For certain uses of AI, the EU AI Act sets strict obligations, for example when software sorts job applications or assesses learning outcomes. With the AI Omnibus, these obligations apply later than originally planned: from December 2027 and from August 2028.
Whether you are affected depends on the purpose. The same program can be an ordinary office tool in one case and a high-risk system in another. The time until December 2027 is enough for a calm review of what you use.
What high-risk AI is
The AI Act classifies AI by risk. Systems that help decide on people’s opportunities, rights or safety count as high-risk. The areas are listed in Annex III of the AI Act, including:
- employment and HR, for example screening and assessing job applications
- education, for example assessing learning outcomes or deciding on admissions
- access to essential services, for example creditworthiness checks
- biometrics, critical infrastructure, law enforcement, migration, the administration of justice and democratic processes
Not every system in these areas is high-risk. If it only performs a narrowly defined or preparatory task and does not materially influence the decision, it does not count as high-risk AI. If it profiles people, it always counts as high-risk.
In addition, there is AI used as a safety component in products that already have to be tested, such as medical devices, lifts or toys (Annex I).
Which dates now apply
With the AI Omnibus, Regulation (EU) 2026/1744, the EU postponed the obligations for high-risk AI. For the areas in Annex III they apply from 2 December 2027, and for AI in regulated products under Annex I from 2 August 2028.
Other parts of the AI Act already apply. The AI literacy obligation under Article 4 has applied since 2 February 2025 to everyone who uses AI, regardless of risk. Since the same day, certain AI practices have been prohibited, such as emotion recognition in the workplace. Since 2 August 2026, the transparency obligations under Article 50 have applied.
How to classify your use of AI
A few questions are enough for an initial assessment. Go through them for each tool separately:
- If the tool produces texts, summaries, translations or research that do not decide about people, it is usually not high-risk AI. Article 4 and data protection law apply.
- If the tool operates in an area listed in Annex III, such as HR, education or credit checks, look more closely.
- If it assesses or sorts people there, or suggests a ranking, there is much to suggest high-risk AI.
- If it profiles people, it is always high-risk.
- If it only performs a narrowly defined or preparatory task and does not materially influence the decision, it may fall outside the high-risk classification. Record your reasoning in writing.
- If you use a general-purpose tool such as ChatGPT for such a purpose, for example to assess job applications, you may yourself count as a provider, with considerably more obligations.
These questions do not replace a legal assessment of the individual case. They show you where to look more closely.
An example from HR
A company with 60 employees reviews its AI tools and finds three uses.
Copilot for emails, minutes and quotes. The tool does not decide about people and does not operate in any area listed in Annex III. Not high-risk AI. Training, rules and data protection remain.
Applicant tracking software with a new AI feature that sorts incoming applications and suggests a ranking. This is the area of employment, and the system assesses people. The company treats it as high-risk AI, clarifies with the provider how it will meet its obligations by 2 December 2027, and plans for its own obligations as a deployer.
A team leader who copies CVs into ChatGPT and asks it for an assessment. Here a general-purpose tool is being used for a high-risk purpose. The company could itself count as a provider as a result. There are also data protection issues, because applicant data ends up in a tool. Management prohibits this use in the AI policy and explains the reason to the team.
Before, nobody knew the third case existed. Now all three uses are known, classified and covered by rules.

What deployers must then do
If you only use a high-risk system, you are a deployer. Your obligations include:
- using the system in accordance with the provider’s instructions for use
- assigning human oversight to people with the necessary competence and authority
- monitoring operation and keeping the automatically generated logs for at least six months
- informing employees and their representatives before such a system is used in the workplace
- informing people when the system helps make decisions about them
In the example above, human oversight could look like this: a person from HR who knows the system and its limits reviews every suggested ranking. They may reject suggestions and decide themselves whom to invite to interview. Whoever takes on this task needs time for it, training on the system and the authority to overrule the system.
If there is a works council, the employer must, independently of the AI Act, inform it in good time about plans to use AI in work procedures or workflows (§ 90 BetrVG, the German Works Constitution Act).
Much of this depends on the provider. You can ask these questions when buying a system or renewing a contract:
- Do you classify your system or individual features as high-risk AI, and on what grounds?
- How do you ensure that your obligations as a provider are met by 2 December 2027?
- Are there instructions for use that describe what the system is intended for and what it is not intended for?
- Which logs does the system generate, where are they stored and how long can we keep them?
- How can our employees understand, check and override the system’s suggestions?
- Can individual AI features be switched off if we do not want to use them?
What you can do now
Get an overview of where AI is used in your company and for what. Above all, check tools used in HR, recruitment and training. If you are buying new systems in these areas, factor the obligations into your selection today.
A simple AI register is enough to start with. Create one row per tool with these details:
- Tool and provider: including AI features in existing software, for example in applicant tracking
- Purpose: what it is used for, in one sentence
- People affected: whether it helps make decisions about employees, applicants, customers or learners
- Annex III area: yes or no, with a brief reason
- Responsible: who looks after the tool and answers questions
- Next step: for example asking the provider, setting rules for its use or planning training
The register shows where high-risk obligations are coming your way. It is also a basis for your measures on AI literacy under Article 4. If you would like to look at your processes together with us, the AI potential analysis classifies your uses of AI in one day on site. Which tools in your HR department already work with AI today?
Frequently asked questions
Is ChatGPT high-risk AI?
No, not in itself. It depends on the intended purpose. If you use a general-purpose AI tool to assess job applications, for example, you move into a high-risk area and may then yourself count as a provider, with considerably more obligations.
Does Article 4 already apply?
Yes. The AI literacy obligation has applied since 2 February 2025 to everyone who uses AI, regardless of risk.
What already applies today?
Certain AI practices have been prohibited since 2 February 2025, such as social scoring, exploiting people’s vulnerabilities or emotion recognition in the workplace. Obligations for providers of general-purpose AI models have applied since 2 August 2025. Since 2 August 2026, the transparency obligations under Article 50 have also applied.
Does the size of our company matter?
Not for the classification. Whether a system is high-risk depends on its intended purpose. A small company that has job applications assessed by an AI system is, as a rule, also using high-risk AI.
We are currently buying new HR software. Should we wait until 2027?
No. Ask during selection whether the provider classifies individual features as high-risk AI and how it will meet its obligations by 2 December 2027. That way you avoid having to make changes shortly before the deadline.
Sources
- EU AI Act, Regulation (EU) 2024/1689, Annex III, consolidated version of 27 July 2026, EUR-Lex
- Regulation (EU) 2026/1744 (AI Omnibus), EUR-Lex
- § 90 BetrVG, German Works Constitution Act (in German)
Updated: . This article is not legal advice.



