EU's High-Risk AI Rules Hit HR Departments: What Changes by December 2027
Published on 08/28/2026 at 07:43 | Editorial boerse-global.de
The clock is ticking for European employers who use artificial intelligence in hiring, performance reviews, or workforce analytics. While the EU AI Act formally entered into force on 2 August 2026, the bloc has granted businesses additional breathing room — but only for certain categories of systems.
Compliance deadlines for high-risk AI applications now stretch to 2 December 2027, a delay of 12 to 16 months compared with the original timeline. Embedded systems get even longer, with a cut-off of 2 August 2028. Experts gathered in late August 2026 to map out exactly what these rules mean for companies still scrambling to align their people operations.
What HR Departments Can and Cannot Do
The regulation draws a hard line in the employment context. Emotion recognition software is explicitly banned in workplace settings. And under Article 22 of the GDPR, fully automated dismissals without human intervention remain off the table — a provision that carries real weight given recent legal action against Meta, where plaintiffs alleged that AI-driven layoffs disproportionately affected employees with chronic illnesses.
As HR teams navigate these new compliance demands, workplace safety obligations remain just as pressing. Many UK employers are unknowingly exposed to fines because their health and safety documentation is out of date or incomplete. A free toolkit provides ready-to-use risk assessments and checklists that help you meet your legal duties without the paperwork burden. Download the free Health & Safety Toolkit
The stakes are considerable. Research from the Institute for Employment Research (IAB) suggests 86 percent of tasks performed by HR clerks could theoretically be automated, making the sector one of the most exposed to algorithmic decision-making.
Germany's enforcement architecture is now taking shape. Market surveillance falls under the KI-Management-Indikatoren-Gesetz (KI-MIG), with the Federal Network Agency (Bundesnetzagentur) serving as the central supervisory authority. Meanwhile, a draft "Digital Omnibus on AI" was presented in November 2025, with formal adoption following sometime in 2026.
Adoption Is Accelerating Despite the Rules
Regulatory pressure hasn't dampened enthusiasm for AI tools in German workplaces. A Kienbaum study found that 35 percent of HR professionals already use AI in recruitment, with another 26 percent planning to do so.
Bitkom's survey of 600 companies shows interest climbing across multiple applications:
- Reference letters: 14 percent of firms now use AI for this task, up from a general interest level that jumped from 45 percent in 2024 to 52 percent today
- Training and development: Usage rose from 12 percent in 2024 to 16 percent
- Onboarding: Adoption increased from 11 percent to 14 percent
- Workload analysis: The sharpest rise — from 6 percent in 2024 to 13 percent currently
- Performance evaluation: 12 percent of surveyed companies now rely on AI for this purpose
A Web of Interlocking Digital Regulations
The AI Act doesn't stand alone. It sits alongside DORA, NIS2, and the Cyber Resilience Act (CRA), which collectively tighten digital resilience and third-party management requirements — particularly for insurers and financial institutions. A KPMG and Lünendonk study reveals a striking gap: while 94 percent of institutions rate digital resilience as important, only 12 percent have achieved a very high maturity level.
With overlapping regulations demanding more from employers than ever, don't overlook your foundational health and safety obligations. Over 37,000 UK businesses use a free toolkit covering fire safety, PPE, first aid and more — everything you need to stay compliant and protect your workforce. Get the free Health & Safety at Work Act 1974 Toolkit
Since December 2025, roughly 29,500 companies have been operating under Germany's NIS2 implementation law. Cybersecurity is now a board-level responsibility, with supervisory board members facing personal liability for oversight failures under a reversed burden of proof. Fines can reach €10 million or 2 percent of global turnover — and typically aren't covered by D&O insurance policies.
New CRA reporting obligations kick in from 11 September 2026. Companies must notify ENISA and CERT-Bund of actively exploited vulnerabilities within 24 hours as an early warning, followed by a full report within 72 hours through a central platform.
Given that Keeper Security's 2026 research found governance gaps in third-party access at 25 percent of German companies, industry experts are urging organisations to close these security holes without delay.
