AI in HR:
Governance Handbook
for the CHRO

Compliance, Employee Representation, and Decision Layer
high-risk obligations from 2 December 2027

Author: Bert Gogolin, Managing Director
Publisher: Gosign GmbH, Hamburg
Published: August 2026
Scope: 25 pages

Contents

1 Why the CHRO Must Lead AI Governance in HR
2 Three Types of Decisions: Human, Rule Engine, AI
3 EU AI Act: 6 Mandatory Requirements for HR AI
4 Employee Representation as Design Partner
5 4 HR Processes in the Decision Layer
6 Readiness Assessment
7 Next Steps
73%
without an AI governance framework
ISACA 2024
6
mandatory requirements from Dec. 2027
EU AI Act
85-92%
zero-touch rate in Decision Layer
Gosign projects

1 - Why the CHRO Must Lead AI Governance in HR

AI in HR is not an IT project. It is a governance project with a technical component.

Who defines at what confidence level a payroll calculation may run automatically? Who determines which bias definitions apply? Who decides whether a recruiting agent may pre-screen resumes?

The answer is not the CIO. It is the CHRO.

According to ISACA (2024), 73% of organisations lack a formal AI governance framework. In HR, this means critical processes such as payroll, recruiting, and workforce planning operate without defined control structures.

Three Governance Levels

LevelResponsibilityWho
Decision MatrixDefines what the agent may do and what stays with humansHR + Legal
Audit TrailEvery action logged, versioned, reproducibleIT (technical), HR (review)
Role ModelWho monitors, who approves, who escalatesHR
Collective Agreement TemplatesDocumentation for the agreement with employee representativesHR + employee representatives
Escalation PathWhat happens in cases of uncertainty or low confidenceHR + IT
Checklist

Before the first agent goes live:

According to Gartner (2024), 30-40% of all AI projects fail due to missing governance structures. Not due to technology. Not due to budget. Due to organisation.

2 - Three Types of Decisions

Every HR process consists of hundreds of micro-decisions. The Decision Framework classifies each one.

TypeDecided byExamples
Human (H)Case worker or employee representativesTermination, formal warning, suspicion of discrimination
Rule Engine (R)Collective bargaining agreement, company agreement, statutePay grade, bonuses, leave entitlement, social security contributions
AI-eligible (A)Agent with confidence routingDocument classification, anomaly detection, routing

The Golden Rule

AI classifies - it does not calculate. An agent recognises that a receipt is a travel expense claim. But the per diem rate is calculated by the rule engine.

Rule engines calculate - they do not decide. The rule engine applies the collective agreement. But whether an employee is promoted is decided by a human.

Humans decide where the law requires it. Not because they are better at it - but because it is required.

Agent Readiness Score

Score = (R + A) / Total x 100

HR ProcessScoreMeaning
Payroll85-95%Highly automatable (rule engine-dominated)
Time Tracking80-90%Highly automatable
Travel Expenses75-85%Well automatable
Recruiting40-55%Partially automatable (significant Human-in-the-Loop)
Performance Mgmt.20-35%Primarily human

The lower the score, the more Human-in-the-Loop. That is not a deficiency - it is by design.

3 - EU AI Act: 6 Mandatory Requirements

The EU AI Act classifies AI systems in employment contexts as high-risk (Annex III No. 4).

AI systems intended to be used for recruitment or selection of natural persons, in particular for placing targeted job advertisements, analysing and filtering applications, and evaluating candidates.

The deadline has moved, and it is settled law. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers the high-risk obligations. It does not remove them.

DateWhat applies
2 August 2026Transparency duties under Art. 50: disclosing that a person is interacting with AI, emotion recognition, labelling of synthetic content. In force now.
2 December 2026Prohibition of AI systems generating non-consensual intimate imagery and child sexual abuse material (Art. 5)
2 December 2027High-risk obligations for standalone systems under Annex III. This is where HR AI sits.
2 August 2028High-risk obligations for AI embedded in products already covered by EU product-safety law (Annex I)

From 2 December 2027, six mandatory requirements apply to high-risk HR AI:

RequirementArt.Decision Layer
Risk Management9Confidence Routing - confidence score per decision, configurable thresholds
Data Governance10Versioned rule engines - every change traceable
Record-Keeping12Audit Trail - input, rule, confidence, and result logged
Transparency13Decision Layer documentation - every decision traceable
Human Oversight14Enforced Human-in-the-Loop - architectural, not optional
Accuracy/Robustness15Bias monitoring - systematic checks by gender, age, origin
Compliance Checklist

Sanctions: Up to EUR 15 million or 3% of global annual turnover for breaches of the high-risk requirements; up to EUR 35 million or 7% for the prohibited practices under Art. 5 (Art. 99 EU AI Act, unchanged by the Digital Omnibus).

What the extra sixteen months are for

Not a pause. Record-keeping, data governance, and enforced human oversight are architectural properties: cheap to design in, expensive to retrofit into a system already in production. The deferral buys one budget cycle to build them deliberately instead of under deadline pressure.

And one duty is already live: since 2 August 2026 every HR chatbot, every AI-drafted candidate letter, and every AI-generated image in employer branding needs its disclosure or label under Art. 50. That is the obligation to check this quarter.

4 - Employee Representation as Design Partner

Employee representatives do not block AI. They block poorly prepared projects.

Which body you must involve, and how much power it holds, is national law and differs in every European market. The layer above it does not differ:

Legal basisSubjectRelevance for HR AI
EU AI Act, Art. 26 (7)Duty to informEmployers must inform workers’ representatives and the affected workers before putting a high-risk AI system into service at the workplace
Directive 2002/14/ECInformation and consultationGeneral EU framework, transposed into national law in every member state
GDPR Art. 22Automated decisionsRight to human review of decisions with legal or similarly significant effect
GDPR Art. 88Employment dataMember states may set stricter rules for the employment context, so check the national rule rather than the EU floor
Directive (EU) 2024/2831Algorithmic managementPlatform work, transposition due 2 December 2026; the reference point for the wider debate on automated management decisions

National Co-Determination: What to Check in Your Market

The national layer decides whether you owe information, consultation, or actual agreement. The strongest regime is the German one, where the works council holds a genuine right of co-determination, meaning no rollout without its consent:

MarketBody and basisStrength of the right
GermanyBetriebsrat - German BetrVG § 87 (1) Nos. 5, 6, 10, §§ 94, 99Co-determination: consent required for technical monitoring systems
SpainComité de Empresa - Estatuto de los Trabajadores, Art. 64.4.dInformation on algorithms and consultation, no veto
PolandRada pracowników - Act on Works Councils (2006), Art. 13Information and consultation, no veto
FranceComité social et économique - Code du travail, Art. L2312-8Consultation required before introducing new technology
NetherlandsOndernemingsraad - WOR Art. 27Consent required for personnel-data and monitoring systems

The practical consequence for a multi-country rollout: the technical design has to satisfy the strictest market you operate in, or you build the system twice.

The Collective Agreement as Technical Constraint

In the Decision Layer, whatever you agree with employee representatives is implemented as a technical constraint - not as a PDF in a folder:

AI Literacy Obligation (Art. 4, in force since February 2025, amended July 2026)

Regulation (EU) 2026/1744 reworded Art. 4. It used to require providers and deployers to ensure a sufficient level of AI literacy. It now requires them to take measures to support the development of AI literacy among the people who operate and oversee their systems.

The difference matters for how you are audited: this is an obligation of effort, not of result. You are not answerable for the competence of each individual, but you do have to show proportionate measures and keep the evidence - a training plan, attendance records, role-specific content, a refresh cycle. According to BCG (2024), allocate 12-22% of the AI budget for training.

RoleTraining ContentRefresher
HR Case WorkerSystem understanding, escalation, interpreting resultsAnnually
Employee representativesAudit functions, bias detection, inspection rightsAnnually
CHRO/HR LeadershipGovernance framework, compliance, strategySemi-annually
IT OperationsTechnical operations, monitoring, incident responseQuarterly

5-4 HR Processes in the Decision Layer

Payroll - Eliminating Correction Postings

According to Hackett Group (2024), companies with explicit rule engines reduce correction postings by 60-80% in the first year.

DecisionTypeExample
Collective agreement gradingRule EnginePay group and step from the applicable collective agreement (example: pay group E8, step 3, regional bargaining area)
Allowance calculationRule EngineNight shift +25%, public holiday +100%
Social security contributionsRule EngineStatutory contribution rates per market and year (the German set - health, pension, unemployment, long-term care - is the illustrative example here)
Anomaly detectionAISalary deviates >15% - flag for review
Approval for deviationHumanConfirm back-payment >EUR 500

Result: 85-92% zero-touch. Correction postings -60-80%.

Travel Expenses - 40-120 Micro-Decisions per Case

According to the GBTA Foundation (2015): USD 58 per case, 19% error rate, USD 52 per correction. At 100,000 cases that is USD 6.8 million a year. The absolute figures are a decade old and understate today’s cost; the ratio between processing and correction is the durable part.

IndustryZero-TouchCases/Year
Aviation/Logistics95%100k-1M
Sales90%120k+
Consulting85%50k-250k

Recruiting - Governance for High-Risk

Annex III No. 4: "Analysing and filtering of applications" = high-risk. Double governance depth required.

PhaseTypeWhat Happens
CV ParsingAIExtraction of qualifications
Requirements MatchingAI + Rule EngineMatching with confidence score
ShortlistingHumanRecruiter reviews all suggestions
DecisionHumanHiring is always a human decision

Leave & Absence

Complexity arises from collective bargaining agreements, company agreements, and statutory special cases, which differ by market: statutory minimum leave, disability provisions, partial retirement, and in regulated sectors mandatory consecutive-leave rules. Result: 78-87% zero-touch.

6 - Readiness Assessment

10 questions for the CHRO. Rate each with 0 (no), 1 (partially), or 2 (yes).

#Question012
1We have an inventory of all AI systems in HR (incl. shadow AI).
2There is a designated owner for AI governance in HR.
3The employee representatives are informed about AI usage (Art. 26 (7) EU AI Act).
4For every automated decision, the type is defined: H, R, or A.
5An audit trail exists for AI-supported decisions.
6Escalation paths and thresholds are documented.
7HR employees have completed AI literacy training (Art. 4).
8A framework agreement on AI with the employee representatives is in progress or completed.
9We can demonstrate freedom from discrimination.
10We have a plan for 2 December 2027 - and we already meet the Art. 50 transparency duties in force since 2 August 2026.
ScoreRatingRecommendation
16-20ReadyChoose a pilot process and build the Decision Layer.
10-15Foundation in placeFormalise governance. Involve the employee representatives.
5-9Catching up neededPrioritise AI literacy and inventory.
0-4Action requiredStart immediately. EU AI Act deadlines are running.
Investment Rule (McKinsey 2024)

EUR 1 in technology = EUR 4-5 in processes, governance, change management.

Technology15-20%
Process Design30-35%
Governance20-25%
Change Management20-25%

7 - Next Steps

The 90-Day Plan

MonthFocusOutcome
1InventoryAI overview, governance ownership, employee representatives informed, pilot process identified
2DesignWorkflow audit, H/R/A classification, thresholds, draft framework agreement
3PilotDecision Layer built, parallel operation, measurement after 4-6 weeks
Consultation

We will show you the Decision Layer applied to your own HR processes.

30 minutes, free of charge, no obligation.

Bert Gogolin - Managing Director, Gosign GmbH

Analyze your HR process: www.gosign.de/en/contact

Web: www.gosign.de