The EU AI Act Explained: A Plain-English Guide to Risk Tiers and Who Is Affected

The EU AI Act sorts AI into 4 risk tiers. What it bans, why hiring tools count as high-risk, who must comply, and the dates after the 2026 amendment.

An illustrated cover card headed “The EU AI Act Explained”, with the line “A plain-English guide to risk tiers and who is affected”. Line drawing of an open laptop on a desk; on its screen three applicant cards drop into a funnel and one card comes out marked with an amber dot. Beside the laptop stands a thick rulebook with a bookmark and a shield on its cover.

The same chatbotchatbot: A program that holds a conversation in everyday language, replying to what a user types or says. Most of today's AI chatbots run on large language models, which can give fluent, confident answers that are partly or wholly wrong.Full entry in the glossary can sit outside the EU AI Act’s strict rules when it drafts a sales email and inside them when it ranks job applicants. That is the law’s design: the European Union’s AI Act regulates artificial intelligence by what it is used for, not by how it works. It bans a short list of practices, sets strict duties for high-risk uses, requires disclosure for chatbots and deepfakes, leaves most everyday AI alone and reaches companies outside the EU. For employers, the core is this: under the AI Act, AI used to recruit, promote, dismiss, allocate tasks to or evaluate workers is high-risk, and a 2026 amendment set the start of those rules at 2 December 2027.12

Three questions settle most of what the Act asks of an organization: what each AI tool is used for, whether you built or branded it or only use it, and whether its output is used in the EU.

Software that sorts job applicants is one of the uses the EU AI Act treats with most care.

What the EU AI Act is and why it sorts AI by risk

The EU AI Act is an EU regulation adopted in 2024, which the European Commission calls the first comprehensive legal framework on AI anywhere. Its logic, as the Commission explains it, is that most AI poses little or no risk, while certain uses threaten people’s safety or rights and need rules in proportion. Hiring is one of the Commission’s own examples: it is often impossible to tell why an AI system reached a decision, so it can be hard to judge whether a rejected applicant was treated unfairly.3

Definition

The EU AI Act (Regulation (EU) 2024/1689) is the European Union’s law on artificial intelligence. It sorts AI systems by the risk of their intended use and sets duties for the organizations that build and use them.

Picture one assistant used twice in a week. On Monday the sales team asks it to tidy a proposal, and a clumsy draft costs a few minutes. On Friday HR asks it to shortlist applicants, and a skewed ranking can cost someone a job without their ever learning why. The law puts its weight on Friday.

So the question to ask inside an organization is “What are we using this for?”, not “Is this tool covered?”, because one product can land in different tiers depending on the task. Our other guides to using AI at work cover the tools; this one covers the rules.

How the EU AI Act sorts AI into four risk tiers

The European Commission describes four levels of risk under the AI Act: unacceptable risk, which is banned; high risk, with strict obligations; transparency risk, which requires telling people; and minimal or no risk, with no new rules. The Commission says the vast majority of AI systems in use in the EU fall into the last group, such as spam filters.3

  1. Unacceptable risk: banned practices, such as emotion recognition at work or social scoring
  2. High risk: strict duties before and during use, for example AI that screens job applicants or evaluates staff
  3. Transparency risk: people must be told, for example when they talk to a chatbot or see a deepfake
  4. Minimal or no risk: no new rules; the Commission says most AI in use in the EU sits here, such as spam filters
The four risk levels of the EU AI Act. The widths are a sketch, not measured shares.

Scaling duties to risk puts the paperwork where harm is most likely, instead of burdening harmless tools. In a single office, a spam filter, a website chatbot, a CV-screening tool and a webcam feature that reads staff moods could each land in a different tier, from no new rules to banned.

The catch is that sorting real systems is harder than the pyramid suggests. In a 2023 white paper, appliedAI, a German initiative set up to speed up business use of AI, classified 106 enterprise AI systems from a database built in a project funded by Germany’s economy ministry. Measured against the Commission’s 2021 draft of the Act, about two in five could not be placed as high-risk or not, and employment was among the areas where the answer was most often unclear.4 The study predates the final text, so it shows the judgment is hard; it is not a current count.

What the Act bans outright, including at work

The AI Act bans harmful manipulation, exploiting people’s vulnerabilities, social scoring, predicting crime from profiling alone, scraping faces to build recognition databases, inferring emotions in workplaces and schools except for medical or safety reasons, and using biometrics to infer traits such as race or sexual orientation. These bans have applied since February 2025.1 A 2026 amendment added a ban on AI that generates non-consensual intimate images or child sexual abuse material, from December 2026.2

The workplace emotion ban reflects the power gap between employer and employee, and it starts at recruitment, the Commission’s 2025 guidelines on prohibited practices explain. Their examples: a call centre using webcams and voice analysis to track staff anger is banned, while analysing customers’ voices to help staff handle angry callers is not caught by this ban; reading emotions in hybrid-team video calls is banned, as is emotion recognition in recruitment or during probation. The guidelines are not binding; only the EU’s Court of Justice can give an authoritative reading.5

Myth
Reading employees' mood from video calls is fine if the goal is team wellbeing.
Fact
The Commission's 2025 guidelines give reading emotions from hybrid-team video calls, even to manage team dynamics, as an example of a banned practice.

What to watch for: “sentiment”, “engagement” or “mood” features in interview, meeting or call-monitoring software. Ask the vendor whether the feature infers the emotions of your staff or candidates from faces, voices, typing or other biometric data. If it does, and serves no medical or safety purpose, it is likely to fall under the ban; the guidelines put sentiment analysis of written text outside it.5

Hiring, promotion and monitoring: the high-risk uses employers meet

The AI Act lists employment as a high-risk area: AI used to recruit or select people, including targeting job ads, filtering applications and evaluating candidates, and AI used to decide promotions or dismissals, allocate tasks based on behaviour or personal traits, or monitor and evaluate workers.1 Such uses are also common.

The study

Limited evidence

Software that directs, tracks or rates staff is already common in EU firms (OECD, 2025)

In the four EU countries surveyed, an average of 79% of managers said their firms used at least one software tool to instruct, monitor or evaluate workers, against 90% in the United States and 40% in Japan. Nearly two-thirds of managers using such tools reported at least one concern, most often unclear accountability when a decision is wrong.6

Much of the software counted is not AI; the OECD notes the AI Act covers only a subset of it.6 What the survey shows is how ordinary managing staff through software already is in Europe.

There is a narrow exit. A listed system is not treated as high-risk if it poses no significant risk, for example because it performs a narrow procedural task, but a system that profiles people always stays high-risk. For employers, using a high-risk system brings duties: follow its instructions, give oversight to people with the competence, training and authority to act, keep its logs, and inform workers’ representatives and affected workers before it goes live at work. People it helps make decisions about must be told, and someone affected by a significant decision can ask for a clear explanation of the AI’s role.1

A worked example: a retailer buys a tool that ranks warehouse staff for shifts by their pick rates. That is task allocation based on individual behaviour, so it is likely high-risk. Where the high-risk rules apply, the retailer must name a manager who can overrule the ranking, keep the logs and inform staff and their representatives before launch.

Provider or deployer: which role your organization plays

Under the AI Act, a provider develops an AI system, or has one developed, and puts it on the market under its own name; a deployer is whoever puts an AI system to use under its own authority, unless the use is purely personal. A deployer becomes the provider of a high-risk system if it puts its name on one, substantially modifies it, or changes a general tool’s purpose so that it becomes high-risk.1 The Commission’s example: the developer of a CV-screening tool is the provider, and a bank using it is the deployer.7

Most duties for high-risk systems sit with the provider, which designs the system. The role switch is the trap. An HR team that builds a custom assistant on a general chatbot and uses it to score applicants may have made itself a provider without meaning to. Before repurposing a general AI tool for decisions about people, check with your legal team whether you are creating a new high-risk system.

Chatbots, deepfakes and general-purpose AI models

Since August 2026, the AI Act has required chatbots to tell people they are dealing with AI, deepfakes to be labelled, and AI-generated content to carry machine-readable marks, the European Commission announced in July 2026.8 Disclosure is the lightest tool in the Act: the risk it targets is deception, so the fix is telling people.

For most employers the duty is narrow. A company that uses AI to make a deepfake must say so, and AI-generated text published to inform the public on matters of public interest must be disclosed, unless a person reviewed it and someone holds editorial responsibility.1 In practice, a marketing video with an AI-generated likeness of a real person is labelled before publication.

Generative AIgenerative AI: AI systems that produce new text, images, audio or code in response to a request, by generating output that resembles the data they were trained on. Chatbots built on large language models are the best-known kind.Full entry in the glossary models themselves, such as the large models behind popular chatbots, fall under separate rules for general-purpose AI models. Their providers face rules on transparency and copyright, and providers of models that may pose systemic risks must also assess and reduce those risks. These rules have applied since August 2025, and the Commission’s AI Office can enforce them, including with fines, from August 2026.3 Giving staff a chatbot does not make you a model provider: your duties come from how you use it.

Who the Act reaches, and what breaking it costs

The AI Act applies to providers anywhere that place AI systems on the EU market, to deployers located in the EU, and to providers and deployers outside the EU whose AI output is used in the EU. Research before a system reaches the market is excluded, as are military, defence and national security uses, and EU countries may keep or adopt rules that protect workers more.1

The reach follows the effect, not the address. A US firm selling a screening tool to Dutch employers is a provider under the Act; a Singapore company using AI to sift applicants for a job in Milan may be a deployer whose output is used in the EU.

Each EU country sets penalties within caps in the regulation. Using a banned practice can cost up to EUR 35 million or 7 percent of worldwide annual turnover, whichever is higher; breaching most other duties, including a deployer’s duties and the transparency rules, up to EUR 15 million or 3 percent. For small and medium firms the cap is whichever amount is lower.1 The 2026 amendment extended that to small mid-cap firms for all but the top tier.2

When each part of the Act applies, after the 2026 amendment

The AI Act entered into force in August 2024 and applies in stages. Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since July 2026, moved the high-risk dates back because harmonised technical standards and national authorities were not ready.2

Date What applies Status on 24 September 2026
2 February 2025 Bans on eight practices; AI-literacy duty Applies1
2 August 2025 Rules for general-purpose AI model providers; governance and penalty rules Applies1
2 August 2026 General application, including transparency duties; enforcement by national authorities and the AI Office Applies3
2 December 2026 Ban on AI generating non-consensual intimate images or child sexual abuse material; marking deadline for generative systems already on the market Coming2
2 December 2027 High-risk rules for Annex III uses, including employment and worker management (originally August 2026) Coming2
2 August 2028 High-risk rules for AI built into regulated products, such as lifts or toys Coming3

The delay is not a pause. The bans already apply, as does the duty to support AI literacy among staff who use AI. And a high-risk system already on the market before December 2027 escapes the new rules only until its design changes significantly, so a hiring tool bought now can still be caught later.2 The practical move is to ask vendors today how their product will meet the high-risk rules, and to put the answer in the contract.

An employer's AI Act starting list

Whether the AI Act applies to a given system depends on facts no general guide can see: where your organization operates, what the tool does and who built it. Even the Commission’s own overview of enforcement warns that it does not replace the text of the Act.9

  • Now: if an interview, call or meeting tool turns out to infer how staff or candidates feel from their faces or voices, for no medical or safety reason, or you find anything else on the banned list, the cautious step is to pause that feature while your legal or compliance team reviews it.
  • Soon: before buying or rolling out AI for hiring, promotion, dismissal, task allocation or performance reviews, and before selling AI into the EU from another country, get advice from a lawyer who practises EU law on your role and duties.
  • Routine: when your AI policy is next revised, have compliance compare the AI inventory with the four tiers, with the data protection officer involved wherever personal data is; the AI Act does not switch off the GDPR.

The bottom line

Most office AI gains no new duties under the EU AI Act; what changes the picture is using AI to judge people. AI that screens applicants, allocates work or evaluates staff faces strict rules from 2 December 2027, and inferring workers’ emotions, outside medical or safety uses, is already banned. The cheapest step comes first: list your tools by what they do.

This article is general information, not legal advice. Rules differ by country and change over time; for your own situation, speak to a qualified lawyer or an official advice service where you live.

Frequently asked questions

Does the EU AI Act apply to UK or US companies?

It can. The regulation covers providers anywhere that place AI systems on the EU market, and providers and deployers outside the EU whose AI output is used in the EU. A US employer that screens candidates for a job in Germany with AI may therefore be covered for that use. Without such an EU link, local law decides, and a lawyer who practises EU law can say which side of the line a firm is on.

Is ChatGPT a high-risk AI system under the AI Act?

Not in itself. Large models such as the one behind ChatGPT fall under the Act's separate rules for general-purpose AI models, which bind the companies that build them. Risk tiers attach to uses: drafting an email is not a high-risk use, but using a general-purpose tool to rank job applicants can be, and the organization that turns it to that purpose can take on provider duties.

Does the AI Act replace the GDPR?

No. The AI Act says EU data protection law, including the GDPR, continues to apply to personal data processed in connection with it. The two work side by side: the AI Act asks deployers of high-risk systems to use the provider's information when they carry out the data protection impact assessment the GDPR may require, and a 2026 amendment lets deployers who must also assess fundamental-rights impacts cross-refer to that assessment.

Can employees complain if they think AI was used unlawfully at work?

Yes. Under the AI Act, any person who has grounds to think the regulation was breached may complain to the relevant national market surveillance authority, without losing other legal remedies. The Act also gives people affected by certain decisions based on high-risk AI a right to a clear explanation of the AI's role, and it lets EU countries keep or adopt laws more protective of workers.

Sources

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). European Parliament and Council of the European Union (13 June 2024). Official Journal of the European Union, L series, 12 July 2024
  2. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). European Parliament and Council of the European Union (8 July 2026). Official Journal of the European Union, L series, 24 July 2026
  3. AI Act. European Commission, Shaping Europe's digital future (last updated 3 August 2026)
  4. AI Act: Risk Classification of AI Systems from a Practical Perspective. appliedAI Initiative GmbH (2023). White paper
  5. Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act), C(2025) 5052 final. European Commission (2025)
  6. How widespread is algorithmic management in workplaces? OECD (19 December 2025). OECD policy brief, based on Milanez, A., Lemmens, A. & Ruggiu, C. (2025), Algorithmic management in the workplace
  7. Navigating the AI Act. European Commission, Shaping Europe's digital future (last updated 7 August 2026)
  8. Commission starts enforcing AI Act rules and new transparency requirements on 2 August. European Commission (31 July 2026)
  9. Enforcement of the AI Act. European Commission, Shaping Europe's digital future (last updated 24 August 2026)

How we researched this

We read Regulation (EU) 2024/1689 and its 2026 amendment, Regulation (EU) 2026/1744, on EUR-Lex, and checked every date against the European Commission's AI Act, enforcement and Q&A pages on 24 September 2026. We added the Commission's 2025 guidelines on prohibited practices, an OECD employer survey and an appliedAI white paper. Main limitation: key parts, such as the high-risk rules, have not yet been applied or tested in court.

Last updated . Read our editorial policy.

Cite this article: WiserHours. (2026). The EU AI Act Explained: A Plain-English Guide to Risk Tiers and Who Is Affected. WiserHours. https://wiserhours.com/ai-at-work/eu-ai-act/. Tables and charts may be reused with a link back to this page.