Compliance, Employee Representation, and Decision Layer
high-risk obligations from 2 December 2027
AI in HR is not an IT project. It is a governance project with a technical component.
Who defines at what confidence level a payroll calculation may run automatically? Who determines which bias definitions apply? Who decides whether a recruiting agent may pre-screen resumes?
The answer is not the CIO. It is the CHRO.
According to ISACA (2024), 73% of organisations lack a formal AI governance framework. In HR, this means critical processes such as payroll, recruiting, and workforce planning operate without defined control structures.
| Level | Responsibility | Who |
|---|---|---|
| Decision Matrix | Defines what the agent may do and what stays with humans | HR + Legal |
| Audit Trail | Every action logged, versioned, reproducible | IT (technical), HR (review) |
| Role Model | Who monitors, who approves, who escalates | HR |
| Collective Agreement Templates | Documentation for the agreement with employee representatives | HR + employee representatives |
| Escalation Path | What happens in cases of uncertainty or low confidence | HR + IT |
Before the first agent goes live:
According to Gartner (2024), 30-40% of all AI projects fail due to missing governance structures. Not due to technology. Not due to budget. Due to organisation.
Every HR process consists of hundreds of micro-decisions. The Decision Framework classifies each one.
| Type | Decided by | Examples |
|---|---|---|
| Human (H) | Case worker or employee representatives | Termination, formal warning, suspicion of discrimination |
| Rule Engine (R) | Collective bargaining agreement, company agreement, statute | Pay grade, bonuses, leave entitlement, social security contributions |
| AI-eligible (A) | Agent with confidence routing | Document classification, anomaly detection, routing |
AI classifies - it does not calculate. An agent recognises that a receipt is a travel expense claim. But the per diem rate is calculated by the rule engine.
Rule engines calculate - they do not decide. The rule engine applies the collective agreement. But whether an employee is promoted is decided by a human.
Humans decide where the law requires it. Not because they are better at it - but because it is required.
Score = (R + A) / Total x 100
| HR Process | Score | Meaning |
|---|---|---|
| Payroll | 85-95% | Highly automatable (rule engine-dominated) |
| Time Tracking | 80-90% | Highly automatable |
| Travel Expenses | 75-85% | Well automatable |
| Recruiting | 40-55% | Partially automatable (significant Human-in-the-Loop) |
| Performance Mgmt. | 20-35% | Primarily human |
The lower the score, the more Human-in-the-Loop. That is not a deficiency - it is by design.
The EU AI Act classifies AI systems in employment contexts as high-risk (Annex III No. 4).
AI systems intended to be used for recruitment or selection of natural persons, in particular for placing targeted job advertisements, analysing and filtering applications, and evaluating candidates.
The deadline has moved, and it is settled law. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers the high-risk obligations. It does not remove them.
| Date | What applies |
|---|---|
| 2 August 2026 | Transparency duties under Art. 50: disclosing that a person is interacting with AI, emotion recognition, labelling of synthetic content. In force now. |
| 2 December 2026 | Prohibition of AI systems generating non-consensual intimate imagery and child sexual abuse material (Art. 5) |
| 2 December 2027 | High-risk obligations for standalone systems under Annex III. This is where HR AI sits. |
| 2 August 2028 | High-risk obligations for AI embedded in products already covered by EU product-safety law (Annex I) |
From 2 December 2027, six mandatory requirements apply to high-risk HR AI:
| Requirement | Art. | Decision Layer |
|---|---|---|
| Risk Management | 9 | Confidence Routing - confidence score per decision, configurable thresholds |
| Data Governance | 10 | Versioned rule engines - every change traceable |
| Record-Keeping | 12 | Audit Trail - input, rule, confidence, and result logged |
| Transparency | 13 | Decision Layer documentation - every decision traceable |
| Human Oversight | 14 | Enforced Human-in-the-Loop - architectural, not optional |
| Accuracy/Robustness | 15 | Bias monitoring - systematic checks by gender, age, origin |
Sanctions: Up to EUR 15 million or 3% of global annual turnover for breaches of the high-risk requirements; up to EUR 35 million or 7% for the prohibited practices under Art. 5 (Art. 99 EU AI Act, unchanged by the Digital Omnibus).
Not a pause. Record-keeping, data governance, and enforced human oversight are architectural properties: cheap to design in, expensive to retrofit into a system already in production. The deferral buys one budget cycle to build them deliberately instead of under deadline pressure.
And one duty is already live: since 2 August 2026 every HR chatbot, every AI-drafted candidate letter, and every AI-generated image in employer branding needs its disclosure or label under Art. 50. That is the obligation to check this quarter.
Employee representatives do not block AI. They block poorly prepared projects.
Which body you must involve, and how much power it holds, is national law and differs in every European market. The layer above it does not differ:
| Legal basis | Subject | Relevance for HR AI |
|---|---|---|
| EU AI Act, Art. 26 (7) | Duty to inform | Employers must inform workers’ representatives and the affected workers before putting a high-risk AI system into service at the workplace |
| Directive 2002/14/EC | Information and consultation | General EU framework, transposed into national law in every member state |
| GDPR Art. 22 | Automated decisions | Right to human review of decisions with legal or similarly significant effect |
| GDPR Art. 88 | Employment data | Member states may set stricter rules for the employment context, so check the national rule rather than the EU floor |
| Directive (EU) 2024/2831 | Algorithmic management | Platform work, transposition due 2 December 2026; the reference point for the wider debate on automated management decisions |
The national layer decides whether you owe information, consultation, or actual agreement. The strongest regime is the German one, where the works council holds a genuine right of co-determination, meaning no rollout without its consent:
| Market | Body and basis | Strength of the right |
|---|---|---|
| Germany | Betriebsrat - German BetrVG § 87 (1) Nos. 5, 6, 10, §§ 94, 99 | Co-determination: consent required for technical monitoring systems |
| Spain | Comité de Empresa - Estatuto de los Trabajadores, Art. 64.4.d | Information on algorithms and consultation, no veto |
| Poland | Rada pracowników - Act on Works Councils (2006), Art. 13 | Information and consultation, no veto |
| France | Comité social et économique - Code du travail, Art. L2312-8 | Consultation required before introducing new technology |
| Netherlands | Ondernemingsraad - WOR Art. 27 | Consent required for personnel-data and monitoring systems |
The practical consequence for a multi-country rollout: the technical design has to satisfy the strictest market you operate in, or you build the system twice.
In the Decision Layer, whatever you agree with employee representatives is implemented as a technical constraint - not as a PDF in a folder:
Regulation (EU) 2026/1744 reworded Art. 4. It used to require providers and deployers to ensure a sufficient level of AI literacy. It now requires them to take measures to support the development of AI literacy among the people who operate and oversee their systems.
The difference matters for how you are audited: this is an obligation of effort, not of result. You are not answerable for the competence of each individual, but you do have to show proportionate measures and keep the evidence - a training plan, attendance records, role-specific content, a refresh cycle. According to BCG (2024), allocate 12-22% of the AI budget for training.
| Role | Training Content | Refresher |
|---|---|---|
| HR Case Worker | System understanding, escalation, interpreting results | Annually |
| Employee representatives | Audit functions, bias detection, inspection rights | Annually |
| CHRO/HR Leadership | Governance framework, compliance, strategy | Semi-annually |
| IT Operations | Technical operations, monitoring, incident response | Quarterly |
According to Hackett Group (2024), companies with explicit rule engines reduce correction postings by 60-80% in the first year.
| Decision | Type | Example |
|---|---|---|
| Collective agreement grading | Rule Engine | Pay group and step from the applicable collective agreement (example: pay group E8, step 3, regional bargaining area) |
| Allowance calculation | Rule Engine | Night shift +25%, public holiday +100% |
| Social security contributions | Rule Engine | Statutory contribution rates per market and year (the German set - health, pension, unemployment, long-term care - is the illustrative example here) |
| Anomaly detection | AI | Salary deviates >15% - flag for review |
| Approval for deviation | Human | Confirm back-payment >EUR 500 |
Result: 85-92% zero-touch. Correction postings -60-80%.
According to the GBTA Foundation (2015): USD 58 per case, 19% error rate, USD 52 per correction. At 100,000 cases that is USD 6.8 million a year. The absolute figures are a decade old and understate today’s cost; the ratio between processing and correction is the durable part.
| Industry | Zero-Touch | Cases/Year |
|---|---|---|
| Aviation/Logistics | 95% | 100k-1M |
| Sales | 90% | 120k+ |
| Consulting | 85% | 50k-250k |
Annex III No. 4: "Analysing and filtering of applications" = high-risk. Double governance depth required.
| Phase | Type | What Happens |
|---|---|---|
| CV Parsing | AI | Extraction of qualifications |
| Requirements Matching | AI + Rule Engine | Matching with confidence score |
| Shortlisting | Human | Recruiter reviews all suggestions |
| Decision | Human | Hiring is always a human decision |
Complexity arises from collective bargaining agreements, company agreements, and statutory special cases, which differ by market: statutory minimum leave, disability provisions, partial retirement, and in regulated sectors mandatory consecutive-leave rules. Result: 78-87% zero-touch.
10 questions for the CHRO. Rate each with 0 (no), 1 (partially), or 2 (yes).
| # | Question | 0 | 1 | 2 |
|---|---|---|---|---|
| 1 | We have an inventory of all AI systems in HR (incl. shadow AI). | ☐ | ☐ | ☐ |
| 2 | There is a designated owner for AI governance in HR. | ☐ | ☐ | ☐ |
| 3 | The employee representatives are informed about AI usage (Art. 26 (7) EU AI Act). | ☐ | ☐ | ☐ |
| 4 | For every automated decision, the type is defined: H, R, or A. | ☐ | ☐ | ☐ |
| 5 | An audit trail exists for AI-supported decisions. | ☐ | ☐ | ☐ |
| 6 | Escalation paths and thresholds are documented. | ☐ | ☐ | ☐ |
| 7 | HR employees have completed AI literacy training (Art. 4). | ☐ | ☐ | ☐ |
| 8 | A framework agreement on AI with the employee representatives is in progress or completed. | ☐ | ☐ | ☐ |
| 9 | We can demonstrate freedom from discrimination. | ☐ | ☐ | ☐ |
| 10 | We have a plan for 2 December 2027 - and we already meet the Art. 50 transparency duties in force since 2 August 2026. | ☐ | ☐ | ☐ |
| Score | Rating | Recommendation |
|---|---|---|
| 16-20 | Ready | Choose a pilot process and build the Decision Layer. |
| 10-15 | Foundation in place | Formalise governance. Involve the employee representatives. |
| 5-9 | Catching up needed | Prioritise AI literacy and inventory. |
| 0-4 | Action required | Start immediately. EU AI Act deadlines are running. |
EUR 1 in technology = EUR 4-5 in processes, governance, change management.
| Technology | 15-20% |
| Process Design | 30-35% |
| Governance | 20-25% |
| Change Management | 20-25% |
| Month | Focus | Outcome |
|---|---|---|
| 1 | Inventory | AI overview, governance ownership, employee representatives informed, pilot process identified |
| 2 | Design | Workflow audit, H/R/A classification, thresholds, draft framework agreement |
| 3 | Pilot | Decision Layer built, parallel operation, measurement after 4-6 weeks |
We will show you the Decision Layer applied to your own HR processes.
30 minutes, free of charge, no obligation.
Bert Gogolin - Managing Director, Gosign GmbH
Analyze your HR process: www.gosign.de/en/contact
Web: www.gosign.de