The AI Act entered into force in August 2024. Its bans and the duty of AI literacy have applied since February 2025; in July 2026 a second regulation moved the rules for high-risk uses, among them hiring and managing workers, to December 2027. Eurostat counts one EU firm in five using AI in 2025. The Act sorts uses into four levels of risk, bans emotion recognition at work, and gives employers who deploy high-risk systems duties of their own, starting with informing the team.
Management Review · Second series · November 2026 · No. 41
AI and the rules at work: the EU AI Act
What applies and when, after the 2026 delay, how many firms use AI, the four levels of risk, what an employer must do before a high-risk system starts, what AI literacy asks, and a card for each AI system in a team.
- No.
- 41
- Pages
- 10
- Sources
- 7
- Topics
- AI
Management Review · No. 41
The figures of the issue
The charts of the printed pages, with their sources.
Sources: Eurostat, Usage of AI technologies increasing in EU enterprises, 2025; Eurostat, Use of artificial intelligence in enterprises (Statistics Explained, data 2025)
The whole text Read the issue as text For reading on a small screen, searching or a screen reader. The same words, without the page design.
In this issue
AI tools can plan shifts, sort job applications or check work, and since 2024 the EU has a law for it. This issue sets out what the AI Act asks of a manager whose team uses AI, what already applies and what was postponed. It describes the law; it is not legal advice.
The AI Act entered into force in August 2024. Its bans and the duty of AI literacy have applied since February 2025; in July 2026 a second regulation moved the rules for high-risk uses, among them hiring and managing workers, to December 2027. Eurostat counts one EU firm in five using AI in 2025. The Act sorts uses into four levels of risk, bans emotion recognition at work, and gives employers who deploy high-risk systems duties of their own, starting with informing the team.
Stiven Janaqi, Editor
Cover story
What applies, and when
The AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in stages. In July 2026 the EU changed part of its calendar with a second regulation, the Digital Omnibus on AI.
- 2025 2 February: the bans, among them emotion recognition at work, and the duty of AI literacy.
- 2026 2 August: most of the Act, including transparency for chatbots and deepfakes.
- 2027 2 December: high-risk rules for Annex III uses, among them work and hiring.
- 2028 2 August: high-risk rules for AI built into regulated products.
The delay is law, not a proposal. The Commission proposed it in November 2025, because the standards for high-risk systems were late; Parliament voted on 16 June 2026, the Council approved on 29 June, and Regulation (EU) 2026/1744 entered into force on 27 July 2026. Annex III moved from 2 August 2026, the product rules from 2 August 2027. Since August 2025 the rules for general-purpose AI models and the penalties have applied.
Our reading
The delay moved the high-risk rules, not the bans or AI literacy. Those have applied since February 2025.
Dates as in Article 113 as amended in 2026. The Act also covers firms outside the EU when the output of their AI is used in the EU (Article 2). A description of the law, not legal advice.
Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Parliament and Council of the European Union, Official Journal of the EU, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026); European Commission, Shaping Europe's digital future, 2026
The numbers
AI in one firm in five
Eurostat asks enterprises in the EU with at least 10 employees whether they use AI technologies, such as text mining, speech recognition or the generation of language. The share has more than doubled in two years.
EU enterprises with 10 or more employees that use AI: 2023 8.0%, 2024 13.5%, 2025 20.0%.
Size makes the difference: in 2025, 55% of large enterprises used AI, 30% of medium-sized and 17% of small ones. In the Act's terms, every firm that uses an AI system under its own authority is a deployer, not only the firms that build it.
Our reading
Most firms will meet the Act as users of bought tools. The duties that reach them are those of the deployer.
EU-27, enterprises with 10 or more employees; micro-enterprises are not counted. Use of at least one AI technology, not only generative AI. The deployer is defined in Article 3(4) of the Act.
Sources: Eurostat, Usage of AI technologies increasing in EU enterprises, 2025; Eurostat, Use of artificial intelligence in enterprises (Statistics Explained, data 2025); European Parliament and Council of the European Union, Official Journal of the EU, 2024
The model
Four levels of risk
The Act regulates uses of AI by the risk they carry for health, safety and fundamental rights. The European Commission describes four levels, from banned to free of new rules.
- Unacce
p table: banned. Among the practices in Article 5: inferring the emotions of people at the workplace, except for medical or safety reasons; social scoring; manipulation. - High: strict duties. Annex III, point 4: AI to recruit and select, to decide on promotion or dismissal, to allocate tasks by behaviour or traits, or to monitor and evaluate performance.
- Transparency: tell people. People must know when they are talking to a chatbot; deepfakes must be labelled (Article 50).
- Minimal: no new rules. For example spam filters or AI in video games.
In its 2025 guidelines the Commission counts as banned a call centre that tracks its employees' anger through webcams and voice recognition. Tracking customers is not, if staff are not tracked at the same time. Fatigue and pain are physical states, not emotions.
Our reading
The level depends on the use, not the software: the same tool can plan routes or rank people.
An Annex III system can fall outside the high level, for instance if it only does a narrow procedural task (Article 6(3)); one that profiles people never does. The guidelines are not binding.
Sources: European Commission, Shaping Europe's digital future, 2026; European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Commission, 2025 (via Lewis Silkin and Covington, 2025)
How it is applied
Before the system star ts
A firm that uses a high-risk AI system under its own authority is its deployer. Article 26 gives the deployer duties of its own, apart from those of the provider; for Annex III systems they apply from 2 December 2027.
- Follow the instructions. Use the system as the provider's instructions for use say (26(1)).
- Name the people who oversee it. With the competence, training and authority to do it, and support (26(2)).
- Inform the team first. Employers tell workers' representatives and the affected workers before the system is used at work (26(7)).
- Moni
t or and repor t. If a risk appears, inform the provider and the authority and suspend use; report serious incidents (26(5)). - Keep the logs, tell the people concerned. Logs for at least six months; people about whom it decides or helps decide are told (26(6), 26(11)).
Our reading
The notice to the team comes before the first use, not after the first complaint.
A selection of the duties in Article 26; the Digital Omnibus moved their date, not their content. The notice follows national rules on informing workers. Not legal advice.
Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Parliament and Council of the European Union, Official Journal of the EU, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026)
How it is measured
AI literacy: what counts
Article 4 has applied since 2 February 2025 to every provider and deployer, whatever the risk of the system. The Digital Omnibus softened its wording in 2026; the duty remains.
Until July 2026
- Ensure, to their best extent, a sufficient level of AI literacy
- of staff and others who operate AI on their behalf
Since July 2026
- Take measures to support the development of AI literacy
- No guaranteed level for any individual
Both versions weigh people's knowledge, experience and training, the context of use and those affected. The Commission's Q&A asks for a general understanding of AI, the firm's role as provider or deployer and the risks of its systems. No certificate is needed; an internal record of trainings is enough. National market surveillance authorities supervise from August 2026.
Hypothe tical example, a dispat ch team with two AI t ools
- Who uses AI: 12 of 14 people, a route planner and a chatbot
- Training: one hour on limits and errors; 10 of 12 done
The record names the date, the content and who took part. Team and numbers are invented.
The two wordings are summarised from Article 4 before and after Regulation (EU) 2026/1744; the example is the editors'.
Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Parliament and Council of the European Union, Official Journal of the EU, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026); European Commission, Shaping Europe's digital future, 2026
More in the essay: “Watch how I do it” is not training
Tool of the issue
The AI card for a team
One card for each AI system the team uses. Fill it in before the first use, keep it with the training record, and look at it again when the system or its use changes. Problems with the system go into the shift handover, with an owner and a time.
- System and provider what it does, who supplies it, where the instructions for use are
- Use and level of risk what we use it for; banned, high, transparency or minimal; who decided
- Oversight who oversees it, with what training, and who may stop it
- Team informed when and how; workers' representatives too
- AI literacy what people learned, when, where the record is
- Problems and logs who reports to the provider, where the logs are kept, for how long
A practice proposed by the editors, after Articles 4, 5, 26 and Annex III of the AI Act and the Commission's four levels. It does not replace legal advice or the provider's instructions.
Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Commission, Shaping Europe's digital future, AI Act: Regulatory framework for AI, 2026; European Commission, Shaping Europe's digital future, AI Literacy: Questions & Answers (updated 27 July 2026)
Open the tool: Shift Handover
Sources and method
Every figure has a source.
The figures in this issue come from the sources below. The year shows how recent each one is.
- European Parliament and Council of the European Union, Official Journal of the EU, “Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)”, 2024. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- European Parliament and Council of the European Union, Official Journal of the EU, “Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI)”, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026). https://eur-lex.europa.eu/eli/reg/2026/1744/oj
- European Commission, Shaping Europe's digital future, “AI Act: Regulatory framework for AI”, 2026. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Commission, “Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act)”, 2025 (via Lewis Silkin and Covington, 2025). https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act
- European Commission, Shaping Europe's digital future, “AI Literacy: Questions & Answers (updated 27 July 2026)”, 2026. https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers
- Eurostat, “Usage of AI technologies increasing in EU enterprises”, 2025. https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20250123-3
- Eurostat, “Use of artificial intelligence in enterprises (Statistics Explained, data 2025)”, 2025. https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Use_of_artificial_intelligence_in_enterprises
Edit orial me thod
Each figure was checked for its year, its publisher and what exactly it measures. Where the publisher's page could not be opened, the figure was checked against independent summaries and is marked “via”. The editors' interpretation is marked “Our reading”. Figures that could not be confirmed are not in the issue.
Management Review · Monthly edition
