Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Law · 2 min read · Updated 16 August 2026

EU AI Act

In shortThe AI Act reaches mid-sized companies mainly through recruitment and worker monitoring.

At a glance

Instrument
Regulation (EU) 2024/1689, in force since August 2024, applying in stages
Approach
Risk-based: prohibited practices, high risk, transparency duties, minimal risk
Who is covered
Providers and deployers of AI systems — including those who merely use somebody else's system
Relevant for mid-sized firms
Recruitment, and evaluation or monitoring of workers, fall into the high-risk tier
Transparency duties
Chatbots, synthetic content and emotion recognition must be labelled
Practical preparation
An inventory of the systems in use with purpose and data categories; a one-page usage rule

The AI Act does not regulate technology but purposes of use. The same language model can fall under minimal risk in one application and become a high-risk system in another — it depends on what it is used for and whom the decision affects.

For companies that is the regulation's most important property. It does not answer "may we use AI?" in the abstract, but per use case.

Prohibited practices such as social scoring by authorities or manipulative systems High risk recruitment, worker monitoring, creditworthiness, critical infrastructure among others Transparency duties chatbots, synthetic content, emotion recognition — labelling required Minimal risk by far the largest share of business applications, no specific duties
The second tier reaches mid-sized companies sooner than expected — recruitment and worker monitoring sit in it.

The tier that reaches mid-sized companies

Prohibited practices concern very few companies. The transparency duties are inconvenient but manageable: chatbots and synthetic content must be recognisable as such.

The tier that actually creates work is high risk — and it contains two applications long since common in mid-sized business: candidate selection, and evaluation or monitoring of workers.

Anyone using an applicant tracking system with automatic pre-sorting, or analysing performance data, is covered — even where the system comes from a third party.

What deployers must do

For high-risk applications that includes human oversight with a genuine ability to intervene, logging, informing the people affected, control over input data, and following the provider's instructions.

Those duties presuppose something many services do not supply: information on how the system works, where processing happens and what data flows out. That is exactly where the regulation meets the sovereignty question — not through the provider's registered office, but through traceability.

The pragmatic starting point

Compile a list of the AI tools actually in use, with purpose and data categories. In most organisations that list is longer than expected, and it incidentally uncovers part of the Shadow IT.

Add a one-page rule on which data categories never go into an external tool. A ban with no usable replacement fails against the tools' usefulness; a clear boundary plus an approved tool works.

Common questions

Does the regulation apply if we only use third-party tools?
Yes. Deploying an AI system carries its own duties, depending on the risk tier. For high-risk applications these include human oversight, logging and informing the people affected.
Which typical applications are high risk?
In companies, above all use in hiring and candidate selection, and in evaluating, allocating and monitoring workers. Both are more widespread than the debate suggests.
What does this have to do with sovereignty?
The duties presuppose traceability: where does the model come from, where is processing done, what data flows out? With a service that will not answer those questions, meeting your own duties is barely possible — regardless of where the provider sits.
What is the pragmatic first step?
A list of the AI tools actually in use, their purpose and the data categories going into them. In most organisations that list is longer than expected — and it uncovers part of the shadow IT at the same time.

Sources

See also

Related terms