*Editor's note, 3 August 2026: until 27 July 2026, 2 August 2026 still applied to central requirements of the AI Act. Under the 'Digital Omnibus on AI', however, some obligations, in particular those for high risk systems, were postponed to December 2027. The obligations for high risk systems named in this article therefore apply from 2 December 2027.
With the EU AI Act, which came into force on 1 August 2024, the European Union created a binding legal framework for the use of artificial intelligence for the first time. The regulation applies regardless of sector and company size and therefore concerns the mid market directly. It is less a technology law than a set of rules for responsible decision making with AI. What matters for companies is that the EU AI Act does not only address providers of AI systems. Organisations that use AI systems and AI features in standard software also carry responsibility, as deployers, for their use in their own context.
Requirements for AI applications in HR from August 2026*
For high risk AI applications in HR, the EU AI Act requires deployers from this August in particular to have structured risk management, to assure data quality and prevent bias, to document contexts of use traceably, and to guarantee human oversight and final decision making authority. Providers of a high risk AI system are additionally subject to further technical, organisational and documentation obligations.
For a first classification of the risk level, the guiding question for any HR department using AI is therefore: does this AI application influence decisions about career opportunities, working conditions or the continuation of an employment relationship? It is enough for the AI to act in a recommending or preparatory role if those recommendations are regularly followed in practice.
Classifying the risk of typical HR use cases with AI
AI does not present a uniform risk. Depending on where and how it is used, it can have very different effects. The EU AI Act therefore takes a risk based approach and distinguishes four risk categories:
- Prohibited AI practices are incompatible with European fundamental values (for example manipulative or heavily surveillant systems) and are banned in principle.
- High risk AI systems cover applications capable of significantly affecting people's fundamental rights, safety or career opportunities. They are permitted but subject to strict requirements.
- AI systems with limited risk carry transparency obligations, such as labelling AI interactions.
- AI systems with minimal risk remain largely unregulated.
Fairly uncritical use cases include HR chatbots for standard enquiries or automated text and document creation. Here AI supports processes without taking decisions about people.
A more differentiated view is needed for learning and development applications in particular. Content recommendations or learning assistants are typically not high risk. High risk relevance arises, however, wherever AI systems assess learning outcomes or control access to education or development measures.
Especially sensitive use cases lie in recruitment or in performance and talent management, when AI prepares or influences assessments, rankings or decisions to end an employment relationship.
For companies this means: not every AI application in HR calls for action, but every application has to be made visible and classified. This differentiation is the key to making the regulatory requirements manageable without slowing the use of AI unnecessarily.
How can the mid market approach the EU AI Act pragmatically in HR?
The EU AI Act calls for clear responsibilities and traceable processes in the use of AI. For those responsible for HR, four pragmatic fields of action follow:
- Create transparency: where is AI already in use in HR, deliberately or as a feature of a software solution?
- Classify use cases: which AI applications influence decisions about people?
- Settle governance: who is responsible for the use of AI? How do HR, IT, data protection, legal and, where applicable, the works council work together?
- Enable HR: those responsible in HR need the ability to interpret AI results, question them critically and take responsibility.
In many companies the use of AI in HR is still at an early stage. The EU AI Act can be used as a point of orientation for setting AI up and developing it further in a structured, purposeful way along clear decision logics.
THE MAK'ED TEAM helps mid sized companies place the EU AI Act in their HR context in a practical way, from classifying existing AI applications through structured risk differentiation to designing and implementing workable governance structures.


.avif)

