EU AI Act compliance for AI employee monitoring and performance tools
AI applied to employees splits into two very different legal categories. Performance evaluation and task allocation are high-risk under Annex III point 4. Emotion inference in the workplace is prohibited outright under Article 5, with no compliance path.
Getting that distinction right matters more than the paperwork, because one category is a documentation exercise and the other is a ban that has been in force since February 2025.
Are you a provider or a deployer?
As the employer you are the deployer, and Article 26 plus national employment and data protection law all apply at once.
How this is classified under the Act
Annex III point 4 covers AI intended to be used to monitor and evaluate the performance and behaviour of persons in work-related relationships, and to make decisions on promotion or termination. Productivity scoring and automated performance assessment fall inside it.
What changes the answer: Article 5(1)(f) prohibits AI systems inferring emotions of a natural person in the workplace, apart from narrow medical and safety purposes. Sentiment scoring of staff communications, engagement or mood detection, and stress inference are prohibited rather than high-risk.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Usage Policy for Deployers Article 26
Defines permitted and prohibited uses, human oversight arrangements, input data standards, logging, and incident reporting for a high-risk AI system you deploy.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Article 5(1)(f) Stop emotion inference about workers
Identify and switch off any feature inferring emotional state of employees. Record the check, because a regulator will ask about it before anything else.
- Article 26(7) Inform workers and representatives
Employees and their representatives must be informed before a high-risk monitoring system is put into use. In several member states works council consultation is also required.
- Article 26(2) Human decision-making
Consequential decisions about promotion, discipline, or termination need a human with authority and enough context to depart from what the system suggests.
- Article 26(9) Data protection interaction
A data protection impact assessment is normally required in parallel. The AI Act documentation and the DPIA answer different questions and you need both.
Common mistakes
- Buying a productivity tool with built-in sentiment analysis and treating it as high-risk paperwork when the feature is actually prohibited.
- Deploying monitoring without informing workers, which breaches Article 26(7) whatever the tool does.
- Relying on a DPIA alone and producing no AI Act classification or usage policy.
- Assuming small companies are exempt. There is no size threshold in the Act, only proportionality in how you implement.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 4 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.