The AI Act

The AI Act (Regulation (EU) 2024/1689) establishes harmonised EU-wide rules on the use of artificial intelligence for the first time. The majority of its provisions have applied since 2 August 2026. Employers who make AI systems available to their employees qualify as deployers and are therefore subject to transparency, documentation and support obligations. This overview sets out which obligations already apply, what to consider when using AI in recruiting, and which sanctions may follow.
The AI Act: what employers now need to consider
Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (the AI Act) establishes EU-wide rules on the use of artificial intelligence for the first time. The Regulation entered into force on 1 August 2024 and applies in stages. The majority of its provisions have applied since 2 August 2026. Several of those provisions are of particular relevance to employers.
AI systems in the professional context
Where a natural or legal person (authority, agency or other body) uses an AI system under its own authority in the course of a professional, commercial or business activity, that person qualifies as a deployer within the meaning of Article 3(4) of the AI Act. Deployers of an AI system must comply with a range of obligations – depending on whether the system is a high-risk, limited-risk or minimal-risk AI system.
Where an employer makes an AI system available to employees in a professional context and under its organisational responsibility, the employer qualifies as a deployer within the meaning of the AI Act.
Transparency obligations under Article 50 of the AI Act for limited-risk AI systems
Deployers of AI systems that pose only a limited risk must comply with the transparency obligations under Article 50 of the AI Act:
- Deepfakes – that is, image, video or audio content generated or manipulated by an AI system that resembles real persons, facts or places and falsely appears authentic or truthful – must be disclosed by the deployer of the AI system as artificially generated or manipulated.
- AI-generated text content published to inform the public on matters of public interest must be disclosed as such by the deployer. Exception: the content is subject to human review or editorial control and a natural or legal person holds editorial responsibility.
- Deployers of an emotion recognition system within the meaning of Article 50 of the AI Act – that is, an AI system intended to identify or infer the emotions or intentions of natural persons on the basis of their biometric data – must inform the natural persons concerned about the operation of the system and the processing of personal data.
Note: AI systems for emotion recognition in the workplace are in principle prohibited under Article 5(1)(f) of the AI Act.
High-risk AI systems
For employers using AI systems as part of their recruiting process, the provisions of the AI Act on high-risk AI systems may be relevant.
Under Article 6(2) in conjunction with Annex III point 4(a) of the AI Act, a high-risk AI system is an AI system intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to screen or filter applications and to evaluate candidates. Chatbots may under certain circumstances also constitute a high-risk AI system.
An employer acting as the deployer of a high-risk AI system in the recruiting process is subject to numerous obligations, in particular the establishment of appropriate technical and organisational measures, monitoring obligations as well as information and record-keeping obligations.
By virtue of Regulation (EU) 2026/1744 (the Digital Omnibus Regulation on AI), the obligations imposed on the deployer of a high-risk AI system under Articles 26 and 86 of the AI Act – irrespective of Article 50 of the AI Act – only take effect on 2 December 2027.
AI literacy
Employers should take stock of the AI systems currently in use in order to be able to meet their obligations according to the category of the AI system concerned. Documenting the software in use – which may also include AI systems – and the AI systems deployed, and keeping these records up to date, is advisable.
Under Article 4 of the AI Act, as already amended by the Digital Omnibus Regulation on AI, employers acting as deployers of AI systems must support staff dealing with the operation and use of AI systems on their behalf in acquiring AI literacy.
AI literacy means the skills and knowledge that make it possible to deploy AI systems competently and to become aware of the opportunities and risks of AI and of the possible harm it may cause.
With regard to training content, the AI Act focuses in particular on the technical knowledge, experience and education of the employees concerned as well as the context in which the AI systems are to be used.
The obligation originally provided for in the AI Act requiring deployers to ensure AI literacy has been significantly softened by the Digital Omnibus Regulation on AI. A guarantee of a particular level of AI literacy is now expressly ruled out.
Sanctions
Articles 99 et seq of the AI Act provide for substantial fines depending on the infringement concerned. Companies infringing the obligations under Articles 26 or 50 of the AI Act face fines of up to EUR 15,000,000 or up to 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Different sanctions apply to SMEs, small mid-cap companies and start-ups.
Do you have questions about implementing the AI Act in your company?
We are happy to advise you on the legally compliant implementation of the AI Act in your company.
The AI Act – the key questions for employers
What does the AI Act regulate and since when has it applied?
Regulation (EU) 2024/1689 (the AI Act) establishes harmonised EU-wide rules on the use of artificial intelligence for the first time. It entered into force on 1 August 2024 and applies in stages – for employers, the transparency obligations under Article 50 of the AI Act have been particularly relevant since 2 August 2026.
Does the AI Act also apply to employers who do not develop AI themselves?
Yes. Anyone using an AI system under their own authority qualifies as a deployer within the meaning of Article 3(4) of the AI Act. This also applies to employers who make AI systems available to their employees for professional use. Only use in the course of a purely personal, non-professional activity is excluded.
Which transparency obligations apply to employers as deployers?
Deepfakes generated by AI must be disclosed as artificially generated or manipulated; AI-generated texts published to inform the public on matters of public interest must likewise be disclosed (except where there is human review or editorial responsibility). Special requirements apply to the use of emotion recognition systems.
What applies where employers use AI systems in recruiting?
Here, the stricter provisions on high-risk AI systems may apply: AI systems intended to be used for the recruitment or selection of candidates – for instance for targeted job advertisements, for screening and filtering applications or for evaluating them – qualify as high-risk AI systems under Article 6(2) in conjunction with Annex III point 4(a) of the AI Act. Deployers are then subject to additional obligations under Articles 26 and 86 of the AI Act. Unlike the transparency obligations under Article 50 of the AI Act, these high-risk obligations are not yet in force: the Digital Omnibus Regulation on AI has postponed their date of application to 2 December 2027.
Must employers train their employees in the use of AI?
Article 4 of the AI Act obliges deployers to support their staff and persons acting on their behalf in acquiring sufficient AI literacy – tailored to their technical knowledge, experience, education and the particular context of use. The originally stricter obligation to ensure AI literacy was softened into an obligation to provide support by the Digital Omnibus Regulation on AI.
What sanctions apply in the event of infringements?
Articles 99 et seq of the AI Act provide for substantial fines depending on the infringement concerned. Companies infringing the obligations under Articles 26 or 50 face fines of up to EUR 15,000,000 or up to 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Different sanctions apply to SMEs, small mid-cap companies and start-ups.
What should employers do now in concrete terms?
It is advisable to take stock of the AI systems currently used in the company in order to assess the obligations that apply according to the relevant risk category, and to maintain ongoing documentation and keep it up to date. Employees should also receive adequate training in the use of AI systems.
.webp)
