The EU AI Act: 5 things every employer must sort out now
The EU AI Act sounds like something for lawyers and tech companies. But since February 2025 the law affects every organisation that uses AI, including yours. The good news: you do not need to become an expert. You can get these five things in order without any legal knowledge.
Want to understand the law itself in plain terms first? Read our explainer The EU AI Act in plain English. Below is purely what you need to do.
1.Know which risk level your AI falls under
The law sorts AI by risk: from minimal (spam filters, free to use) to banned (social scoring, not allowed). Most office tools, like ChatGPT or an AI assistant inside your software, sit in the lower categories. But the moment AI helps decide about people, for example in hiring or appraisals, it becomes high-risk with strict requirements. Action: make a short list of the AI tools used in your organisation and note what each one is for.
2.Sort out AI literacy for your team
This is the most important and most overlooked obligation. Since 2 February 2025, Article 4 of the law requires everyone who works with AI to understand enough to use it safely. Not optional, but mandatory. Action: make sure staff know the basics, what AI can and cannot do, where it goes wrong and when to step in. A short, practical training is enough to meet this.
3.Check you are not using anything that is banned
Some applications are banned outright, including at work. Think of AI that measures the emotions or stress of employees, systems that give people a behaviour score, or tools that scrape faces from the internet at random. Action: run your tools and plans past this list. Unsure about a system that monitors staff? Then it is worth checking.
4.Set clear rules on data and transparency
Two simple rules prevent most problems. First: no personal data or company secrets in public AI tools. Second: be open when something was made with AI, especially in customer communication. Action: put this in a short, understandable guideline of half a page. People stick to rules they understand, not to a twenty-page policy.
5.Lock in human oversight for decisions about people
The thread running through the whole law: for decisions that affect people, a human stays accountable. AI may advise, but must not decide on its own about an applicant, a customer or a colleague. Action: agree who checks AI output before anything is done with it. That keeps you in control, which is exactly what the law wants.
Point 2 sorted in half a day. Our AI Literacy Essentials training gets your whole team onto a shared foundation and meets the AI literacy obligation. See the training →