EU AI Act Employer Obligations: Deployer Duties Explained
Most employers will not build AI systems, but they will use them. Under the EU AI Act, that makes them deployers, with their own legal responsibilities that vendors cannot take on for them.
Short answer
Under the EU AI Act, employers deploying high-risk AI systems must use them in accordance with the provider's instructions, assign human oversight to people with the necessary competence, training and authority, ensure input data under their control is relevant and sufficiently representative, monitor operation and report risks and serious incidents, keep automatically generated logs for at least six months, inform workers' representatives and affected workers before use at the workplace, inform people subject to decisions made with the system's help, and support explanations and data protection impact assessments. These duties apply to employment AI from 2 December 2027.
Key takeaways
- Deployer duties are the employer's own and cannot be outsourced to the vendor.
- Human oversight must be real: competent, trained and empowered to intervene.
- Workers and their representatives must be informed before high-risk AI is used at work.
- Modifying or rebranding a system can turn a deployer into a provider.
Deployer duties at a glance
| Duty | What it means for HR |
|---|---|
| Follow instructions for use | Use the system only as the provider intends; train users on the instructions |
| Human oversight | Named people with competence, training, authority and support to understand, question and override outputs |
| Input data | Where you control inputs, ensure they are relevant and sufficiently representative for the purpose |
| Monitoring | Watch operation, inform the provider and authorities of risks, suspend use if a risk emerges |
| Serious incidents | Report serious incidents without undue delay |
| Logs | Keep automatically generated logs under your control for at least six months |
| Inform workers | Before use at the workplace, inform workers' representatives and affected workers |
| Inform affected people | Tell people that they are subject to a high-risk AI system used in decisions about them |
| Explanations | Support the right to a clear and meaningful explanation of AI's role in certain significant decisions (Article 86) |
| Data protection | Use provider information to carry out data protection impact assessments where required |
Making human oversight real
Oversight fails when reviewers lack time, information or confidence to disagree with a system. In practice:
- Select overseers with relevant expertise, such as experienced recruiters.
- Train them on the system's capabilities, limits, bias risks and override procedures.
- Give them evidence behind outputs, not just scores.
- Track override rates; near-zero overrides may signal automation bias.
- Document escalation routes.
See how to reduce bias in AI recruitment.
When an employer becomes a provider
An employer takes on provider obligations if it places its own name or trademark on a high-risk system, makes a substantial modification to one, or changes the intended purpose of an AI system so it becomes high-risk. Customising vendor tools or building in-house HR AI should be assessed with this in mind.
Interaction with other laws
- GDPR: lawful basis, transparency, automated decision-making rules and impact assessments continue to apply. See AI and employee data privacy.
- Employment and consultation law: national works council and union consultation duties may apply in addition to the AI Act's information duty.
- Anti-discrimination law: applies to outcomes regardless of AI Act compliance.
Preparing for 2 December 2027
- Map deployer duties to owners in HR, IT, legal and data protection.
- Build oversight roles and training into HR processes.
- Set up logging, monitoring and incident reporting routines.
- Draft worker and candidate information notices.
- Agree information and cooperation terms with vendors.
This is general information, not legal advice. The AI Act is being implemented through guidance, standards and national enforcement that continue to develop. Take qualified advice on your specific systems and jurisdictions.
Related guides
- The EU AI Act and HR: What Employers Need to Know in 2026
The AI Act for HR, updated for the 2026 Omnibus: what is high-risk, what is banned, and the timeline.
- EU AI Act Compliance Checklist for Employers and HR Teams
A seven-part checklist ordered by what applies now and what applies from December 2027.
- Ethical AI in HR: A Framework for Responsible Use of AI with People
Principles, issues, governance and ethical review for using AI responsibly with people.
- AI and Employee Data Privacy: A Guide for HR
How AI changes the privacy picture for employee data, the principles that apply and practical safeguards.
Frequently asked questions
What are employer obligations under the EU AI Act?
As deployers of high-risk AI, employers must follow instructions for use, assign competent human oversight, ensure relevant input data, monitor and report risks, keep logs, inform workers and affected people, and support explanations and data protection assessments.
When do employer obligations under the EU AI Act apply?
Deployer obligations for high-risk employment AI apply from 2 December 2027 following the Digital Omnibus. The prohibitions, AI literacy and transparency duties already apply.
Can an employer rely on the vendor for AI Act compliance?
No. Vendors have provider duties, but deployer duties such as human oversight, monitoring and informing workers are the employer's own responsibility.
Do employers have to consult employees before using high-risk AI?
The AI Act requires informing workers' representatives and affected workers before using high-risk AI at the workplace. National law may require formal consultation as well.
