AI got into HR software quietly. It finishes the sentence while you write a review, turns three bullet points into a paragraph, transcribes the notes from a one to one. Anyone choosing a performance management tool today finds those features in the product, whether they went looking for them or not.

Which raises the question that always comes up during the evaluation: under the AI Act, what changes for the people using these tools? The short answer is that less changes on the deadlines than most people fear, and quite a lot changes in what has to be written down.

What the AI Act is, and when it applies

The regulation is (EU) 2024/1689. It entered into force on 1 August 2024 and has applied generally since 2 August 2026.

In July 2026 the picture changed with Regulation (EU) 2026/1744, the simplification omnibus, published in the Official Journal on 24 July 2026 and in force since 27 July. The main shift lands exactly on the area that concerns HR: the obligations for high-risk systems under Annex III, due to bite on 2 August 2026, now apply from 2 December 2027. For AI embedded in products already covered by EU product safety law (Annex I), the date is 2 August 2028.

Two sets of rules already apply, though: the transparency obligations in Article 50, applicable since 2 August 2026, and Article 4 on AI literacy, in the version rewritten by the omnibus and applicable since 27 July 2026.

When HR software counts as high risk

This is the part that concerns anyone who runs performance reviews. Annex III, point 4(b), lists as high risk the AI systems intended to make decisions affecting terms of work-related relationships, to allocate tasks based on individual behaviour or personal traits, or “to monitor and evaluate the performance and behaviour” of people in those relationships.

Read that way, any performance management tool with AI inside would be high risk by default, and Article 6(2) does set the default there. Article 6(3) then provides a derogation. An Annex III system is not high risk where it does not pose a significant risk of harm to health, safety or fundamental rights, and where at least one of these conditions applies: it performs a narrow procedural task; it improves the result of a previously completed human activity; it detects deviations from prior decision patterns without replacing the human assessment absent proper human review; it performs a preparatory task to an assessment.

There is a hard stop, and in HR it is the one that matters: the derogation is never available where the system performs profiling of natural persons. Software that builds a profile of a person, predicts their performance or assigns them an automatic score stays high risk, with no shortcuts.

The derogation also comes with a price. Article 6(4) requires the provider to document the assessment before placing the system on the market, to register under Article 49(2) in the EU database, and to hand the documentation to the competent authorities on request.

For a buyer, the practical consequence is simple: ask the vendor which of the two routes they took, and ask to see the document.

What already applies today

A simplified and wrong version of Article 50 is going around, namely that from 2 August 2026 any text written with AI has to be labelled as such. The regulation says something else, and it splits the duties by who does what.

Providers of systems intended to interact directly with people have to make clear that there is an AI on the other side, unless that is obvious. Providers of systems generating synthetic content, meaning audio, images, video or text, have to mark the outputs in a machine-readable format; for systems placed on the market before 2 August 2026 the deadline is 2 December 2026. Deployers of emotion recognition or biometric categorisation systems have to inform the people exposed to them. Deployers generating deepfakes, or generating text published with the purpose of informing the public on matters of public interest, have to disclose it.

A comment written with AI assistance inside an internal review form does not fall under that last case, because it is not text published to inform the public. Disclosing it anyway is good practice and it is the route we took, but it is a choice, not a legal obligation.

Article 4 is about people’s skills instead. In the version rewritten by the omnibus, providers and deployers have to take measures to support the development of AI literacy among their staff, and the text specifies that they are not required to guarantee any specific level for any individual. It remains a duty to act, and it applies to the company using the software, not only to the company building it.

The fines, read in the right place

The figures in Article 99 are large. Prohibited practices under Article 5 reach EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Non-compliance with other obligations, including those on deployers and the transparency rules, reaches EUR 15 million or 3%. Incorrect or misleading information supplied to authorities reaches EUR 7.5 million or 1%.

For SMEs and startups the applicable cap is the lower of the percentage and the fixed amount. And these are caps: the actual fine depends on the gravity, duration and consequences of the infringement. A sixty-person company using a writing assistant is not risking thirty-five million euros; that ceiling is there for prohibited practices, which are a different matter.

The Italian layer, which often gets forgotten

Law no. 132 of 23 September 2025 is Italy’s first law on artificial intelligence: published in the Official Gazette on 25 September 2025, in force since 10 October 2025. Article 11(2) provides that the use of AI at work must be safe, reliable and transparent, that it cannot conflict with human dignity or breach the confidentiality of personal data, and that the employer or principal “is required to inform the worker of the use of artificial intelligence in the cases and in the manner set out in Article 1-bis of Legislative Decree no. 152 of 26 May 1997”.

That cross-reference is the part that counts. Article 1-bis of Legislative Decree 152/1997, introduced by Legislative Decree 104/2022 and amended by the 2023 labour decree, applies to “fully automated decision-making or monitoring systems” that provide information relevant to hiring, managing or terminating the employment relationship, allocating tasks and duties, surveillance, evaluation and performance. The word “fully” was added in 2023 and narrowed the scope: where there is real human input, the Article 1-bis notice in principle does not kick in.

If you have to decide whether to issue it, though, the honest answer is to have it assessed. The boundary of “fully automated” applied to a writing assistant has no settled case law yet, and Article 11 asks for transparent use in any event. Telling employees which AI features are switched on in the HR system costs little and closes the question.

Article 4 of the Workers’ Statute on remote monitoring and the GDPR obligations apply regardless. Article 1-bis itself, at paragraph 4, requires the employer to carry out a risk analysis and a data protection impact assessment on the processing involved.

Two details on the side, useful if you ever need someone to ask: Law 132/2025 set up an Observatory on the adoption of artificial intelligence systems in the world of work at the Ministry of Labour (Article 12), and designated AgID and ACN as Italy’s national authorities for artificial intelligence (Article 20).

Three questions to ask a vendor

None of them need legal training.

First: does the system assign scores, predict performance or build profiles of people? If the answer is yes, you are in high-risk territory, and the whole set of obligations changes, for the vendor and for the company adopting it.

Second: have you carried out the classification assessment under Article 6, and are you registered in the EU database? Ask to see the document, not the reassurance.

Third: where is the data processed, and who retains it? Text and audio can take different routes inside the same product, and it is worth having the vendor spell out which.

How we handled it in TalentRewards

The AI features in TalentRewards are writing tools: text completion while you type, expanding a note into a paragraph, generating and refining questionnaires, dictation with transcription. They do not assign grades, do not compute scores, do not predict anyone’s performance and do not reconstruct a person’s profile.

What reaches the model is the text the user is writing plus some working context: review type, role, department, titles of the active goals, requested tone. What does not reach it is the employee’s name or the history of their past reviews.

On that basis we wrote the classification assessment required by Article 6(4) and concluded that the features fall under the Article 6(3) derogation, on the conditions set out in the document: no automatic scoring, no profiling, effective human oversight. It is our own documented assessment, not a certification issued by a third party, and it has to be revisited if the features change or when the Commission publishes its classification guidelines. As for registration in the EU database under Article 49(2), we will file it as soon as the register is operational: at the date of this article the database is not open yet.

In the interface, the AI is declared where it works. The AI toolbar and the questionnaire generator show an “AI assisted” label, and dictation warns that the transcript should be reread before use.

On data the constraint is technical, and it applies to every single request. Only EU-region endpoints are allowed, and only endpoints that declare they do not retain the text and do not use it to train models. There is no fallback: if no endpoint meets those conditions the request does not go out at all, rather than leaving the Union.

Dictation audio is the weak spot, and we would rather say so: the transcription model we use has no European variant, so the audio is processed in the United States. The feature can be switched off, and we are looking for an alternative with a European endpoint.

For companies adopting the software we put together a kit: instructions for use with the stated limits of the AI features, a template notice to workers for Article 1-bis of Legislative Decree 152/1997, and some notes for the impact assessment. These are support materials, not legal advice: the obligations stay with the company using the software, which would do well to have them validated by its own counsel or DPO.

What is left

The useful part of the AI Act, for anyone buying HR software, is not the deadline. It is that it forces a vendor to write down what the system does, what it does not do, and where the data ends up. Those are the same questions an HR manager would ask anyway, regulation or no regulation.

If you want to see where AI steps in inside TalentRewards and where it does not, you can request a product walkthrough.

This article is for information only and is not legal advice. Updated 18 September 2026.

Share this article

Ready to fix your performance review process?

TalentRewards makes it easy to build a performance management system your team actually loves. Start your free trial today.

Start Free Trial Talk to Sales