The EU AI Act places almost every AI system used in HR processes into the high-risk category. Those systems must meet strict requirements for risk management, transparency, and human oversight from 2 December 2027. The date moved, and it moved by law: Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and deferred the original 2 August 2026 deadline. What it did not do is change the classification, or the fact that one set of duties is already live.
At a Glance - HR AI Is High-Risk Under the EU AI Act
- AI systems for recruiting, performance reviews, promotions, and terminations are classified as high-risk under Annex III, No. 4 of the EU AI Act.
- Prohibited AI practices (social scoring, manipulation) have been in force since 2 February 2025. The transparency duties under Art. 50 have applied since 2 August 2026. The full high-risk obligations apply from 2 December 2027 under Regulation (EU) 2026/1744.
- Six mandatory requirements: risk management, data governance, record-keeping, transparency, human oversight, and accuracy/robustness.
- The Decision Layer maps each requirement architecturally: Confidence Routing for risk, versioned rule sets for data governance, audit trail for records, Human-in-the-Loop for oversight.
- Penalties reach up to 15 million euros or 3% of global annual turnover for violations of the high-risk obligations (Art. 99(4)) - up to 35 million euros or 7% for prohibited AI practices (Art. 5).
According to a PwC survey (2024), only 24% of enterprises using AI in HR processes had begun formal EU AI Act compliance preparation. The high-risk deadline has since moved to 2 December 2027 - which converts that gap from an emergency into a budget cycle, provided it is used.
| EU AI Act Article | Requirement | Decision Layer Implementation |
|---|---|---|
| Art. 9 | Risk Management System | Confidence Routing with configurable thresholds |
| Art. 10 | Data Governance | Versioned rule sets with validity dates |
| Art. 12 | Record-Keeping | Immutable audit trail per decision |
| Art. 13 | Transparency | Auditor Portal with full decision path |
| Art. 14 | Human Oversight | Enforced Human-in-the-Loop for defined types |
| Art. 15 | Accuracy and Robustness | Bias monitoring and model-agnostic design |
| Art. 86 | Right to an explanation of the individual decision | Decision act per micro-decision with contestation path |
The Classification: HR AI is High-Risk
The EU AI Act classifies AI systems used in employment, worker management, and access to self-employment as high-risk (Annex III, No. 4). This specifically covers:
AI systems for recruiting and candidate selection. AI systems that influence promotion, termination, task assignment, or performance monitoring. AI systems that affect working conditions - including salary adjustments, classifications, and shift planning.
In short: almost every AI agent that prepares, supports, or makes decisions in HR processes falls under the high-risk category.
The Deadlines
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It rewrote the timetable. It did not rewrite the classification.
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited AI practices under Art. 5: social scoring, manipulative techniques. In force. |
| 2 August 2026 | Transparency duties under Art. 50: disclosing that a person is interacting with AI, emotion recognition, labelling of synthetic content. In force - this deadline was not deferred. |
| 2 December 2026 | Prohibition of AI systems that generate non-consensual intimate imagery or child sexual abuse material (Art. 5, added by the Omnibus). |
| 2 December 2027 | High-risk obligations for standalone systems under Annex III. This is where HR AI sits. |
| 2 August 2028 | High-risk obligations for AI embedded in products already covered by EU product-safety law (Annex I). |
Neither of the two high-risk dates is conditional on a further Commission decision. They are fixed.
The Omnibus also softened Art. 4: the duty to ensure a sufficient level of AI literacy became a duty to take measures supporting its development - an obligation of effort rather than of outcome. Training records and an AI inventory remain the evidence you will be asked for.
Sixteen additional months are not a pause. Record-keeping, data governance, and enforced human oversight are architectural properties: cheap to design in, expensive to retrofit into a system already running in production. And one duty is live today - every HR chatbot and every AI-drafted candidate letter needs its disclosure under Art. 50 this quarter, not in 2027.
What Is Specifically Required - and How the Decision Layer Fulfils It
The following requirements apply to every operator of a high-risk AI system in the HR domain:
Article 9 - Risk Management System: The EU AI Act requires a continuous risk management system that identifies, assesses, and mitigates risks. In the Decision Layer, this is implemented through Confidence Routing: every agent decision is automatically evaluated by confidence and risk category. High risk or low confidence leads to escalation to a human. Thresholds are configurable and documented.
Article 10 - Data Governance: Versioned rule sets in the Decision Layer ensure that the data basis of every decision is traceable. Collective agreements, works council agreements (German Betriebsvereinbarungen), and compliance rules have versions, validity dates, and scopes. During an audit, it is traceable which rule set in which version applied at the time of the decision.
Article 12 - Record-Keeping Obligations: The audit trail in the Decision Layer generates a complete, immutable data record for every decision: input, model, rule set, confidence, routing decision, result, timestamp. Automatically, not compiled after the fact.
Article 13 - Transparency: Every agent decision is traceable in the Auditor Portal. Works councils, data protection officers, and auditors can view the decision path. No black box.
Article 14 - Human Oversight: Human-in-the-Loop is an architectural principle in the Decision Layer, not an optional setting. For defined decision types - discrimination potential, co-determination topics, value thresholds - the architecture enforces human review. An agent cannot bypass this review.
Article 15 - Accuracy, Robustness, and Cybersecurity: Bias monitoring systematically checks for discriminatory patterns. Confidence thresholds ensure that the agent only decides autonomously with sufficient certainty. Model-agnostic design enables switching the language model without changing the governance logic.
Article 86 - Right to an Explanation: Beyond the six operator obligations, Art. 86 gives every affected person a claim to an explanation of the individual decision - not of the system in general, but of this one case. That question can be answered only through a decision act per micro-decision: input, applied business rule including version, confidence, result, and contestation path. The Decision Layer creates this act at the moment of the decision, making the Art. 86 claim satisfiable per individual case.
Free eBook: AI in HR
EU AI Act checklist, Decision Framework, works council perspective, and readiness assessment - the governance handbook for HR leaders.
Download for freeWhat This Means for HR Departments
Companies that use or plan to use AI in HR processes today should build governance structures in time for the high-risk deadline of 2 December 2027 - while meeting the Art. 50 transparency duties that already apply. This specifically means:
Documented decision logic for every AI-supported HR process. Technically enforced Human-in-the-Loop mechanisms for decisions with personnel impact. Audit-proof audit trails that make traceable how every decision was made. Bias monitoring that detects and reports discriminatory patterns.
In Germany, the requirements of the Works Constitution Act (Betriebsverfassungsgesetz) add to this: works councils have a co-determination right for technical facilities that monitor the behaviour or performance of employees (§ 87(1) No. 6 BetrVG). AI agents in HR processes fall under this category.
The Decision Layer addresses both requirement blocks - EU AI Act and German co-determination law (Mitbestimmungsrecht) - in one architecture.
→ The Decision Act: Why Every AI Decision Must Be Contestable
→ Co-determination and works council
→ HR Agent
Schedule a call - We’ll show you which of your HR processes fall under the high-risk category and how the Decision Layer meets the requirements.

Bert Gogolin
CEO & Founder, Gosign
AI Governance Briefing
Enterprise AI, regulation, and infrastructure - once a month, directly from me.