • Sufficient time to review outputs 
  • Information about system capabilities and limitations 
  • Means to identify anomalies 
  • Escalation procedures 
  • Mechanisms to document their decisions 

Prevent Automation Bias 

Automation bias refers to the tendency to place excessive trust in AI recommendations simply because they appear objective or scientific. 

Organizations can mitigate this risk by: 

  • Hiding overall scores during an initial review 
  • Requiring recruiters to formulate their own assessment first 
  • Displaying confidence levels and known limitations 
  • Monitoring disagreement rates between humans and AI 
  • Investigating cases where recommendations are almost always accepted 
  • Conducting regular sample reviews 
  • Requiring secondary approval for sensitive decisions 

Example Procedure 

For a candidate recommendation system: 

  1. The system provides a recommendation, not a final decision. 
  1. The recruiter reviews objective information contained in the application. 
  1. The recruiter assesses whether the recommendation is reasonable. 
  1. The reasons supporting the final decision are documented. 
  1. A second review is triggered in cases of anomaly. 
  1. Candidates can request reassessment through a dedicated channel. 

Organizations should also verify whether their processes amount to solely automated decision-making that produces legal effects or similarly significant effects. If so, they must ensure compliance with Article 22 of the GDPR. 

Action 6: Inform and Train Teams, Employees, and Employee Representatives 

Compliance requires an adequate level of AI literacy, role-specific guidance, and meaningful information for affected individuals. 

Since February 2, 2025, providers and deployers must take measures to ensure a sufficient level of AI literacy among individuals who use or operate AI systems on their behalf. 

Training should be tailored to: 

  • Users’ existing knowledge 
  • Their experience 
  • The context of use 
  • The individuals or groups affected 
  • The system’s risk level 

Recommended Training Program 

Audience Priority Competencies 
Recruiters Bias awareness, usage instructions, prohibited data, oversight 
Managers Interpreting outputs, limitations, employee remedies 
HR Teams Use-case qualification, documentation, monitoring 
DPOs Personal data, DPIAs, automated decision-making 
CISOs Threats, supplier oversight, access control, logging, incidents 
Procurement Teams AI Act clauses, supplier evidence, modifications 
Executive Management Governance, risk acceptance, accountability 
Developers & Data Scientists Data quality, testing, traceability, performance monitoring 

A generic 30-minute training session is not sufficient for users operating high-risk AI systems. They need to understand possible errors, operating conditions, and situations requiring escalation or suspension. 

Inform Employees and Their Representatives 

Before deploying or using a high-risk AI system in the workplace, deployers must inform employee representatives and affected workers in accordance with applicable laws and practices. 

This AI Act requirement complements national labor law obligations relating to information, consultation, and employee monitoring. 

Candidates and employees must also receive all information required by the GDPR regarding the processing of their personal data. Such information must be understandable, accessible, and consistent with the actual functioning of the system. 

Action 7: Establish Monitoring, Traceability, and Incident Management Processes

AI Act compliance is not a one-time exercise completed before deployment. It requires continuous monitoring of system performance, impacts, incidents, and changes over time.

An AI system may become riskier after deployment due to:

  • The introduction of new user groups;
  • Changes in input data;
  • Model updates;
  • Purpose drift;
  • Performance degradation;
  • Regulatory changes;
  • Increasing reliance on AI recommendations by human users.

Useful Metrics for HR AI Systems

Organizations may monitor:

  • The percentage of decisions following AI recommendations;
  • Selection rates at each stage of the hiring process;
  • Outcome disparities between groups, where legally permissible;
  • False positive and false negative rates;
  • Appeals and requests for reassessment;
  • Corrections introduced by users;
  • Errors and service outages;
  • Security incidents;
  • Complaints;
  • Cases of purpose drift;
  • The frequency and impact of model updates.

Implement an AI Incident Management Procedure

The incident management process should make it possible to:

  1. Detect abnormal behavior;
  2. Suspend system usage when necessary;
  3. Preserve logs and evidence;
  4. Identify potentially affected individuals;
  5. Involve HR, the DPO, the CISO, Legal, and Compliance teams;
  6. Notify the supplier;
  7. Determine applicable regulatory notifications;
  8. Correct decisions or remediate harm;
  9. Document preventive measures.

For high-risk AI systems, deployers must retain automatically generated logs when those logs are under their control. The AI Act requires retention appropriate to the system’s purpose, with a minimum period of six months unless otherwise specified by applicable Union or national law.

How Should AI Governance Be Organized in HR?

AI governance should clearly assign responsibilities, define risk acceptance criteria, and integrate AI oversight into existing compliance, security, procurement, and internal control frameworks.

Responsibility for compliance cannot rest solely with the DPO or the HR department.

An effective governance structure may include:

  • An executive sponsor;
  • An AI governance committee;
  • A business owner for each AI system;
  • An AI Act compliance lead;
  • The DPO for privacy-related matters;
  • The CISO for security;
  • Procurement teams for supplier oversight;
  • Legal teams for contracts and employment law;
  • Internal audit functions to test control effectiveness;
  • Employee representatives where applicable.

Simplified Governance Matrix

DecisionPrimary OwnerContributors
AI inventory registrationBusiness ownerIT, Procurement, Compliance
AI Act classificationCompliance or LegalHR, DPO, CISO
DPIADPOHR, Security, Business teams
Vendor approvalProcurementLegal, CISO, Compliance
Risk acceptanceExecutive managementAI committee
Production deploymentSystem ownerHR, IT, Compliance
Ongoing monitoringBusiness ownerRisk, DPO, CISO
Incident managementDesignated leadCross-functional response team

ISO/IEC 42001, the international standard for AI management systems, can help structure this governance framework. It provides a continuous management approach built around policies, responsibilities, risk assessment, objectives, controls, and continuous improvement.

While alignment with ISO/IEC 42001 does not automatically ensure AI Act compliance, it can significantly strengthen an organization’s ability to demonstrate a documented and consistent governance approach.

AI Act Compliance Checklist for HR AI Systems

Before deploying an AI system, verify that:

✅ The system is recorded in the AI inventory.

✅ Its intended purpose has been defined and approved.

✅ The organization’s role has been identified.

✅ The applicable risk level has been documented.

✅ Prohibited practices have been ruled out.

✅ Fundamental rights risks have been assessed.

✅ The need for a DPIA has been evaluated.

✅ The supplier has provided sufficient documentation.

✅ The contract addresses updates and incident management.

✅ The data used is necessary and lawfully processed.

✅ Effective human oversight has been implemented.

✅ Users have received appropriate training.

✅ Employees and employee representatives have been informed where required.

✅ Required logs are available and retained.

✅ Performance and fairness indicators have been established.

✅ A challenge and review process exists.

✅ Incident response and suspension procedures have been tested.

✅ A periodic review date has been defined.

Practical Compliance Roadmap

The immediate priority should be to address prohibited practices and AI literacy requirements, then secure the classification and governance of potentially high-risk systems.

Milestone DateKey Requirements
1 August 2024Entry into force of the AI Act
2 February 2025Prohibited practices and AI literacy obligations apply
2 August 2025Governance framework and general-purpose AI provisions apply
2 August 2026Most other AI Act obligations become applicable
2 August 2027Certain requirements for Annex III high-risk AI systems become applicable
2 August 2028Certain requirements relating to Annex I high-risk AI systems become applicable

The exact timeline applicable to a particular AI system depends on its nature, date of placement on the market, the organization’s role, and applicable transitional measures.

Where uncertainty exists, organizations should seek specialized legal advice and consult the latest official regulatory guidance.

Key Takeaways

Main Points

  • Recruitment, candidate selection, employee evaluation, task allocation, and workplace monitoring tools may qualify as high-risk AI systems.
  • Emotion recognition in the workplace is generally prohibited, except under limited medical or safety-related exceptions.
  • The AI Act, GDPR, and employment law apply in a complementary manner.
  • Deployers remain responsible even when AI systems are provided by third-party vendors.
  • Human oversight must be meaningful, competent, and documented.

Priority Actions

  1. Inventory all AI use cases within HR.
  2. Identify potentially prohibited practices.
  3. Classify each AI system and document the rationale.
  4. Conduct the necessary impact assessments.
  5. Strengthen supplier due diligence and contractual controls.
  6. Train users according to their responsibilities.
  7. Monitor performance, complaints, and incidents on an ongoing basis.

Common Mistakes to Avoid

  • Relying solely on the supplier’s risk classification.
  • Assuming that a formal human approval step is sufficient.
  • Overlooking AI features added to existing software.
  • Uploading CVs or employee data into public AI assistants.
  • Limiting compliance efforts to ethics policies without operational controls.
  • Confusing AI Act compliance with GDPR compliance.
  • Waiting until regulatory deadlines approach before building inventories and compliance evidence.

Conclusion

Achieving AI Act compliance for HR-related AI systems is not about banning innovative tools or adding a legal review at the end of a project. It requires a structured approach that connects regulatory requirements, business risks, governance, and operational processes.

The AI inventory serves as the foundation. Regulatory classification then allows organizations to apply controls proportionate to risk. Impact assessments, human oversight, supplier management, training programs, and continuous monitoring transform AI Act requirements into practical and verifiable compliance measures.

Ultimately, this approach protects not only candidates and employees but also the organization itself. It reduces the risk of discrimination claims, regulatory violations, reputational damage, loss of trust, and AI deployments that cannot be adequately justified or defended.

Assess the maturity of your AI governance framework 

Is your organization already using artificial intelligence tools but lacking visibility into risks, responsibilities, or compliance requirements? 

Conduct an AI governance assessment with Naaia to identify your AI use cases, inventory your systems, evaluate risks, and implement a governance framework aligned with applicable AI requirements, including those introduced by the AI Act and ISO/IEC 42001.