The EU AI Act requires employers using AI in the workplace to ensure staff AI literacy, particularly for high-risk systems, including oversight, monitoring, record-keeping, and informing affected workers. Obligations depend on the employer's role and the risk level and purpose of the AI system in use.
The EU AI Act establishes a clear framework for how employers across Europe must manage and use artificial intelligence (AI) in the workplace. Crucially, it imposes duties not only on AI developers but also on entities—such as startups and established firms—deploying AI for hiring, worker management or other employment decisions. Employers must identify their formal ‘role’ under the Act (provider or deployer) and adjust their internal policies accordingly. This practical guide explains what actions are required, focusing on AI literacy, high-risk systems, and essential worker safeguards.
- Employers must ensure proper AI literacy and training for relevant staff.
- High-risk workplace AI use triggers extra requirements: human oversight, monitoring, record-keeping, and worker notification.
- Duties differ depending on whether an employer deploys, provides, or imports the AI system, and the risk category of its use.
Who Is a Provider or Deployer Under the EU AI Act?
Under the EU AI Act, most employers using third-party AI tools are classified as 'deployers.' A provider is the entity developing or placing an AI system on the market under its own name, while a deployer is typically an end-user applying the system in business operations. Importers or distributors have distinct compliance duties if the system originates outside the EU or is distributed onwards. Obligations for each role vary: deployers must ensure system suitability and ongoing compliance, while providers focus on technical documentation and market conformity.[2]
Which Workplace AI Uses May Be High-Risk?
The Act specifically lists high-risk uses in an employment context. These include AI deployed in recruitment, candidate screening, performance evaluation, worker monitoring, automated task allocation, promotion and dismissal decisions. To be classified as high-risk, the system must be intended to make or support decisions that significantly affect worker rights or opportunities. Routine or trivial uses may not qualify, but employers must document risk assessments to justify their classification. Clarifying the system’s intended use and actual impact is essential before deployment.[3]
AI Literacy: What Employers Must Do
All employers deploying AI systems—regardless of risk level—are required to ensure that staff entrusted with using or overseeing these tools possess sufficient AI literacy. This encompasses tailored training proportional to an employee’s responsibilities and the technological risks of the specific AI system. Employers must consider individual knowledge, prior training, and the workplace setting when designing their AI literacy programmes, supporting responsible and informed AI use.
High-Risk Deployer Duties: Oversight, Monitoring and Records
Extra obligations apply for high-risk AI. Deployers must implement robust human oversight: this means assigning competent people empowered to monitor AI operation, intervene, and if necessary, override automated decisions. Regular system monitoring, detailed record-keeping, and incident logging are mandatory. Technical documentation—detailing the AI’s functionality, data sources, and ongoing risk controls—must be kept and may need to be provided to regulatory authorities upon request. Employers are also required to report serious incidents or malfunctions linked to high-risk AI to the relevant authorities.[3]
Informing Workers and Their Representatives
Before introducing high-risk AI at work, employers must inform the employees affected and their representatives about the system’s use, purpose, capabilities, and potential impact. The notification should be transparent and in clear language, enabling workers to understand how automated decision-making might influence their employment conditions, evaluation, or advancement. In some cases, this notice must happen before deployment, giving employee representatives or works councils sufficient time to respond or consult, as mandated by applicable labour law.[2]
A Startup Compliance Checklist
Startups and founders, often operating with limited compliance resources, face particular challenges. Nonetheless, as deployers, they must conduct risk assessments before using any workplace AI, maintain up-to-date technical records, and establish internal protocols for oversight and reporting. Vendor management becomes critical: even if the AI is off-the-shelf, startups must verify the provider’s compliance documentation and ensure employees receive appropriate AI training. Failure to meet these requirements risks significant liabilities and reputational harm.[3][4]
What Changes If You Build or Adapt the AI System?
If a startup develops its own AI system or substantially adapts a vendor tool and then uses or markets it under its own name, it may be treated as a ‘provider’ under the Act. In this case, the employer is responsible for risk management, conformity assessment, technical documentation throughout the system’s lifecycle, and post-market monitoring. These are broader and more onerous than the deployer’s duties, requiring more sophisticated compliance infrastructure and resources.[2][3]
Typische Probleme
Many startups and small employers struggle with the resources and expertise needed for comprehensive oversight and record-keeping. Off-the-shelf AI tools can be difficult to customise, leaving deployers at risk of using systems that are not fully transparent or configurable. This increases the challenge of demonstrating compliance during audits and makes it difficult to explain automated decisions to affected workers.[4]
Aktuelle Entwicklungen
Since the final adoption of the EU AI Act in 2024, the definition of high-risk workplace AI and corresponding employer obligations have been clarified further by sector-specific guidance at both EU and national levels. Implementation details—including timelines for particular sectors or company sizes—may be subject to change, and employers are encouraged to monitor updates closely before launching or updating workplace AI deployments.[4]
Conclusion: Next Steps for Employers
The EU AI Act marks a significant shift in how employers must manage workplace technology. Whether an employer is a startup founder or an established company, understanding their role (provider, deployer, or both) is critical. Proactive steps—such as arranging AI literacy training, maintaining documentation, and transparently informing workers—are essential for compliance and organisational trust. With enforcement and national guidelines evolving, it is crucial to remain updated and prepared for ongoing obligations, especially if workplace AI use involves high-risk systems affecting employee rights.
Quellen
[2] EU AI Act: Key Obligations for Employers (Lexology, 2024-05-14)
[3] EU AI Act: Guide for Employers and Human Resource Managers (CMS Law-Now, 2024-04-26)
[4] Employers: What You Need to Know About the New EU AI Act (Bloomberg Law, 2024-03-20)



