EU AI Act Compliance Checklist for Employers and HR Teams
This checklist is organised by what applies now and what applies later, so HR teams can act on current duties while preparing for the high-risk deadline of 2 December 2027.
Short answer
An EU AI Act compliance checklist for employers covers seven areas: inventory and classification of HR AI systems; removing prohibited practices such as workplace emotion recognition (applies now); AI literacy measures for staff (applies now); transparency, including labelling HR chatbots (applies from 2 August 2026); high-risk deployer duties such as human oversight, monitoring, logs and informing workers (applies from 2 December 2027); vendor contracts; and governance.
Key takeaways
- Prohibited practices and AI literacy duties already apply.
- Transparency duties apply from 2 August 2026.
- High-risk deployer duties for HR AI apply from 2 December 2027.
- Start inventory, classification and vendor engagement now.
Key dates
| Date | What applies | Relevance to HR |
|---|---|---|
| 1 August 2024 | AI Act enters into force | Start of phased timeline |
| 2 February 2025 | Prohibited practices (Article 5) and AI literacy (Article 4) | Ban on workplace emotion recognition; staff AI literacy measures |
| 2 August 2025 | General-purpose AI model obligations | Mainly affects model providers |
| 27 July 2026 | Digital Omnibus (Regulation (EU) 2026/1744) in force | Deadlines deferred; Article 4 reworded |
| 2 August 2026 | General application, Article 50 transparency duties, national enforcement | Tell people when they interact with AI such as HR chatbots |
| 2 December 2027 | High-risk obligations for Annex III systems | AI in recruitment, promotion, termination, task allocation and worker monitoring |
| 2 August 2028 | High-risk obligations for AI in regulated products (Annex I) | Limited direct HR relevance |
Inventory and classification
- List every AI system used in HR, including AI features inside HR software
- Record intended purpose and actual use for each
- Classify as prohibited, high-risk, transparency or minimal risk
- Document classification reasoning, including any Article 6(3) assessment
Prohibited practices (applies now)
- Confirm no emotion recognition of employees or candidates
- Confirm no prohibited biometric categorisation
- Remove or disable any prohibited features
AI literacy (applies now)
- Take measures to support staff AI literacy proportionate to systems and roles
- Provide system-specific training for people overseeing AI
- Keep records of measures and training
Transparency (applies from 2 August 2026)
- Label HR chatbots and assistants as AI
- Check duties for AI-generated content used externally
- Update candidate and employee notices
High-risk deployer duties (from 2 December 2027)
- Obtain and follow provider instructions for use
- Assign competent, trained human oversight with authority to intervene
- Ensure input data under your control is relevant and representative
- Monitor operation and report serious incidents and risks
- Keep automatically generated logs for at least six months, or longer where required
- Inform workers' representatives and affected workers before use at work
- Inform individuals subject to decisions supported by high-risk AI
- Prepare to provide explanations under Article 86
- Use provider information to support data protection impact assessments
Vendors and contracts
- Confirm vendors' provider compliance plans and timelines
- Secure access to documentation, instructions and logs
- Agree cooperation on incidents, audits and explanations
- Check whether your modifications could make you a provider
Governance
- Name an accountable owner for AI Act compliance in HR
- Integrate with data protection and bias testing processes
- Schedule periodic reviews and track guidance updates
For detail on deployer duties, see EU AI Act employer obligations. For bias testing that supports these duties, see how to audit AI hiring tools.
This is general information, not legal advice. The AI Act is being implemented through guidance, standards and national enforcement that continue to develop. Take qualified advice on your specific systems and jurisdictions.
Related guides
- The EU AI Act and HR: What Employers Need to Know in 2026
The AI Act for HR, updated for the 2026 Omnibus: what is high-risk, what is banned, and the timeline.
- EU AI Act Employer Obligations: Deployer Duties Explained
Each deployer duty for high-risk HR AI explained, with practical actions for HR.
- AI Policy for Employees: Why You Need One and What It Should Cover
Why an employee AI policy is essential, what it covers and who owns it.
- AI Literacy in the Workplace: What It Is and What the EU AI Act Requires
What AI literacy means, the amended Article 4 obligation, and a proportionate programme design.
Frequently asked questions
What should employers do now to comply with the EU AI Act?
Inventory and classify HR AI systems, remove prohibited practices such as emotion recognition, document AI literacy measures, label AI chatbots, engage vendors and prepare high-risk deployer processes ahead of 2 December 2027.
Which EU AI Act obligations apply to employers today?
The prohibited practices and AI literacy duty since 2 February 2025, and transparency duties such as disclosing AI chatbots since 2 August 2026.
How long must deployers keep AI logs?
Deployers of high-risk systems must keep automatically generated logs under their control for at least six months, unless other law requires otherwise.
Do employers need to inform employees about high-risk AI?
Yes. Before putting a high-risk AI system into use at the workplace, deployers must inform workers' representatives and affected workers.
