Using AI for employee monitoring was already legally restricted. The EU AI Act makes it even more complex – and costly. Companies deploying high-risk AI systems for application analysis, performance tracking, or emotion recognition must now comply not only with data protection and labor law, but also with extensive requirements of the new AI Regulation. Violations threaten damages claims, fines, and regulatory orders.
Key Facts
- High-risk AI systems in recruiting (application analysis), schools (grade assignment), and customer contact (emotion recognition via voice) fall under the AI Regulation
- The operator (the company) bears responsibility for compliant use – not just the manufacturer
- Automated logs must be retained for at least six months according to the AI Regulation
- The works council has co-determination rights; mere notification is insufficient
Operators, Not Just Manufacturers, Bear Responsibility
The AI Regulation redistributes accountability. While the manufacturer of a high-risk AI system defines its intended purpose and operating instructions, the company as operator must ensure these guidelines are actually followed. Consider this analogy: a truck manufacturer must meet technical standards before the vehicle can hit the road. The company that buys the truck must ensure drivers are trained, know traffic rules, and comply with driving and rest hours.
Applied to AI, this means: Operating instructions cannot disappear into the legal department. They must be read, understood, and applied. Employees must receive training. The employer must verify that the system is actually used as intended.
The Critical Role of Input Data
Particularly sensitive are input data – the prompts and information employees feed into the AI system. This data often comes directly from staff and determines what output the AI generates. In a recruiting example: if a company uses AI to pre-screen applicants, it must control what data HR staff enters. If inappropriate or irrelevant information is used, the AI result can be distorted – potentially discriminating against candidates.
The employer must therefore:
| Requirement | Significance |
|---|---|
| Technical safeguards | System must be protected from unauthorized access |
| Traceability | Every use must be documented and verifiable |
| Compliant use | Ensure the system is used only for its intended purpose |
| Data control | Oversight of input data entered by employees |
Works Council Remains a Co-Decision Maker
Even if AI Regulation compliance is met, the works council retains co-determination rights over technical systems designed to monitor employee behavior or performance. Merely informing the council and then launching monitoring is insufficient. Co-determination is an independent right – separate from data protection and AI Regulation requirements.
What This Means for You
For German companies, especially mid-market firms, compliance becomes three-layered: data protection law, labor law, and now the AI Regulation must all be satisfied in parallel. Companies wanting to deploy high-risk AI should not just purchase a technical solution but develop a compliance framework – with training, documentation, and clear role and responsibility definitions. The FAZ documents one of the most common AI uses in German mid-market: application filtering. Underestimating this risks not only fines but also damages claims from applicants and employees.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




