EU AI Act · use case
EU AI Act for Employee Monitoring and Performance AI: Rules and Bans
AI that allocates tasks, evaluates performance or decides on promotion and dismissal is high-risk under the EU AI Act. Emotion recognition at work is banned outright.
Classify my system in 3 minutesFree, no account. Pre-filled for this use case.
Risk tier
High-risk
High-risk (Annex III, point 4(b)); partly prohibited (Art. 5(1)(f))
When it applies
Prohibitions apply since 2 February 2025. High-risk obligations apply from 2 December 2027.
Regulation (EU) 2024/1689, Annex III(4)(b); Art. 5(1)(f); Art. 26(7) worker information
Workforce-management AI sits in one of the most tightly regulated corners of the EU AI Act. Systems that decide or materially influence promotion, dismissal, task allocation based on individual behaviour or traits, or that monitor and evaluate performance, are high-risk under Annex III. And one specific feature, inferring emotions from biometric data at work, is prohibited altogether.
This page covers productivity analytics, shift and task-allocation engines, gig-platform dispatch and rating systems, call-centre quality scoring, and any HR dashboard that turns behavioural data into a score used for decisions about people.
Classification
Why this classification applies
Annex III, point 4(b) covers AI “intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships”. Both the decision and the monitoring limbs are in scope, and both apply to platform workers as well as employees.
Article 5(1)(f) prohibits AI systems that infer emotions of a natural person in the workplace or in education, unless intended for medical or safety reasons. A “burnout risk” model based on facial expressions or voice tone, a webcam attention tracker, or sentiment-from-face scoring in customer service falls under the ban.
Systems that only aggregate anonymised team metrics without evaluating individuals can sit outside Annex III. The dividing line is whether outputs are attributable to, and used about, identifiable people.
Obligations
What you have to do
- Do not deploy emotion inference from biometric data at work; remove the feature or restrict it strictly to medical or safety purposes with documentation (Art. 5).
- Provider obligations for high-risk systems: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment, CE marking, EU database registration.
- Employers must inform workers and their representatives before putting the system into service (Art. 26(7)) and comply with national labour law and works-council consultation duties on top.
- Human oversight must allow a manager to override or disregard any score before it affects a person, and the interface must not nudge managers into automatically accepting the output.
- Workers subject to a decision can request an explanation of the AI’s role (Art. 86); GDPR Art. 22 rights on solely automated decisions apply in parallel.
Paperwork
Documents to have on file
Get these documents drafted for your system
Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.
Common mistakes
Where companies get this wrong
- Shipping “sentiment” or “engagement” scores derived from video or voice. Under Art. 5 this is a prohibited practice regardless of consent.
- Rating or dispatch algorithms on gig platforms treated as “just matching”. Task allocation based on behaviour is expressly listed as high-risk.
- Relying on employee consent as a legal basis. In an employment relationship consent is rarely freely given under GDPR, and the AI Act obligations do not depend on consent at all.
- No worker information. The AI Act adds an explicit duty to inform workers’ representatives before deployment, separate from GDPR privacy notices.
FAQ
Frequently asked questions
Is a simple time-tracking or attendance tool high-risk?
Not by itself. Recording hours is not “monitoring and evaluating performance” in the AI Act sense unless the system scores or ranks people or feeds decisions about them. Add a productivity score used in reviews and it becomes high-risk.
Can we use emotion recognition if employees agree to it?
No. Article 5(1)(f) is a prohibition, not a consent requirement. The only exceptions are systems intended for medical or safety reasons, for example detecting driver fatigue for safety.
We bought the system from a vendor. Who is responsible?
The vendor is the provider and owns the technical file and conformity assessment. As deployer you own correct use, human oversight, worker information, log retention and monitoring. If you retrain or repurpose the system, you may become the provider.
This page is general information about Regulation (EU) 2024/1689, updated 2026-09-17. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026.