News
EU AI Act Classifies Employee Evaluation as High-Risk System

The EU's AI Act does not ban the use of artificial intelligence to evaluate employees, but starting in August 2026 it imposes a set of strict obligations on employers, backed by fines of up to 35 million euros.
Contents
An employer can deploy an algorithm that evaluates team performance, decides on promotions, or flags candidates for layoffs. The EU's AI Act does not prohibit this. But starting in August 2026, any such system will have to be treated as high-risk, complete with full documentation, human oversight, and a genuine right for employees to an explanation of why the algorithm decided the way it did.
What the AI Act Changes
The AI regulation explicitly lists the HR areas where algorithms are subject to the strictest requirements: filtering job applications, candidate selection, promotion decisions, performance evaluation, task allocation, and decisions to terminate employment. All of these uses fall into the high-risk category because they can directly affect an employee's fundamental rights, including the right to work and to equal treatment.
That doesn't amount to a ban. A company can keep using tools that analyze data about its workforce. What changes is the formal bar it must clear before such a system goes into use and remains in use.
Employer Obligations
The key requirement is human oversight. Companies must appoint suitably qualified people to continuously monitor how the algorithm operates, and those people must have a genuine ability to ignore, suspend, or override the system's decisions. A final HR decision cannot result solely from the algorithm's output, without a human capable of changing it.
On top of that comes a documentation requirement: automatically recording and retaining the logs generated by the AI system, along with a formal discrimination risk assessment before deployment. Employers must also ensure adequate quality of the training data the system learned from.
The Employee's Right to an Explanation
If an AI system made, or significantly influenced, a decision with legal consequences for an employee, such as denying a promotion, a demotion, or selection for layoff, the employee can demand that the employer provide a clear and understandable explanation of the system's role in that decision. The explanation must cover the specific evaluation criteria and the data the algorithm took into account.
The rules also explicitly ban one category of use: employing AI systems to infer an employee's emotions from facial expressions, tone of voice, or other biometric indicators in the workplace. This ban applies without exceptions, regardless of the stated purpose of the monitoring.
A Dual Protection Regime
The AI Act does not replace GDPR (RODO in Polish law). Both regulations apply in parallel, which in practice means a double set of obligations for employers: they must meet GDPR's requirements on personal data protection, processing minimization and legal basis, while also meeting the AI Act's requirements on transparency, oversight and documentation. Companies must inform employees and their representatives, including trade unions, in advance of their intent to deploy a high-risk system, specifying its purpose, the scope of monitoring, the types of data collected, and how that data influences HR decisions.
What This Means for Companies in Poland
For Polish employers already using AI tools in recruitment or periodic reviews, August 2026 is a hard deadline for completing their procedures. In practice, that means auditing existing algorithm-based HR systems, implementing decision-logging mechanisms, and designating people responsible for oversight before the full enforcement regime kicks in. Employees who believe their employer is breaking these rules will be able to file complaints with national supervisory authorities or the Państwowa Inspekcja Pracy (Poland's National Labour Inspectorate).
The financial risk is real. The upper limit of the fine, 35 million euros or 7 percent of a company's global annual turnover from the previous financial year, whichever is higher, puts AI Act compliance on the same priority level as GDPR compliance.

