Strategy and Planning · Priority topic

    AI in HR with Governance

    By Redaktion techport.ai, HR-Beratung · Last updated on

    AI has long been running in many HR departments, but nobody officially knows it. The recruiter has job advertisements written by a language model, the applicant management provider has activated a ranking feature, and the colleague from payroll asks a chatbot for collective agreement details. This is not misconduct. It is the result of a lack of decisions.

    The question is not whether AI is used in HR work. The question is whether you know where, with what data, with what control, and with what benefit.

    How to recognise it

    • There is no list of AI functionalities active in your HR systems.
    • The provider has switched on a new feature, and the works council noticed it before you did.
    • Pilot projects are running, but nobody can say what they have achieved.
    • When asked about the AI Act, IT replies that it is HR's responsibility, and HR says it is IT's responsibility.

    The legal situation since summer 2026

    The EU AI Regulation classifies AI systems for recruiting, applicant selection, promotion and termination decisions, task allocation, and performance and behaviour assessment as high-risk. With the Digital Omnibus zur KI (Digital Omnibus on AI), which came into force on 27 July 2026, the obligations for these systems apply only from 2 December 2027. Three things nevertheless apply already: Prohibitions, such as emotion recognition in the workplace, have been in effect since February 2025. Transparency obligations, such as the labelling of chatbots, have been in effect since 2 August 2026. And the co-determination of the Betriebsrat (works council) according to the Betriebsverfassungsgesetz (Works Constitution Act) has nothing to do with the AI Act and applies immediately.

    For you, this means: the postponement is preparation time, not a reprieve. Anyone operating high-risk systems in December 2027 must be able to demonstrate risk management, documentation, human oversight, and training by then. Nobody builds that in three months.

    Our approach

    1. Inventory. We record all AI functionalities in your HR systems and in the tools actually used by your employees. The list is usually longer than expected.
    2. Classification. Each use case receives a risk class according to the AI Act, a data protection assessment, and an evaluation regarding co-determination. This results in a matrix with three columns: continue using, rework, decommission.
    3. Governance. We define who approves new AI functionalities, what human oversight specifically entails, and what is documented. This is a two-sided process, not a twenty-page policy.
    4. Secure benefits. For the use cases that remain, we define key performance indicators. An assistant in the HR service desk must measurably reduce tickets, otherwise, it is a gimmick.

    What you gain from it

    • You can tell the works council, management, and if in doubt, the supervisory authority, what AI you use and why.
    • The preparation time until December 2027 is utilised, rather than wasted.
    • AI projects compete for budget with a business case, not with a promise.

    From our projects

    During AI inventories in HR departments, we regularly find twice as many active AI functionalities as HR management had suspected, most of them activated by the software provider via an update. The second recurring observation: The works council is rarely against AI, but almost always against the way they learned about it. An inventory with risk classification defuses both, and it takes three to four weeks in a medium-sized company.

    Good to know

    The text of the KI-Verordnung (AI Regulation) is available on EUR-Lex. The changes introduced by Verordnung (EU) 2026/1744 have been summarised by, among others, KPMG Law. The Bundesnetzagentur (Federal Network Agency) is responsible for market surveillance in Germany. The Bitkom has published a guideline on co-determination in AI.

    Frequently asked questions

    Is a chatbot for employee queries a high-risk system?

    Generally not, as long as it provides information and does not make or prepare decisions about individuals. However, it is subject to transparency obligations: users must be able to recognise that they are interacting with a machine. And it is generally subject to co-determination because it generates usage data.

    What about AI functionalities provided by the software vendor?

    The vendor bears the vendor obligations. As the operator, you bear the operator obligations, which include human oversight, training of users, and informing affected individuals. You cannot buy out of responsibility.

    Let's talk about AI in HR with Governance

    In a thirty-minute first call we clarify where your biggest lever is and whether we are the right partner for it.

    Further reading

    Back to the field Strategy and Planning

    Sources