Search
Contact
Symbolbild zu KI im HR-Bereich: Menschlicher Finger berührt Finger von Roboter
02.08.2024 | KPMG Law Insights

AI and employment law: what the AI Act means for HR

On August 1, the EU AI Act in force.
It regulates the use of artificial intelligence within the European Union.
As a regulation, the AI Act applies directly without any further act of implementation.
The effects of its provisions may also extend to HR departments.
The HR department must take into account both employment law and other legal requirements when AI is used in the company.
The possible applications of artificial intelligence in HR are diverse.
AI can be used to analyze personnel requirements and write a job advertisement to meet these needs.
AI screens and filters applications by means of automated candidate screening.
A recruiting bot conducts initial interviews. An HR service bot can present interested parties with a needs-based job offer within the company.
This could soon be how the recruitment process works.
AI can also support personalized onboarding and act as a digital mentor or coach.
Artificial intelligence could also assess whether and how well new employees meet the requirements and, on this basis, make a recommendation for passing the probationary period, promotions and salary increases.
In theory, an AI could also determine the likelihood of individual employees being dismissed.
Reporting, skills management, risk assessments and many other HR processes offer potential applications for artificial intelligence.
It could also be used to compare gender-neutral remuneration or in the target agreement process for employees.
But what does employment law allow and what legal requirements still need to be observed?

AI Act: AI in HR is often high-risk AI

The AI Act is particularly relevant.
The AI regulation divides AI systems into risk classes.
Depending on this, stricter or less strict requirements apply.
Artificial intelligence that entails an unacceptable risk is prohibited.
Article 5 of the AI Act lists a number of AI systems that fall into this category.
This includes, for example, AI for inferring the emotions of a natural person in the workplace.
Many of the above-mentioned AI systems in the HR sector are likely to be high-risk systems.
These are systems that endanger safety or fundamental rights.
High-risk AI systems are supplemented in Annex III of the AI Act. Digit. 4 of Annex III explicitly covers AI systems for personnel selection as well as systems that make decisions in connection with the conditions of employment, the promotion or termination of employment contracts.
It also covers AI systems that assign tasks on the basis of individual behavior or personal characteristics or traits or that monitor or evaluate the performance and behavior of individuals in such relationships.

Strict requirements apply to high-risk AI

High-risk AI systems must meet the requirements set out in the AI Act, which are subject to legal review.
Among other things, this applies to them: The company must ensure an appropriate risk management system over the entire life cycle of the AI.
It must also ensure appropriate data governance and data management procedures.
Companies must technically document compliance with the obligations and log the results.
Uses, data and employee recognition must also be logged.
High-risk AI systems must be registered in an EU database of providers and operators.

Simple chatbots must meet transparency requirements

If employers use chatbots, these are normally classified as AI with limited risk.
However, transparency obligations must also be observed here.
In particular, the company must disclose that it is communicating with an AI.
Deep fake content must be labeled.
However, the implementation should be legally reviewed together with IT in each individual case.

Beware of data breaches

The HR department works with a lot of personal data, sometimes even sensitive data.
If this data is to be processed using artificial intelligence, it must be ensured that the data cannot leave the company’s IT environment and that no unauthorized persons within the company can access the data.
The employer must also ensure that the AI does not collect any data that the company does not need.
This also applies if the HR department has no intention of evaluating the data.
This is because the GDPR stipulates the principle of data minimization.

The works council must be involved in the introduction of AI

If employers want to use artificial intelligence in the company, they should always involve the works council.
Even when planning the use of AI, the company must inform the works council in accordance with Section 90 Para.
1 no. 3 of the BetrVG.
The use of AI is also generally subject to § 87 Para.
1 No. 6 BetrVG.
At least if the employer prescribes its use or provides its own AI systems.
This also applies to guidelines on the use of AI.
Only the voluntary use of ChatGPT via private accounts is not subject to co-determination, according to the Hamburg Labor Court.
Employees could inadvertently violate data protection or infringe copyrights if they use AI at work.
As a rule, the employer will be liable for this in the external relationship.
For this reason alone, companies should always draw up rules for the use of AI.

AI language models have a high potential for discrimination

AI is often perceived as objective.
However, the decision it makes is based on the respective language model.
This is generally not based on German labor law and the decisions made could discriminate against people and violate the General Equal Treatment Act (AGG).
Anyone using AI in HR processes must ensure that the language model used is adapted to labor law regulations.
This applies to recruiting, in particular job advertisements and applicant selection, as well as to the analysis of gender-neutral remuneration.
A breach of the prohibition of discrimination can lead to claims for damages.

Conclusion

The list of regulations to be observed was already long.
The AI Act has now added numerous obligations that employers must comply with if they wish to use AI in their company.
The implementation deadlines vary depending on the AI; however, companies should start preparing now.
From an employment law perspective, the works council should always be brought on board at an early stage if the use of AI is planned.
Close cooperation between the IT department, legal department and HR department is important so that the relevant regulatory issues can be properly assessed.
Internal training on AI systems or the design of application examples can be beneficial for acceptance within the company.

Explore #more

02.04.2026 | KPMG Law Insights

Building Modernization Act (GMG): What is now important for companies

The planned Building Modernization Act (GMG) is set to replace significant parts of the previous Building Energy Act (GEG). Companies in the real estate industry,…

01.04.2026 | In the media

Manager Magazin: KPMG Law in first place for legal advice

Every two years, Manager Magazin, together with the Wissenschaftliche Gesellschaft für Management und Beratung (WGMB), awards Germany’s best auditors with a “Best-in-Class” seal and evaluates

27.03.2026 | KPMG Law Insights

Special Infrastructure Fund and State Aid Law: Orientation for Funding Practice and Planning

The special fund “Infrastructure and Climate Neutrality” (SVIK) also entails considerable responsibility under state aid law for federal states, municipalities and recipients of funds. Anyone

23.03.2026 | Deal Notifications

KPMG Law, KPMG Law AT as well as KPMG in Germany and KPMG in Austria advise GOLDBECK GmbH on the acquisition of 50 percent of the shares in ZAUNERGROUP Holding GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and Buchberger Ettmayer Rechtsanwälte GmbH (KPMG Law AT) as well as KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG in Germany) and KPMG…

19.03.2026 | KPMG Law Insights

Business Judgement Rule in the use of AI: how governing bodies are liable for decisions

If an AI provides the basis for business decisions, the people responsible are liable, not the machine. This makes the use of artificial intelligence risky…

16.03.2026 | KPMG Law Insights

KPIs in the legal department: How legal becomes strategically effective through control, transparency and data analysis

Today, legal departments are facing a strategic turning point: they must reliably hedge risks, but at the same time enable speed, control costs and make…

13.03.2026 | KPMG Law Insights

Commercial courts: when they are worthwhile for companies – and when they are not

Large commercial disputes are given courts specially tailored to their needs: the Commercial Courts. The German legislator introduced it with the Act to Strengthen the

10.03.2026 | Deal Notifications

KPMG Law advises on the sale of Krasemann Hausverwaltung to Buena

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) provided legal advice to the KRASEMANN family on the sale of KRASEMANN Immobilien- & Gebäudeservice GmbH (KIGS) and KRASEMANN…

09.03.2026 | KPMG Law Insights

MiCAR and whitepaper obligations – what the transitional regulations mean

The Markets in Crypto-Assets Regulation (MiCAR) has been in force for just over a year. Among other things, MiCAR obliges issuers and providers of crypto…

09.03.2026 | In the media

Guest article in Private Banking Magazine: What tokenized banknotes mean in day-to-day treasury operations

The future of payment transactions will be shaped not by new currencies, but by new processing models. A practical report by Marc Pussar (KPMG Law),…

Contact

André Kock

Manager

Fuhlentwiete 5
20355 Hamburg

Tel.: +49 (0)40 360994-5035
andrekock@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll