Skip to content

Brought to you by

Dentons logo in black and white

UK Employment and Pensions Hub

The latest updates in employment, benefits, and pensions

open menu close menu

UK Employment and Pensions Hub

  • Home
  • Who We Are
    • Meet the team
  • How we can help
  • Events and training

EU AI Act: draft guidance on the use of high-risk AI in the workplace

By Hannah Harris
September 10, 2026
  • Artificial intelligence
  • Legislative changes
Share on Facebook Share on Twitter Share via email Share on LinkedIn

If your organisation uses AI to screen CVs, rank job candidates, monitor employee performance or allocate shifts, you will likely need to comply with the EU’s new high-risk AI rules from December 2027. The European Commission recently closed its consultation on draft guidelines clarifying which “high-risk” AI systems fall within scope of the EU AI Act (the Act). The threshold is lower than many employers may expect.

The draft guidance provides the clearest indication to date of how the Commission interprets the high-risk classification rules and is expected to guide enforcement once the relevant rules apply from 2 December 2027. The Commission expects to publish the final guidelines by the end of 2026.

In a previous blog (available here), we looked more generally at which AI systems may be classed as high risk under the Act and what this may mean for employers. The new draft guidance builds on that framework by providing more detail on how the classification rules may apply in practice, including through several examples relating specifically to recruitment and workforce management.

As well as EU-based employers, these developments are also relevant to many UK employers. The Act can apply to organisations established outside the EU where the output of an AI system is used in the EU, including UK-headquartered businesses with EU operations.

What does the draft guidance say about HR systems?

The Act classifies certain AI systems used in recruitment and workforce management as high risk, subject to limited exemptions. This includes systems used to evaluate candidates, make decisions about promotion or termination, allocate work based on individual behaviour or monitor workers’ performance.

The draft guidance provides more practical detail on where the classification line may fall. A key consideration is whether an AI system materially influences the outcome of a decision affecting an individual.

The Commission gives examples of high-risk systems which:

  • score or rank candidates and produce recruitment shortlists;
  • score candidates’ written or oral responses during recruitment;
  • conduct background checks and produce candidate risk scores;
  • determine which individuals are shown particular job advertisements; and
  • allocate shifts based on factors such as punctuality, performance ratings or previous acceptance of shifts.

These examples suggest that the Commission’s focus is on the substantive role AI plays in the decision-making process. Systems that analyse, filter, score or rank individuals, or generate evaluations relied upon in employment decisions, are more likely to fall within the high-risk regime.

When AI in HR is not high risk

The Commission makes clear that not every tool used within an HR process will necessarily be high risk. The Act provides exemptions for certain systems that do not materially influence decision-making, including those performing narrow procedural or preparatory tasks. The guidance includes examples of AI systems used to schedule candidate interviews or one which may verify a candidate’s professional accreditation against an official register. A tool that recognises and organises information in CVs without assessing candidates may also qualify for an exemption.

The distinction is therefore less about whether AI appears somewhere in an HR process and more about whether it has a substantive influence on the outcome.

Does human involvement make a difference?

Having a human make the final decision does not, by itself, prevent a system from being classified as high risk. The Commission gives the example of a recruitment system that scores and ranks candidates. Although recruiters can review or override its recommendations, the Commission considers the system high risk where those scores and rankings are primary input into the recruitment decision.

The guidance also indicates that the assessment should look at the overall decision-making process. Where several AI tools or components work together and their combined outputs materially influence a decision, dividing the functions between separate tools will not necessarily prevent the overall system from being classified as high risk.

Employers may therefore need to consider how AI operates in practice, rather than relying on a tool being described as merely assistive, or on the fact that a manager may ultimately sign off on the decision.

How to prepare

Although the relevant high-risk employment rules will not apply until 2 December 2027, you may wish to use this period to ensure you understand how you are using AI.

In particular, consider:

  • mapping your use of AI across recruitment, performance management, monitoring, scheduling, promotion and termination;
  • understanding what individual systems actually do, particularly whether they score, rank, filter or otherwise evaluate individuals;
  • reviewing AI-enabled workflows as a whole, rather than looking only at individual tools in isolation;
  • engaging with providers about how they have classified their systems and what information is available to support your compliance obligations; and
  • maintaining appropriate records of how you use high-risk AI systems and the decisions made with their assistance, as the Act requires deployers to keep logs of system use.

It is also important to consider wider employment law issues, including discrimination, data protection and employee information or consultation requirements.

If you use high-risk AI tools, you will also be subject to specific obligations under the Act, including the requirement to assign human oversight to individuals with the necessary competence, training and authority. In practice, this may mean designating a named individual (or role) responsible for reviewing AI outputs before managers action decisions and ensuring that person has the training and authority to override the system. Before putting a high-risk AI system into service or using it in the workplace, the Act also requires you to inform workers’ representatives and affected workers that they will be subject to its use.

Key takeaways

Although the Commission’s guidelines remain in draft, they provide useful insight into how the high-risk rules may operate in practice. There are four key points to take away:

  • AI systems that score, rank, filter or evaluate workers or candidates are likely to be high risk, even where a human makes the final decision.
  • The test is substantive influence: the question is what the AI actually does, not how it is labelled or marketed.
  • UK employers with EU operations, or whose AI outputs are used in the EU, fall within scope and should start preparing now.
  • Use the lead-in period to map your current AI use, engage vendors on compliance support, assign human oversight responsibilities and build the processes you will need.

Share on Facebook Share on Twitter Share via email Share on LinkedIn
Subscribe and stay updated
Receive our latest blog posts by email.
Stay in Touch
Artificial intelligence, legislative changes
Hannah Harris

About Hannah Harris

All posts Full bio

You might also like...

  • Atypical workers
  • Employee benefits
  • Employment contracts
  • Employment policies
  • Employment status
  • Holiday pay
  • Legislative changes
  • Pay, benefits and bonuses

Employers’ essential read: new government guidance on holiday pay and entitlement

By Alison Weatherhead and Lorelle Doyle
  • Industrial action
  • Legislative changes
  • Trade unions

High Court declares regulations allowing use of agency staff to replace striking workers to be unlawful

By Alison Weatherhead and Laura Jackson
  • Disciplinary procedures
  • Employment policies
  • General
  • Legislation
  • Legislative changes
  • Proposed legislative changes
  • Vicarious liability

New employer considerations amid the UK government’s introduction of a “failure to prevent fraud” offence

By Laura Jackson

About Dentons

Redefining possibilities. Together, everywhere. For more information visit dentons.com

Grow, Protect, Operate, Finance. Dentons, the law firm of the future is here. Copyright 2023 Dentons. Dentons is a global legal practice providing client services worldwide through its member firms and affiliates. Please see dentons.com for Legal notices.

Categories

Dentons logo in black and white

© 2026 Dentons

  • Legal notices
  • Privacy policy
  • Terms of use
  • Cookies on this site