👥 AI rules: HR and recruitment
HR is where the AI Act bites hardest for ordinary companies: almost every AI that decides about candidates or employees is high-risk, and emotion recognition at work is banned.
Typical AI uses and their risk level
Minimal risk — but avoid discriminatory wording and do not paste candidates’ data into free tools.
High risk (Annex III, point 4) from 2 Dec 2027; GDPR Art. 22 and a DPIA already now.
High risk; consult the works council before introduction.
Prohibited since 2 Feb 2025.
Must say it is AI; answers on rights and pay must be checked.
What to do
- Ask vendors whether their tool is high-risk and how it supports human oversight.
- Tell candidates that AI is used and let a person make the final decision.
- Run a DPIA and check results for discrimination (gender, age, origin).
- Consult the works council or trade union before introducing AI monitoring or evaluation.
- Train HR staff on bias and on explaining decisions.
Common pitfalls
- “The tool only recommends, a person decides” — if the person always follows the recommendation, it is effectively automated.
- Using a general chatbot for CV ranking can make you a provider of a high-risk system.
- Personality tests with AI that infer emotions are prohibited.
Examples
Using ChatGPT to summarise each CV is not high-risk by itself; letting it pick the top 10 is. Safer: AI summarises, a person shortlists.
High risk from Dec 2027 and already now a DPIA, a clear purpose and consultation; ranking people for dismissal would be very risky.
Rules that apply
Applies to anyone who develops AI (provider), uses AI in their business (deployer), imports or distributes it in the EU — also to companies outside the EU if the output is used in the EU. Private, non-professional use is excluded.
In forceGDPRFor most companies GDPR matters more than the AI Act: it decides whether you may put customer or employee data into an AI tool at all. In Slovenia it is supplemented by ZVOP-2 and supervised by the Information Commissioner.
In forceEmployment law (ZDR-1, ZSDU)Introducing AI that monitors or evaluates employees (productivity tracking, AI in hiring) needs a legal basis, prior information and consultation of the works council or trade union. The AI Act adds: inform workers before high-risk AI is used at the workplace (Art. 26(7)).
In forceZVOP-2AI on cameras (face recognition, behaviour analysis) and biometric attendance systems fall under strict ZVOP-2 rules — often they are simply not allowed. The Information Commissioner has published opinions on AI, e.g. on misleading use of AI systems and on accountability.
Coming soonPlatform Work DirectivePlatforms must disclose which automated systems monitor and decide, may not process certain data (e.g. emotional state, private conversations) and must ensure human review of significant decisions.
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.