AI Act from 2 August 2026 - Is your HR department ready for an inspection?

Milena Kowalik-Szeruga | Consulting Director | Crowe Poland
7/20/2026
AI Act from 2 August 2026 - Is your HR department ready for an inspection?

From 2 August 2026, the use of artificial intelligence in HR processes will mean not only greater efficiency, but also new legal obligations.

Organizations using AI for recruitment, candidate screening, employee evaluation, or supporting HR decisions will be required to demonstrate compliance with the requirements of the AI Act. The absence of appropriate procedures and documentation may result in inspections, financial penalties, and liability for violations of the rights of employees and candidates.

This is particularly important for HR departments, recruitment teams, compliance functions, and company management boards.

Over the past few years, many organizations have focused primarily on the opportunities offered by artificial intelligence. Today, AI tools support recruitment processes, CV analysis, candidate assessment, job advertisement creation, talent management, and employee evaluations. At the same time, generative AI tools are increasingly being used to prepare job descriptions, reports, and HR analyses.

The challenge is that in many companies, implementations have taken place rapidly, often without central oversight and without consistent rules governing AI use.

This is where AI Governance comes into play.

AI Act from 2 August 2026

AI Governance - why is it not an IT department project?


One of the most common mistakes organizations make is assuming that compliance with the AI Act can be left entirely to the IT department.

AI Governance is not a technology project.

It is a system for managing the use of artificial intelligence that encompasses processes, people, data, accountability, and oversight.

In practice, responsibility is distributed across multiple organizational functions:

  • HR is responsible for employment-related processes and employee evaluations.
  • Compliance oversees regulatory compliance.
  • Legal assesses legal risks.
  • The Data Protection Officer (DPO) monitors personal data processing.
  • Risk Management identifies and evaluates risks.
  • The Management Board is responsible for oversight mechanisms and fostering a culture of compliance within the organization.

Therefore, AI Governance should be treated as an element of corporate governance, rather than merely a technology initiative.

Read more:
Support from Crowe Poland experts in implementing AI Governance

Why does the AI Act particularly affect HR and recruitment departments?


AI Act from 2 August 2026 - Is your HR department ready for an inspection?

In the employment context, artificial intelligence can influence decisions concerning people. This is precisely why solutions used in recruitment and workforce management are at the center of regulatory attention.

This includes systems supporting:

  • CV analysis and screening,
  • candidate assessment,
  • candidate ranking,
  • hiring recommendations,
  • employee evaluations,
  • promotion decisions,
  • task allocation,
  • performance monitoring,
  • decisions related to termination of employment or cooperation.

The greater the influence of AI on employment-related decisions, the more important transparency, human oversight, risk management, and accountability become.

Are AI systems used by HR considered high-risk systems?


One of the most important elements of the AI Act is its risk-based approach.

The Regulation does not treat all AI applications equally. The greater the impact an AI system has on an individual's rights, opportunities, and life circumstances, the greater the obligations placed upon the organization.

This is why regulators pay particular attention to AI solutions used in employment and workforce management processes.

This means that even if an organization uses AI solely as a support tool for recruiters or managers, it should assess whether the solution is subject to additional requirements under the AI Act.

In practice, the key question is no longer only:

“Do we use AI?”

but also:

“Do we understand the regulatory risks associated with the way we use it?”

Are organizations really facing penalties?


Public discussions surrounding the AI Act often focus on potentially high financial penalties. While sanctions are an important element of the regulation, for most organizations the greater challenge may be demonstrating that AI is used in a controlled and compliant manner.

Nevertheless, the AI Act provides for significant administrative fines for certain violations. Depending on the nature of the infringement, penalties may reach:

  • EUR 35 million or 7% of total worldwide annual turnover for the most serious violations,
  • EUR 15 million or 3% of total worldwide annual turnover for certain compliance-related obligations,
  • EUR 7.5 million or 1% of turnover for selected breaches involving information and documentation obligations.

For most organizations, however, the key takeaway should not be the level of penalties alone.

A far more important question is:

Can we demonstrate during an audit, regulatory inspection, or client inquiry that we have an effective AI Governance framework in place?

Documentation, AI system inventories, risk assessments, oversight procedures, and employee training will form the organization's first line of defense.

The greatest AI risk in HR does not stem from technology


Many organizations assume that if a tool works properly, the problem is solved. This is a dangerous assumption.

AI Governance assessments frequently reveal that companies use dozens of different AI tools implemented independently by various teams.

A typical scenario looks like this: 

  • recruiters use CV screening tools,
  • an AI chatbot communicates with candidates,
  • generative AI creates recruitment advertisements,
  • managers use public AI models to prepare employee evaluations,
  • individual departments independently test new AI solutions.

At the same time, organizations often lack:

  • an AI systems inventory,
  • a formal AI usage policy,
  • a process for approving new tools,
  • risk assessments,
  • human oversight procedures,
  • employee training,
  • a designated business owner responsible for AI.

The technology works.

The governance framework does not exist.

And that may become the organization's greatest challenge during an inspection or audit.

What questions could an inspector or auditor ask?


Imagine a situation in which a candidate or employee raises concerns regarding a process supported by artificial intelligence.

In such circumstances, the organization may be asked to demonstrate how it manages its AI systems.

Common questions include:

  • What AI systems are used within the organization?
  • Who is responsible for their implementation and oversight?
  • Has a risk assessment been conducted?
  • Are AI-supported decisions subject to human review?
  • Have employees and candidates been properly informed about the use of AI?
  • Does the organization maintain AI Governance documentation?
  • Are there procedures for implementing new AI solutions?
  • Have employees been trained in the responsible use of artificial intelligence?

Failure to answer these questions may indicate not only a regulatory issue but also significant business risks.

What risks does the organization face?


Regulatory risk

Financial penalties typically receive the most attention. However, sanctions are only one aspect of the risk.

A much greater challenge may be demonstrating that the organization has a genuine AI management framework and appropriate documentation.

Reputational risk

In HR, reputation plays a crucial role. Information about non-transparent use of AI in recruitment processescan quickly affect how candidates, customers, and business partners perceive the employer.

Legal risk

Improper use of artificial intelligence may lead to:

  • allegations of discrimination,
  • disputes with candidates or employees,
  • proceedings related to personal data protection,
  • compensation claims,
  • negative audit results from clients and business partners.

Ryzyko biznesowe

Increasingly, customers and business partners are asking questions similar to those raised a few years ago regarding GDPR:

  • Does the organization have an AI Governance framework?
  • Does it maintain an AI system inventory?
  • Has it implemented an AI usage policy?
  • Have employees been trained?
  • Is AI being used in compliance with the AI Act?

Answers to these questions are increasingly becoming part of procurement processes, supplier audits, and contractual risk assessments.

Watch now:
AI Governance webinar - responsibilities of management boards and employees

AI Governance assessment - where should you start?


The first step should not be purchasing another AI tool.

The first step should be assessing the organization's current level of AI Governance maturity.

Every company should be able to answer the following questions:

  • Do we know where AI is being used within the organization?
  • Do we maintain an inventory of AI systems?
  • Have we identified high-risk use cases?
  • Is HR using AI in compliance with AI Act requirements?
  • Has a risk assessment been conducted?
  • Is there effective human oversight of AI-supported decisions?
  • Do we have an AI Governance policy?
  • Have employees been trained?
  • Does the management board regularly receive information on AI-related risks?

If the answer to even one of these questions is “no” or “I don't know,” it should be treated as a signal to conduct a comprehensive assessment.

A key question for the management board


In 2026, the most important question is not:

“Are we using artificial intelligence?”

Most organizations already are.

The more important question is:

“Can we demonstrate that we manage artificial intelligence in compliance with the AI Act?”

The ability to document processes, responsibilities, oversight arrangements, and risk assessments will be one of the most important indicators of mature AI Governance.

Technology can be implemented in minutes. The trust of employees, candidates, customers, and regulators takes years to build. That is why the greatest risk is not the use of artificial intelligence itself. The greatest risk is not knowing where, how, and under what rules AI is being used throughout the organization.

Read more:
Support from Crowe Poland experts in implementing AI Governance

Summary


From 2 August 2026, the use of artificial intelligence within organizations will become not only a matter of innovation but also of business and regulatory responsibility.

For many organizations, the greatest challenge will not be the technology itself, but proving that AI is used in a controlled, transparent, and compliant manner.

This is particularly important in HR and recruitment, where AI-assisted decisions can directly affect candidates and employees. Organizations should already be identifying their AI tools, building AI system inventories, implementing policies, and establishing oversight and risk management mechanisms.

AI Governance is no longer a technology project. It is becoming part of corporate governance, much like information security, compliance, and data protection. Organizations that establish a mature AI management framework early will not only mitigate regulatory risks but also gain competitive advantage and greater trust from customers, employees, and business partners.

AI Act - key dates for organizations

The AI Act is being implemented in stages, which means organizations should closely monitor the timeline for the applicability of specific requirements.

Key upcoming dates

  • 2 August 2026 - Most provisions of the AI Act will become applicable, including numerous obligations for organizations using artificial intelligence.
  • 2 August 2027 - Certain additional requirements for selected high-risk AI systems will come into force.

For many organizations, 2026 will be the first year in which regulators begin to expect a documented approach to AI Governance.

Frequently asked questions about the AI Act and AI Governance (FAQ)


Does every company that uses AI fall under the AI Act?

Yes. The AI Act applies both to providers of AI systems and to organizations that use artificial intelligence in their operations. However, the scope of obligations depends on the type of solution and the level of risk associated with its use.

Should the use of ChatGPT within a company also be covered by AI Governance?

Yes. Many organizations mistakenly assume that AI Governance applies only to large, specialized AI systems. In reality, the use of popular generative AI tools such as ChatGPT, Copilot, Gemini, or Claude should also be governed by appropriate policies, procedures, and oversight mechanisms.

Who should be responsible for AI Governance within an organization?

There is no single universal model. Responsibility is typically shared among the management board, compliance, legal, HR, IT, cybersecurity, and the Data Protection Officer. However, it is essential to appoint a process owner and clearly define responsibilities.

Should small and medium-sized enterprises also maintain an inventory of AI systems?

Yes. An AI systems inventory is one of the fundamental tools for risk management. It enables organizations to identify which solutions are being used, by which departments, for what purposes, and with what associated risks.

How often should AI risk assessments be updated?

Risk assessments should not be treated as one-off exercises. They should be reviewed whenever new tools are implemented, business processes change, AI systems gain new functionalities, or incidents and irregularities occur.

Will AI training become necessary?

In practice, yes. Even the best procedures will be ineffective if employees do not know how to use AI safely. Training is particularly important for HR teams, managers, employees who use AI in their daily work, and senior leadership.

Is AI Governance the equivalent of GDPR for artificial intelligence?

This is a simplification, but a partly accurate one. Just as GDPR standardized the management of personal data, AI Governance standardizes the management of artificial intelligence. In both cases, documentation, accountability, oversight, and risk management are critical.

What are the first signs that an organization is not ready for the AI Act?

The most common indicators include:

  • lack of visibility into which AI tools employees use,
  • absence of an AI usage policy,
  • absence of an AI systems inventory,
  • lack of training,
  • lack of risk assessments,
  • absence of an AI Governance process owner,
  • use of public AI models for business information without defined rules.
Beyond regulatory compliance, what benefits does mature AI Governance provide?

The benefits extend far beyond compliance. Organizations gain:

  • greater control over AI usage,
  • reduced legal and operational risks,
  • stronger data protection,
  • increased trust from customers and partners,
  • smoother audit processes,
  • faster and safer implementation of new AI solutions.
Where should organizations begin when building AI Governance?

The best starting point is an assessment of the organization's current state. Only after identifying existing tools, processes, risks, and gaps can an organization effectively design policies, procedures, accountability structures, and training programs.

Milena Kowalik-Szeruga, ESG Manager
Milena Kowalik-Szeruga
Consulting DirectorCrowe Poland

AI Governance

Crowe Poland

See also: