What does the AI Act require of HR and coaching tools now?

Inferring employees' emotions with AI has been banned since February 2025. The high-risk duties for recruitment tools moved to December 2027.

The European Union flag reflected in the glass facade of a modern building.
The deadline moved in July 2026. The prohibition on inferring employees' emotions did not. Photo: Fabian Kleiser on Unsplash

Most of what has been written about the AI Act and human resources was written for the deadline of 2 August 2026, and most of it is now wrong. The deadline moved. It moved late, and the amendment that moved it entered into force less than a week before the date it was changing.

What did not move is the part that matters most to anyone buying coaching or engagement software, because that part has been in force since February 2025.

Inferring emotions at work is banned, not regulated

Article 5 of Regulation (EU) 2024/1689 lists the practices the AI Act prohibits outright. Point (f) of the first paragraph covers the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, with an exception only where the system is intended for medical or safety reasons.

Three features of that provision are routinely missed.

It is a prohibition, not a risk category. There is no conformity assessment, no documentation package and no legitimate interest analysis that makes it lawful. Prohibited means prohibited.

It applies to the deployer, not only the vendor. An employer that uses such a system is caught by it. A statement from a supplier that their product is compliant does not transfer the exposure.

It has applied since 2 February 2025. Article 5 sits in Chapter II, which under Article 113 of the Act took effect on that date. This is not a future obligation.

The reach is wider than it looks. Sentiment analysis over internal messages, tone or stress detection in a voice or video interview, engagement scoring that claims to read mood from behavioural signals, wellbeing tools that infer emotional state from usage patterns: all of these are candidates. So is anything in a coaching platform that offers to tell a manager how their team is feeling.

Products marketed on exactly that capability were still being sold into European organisations in 2024. Some have relabelled the feature since. Relabelling is not a defence; what the system does is what counts.

The training obligation nobody budgeted for

Article 4 of the same regulation has also applied since 2 February 2025. It requires providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy among their staff and other people operating the systems on their behalf, taking into account those people's technical knowledge, experience and education and the context the system is used in.

The obligation sits on deployers, which means on almost every employer of any size. It is drafted as a duty to take measures rather than to reach a defined standard, and the Act says explicitly that it does not guarantee any particular level of literacy for any individual.

This is a learning and development obligation written into technology regulation, and it is the one line of the AI Act that lands directly on the function that usually reads none of it. Nobody has been fined over it. It has been enforceable for more than eighteen months.

What moved, and what did not

Annex III of the Act lists the high-risk categories. Point 4 covers employment and workers management, and it is broad. It captures AI used for recruitment or selection, in particular to place targeted job advertisements, to filter applications and to evaluate candidates. It also captures AI used to make decisions affecting the terms of a work relationship, to decide on promotion or termination, to allocate tasks based on individual behaviour or personal traits, and to monitor and evaluate performance and behaviour.

Point 3 does the same for education and vocational training, including systems that evaluate learning outcomes or determine a person's appropriate level of education.

High-risk classification brings the heavy obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness requirements, and registration.

Those obligations were due on 2 August 2026. In November 2025 the European Commission proposed a package of amendments, agreement was reached in May 2026, and Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force in late July 2026, days before the deadline it was changing.

ObligationApplies from
Prohibited practices, Article 5, including workplace emotion inference2 February 2025
AI literacy, Article 42 February 2025
General-purpose AI model obligations2 August 2025
Transparency for systems interacting with people, Article 502 August 2026, with a transition to 2 December 2026 for systems already on the market
High-risk obligations for Annex III systems, including HR2 December 2027, moved from 2 August 2026
High-risk obligations for AI embedded in regulated products2 August 2028, moved from 2 August 2027

The amendment also added a new prohibition covering systems that generate non-consensual intimate imagery or child sexual abuse material, with a transition to 2 December 2026, and made several changes narrowing scope elsewhere.

What the postponement does not do

It does not change the classification. An applicant screening tool is still a high-risk AI system as of today. What moved is when the compliance file has to exist.

For anyone procuring HR or coaching technology, that distinction has a practical consequence. A fifteen-month extension on a documentation obligation is a poor reason to sign a five-year contract with a vendor who cannot describe how they will meet it. The questions worth asking now are the ones that take a supplier a year to be able to answer: what the training data is, how the model's outputs are logged, what human oversight actually looks like in the product rather than in the policy, and what happens when an employee contests a decision the system informed.

The transparency duty in Article 50 is already live and is the cheapest thing to get wrong. If a coaching platform puts a chatbot in front of an employee, the employee has to be able to tell they are talking to a machine. That is a labelling problem, not an engineering one, and it applies from August 2026 with a transition window to December for systems already in the market.

A note on sourcing

The Official Journal is the authority on all of this and is linked in the sources. The amending regulation is recent enough that the secondary analyses of it still disagree on small points; the law firm briefings cited here agree on the substance and on the December 2027 date, and differ by a few days on the publication date. Where this article gives a date it is one that two independent analyses state consistently.

This is a summary of published law, not legal advice, and the scope questions in any specific case turn on what a given system actually does rather than on how it is marketed. The general question of what these tools deliver is covered in what the trials found about AI coaching, and the market they are sold into in how big the coaching industry really is.

Common questions

Can we use AI to measure employee sentiment or emotion? Not in the EU. Article 5(1)(f) of the AI Act prohibits using AI systems to infer emotions of a natural person in the workplace, with an exception only for medical or safety purposes. It has applied since 2 February 2025.

Does the ban apply to us or to the software vendor? Both. The prohibition covers placing such a system on the market, putting it into service and using it. An employer using the system is caught, regardless of what the supplier says.

What is the AI literacy obligation in Article 4? Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and others operating AI systems on their behalf, in proportion to their knowledge, experience and context of use. It has applied since 2 February 2025 and it covers employers, not just technology companies.

When do the high-risk rules for recruitment and performance tools apply? 2 December 2027 for standalone Annex III systems, postponed from 2 August 2026 by Regulation (EU) 2026/1744. For AI embedded in products already covered by EU harmonisation legislation, 2 August 2028.

Is an AI recruitment screening tool still high risk after the postponement? Yes. The classification did not change. Only the date the compliance obligations attach did.

Does an AI coaching chatbot have to tell the user it is not human? Yes, under the transparency obligation in Article 50, which applies from 2 August 2026, with a transition to 2 December 2026 for systems already on the market.

Does the AI Act apply to a non-EU provider? It applies where the system is placed on the EU market or its output is used in the EU, so a provider outside the EU serving EU employers is in scope.

Sources

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text on EUR-Lex
  2. Article 5 of the AI Act, prohibited AI practices, AI Act Explorer
  3. Article 4 of the AI Act, AI literacy, AI Act Explorer
  4. Annex III of the AI Act, high-risk AI systems, including point 4 on employment and workers management
  5. Gibson Dunn, EU AI Act Omnibus Agreement: postponed high-risk deadlines and other key changes
  6. Orrick, EU AI Act Update: Digital Omnibus finalizes eight compliance changes

More from the Journal