Running AI on employee data puts you under two sets of rules that say different things and start on different dates. GDPR and French labour law already govern your HR processing, today, with no grace period. The AI Act adds a further layer, and its heaviest part, the high-risk regime, will not apply until 2 December 2027. In practice, the immediate risk for a small or mid-sized company almost never comes from the AI Act.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
Running AI on employee data puts you under two sets of rules that say different things and start on different dates. GDPR and French labour law already govern your HR processing, today, with no grace period. The AI Act adds a further layer, and its heaviest part, the high-risk regime, will not apply until 2 December 2027. In practice, the immediate risk for a small or mid-sized company almost never comes from the AI Act.
That is the point most coverage of this topic misses. Plenty of articles published in 2025 still announce an August 2026 deadline for high-risk AI systems in employment. That date no longer exists. Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force on 27 July 2026 and pushed the obligations for stand-alone systems listed in Annex III to 2 December 2027. If you built your HR compliance plan on the old timeline, it needs revisiting. For the full picture, our AI Act compliance guide for SMEs covers the whole framework; here we focus on the specific point where AI touches your employees'' data.
Three sets of obligations are in force today, and none of them depends on the high-risk timeline.
The first is GDPR. It never paused. Any employee or candidate data fed into an AI tool remains personal data processing, with a legal basis, a purpose, a retention period, a record of processing activities and data subject rights. Article 22 GDPR additionally governs fully automated decisions, which bears directly on candidate screening.
The second is labour law. In France, three provisions frame any system that observes employee activity: Article L.1121-1 of the Labour Code (proportionality of restrictions on individual freedoms), Article L.1222-4 (informing employees) and Article L.2312-8, II, 4° (informing the works council before deploying new monitoring technologies). These predate AI and apply without waiting for anything.
The third comes from the AI Act itself, but not from the high-risk chapter. Article 4, applicable since 2 February 2025, requires a sufficient level of AI literacy from people operating these systems on your behalf. That includes your HR team. Our article on Article 4 and mandatory AI training sets out what "sufficient level" means in practice. Article 5, on prohibited practices, has also applied since February 2025 and speaks directly to the workplace: emotion recognition at work is banned, except for medical or safety reasons.
| Obligation | Source | Applicable from |
|---|---|---|
| Legal basis, minimisation, data subject rights | GDPR | 25 May 2018 |
| Informing employees and the works council | Labour Code, L.1222-4 and L.2312-8 | In force |
| Ban on emotion recognition at work | AI Act, Article 5 | 2 February 2025 |
| AI literacy for users | AI Act, Article 4 | 2 February 2025 |
| High-risk obligations in employment | AI Act, Annex III point 4 and Article 26 | 2 December 2027 |
| High-risk systems embedded in regulated products | AI Act, Annex I | 2 August 2028 |
For every deadline in sequence, see our complete AI Act timeline.
Annex III point 4 does not cover "AI in HR" as a category. It names four precise families of use, and most tools used in smaller companies fall outside them.
High-risk covers systems intended for the recruitment or selection of individuals, in particular to place targeted job advertisements, analyse and filter applications and evaluate candidates. It also covers systems used to decide on promotion or termination, to allocate tasks based on individual behaviour or personality traits, and to monitor or evaluate performance and behaviour within the employment relationship.
The dividing line is the system''s role, not the technology. Asking a conversational assistant to rewrite a job ad produces no assessment of any person, so it is not a high-risk use. Having the same tool summarise interview notes the recruiter wrote themselves is not either. Plugging in a tool that assigns a compatibility score to each CV and returns a ranking, however, brings you inside Annex III, even if a human signs off afterwards. The text refers to systems intended to filter and evaluate candidates, without requiring that the final decision be automated. Our article on high-risk AI systems works through the qualification criteria.
Three cases that cause genuine hesitation:
In most of the companies we audit, the problem is not high-risk qualification. It is HR data flowing into consumer-grade tools.
An HR director who pastes a compensation table into a free AI assistant to get an analysis is transferring personal data, sometimes special category data, to a processor with no contract, often outside the European Union, with no identified legal basis and no trace in the record of processing activities. That is not an AI Act issue. It is a GDPR issue, and it is enforceable today.
The concrete checkpoints, in the order we work through them:
Shadow AI is central here. A written, circulated usage policy costs little and resolves a large share of the exposure: we publish a reusable AI policy template for businesses.
The AI Act and labour law each impose prior notice, with different scopes and different timelines. One does not replace the other.
On the AI Act side, Article 26(7) provides that before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers'' representatives and the affected workers that they will be subject to its use. This obligation follows the high-risk timeline, so December 2027 for Annex III uses.
On the labour law side, the obligation is immediate and broader. According to the French data protection authority, a system monitoring staff activity must meet three cumulative conditions: pass the justification and proportionality test, be submitted to employee representative bodies under the applicable rules, and be brought to employees'' attention before deployment. Works council consultation is mandatory in companies with 50 or more employees, prior to implementation. The authority cites as unlawful the installation of a time clock or video surveillance system without prior works council consultation in a company of that size. The reasoning is identical for an AI tool that monitors activity.
On form, a note read out in a meeting will not prove compliance. The employer must be able to demonstrate that these conditions were met: the necessity and proportionality analysis in detail, the data lifecycle, and the measures taken for information and the exercise of rights. Our article on the AI information notice sets out the expected structure and the wording not to omit.
Article 22 GDPR prohibits, as a matter of principle, decisions producing legal effects or significantly affecting a person being taken solely on the basis of automated processing.
Applied to recruitment, that means a screening tool cannot reject an application on its own. Human involvement has to be real, not formal. A recruiter who approves a batch of rejections produced by a score without looking at the files is not providing meaningful human involvement: the decision remains automated in substance. GDPR further requires that the data subject be able to obtain human intervention, express their view and contest the decision.
Three operational consequences:
For how the two texts fit together, our comparison of the AI Act and GDPR sets out the difference in logic: GDPR protects the person and their data, the AI Act governs the product and its lifecycle.
A thirty-person company has no mandatory data protection officer, no works council and no in-house lawyer. That is not an exemption, it is a different allocation of roles.
What we put in place in that situation, and what it takes a few days of work:
Our AI Act guide for small businesses lays out this lighter path, and our article on the conformity assessment describes the real steps when you have no legal department.
Today''s enforcement risk sits with GDPR and labour law, not with the AI Act''s high-risk obligations, which are not yet applicable.
GDPR provides for administrative fines of up to 20 million euros or 4 % of worldwide annual turnover. In practice, amounts imposed on French small and mid-sized companies run in the tens of thousands of euros, but the regulator increasingly uses its simplified sanction procedure: it issued 23 new sanctions through that route between January and early July 2026.
More to the point, recruitment is one of the French regulator''s priority enforcement themes for 2026. Around 20 % of its annual inspections fall under these themes, and this one explicitly targets automated decision-making systems, candidate information and retention periods. The authority says it will focus first on large companies and recruitment agencies, but it also states that the campaign foreshadows its future role as market surveillance authority in the employment field under the AI Regulation. In other words, the practices it documents this year will shape the doctrine that applies to everyone afterwards.
On the AI Act side, Article 5 on prohibited practices is already enforceable at up to 35 million euros or 7 % of worldwide turnover. It is the only part of the Regulation exposing a smaller company to a fine today on an HR topic, through the ban on emotion recognition at work. Other obligations, including those of deployers, are capped at 15 million euros or 3 % and follow the December 2027 timeline. Our article on AI Act penalties breaks down the tiers by type of breach.
Can we use ChatGPT or a comparable AI assistant for HR tasks?
Yes, with a business account that guarantees no training on your data and a defined data perimeter. Drafting a job ad, preparing an interview grid or rewriting an internal memo raises no difficulty. Analysing real CVs, named performance reviews or compensation data in a consumer tool exposes you to a GDPR breach. Our article on ChatGPT and AI Act compliance covers the configuration in detail.
Do we have to consult the works council before deploying an AI tool in HR?
In a company with 50 or more employees, yes, if the tool constitutes an activity monitoring system or a new technology affecting working conditions. Article L.2312-8, II, 4° of the French Labour Code requires informing the works council before new monitoring technologies are deployed. Below 50 employees, works council consultation does not apply, but individual notice to employees under Article L.1222-4 is still owed.
Is a CV scoring tool banned?
No. It is classified as high-risk by Annex III point 4, which triggers documentation, human oversight and log retention obligations from 2 December 2027. What is prohibited today is letting that score decide on its own to reject an application: Article 22 GDPR stands in the way.
Is emotion recognition in interviews legal?
Not at the workplace. Article 5 of the AI Act bans emotion inference systems in the workplace and in education, except for medical or safety reasons. The ban has applied since 2 February 2025, and a recruitment interview for a role at the company falls within that scope.
How long should we keep CVs analysed by AI?
Using AI does not extend the retention period. It stays aligned with the purpose of the processing, meaning two years after the last contact for a speculative application or a talent pool under French regulatory guidance, provided the candidate has been informed. Retention periods are among the points the regulator is explicitly checking in 2026 on recruitment.
What if our payroll provider uses AI without telling us?
You remain the controller for your employees'' data. Review the processing agreement, obtain a description of the automated processing performed and, where needed, have the technical annex updated. A provider who refuses to document its AI usage is a risk point to record in writing.
Do we have to train the whole company or just the HR team?
Article 4 of the AI Act targets people operating AI systems on the company''s behalf. If only three people in HR use these tools, the obligation covers them. In practice usage spreads quickly, and we recommend covering the functions that handle personal data first: HR, sales, management.
We work on this overlap of AI Act, GDPR and labour law in a short format, calibrated for organisations with no DPO and no legal department.
The HR audit starts with an inventory of actual AI usage, including the uses management does not know about. We then qualify each one: out of scope, GDPR processing to be brought into order, or future high-risk under Annex III. You come out with an up-to-date record, a policy you can circulate, the notice documents for employees and the works council, and a prioritised list of what has to be fixed before December 2027.
Training completes the picture. Our AI for business programme covers the Article 4 obligation and the reflexes for handling personal data, and the operational AI track goes further for teams building their own use cases. GrowthPerf holds the French Qualiopi certification, which opens up funding through your sector training fund.
The most effective starting point is a status check. A free 30-minute audit is enough to tell whether your HR uses of AI are already in breach or simply undocumented. For the full framework, go back to our AI Act compliance guide for SMEs and non-profits, which lists every obligation by deadline.