AI in HR Guide
EU AI Act and HR

EU AI Act Employer Obligations: Deployer Duties Explained

Most employers will not build AI systems, but they will use them. Under the EU AI Act, that makes them deployers, with their own legal responsibilities that vendors cannot take on for them.

By the HRight Talks editorial teamUpdated 3 minute read

Short answer

Under the EU AI Act, employers deploying high-risk AI systems must use them in accordance with the provider's instructions, assign human oversight to people with the necessary competence, training and authority, ensure input data under their control is relevant and sufficiently representative, monitor operation and report risks and serious incidents, keep automatically generated logs for at least six months, inform workers' representatives and affected workers before use at the workplace, inform people subject to decisions made with the system's help, and support explanations and data protection impact assessments. These duties apply to employment AI from 2 December 2027.

Key takeaways

  • Deployer duties are the employer's own and cannot be outsourced to the vendor.
  • Human oversight must be real: competent, trained and empowered to intervene.
  • Workers and their representatives must be informed before high-risk AI is used at work.
  • Modifying or rebranding a system can turn a deployer into a provider.

Deployer duties at a glance

DutyWhat it means for HR
Follow instructions for useUse the system only as the provider intends; train users on the instructions
Human oversightNamed people with competence, training, authority and support to understand, question and override outputs
Input dataWhere you control inputs, ensure they are relevant and sufficiently representative for the purpose
MonitoringWatch operation, inform the provider and authorities of risks, suspend use if a risk emerges
Serious incidentsReport serious incidents without undue delay
LogsKeep automatically generated logs under your control for at least six months
Inform workersBefore use at the workplace, inform workers' representatives and affected workers
Inform affected peopleTell people that they are subject to a high-risk AI system used in decisions about them
ExplanationsSupport the right to a clear and meaningful explanation of AI's role in certain significant decisions (Article 86)
Data protectionUse provider information to carry out data protection impact assessments where required

Making human oversight real

Oversight fails when reviewers lack time, information or confidence to disagree with a system. In practice:

  • Select overseers with relevant expertise, such as experienced recruiters.
  • Train them on the system's capabilities, limits, bias risks and override procedures.
  • Give them evidence behind outputs, not just scores.
  • Track override rates; near-zero overrides may signal automation bias.
  • Document escalation routes.

See how to reduce bias in AI recruitment.

When an employer becomes a provider

An employer takes on provider obligations if it places its own name or trademark on a high-risk system, makes a substantial modification to one, or changes the intended purpose of an AI system so it becomes high-risk. Customising vendor tools or building in-house HR AI should be assessed with this in mind.

Interaction with other laws

  • GDPR: lawful basis, transparency, automated decision-making rules and impact assessments continue to apply. See AI and employee data privacy.
  • Employment and consultation law: national works council and union consultation duties may apply in addition to the AI Act's information duty.
  • Anti-discrimination law: applies to outcomes regardless of AI Act compliance.

Preparing for 2 December 2027

  1. Map deployer duties to owners in HR, IT, legal and data protection.
  2. Build oversight roles and training into HR processes.
  3. Set up logging, monitoring and incident reporting routines.
  4. Draft worker and candidate information notices.
  5. Agree information and cooperation terms with vendors.

This is general information, not legal advice. The AI Act is being implemented through guidance, standards and national enforcement that continue to develop. Take qualified advice on your specific systems and jurisdictions.

Frequently asked questions

What are employer obligations under the EU AI Act?

As deployers of high-risk AI, employers must follow instructions for use, assign competent human oversight, ensure relevant input data, monitor and report risks, keep logs, inform workers and affected people, and support explanations and data protection assessments.

When do employer obligations under the EU AI Act apply?

Deployer obligations for high-risk employment AI apply from 2 December 2027 following the Digital Omnibus. The prohibitions, AI literacy and transparency duties already apply.

Can an employer rely on the vendor for AI Act compliance?

No. Vendors have provider duties, but deployer duties such as human oversight, monitoring and informing workers are the employer's own responsibility.

Do employers have to consult employees before using high-risk AI?

The AI Act requires informing workers' representatives and affected workers before using high-risk AI at the workplace. National law may require formal consultation as well.

Sources and further reading

  1. Regulation (EU) 2024/1689 (EU AI Act), EUR-Lex
  2. GDPR (Regulation (EU) 2016/679), EUR-Lex
  3. Hunton Andrews Kurth (July 2026): EU Digital Omnibus on AI enters into force
  4. Modulos (July 2026): EU AI Act Omnibus published, new deadlines