Brussels, Sets

Brussels Sets a December 2027 Deadline for Employers Running High-Risk AI

Published on 09/23/2026 at 09:10 | Editorial boerse-global.de

EU AI Act operator duties start 2 December 2027 and 2 August 2028, covering high-risk AI in hiring, emotion reading and exam grading.

EU AI Act: New Duties for Employers Using AI in Hiring and Grading
Brussels Sets a December 2027 Deadline for Employers Running High-Risk AI Illustration mit AI erstellt.

Companies that use artificial intelligence to screen job applicants, read employees' emotions or grade exam papers will have to meet a fresh set of obligations under the EU's AI Act — and the clock is already running. Article 113 of the regulation staggers the start dates: 2 December 2027 for the first wave of operator duties, followed by 2 August 2028.

Those duties are not trivial. Employers acting as "operators" of high-risk systems must continuously verify that the technology is being used as intended, train staff thoroughly, and check that the prompts and input data fed into the systems are permissible. Automatically generated logs have to be retained for at least six months as part of the documentation trail.

Works councils, prompts and the limits of automated decisions

The arrival of these tools reshapes the balance of power inside the workplace. Under the Gewerbeordnung (Germany's trade code), an employer may in principle dictate which AI tools count as work equipment — but staff have no blanket right to use particular applications such as ChatGPT or Gemini. Where a system is objectively capable of monitoring performance or behaviour, however, the works council's right of co-determination kicks in.

Prompt and token analytics are a particular flashpoint, since they can reveal a great deal about how an individual works and what they are capable of. Purely automated decisions with a significant effect on the people concerned fall under Article 22 of the General Data Protection Regulation (GDPR), which provides for exceptions built around human review, the chance to state one's case and the right to contest the outcome. The Allgemeines Gleichbehandlungsgesetz (AGG), Germany's equal treatment law, remains a binding yardstick as well.

Shadow AI and the security blind spot

Legal exposure is only half the story. An Exabeam study from June 2026 found that 48 percent of security decision-makers rank AI agents with excessive or unintended access rights as their single biggest threat — ahead of external attacks, cited by 28 percent of respondents.

Unsanctioned tools are compounding the problem. The AI Governance Benchmark 2026, produced by Box and the Handelsblatt Research Institute, reports that unapproved generative AI tools are used occasionally at 42 percent of companies and frequently at 34 percent. Just 9 percent of surveyed firms ban external AI tools outright. The consequences are already visible: in a survey by Absolute Security, 71 percent of CISOs reported data leaks traced to unapproved AI applications.

Eight hours back, and a squeeze on junior pay

Efficiency gains keep drawing employers in regardless. Research by Adobe Acrobat from spring 2026 found that 67 percent of workers in Germany expect AI to save them up to eight hours a week, with business, management and engineering roles already leaning on the technology for document handling.

Those gains may come with a price tag attached to salaries. Economists at the ifo Institute observe that many managers expect AI to push wages down over the next five years. Among companies already using AI, roughly one in two anticipates lower pay for workers with fewer than five years of experience; for more seasoned staff the figure sits at around 40 percent. In consulting, AI has already taken over research and data analysis — tasks traditionally handed to junior consultants.

Copilot champions, five action areas, and a jump in vetting

Firms are responding in markedly different ways. Insurer Talanx has adopted a three-phase model and deployed more than 430 "Copilot Champions" as multipliers to train its roughly 24,000 employees in generative AI. Its head of HR, Caroline Schlienkamp, said the hardest part is not the technology but the uneven willingness of the workforce to change.

A report published on 23 September 2026 by AXA XL and S-RM recommends five priority areas for employers: clear accountability for AI governance, protection of sensitive data through identity management, and systematic risk management across the entire lifecycle of AI systems.

Awareness appears to be shifting. The same report notes that 64 percent of companies now vet the security of AI tools before deploying them, up from 37 percent a year earlier.

Disclaimer...

en | boerse | 70164158 |