Guide

EU AI Act and performance reviews: what HR must do

If your company uses software that scores, ranks or summarizes employees’ performance, the EU AI Act probably treats it as a high-risk AI system. Here is what that means for HR, in plain terms. This is general information, not legal advice.

Updated 5 October 2026

The short version

The EU AI Act (Regulation (EU) 2024/1689) classifies AI systems used in employment and worker management as high-risk. That explicitly includes systems used to monitor and evaluate the performance and behavior of workers, and to make or inform decisions on promotion, termination or the terms of employment (Annex III, point 4).

High-risk does not mean banned. It means the vendor (the “provider”) and your company (the “deployer”) each have obligations. As the buyer, yours centre on using the system as intended, keeping real human oversight, telling the people affected, keeping the logs, and making sure your staff understand the tool.

Does your review software count?

It depends on what the software does, not on whether it says “AI” on the website. A form that collects feedback and stores it is ordinary software. A tool that uses AI to rate people, to rank them, or to produce recommendations that feed into decisions about them is in scope.

The Act has an exemption for systems that only do narrow procedural or preparatory tasks, but it does not apply where the system profiles individuals. Because scoring people against competencies is profiling, assume AI-generated performance ratings are high-risk unless your lawyers conclude otherwise. A summary of free-text feedback that a person reviews and rewrites sits in a grayer zone. Ask your vendor how they classify it, and why.

What HR has to do as the deployer

Article 26 sets out the deployer duties for high-risk systems. In practice, for a performance review tool, that means:

  1. Use the system according to the provider’s instructions, and check that your use matches its intended purpose.
  2. Assign human oversight to people who have the competence, training and authority to question or override the output.
  3. Make sure the input data you provide, such as the feedback and ratings, is relevant and representative for the purpose.
  4. Monitor how the system behaves and tell the provider, and where relevant the authorities, about serious incidents or risks.
  5. Keep the logs the system generates for at least six months, unless other law requires longer.
  6. Before putting it into use at work, inform the workers’ representatives and the affected employees that they will be subject to a high-risk AI system.
  7. Where a decision affecting someone is based on the output, be ready to explain the role the system played (Article 86 gives the person a right to that explanation).

What “human oversight” has to mean in practice

Oversight is not satisfied by a person clicking “approve” on every output. The reviewer needs to be able to understand what the system produced, see the evidence behind it, disagree, and change the result. If nobody ever changes a suggested rating, treat that as a warning sign rather than evidence the tool is perfect.

Separately, GDPR Article 22 limits decisions based solely on automated processing that significantly affect a person. A performance rating that feeds into pay or promotion is a good candidate, so a human sign-off step is the safest design under both laws.

Questions to put to a vendor

  • What does the AI do at each setting, and which outputs does a person confirm before they take effect?
  • Can a manager see the evidence behind a suggested rating and change it?
  • What is logged, for how long, and can we export it?
  • Which sub-processors receive employee data, and where?
  • How do you classify this system under the AI Act, and what is your compliance plan for the high-risk requirements?

AI literacy and prohibited practices

Two obligations apply regardless of whether your system is high-risk. Article 4, in force since 2 February 2025, requires providers and deployers to take measures so that staff who operate AI systems have a sufficient level of AI literacy. For HR, that means a short briefing on what the tool does, where it is wrong, and when to override it.

Also since 2 February 2025, using AI to infer emotions of people in the workplace is prohibited, with narrow medical and safety exceptions. Check that no review or engagement tool you use does this.

Timeline

The high-risk requirements were originally scheduled to apply from 2 August 2026. The EU’s Digital Omnibus package moved the date for employment-related high-risk systems to 2 December 2027. Dates in this area have been changing, so verify the current position before you rely on it.

The practical advice is the same either way: do not wait for the date. Choosing a tool with human sign-off, logging and clear documentation now is easier than replacing one later, and telling employees early is good practice regardless of the law.

Works councils and local law

The Act sits on top of national employment law. In many member states, such as Germany, Austria, the Netherlands and France, introducing a tool that monitors or evaluates employees needs consultation with, or agreement from, the works council or employee representatives. Involve them early, and bring the vendor documentation to the first conversation.

FAQ

Frequently asked questions

Is performance review software high-risk under the EU AI Act?

If it uses AI to monitor or evaluate worker performance, or to inform decisions on promotion, pay or termination, then yes, it falls within Annex III, point 4, and is high-risk. Software that only collects and stores feedback without AI evaluation is not.

When do the high-risk rules apply to HR tools?

They were first due on 2 August 2026, and the Digital Omnibus package moves the date for employment systems to 2 December 2027. The AI literacy duty and the ban on workplace emotion recognition already apply since 2 February 2025. Confirm current dates before relying on them.

Do we need to tell employees we use AI in reviews?

For high-risk systems, yes: deployers must inform workers’ representatives and the affected employees before putting the system into use at work. Even where that duty does not yet bite, telling people early builds trust and avoids disputes.

Can AI make the final decision on a performance review?

It should not. For the sake of the AI Act’s human-oversight requirement and GDPR Article 22, a person with real authority should review and own the outcome. Ratings that affect pay, promotion or employment should not rest on automated output alone.

Who is responsible, the vendor or the employer?

Both, for different things. The vendor, as provider, owes risk management, documentation, logging capability and a conformity assessment. The employer, as deployer, owes proper use, human oversight, informing employees and keeping logs. Buying a compliant tool does not remove the deployer’s duties.

Where review.center fits

review.center keeps a human in the loop at every automation level and can require a one-click manager confirmation before an automatically compiled review is submitted. It documents what the AI does and which sub-processors see data on its trust page, including where its own AI Act work stands today. We are not a law firm: use this as a checklist for the conversation with your counsel.