Skip to main content

Many AI systems used in performance reviews or promotion decisions fall into the EU AI Act’s high-risk category, bringing specific requirements for providers and employers that deploy them.

Key Takeaways

  • AI used for promotion, termination, task allocation, or worker monitoring and evaluation is generally classified as high-risk under the EU AI Act.
  • Emotion recognition in the workplace is a separate prohibited practice, with narrow medical and safety exceptions.
  • High-risk employment AI carries requirements around risk management, documentation, human oversight, record-keeping, and worker notification. The relevant high-risk rules now apply from December 2, 2027.

High-Risk Does Not Mean Banned

The EU AI Act treats many employment systems as high-risk because they can affect people's careers, livelihoods, and rights.

That includes AI systems used for:

  • Recruitment and candidate evaluation
  • Promotion or termination decisions
  • Task allocation based on behavior or personal characteristics
  • Monitoring or evaluating worker performance and behavior

These systems fall under the Act's high-risk framework. That means they can be used if the applicable requirements are met; the classification itself is not a ban.

There’s a narrow exception in Article 6 for some Annex III systems that don’t pose a significant risk and don’t materially influence a decision. For example, the exception can cover certain narrow procedural or preparatory tasks.

But there’s an important limit: a system that profiles natural persons is always considered high-risk under Annex III. A provider relying on the exception also has to document that assessment before placing the system on the market or putting it into service.

What the EU AI Act Actually Prohibits

The Act separately prohibits certain AI practices outright.

One especially relevant to employers is using AI to infer a person's emotions in the workplace, except for narrow medical or safety reasons.

That’s different from using AI to evaluate work output or support an employment decision. A system doesn’t become an emotion-recognition system simply because its output may influence a performance review or promotion.

For employers, these are two separate questions:

  • Is the system being used to infer emotion in the workplace? That may fall under a prohibited practice.
  • Is it being used to monitor, evaluate, promote, terminate, or allocate work? That may make it a high-risk employment system.

What High-Risk Classification Requires

The Act divides responsibilities between the company providing the high-risk AI system and the organization deploying it.

Provider Responsibilities

High-risk AI providers are responsible for requirements, including:

  • Ongoing risk management
  • Data governance
  • Technical documentation
  • Automatic record-keeping
  • Human oversight built into the system
  • Accuracy, robustness, and cybersecurity
  • Quality management
  • Conformity assessment before the system is placed on the market

Employer and Deployer Responsibilities

Organizations using high-risk AI have their own obligations under Article 26, including:

  • Using the system according to the provider's instructions
  • Assigning human oversight to people with appropriate competence, training, and authority
  • Monitoring the system and reporting certain risks or incidents
  • Keeping relevant input data appropriate where the organization controls that data
  • Retaining automatically generated logs for at least six months when those logs are under the deployer's control

Employers also have workplace-specific duties. Before using a high-risk AI system at work, they must inform affected workers and workers' representatives. Some deployers must also inform individuals when an Annex III system makes or assists with decisions about them.

When Do the High-Risk Employment Rules Apply?

The timeline changed in 2026.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the application date for high-risk systems classified under Article 6(2) and Annex III to December 2, 2027. That category includes the employment systems discussed here.

That gives buyers and vendors more implementation time, but it doesn't make readiness irrelevant.

A vendor doesn’t necessarily need to have completed every future requirement today. What matters now is whether it can explain how it plans to meet them.

What Buyers Should Ask Vendors Now

If you're evaluating AI that may affect employee monitoring, performance, promotion, or termination, ask:

  • How does the vendor classify the system under the EU AI Act?
  • If the vendor says the system is not high-risk, what Article 6 exception is it relying on, and has that assessment been documented?
  • How will human oversight work?
  • What logs and documentation will be available to your organization?
  • What responsibilities fall on the vendor, and what responsibilities fall on you as the deployer?
  • What is the vendor's readiness plan for December 2, 2027?

Specific answers are more useful than a generic claim that a product is “EU AI Act compliant.”

Frequently Asked Questions

Does the EU AI Act ban AI in performance reviews?

No. Many AI systems used to monitor or evaluate workers or support promotion and termination decisions are classified as high-risk rather than prohibited. Their use comes with specific compliance requirements.

Is workplace emotion recognition banned under the EU AI Act?

Generally, yes. The Act prohibits AI used to infer emotions in the workplace, subject to narrow exceptions for medical or safety reasons.

Do employers have obligations if they use high-risk employment AI?

Yes. Deployers have duties around human oversight, monitoring, logs, and proper use of the system. Employers also have specific notification duties for workers and workers' representatives.

Measure Enterprise AI Without Individual Rankings

Larridin helps organizations measure AI adoption, proficiency, spend, and business impact without using individual employee rankings as the measure of success.

Talk to an expert.