Back to Insights
AI & People

What the EU AI Act means for your company

Most business leaders have never heard of the EU AI Act, yet some of its rules already apply to your organisation today, especially if you're leading HR or People teams. Maria Kelly recently sat with a senior leader who'd uploaded his company's entire strategy and client database into ChatGPT to build a presentation, with no idea what happened to that data next. That gap between what people assume is safe and what's actually happening is exactly what this law is trying to close.

Published
September 17, 2026
|
with

Maria Kelly

A NOTE BEFORE WE START

While I'm sharing practical guidance based on professional experience and current official EU guidance, this isn't legal advice. If you're unsure about your obligations, liability or a specific use case, please consult a qualified legal adviser.

A lot of business leaders have never heard of the EU AI Act. Have you?

You should, because some of the rules already apply to your organisation today, especially if you're leading HR and People teams.

I was speaking with a senior leader of a small business a couple of months ago. He'd taken the company's entire strategy, along with the client database, and uploaded the lot into ChatGPT to help build a set of decks for a presentation. He was proud of how much time it had saved him and felt pretty AI-savvy.

When I asked whether he'd turned off data training in his settings, his eyes went blank.

"I have the paid version," he replied.

He was assuming that meant his chats were automatically protected in the same way as a company account.

I felt bad having to tell him that was not the case.

To make things worse, it hadn't even occurred to him that using his personal ChatGPT account rather than a company-approved account could be a problem.

We're talking about an experienced CMO here, and this is not an isolated conversation.

Swap "company strategy and client database" for "candidate CVs and performance reviews," and you'll recognise the same story playing out across plenty of people teams.

And that's the kind of thing the EU AI Act is trying to address, alongside existing rules such as GDPR.

An AI policy sitting in a folder doesn't help much if your employees are using personal accounts, experimenting with tools nobody has approved, uploading company information and building their own workflows.

Most of the time, people are simply trying to work faster and don't realise the risks. The bigger the company, the harder it is to know where AI is actually being used.

The idea behind the law is pretty simple: people need to know how to use these tools responsibly, and where the limits are, whether that's someone exposing sensitive employee or candidate data without realising it, like my client, or an organisation using AI in ways that are deliberately harmful or manipulative.

Whether you're running people operations at a fast-growing scale-up, leading HR for an established company, or managing recruitment and workforce policy somewhere in between, it's worth taking five minutes to find out where your organisation stands under this law.

So what is it, in plain terms?

The EU AI Act is the world's first comprehensive legal framework for artificial intelligence.

AI tools have developed incredibly quickly, while the rules around how they're built and used have lagged. Legislation was well overdue.

This law is designed to put boundaries around uses of AI that could cause real harm.

And we've already seen the kinds of problems it is trying to address:

  • Companies building recruitment tools using historical data without properly understanding whether the system discriminates against certain groups
  • AI screening and ranking job applicants
  • Systems being used to monitor workers, assess behaviour or influence decisions about promotion and employment
  • AI designed to manipulate people in ways that seriously undermine their ability to make an informed decision and cause, or are likely to cause, significant harm
  • AI being used to understand people's emotions in situations where there is a significant imbalance of power, such as the workplace.

The EU AI Act sets out who's responsible for what depending on the AI system, what it's being used for and the role your organisation plays.

South Korea brought in something similar at the start of this year, and plenty of other countries are watching closely to see how this plays out. Europe got there first, though, and given how fast this technology moves, it's a good thing someone is leading the way.

The four risk levels

The easiest way to understand the Act is to think of AI use as sitting somewhere on a scale that's split into four bands.

The four risk levels

Employment is one of the areas specifically identified in the Act as potentially high risk.

This includes AI used to analyse and filter job applications, evaluate candidates, make decisions affecting promotion or termination, allocate work based on personal behaviour or characteristics, or monitor and evaluate employee performance and behaviour.

Just to be clear, that doesn't mean every use of AI by HR suddenly becomes high risk. An AI writing assistant helping you improve the wording of an already completed performance review is very different from an AI system generating the performance score in the first place.

What matters is what role the AI is playing in the decision.

There's a difference between systems influencing employment decisions and tools carrying out narrow administrative or supportive tasks.

What this means for HR

You do not need to audit every AI tool against 100 pages of legislation tomorrow.

Start with three questions:

  • Where are we already using AI?
  • Is any of it influencing decisions about people?
  • Do our people know what they can use, what they can upload and who to ask?

There's one more thing you need to work out before you can understand what the Act expects from your company: what role are you playing?

The law treats the company building an AI system differently from the company simply using it. In EU AI Act language, those two roles are called provider and deployer. It sounds technical, but the distinction is pretty simple.

Did you build the AI, or are you using someone else's?

Picture a car.

The manufacturer is responsible for the brakes working, the airbags deploying, and the whole thing being safe to put on the road. You, as the driver, are responsible for how you use it.

If the airbag fails because of a manufacturing fault, that's on the manufacturer. If you crash because you were checking your phone, that's on you.

The EU AI Act works the same way.

If your company develops an AI system and places it on the market or puts it into service under its own name, the law calls you the provider, and you have a lot more responsibility for how that system works.

If your company is using an AI system built by somebody else, you're the deployer.

Most companies using Microsoft Copilot, ChatGPT, Claude or an AI-enabled HR platform will therefore be deployers for those uses.

Worth noting: the bigger the organisation, the more likely this line gets blurry.

If your engineering or data team has built or substantially changed a screening or performance tool in-house, rather than buying one off the shelf, you may have become a provider too, with the heavier rules that come with it.

So not being the original builder (provider) doesn't always mean you're off the hook.

Where companies need to pay particular attention

Recruitment and CV screening

If AI is being used to analyse applications, filter CVs, rank candidates or evaluate whether someone is suitable for a role, this may count as high-risk.

So if you're a recruiter asking ChatGPT to improve the wording of a job advert, that's one thing. But if your recruitment platform automatically ranks 300 applicants according to its assessment of who is the "best fit", that's quite different.

And it isn't always something that looks obviously like an "AI hiring tool". It could be a CV parser sitting inside your applicant tracking system or another feature helping to determine which candidates move forward.

The question to ask yourself is:

"What is the AI doing, and does its output influence who gets an opportunity?"

Promotion, performance and employee decisions

The same principle carries through once someone works for you.

If you use AI to help make decisions about promotion, termination or the terms of someone's contract, that can fall within the high-risk employment category. It also applies to systems used to allocate work or to monitor and evaluate someone's performance or behaviour.

That could include a productivity dashboard that scores staff or an algorithm that allocates shifts based on past performance. It could also be a tool recommending who gets promoted.

This is an area I think many companies will underestimate. AI can now analyse enormous amounts of workplace behaviour: productivity, attendance, call data, sales activity, communication patterns, meeting participation and performance.

Some of those uses may be relatively mundane. Others can fall into the high-risk category.

And if you are dealing with a high-risk workplace system, extra responsibilities come with it.

These can include making sure there is proper human oversight (a real person checking and taking responsibility for the decision), monitoring how the system is operating, keeping records created by the system where they are under your control, and informing affected workers and their representatives before the system is used.

Where a high-risk AI system is being used to make or assist a decision about someone, that person may also need to be told that AI is involved.

Those high-risk obligations are now scheduled to apply from December 2027.

That date may feel reassuringly far away, but I wouldn't wait until November 2027 to find out what your HR software has been doing for the previous two years.

AI analysing sentiment, engagement or emotions

This is one I discovered while researching the EU AI Act, and I had no idea this was even possible when I first came across it.

Some AI tools can analyse things like sentiment, engagement or attention, and companies are already using them.

Analysing engagement or sentiment isn't automatically banned. But using AI to read someone's emotions from their face or voice, what the law calls biometric data, is banned in the workplace, with narrow exceptions for medical or safety reasons. The reasoning: these systems aren't considered reliable, and employees are rarely in a position to push back if their employer starts using one on them.

So if you use analytics tools, check what they are actually measuring and how they are measuring it. Don't assume that because a feature is sitting inside software you've already bought, somebody in HR, Legal or IT has checked what it does.

Note-taking and meeting bots

If you're using an AI tool that joins a call, records it or generates a summary, make sure the people on that call know it's there.

Between Meta glasses and all the trendy wearable devices, it's become increasingly easy to record people without their knowledge, and separate privacy and recording rules can apply.

I get my own notetaker to join calls under the name "Maria's Notetaker", so it's clear to everyone.

If someone is uncomfortable or would rather not have it there, they can simply say so and I'll turn it off.

Inside a company, the bigger question is whether your employees are choosing their own notetakers and meeting tools without anybody knowing. This goes beyond simple meeting etiquette and can be a question of where that data goes and who has access to it.

AI-generated content, avatars and deepfakes

You don't have to label every piece of marketing copy or generic image simply because AI helped create it.

But if I publish a realistic AI-generated video of myself speaking words I never actually recorded, I need to disclose that it's artificially generated. Article 50 covers exactly this: once AI is generating what someone says or how they say it, rather than just editing footage that was really recorded, it needs to be labelled.

This is useful for marketing and comms teams, who instead of chasing a busy executive's diary for a five-minute video, can now generate one with AI from their laptop.

The disclosure rule is the trade-off. Not a reason to avoid the tool; it's simply part of using it properly.

The biggest corporate problem may be shadow AI

One of the most common problems I see in companies goes like this: leaders decide on a tool, let's say Copilot, and buy the licences for everyone. Six months later, they realise nobody's using it.

In fact, they are using AI, just not the version the company paid for. They're on personal accounts instead, either because they prefer them or because nobody's trained them on the approved one.

That's called shadow AI.

{{quote-item-1}}

In short, paid, company-approved accounts usually come with data privacy protections. Personal accounts don't. When employees use personal logins, they might be feeding confidential company or client data directly into public AI models without realising it.

And banning ChatGPT isn't going to solve it, because if people find AI useful, they will find ways to use it. The practical job for the company is to give them safe, approved ways of doing that, with enough understanding to know where the boundaries are.

That brings us to one of the parts of the EU AI Act that already applies.

AI literacy isn't just sending everyone on a Copilot course

Since February 2025, companies using AI have been required to take measures to support the development of AI literacy among staff and other people using AI systems on their behalf. In plain English, people need enough understanding to use the tools safely and sensibly.

That doesn't mean every employee needs the same level of AI knowledge.

The current wording specifically says organisations should take account of people's technical knowledge, experience, education and training, the context in which the AI is being used and the people who may be affected by it.

The person in marketing using AI to brainstorm campaign ideas does not need exactly the same understanding as the recruiter using an AI-enabled hiring platform.

AI literacy should reflect the work people are actually doing.

In practice, I would want people to know:

  • which AI tools and accounts the company has approved
  • what information should never be uploaded
  • when AI output needs human checking
  • where AI is influencing decisions about people
  • who to ask when they're unsure

That is where training and policy need to meet.

A beautifully written policy nobody remembers is useless, and so is training people without giving them clear company rules.

Somebody needs to own this

This is where larger organisations have a challenge. AI touches HR, IT, Legal, Marketing, Operations, Finance, Procurement and almost every other function, which makes it very easy for everybody to assume somebody else owns it.

The EU AI Act doesn't require every company to appoint a Chief AI Officer, but somebody does need to be clearly responsible for how AI is used across the company.

It's not just about where your company is located

If your company is established or located in the EU, the Act applies to it regardless of where your customers are.

Companies outside the EU can fall within scope too, if the AI system's output is actually used in the EU. That doesn't mean every AI use becomes covered just because you have EU customers or operations; it depends on the specific use. But it does mean you can't assume you're safe just because your company isn't based in Europe.

For international companies, this is another reason not to treat the AI Act as something for their European offices to sort out on their own.

Where things stand now

As of August 2026, the EU AI Act is rolling out in simple, logical phases:

  • February 2025 (Banned Practices): Strictly illegal practices, like using AI to read employee emotions in the workplace, went into effect. Basic AI safety awareness (AI literacy) has also been required since then.
  • August 2026 (Transparency Rules): Rules requiring you to disclose when people are interacting with AI (such as customer-facing chatbots or highly realistic AI-generated videos) are now active.
  • December 2027 (High-Risk HR Systems): Rules governing tools that filter CVs, rank candidates, or grade employee performance are scheduled to apply.

And frankly, I don't understand why some of those rules are coming in so late. If an AI system is having an impact on people's livelihoods, waiting until the legal deadline before understanding how it works doesn't strike me as particularly sensible.

What non-compliance can cost you

The biggest fines under the EU AI Act are significant.

The absolute worst-case scenario (like using banned, manipulative AI practices) can carry staggering fines of up to €35 million or 7% of global annual turnover.

While those giant numbers are designed to keep tech conglomerates in line, the real day-to-day risk for standard businesses is much more practical:

  • An employee accidentally uploads confidential client data into a public tool.
  • An HR screening system is switched on without anyone checking if it's fair.

For most companies, the goal isn't to become legal experts, but to put simple guardrails in place so these mistakes don't happen in the first place.

Personally, when I'm not sure if I should upload something to one of these tools, I remember this rule of thumb my dad handed down to me years ago:

If you wouldn't be comfortable seeing it on the front page of a newspaper, don't put it into AI.

It may be outdated, but it still works.

Confidential company information, client information, employee data, financial details, anything you wouldn't want made public. Make sure you know where it's going before you upload it.

Five things your company can do this week

1. Find out which AI tools your people are usingAsk HR, Marketing, Sales, Operations and your leadership team and include personal accounts, browser extensions, meeting bots and any AI feature embedded inside existing software.You need the real picture before you can set sensible rules.

2. Decide who owns AI internallyYou don't necessarily need to hire a Chief AI Officer, but you do need someone to be responsible for coordinating it across the company. It goes back to clear communication about who maintains the overview, who approves tools and where an employee goes when they have a question.

3. Look at HR and People uses firstCheck recruitment, candidate screening, employee analytics, performance management, workforce planning and any tool that monitors or scores people.Then separate the everyday productivity tools from anything that influences a decision about a person.Ask one simple question: Does this AI influence who gets hired, promoted, monitored, evaluated or given an opportunity? If the answer is yes, that's one to review more closely.

4. Set clear rules around approved tools and dataPeople need to know which tools they can use, which company accounts they should use and what information should never be uploaded.Don't make them read a 20-page policy every time they want to use ChatGPT; create a one-page guide they can keep handy. Make the safe choice obvious and easy.

5. Train people according to how they use AIAI literacy doesn't mean sending everybody on the same generic training course. It's much more effective to teach people what they need for their role.Help them understand where AI gets things wrong and when they need to use their own judgement.

The EU AI Act can look intimidating when you read the legislation.
For most companies, I think the more useful place to start is much simpler.
Can you say with confidence where AI is already being used in your organisation, what's allowed and who's responsible for it?
If not, that's where I'd start.

A note on sources: this article draws primarily on Regulation (EU) 2024/1689, the July 2026 amendments in Regulation (EU) 2026/1744, and current guidance from the European Commission's AI Act Service Desk. Information reflects the position as of August 2026.

Get in touch

{{quote-item-2}}

Key Take-aways

  • Parts of the EU AI Act already apply to your company today — this isn't a future problem.
  • AI use falls into four risk bands, from banned outright to high-risk employment tools like recruitment and performance systems.
  • Most companies are "deployers" using AI someone else built, not "providers" — but building or heavily customising a tool in-house can shift that.
  • High-risk HR obligations (CV filtering, candidate ranking, performance grading) apply from December 2027.
  • Transparency rules — disclosing AI chatbots and AI-generated video — are already active as of August 2026.
  • Shadow AI is the biggest everyday risk: employees using personal, unapproved accounts to upload confidential company or client data.
  • Fines can reach €35 million or 7% of global turnover, but the real day-to-day risk is simpler: unchecked uploads and unreviewed HR tools.
  • Start this week: find out where AI is already being used, decide who owns it internally, and set clear rules on approved tools and data.

My CMO example is a good illustration of this. He wasn't careless; he'd found a useful tool and was simply trying to be more efficient. The problem was that his company hadn't made it clear which AI tools were approved, which accounts he should use or what information could and couldn't be uploaded.

If you're trying to work out where AI is already being used across your organisation, what your teams need to understand, or where to begin with a practical AI policy and training, that's the work I help companies with.

featured experts
Maria Kelly
Business Strategist & AI Adoption Specialist

Helping leadership teams cut through complexity, fix what isn't working, and build real confidence with AI.

Learn more
Featured Podcast
AI & People

Need an Expert for your challenge?

We've sourced the best independent global talent so you don't have to. Every People and Culture specialism covered in one place by our trusted Experts. Search, book, brief and pay through one easy-to-use platform.

Explore Experts

Book a demo and see
the platform working live.

  • Just exploring? We’ll show you how it works and answer your questions.
  • Got a live challenge? We'll search, shortlist and brief an Expert on the call.
Book your demoNot right now×