LegalLab
Free

The New Rules for AI Decision-Making: What Automated-Decision Regulation Requires Now

The EU AI Act's high-risk rules take effect August 2, 2026, giving anyone affected by an automated decision — especially in hiring — a right to a clear explanation, going beyond GDPR.

· 30 September 2026
Share
The New Rules for AI Decision-Making: What Automated-Decision Regulation Requires Now

By August 2, 2026, companies operating in the EU must comply with a new layer of transparency rules for high-risk AI systems under the EU AI Act — and the area getting the most attention from employment lawyers is how directly it reaches into hiring and workforce management.

The right that goes beyond GDPR

Under the Act, anyone subject to a decision significantly affected by a high-risk AI system is entitled to a clear explanation: the AI's role in the decision, the main parameters that influenced the output, and the level of human oversight involved. That's a meaningfully broader right than GDPR's Article 22, which only covers decisions that are fully automated — the AI Act's explanation right applies more broadly, to AI-assisted decisions generally, not just fully automated ones.

Why employment AI is treated as high-risk almost by default

Annex III of the Act classifies AI used for recruitment, selection, hiring, promotion, termination, task allocation, and performance/behaviour monitoring as high-risk. That's a wide net — it captures most of the AI tools HR and people-ops teams have adopted over the past several years, from resume-screening software to performance-monitoring dashboards, regardless of how limited any individual tool's role in a final decision might be.

What compliance actually requires

The obligations aren't just about the explanation right. They include controls on data quality, transparency, human oversight, and ongoing monitoring for discrimination — a compliance program, not a single disclosure requirement. The European Commission is expected to issue further practical guidance later in 2026, including on how the AI Act interacts with existing EU data-protection law.

What HR and people-ops teams should do now

If your hiring or performance-management stack includes any AI-assisted scoring, ranking, or flagging tool, the practical starting point is an Annex III classification check: does the tool fall within recruitment, hiring, promotion, termination, task allocation, or conduct monitoring? If so, treat August 2026 as a real compliance deadline, not a distant one — building the explanation-generation and human-oversight processes the Act requires takes longer than most HR tech procurement cycles assume.


Sources: Wilson Sonsini · Crowell & Moring · Secure Privacy