Management Review · Second series · November 2026 · No. 41

AI and the rules at work: the EU AI Act

What applies and when, after the 2026 delay, how many firms use AI, the four levels of risk, what an employer must do before a high-risk system starts, what AI literacy asks, and a card for each AI system in a team.

No.
41
Pages
10
Sources
7
Topics
AI
Stiven CatalystSecond series · November 2026
ManagementReview

Management without theatre.

AI

AI and the rules at work:the EU AI Act

What applies and when, after the 2026 delay, how many firms use AI, the four levels of risk, what an employer must do before a high-risk system starts, what AI literacy asks, and a card for each AI system in a team.

No.41

16

months later than first planned: the AI Act's rules for high-risk AI used to hire and manage workers now apply from 2 December 2027.Regulation (EU) 2026/1744

Inside

  1. Cover storyWhat applies, and whenPage 03
  2. The modelFour levels of riskPage 05
  3. Tool of the issueThe AI card for a teamPage 08

stivencatalyst.com

Management Review · No. 41 · November 2026AI
stivencatalyst.comStiven Catalyst2

No. 41 · AI

In this issue

AI tools can plan shifts, sort job applications or check work, and since 2024 the EU has a law for it. This issue sets out what the AI Act asks of a manager whose team uses AI, what already applies and what was postponed. It describes the law; it is not legal advice.

The AI Act entered into force in August 2024. Its bans and the duty of AI literacy have applied since February 2025; in July 2026 a second regulation moved the rules for high-risk uses, among them hiring and managing workers, to December 2027. Eurostat counts one EU firm in five using AI in 2025. The Act sorts uses into four levels of risk, bans emotion recognition at work, and gives employers who deploy high-risk systems duties of their own, starting with informing the team.

  1. 03Cover storyWhat applies, and when
  2. 04The numbersAI in one firm in five
  3. 05The modelFour levels of risk
  4. 06How it is appliedBefore the system starts
  5. 07How it is measuredAI literacy: what counts
  6. 08Tool of the issueThe AI card for a team
  7. 09SourcesSources and method

How to read this issue

Figure

Every figure has its source and year at the foot of its page.

Our reading

Where the editors interpret rather than the research, it says so.

Practice

The steps and the card are proposals to try, not research results.

Management Review · No. 41 · November 2026AI
stivencatalyst.comStiven Catalyst3

Cover story

What applies,and when

The AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in stages. In July 2026 the EU changed part of its calendar with a second regulation, the Digital Omnibus on AI.

  1. 20252 February: the bans, among them emotion recognition at work, and the duty of AI literacy.
  2. 20262 August: most of the Act, including transparency for chatbots and deepfakes.
  3. 20272 December: high-risk rules for Annex III uses, among them work and hiring.
  4. 20282 August: high-risk rules for AI built into regulated products.

The delay is law, not a proposal. The Commission proposed it in November 2025, because the standards for high-risk systems were late; Parliament voted on 16 June 2026, the Council approved on 29 June, and Regulation (EU) 2026/1744 entered into force on 27 July 2026. Annex III moved from 2 August 2026, the product rules from 2 August 2027. Since August 2025 the rules for general-purpose AI models and the penalties have applied.

Our reading

The delay moved the high-risk rules, not the bans or AI literacy. Those have applied since February 2025.

Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Parliament and Council of the European Union, Official Journal of the EU, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026); European Commission, Shaping Europe's digital future, 2026

Dates as in Article 113 as amended in 2026. The Act also covers firms outside the EU when the output of their AI is used in the EU (Article 2). A description of the law, not legal advice.

Management Review · No. 41 · November 2026AI
stivencatalyst.comStiven Catalyst4

The numbers

AI in one firmin five

Eurostat asks enterprises in the EU with at least 10 employees whether they use AI technologies, such as text mining, speech recognition or the generation of language. The share has more than doubled in two years.

EU enterprises with 10 or more employees that use AI

05101520252023202420258.0%13.5%20.0%

Size makes the difference: in 2025, 55% of large enterprises used AI, 30% of medium-sized and 17% of small ones. In the Act's terms, every firm that uses an AI system under its own authority is a deployer, not only the firms that build it.

Our reading

Most firms will meet the Act as users of bought tools. The duties that reach them are those of the deployer.

Sources: Eurostat, Usage of AI technologies increasing in EU enterprises, 2025; Eurostat, Use of artificial intelligence in enterprises (Statistics Explained, data 2025); European Parliament and Council of the European Union, Official Journal of the EU, 2024

EU-27, enterprises with 10 or more employees; micro-enterprises are not counted. Use of at least one AI technology, not only generative AI. The deployer is defined in Article 3(4) of the Act.

Management Review · No. 41 · November 2026AI
stivencatalyst.comStiven Catalyst5

The model

Four levelsof risk

The Act regulates uses of AI by the risk they carry for health, safety and fundamental rights. The European Commission describes four levels, from banned to free of new rules.

  1. Unacceptable: banned

    Among the practices in Article 5: inferring the emotions of people at the workplace, except for medical or safety reasons; social scoring; manipulation.

  2. High: strict duties

    Annex III, point 4: AI to recruit and select, to decide on promotion or dismissal, to allocate tasks by behaviour or traits, or to monitor and evaluate performance.

  3. Transparency: tell people

    People must know when they are talking to a chatbot; deepfakes must be labelled (Article 50).

  4. Minimal: no new rules

    For example spam filters or AI in video games.

In its 2025 guidelines the Commission counts as banned a call centre that tracks its employees' anger through webcams and voice recognition. Tracking customers is not, if staff are not tracked at the same time. Fatigue and pain are physical states, not emotions.

Our reading

The level depends on the use, not the software: the same tool can plan routes or rank people.

Sources: European Commission, Shaping Europe's digital future, 2026; European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Commission, 2025 (via Lewis Silkin and Covington, 2025)

An Annex III system can fall outside the high level, for instance if it only does a narrow procedural task (Article 6(3)); one that profiles people never does. The guidelines are not binding.

Management Review · No. 41 · November 2026AI
stivencatalyst.comStiven Catalyst6

How it is applied

Before the systemstarts

A firm that uses a high-risk AI system under its own authority is its deployer. Article 26 gives the deployer duties of its own, apart from those of the provider; for Annex III systems they apply from 2 December 2027.

  1. Follow the instructions

    Use the system as the provider's instructions for use say (26(1)).

  2. Name the people who oversee it

    With the competence, training and authority to do it, and support (26(2)).

  3. Inform the team first

    Employers tell workers' representatives and the affected workers before the system is used at work (26(7)).

  4. Monitor and report

    If a risk appears, inform the provider and the authority and suspend use; report serious incidents (26(5)).

  5. Keep the logs, tell the people concerned

    Logs for at least six months; people about whom it decides or helps decide are told (26(6), 26(11)).

Our reading

The notice to the team comes before the first use, not after the first complaint.

Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Parliament and Council of the European Union, Official Journal of the EU, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026)

A selection of the duties in Article 26; the Digital Omnibus moved their date, not their content. The notice follows national rules on informing workers. Not legal advice.

Management Review · No. 41 · November 2026AI
stivencatalyst.comStiven Catalyst7

How it is measured

AI literacy:what counts

Article 4 has applied since 2 February 2025 to every provider and deployer, whatever the risk of the system. The Digital Omnibus softened its wording in 2026; the duty remains.

Until July 2026

  • Ensure, to their best extent, a sufficient level of AI literacy
  • of staff and others who operate AI on their behalf

Since July 2026

  • Take measures to support the development of AI literacy
  • No guaranteed level for any individual

Both versions weigh people's knowledge, experience and training, the context of use and those affected. The Commission's Q&A asks for a general understanding of AI, the firm's role as provider or deployer and the risks of its systems. No certificate is needed; an internal record of trainings is enough. National market surveillance authorities supervise from August 2026.

Hypothetical example, a dispatch team with two AI tools
Who uses AI
12 of 14 people, a route planner and a chatbot
Training
one hour on limits and errors; 10 of 12 done

The record names the date, the content and who took part. Team and numbers are invented.

Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Parliament and Council of the European Union, Official Journal of the EU, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026); European Commission, Shaping Europe's digital future, 2026

The two wordings are summarised from Article 4 before and after Regulation (EU) 2026/1744; the example is the editors'.

Management Review · No. 41 · November 2026AI
stivencatalyst.comStiven Catalyst8

Tool of the issue

The AI cardfor a team

One card for each AI system the team uses. Fill it in before the first use, keep it with the training record, and look at it again when the system or its use changes. Problems with the system go into the shift handover, with an owner and a time.

  1. 01System and providerwhat it does, who supplies it, where the instructions for use are

  2. 02Use and level of riskwhat we use it for; banned, high, transparency or minimal; who decided

  3. 03Oversightwho oversees it, with what training, and who may stop it

  4. 04Team informedwhen and how; workers' representatives too

  5. 05AI literacywhat people learned, when, where the record is

  6. 06Problems and logswho reports to the provider, where the logs are kept, for how long

Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Commission, Shaping Europe's digital future, AI Act: Regulatory framework for AI, 2026; European Commission, Shaping Europe's digital future, AI Literacy: Questions & Answers (updated 27 July 2026)

A practice proposed by the editors, after Articles 4, 5, 26 and Annex III of the AI Act and the Commission's four levels. It does not replace legal advice or the provider's instructions.

Management Review · No. 41 · November 2026Sources
stivencatalyst.comStiven Catalyst9

Sources and method

Every figurehas a source.

The figures in this issue come from the sources below. The year shows how recent each one is.

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)European Parliament and Council of the European Union, Official Journal of the EU, 2024https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI)European Parliament and Council of the European Union, Official Journal of the EU, 2026 · via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026https://eur-lex.europa.eu/eli/reg/2026/1744/oj
  3. AI Act: Regulatory framework for AIEuropean Commission, Shaping Europe's digital future, 2026https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  4. Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act)European Commission, 2025 · via Lewis Silkin and Covington, 2025https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act
  5. AI Literacy: Questions & Answers (updated 27 July 2026)European Commission, Shaping Europe's digital future, 2026https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers
  6. Usage of AI technologies increasing in EU enterprisesEurostat, 2025https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20250123-3
  7. Use of artificial intelligence in enterprises (Statistics Explained, data 2025)Eurostat, 2025https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Use_of_artificial_intelligence_in_enterprises
Editorial method

Each figure was checked for its year, its publisher and what exactly it measures. Where the publisher's page could not be opened, the figure was checked against independent summaries and is marked “via”. The editors' interpretation is marked “Our reading”. Figures that could not be confirmed are not in the issue.

ManagementReview

Management without theatre.

Every issue, one management question, checked against the best research.

All issues

stivencatalyst.com/magazine/management-review.html

Management Review · No. 41 · November 2026 · Stiven Catalyst

Management Review · No. 41

The figures of the issue

The charts of the printed pages, with their sources.

The numbersEU enterprises with 10 or more employees that use AI
05101520252023202420258.0%13.5%20.0%
05101520252023202420258.0%13.5%20.0%

Sources: Eurostat, Usage of AI technologies increasing in EU enterprises, 2025; Eurostat, Use of artificial intelligence in enterprises (Statistics Explained, data 2025)

The whole text Read the issue as text For reading on a small screen, searching or a screen reader. The same words, without the page design.

In this issue

AI tools can plan shifts, sort job applications or check work, and since 2024 the EU has a law for it. This issue sets out what the AI Act asks of a manager whose team uses AI, what already applies and what was postponed. It describes the law; it is not legal advice.

The AI Act entered into force in August 2024. Its bans and the duty of AI literacy have applied since February 2025; in July 2026 a second regulation moved the rules for high-risk uses, among them hiring and managing workers, to December 2027. Eurostat counts one EU firm in five using AI in 2025. The Act sorts uses into four levels of risk, bans emotion recognition at work, and gives employers who deploy high-risk systems duties of their own, starting with informing the team.

Stiven Janaqi, Editor

Cover story

What applies, and when

The AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in stages. In July 2026 the EU changed part of its calendar with a second regulation, the Digital Omnibus on AI.

  • 2025 2 February: the bans, among them emotion recognition at work, and the duty of AI literacy.
  • 2026 2 August: most of the Act, including transparency for chatbots and deepfakes.
  • 2027 2 December: high-risk rules for Annex III uses, among them work and hiring.
  • 2028 2 August: high-risk rules for AI built into regulated products.

The delay is law, not a proposal. The Commission proposed it in November 2025, because the standards for high-risk systems were late; Parliament voted on 16 June 2026, the Council approved on 29 June, and Regulation (EU) 2026/1744 entered into force on 27 July 2026. Annex III moved from 2 August 2026, the product rules from 2 August 2027. Since August 2025 the rules for general-purpose AI models and the penalties have applied.

Our reading

The delay moved the high-risk rules, not the bans or AI literacy. Those have applied since February 2025.

Dates as in Article 113 as amended in 2026. The Act also covers firms outside the EU when the output of their AI is used in the EU (Article 2). A description of the law, not legal advice.

Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Parliament and Council of the European Union, Official Journal of the EU, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026); European Commission, Shaping Europe's digital future, 2026

The numbers

AI in one firm in five

Eurostat asks enterprises in the EU with at least 10 employees whether they use AI technologies, such as text mining, speech recognition or the generation of language. The share has more than doubled in two years.

EU enterprises with 10 or more employees that use AI: 2023 8.0%, 2024 13.5%, 2025 20.0%.

Size makes the difference: in 2025, 55% of large enterprises used AI, 30% of medium-sized and 17% of small ones. In the Act's terms, every firm that uses an AI system under its own authority is a deployer, not only the firms that build it.

Our reading

Most firms will meet the Act as users of bought tools. The duties that reach them are those of the deployer.

EU-27, enterprises with 10 or more employees; micro-enterprises are not counted. Use of at least one AI technology, not only generative AI. The deployer is defined in Article 3(4) of the Act.

Sources: Eurostat, Usage of AI technologies increasing in EU enterprises, 2025; Eurostat, Use of artificial intelligence in enterprises (Statistics Explained, data 2025); European Parliament and Council of the European Union, Official Journal of the EU, 2024

The model

Four levels of risk

The Act regulates uses of AI by the risk they carry for health, safety and fundamental rights. The European Commission describes four levels, from banned to free of new rules.

  • Unacceptable: banned. Among the practices in Article 5: inferring the emotions of people at the workplace, except for medical or safety reasons; social scoring; manipulation.
  • High: strict duties. Annex III, point 4: AI to recruit and select, to decide on promotion or dismissal, to allocate tasks by behaviour or traits, or to monitor and evaluate performance.
  • Transparency: tell people. People must know when they are talking to a chatbot; deepfakes must be labelled (Article 50).
  • Minimal: no new rules. For example spam filters or AI in video games.

In its 2025 guidelines the Commission counts as banned a call centre that tracks its employees' anger through webcams and voice recognition. Tracking customers is not, if staff are not tracked at the same time. Fatigue and pain are physical states, not emotions.

Our reading

The level depends on the use, not the software: the same tool can plan routes or rank people.

An Annex III system can fall outside the high level, for instance if it only does a narrow procedural task (Article 6(3)); one that profiles people never does. The guidelines are not binding.

Sources: European Commission, Shaping Europe's digital future, 2026; European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Commission, 2025 (via Lewis Silkin and Covington, 2025)

How it is applied

Before the system starts

A firm that uses a high-risk AI system under its own authority is its deployer. Article 26 gives the deployer duties of its own, apart from those of the provider; for Annex III systems they apply from 2 December 2027.

  • Follow the instructions. Use the system as the provider's instructions for use say (26(1)).
  • Name the people who oversee it. With the competence, training and authority to do it, and support (26(2)).
  • Inform the team first. Employers tell workers' representatives and the affected workers before the system is used at work (26(7)).
  • Monitor and report. If a risk appears, inform the provider and the authority and suspend use; report serious incidents (26(5)).
  • Keep the logs, tell the people concerned. Logs for at least six months; people about whom it decides or helps decide are told (26(6), 26(11)).

Our reading

The notice to the team comes before the first use, not after the first complaint.

A selection of the duties in Article 26; the Digital Omnibus moved their date, not their content. The notice follows national rules on informing workers. Not legal advice.

Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Parliament and Council of the European Union, Official Journal of the EU, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026)

How it is measured

AI literacy: what counts

Article 4 has applied since 2 February 2025 to every provider and deployer, whatever the risk of the system. The Digital Omnibus softened its wording in 2026; the duty remains.

Until July 2026

  • Ensure, to their best extent, a sufficient level of AI literacy
  • of staff and others who operate AI on their behalf

Since July 2026

  • Take measures to support the development of AI literacy
  • No guaranteed level for any individual

Both versions weigh people's knowledge, experience and training, the context of use and those affected. The Commission's Q&A asks for a general understanding of AI, the firm's role as provider or deployer and the risks of its systems. No certificate is needed; an internal record of trainings is enough. National market surveillance authorities supervise from August 2026.

Hypothetical example, a dispatch team with two AI tools

  • Who uses AI: 12 of 14 people, a route planner and a chatbot
  • Training: one hour on limits and errors; 10 of 12 done

The record names the date, the content and who took part. Team and numbers are invented.

The two wordings are summarised from Article 4 before and after Regulation (EU) 2026/1744; the example is the editors'.

Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Parliament and Council of the European Union, Official Journal of the EU, 2026 (via European Parliament, P10_TA(2026)0198; European Commission; Gibson Dunn and Cooley, 2026); European Commission, Shaping Europe's digital future, 2026

More in the essay: “Watch how I do it” is not training

Tool of the issue

The AI card for a team

One card for each AI system the team uses. Fill it in before the first use, keep it with the training record, and look at it again when the system or its use changes. Problems with the system go into the shift handover, with an owner and a time.

  1. System and provider what it does, who supplies it, where the instructions for use are
  2. Use and level of risk what we use it for; banned, high, transparency or minimal; who decided
  3. Oversight who oversees it, with what training, and who may stop it
  4. Team informed when and how; workers' representatives too
  5. AI literacy what people learned, when, where the record is
  6. Problems and logs who reports to the provider, where the logs are kept, for how long

A practice proposed by the editors, after Articles 4, 5, 26 and Annex III of the AI Act and the Commission's four levels. It does not replace legal advice or the provider's instructions.

Sources: European Parliament and Council of the European Union, Official Journal of the EU, 2024; European Commission, Shaping Europe's digital future, AI Act: Regulatory framework for AI, 2026; European Commission, Shaping Europe's digital future, AI Literacy: Questions & Answers (updated 27 July 2026)

Open the tool: Shift Handover

Sources and method

Every figure has a source.

The figures in this issue come from the sources below. The year shows how recent each one is.

Editorial method

Each figure was checked for its year, its publisher and what exactly it measures. Where the publisher's page could not be opened, the figure was checked against independent summaries and is marked “via”. The editors' interpretation is marked “Our reading”. Figures that could not be confirmed are not in the issue.

Management Review · Monthly edition

Read another issue

All issues