The use of Artificial Intelligence (AI) in the workplace is currently generating intense discussions in many companies. With the new AI regulation, which was adopted by the Council of the European Union in May 2024, significant changes are emerging for the use of such technologies in businesses. Now it is important to clarify what employers need to consider, which systems are prohibited, and how they can be used in companies.
The most important points in brief
- The AI Regulation categorizes AI systems into different risk categories, from minimal to high risk, and establishes corresponding strict requirements for their use.
- The regulation applies to all companies based in the EU that use AI systems. Operators outside the EU whose AI systems are used in the EU are also subject to these regulations.
- Employers must ensure that their employees are trained in the use of AI and comply with all relevant information, documentation, and monitoring obligations.
- In addition to the specific regulations of the AI Regulation, general labor law frameworks must also be observed.
Background
In many private sector companies and public administrations, a new world of work has emerged during the COVID crisis. Flexible working from home or „remotely“ has become established and has massively accelerated the use of digital potential. The responsible, efficient, and economical use of artificial intelligence in companies for task completion and organization cannot be stopped and is already relevant in competition.
With these developments in the background, the European Parliament, in collaboration with the OECD (Organisation for Economic Co-operation and Development), has developed the AI Regulation.
According to the definition by the European Parliament and Council, an AI system is a machine-based system that can operate with varying degrees of autonomy and, based on the inputs it receives, derive outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
The regulation primarily applies to providers and operators of AI systems. Employers who use third-party developed AI systems under their own responsibility are considered operators. Employers who develop AI systems themselves or have them developed are classified as providers.
Objectives of the AI Regulation
The AI Regulation aims to promote human-centric and trustworthy AI, as well as ensure a high level of protection for health, safety, democracy, the rule of law, and the environment. At the same time, it is intended to support the development of innovation.
To achieve these objectives, the regulation provides for a risk-based approach that imposes obligations depending on the area of application of the AI: Specific requirements apply to high-risk AI systems and general-purpose AI (GPAI) models, while basic transparency requirements apply to a broader range of AI systems. In contrast, certain practices involving unacceptable risk—such as manipulating or deceiving individuals, exploiting vulnerabilities, or negatively evaluating individuals based on social behavior (so-called social scoring)—are completely prohibited.
High-risk AI systems
Particularly relevant provisions concern high-risk AI systems used in areas such as human resource management and labor law. These include systems used for hiring or selecting employees, for decisions regarding working conditions, promotions, and terminations, or for monitoring and evaluating the performance and behavior of employees. These systems can significantly impact employees' career prospects and rights.
Prohibited AI Systems
The AI regulation prohibits certain applications classified as an unacceptable risk. This includes practices like social scoring, where people are categorized based on behavior, socioeconomic status, and personal characteristics. Biometric identification and categorization systems, as well as real-time remote identification systems like facial recognition, are also prohibited, except in specific exceptions, for example, for law enforcement agencies.
Employer Requirements
Regardless of the level of risk, employers are required to ensure that their employees have sufficient skills in working with artificial intelligence.
This includes technical knowledge, experience, and relevant education and training. There are also transparency requirements, particularly regarding the interaction of AI systems with humans and the publication of AI-generated content.
In addition, there are specific obligations regarding information, record-keeping, and oversight that are particularly relevant for high-risk AI systems. Employers must ensure that employees affected by a high-risk AI system are informed in advance.
If a works council exists, it must also be informed. Existing union law and national regulations must be observed, including the obligations to inform and consult the works council as laid down in the Works Constitution Act (Betriebsverfassungsgesetz - BetrVG).
Operators of high-risk AI are also required to maintain comprehensive documentation. This includes the automatic logging of system activities, which contain detailed information about the functioning of the AI system, including inputs, processing steps, and outputs. The generated logs must be retained for at least six months. This storage is necessary to allow for subsequent review and analysis of system activities.
Another challenge is the requirement for human supervision. This supervision cannot be carried out by just anyone; rather, the supervisor must possess the necessary competence, training, and authority. Operators must provide these individuals with the necessary support.
Special information requirements apply when high-risk AI systems make decisions regarding natural persons or assist in such decisions. In such cases, data subjects have the right to an explanation of the individual decision, as set forth in Article 86 of the AI Regulation.
Furthermore, employers are obliged to ensure continuous monitoring of the AI system and to take the system out of operation if there is a justified assumption of a disproportionate risk to health, safety, or fundamental rights. There is also a reporting obligation for serious incidents..
Labor law framework
In addition to the specific regulations of the AI Act, the general labor law framework must also be observed:
1. Employee rights and obligations
In an employment relationship, the employee owes, as a rule, the highest personal fulfillment of their work duties according to § 613 of the German Civil Code (BGB), which can be questionable when using AI. Employees are selected based on their personal qualifications and suitability. The use of assistants and tools generally contradicts the requirement of highest personal performance. However, the mere supportive use of AI should not contradict the principle of highest personal performance.
2. The employer’s right to issue instructions
When using AI, employers must also consider that while employees are bound by instructions, they can fundamentally only be assigned activities and tasks that are covered by their duty to work. The scope and limits of the employer's right to issue instructions are determined by § 611a BGB and § 106 GewO, as well as by collective bargaining agreements and company or works council agreements. These principles must also apply when the employer exercises the right to issue instructions to employees in an AI-based manner..
Conclusion
The use of artificial intelligence in the workplace is expected to become widespread or continue to grow in all digitally advanced companies, despite the existing risks. Much like remote work during the COVID-19 crisis, the use of AI will also become established in public administration. The use of AI offers employers numerous opportunities to increase efficiency and will bring about lasting changes to the world of work. The AI Regulation establishes the fundamental legal framework that, together with existing national laws, enables the safe and legally compliant use of AI technologies.
„>