Guide · HR & Talent Acquisition

AI across hiring, performance and dismissal.

AI takes real work off an HR team — and it can quietly land you a high-risk system the EU AI Act regulates hard. The line runs through the whole people lifecycle: recruitment and talent acquisition, performance management, and decisions on promotion, terms and termination. This guide is for the people who own that line — HR and talent-acquisition leaders, HR business partners, the people driving AI adoption, and change managers — and it sorts the easy wins from the systems you must handle with real care.

Start with the map

Four tiers, not two.

“AI in HR” is not one thing. The Act sorts it into four tiers by what the tool actually does to people — and the same-sounding tool can land in any of them. Knowing which tier you are in is the whole game.

Tier 1 · Minimal

AI just speeds you up

Drafting a job advert, summarising long CVs for your own reading, turning interview notes into actions, brainstorming a policy. The AI proposes; a person decides; nobody is filtered out by the machine. This is where everyday, assistive AI in HR belongs.

Tier 2 · Limited

You owe people transparency

A chatbot that answers staff questions on leave, policy or benefits. Permitted and useful — but people must be told they are dealing with an AI, and edge cases must reach a human. The duty here is honesty, not a compliance programme.

Tier 3 · High-risk

The Act lands with full weight

AI that selects, scores, monitors or ranks people — across recruitment, performance, promotion, the terms of the job and termination. This is where the obligations, the paperwork and the penalties concentrate. Most of this guide is about this tier.

Tier 4 · Prohibited

A line you cannot cross

Some workplace AI is banned outright, not merely regulated. Emotion recognition at work — inferring mood, stress or engagement from a face or a voice in an interview or at a desk — is a prohibited practice under Article 5, in force since February 2025, with only narrow medical and safety exceptions.

The line to hold across all of HR: don’t let assist drift into decide. The moment AI starts selecting, scoring or monitoring people, you have moved into Tier 3 — and a different body of law applies.

How the Act decides

The gateway — and the one narrow way out.

Employment is one of eight “high-risk” areas the Act singles out (Annex III, point 4). The rule of thumb is blunt: if an AI system is used for recruitment, selection or in-work decisions about people, it is presumed high-risk (Article 6) — and the burden is on you to show it is not.

There is one narrow escape. A system doing genuinely preparatory or procedural work — work that does not materially shape the decision — can fall outside the high-risk tier (Article 6(3)). But it is far narrower than vendors imply, and it has an absolute limit: once a system profiles people, the escape no longer applies. Profiling means evaluating personal aspects to assess or predict someone’s performance, behaviour or traits — which is exactly what scoring, ranking and matching tools are built to do.

So the operative question is rarely “is this preparatory?” It is “does this rank, score, filter or profile a person?” Four tools with near-identical sales pitches can land in four different classifications. The label is the vendor’s; the law follows the function.

The European Commission’s detailed Article 6 / Annex III classification guidelines are still in draft and out for consultation — useful for direction, but not yet settled soft law. The principles above are drawn from the Regulation itself.

The heart of it

Three places the Act treats employment AI as high-risk.

Annex III, point 4 splits into two limbs — (a) recruitment and selection, and (b) in-work decisions and monitoring. Between them they cover the whole hiring-to-firing arc. Here is each area, with worked examples of what crosses the line and what tends not to.

Annex III(4)(a)

Recruitment & talent acquisition

The Act names AI used “for the recruitment or selection of natural persons” — in particular to place targeted job adverts, to analyse and filter applications, and to evaluate candidates. In plain terms: the moment AI helps decide who gets through, it is in scope.

CV screening or ranking that filters or shortlists applicants High-risk
AI scoring of recorded interviews, tests or assessments High-risk
Job-advert delivery that targets people by an inferred profile High-risk
An inclusive-language check that only edits the advert text Likely safe
A neutral “key strengths” summary a recruiter routinely overrides Depends

Annex III(4)(b)

Performance management

The same point covers AI used “to monitor and evaluate the performance and behaviour” of workers, and to allocate tasks based on individual behaviour, traits or characteristics. People-analytics and productivity-monitoring tools are the usual culprits — and they tend to profile, which makes the high-risk classification very hard to argue away.

Productivity or behaviour monitoring that scores or rates staff High-risk
People-analytics that feeds promotion, pay or task allocation High-risk
Task allocation driven by inferred personal traits High-risk
An anomaly flag a manager reviews, with the manager deciding Likely safe
A tool that only polishes the wording of a written review Likely safe

Annex III(4)(b)

Promotion, terms & dismissal

Annex III names “termination of work-related contractual relationships” in as many words, alongside promotion and decisions on the terms of the job. A tool that makes or materially shapes a dismissal, redundancy or promotion call is squarely high-risk — there is no clever reading that takes a firing tool out of the category.

A “flight-risk” or “termination-risk” model that flags people for action High-risk
Scoring that drives a redundancy, dismissal or promotion decision High-risk
Auto-deactivating a worker’s account on a falling score High-risk
A model that only schedules an already-decided review meeting Likely safe

The most-cited warning is real: a major retailer built an experimental CV-screening tool, trained it on a decade of mostly male CVs, and it taught itself to downgrade the word “women’s” and graduates of two women’s colleges. The firm scrapped it before it ever screened a real candidate. The technology wasn’t malicious — the use was wrong.

Reported by Reuters, 2018.

If you run one

What a high-risk system then requires of you.

Run a high-risk employment system and you are its deployer — the operator. Your duties are real but manageable, and they cluster around two things the Act cares about most: a human genuinely in control, and an explanation a person can actually understand.

Human oversight that is real

A named, competent person with the training, authority and time to understand the output and genuinely override it. A rubber-stamp is not oversight — and under the GDPR it does not break “solely automated”, so the machine is still treated as the decider.

Art. 26(2)

Tell the workforce first

Before the system goes live, inform the affected staff and their representatives that they will be subject to it — through the worker-information rules of national law. This is a precondition, not an afterthought.

Art. 26(7)

Tell the individual

Where the system makes or assists a decision about a specific person, that person must be told an AI is in the loop. A rejected candidate or a passed-over employee is entitled to know.

Art. 26(11)

An explanation that stands up

A person significantly affected by such a decision can demand a clear, meaningful explanation of the AI’s role and the main elements of the decision. Logs, input-data relevance and at least six months of records are what let you give one.

Art. 86

On the explanation, two regimes point the same way — the AI Act’s right to explanation and the GDPR’s rules on automated decisions. Our reading is that they are two doors into the same room — though the GDPR’s door opens on a decision made solely by the machine with significant effect, and the AI Act’s on a high-risk system assisting the decision: a meaningful human in the loop, and a reason a rejected candidate or dismissed employee can understand and contest. Europe’s top court has already shut the usual escape routes — the score that drives a decision is the decision (the SCHUFA ruling, C-634/21, 2023), and “it’s our proprietary algorithm” is not a lawful answer: the explanation must be intelligible, and a trade-secret claim is balanced by a court or regulator, not used to refuse outright (Dun & Bradstreet, C-203/22, February 2025).

A fundamental-rights impact assessment — a structured check of who a system could harm — before go-live is mandatory for public-sector employers (and a few other deployers); for private employers it is not strictly required for hiring systems, but we treat it as good practice — one assessment discharges several duties at once and is your evidence if a regulator asks.

A Luxembourg gate, and a wider European reality. In Luxembourg you cannot quietly switch on a monitoring tool over staff: the staff delegation must be informed first and can refer the system to the data-protection regulator (the CNPD) within a 15-day window that suspends the rollout. Across the border, a French court has already suspended an HR-AI deployment for skipping works-council consultation — while a genuinely temporary, voluntary pilot survived the same challenge. “AI is just software” is not a defence in Europe.

General-purpose AI

The chatbot on your desk: a brilliant assistant, a dangerous judge.

General-purpose AI — the models behind ChatGPT, Claude and Gemini — is where most HR teams meet AI first, and for good reason. Used as an assistant it is a genuine win: drafting job adverts and rejection letters, summarising CVs and interview notes for your own reading, generating outreach variants, building a first-draft policy, designing training. All of this stays low-risk — as long as a person writes the decision and no automated gate is built.

The trap is the next step, and it is quiet. Point that same general model at a decision about people — “rank these 200 CVs”, “score each candidate out of 100”, “flag who to put on a performance plan” — and you have not found a productivity hack. You have built a high-risk hiring or performance system with none of the controls. The prompt is the act that does it.

Three things then go wrong at once. Bias is industrialised: a general model trained on your past decisions reproduces old patterns at scale, across every applicant, behind a tidy-looking score. Data leaks: a recruiter pasting a candidate shortlist or an employee’s record into a personal chatbot account hands it to a tool you have no contract with and cannot control. And no explanation survives: a black-box prompt chain cannot produce the intelligible, contestable reason the law now requires. Banning the tools doesn’t fix this — it just pushes the same work into personal accounts where you can neither see it nor defend it. Governed, sanctioned tools are the fix.

A note on who owes what: the heavy obligations on the general-purpose model itself sit upstream, with the company that built it — not with you for using ChatGPT. Your exposure runs through a different door, explained next: by repurposing the tool, you can become the provider of a high-risk system.

A role you can change by accident

You’re a deployer — until you’re a provider.

The Act splits the world into roles. A provider builds an AI system or puts it on the market — the maker. A deployer runs one in their own organisation — the operator. Most employers are deployers, with the manageable duties above. But three everyday moves flip you into being the provider, and you inherit a maker’s full obligations (Article 25):

  • Rebrand — put your own name or brand on a high-risk system someone else built.
  • Modify — change a high-risk system substantially, beyond what its maker planned and tested.
  • Repurpose — take a tool that wasn’t high-risk (including a general chatbot) and point it at a high-risk job. This is the common one in HR: wiring a general model into a pipeline that ranks, scores or shortlists candidates is exactly this move.

Why it matters: a provider’s duties are a different order of work — a conformity assessment (a formal, documented check that a system meets the law before launch), technical documentation, a quality-management system, CE marking, EU-database registration and post-market monitoring for the life of the system. None of it can be retrofitted after go-live. Nobody ever signs a note saying “we are now the provider of a high-risk AI system” — you discover it later, from the wrong side, often when an enterprise buyer’s due diligence asks “so who is the provider here?” and you have no clean answer.

Calling the change a “configuration”, a “wrapper”, a “light fine-tune” or “just a pilot” is no defence — the Act looks at what the system does, not the name on the change request. The full mechanism, with a two-minute self-check, is in Deployer or provider?

What it costs when it goes wrong

Three penalty regimes, not one.

Getting this wrong is rarely one fine: three separate regimes can apply to the same conduct, and in Luxembourg one of them is criminal.

EU AI Act

Breaching a prohibited practice can cost up to 35 million euros, or 7% of total worldwide annual turnover — whichever is higher. Breaching the high-risk obligations that fall on deployers and providers: up to 15 million euros or 3%. Giving authorities incorrect information: up to 7.5 million euros or 1%. Smaller firms and start-ups are capped at the lower of the two figures.

Art. 99

The GDPR

Almost every high-risk HR use also processes personal data, so the GDPR runs in parallel — applying alongside the AI Act, not instead of it. Its upper tier, which covers automated decisions and the data-subject rights, reaches up to 20 million euros or 4% of worldwide annual turnover.

Art. 83

Luxembourg law

In Luxembourg, the workplace-monitoring rules sit in the Labour Code (Code du travail): an employer needs a lawful basis and must inform the staff delegation before monitoring staff. Breaching those rules is an offence that carries a criminal sanction — imprisonment of eight days to one year and/or a fine of 251 to 125 000 euros (up to roughly double that, about 250 000 euros, for a company), prosecuted by the public prosecutor — alongside the data-protection exposure.

Code du travail, L.261-2

These regimes apply in parallel, not as alternatives — but they do not simply add up without limit. The EU principle of ne bis in idem (Article 50 of the Charter) and the requirement of proportionality constrain how far criminal and administrative penalties for the same conduct may be combined, and the AI Act requires an authority to weigh fines already imposed on the same operator for the same activity (Article 99(7)). The exposure is cumulative; the total must stay proportionate to the wrongdoing.

And the costs that never reach a fine are often the sharpest: a discrimination claim; a works council that halts your rollout overnight; the enterprise deal that stalls in due diligence; and the reputational damage of a public bias story, which outlasts any penalty. Europe has seen where un-governed scoring leads — the Dutch childcare-benefits scandal, where an opaque risk-scoring system wrongly ruined tens of thousands of families and helped bring down a government. And “the AI did it” has already failed in court: when an airline argued its chatbot was a separate entity responsible for its own words, the tribunal called that remarkable and held the company liable anyway.

One date worth knowing — and one trap inside it. The AI Act’s high-risk obligations for employment systems were due to apply from 2 August 2026; the Digital Omnibus reform, adopted by the Council on 29-06-2026, has deferred them to 2 December 2027. But the deadline that moved is not the exposure. The GDPR’s rules on automated decisions, and national labour law — including the Luxembourg monitoring gate and French works-council consultation — already apply today. The high-risk clock buys you time to prepare; it does not put HR AI on hold.

How Kramer Consulting helps

From the map to a defensible position.

We deliver the AI training for HR and talent-acquisition professionals at the Digital Learning Hub in Belval — from using AI in learning and development to the full practical-and-high-risk day on AI for HR and talent acquisition that walks through exactly these tiers. We place each of your AI systems on the right side of the line through the AI Act Compliance Accelerator — and turn the Act’s employment duties into role-by-role capability with Reg-to-Skills. And for the training-design side of all this — where, unlike hiring, almost everything is low-risk — see the companion guide, AI for learning and development.

This guide is general information to help you ask better questions — not legal advice on any specific system or situation.

Bring your HR use case — and we’ll place it on the map.

Easy win or high-risk system? An honest read, no pitch.

Book a discovery call