PowerQuantEU

AI Performance Management — EU AI Act Obligations for Employers

AI Performance Management and the EU AI Act

AI systems used to continuously monitor, score or rank employee performance are classified as high-risk under Regulation (EU) 2024/1689 ("EU AI Act"), Annex III, point 4.

This includes productivity tracking in logistics and manufacturing, AI-assisted performance reviews, predictive attrition models, and automated scoring tools used in call centres or sales organisations. The common element is that the system processes data about identifiable individuals to produce an assessment that influences decisions about their employment.

Scope: What Is Covered

Annex III, point 4 explicitly covers AI systems used to:

  • "monitor and evaluate the performance and behaviour of persons within employment relationships".
  • "allocate tasks based on individual behaviour, personal traits or characteristics".

The wording is broad by design. It covers real-time productivity measurement, periodic performance scoring, AI-driven 360-degree feedback aggregation, and systems that flag underperformance for human review.

Deployer Obligations (Article 26)

As an employer deploying a performance AI system, you are the deployer under the Regulation and bear the following obligations directly:

Human Oversight (Article 14)

The system must be deployed so that qualified and authorised persons can:

  • understand why a particular score or ranking was generated (to the extent the vendor's technical documentation makes this possible),
  • identify anomalies, drift or bias in outputs,
  • override or disregard specific outputs, and
  • pause or switch off the system if needed.

Formal "override" functionality that is never used in practice does not satisfy Article 14. The oversight must be substantive.

Informing Workers (Article 26(7))

Before deploying a high-risk AI system that monitors or evaluates employees, you are required to inform affected workers and their representatives. This is a regulatory obligation distinct from any labour law or collective bargaining requirements, though the two will often apply simultaneously.

Employees have a right to know that a high-risk AI system is being used in connection with decisions about their performance, promotion or working conditions.

Log Retention (Article 26(6))

Operational logs generated by the system during use must be retained for at least six months, to the extent you as deployer control them. For systems where AI outputs directly influenced a documented HR decision (performance review, bonus, disciplinary action), maintaining a record of the system's output alongside the human decision is strongly advisable.

Interaction with GDPR Article 22

GDPR Article 22 gives employees the right not to be subject to a decision based solely on automated processing that significantly affects them — unless explicit consent, contractual necessity or a legal basis exists. Performance decisions (pay, promotion, disciplinary) that directly follow AI outputs without genuine human judgement may trigger this protection. AI Act compliance and GDPR Article 22 compliance must be assessed together.

AI Literacy (Article 4)

Applicable since 2 February 2025. Managers who use AI-generated performance data to inform decisions must have documented training covering: what the system measures, what it does not measure, how to identify potential bias, and how to exercise genuine independent judgement.

Timeline

  • 2 February 2025 — Article 4 (AI literacy) in force.
  • 2 August 2026 — Full EU AI Act enforcement. Fines up to EUR 15 M or 3 % of global turnover for breach of Annex III obligations (Article 101(3)).
  • 2 December 2027 — Digital Omnibus (adopted by European Parliament 16 June 2026, Council 29 June 2026) defers Annex III high-risk obligations to this date. Awaiting publication in the Official Journal; not yet in force. Plan for 2 August 2026 until publication.

What You Need

Documentation for a high-risk performance management AI system covers: system identification and Annex III classification, risk assessment, human oversight policy, worker information records, log retention procedures, and AI literacy training records per manager cohort.

PowerQuant Module 1 delivers this as a source-cited evidence pack within a defined timeframe.

See Module 1 → | Contact us →