Direct answer
We use AI to monitor or evaluate employees. What applies?
This falls under Annex III: high-risk AI. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.
First step: Justify the Article 6(3) exception against each individual condition.
You describe: AI for task allocation, performance evaluation, promotion or termination decisions, or monitoring employee behaviour. Likely role: deployer (you use the system).
This applies now
- Article 5: prohibited practicesApplicable
- Article 4: AI literacyApplicable
Coming up
- Annex III: high-risk AIfrom 2 December 2027
Then you are the deployer. Your vendor builds the system in conformity, you use it in conformity: according to the instructions for use, with human oversight that can genuinely intervene, and with the documents you should receive from them. Request the technical documentation and the declaration of conformity now; without them you cannot demonstrate your own duties later, and that is a contract question to raise before signing.
Your first actions
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
- Screen every use case against Article 5 first. Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.
- Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Record this
- Article 49(2) registration record for the system assessed as not high-risk
- Article 5 screening record
- AI literacy measures record
workplace and staff
Writing assistant refining completed promotion evaluations
A consultancy firm uses an AI writing assistant to refine managers' promotion reports after evaluations are fully completed. Managers have already recorded the recommendation, justification and ratings; the system improves clarity of language, ensures consistency with corporate style and flags potentially biased wording, after which the manager is required to double-check the revised text.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Have the manager fully record the recommendation, justification and ratings first and restrict the system to wording and consistency, and it remains an after-the-fact improvement.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
workplace and staff
Deviation detection in recruitment that also evaluates the recruiters themselves
An AI system is used in the recruitment of employees. It identifies deviations from previous recruitment decision-making patterns to detect potential inconsistencies with corporate recruitment policies, and in doing so also evaluates the personal characteristics of the recruiters conducting the job interviews. The system runs before recruitment is completed.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
A system detecting deviations in decision-making can fall under the exemption, but once it also weighs personal characteristics of your own staff there is profiling and that route closes.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
workplace and staff
Call centre measures employees' anger
A call centre uses webcams and voice recognition to track employees' emotions, such as anger. The same company also uses voice analysis to detect when a customer becomes irritated.
Provenance: The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.
The prohibition follows the relationship of authority rather than the technique: the same voice analysis is prohibited on employees but not on customers, and workplace also covers applicants and probation periods.
Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5
workplace and staff
Medical exception: accessibility yes, burnout detection no
An employer wants to deploy emotion recognition. In one scenario the system assists employees with autism and improves accessibility for blind and deaf colleagues. In the other it measures stress levels to flag burnout, boredom or loss of motivation.
Provenance: The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.
The medical exception is narrow: supporting a specific impairment qualifies, general monitoring of wellbeing, stress or motivation does not, and data gathered under a permitted use may not be reused for other purposes.
Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5
Article 6 has two separate routes to high-risk
The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)
Broadly positioned and general purpose AI systems: a disclaimer is not enough
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)
High-risk does not mean prohibited, and not high-risk does not mean permitted
The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (3) that the fact an AI system is listed as an example in these guidelines does not mean its use should automatically be considered lawful, since such use would still need to comply with other applicable legislation, and in paragraph (4) that the scope of these guidelines is limited to whether an AI system is high-risk or not. In the Annex III chapter of this draft, paragraph (68) states that classifying systems as high-risk under Article 6(2) does not mean their use is prohibited, but that those systems are subject to appropriate requirements. Paragraphs (82) and (83) of this draft explain the wording in so far as their use is permitted under relevant Union or national law and state that falling within a use case does not necessarily mean the system may lawfully be used in those cases, that in addition to the prohibitions other provisions of Union or national law may restrict use, and that under Article 2(9) the AI Act applies without prejudice to rules on consumer protection, product safety and data protection.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)
Split and agentic architectures are assessed as a whole
The non-binding draft guidelines of 19 May 2026 provide in paragraphs 75, 76 and 90 that where several AI systems form part of a more complex whole and their combined intended purpose or joint outputs materially influence an individual decision, that configuration is treated as a single AI system for classification. The draft expressly states that split architectures are assessed as a whole to prevent circumvention by system design, that exemptions for individual modules do not apply where the overall configuration influences key aspects of the decision, and that this also extends to complex interconnected setups such as agentic AI systems whose linked actions jointly serve a high-risk purpose. Under the same draft, strictly procedural or preparatory functions do remain eligible for exemption where they are genuinely separable from the system and do not structure or feed outputs that materially influence the examination of an individual case.
Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationExecution
Record the classification in an AI register
A classification without a register and ownership is not demonstrable. Embed AI guides classification, register and reassessment in a fixed approach.
See the Embed AI approach