On Aug. 2, Article 50 of the EU AI Act takes effect, requiring providers and deployers (including many employers) of covered AI systems to disclose when people are interacting with AI and to label certain AI-generated content.
Employers relying on third-party AI systems for hiring, performance reviews or workforce monitoring also have another task worth flagging now. Under the EU AI Act, employers using a vendor’s AI system for employment purposes are required to follow the vendor’s instructions for use, which vendors are legally obligated to provide, according to a recent analysis from law firm Ogletree Deakins.
HR leaders have more runway on the heavier compliance lift. The Aug. 2 deadline is narrower but immediate because it covers disclosure and labeling. A separate set of high-risk provisions covering employment-related AI, including hiring and performance tools, has been pushed to Dec. 2, 2027 under the EU’s Digital Omnibus package.
Read more | Google DeepMind exec: U.S. needs ‘urgent action’ on AI governance
EU AI Act deadline: what HR needs to know
New global data suggests most companies aren’t ready for either deadline. The Thomson Reuters Foundation and UNESCO’s AI Company Data Initiative, drawing on disclosures from nearly 3,000 companies across 11 sectors, found that only 13% of companies publicly commit to any AI governance framework. Where companies do cite one, 53% point to the EU AI Act, even when they operate outside the EU, making it the default reference point worldwide.
The workforce numbers are lower still. Just 31% of companies show evidence of offering AI training or reskilling programs, and only 12% of those describe training that’s structured or available across the organization. Fourteen percent have evidence of policies to protect workers from the negative effects of AI. About 2% report an internal complaints channel for AI-related concerns. Among companies using AI in HR specifically, only 7.4% say they consult diversity and inclusion staff on those projects.
Ogletree Deakins notes that “high-risk” employment systems specifically include AI used to place targeted job advertisements, filter applications, evaluate candidates, make decisions affecting employment terms, promotions, terminations and task allocation and monitor or evaluate workers’ performance or behavior. For HR teams trying to figure out which tools in their stack actually fall under the regulation, that list is a useful starting point, covering much of the recruitment and performance technology already in common use.
Read more: 8 principles for ethical AI at work, according to the White House
A ‘failure of literacy’
Michael Burch, vice president of AI enablement and acceleration at security training platform Security Journey, says the compliance framing misses the underlying problem.
Burch suggests that “compliance paperwork” is important, but the Act’s legal requirement for AI literacy validates what he believes security teams have been warning for two years. “Access to AI is not the same as capability with it,” he said in an email. “Giving someone an AI tool without training is like handing them the keys to a motorcycle. It’s powerful, useful and potentially dangerous if not used in the right way. Organizations have spent 18 months distributing the keys without teaching anyone how to ride.”
The EU AI Act’s AI literacy requirement already took effect back in February 2025, so the deadline has effectively passed for organizations that should have put training and other literacy measures in place. Despite that milestone requirement, Burch points to a pattern he’s observed directly. “I’ve watched experienced teams stunned by how easily an AI-generated workflow can execute malicious code on their machine, simply because they have never been trained to check,” said Burch. He calls this a “failure of literacy” and is exactly the gap the EU AI Act is trying to close.
Credit: Source link









